NetSky.Y worm was discovered late night on April 20th, 2004. It is similar to the Netsky.X variant found earlier during the same day. It is repacked with PEpack.

Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Eliminating a Local Network Outbreak

If the infection is in a local network, please follow the instructions on this webpage:

Technical Details

For more information on Netsky.X see: Netsky.X

Netsky.Y sends email messages that look as follows:

Subject: Delivery failure notice (ID-random number)
 Attachment: www.random domain name.random user name.session.random number.com

The body of the message contains one of the following words:

Partial, External, New or Delivered

followed by the text:

message is available

