Worm.Win32.NetSky.D
- 0
- Add a Comment
“Symptoms:
Presence of the following file in Windows directory (%WINDIR%)
“winlogon.exe”
Presence of the following entry in “HKLM\Software\Microsoft\Windows\CurrentVersion\Run” registry key:
“ICQ Net” = “winlogon.exe -stealth”
Technical description:
This variant of the NetSky worm (.D) spreads only via e-mail (in contrast
with previous versions, which spread through some P2P applications as well),
sending itself to e-mail addresses found in the infected computer.”
