E-Mail:

Worm.Win32.NetSky.D

Symptoms:
Presence of the following file in Windows directory (%WINDIR%)
“winlogon.exe”

Presence of the following entry in “HKLM\Software\Microsoft\Windows\CurrentVersion\Run” registry key:
“ICQ Net” = “winlogon.exe -stealth”

Technical description:
This variant of the NetSky worm (.D) spreads only via e-mail (in contrast
with previous versions, which spread through some P2P applications as well),
sending itself to e-mail addresses found in the infected computer.”

What Do You Think?

 

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense hard-earned information back to the community, stake a claim on your very own Lockergnome blog today! You can write about anything - no matter the topic. Sign-up to start blogging!

Books, Science - Oct 1, 2008

Head First Physics

64 queries / 2.648 seconds.