Summary

Summary
Action
More Information
| Included in our products from | April 2004 (3.80) |
|---|---|
| Protection available since | 19 February 2004 12:01:34 (GMT) |
| Last updated | 21 April 2004 08:57:54 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
service= "C:\\WINDOWS\\services.exe -serv
and delete it if it exists.
Close the registry editor.
More Information
W32/Netsky-A is a worm that spreads using email and Windows network shares.
W32/Netsky-A searches all mapped drives for files with the following extensions in order to find email adresses: MSG, OFT, SHT, DBX, TBB, ADB, DOC, WAB, ASP, UIN, RTF, VBS, HTML, HTM, PL, PHP, TXT, EML
The worm will also attempt to copy itself into the root folders of drives C: to Z: using the following filenames:
angels.pif
coolscreensaver.scr
dictionary.doc.exe
dolly_buster.jpg.pif
doom2.doc.pif
e.book.doc.exe
e-book.archive.doc.exe
eminem-lickmypussy.mp3.pif
hardcoreporn.jpg.exe
howtohack.doc.exe
matrix.scr
maxpayne2.crack.exe
nero.7.exe
office_crack.exe
photoshop9crack.exe
porno.scr
programmingbasics.doc.exe
rfccompilation.doc.exe
serial.txt.exe
sexsexsexsex.doc.exe
strippoker.exe
virii.scr
winlonghorn.doc.exe
winxp_crack.exe
W32/Netsky-A may arrive in an email with the following characteristics:
Sender: one of -
auctions@yahoo.com
responder@ebay.com
responder@amazon.com
auctions@msn.com
responder@qxl.com
Subject line: Auction successful!
#----------------- message was sent by automail agent ------
Congratulations!
You were successful in the auction
Auction ID <random>
Product ID <random>
A detailed description about the product and the bill are attached to this mail.
Please contact the seller immediately
Thank you!
Attached file: one of -
prod_info_04155.bat
prod_info_04650.bat
prod_info_33325.txt.scr
prod_info_33462.cmd
prod_info_33543.rtf.scr
prod_info_33967.cmd
prod_info_34157.htm.exe
prod_info_42313.pif
prod_info_42314.pif
prod_info_42818.pif
prod_info_43631.doc.exe
prod_info_43859.htm.scr
prod_info_47532.doc.scr
prod_info_49146.exe
prod_info_49541.exe
prod_info_54234.scr
prod_info_54235.scr
prod_info_54433.doc.exe
prod_info_54739.scr
prod_info_55761.rtf.exe
prod_info_56474.txt.exe
prod_info_56780.doc.exe
prod_info_65642.rtf.scr
prod_info_77256.txt.scr
prod_info_87968.htm.scr
or
prod_info_04155.zip
prod_info_04650.zip
prod_info_33325.zip
prod_info_33462.zip
prod_info_33543.zip
prod_info_33967.zip
prod_info_34157.zip
prod_info_42313.zip
prod_info_42314.zip
prod_info_42818.zip
prod_info_43631.zip
prod_info_43859.zip
prod_info_47532.zip
prod_info_49146.zip
prod_info_49541.zip
prod_info_54234.zip
prod_info_54235.zip
prod_info_54433.zip
prod_info_54739.zip
prod_info_55761.zip
prod_info_56474.zip
prod_info_56780.zip
prod_info_65642.zip
prod_info_77256.zip
prod_info_87968.zip
When the file is extracted end opened the virus may display the message "The file could not be opened".
W32/Netsky-A copies itself into the Windows folder as services.exe.
In order to run automatically when Windows starts up W32/Netsky-A creates the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
service= "C:\\WINDOWS\\services.exe -serv
