Proland Software  Buy Antivirus software now!

Home
Antivirus products
Download Antivirus Software
Order On-line
Support
Email
Protector Plus Antivirus Software for
Antivirus Software for Windows XP and 2000
Antivirus Software for Windows Vista
Antivirus Software for Windows Me and 98
Antivirus Software for Exchange
Antivirus Software for NetWare
Protector Plus Console
Buy Antivirus software now!


SpamChoke Antispam
Software

Subscribe to Virus Alert
Mailing List

Enter your Email
(Ex : john@company.com)






Download Anti virus software

W32/Netsky.I Worm

Blueball Information about the W32/Netsky.I worm:

W32/Netsky.I is a mass mailing worm. This worm infects Windows systems and spreads through email.

The infected email carries the following 'From' address;

service@(user's domain).com

The subject of the infected email will be any one of the following;

Mail account closed
Mail accounnt deactivated
Mail account expired

The body of the email will be any one of the following;

Your mail account has been closed. Click on the link for further details.
Your mail account has been deactivated. To reactivate, follow the link.
Your mail account expired. Please follow the link to reactivate.

The infected email has an attachment which looks like a hyperlink;

http://www.(user's domain).com/username/index.scr

Upon execution of the infected attachment, the worm copies itself as FOODING.EXE in the Windows folder. It creates a mutex KO[SkyNet.cz]SystemsMutex to check the presence of the worm in system memory.

The worm modifies registry at the following location to run itself at the startup;

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

To propagate itself, the worm scans the files having the following extensions and collects all the available email addresses from the infected system;

.wab
.vbs
.uin
.txt
.tbb
.shtm
.sht
.rtf
.pl
.php
.oft
.msg
.html
.htm
.eml
.doc
.dhtm
.dbx
.cgi
.asp
.adb

The worm skips certain email addresses, which contain the following text strings, to evade security software detection:

ymantec
sophos
skynet
orton
orman
messagelabs
itdefender
iruslis
icrosoft
freeav
f-secur
f-pro
cafee
aspersky
antivir
antivi
andasoftwa
abuse

After this, the worm mails itself to these addresses using its own SMTP engine.

This worm first appeared on March 8, 2004.

Blueball Other names of W32/Netsky.I worm:

This worm is also known as W32/NetSky.I@mm, I-Worm.NetSky.i, W32.NetSky.I@mm.


Click here to download a 30 day Evaluation Copy of
Protector Plus anti virus software for your operating system

Blueball About Protector Plus Antivirus Software Packages:

Proland Software is the developer of Protector Plus range of antivirus software packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS and NetWare servers.

SpamChoke Antispam Software

New:
SpamChoke Antispam Software
Download Now!

Protector Plus range of antivirus products offer on-line virus detection and removal. All the packages have the ability to detect and isolate all types of viruses, trojans, worms and other types of malware. Protector Plus antivirus software can detect and remove W32/Netsky.I worm reliably.

These products are updated on a continuous basis and the latest upgrades for all the platforms are made available for downloading from this site.

Click here to order
Protector Plus Antivirus software
 

Buy Antivirus software now!


You can download the 30 day evaluation copy of the
antivirus software free of cost for these platforms:
Antivirus Software for Windows XP and 2000 Antivirus Software for Windows Me and 98 Antivirus Software for Exchange Antivirus Software for NetWare


HomeAntivirus productsDownload Antivirus SoftwareOrder On-lineEmail

Copyright © 2007 Proland Sofrware. All rights reserved.


Download Anti virus software