Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32/Netsky.a@MM

Feb 16, 2004 12:04AM PST

Internet Worm Information
Discovery Date: 02/16/2004
Origin: Unknown
Length: 21504 bytes
Type: Internet Worm
SubType: E-mail worm

This is a detection for a new nework worm spreading via EMail, sending itself to addresses found on the victim machine and by copying itself mapped network drives.

When executed, the worm copies itself into %windir% folder using the filename SERVICES.EXE. It addes a key to the registry, so it gets activated on system start.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run "service" =
C:\WINNT\services.exe -serv

Read more: http://vil.nai.com/vil/content/v_101027.htm

Discussion is locked