Virus Information
Discovery Date: 03/04/2004
Origin: Unknown
Length: 27,648 bytes (telock)
Type: Virus
SubType: E-mail
This variant is very similar to W32/Netsky.f@MM .
This virus spreads via email. It sends itself to addresses found on the victim's machine. The virus also attempts to deactivate the various other viruses (variants of W32/Mydoom and W32/Bagle).
Mail propagation
The virus may be received in an email message as follows:
From: (forged address taken from infected system)
More: http://vil.nai.com/vil/content/v_101076.htm
Aliases
I-Worm.NetSky.g, W32/Netsky.c@MM
Type
Win32 worm
Description
W32/Netsky-G is a worm that spreads via email.
In order to run automatically when Windows starts up the worm copies itself to the file avguard.exe in the Windows folder and creates the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Special Firewall Service
= "C:\WINDOWS\avguard.exe -av service"
A detailed analysis of W32/Netsky-G will be published here shortly. Please check again later.
http://www.sophos.com/virusinfo/analyses/w32netskyg.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic