  Randy Bell Premium join:2002-02-24 Santa Clara, CA
| reply to Randy Bell Re: W32/Netsky-AC {Sophos}
Trend: WORM_NETSKY.AC »www.trendmicro.com/vinfo/virusen···ETSKY.AC Tech Details: »www.trendmicro.com/vinfo/virusen···&VSect=T
quote: Upon execution, this NETSKY variant drops the following files in the Windows folder:
•CCOMP.CPL a copy of itself •WSERVER.EXE its memory-resident component
It creates the following registry entry so that it executes at every system startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\Run Wserver = "%Windows%\wserver.exe"
(Note: %Windows% is the default Windows folder, usually C:\Windows or C:\WINNT.)
{See above link for tech details including email message bodies, attachments} -- "But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13) |