|W32.Netsky.L@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning hard drives and mapped drives.
Copies itself as %Windir%\AVprotect.exe.
Adds the value:
to the registry key:
so that the worm runs when you start Windows.
Retrieves email addresses from the files that have these extensions:
.adb .asp .cgi .dbx .dhtm .doc .eml .htm .html .jsp .msg .oft .php .pl .rtf
.sht .shtm .tbb .txt .uin .vbs .wab .wsh .xml
The email has the following characteristics:
Subject: The subject is one of the following:
Re: Your document
Re: Your details
Message: The message is one of the following:
Your file is attached.
Please read the document.
Your document is attached.
Please read the attached file.
Please see the attached file for details.
Attachment: The attachment is one of the following:
your_file_%s.pif, details_%s.pif, document_%s.pif, %s.pif
where %s is the portion of the "To" address before the "@".
Navigate to the key:
and delete the value:
Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.
Still have a problem? Ask for help at our discussion forum.