W32/Netsky.p.eml!exe

This page shows details and results of our analysis on the malware W32/Netsky.p.eml!exe

Overview

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.


Minimum DAT

4347 (2004-04-04)

Updated DAT

4698 (2006-02-16)

Minimum Engine

5.1.00

File Length

N/A

Description Added

2004-04-21

Description Modified

2004-04-21

Malware Proliferation

Characteristics

W32/Netsky.p.eml!exe is the detection of W32/Netsky.p@MM in .exe format within an email message.

Receiving this detection is not an indication that the local system has become actively infected.  It's simply an indication that a user has received an email message that contained an infectious attachment.  The attachment must be run, manually, in order for infection to occur.

For information on this threat, see:
http://vil.nai.com/vil/content/v_101119.htm

Symptoms

Method of Infection

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Variants