|
-
February 18th, 2004, 03:31 PM
#11
Here is a bit more information on Netsky.b from Symantec:
Creates a mutex named "AdmSkynetJKIS003." This mutex allows only one instance of the worm to execute in memory.
Deletes the values:
"Taskmon"
"Explorer"
from the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Deletes the values:
"KasperskyAV"
"System."
from the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Deletes the registry key:
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
Symantec has it listed as a category 3 outbreak and has posted beta definitions here.
Cheers:
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|