 |
|
W32.Netsky.B is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning the hard drives and mapped drives. This worm also searches drives C through Z for folder names containing "Share" or "Sharing," and then copies itself to those folders.
The Subject, Body, and email attachment vary.
Symantec Security Response has developed a removal tool to clean the infections of W32.Netsky.B@mm.
For more information and removal instructions,
please visit Symantec Security Response: If you cannot access this url, copy and paste it into your browser. http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.b@mm.htmll
This worm re-emphasizes the basic
practice that corporations need to take:
Download
and deploy the most up-to-date virus definitions
Turn
off and remove unneeded services
Check
vendor Web sites for patches and updates
Block
or remove email that contains suspect file attachments
Isolate
infected machines from the network
Train
users not to open attachments unless they are expecting them
Research
information about the virus
Trace
the path of introduction
Symantec can provide customers support
against this worm in several ways:
Symantec
AntiVirus solution provide definition file to protect users in multiple
levels, including gateway, mail server and client.
Norton
AntiVirus prevents infected file to be spread out to other users by using
worm-blocking technology.
DeepSight
Alert Services and Threat Management System sends a notification when a
worm is detected with updates on how to mitigate the risk, information
on multiple antivirus vendor updates.
Symantec
IDS solutions will have signatures to be able to detect this new worm.
|
|
|
 |