Jammer2nd.exe
What is it?
WORM_NETSKY.Z
-
Jammer2nd.exe
What does it do?
This NETSKY variant propagates via email using its own Simple Mail Transfer Protocol (SMTP) engine.
It gathers email address from files with certain extension names to spoof the "From:" field of the email. It randomizes the email?s subject, message body and attachment names from lists of specific strings and file names present in the malware code. It may use several external DNS servers for its propagation routine, which are hardcoded in its body.
This malware also has backdoor capabilities. It listens to port 665 for commands from remote users. Once outside connection is established, this malware is then able to download and execute files on infected systems.
Removal:
Trend Micro has the full dirt ( HERE )