Symantec has declared both the "X" and "Y" variants of Netsky as MEDIUM RISK due to extensive occurrences in the wild.
Netsky.Y - MEDIUM RISKhttp://vil.nai.com/vil/content/v_112148.htmhttp://www.symantec.com/avcenter/venc/data...email@example.com
W32.Netsky.Y@mm is a variant of W32.Netsky.X@mm that scans for the email addresses on all non-CD-ROM drives on an infected computer. Then, the worm uses its own SMTP engine to send itself to the email addresses that it finds. This threat is compressed with PE-Pack.
The format of the email is:
Subject: Delivery failure notice (ID-<random number>)
Attachment: www.<random domain name>.<random username>.session-<random number>.com