手机站
网通分站
电信主站
密 码:
用户名:
当前位置 : 主页>服务器技术>安全防护>列表

Worm.Win32.Atak.j

来源:互联网 作者:west263.com 时间:2008-02-23
西部数码-全国虚拟主机10强!40余项虚拟主机管理功能,全国领先!双线多线虚拟主机南北访问畅通无阻!免费赠送企业邮局,.CN域名,自助建站480元起,免费试用7天,满意再付款! P4主机租用799元/月.月付免压金!
病毒名称: Worm.Win32.Atak.j 类别: 蠕虫病毒 病毒资料: 破坏方法:

一个简单的蠕虫病毒.

病毒行为:

病毒运行后,将自己复制到%system%目录下,文件名为%随机字符%.exe.并在WIN.INI的WINDOWS节RUN项中加入%system%\%随机字符%.EXE以达到随系统启动的目的.

随后病毒驻留内存,搜索磁盘尝试从以下扩展名的文件中提取email地址.并向其发送病毒
邮件.
病毒将跳过地址中包含以下字串的地址

@pspl
@norman
@ozemail
@karpersky
@commandsoftware
@centralcommand
@eAladdin
@free-av
@bitdefender
@vsnl
@complex
@f-secure
@sophos
@symantec
@microsoft
submit
virus
samples
microsoft

邮件标题:

human spirit
Not Wars
and get money
for fun
will freedom
to other
with me
Not spam
...

邮件正文:

We have installed our anti-spam tools to protect your email
Your account info has been setting up to block spam email
We have make a few change for our customer. Please be informed
We have upgraded your account features
Your account has been upgraded with our new services
has been attached as a file and ready to be printed
[please change it after registeration]
(You can change it later)
(temp. pwd only)
(temporary passWord)

Remember this note
Please take note this info
Keep this info
Your account info
know about account features.
learn about our features.
get more info.
find out our services.
...

邮件附件扩展名:

.zip
病毒的清除法: 使用光华反病毒软件,彻底删除。 病毒演示: 病毒FAQ: Windows下的PE病毒。
发现日期: 2004-12-17

文章整理:西部数码--专业提供域名注册虚拟主机服务
http://www.west263.com
以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢!