手机站
网通分站
电信主站
密 码:
用户名:
当前位置 : 主页>服务器技术>安全防护>列表

Worm.P2P.Vb.a

来源:互联网 作者:west263.com 时间:2008-02-23
西部数码-全国虚拟主机10强!40余项虚拟主机管理功能,全国领先!双线多线虚拟主机南北访问畅通无阻!免费赠送企业邮局,.CN域名,自助建站480元起,免费试用7天,满意再付款! P4主机租用799元/月.月付免压金!
病毒名称: Worm.P2P.Vb.a 类别: 蠕虫 病毒资料: 破坏方法:

VB写的 蠕虫,通过P2P和邮件传播

它将创建下列注册表键值来使自己随Windows系统自启动:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion\Run
worm = "%CURDIR%\%CURFILE%"

感染:

病毒通过P2P文件共享和邮件传播,病毒通过P2P传播时发送的信息为:
Watch this first!
Cool addon
New Microsoft Service Pack Available
Try to use this
Very nice IRC script
Please help
War makes no good...help!
New ProdUCt: AMD Athlon XP Processor 2300
Let the religion conflicts die!
Happy to hear from you!
Lets go out some day!
Security Patch for Windows
Tips: HOW TO PREVENT YOUR PC FROM ATTACKED!
Free porno trailer here!!!
Hot,wild tits for free...
Check this out...very funny!
Microsucks gets busted with low security
Matrix all the way!
Loveletter...noooo!
GTA ViceCity FAQ
Human body lecture
Your wife naked
Metallica concert pics
Company jobs now
Pamela Anderson naked!
Biggest tits arround!
Horny teens ...wow!
Get naked for me
Blow job causes cancer!
Metallica new album!!!
Free concert tickets!
Your new payday is today
Very funny animation
Hotmail Staff needs your help!
Try it now! Totally awsome!

Summer means hot girls!
Meet Angelica Jolie's pussy
Police wanted level
FBI gives reward for criminal
New porn show every day for FREE!
Mission Impossible 3 Stunts Trailer
Just try this!
发送的文件就是病毒。

通过Outlook邮件传播时可能的信息是:

标题: "Hello my friend!
I dont know if you remember me so good. I do and I will never forget you and
Please reply if you want to know who I am!"
正文:
"how you helped me the last time we met. Thats why I wish to make you a gift,
a small sign of my everlasting friendship! Please check it out before its not too late.
With deep friendship,
Your old friend."
附件就是病毒。

网络传播:

此处是网络传播信息

病毒危害:

注:

%SYSDIR% 是可变的WINDOWS系统文件夹,默认为: C:\Windows\System (Windows 95/98/Me),
C:\Winnt\System32 (Windows NT/2000), 或 C:\Windows\System32 (Windows XP).
%WINDIR% 是可变的,是WINDOWS的安装目录(默认为: C:\Windows or C:\Winnt).
病毒的清除法: 使用光华反病毒软件,彻底删除。 病毒演示: 病毒FAQ: Windows下的PE病毒。
发现日期: 2004-4-15

文章整理:西部数码--专业提供域名注册虚拟主机服务
http://www.west263.com
以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢!