主 页  下载中心 文章中心 在线杀毒 软件论坛
国内杀毒软件     瑞星杀毒 金山毒霸 江民杀毒 光华反病毒 更多... 木马专杀   木马杀客 木马克星 木马清道夫 AVG(原Ewido)Anti-Spyware 更多...
国外杀毒软件     卡巴斯基   诺顿   趋势 安博士 熊猫卫士  小红伞 驱逐舰 麦咖啡McAfee   NOD32   F-Secure   Dr.Web   Avast   更多...
升级补丁   瑞星升级 金山毒霸升级 江民升级 光华升级 卡巴斯基升级 诺顿升级 趋势升级 安博士升级 NOD32升级 Dr.Web升级 Avast升级
流氓软件清理     360安全卫士 瑞星卡卡   金山毒霸系统清理专家 Wopti流氓软件清除大师   恶意软件清理助手   超级兔子网络卫士 更多...
防火墙     天网 费尔 冰盾 更多... 病毒专题     熊猫烧香病毒专题 电眼间谍病毒专题 AV终结者病毒专题 灰鸽子清理     更多...
系统漏洞补丁     windowXP系统漏洞补丁 window2000系统漏洞补丁 window2003系统漏洞补丁 windowVISTA系统漏洞补丁 更多...
 您当前的位置:爱客者 -> 文章中心 -> 安全技术 -> 杀毒技术 -> 文章内容
mydoom最新变种ab(worm.mydoom.ab)分析报告
来源:网络 时间:2006-5-18
 

病毒名称: worm.mydoom.ab

中文名称: 诺维格变种ab

威胁级别: 二级

病毒别名: i-worm.mydoom.y[avp]

发现日期: 2004.09.17

病毒简介:

a、该病毒会把自身复制到windows目录下并以服务的形式随计算机启动而运行.;

b、通过修改注册表禁止使用注册表工具(regedit);

c、修改hosts文件使用户无法登录一些安全或反病毒公司主页;

d、通过icq发送带毒链接来传播自身;

e、从指定的网站下载后门木马到用户机器上;

f、结束用户机器上的反病毒软件的进程;

g、向外发送大量的带毒邮件,而造成网络堵塞。

技术特点:

1、把自己复制到%systemroot%services.exe

2、修改注册表:

a.win9x:

在注册表主键"hklm\software\microsoft\windows\currentversion\run"下,

添加如下键值:"serv"="%systemroot%services.exe"

b.win2000/xp:

创建服务:

服务名: netbios ext

显示名称: netbios ext

执行路径: %windir%\services.exe serv

启动类型: automatic

增加hkey_local_machine\system\currentcontrolset\services\netbios ext

hkey_local_machine\system\currentcontrolset\services\netbios ext\type = "0x10"

hkey_local_machine\system\currentcontrolset\services\netbios ext\start = "0x2"

hkey_local_machine\system\currentcontrolset\services\netbios ext\errorcontrol = "0x1"

hkey_local_machine\system\currentcontrolset\services\netbios ext\imagepath =

"%systemroot%\services.exe serv"

hkey_local_machine\system\currentcontrolset\services\netbios ext\displayname = "netbios ext"

hkey_local_machine\system\currentcontrolset\services\netbios ext\security\security

hkey_local_machine\system\currentcontrolset\services\netbios ext\objectname = "localsystem"



3、修改注册表项

hkey_current_user\software\microsoft\windows\currentversion\policies

\disableregistrytools = "0x0"

hkey_local_machine\software\microsoft\windows\currentversion\policies

\disableregistrytools = "0x0"


4、修改%system%\drivers\etc\hosts文件,使用户不能正常登录反病毒相关网站

127.0.0.1 www.avp.com

127.0.0.1 www.viruslist.com

127.0.0.1 viruslist.com

127.0.0.1 www.symantec.com

127.0.0.1 networkassociates.com

127.0.0.1 secure.nai.com

127.0.0.1 downloads1.kaspersky-labs.com

127.0.0.1 downloads2.kaspersky-labs.com

127.0.0.1 downloads3.kaspersky-labs.com

127.0.0.1 downloads4.kaspersky-labs.com

127.0.0.1 downloads-us1.kaspersky-labs.com

127.0.0.1 downloads-eu1.kaspersky-labs.com

127.0.0.1 kaspersky-labs.com

127.0.0.1 www.networkassociates.com

127.0.0.1 us.mcafee.com

127.0.0.1 f-secure.com

127.0.0.1 avp.com

127.0.0.1 www.sophos.com

127.0.0.1 sophos.com

127.0.0.1 www.ca.com

127.0.0.1 ca.com

127.0.0.1 securityresponse.symantec.com

127.0.0.1 symantec.com

127.0.0.1 mast.mcafee.com

127.0.0.1 my-etrust.com

127.0.0.1 www.kaspersky.com

127.0.0.1 www.f-secure.com

127.0.0.1 dispatch.mcafee.com

127.0.0.1 update.symantec.com

127.0.0.1 nai.com

127.0.0.1 www.nai.com

127.0.0.1 liveupdate.symantec.com

127.0.0.1 customer.symantec.com

127.0.0.1 rads.mcafee.com

127.0.0.1 trendmicro.com

127.0.0.1 liveupdate.symantecliveupdate.com

127.0.0.1 www.mcafee.com

127.0.0.1 mcafee.com

127.0.0.1 viruslist.com

127.0.0.1 www.my-etrust.com

127.0.0.1 download.mcafee.com

127.0.0.1 updates.symantec.com

127.0.0.1 kaspersky.com

127.0.0.1 www.trendmicro.com

5、通过icq发送带毒链接来传播自身

funn http:/ /*******/icon/game.exe :-):-):-)



http:/ /******/icon/game.exe :-):-)

http:/ /******/icon/game.exe funny :-);-)

http:/ /******50/icon/game.exe ;-);-);-);-)

best game http:/ /******/icon/game.exe ;-);-);-)

http:/ /******/icon/game.exe lol!! ;-);-);-)

http:/ /www.******/claroline142/photo.exe i cried :-)

http:/ /www.******/claroline142/photo.exe lol :-):-)

my photos (archived) http:/ /www.******/claroline142/photo.exe

i now play in game http://www.******.com/ajr/game.exe :-):-)

funy game http:/ /www.******.com/ajr/game.exe ;-);-);-)

fun game http:/ /www.******.com/ajr/game.exe :-):-):-)

6、从以下网站下载一后门木马:

http:/ /www.******.com/heyyo/wassup/00000008.cgi

http:/ /www.*******.com/adclik/click.dat

http:/ /www.*******.it/forumbb/postmsg.gif

http:/ /www.*******.de/html/content/guestbook/data/data2.dat

http:/ /www.*******.unibo.it/claroline142/claroline/index.gif

http:/ /www.*******.com/grafix/cover_v3.jpg

http:/ /*******/manual/images/apache.gif

7、查找反病毒软件和其它蠕虫病毒(结束并删除),如下:


f-agobot.exe

hijackthis.exe

_avpm.exe

_avpcc.exe

_avp32.exe

zonealarm.exe

zonalm2601.exe

zatutor.exe

zapsetup3001.exe

zapro.exe

xpf202en.exe

wyvernworksfirewall.exe

wupdt.exe

wupdater.exe

wrctrl.exe

wradmin.exe

wnt.exe

wnad.exe

wkufind.exe

winupdate.exe

wintsk32.exe

winstart001.exe

winstart.exe

winssk32.exe

winrecon.exe

winppr32.exe

winmain.exe

winlogin.exe

wininitx.exe

wininit.exe

wininetd.exe

windows.exe

window.exe

winactive.exe

win32us.exe

win32.exe

win-bugsfix.exe

wimmun32.exe

whoswatchingme.exe

wgfe95.exe

wfindv32.exe

webtrap.exe

webscanx.exe

webdav.exe

watchdog.exe

w9x.exe

w32dsm89.exe

vswinperse.exe

vswinntse.exe

vswin9xe.exe

vsstat.exe

vsmon.exe

vsmain.exe

vsisetup.exe

vshwin32.exe

vsecomr.exe

vsched.exe

vscenu6.02d30.exe

vscan40.exe

vptray.exe

vpfw30s.exe

vpc42.exe

vpc32.exe

vnpc3000.exe

vnlan300.exe

virusmdpersonalfirewall.exe

vir-help.exe

vfsetup.exe

vettray.exe

vet95.exe

vet32.exe

vcsetup.exe

vbwinntw.exe

vbwin9x.exe

vbust.exe

vbcons.exe

vbcmserv.exe

utpost.exe

upgrad.exe

updat.exe

undoboot.exe

tvtmd.exe

tvmd.exe

tsadbot.exe

trojantrap3.exe

trjsetup.exe

trjscan.exe

trickler.exe

tracert.exe

titaninxp.exe

titanin.exe

tgbob.exe

tfak5.exe

tfak.exe

teekids.exe

tds2-nt.exe

tds2-98.exe

tds-3.exe

tcm.exe

tca.exe

tc.exe

tbscan.exe

taumon.exe

taskmon.exe

taskmo.exe

sysupd.exe

system32.exe

system.exe

sysedit.exe

symtray.exe

symproxysvc.exe

sweepnet.sweepsrv.sys.swnetsup.exe

sweep95.exe

svchostc.exe

svc.exe

supporter5.exe

support.exe

supftrl.exe

stcloader.exe

start.exe

st2.exe

ssg_4104.exe

ssgrate.exe

ss3edit.exe

srng.exe

srexe.exe

spyxx.exe

spoolsv32.exe

spoolcv.exe

sphinx.exe

spf.exe

sperm.exe

sofi.exe

soap.exe

smss32.exe

sms.exe

smc.exe

showbehind.exe

shn.exe

shellspyinstall.exe

sh.exe

sgssfw32.exe

sfc.exe

setup_flowprotector_us.exe

setupvameeval.exe

servlces.exe

servlce.exe

serv95.exe

sd.exe

scrsvr.exe

scrscan.exe

scanpm.exe

scan95.exe

scan32.exe

scam32.exe

sc.exe

sbserv.exe

savenow.exe

save.exe

sahagent.exe

safeweb.exe

ruxdll32.exe

rundll16.exe

rundll.exe

rulaunch.exe

rtvscn95.exe

rtvscan.exe



rshell.exe

rrguard.exe

rescue32.exe

rescue.exe

reged.exe

realmon.exe

rcsync.exe

rb32.exe

ray.exe

rav8win32eng.exe

rav7win.exe

rav7.exe

rapapp.exe

qserver.exe

qconsole.exe

pview95.exe

pussy.exe

purge.exe

pspf.exe

protectx.exe

proport.exe

programauditor.exe

procexplorerv1.0.exe

processmonitor.exe

procdump.exe

prmvr.exe

prmt.exe

prizesurfer.exe

ppvstop.exe

pptbc.exe

ppinupdt.exe

powerscan.exe

portmonitor.exe

portdetective.exe

popscan.exe

poproxy.exe

pop3trap.exe

platin.exe

pingscan.exe

pgmonitr.exe

pfwadmin.exe

pf2.exe

perswf.exe

persfw.exe

periscope.exe

penis.exe

pdsetup.exe

pcscan.exe

pcip10117_0.exe

pcfwallicon.exe

pcdsetup.exe

pccwin98.exe

pccwin97.exe

pccntmon.exe

pcciomon.exe

pcc2k_76_1436.exe

pcc2002s902.exe

pavw.exe

pavsched.exe

pavproxy.exe

pavcl.exe

patch.exe

panixk.exe

padmin.exe

outpostproinstall.exe

outpostinstall.exe

otfix.exe

ostronet.exe

optimize.exe

onsrvr.exe

ollydbg.exe

nwtool16.exe

nwservice.exe

nwinst4.exe

nvc95.exe

nvarch16.exe

nui.exe

ntxconfig.exe

ntrtscan.exe

nt.exe

nsupdate.exe

nstask32.exe

nssys32.exe

nsched32.exe

npssvc.exe

npscheck.exe

nprotect.exe

npfmessenger.exe

npf40_tw_98_nt_me_2k.exe

notstart.exe

norton_internet_secu_3.0_407.exe

normist.exe

nod32.exe

nmain.exe

nisum.exe

nisserv.exe

netutils.exe

netspyhunter-1.2.exe

netscanpro.exe

netmon.exe

netinfo.exe

netd32.exe

netarmor.exe

neowatchlog.exe

neomonitor.exe

ndd32.exe

ncinst4.exe

nc2000.exe

navwnt.exe

navw32.exe

navstub.exe

navnt.exe

navlu32.exe

navengnavex15.navlu32.exe

navdx.exe

navapw32.exe

navapsvc.exe

navap.navapsvc.exe

auto-protect.nav80try.exe

nav.exe

n32scanw.exe

mwatch.exe

mu0311ad.exe

msvxd.exe

mssys.exe

mssmmc32.exe

msmsgri32.exe

msmgt.exe

mslaugh.exe

msinfo32.exe

msiexec16.exe

msdos.exe

msdm.exe

msconfig.exe

mscman.exe

msccn32.exe

mscache.exe

msblast.exe

msbb.exe

msapp.exe

mrflux.exe

mpftray.exe

mpfservice.exe

mpfagent.exe

mostat.exe

moolive.exe

monitor.exe

mmod.exe

minilog.exe

mgui.exe

mghtml.exe

mgavrte.exe

mgavrtcl.exe

mfweng3.02d30.exe

mfw2en.exe

mfin32.exe

md.exe

mcvsshld.exe

mcvsrte.exe

mctool.exe

mcshield.exe

mcmnhdlr.exe

mcagent.exe

mapisvc32.exe

luspt.exe

luinit.exe

lucomserver.exe

luau.exe

lsetup.exe

lordpe.exe

lookout.exe

lockdown2000.exe

lockdown.exe

localnet.exe

loader.exe

lnetinfo.exe

ldscan.exe

ldpromenu.exe

ldpro.exe

ldnetmon.exe

launcher.exe

killprocesssetup161.exe

kernel32.exe

kerio-wrp-421-en-win.exe

kerio-wrl-421-en-win.exe

kerio-pf-213-en-win.exe

keenvalue.exe

kavpf.exe

kavpers40eng.exe

kavlite40eng.exe

jedi.exe

jdbgmrg.exe

jammer.exe

istsvc.exe

isrv95.exe

isass.exe

iris.exe

iparmor.exe

iomon98.exe

intren.exe

intdel.exe

init.exe

infwin.exe

infus.exe

inetlnfo.exe

ifw2000.exe

iface.exe

iedriver.exe

iedll.exe

idle.exe

icsuppnt.exe

icmon.exe

icloadnt.exe

icload95.exe

ibmavsp.exe

ibmasn.exe

iamstats.exe

iamserv.exe

iamapp.exe

hxiul.exe

hxdl.exe

hwpe.exe

htpatch.exe

htlog.exe

hotpatch.exe

hotactio.exe

hbsrv.exe

hbinst.exe

hacktracersetup.exe

guarddog.exe

guard.exe

gmt.exe

generics.exe

gbpoll.exe

gbmenu.exe

gator.exe

fsmb32.exe

fsma32.exe

fsm32.exe



fsgk32.exe

fsav95.exe

fsav530wtbyb.exe

fsav530stbyb.exe

fsav32.exe

fsav.exe

fsaa.exe

frw.exe

fprot.exe

fp-win_trial.exe

fp-win.exe

fnrb32.exe

flowprotector.exe

firewall.exe

findviru.exe

fih32.exe

fch32.exe

fast.exe

fameh32.exe

f-stopw.exe

f-prot95.exe

f-prot.exe

f-agnt95.exe

explore.exe

expert.exe

exe.avxw.exe

exantivirus-cnet.exe

evpn.exe

etrustcipe.exe

ethereal.exe

espwatch.exe

escanv95.exe

escanhnt.exe

escanh95.exe

esafe.exe

ent.exe

emsw.exe

efpeadm.exe

ecengine.exe

dvp95_0.exe

dvp95.exe

dssagent.exe

drweb32.exe

drwatson.exe

dpps2.exe

dpfsetup.exe

dpf.exe

doors.exe

dllreg.exe

dllcache.exe

deputy.exe

defwatch.exe

defscangui.exe

defalert.exe

dcomx.exe

datemanager.exe

claw95.exe

cwntdwmo.exe

cwnb181.exe

cv.exe

ctrl.exe

cpfnt206.exe

cpf9x206.exe

cpd.exe

connectionmonitor.exe

cmon016.exe

cmgrdian.exe

cmesys.exe

cmd32.exe

click.exe

cleanpc.exe

cleaner3.exe

cleaner.exe

clean.exe

claw95cf.exe

cfinet32.exe

cfinet.exe

cfiadmin.exe

cfgwiz.exe

cfd.exe

cdp.exe

ccpxysvc.exe

ccevtmgr.exe

ccapp.exe

bvt.exe

bundle.exe

bs120.exe

brasil.exe

bpc.exe

borg2.exe

bootwarn.exe

bootconf.exe

blss.exe

blackice.exe

blackd.exe

bisp.exe

bipcpevalsetup.exe

bipcp.exe

bidserver.exe

bidef.exe

belt.exe

bd_professional.exe

bargains.exe

backweb.exe

avxmonitornt.exe

avxmonitor9x.exe

avwupsrv.exe

avwupd.exe

avwinnt.exe

avwin95.exe

avsynmgr.exe

avsched32.exe

avptc32.exe

avpm.exe

avpdos32.exe

avpcc.exe

avp32.exe

avp.exe

avnt.exe

avltmain.exe

avkwctl9.exe

avkservice.exe

avkserv.exe

avkpop.exe

avgw.exe

avguard.exe

avgserv9.exe

avgserv.exe

avgnt.exe

avgctrl.exe

avgcc32.exe

ave32.exe

avconsol.exe

au.exe

atwatch.exe

atro55en.exe

atguard.exe

atcon.exe

arr.exe

apvxdwin.exe

aplica32.exe

apimonitor.exe

ants.exe

antivirus.exe

anti-trojan.exe

amon9x.exe

alogserv.exe

alevir.exe

alertsvc.exe

agentw.exe

agentsvr.exe

advxdwin.exe

adaware.exe

ackwin32.exe

beagle.exe

d3dupdate.exe

sysxp.exe

winxp.exe

ssgrate.exe

jammer2nd.exe

fvprotect.exe

hxdef.exe

visualguard.exe

gfxacc.exe

ravmond.exe

systra.exe

mcupdate.exe

cfiaudit.exe

avxquar.exe

autoupdate.exe

autotrace.exe

autodown.exe

aupdate.exe

nupgrade.exe

update.exe

icsupp95.exe

icssuppnt.exe

drwebupw.exe

luall.exe

avpupd.exe

avwupd32.exe

atupdater.exe

wuamga.exe

taskmanagr.exe

wuamgrd.exe

wowpos32.exe

dailin.exe

rasmngr.exe

msssss.exe

backdoor.rbot.gen_(17).exe

backdoor.rbot.gen.exe

rb.exe

iaoin.exe

outpost.exe

8、用自带的smtp引擎发送带毒邮件

该邮件具有如下特征:

名称组合firstname:

bowers

carson

figueroalloyd

massey

huff

norton

patrick

sparks

abbott

morton

park

wong

drake

marsh

bass

owen

logan

frank

poole

holloway

mccormick

brady

pittman

copeland

moran

buchanan

french

zimmerman

mclaughlin

parsons

briggs

pratt

klein

christensen

houston

mcbride

schwartz

ballard

nunez

waters

simon

padilla

greer

alvarado

gill

colon

wise

saunders

doyle

stokes

fitzgerald

gross

tyler

gibbs

sandoval

estrada

lindsey

guerrero

mccarthy

paul

osborne

schneider

wolfe

ramsey

lyons

walsh

weber

chandler

keller

ball

munoz

page

guzman

barker

schultz

powers

curry

steele

love

hardy

norris

santiago



dawson

parks

vaughn

bush

mendez

mcdaniel

haynes

newman

beck

pena

rhodes

hale

bates

watts

fletcher

lambert

holt

chambers

rodriquez

miles

lucas

mckinney

gregory

sutton

castro

obrien

barrett

shelton

horton

jimenez

graves

barnett

jennings

lowe

caldwell

neal

walters

soto

wade

herrera

may

hopkins

davidson

byrd

vargas

jensen

fleming

douglas

holland

pearson

silva

carlson

hoffman

brewer

fowler

medina

bowman

moreno

mendoza

day

hanson

burke

frazier

larson

welch

romero

garrett

gilbert

dean

lynch

fuller

kim

reid

jacobs

george

nguyen

burton

little

harvey

garza

fernandez

hansen

morrison

alvarez

howell

mccoy

bishop

meyer

banks

johnston

williamson

richards

montgomery

chapman

wheeler

castillo

stone

rose

ferguson

knight

grant

nichols

mills

palmer

daniels

black

hunt

robertson

rice

holmes

shaw

gordon

burns

reyes

ramos

dixon

warren

kennedy

morales

mason

boyd

henry

crawford

hicks

hunter

porter

tucker

stevens

simpson

webb

wells

freeman

murray

gomez

ortiz

mcdonald

gibson

harrison

ellis

fisher

reynolds

owens

west

woods

sullivan

graham

hamilton

ford

myers

hayes

diaz

griffin

alexander

bryant

gonzales

foster

simmons

butler

washington

flores

hughes

patterson

long

powell

perry

jenkins

coleman

henderson

barnes

wood

bennett

price

sanders

brooks

watson

james

ramirez

gray

peterson

torres

cox

richardson

cooper

rivera

bailey

murphy

bell

morgan

cook

rogers

sanchez

stewart

collins

edwards

kurtis

trenton

carlo

cleo

harris

lane

marcelino

charley

merrill

merlin

cruz

irwin

kirby

dick

frederic

silas

johnathon

delmar

truman

isidro

galen

weldon

beau

linwood

art

donny

stefan

hollis

nestor

barney

carmelo

colby

sanford

brock

dudley

mary

issac

bruno

jarvis

maxwell

odell

coy

clement

dante

dion

jayson

romeo

ward

emery

gavin

davis

denny

cole

donnell

heriberto

ulysses

federico

sebastian

eddy

quincy

vince

scot

maynard

nickolas

ollie

riley

basil

donovan

hiram

mauricio

bernardo

elvis

jefferson

reed

bobbie

vern

noe

rickie

shelby

alphonso

rigoberto

wiley

carmen

stacey

gerry

rodrigo

derick

gonzalo

nolan

williams

elvin

norbert

scotty

solomon

anton

esteban

roscoe

kermit

xavier

buddy

gregorio

ashley

darwin

elliot

desmond

harlan

joaquin

damien

denis

vance

jarrod

merle

bradford

dexter

percy

clay

rolando

lamar

cornelius

phil

grady

noah

pat

conrad

ramiro

elbert

bert

devin

wilson

sherman

gregg

lowell

cedric

rodolfo

cameron

ernesto

carlton

rex

orlando

alfonso

lynn

matt

lyle

shaun

angelo

hubert

kenny

doug

gerard

homer

luke

oliver

trevor

shannon

otis

donnie

dana

julius

marshall

andy

virgil

ross

daryl

willard

clifton

morris

isaac

julian

byron

sidney

johnnie

ivan

dave

alberto

alfredo

casey

jaime

bob

ken

wallace

ian

jordan

everett

jimmie

felix

armando

dwight

dwayne

max

hugh

clayton

guy

nelson

allan

kurt

kelly

julio

cody

lance

lonnie

darren

tyrone

mathew

ted

clinton

fernando

javier

barry

randall

troy

ricky

eddie

don

edwin

joel

ray

frederick

herbert

jesus

bradley

francis

kyle

alfred

melvin

lee

jacob

chad

jeff

travis

jeffery

glenn

vincent

marvin

allen

norman

curtis

rodney

manuel

dale

nathan

leonard

stanley

mike

luis

tony

bryan



danny

antonio

jimmy

earl

johnny

chris

philip

sean

clarence

shawn

alan

craig

jesse

todd

phillip

ernest

martin

victor

bobby

russell

carlos

eugene

howard

randy

aaron

jeremy

louis

steve

billy

wayne

fred

harry

adam

brandon

bruce

benjamin

roy

nicholas

lawrence

ralph

willie

samuel

keith

gerald

terry

justin

jonathan

albert

jack

juan

joe

roger

ryanleon

名称组合lastname:

porter

tucker

stevens

simpson

webb

wells

freeman

murray

gomez

ortiz

marshall

cruz

parker

campbell

phillips

turner

roberts

perez

mitchell

carter

nelson

gonzalez

baker

adams

green

hill

lopez

wright

king

hernandez

young

allen

hall

walker

lee

lewis

rodriguez

clark

robinson

martinez

garcia

thompson

martin

harris

white

jackson

anderson

taylor

moore

wilson

miller

davis

brown

jones

williams

johnson

smith

域名组合:

@ziplink.net

@yahoo.com

@wwc.com

@worldshare.net

@worldcom.com

@wanadoo.com

@verizon.net

@ultimanet.com

@toad.net

@tiscali.com

@t-online.de

@t-online.com

@surfree.com

@ricochet.com

@rcn.com

@pics.com

@peoplepc.com

@pathlink.com

@palm.net

@pacific.net.sg

@netzero.net

@netrox.net

@netcenter.com

@nccw.net

@msn.com

@madriver.com

@macconnect.com

@loa.com

@juno.com

@istep.com

@ispwest.com

@isp.com

@iquest.net

@infoave.net

@inext.fr

@ieway.com

@hiwaay.net

@highstream.net

@globetrotter.net

@globalbiz.net

@gbronline.com

@flex.com

@fcc.net

@fast.net

@excite.com

@ev1.net

@eisa.com

@eclipse.net

@earthlink.net

@dialupnet.com

@cybernex.net

@cox.net

@core.com

@compuserve.com

@chello.com

@ccpc.net

@ccp.com

@cayuse.net

@canada.com

@cais.com

@cableone.net

@att.net

@aristotle.net

@arczip.com

@apci.net

@aol.com

@ameralinx.net

@address.com

@accessus.net

@a1isp.net

@1access.net

@yahoo.co.uk

@gmx.net

@hotmail.com

@mail.com

@dailymail.co.uk

主题:

do you know this girl?

do you know this people?

do you know this ppl?

is it your photo?

look!

my new photos

with best wishes

a lot of fun.

hello...funny pic...hehehe

i"ve never seen this before. look at that !

look :)

hello!

you"ve got a postcard. to view this postcard, click on the attached file

have you seen this before?

loool!! :-)

fun

fun pictures

hi!

look at new photos

re[2]:fun pictures

re:fun pictures

fw:fun pictures

re[2]:cool!

re:cool!

fw:cool!

re[2]:cool

re:cool

fw:cool

re[2]:

re:

fw:

:))

fw: cool

look!

new photos

2 new photos

hi, it"s me

it"s me

(no subject)

that"s me :-d

my photos

hello sweety :>

remember me?..

fw: jenna"s photos :)

fw: new photos

fw: 2 new photos

fw: hi, it"s me

fw: it"s me

fw: (no subject)

fw: that"s me :-d

fw: my photos

fw: hello sweety :>

fw: hi

fw: remember me?..


正文:

正文由下面abc三部分组成

a.(随机选取一条)

-----original message-----

from: jeny k.

sent: monday, september 13, 2004 8:57 pm

to: morpheus

check my new photos

:))

miss you, jeny k

-----original message-----

from: jena k.

sent: monday, september 13, 2004 5:23 am

to: friends

check out archive.. so.. what do you think... am i hot? :)

waining for your answer

jena key

-----original message-----

from: jenny k.

sent: monday, september 13, 2004 10:23 am

to: my tiger (e-mail)

new fotos(archived) you asked



jenny k

-----original message-----

from: jenna k. (e-mail)

sent: monday, september 13, 2004 11:38 am

to: cat

my new fotos archived ))

kiss, jenna k

-----original message-----

from: jeny

sent: monday, september 13, 2004 8:57 pm

to: neo

see the photos in attached archive

:))

kiss you, jeny

-----original message-----

from: jena

sent: monday, september 13, 2004 5:23 am

to: friend

photos in archive.. so.. am i hot? :)

waining for your answer

jena

-----original message-----

from: jenna knukles

sent: monday, september 13, 2004 9:05 am

to: friends group

in self-extracting archive my photos

jenna :)

-----original message-----

from: jenna (e-mail)

sent: monday, september 13, 2004 11:38 am

to: ma kittie

my photos archived ))

kiss, jenna

fun flash game!

fun flash!

game!

fun game!

print money at home!

look at atach

-----original message-----

from: jeny k.

sent: monday, september 13, 2004 8:57 pm

to: morpheus

check out the new photos

:))

miss you, jeny k

-----original message-----

from: jena k.

sent: monday, september 13, 2004 5:23 am

to: friends

so.. what do you think... am i hot? :)

waining for your answer

jena key

-----original message-----

from: jenna knukles

sent: monday, september 13, 2004 9:05 am

in archive my new fotos

jenna k :)

-----original message-----

from: jenny k.

sent: monday, september 13, 2004 10:23 am

to: my tiger (e-mail)

new fotos you asked

jenny k

-----original message-----

from: jenna k. (e-mail)

sent: monday, september 13, 2004 11:38 am

to: cat

my new fotos zipped ))

kiss, jenna k

-----original message-----

from: jeny

sent: monday, september 13, 2004 8:57 pm

to: neo

see the photos

:))

kiss you, jeny

-----original message-----

from: jena

sent: monday, september 13, 2004 5:23 am

to: friend

so.. am i hot? :)

waining for your answer

jena

-----original message-----

from: jenna knukles

sent: monday, september 13, 2004 9:05 am

to: friends group

in archive my photos

jenna :)

-----original message-----

from: jenny

sent: monday, september 13, 2004 10:23 am

to: mr.x (e-mail)

photos you asked

jenny

-----original message-----

from: jenna (e-mail)

sent: monday, september 13, 2004 11:38 am

to: ma kittie

my photos zipped ))

kiss, jenna

-----original message-----

from: jeny k.

sent: tuesday, september 7, 2004 8:57 pm

to: morpheus

check my new photos

:))

miss you, jeny k

b.

+++ attachment: no virus found

+++ [avprod

c.(随机选取一条)

norton antivirus - www.symantec.de

f-secure antivirus - www.f-secure.com

norman antivirus - www.norman.com

panda antivirus - www.pandasoftware.com

kaspersky antivirus - www.kaspersky.com

mc-afee antivirus - www.mcafee.com

bitdefender antivirus - www.bitdefender.com

messagelabs antivirus - www.messagelabs.com

附件:(随机)

myfoto.exe、photos.selfextracting.exe 、photoarchive.exe 、photofile.exe 、arc.exe

my_foto.exe 、fotos.exe 、foto.exe 、photos.exe.safe 、photo_se.exe

new_photos.exe 、newphotos.exe 、myphotos_arc.exe 、my_photos.exe 、photos_arc.exe

myfoto.cpl 、photoarchive.cpl 、photofile.cpl 、arc.cpl 、my_foto.cpl 、fotos.cpl

foto.cpl 、photo_se.cpl 、new_photos.cpl 、newphotos.cpl 、my_photos.cpl

photos_arc.cpl 、arhive.zip 、new_pic.zip 、pic.zip



new_photos.zip 、images.zip 、fotos.zip 、my_photos.zip

myphotos.zip 、photos.zip 、my_photo.jpg .pif 、flowers.jpg .pif 、document.jpg .pif

pic.jpg .pif 、photo.jpg .pif

black.gif .pif 、dcp_0002.jpg .pif 、me_01.jpg .pif 、2004042301.jpg .pif

with_flowers.jpg .pif 、sunny.jpg .pif 、photo08.jpg .pif 、nude_.jpg .pif

marie_dancing.jpg .pif 、julia038.jpg .pif 、dap53 crack.exe 、imeshv4 crack.exe

icqpro2003b crack.exe 、wrar330 crack.exe 、winzip 9.0 crack.exe

dap71.exe 、trillian-v2.74h.exe 、wrar330.exe 、limewirewin.exe

morpheus.exe 、zlssetup_45_538_001.exe 、icqpro2003b.exe 、imeshv4.exe

winzip 9.0.exe 、icqlite.exe 、kmd.exe 、trillian 2.0 crack.exe

dap53.exe 、dvdplayer.exe 、opera7.x crack.exe

crazzygirls.scr 、childporno.pif 、opera7.7.exe 、winamp6.exe

eroticgirls2.0.exe 、tropicallagoonss.scr 、nicegirlsshowv12.scr

icq2004-final.exe 、winamp5.exe 、1.exe 、mymusic.pif 、rulezzz.scr

matrix.scr 、newvirus.exe 、mylove.pif 、antibush.scr 、icqcrack.exe

myfack.pif 、hello.pif 、pinguin5.exe 、you the best.scr 、fantasy.scr

coolgame.zip .exe 、mynewphoto.zip .exe 、mult.exe

以上为带毒邮件的特征

但该病毒不会发送邮件到包含以下字符串的邮箱中:

gold-certs 、feste 、submit

help 、service 、privacy 、somebody 、contact

site 、someone 、anyone 、nothing 、nobody 、noreply

noone 、ebmaster 、news 、rating 、postmaster

samples 、info 、root 、www 、upport

abuse 、accoun 、certific 、listserv 、bsd

ntivi 、admin 、icq.com 、mozilla 、utgers.ed

tanford.e 、pgp 、acketst 、secur

isc.o 、isi.e 、ripe. 、arin. 、sendmail 、rfc-ed 、ietf

usenet 、fido 、kernel 、google 、ibm.com

fsf. 、gnu 、mit.e 、math 、berkeley

support 、messagelabs 、antivi 、kasp 、linux

unix 、spam 、@iana 、@foo. 、.mil

gov. 、.gov 、icrosoft 、ruslis 、nodomai

mydomai 、example 、inpris 、borlan

sopho 、panda 、icrosof 、syman 、avp.

相关新闻
学习从系统中删除病毒2007/6/28
吃透木马运行原理把它扼杀2007/6/28
McAfee杀毒软件高级设置技巧五招2007/6/28
隐藏文件看不到?中毒了!2007/6/25
360安全卫士推出集三重防护理念2007/6/25
 
    其它相关新闻
·学习从系统中删除病毒
·吃透木马运行原理把它扼杀
·McAfee杀毒软件高级设置技巧五招
·隐藏文件看不到?中毒了!
·360安全卫士推出集三重防护理念
·使用杀毒软件应该注意什么
·CA发布声明:我的杀毒软件漏洞很大
    最新新闻
·磁碟机病毒的十大罪行
·病毒预警:光华反病毒资讯(7月16日-7月22日)
·病毒预警:光华反病毒资讯(7月9日-7月15日)
·用Regsvr32命令解决系统疑难杂症
·Windows的DLL文件原理与修改方法
·如何隐藏硬盘分区
·攻防全面分析 常用九种攻击方法
·卡巴再次误报 将注册表判为木马
·英特尔酷睿2存在安全缺陷
    相关软件下载
·AVG(原Ewido)Anti-Spyware最新完整病毒库更新(2008.06.02)-Anti-Spyware升级包
·AVG(原Ewido)Anti-Spyware每日增量病毒库更新(2008.06.02)-Anti-Spyware升级包
·Kaspersky Anti-Virus7.0.0.125增量包(2008.05.31)-卡巴斯基升级包
·Kaspersky Internet Security7.0.0.125完整升级包(2008.06.01)-卡巴斯基升级包
·熊猫卫士06月01号最新病毒升级包通用版-熊猫卫士升级包
·Avast杀毒软件病毒库升级包(2008-06-01)for avast! 4.0 VPS更新-Avast升级包
·Avast杀毒软件病毒库升级包(2008-06-01)for avast! 4.x VPS更新-Avast升级包
·小红伞AntiVir最新病毒库(2008.06.01) for WindowsNT/2000/XP-小红伞升级包
·McAfee VirusScan DAT 5306病毒库-麦咖啡升级包
·更多相关杀毒软件
  [本站导航]  
瑞星  瑞星杀毒软件瑞星升级包 瑞星杀毒瑞星2007 瑞星在线杀毒瑞星杀毒软件下载瑞星升级
卡巴斯基  卡巴斯基下载卡巴斯基6.0卡巴斯基杀毒软件卡巴斯基7.0卡巴斯基病毒库卡巴斯基升级包
江民  江民杀毒软件江民杀毒江民2007江民杀毒软件下载江民升级包江民升级江民离线升级包
金山毒霸  金山毒霸2007下载金山毒霸下载金山毒霸2007升级包金山毒霸升级金山毒霸杀毒软件
诺顿  诺顿杀毒软件诺顿杀毒诺顿病毒库诺顿企业版诺顿升级包诺顿升级诺顿下载
小红伞AntiVir  德国小红伞小红伞下载小红伞中文小红伞杀毒软件小红伞汉化Avira AntiVir
麦咖啡McAfee  麦咖啡杀毒软件麦咖啡升级包麦咖啡8.0麦咖啡企业版麦咖啡8.5mcafee virusscan
NOD32  nod32升级nod32升级服务器nod32下载nod32 2.7nod32升级idnod32更新nod32升级包
F-Secure  F-secure杀毒软件f-secure anti-virusF-secure汉化版F-secure注册机F-secure2007
Dr.Web  dr.web keydr.web cureitdr.web注册码dr.web汉化dr.web病毒库大蜘蛛大蜘蛛杀毒软件
Avast  avast注册码 序列号avast antivirusavast杀毒软件avast中文版avast 升级avast升级包
木马专杀  木马杀客木马克星AVG Ewido Anti-SpywareAVG Ewido Anti-Spyware升级包 更新
防火墙  瑞星防火墙天网防火墙arp防火墙瑞星个人防火墙江民防火墙防火墙下载风云防火墙
流氓软件清理  瑞星卡卡360安全卫士Wopti流氓软件清除大师奇虎360安全卫士360安全卫士绿色版
推荐软件  Firefox火狐浏览器浏览器Picasa照片处理软件非主流图片制作软件非主流照片制作
关于本站 - 广告合作 - 联系我们 - 下载声明 - 网站地图 - RSS2.0 - 合作伙伴:爱客宝
Copyright©1998 - 2007 爱客者 All Rights Reserved

粤ICP备07006801号