请输入您要查询的百科知识:

 

词条 Worm.Bagz.b
释义

简介

病毒别名:I-Worm.Bagz.b [AVP],I-Worm/Bagz.b [KV]

处理时间:

威胁级别:★★

中文名称:袋子变种B

病毒类型:蠕虫

影响系统:Win9x / WinNT

病毒行为:

这是一个通过电子邮件传播的蠕虫病毒。该病毒会关闭Windows防火墙,从网络上下载文件并执行,从.txt、.htm、.dbx、.tbi、.tbb文件中收集邮件地址保存在一个临时文件中,再将病毒做为邮件附件发送到这些邮件接收者。该病毒发送的邮件带有较大的欺骗性,用户可能会受骗去打开里面的附件,从而导致系统感染该蠕虫病毒。

1)将病毒的副本拷贝到%System%\\tutorial.doc <空格> .exe

2)建立文件%System%\\dl.exe和%System%\\syslogin.exe

病毒特征

3)在注册表中添加启动项:

HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run

"syslogin.exe"="syslogin.exe"

4)禁止Windows防火墙

5)从网络上下载文件并执行

6)将收集到的邮件地址、本地机器IP地址和邮件网关存放到下列3个临时文件中:

%System%\\jobdb.dll

%System%\\ipdb.dll

%System%\\wdate.dll

7)从以下扩展名的文件中收集邮件地址:

.txt

.htm

.dbx

.tbi

.tbb

8)邮件:

From: [伪造的发信人]

Subject: [邮件主题]

Message: [正文]

Attachment: [附件名]

邮件主题列表

Re: User ID Update

Fwd: Your Funds are Eligible for Withdrawal

find a solution with this customer

No Subject

Re: Help Desk Registration

failure notice

Fwd: Password

when should i call you?

RE: Re: A question

Knowledge Base Article

Open Invoices

Returned mail: see transcript for details

building maintenance

[Fwd: Broken link]

WinXP

troubles are back again

Questions

Order Approval

units available

progress news

big announcements

Need help pls

You have recieved an eCard!

What is this ????

Deactivation Notice

Message recieved, please confirm

My funny stories

Cost Inquiry

Re: payment

referrences

Webmail Invite

RE: quote request

正文列表

Hello,

Sorry, I forgot to attach the new contact information.

Please view the attached (.pdf) contact sheet.

Sincerely,

User

Hello,

I resent this email as attachment because

it was previously blocked by your email filters.

Please read the attachment and respond.

Thanks,

User

Hello,

I was in a hurry and I forgot to attach an important

document. Please see attached.

Best Regards,

User

Hello,

Your email was received.

YOUR REPLY IS URGENT!

Please view the attached text file for instructions.

Regards,

User

Hello,

Your email was sent in an INVALID format.

To verify this email was sent from you,

simply open the attached email (.eml) file

and click yes in the sender options box.

Thank You,

User

Hello,

My PC crashed while I was sending that last email.

I have re-attached the document of yours that I discovered.

Please read attached document and respond ASAP.

Sincerely,

User

Hello,

What version of windows you are using?

This last document I received from you came out weird.

Please see the attached word file and resend the file to me.

Many thanks,

User

***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***

Hello,

The previous email you sent has been recognized as spam.

This means your email was not delivered to your friend or client.

You must open the attached file to receive more information.

***YOUR MESSAGE HAS BEEN RECOGNIZED AS SPAM***

***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***

You are currently unable to send emails.

This may be a billing issue.

Please call the billing center.

The # for the billing office is located in the attached

contact list for your convenience.

***ATTENTION: YOUR EMAIL IS NOT BEING DELIVERED!***

***URGENT: SERVICE SHUTDOWN NOTICE***

Due to your failure to comply with our email

Rules and Regulations, your email account has been

temporarily suspended for 24 hours unless we are contacted regarding

this situation.

You must read the attached document for further

instructions. Failure to comply will result in termination of your account.

Regards,

Net Operator

***URGENT: SERVICE SHUTDOWN NOTICE***

last request before refunding

附件名列表

Ctutorial.doc <空格> .exe

doc.doc <空格> .exe

documents.doc <空格> .exe

atach.doc <空格> .exe

file.doc <空格> .exe

read.doc <空格> .exe

readme.doc <空格> .exe

contact.doc <空格> .exe

mail.doc <空格> .exe

att.doc <空格> .exe

warning.doc <空格> .exe

db.doc <空格> .exe

msg.doc <空格> .exe

message.doc <空格> .exe

messages.doc <空格> .exe

archive.doc <空格> .exe

arch.doc <空格> .exe

support.doc <空格> .exe

account.doc <空格> .exe

doc.zip

documents.zip

atach.zip

file.zip

read.zip

readme.zip

contact.zip

mail.zip

att.zip

warning.zip

db.zip

msg.zip

message.zip

messages.zip

archive.zip

arch.zip

support.zip

account.zip

随便看

 

百科全书收录4421916条中文百科知识,基本涵盖了大多数领域的百科知识,是一部内容开放、自由的电子版百科全书。

 

Copyright © 2004-2023 Cnenc.net All Rights Reserved
更新时间:2025/1/27 21:08:45