词条 | 艾克蠕虫 |
释义 | 艾克蠕虫病毒通过电子邮件进行传播。它伪装为Windows XP SP2的补丁,诱使用户运行邮件附件。病毒运行后会禁止用户的注册表编辑器、记事本、写字板、自动更新、MSN等应用程序的正常工作。它还修改Host文件以禁止用户访问一些著名网站。 病毒行为(1、将自身复制到以下目录: 2、在C盘生成以下配置文件 3、在注册表中: 4、通过修改以下键值禁止常见软件执行 5、尝试从以下网站下载含有自身的压缩包 6、尝试通过OutLook地址薄查找电子邮件 8、病毒利用了以下漏洞: 9、在注册表中添加病毒版本信息: 10、病毒尝试关闭以下进程:) 简介Worm.Ahker.b(艾克蠕虫) 病毒别名:WORM_AHKER.B[趋势] Email-Worm.Ahker.a[AVP] 处理时间:2005-01-23 威胁级别:★★ 影响系统:Win9x / WinNT 病毒行为1、将自身复制到以下目录:%System%\\Services.exe 2、在C盘生成以下配置文件C:\orton AntiVirus.txt 3、在注册表中:HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run "Norton Auto-Protect" = "SERVICES.exe" HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update "默认" = "SERVICES.exe" HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\runservices- "Windows Service" = "SERVICES.exe" 以在开机时自动运行。 4、通过修改以下键值禁止常见软件执行①禁止任务管理器和注册表工具 HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System "DisableTaskMgr" = ""dword:00000001" "DisableRegistryTools" = "dword:00000001" ②禁止运行 HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer "NoRun" = "dword:00000001" "DisallowRun" = "1" ③Windows XP Sp2 会停止自动更新 HKEY_CURRENT_USER\\Software\\Microsoft\\security center UpdatesDisableNotify = "dword:00000001" AntiVirusDisableNotify = "dword:00000001" HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU NoAutoUpdate = "dword:00000001" ④禁止运行以下程序 HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun "1" = "regedit.exe" "2" = "notepad.exe" "3" = "wordpad.exe" "4" = "write.exe" "5" = "wuauclt.exe" "6" = "wupdmgr.exe" "7" = "C:\\Program Files\\MSN Messenger\\msnmsgr.exe" 5、尝试从以下网站下载含有自身的压缩包并保存到 C:\\Fix_SP2.zip 6、尝试通过OutLook地址薄查找电子邮件并向找到邮件发送以下内容的邮件: 主题: Service Pack 2 BUG!! 内容: Dear user I have been informed thate there was a BUG in Windows Service Pack 2 which was fixed I recommend you to download this Patch version which will fixs the bug and keep your system safe.You will find the Patch file in the attachment, feal free to send it to anyone. I'll be in touch with you as soon another bug is found. Regards, A.H 附件: Fix_SP2.zip(内有一个名为 Fix_SP2.exe的可执行文件,即病毒本身) 7、修改Host文件,以禁止用户访问这些网站 8、病毒利用了以下漏洞:诺顿反病毒软件脚本禁止拒绝服务漏洞(2004.06) 9、在注册表中添加病毒版本信息:HKEY_LOCAL_MACHINE\\SOFTWARE\\CurrentVersion\\ "ProductId" = "Agent Hacker" HKEY_LOCAL_MACHINE\\SOFTWARE\\CurrentVersion\\Agent Hacker\\ "默认" = "W32.Ahker.B@mm" "Version" = "B" "Code In" = "Visual Basci 6.0" "Code By" = "Agent Hacker" "Spread" = "VIA Outlook" "Exploit" = "Symantec Norton Antivirus Script Blocker Denial Of Service Vulnerability" 10、病毒尝试关闭以下进程:AGENTSVR.exe ANTIVIRUS.exe ANTS.EXE APIMONITOR.EXE APLICA32.EXE ATCON.EXE ATRO55EN.EXE ATUPDATER ATUPDATER.exe ATWATCH.EXE AUPDATE.exe AUTODOWN.exe AUTOTRACE.exe AUTOUPDATE.exe AVCONSOL.EXE AVGSERV9.EXE AVLTMAIN.exe AVPUPD.exe AVSYNMGR.EXE AVWUPD32.exe AVXQUAR.exe AVprotect9x.exe Ackwin32.exe Alogserv.exe Amon.exe Anti-trojan.exe Apvxdwin.exe Atguard.exe Au.exe Ave32.exe Avkserv.exe Avnt.exe Avpcc.exe Avpm.exe Avwin95.exe BD_PROFESSIONAL.EXE BIDEF.EXE BIDSERVER.EXE BIPCP.EXE BISP.EXE BLACKD.EXE BOOTWARN.EXE BORG2.EXE BS120.EXE BlackIce.exe CDP.EXE CFGWIZ.EXE CFIADMIN.EXE CFIAUDIT.exe CFINET.EXE CFINET32.EXE CLEAN.EXE CLEANER.EXE CLEANER3.EXE CLEANPC.EXE CMGRDIAN.EXE CMON016.EXE CPD.EXE CPF9X206.EXE CPFNT206.EXE CV.EXE CWNB181.EXE CWNTDWMO.EXE Claw95cf.exe Cmgrdian.exe D3dupdate.exe DEFWATCH.EXE DEPUTY.EXE DPF.EXE DPFSETUP.EXE DRWATSON.EXE DRWEBUPW.EXE DRWEBUPW.exe ENT.EXE ESCANH95.EXE ESCANHNT.EXE ESCANV95.EXE EXANTIVIRUS-CNET.EXE Ecengine.exe Esafe.exe F-prot95.exe FAST.EXE FIREWALL.EXE FLOWPROTECTOR.EXE FP-WIN_TRIAL.EXE FRW.EXE FSAV.EXE FSAV530STBYB.EXE FSAV530WTBYB.EXE FSAV95.EXE Findviru.exe Fp-win.exe Fprot.exe GBMENU.EXE GBPOLL.EXE GUARD.EXE Guarddog.exe HACKTRACERSETUP.EXE HTLOG.EXE HWPE.EXE IAMAPP.EXE IAMSERV.EXE ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSSUPPNT.EXE ICSSUPPNT.exe ICSUPP95.EXE ICSUPP95.exe ICSUPPNT.EXE IFW2000.EXE IPARMOR.EXE IRIS.EXE Iamapp.exe Iomon98.exe JAMMER.EXE KAVLI00003A74 KAVPERS40ENG.EXE KERIO-PF-213-EN-WIN.EXE KERIO-WRL-421-EN-WIN.EXE KERIO-WRP-421-EN-WIN.EXE KILLPROCESSSETUP161.EXE LDPRO.EXE LOCALNET.EXE LOCKDOWN.EXE LOCKDOWN2000.EXE LSETUP.EXE LUALL.exe LUCOMSERVER.EXE LUINIT.EXE Lookout.exe MCAGENT.EXE MCUPDATE.EXE MCUPDATE.exe MFW2EN.EXE MFWENG3.02D30.EXE MGUI.EXE MINILOG.EXE MOOLIVE.EXE MRFLUX.EXE MSCONFIG.EXE MSINFO32.EXE MSSMMC32.EXE MU0311AD.EXE NAV80TRY.EXE NAVAPSvc.exe NAVDX.EXE NAVSTUB.EXE NC2000.EXE NCINST4.EXE NDD32.EXE NEOMONITOR.EXE NETARMOR.EXE NETINFO.EXE NETMON.EXE NETSCANPRO.EXE NETSPYHUNTER-1.2.EXE NETSTAT.EXE NISSERV.EXE NISUM.EXE NMAIN.EXE NORTON_INTERNET_SECU_3.0_407.EXE NPF40_TW_98_NT_ME_2K.EXE NPFMESSENGER.EXE NSCHED32.EXE NTVDM.EXE NUPGRADE.exe NUPGRADE.exe NVARCH16.EXE NWINST4.EXE NWTOOL16.EXE Navapsvc.exe Navapw32.exe Navt.exe Navw32.exe Navwnt.exe Navwt.exe Nod32.exe Nsplugin.exe OSTRONET.EXE OUTPOST.EXE OUTPOSTINSTALL.EXE OUTPOSTPROINSTALL.EXE Ogrc.exe Outpost.exe PADMIN.EXE PANIXK.EXE PAVPROXY.EXE PCC2002S902.EXE PCC2K_76_1436.EXE PCCIOMON.EXE PCDSETUP.EXE PCFWALLICON.EXE PCIP10117_0.EXE PDSETUP.EXE PERISCOPE.EXE PERSFW.EXE PF2.EXE PFWADMIN.EXE PINGSCAN.EXE PLATIN.EXE POPROXY.EXE POPSCAN.EXE PORTDETECTIVE.EXE PPINUPDT.EXE PPTBC.EXE PPVSTOP.EXE PROCEXPLORERV1.0.EXE PROPORT.EXE PROTECTX.EXE PSPF.EXE PURGE.EXE PVIEW95.EXE QCONSOLE.EXE QSERVER.EXE RAV8WIN32ENG.EXE RESCUE.EXE RESCUE32.EXE RRGUARD.EXE RSHELL.EXE RTVSCN95.EXE RULAUNCH.EXE Rav7.exe Rulaunch.exe SAFEWEB.EXE SAVScan.exe SBSERV.EXE SD.EXE SETUPVAMEEVAL.EXE SETUP_FLOWPROTECTOR_US.EXE SFC.EXE SGSSFW32.EXE SHELLSPYINSTALL.EXE SHN.EXE SMC.EXE SPF.EXE SPHINX.EXE SPYXX.EXE SS3EDIT.EXE ST2.EXE SUPFTRL.EXE SUPPORTER5.EXE SYMPROXYSVC.EXE SYSEDIT.EXE Scan32.exe Smss.exe Spider.exe TASKMON.EXE TAUMON.EXE TAUSCAN.EXE TC.EXE TCA.EXE TCM.EXE TDS-3.EXE TDS2-98.EXE TDS2-NT.EXE TFAK5.EXE TGBOB.EXE TITANIN.EXE TITANINXP.EXE TRACERT.EXE TRJSCAN.EXE TRJSETUP.EXE TROJANTRAP3.EXE UNDOBOOT.EXE UPDATE.EXE UPDATE.exe VBCMSERV.EXE VBCONS.EXE VBUST.EXE VBWIN9X.EXE VBWINNTW.EXE VCSETUP.EXE VFSETUP.EXE VIRUSMDPERSONALFIREWALL.EXE VNLAN300.EXEVNPC3000.EXE VPC42.EXE VPFW30S.EXE VPTRAY.EXE VSCENU6.02D30.EXE VSECOMR.EXE VSHWIN32.EXE VSISETUP.EXE VSMAIN.EXE VSMON.EXE VSSTAT.EXE VSWIN9XE.EXE VSWINNTSE.EXE VSWINPERSE.EXE Vet95.exe Vettray.exe Vsmain.exe W32DSM89.EXE W9X.EXE WATCHDOG.EXE WEBSCANX.EXE WGFE95.EXE WHOSWATCHINGME.EXE WINRECON.EXE WNT.EXE WRADMIN.EXE WRCTRL.EXE WYVERNWORKSFIREWALL.EXE XPF202EN.EXE ZAPRO.EXE ZAPSETUP3001.EXE ZATUTOR.EXE ZAUINST.EXE ZONALM2601.EXE ZONEALARM.EXE Zonalarm.exe _Avpcc.exe _avpm.exe _findviru.exe avserve2.exe ccApp.exe dfw.exe fsav32.exe fsbwsys.exe fsgk32.exe fsm32.exe fssm32.exe fvprotect.exe mcagent.exe msblast.exe navdx.exe navstub.exe nc2000.exe ndd32.exe netarmor.exe netinfo.exe netmon.exe nmain.exe nprotect.exe ntvdm.exe ostronet.exe pccguide.exe pcciomon.exe regedit.exe regedit32.exe taskmgr.exe tnbutil.exe vbcons.exe vbsntw.exe vbust.exe vsmain.exe vsmon.exe vsstat.exe winlogon.exe |
随便看 |
百科全书收录4421916条中文百科知识,基本涵盖了大多数领域的百科知识,是一部内容开放、自由的电子版百科全书。