词条 | Worm.Wurmark.k |
释义 | 病毒别名: 处理时间: 威胁级别:★★ 中文名称: 病毒类型:蠕虫 影响系统:Win9x / WinNT 病毒行为: 该病毒通过电子邮件传播,邮件伪装成个含有图片、音乐、新闻或屏保的电子邮件,诱使用户运行,附件中的病毒。病毒信件,没有内容,只有主题和附件。病毒一旦运行后,会搜索用户本地计算机中的电子邮箱地址,并向这些邮箱地址发送病毒体。 1.该病毒运行时调用IE显示一张大猩猩的图片,如下 2.从网络上下载Rot系列病毒 3.向染毒用户机器的其它好友发送带毒邮件,该邮件具有如下特征: 主题: (随机) Hehehe LOL!! Your Photo Is On A Webpage!! Hey Rate My Pic Plz... Someone admire's you! 正文:(随机) I just saw this on my computer from a while ago download it and see if you can remember it lol i was lauging like crazy when i saw it! :D email me back hehe... I was vieweing this website and came across a picture they look just like you! infact im sure it is haha , did you email this pic into them ? or is it someonce else :S ? pic is attached a zip so download it and check & email me back! Hi ive sent 5 emails now and nobody will rate my pic!! :( please download and tell me what you think out of 10 , dont worry if you dont like it just say i wont be offended p.s i was drunk when it was taken :P Someone has asked us on there behalf to send you this email and tell you they think you are wonderfull!!! All the The mystery persons details you need are enclosed in the attachment :) please download and respond telling us if you would like to make further contact with this person. Regards Hallmark Admirer Mail Admin. 附件: Download.zip 5.该病毒会在用户机器System32目录下释放以下文件: regedit.com taskmgr.exe tasklist.com taskkill.com netstat.com tracert.com ping.com cmd.com bszip.dll wini.exe 6.修改注册表使病毒能够随计算机启动启动 HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices IE Runtime "wini.exe" HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run IE Runtime "wini.exe" |
随便看 |
百科全书收录4421916条中文百科知识,基本涵盖了大多数领域的百科知识,是一部内容开放、自由的电子版百科全书。