Access������--
À´Ô´£º¹ú¼ò¼æëã»ú²¡¶¾ó¦¼±´¦àíöððä ¸üÐÂÈÕÆÚ£º2004-2-1 12:23:44 ÔĶÁ´ÎÊý£º126

ÎÒ¹ú·¢ÏÖ¡°Ð¡Óʲ£¨Worm_Mydoom.A£¬WORM_MIMAIL.R£©²¡¶¾±äÖÖ


¹ú¼ò¼æëã»ú²¡¶¾ó¦¼±´¦àíöððäͨ¹ý¶Ô»¥ÁªÍøµÄ¼à²â£¬ÓÚ2004Äê1ÔÂ27ÈÕÖÐÎç·¢ÏÖÒì³£µÄ²¡¶¾µÄÓʼþ£¬¾­·ÖÎö֤ʵ¸Ã²¡¶¾Îª¡°Ð¡Óʲ²¡¶¾µÄÓÖÒ»±äÖÖ£¬²¢½«²¡¶¾ÃüÃûΪ¡°Ð¡Óʲ£¨WORM_MIMAIL.R£©¡£
Ä¿Ç°£¬¹úÄÚÒÑÓÐһЩÓû§Êܵ½¸ÐȾ£¬¹ú¼ò¼æëã»ú²¡¶¾ó¦¼±´¦àíöððäÔÚÕâÀïÌáÐѹã´óÓû§£¬Á¢¼´Éý¼¶É±¶¾Èí¼þ£¬²¢Æô¶¯¡°ÊµÊ±¼à¿Ø¡±¹¦ÄÜ£¬×öºÃ²¡¶¾µÄ·À·¶¹¤×÷¡£

Óйظò¡¶¾·ÖÎö±¨¸æÈçÏ£º


²¡¶¾Ãû³Æ£º¡°Ð¡Óʲ£¨Worm_Mydoom.A£¬WORM_MIMAIL.R£©
ÆäËüÖÐÎÄÃüÃû£º¡°Ã׳桱,¡°SCOÕ¨µ¯¡±£¨ÈðÐÇ£©£¬¡°ÅµÎ¬¸ñ¡±£¨½ðɽ£©
ÆäËüÓ¢ÎÄÃüÃû£ºW32/Mydoom@MM, Mydoom, Win32.Mydoom.A, W32.Novarg.A@mm
²¡¶¾ÀàÐÍ£ºÈä³æ
²¡¶¾³¤¶È£º22,528 ×Ö½Ú
Ó°Ïìϵͳ£ºWin 95/98/NT/2000/Me/XP

²¡¶¾½éÉÜ£º

²¡¶¾Í¨¹ýµç×ÓÓʼþ£¬KaZaA£¨µã¶Ôµã´«²¥Èí¼þ£©½øÐд«²¥¡£¸ÃÈä³æ³ÌÐòÖеÄ×Ö·û´®¾­¹ýÁ˼ÓÃÜ´¦Àí¡£²¡¶¾»á¶Ôwww.sco.comÕ¾µã½øÐоܾø·þÎñ¹¥»÷¡£¹¥»÷ʱ¼äΪ2004Äê2ÔÂ1ÈÕ¼°Ö®ºó£¬µ±Ê±¼äΪ2004ÔÂ2ÔÂ12ÈÕʱ£¬Èä³æ½«ÖÐÖ¹¹¥»÷¼°Æ书ÄÜ¡£²¡¶¾»áÔËÐÐÆäºóÃÅ×é¼þ£¨HIMGAPI.DLL£©£¬¸Ã×é¼þ½«ÔÚ±»¸ÐȾµÄϵͳÖдò¿ª¶Ë¿Ú3127ÒÔ½ÓÊÜÀ´×ÔÔ¶³ÌÓû§µÄ·ÃÎÊ¡£


1¡¢Éú³É²¡¶¾Îļþ
²¡¶¾ÔËÐкó»áÔÚϵͳÖÐÉú³ÉÈçÏÂÎļþ:
%System%\shimgapi.dll
%System%\taskmon.exe
£¨ÆäÖУ¬%System%ÔÚWindows 95/98/MeÏÂΪC:\Windows\System£¬ÔÚWindows NT/2000ÏÂΪC:\Winnt\System32£¬ÔÚWindows XPÏÂΪ C:\Windows\System32£©

2¡¢ÐÞ¸Ä×¢²á±íÏî
²¡¶¾Ìí¼Ó×¢²á±íÏʹµÃ×ÔÉíÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯ÔËÐУ¬ÔÚ
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunÖÐÌí¼Ó TaskMon = %System%\taskmon.exe

3¡¢Í¨¹ýµç×ÓÓʼþ½øÐд«²¥
¸ÃÈä³æʹÓÃSMTP½øÐд«²¥¡£
²¡¶¾·¢Ë͵Ĵø¶¾µç×ÓÓʼþ¸ñʽÈçÏ£º
Ö÷Ì⣺(ÏÂÁÐÖ®Ò»)
Error
Status
Server Report
Mail Transaction Failed
Mail Delivery System hello
hi

ÄÚÈÝ£º(ÏÂÁÐÖ®Ò»)
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
test

¸½¼þ£º£¨Ëæ»ú×Ö·û´®£©.zip
¸½¼þ°üº¬ÁËÈä³æµÄ¿ÉÖ´ÐгÌÐò£¬¸Ã³ÌÐòµÄÃû³Æ¿ÉÄÜΪÏÂÁÐÖ®Ò»£º
body
message
test
data
file
text
doc
readme
document

¸Ã¿ÉÖ´ÐгÌÐòµÄÀ©Õ¹ÃûΪÈçÏÂÖ®Ò»£º
BAT
EXE
PIF
SCR

Çå³ý¸Ã²¡¶¾µÄÏà¹Ø²Ù×÷£º

1¡¢ÖÕÖ¹²¡¶¾½ø³Ì
ÔÚWindows 9x/MEϵͳ£¬Í¬Ê±°´ÏÂCTRL+ALT+DELETE£¬ÔÚWindows NT/2000/XPϵͳÖУ¬Í¬Ê±°´ÏÂCTRL+SHIFT+ESC£¬Ñ¡Ôñ¡°ÈÎÎñ¹ÜÀíÆ÷¡ª¡ª¡µ½ø³Ì¡±£¬Ñ¡ÖÐÕýÔÚÔËÐеIJ¡¶¾½ø³Ì£¬²¢ÖÕÖ¹ÆäÔËÐС£

2¡¢×¢²á±íµÄ»Ö¸´
µã»÷¡°¿ªÊ¼¡ª¡ª¡µÔËÐС±£¬ÊäÈëregedit,ÔËÐÐ×¢²á±í±à¼­Æ÷£¬ÒÀ´ÎË«»÷×ó²àµÄHKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run £¬²¢É¾³ýÃæ°åÓÒ²àµÄTaskMon = %System%\taskmon.exe

3¡¢É¾³ý²¡¶¾Îļþ
µã»÷¡°¿ªÊ¼¡ª¡ª¡µ²éÕÒ¡ª¡ª¡µÎļþºÍÎļþ¼Ð¡±£¬²éÕÒÎļþ¡°shimgapi.dll¡±ºÍ¡°taskmon.exe¡±£¬²¢½«ÕÒµ½µÄÎļþɾ³ý¡£

4¡¢ÔËÐÐɱ¶¾Èí¼þ¶Ôϵͳ½øÐÐÈ«ÃæµÄ²¡¶¾²éɱ

Ä¿Ç°£¬Ç÷Êƺͽ­Ãñ¡¢ÈðÐǺͽðɽ¹«Ë¾ÒѾ­Éϱ¨½â¾ö·½°¸£¬²¢¶Ô²úÆ·½øÐÐÁËÉý¼¶£¬¶¼¿ÉÒÔÓÐЧµÄÇå³ý¸Ã²¡¶¾¡£


--------------------------------------------------------------------------------
Ïà¹ØÐÂÎÅ
°²È«¾¯¸æ - ÐÂÈä³æ²¡¶¾£ºW32/Mimail@mm 2004-1-30 11:30:13


×îеÄ10ƪÐÂÎÅ
°´Ê±¼ä½µÐòÅÅÁÐ
°´Ê±¼äÉýÐòÅÅÁÐ

ÖÆ×÷ά»¤£ºÀîÑ°»¶     Mail:[email protected]

¹ØÓÚ±¾Õ¾ -- ÍøÕ¾·þÎñ -- °æȨÌõ¿î -- ÁªÏµ·½·¨ -- ÍøÕ¾°ïÖú
Access°®ºÃÕß°æȨËùÓÐ Copyright 2003-2005 All Rights Reserved δ¾­Ðí¿É²»µÃµÁÁ´