ÎÒ¹ú·¢ÏÖ¡°Ð¡Óʲ£¨Worm_Mydoom.A£¬WORM_MIMAIL.R£©²¡¶¾±äÖÖ
¹ú¼ò¼æëã»ú²¡¶¾ó¦¼±´¦àíöððäͨ¹ý¶Ô»¥ÁªÍøµÄ¼à²â£¬ÓÚ2004Äê1ÔÂ27ÈÕÖÐÎç·¢ÏÖÒì³£µÄ²¡¶¾µÄÓʼþ£¬¾·ÖÎö֤ʵ¸Ã²¡¶¾Îª¡°Ð¡Óʲ²¡¶¾µÄÓÖÒ»±äÖÖ£¬²¢½«²¡¶¾ÃüÃûΪ¡°Ð¡Óʲ£¨WORM_MIMAIL.R£©¡£ Ä¿Ç°£¬¹úÄÚÒÑÓÐһЩÓû§Êܵ½¸ÐȾ£¬¹ú¼ò¼æëã»ú²¡¶¾ó¦¼±´¦àíöððäÔÚÕâÀïÌáÐѹã´óÓû§£¬Á¢¼´Éý¼¶É±¶¾Èí¼þ£¬²¢Æô¶¯¡°ÊµÊ±¼à¿Ø¡±¹¦ÄÜ£¬×öºÃ²¡¶¾µÄ·À·¶¹¤×÷¡£ Óйظò¡¶¾·ÖÎö±¨¸æÈçÏ£º ²¡¶¾Ãû³Æ£º¡°Ð¡Óʲ£¨Worm_Mydoom.A£¬WORM_MIMAIL.R£© ÆäËüÖÐÎÄÃüÃû£º¡°Ã׳桱,¡°SCOÕ¨µ¯¡±£¨ÈðÐÇ£©£¬¡°ÅµÎ¬¸ñ¡±£¨½ðɽ£© ÆäËüÓ¢ÎÄÃüÃû£ºW32/Mydoom@MM, Mydoom, Win32.Mydoom.A, W32.Novarg.A@mm ²¡¶¾ÀàÐÍ£ºÈä³æ ²¡¶¾³¤¶È£º22,528 ×Ö½Ú Ó°Ïìϵͳ£ºWin 95/98/NT/2000/Me/XP ²¡¶¾½éÉÜ£º ²¡¶¾Í¨¹ýµç×ÓÓʼþ£¬KaZaA£¨µã¶Ôµã´«²¥Èí¼þ£©½øÐд«²¥¡£¸ÃÈä³æ³ÌÐòÖеÄ×Ö·û´®¾¹ýÁ˼ÓÃÜ´¦Àí¡£²¡¶¾»á¶Ôwww.sco.comÕ¾µã½øÐоܾø·þÎñ¹¥»÷¡£¹¥»÷ʱ¼äΪ2004Äê2ÔÂ1ÈÕ¼°Ö®ºó£¬µ±Ê±¼äΪ2004ÔÂ2ÔÂ12ÈÕʱ£¬Èä³æ½«ÖÐÖ¹¹¥»÷¼°Æ书ÄÜ¡£²¡¶¾»áÔËÐÐÆäºóÃÅ×é¼þ£¨HIMGAPI.DLL£©£¬¸Ã×é¼þ½«ÔÚ±»¸ÐȾµÄϵͳÖдò¿ª¶Ë¿Ú3127ÒÔ½ÓÊÜÀ´×ÔÔ¶³ÌÓû§µÄ·ÃÎÊ¡£ 1¡¢Éú³É²¡¶¾Îļþ ²¡¶¾ÔËÐкó»áÔÚϵͳÖÐÉú³ÉÈçÏÂÎļþ: %System%\shimgapi.dll %System%\taskmon.exe £¨ÆäÖУ¬%System%ÔÚWindows 95/98/MeÏÂΪC:\Windows\System£¬ÔÚWindows NT/2000ÏÂΪC:\Winnt\System32£¬ÔÚWindows XPÏÂΪ C:\Windows\System32£©
2¡¢ÐÞ¸Ä×¢²á±íÏî ²¡¶¾Ìí¼Ó×¢²á±íÏʹµÃ×ÔÉíÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯ÔËÐУ¬ÔÚ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunÖÐÌí¼Ó TaskMon = %System%\taskmon.exe 3¡¢Í¨¹ýµç×ÓÓʼþ½øÐд«²¥ ¸ÃÈä³æʹÓÃSMTP½øÐд«²¥¡£ ²¡¶¾·¢Ë͵Ĵø¶¾µç×ÓÓʼþ¸ñʽÈçÏ£º Ö÷Ì⣺(ÏÂÁÐÖ®Ò») Error Status Server Report Mail Transaction Failed Mail Delivery System hello hi ÄÚÈÝ£º(ÏÂÁÐÖ®Ò») The message contains Unicode characters and has been sent as a binary attachment. The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. Mail transaction failed. Partial message is available. test ¸½¼þ£º£¨Ëæ»ú×Ö·û´®£©.zip ¸½¼þ°üº¬ÁËÈä³æµÄ¿ÉÖ´ÐгÌÐò£¬¸Ã³ÌÐòµÄÃû³Æ¿ÉÄÜΪÏÂÁÐÖ®Ò»£º body message test data file text doc readme document ¸Ã¿ÉÖ´ÐгÌÐòµÄÀ©Õ¹ÃûΪÈçÏÂÖ®Ò»£º BAT EXE PIF SCR Çå³ý¸Ã²¡¶¾µÄÏà¹Ø²Ù×÷£º 1¡¢ÖÕÖ¹²¡¶¾½ø³Ì ÔÚWindows 9x/MEϵͳ£¬Í¬Ê±°´ÏÂCTRL+ALT+DELETE£¬ÔÚWindows NT/2000/XPϵͳÖУ¬Í¬Ê±°´ÏÂCTRL+SHIFT+ESC£¬Ñ¡Ôñ¡°ÈÎÎñ¹ÜÀíÆ÷¡ª¡ª¡µ½ø³Ì¡±£¬Ñ¡ÖÐÕýÔÚÔËÐеIJ¡¶¾½ø³Ì£¬²¢ÖÕÖ¹ÆäÔËÐС£ 2¡¢×¢²á±íµÄ»Ö¸´ µã»÷¡°¿ªÊ¼¡ª¡ª¡µÔËÐС±£¬ÊäÈëregedit,ÔËÐÐ×¢²á±í±à¼Æ÷£¬ÒÀ´ÎË«»÷×ó²àµÄHKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run £¬²¢É¾³ýÃæ°åÓÒ²àµÄTaskMon = %System%\taskmon.exe 3¡¢É¾³ý²¡¶¾Îļþ µã»÷¡°¿ªÊ¼¡ª¡ª¡µ²éÕÒ¡ª¡ª¡µÎļþºÍÎļþ¼Ð¡±£¬²éÕÒÎļþ¡°shimgapi.dll¡±ºÍ¡°taskmon.exe¡±£¬²¢½«ÕÒµ½µÄÎļþɾ³ý¡£ 4¡¢ÔËÐÐɱ¶¾Èí¼þ¶Ôϵͳ½øÐÐÈ«ÃæµÄ²¡¶¾²éɱ Ä¿Ç°£¬Ç÷ÊƺͽÃñ¡¢ÈðÐǺͽðɽ¹«Ë¾ÒѾÉϱ¨½â¾ö·½°¸£¬²¢¶Ô²úÆ·½øÐÐÁËÉý¼¶£¬¶¼¿ÉÒÔÓÐЧµÄÇå³ý¸Ã²¡¶¾¡£
--------------------------------------------------------------------------------
Ïà¹ØÐÂÎÅ
°²È«¾¯¸æ - ÐÂÈä³æ²¡¶¾£ºW32/Mimail@mm 2004-1-30 11:30:13
|