Worm.Mytob.dc

Worm.Mytob.dc病毒是一個通過郵件傳播的蠕蟲病毒。該病毒會連線IRC聊天室,供黑客控制用戶主機,是用戶機器淪為“肉雞”。該病毒會禁止大量網站,會結束大量進程,並通過搜尋特定後綴的檔案,獲得郵件地址,並傳送病毒。

基本介紹

  • 外文名:Worm.Mytob.dc
  • 處理時間:2005-10-17
  • 威脅級別:★
  • 病毒類型蠕蟲
  • 影響系統:Win 9x/Win 2000/XP,Win 2003
  • 傳播途徑:通過郵件傳播
病毒行為,從下列後綴檔案中搜尋郵件地址,不向包含以下字元的郵件地址傳送郵件,傳送的郵件內容為,

病毒行為

從下列後綴檔案中搜尋郵件地址

doc
txt
htm
tmp
wab
html
pl
adbh
tbbg
dbxn
aspd
phpq
ls
cgil
jspl
shtl
htmb

不向包含以下字元的郵件地址傳送郵件

sandra
adam
frank
linda
julie
jimmy
jerry
helen
debby
claudia
brenda
anna
sales
brent
paul
ted
fred
jack
bill
stan
smith
等等
3
關閉下列進程
NEC.EXE
TASKMGR.EXE
CMD.EXE
_AVPM.EXE
_AVPCC.EXE
_AVP32.EXE
ZONEALARM.EXE
ZONALM2601.EXE
ZATUTOR.EXE
ZAPSETUP301.EXE
ZAPRO.EXE
XPF202EN.EXE
WYVERNWORKSFIREWALL.EXE
WUPDT.EXE
WUPDATER.EXE
WSBGATE.EXE
WRCTRL.EXE
WRADMIN.EXE
WNT.EXE
WNAD.EXE
WKUFIND.EXE
WINUPDATE.EXE
WINTSK32.EXE
WINSTART01.EXE
WINSTART.EXE
WINSSK32.EXE
WINSERVN.EXE
WINRECON.EXE
WINPPR32.EXE
WINNET.EXE
WINMAIN.EXE
WINLOGIN.EXE
WININITX.EXE
WININIT.EXE
WININETD.EXE
WINDOWS.EXE
WINDOW.EXE
WINACTIVE.EXE
WIN32US.EXE
WIN32.EXE
WIN-BUGSFIX.EXE
WIMMUN32.EXE
WHOSWATCHINGME.EXE
WFINDV32.EXE
WEBTRAP.EXE
WEBSCANX.EXE
WEBDAV.EXE
WATCHDOG.EXE
W9X.EXE
W32DSM89.EXE
VSWINPERSE.EXE
VSWINNTSE.EXE
VSWIN9XE.EXE
VSSTAT.EXE
VSMON.EXE
VSMAIN.EXE
VSISETUP.EXE
VSHWIN32.EXE
VSECOMR.EXE
VSCHED.EXE
VSCENU6.02D30.EXE
VSCAN40.EXE
VPTRAY.EXE
VPFW30S.EXE
VPC42.EXE
VPC32.EXE
VNPC300.EXE
VNLAN30.EXE
VIRUSMDPERSONALFIREWALL.EXE
VIR-HELP.EXE
VFSETUP.EXE
VETTRAY.EXE
VET95.EXE
VET32.EXE
VCSETUP.EXE
VBWINNTW.EXE
VBWIN9X.EXE
VBUST.EXE
VBCONS.EXE
VBCMSERV.EXE
UTPOST.EXE
UPGRAD.EXE
UPDATE.EXE
UPDAT.EXE
UNDOBOOT.EXE
TVTMD.EXE
TVMD.EXE
TSADBOT.EXE
TROJANTRAP3.EXE
TRJSETUP.EXE
TRJSCAN.EXE
TRICKLER.EXE
TRACERT.EXE
TITANINXP.EXE
TITANIN.EXE
TGBOB.EXE
TFAK5.EXE
TFAK.EXE
TEEKIDS.EXE
TDS2-NT.EXE
TDS-3.EXE
TCM.EXE
TCA.EXE
TC.EXE
TBSCAN.EXE
TAUMON.EXE
TASKMON.EXE
TASKMO.EXE
TASKMG.EXE
SYSUPD.EXE
SYSTEM32.EXE
SYSTEM.EXE
SYSEDIT.EXE
SYMTRAY.EXE
SYMPROXYSVC.EXE
SWNETSUP.EXE
SWEEP95.EXE
SVSHOST.EXE
SVCHOSTS.EXE
等等

傳送的郵件內容為

Dear user %s,
You have successfully updated the password of your %s account.
If you did not authorize this change or if you need assistance with your account, please contact %s customer service at: %s
Thank you for using %s!
The %s Support Team
+++ Attachment: No Virus (Clean)
+++ %s Antivirus - www.%s
Dear user %s,
It has come to our attention that your %s User Profile ( x ) records are out of date. For further details see the attached document.
Thank you for using %s!
The %s Support Team
+++ Attachment: No Virus (Clean)
+++ %s Antivirus - www.%s
Dear %s Member,
We have temporarily suspended your email account %s.
This might be due to either of the following reasons:
1. A recent change in your personal information (i.e. change of address).
2. Submiting invalid information during the initial sign up process.
3. An innability to accurately verify your selected option of subscription due to an internal error within our processors.
See the details to reactivate your %s account.
Sincerely,The %s Support Team
+++ Attachment: No Virus (Clean)
+++ %s Antivirus - www.%s
Dear %s Member,
Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.
If you choose to ignore our request, you leave us no choice but to cancel your membership.
Virtually yours,
The %s Support Team
+++ Attachment: No Virus found
+++ %s Antivirus - www.%s

相關詞條

熱門詞條

聯絡我們