Worm.Wurmark.k

Worm.Wurmark.k,該病毒通過電子郵件傳播,郵件偽裝成個含有圖片、音樂、新聞或屏保的電子郵件,誘使用戶運行,附屬檔案中的病毒。

基本介紹

  • 外文名:Worm.Wurmark.k
  • 威脅級別 :★★
  • 病毒類型 :蠕蟲
  • 影響系統 :Win9x / WinNT
病毒行為,運行特徵,

病毒行為

病毒信件,沒有內容,只有主題和附屬檔案。病毒一旦運行後,會搜尋用戶本地計算機中的電子信箱地址,並向這些信箱地址傳送病毒體。

運行特徵

1.該病毒運行時調用IE顯示一張大猩猩的圖片,如下
2.從網路上下載Rot系列病毒
3.向染毒用戶機器的其它好友傳送帶毒郵件,該郵件具有如下特徵:
主題: (隨機)
Hehehe LOL!!
Your Photo Is On A Webpage!!
Hey Rate My Pic Plz...
Someone admire's you!
正文:(隨機)
I just saw this on my computer from a while ago
download it and see if you can remember it
lol i was lauging like crazy when i saw it! :D
email me back hehe...
I was vieweing this website and came across
a picture they look just like you! infact im sure
it is haha , did you email this pic into them ? or
is it someonce else :S ? pic is attached
a zip so download it and check & email me back!
Hi ive sent 5 emails now and nobody will rate
my pic!! :( please download and tell me what you
think out of 10 , dont worry if you dont like it
just say i wont be offended p.s i was drunk when
it was taken :P
Someone has asked us on there behalf to send
you this email and tell you they think you are
wonderfull!!! All the The mystery persons details
you need are enclosed in the attachment :)
please download and respond telling us if you
would like to make further contact with this
person.
Regards Hallmark Admirer Mail Admin.
附屬檔案:
Download.zip
5.該病毒會在用戶機器System32目錄下釋放以下檔案:
regedit.com
taskmgr.exe
tasklist.com
taskkill.com
netstat.com
tracert.com
ping.com
cmd.com
bszip.dll
wini.exe
6.修改註冊表使病毒能夠隨計算機啟動啟動
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
IE Runtime "wini.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IE Runtime "wini.exe"

相關詞條

熱門詞條

聯絡我們