万卷书   首页 > 电脑书籍 > 安全在线 > 恶性蠕虫-"赛舍"(Worm.Zezer)分析报告
 
   5、病毒假冒如下邮箱地址向MSN联系人发送带毒邮件:

   winpatch@microsoft.com

   services@microsoft.com

   msnsupport@microsoft.com

   helpdesk@microsoft.com

   security@microsoft.com

   windowsupdate@microsoft.com

   附件名称:"Msn_inst.exe"

   邮件主题:"Windows Update ( MSN Messenger Update 6 MSN Messenger vulnerability)"

   邮件正文:"Attention All Microsoft Users: A patch has been issued to correct a vulnerability in MSN Messenger which can be performed by a malicious user in order to gain unauthorized access to compromised computers. Windows users who have MSN Messenger 4.x and higher versions are affected by this vulnerability and must download and install the patch labeled , which is attached to this email message. For any support regarding this patch please contact support@microsoft.com for more information."
(注,发送邮件使用worldcomputers.com这个服务器(不要写到新闻稿中))

   6、关闭许多反病毒软件、网络防火墙、病毒防火墙:

   "_AVP.EXE"

   "_AVP32.EXE"

   "_AVPCC.EXE"

   "_AVPM.EXE"

   "ACKWIN32.EXE"

   "ANTI-TROJAN.EXE"

   "APVXDWIN.EXE"

   "AUTODOWN.EXE"

   "AVCONSOL.EXE"

   "AVE32.EXE"

   "AVGCTRL.EXE"

   "AVKSERV.EXE"

   "AVNT.EXE"

   "AVP.EXE"

   "AVP32.EXE"

   "AVPCC.EXE"

   "AVPDOS32.EXE"

   "AVPM.EXE"

   "AVPMON.EXE"

   "AVPNT.EXE"
 
上一页 WanJuanShu 下一页