|
3月4日,瑞星全球反病毒监测网截获“恶鹰”病毒的最新变种K—“恶鹰变种K(Worm.BBeagle.k)”,该病毒的特性如下:
一、病毒评估:
1.病毒危险等级:★★★☆
2.病毒类型: 蠕虫 病毒
3.病毒传播途径:网络/邮件
4.病毒依赖系统:WINDOWS NT/2000/XP
二、病毒特性:
1.该病毒将检测系统时间,当前时间大于2005年4月25号之后时病毒会删除自己在 注册表 里加的启动项。并退出(什么事也不做)
2.病毒运行时会将自己复制到%system%目录下,文件名为:winsys.exe,
3.病毒会在注册表HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run中加入自己的键值ssate.exe。
4.病毒会建立几个线程分别执行病毒的破坏功能:
三、病毒破坏:
1.发送大量病毒邮件(线程1)。
病毒会搜索所有硬盘,并尝试在以下扩展名文件中搜索email地址并向这些地址发送带毒邮件。病毒搜索email地址的文件扩展名:wab,txt,msg,htm,xml,dbx,mdx,eml,nch,mmf,ods,cfg,asp,php,pl,adb,tbb,sht,uin,cgi。
病毒邮件的内容包括以下字符串。
E-mail account security warning,Notify about using the e-mail account,Warning about your e-mail account Important notify about your e-mail account,Email account utilization warning
Notify about your e-mail account utilization,E-mail account disabling warning
Some of our clients complained about the spam (negative e-mail content)
outgoing from your e-mail account. Probably, you have been infected by,a proxy-relay trojan server.In order to keep your computer safe,..follow the instructions
For more information see the attached file,Further details can be obtained from attached file,
Advanced details can be found in attached file,For details see the attach,For details see the attached file For further details see the attach..Please, read the attach for further details
Pay attention on attached file.
2.发送大量的病毒邮件(线程1)。
病毒运行时将会从以下扩展
名:.xls,.jpg,.avi,.wma,.mp4,.mp3,.wav,.wab,.mht,.adb,.tbb,.uin .rtf.,dbx,.eml,.mmf,.nch,.mbx,.htm,.pl,.sht,.php.的文件中搜索有效的email地址(病毒将避开.edu结尾的email地址),并向这些地址发送病毒邮件。
3.感染目录(线程1)。
当病毒发现搜索的目录名中包含字串“shar”时会把自己的复本复制过去文件名为以下之一:
Microsoft Office 2003 Crack, Working!.exe,Microsoft Office XP working Crack, Keygen.exe ,Microsoft Windows XP, WinXP Crack, working Keygen.exe,Porno Screensaver.scr.Porno, sex, oral, anal cool, awesome!!.exe、Porno pics arhive, xxx.exe,Serials.txt.exe.Windown Longhorn Beta Leak.exe,Windows Sourcecode update.doc.exe,XXX hardcore images.exe,Opera 8 New!.exe.WinAmp 5 Pro Keygen Crack Update.exe,WinAmp 6 New!.exe,Matrix 3 Revolution English Subtitles.exe,Adobe Photoshop 9 full.exe,Ahead Nero 7.exe,ACDSee 9.exe
|