¡¡ µ±Ç°Î»ÖÃ:Ê×Ò³ >> ÐÂÎÅ >> ITÐÂÎÅ >> ÕýÎÄ ¡¡
¡¡ ¡¡ ¡¡
¡¡

ÎÒ¹ú³öÏÖ¡°Ð¡Óʲ£¨Worm_Mimail.A£©²¡¶¾

(gx.chinavnet.com »¥ÁªÐÇ¿Õ 2003Äê08ÔÂ07ÈÕ12:45:41)

¡¡
¡¡

    ¡°Ð¡Óʲ£¨Worm_Mimail.A£©²¡¶¾ÓÚ8ÔÂ1ÈÕÊ״γöÏÖ£¬¸Ã²¡¶¾Ä¿Ç°ÔÚÃÀ¹ú¡¢Å·ÖÞ´«²¥½ÏΪѸËÙ£¬ÎÒ¹úÓû§Ò²³öÏÖÁ˸ÐȾ°¸Àý£¬¸ÃÓû§ÓÉÓÚ´ò¿ªÁ˲¡¶¾Óʼþ£¬ÔâÊÜÁ˸ò¡¶¾µÄ¸ÐȾ¡£ÔâÊܸò¡¶¾¸ÐȾºó£¬²¡¶¾¶Ô²»¶ÏÏòÍâ·¢ËÍȾ¶¾Óʼþ£¬µ¼Ö²¡¶¾½øÒ»²½À©É¢£¬Í¬Ê±ÏµÍ³ÄÚ´æ±»´óÁ¿Õ¼Óã¬Ê¹µÃϵͳÔËÐÐËٶȼõÂý¡£

    ¸Ã²¡¶¾µÄ´«²¥ÀûÓÃÁËÒÑÖªµÄ©¶´£¬Ïà¹ØÂ©¶´²éѯÇë²Î¼û

    MS02-15 http://www.microsoft.com/technet/treeview/

    default.asp?url=/technet/security/bulletin/MS02-015.asp

    ÒÔ¼°MS03-14 http://www.microsoft.com/technet/treeview/

    default.asp?url=/technet/security/bulletin/MS03-014.asp

    ²¢Çëµ½ÒÔÏÂÁ´½ÓÏÂÔØÉý¼¶Îļþ

    http://www.microsoft.com/windows/ie/downloads/critical/

    330994/default.asp

    ¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÌáÐѹã´óÓû§£¬¼°Ê±ÏÂÔØ°²×°²¹¶¡³ÌÐò¡£ÁôÒâ¸Ã²¡¶¾µÄÖ÷ÒªÌØÕ÷£¬Óöµ½´ËÀàÓʼþ²»Òª´ò¿ª£¬Ó¦Á¢¼´É¾³ý¡£

    ¸Ã²¡¶¾µÄ¼¼Êõ±¨¸æÈçÏ£º

    ²¡¶¾Ãû³Æ£º¡°Ð¡Óʲ£¨Worm_Mimail.A£©

    ²¡¶¾ÀàÐÍ£ºÈ䳿

    ¸ÐȾϵͳ£ºWindows 95/98/Me/NT/2000/XP

    ²¡¶¾ÌØÕ÷£º

    ¸Ã²¡¶¾µÄ´«²¥ÀûÓÃÁËÒÑÖªµÄ©¶´£¬²¡¶¾Í¬Ê±Ê¹ÓÃUPX½øÐÐѹËõ¡£

    1¡¢Í¨¹ýµç×ÓÓʼþ½øÐд«²¥

    ²¡¶¾Í¨¹ý×ÔÉíµÄSMTPÒýÇæ´«²¥£¬Í¨¹ýµç×ÓÓʼþ½øÐд«²¥Ê±£¬Î±×°³É¹ÜÀíÔ±·¢¸øÓû§µÄÓʼþ£¬²¢Éù³Æ¸ÃÓû§ËùʹÓõĵç×ÓÓʼþµØÖ·½«Òªµ½ÆÚ£¬ÓÕÆ­Óû§´ò¿ªÓʼþ¸½¼þ£¬´Ó¶ø¸ÐȾ²¡¶¾¡£²¡¶¾Óʼþ¸ñʽÈçÏ£º

    ·¢ÐÅÈË£ºadmin@%x%£¨%x%Ϊ¿É±äµÄ£¬¾­³£Î±×°³ÉÓʼþÓû§ËùÔÚÓò£©

    Ö÷Ì⣺your account %y%£¨%y%ΪÈÎÒâ×Ö·û£©

    ÄÚÈÝ£º

    Hello there,

    I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details.

    Best regards,Administrator %z%£¨%z%ΪÈÎÒâ×Ö·û£©

    ¸½¼þ£ºmessage.zip

    ¸½¼þmessage.zip°üº¬Ò»¸öHTMLÎļþºÍÒ»¸ö¾­UPXѹËõµÄWin32¿ÉÖ´ÐÐÎļþ¡£µ±´ò¿ªHTMLʱ£¬¶ñÒâ³ÌÐò´úÂë¾Í±»Ö´ÐÐÁË£¨ÀûÓÃInternet ExplorerµÄ©¶´£©£¬Ö®ºó.exeÎļþ±»Ö´ÐУ¬¸Ã³ÌÐòΪ²¡¶¾µÄÖ÷Ìå¡£

    ³ýÁËÒÔÏÂ18ÖÖÀàÐ͵ÄÎļþÖ®Í⣬²¡¶¾ÔÚ±»¸ÐȾÓû§µÄ¼ÆËã»úÉÏËÑË÷Ê£ÓàËùÓÐÀàÐ͵ÄÎļþ£¬Ñ°ÕÒ¿ÉÓõĵç×ÓÓʼþµØÖ·£¬²¢ÏòÕâЩµØÖ··¢ËÍ´øÓв¡¶¾µÄµç×ÓÓʼþ¡£Õâ18ÖÖÀàÐ͵ÄÎļþ°üÀ¨.avi¡¢.bmp¡¢.cab¡¢.com¡¢.dll¡¢.exe¡¢.gif¡¢.jpg¡¢.mp3¡¢

    .mpg¡¢.ocx¡¢.pdf¡¢.psd¡¢.rar¡¢.tif¡¢.vxd¡¢.wavºÍ.zip¡£

    2¡¢Éú³É²¡¶¾Îļþ

    ²¡¶¾Ò»µ©ÔËÐУ¬È䳿ÔÚWindowsÎļþ¼ÐÖÐÉú³É×ÔÉí¿½±´£¬²¢ÃüÃûΪvideodrv.exe¡££¨WindowsĿ¼ͨ³£ÎªC:Windows»òC:WINNT£©£¬ÁíÍ⣬²¡¶¾Í¬Ê±ÔÚWindowsĿ¼ÖÐÉú³ÉÏÂÁÐÈý¸öÎļþ£º

    eml.tmp--´Ó±¾µØ¼ÆËã»úÖÐËѼ¯µÄÓʼþµØÖ·ÁÐ±í¡£

    zip.tmp--message.zipµÄÁÙʱÎļþ£¬²¡¶¾·¢Ë͵ÄÓʼþʱʹÓõÄzip¸½¼þ

    exe.tmp--HTMLÒÔ¼°¾­UPXѹËõµÄWin32 exe Îļþ¡£

    3¡¢ÐÞ¸Ä×¢²á±í

    ²¡¶¾¶Ô×¢²á±í½øÐÐÐ޸ģ¬Ê¹µÃ²¡¶¾Äܹ»ËæÏµÍ³Æô¶¯¶ø×Ô¶¯ÔËÐÐ

    HKEY_Local_MachineSoftwareMicrosoftWindows

    CurrentVersionRun "VideoDriver"="%Windows%

    videodrv.exe"

    ²¡¶¾»¹´´½¨ÒÔÏÂ×¢²á±íÏîÄ¿

    HKEY_Local_MachineSoftware>Microsoft>Code Store Database>Distribution Units {11111111-1111-1111-1111-111111111111}

    Çå³ý²¡¶¾µÄÏà¹Ø²Ù×÷

    1¡¢É¾³ý²¡¶¾µç×ÓÓʼþ

    2¡¢ ÖÕÖ¹²¡¶¾½ø³Ì

    Windows 9x/MEϵͳ£¬Í¬Ê±°´ÏÂCTRL+ALT+DELETE¼ü£¬

    Windows NT/2000/XPϵͳ£¬Í¬Ê±°´ÏÂCTRL+SHIFT+ESC¼ü£¬

    Ñ¡ÖÐÕýÔÚÔËÐеIJ¡¶¾½ø³ÌVideodrv.exe£¬²¢ÖÕÖ¹¸Ã½ø³ÌµÄÔËÐС£

    3¡¢¶Ô×¢²á±í½øÐлָ´

    £¨1£©µã»÷¡°¿ªÊ¼->ÔËÐС±£¬ÊäÈëregedit.exe²¢»Ø³µ

    £¨2£©ÒÀ´ÎË«»÷×ó²àÃæ°åÖÐµÄ HKEY_Local_MachineSoftware

    MicrosoftWindowsCurrentVersionRun£¬ÔÚÓÒ²àÁбíÖвéÕÒ²¢É¾³ýÒÔÏÂÏîÄ¿£º"VideoDriver"="%Windows%videodrv.exe"

    £¨ÆäÖÐ%Windows%ΪWindowsĿ¼£¬Í¨³£ÎªC:Windows»òC:WINNT£©

    £¨3£©ÒÀ´ÎË«»÷×ó²àÃæ°åÖÐµÄ HKEY_LOCAL_MACHINE>SOFTWARE>

    Microsoft>Code Store Database>Distribution Units£¬

    ÔÚÓÒ²àÁбíÖвéÕÒ²¢É¾³ýÒÔÏÂÏîÄ¿£º{11111111-1111-1111-1111-111111111111}

    4¡¢É¾³ý²¡¶¾Îļþ

    ²éÕÒ²¡¶¾Îļþeml.tmp¡¢zip.tmp¡¢exe.tmp²¢É¾³ý¡£

    5¡¢Ê¹ÓÃɱ¶¾Èí¼þ¶Ô¼ÆËã»ú½øÐÐÈ«ÃæµÄ²¡¶¾Çå³ý

    £¨¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄ£©

    À´Ô´:лªÍø
    Ôð±à:ÁõÇå

¡¡
¡¡ ¡¡ ¡¡
科幻小說