病毒名称:
Worm.Win32.Atak.g
类别: 蠕虫病毒
病毒资料:
破坏方法:
一个简单的蠕虫病毒
病毒行为:
病毒运行后,将自己复制到%system%目录下,文件名为:mpexec.exe并在win.ini
文件的WINDOWS节的LOAD项中加入自己.以达到自启动目的.
随后病毒驻留内存,搜索磁盘文件并尝试从中提取email地址,向其发送带毒邮件.
邮件标题:
human spirit
Not Wars
and get money
for fun
will freedom
to other
with me
Not spam
Have a...
邮件内容:
We have installed our anti-spam tools to protect your email
Your account info has been setting up to block spam email
We have make a few change for our customer. Please be informed
We have upgraded your account features
Your account has been upgraded with our new services
Help Team
Technical Support
Customer Services
Administrator
Services Team
has been saved. Please check when needed
can be found at your email attachment
has been clipped to your email
already included into your email
has been attached as a file and ready to be printed
Saved
Email account
Your credential
Your account
NOTE: All your account
Thank you
Your sincerely
Regard
[please change it after registeration]
(You can change it later)
(temp. pwd only)
(temporary passWord)
Remember this note
Please take note this info
Keep this info
Your account info
know about account features
learn about our features
get more info
find out our services
Logon to
Please check our
Visit our
Goto our...
附件为:
%随机字符%.zip
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
Windows下的PE病毒。
发现日期:
2004-12-16