病毒名称:
Worm.P2P.Vb.a
类别: 蠕虫
病毒资料:
破坏方法:
VB写的 蠕虫,通过P2P和邮件传播
它将创建下列注册表键值来使自己随Windows系统自启动:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion\Run
worm = "%CURDIR%\%CURFILE%"
感染:
病毒通过P2P文件共享和邮件传播,病毒通过P2P传播时发送的信息为:
Watch this first!
Cool addon
New Microsoft Service Pack Available
Try to use this
Very nice IRC script
Please help
War makes no good...help!
New ProdUCt: AMD Athlon XP Processor 2300+
Let the religion conflicts die!
Happy to hear from you!
Lets go out some day!
Security Patch for Windows
Tips: HOW TO PREVENT YOUR PC FROM ATTACKED!
Free porno trailer here!!!
Hot,wild tits for free...
Check this out...very funny!
Microsucks gets busted with low security
Matrix all the way!
Loveletter...noooo!
GTA ViceCity FAQ
Human body lecture
Your wife naked
Metallica concert pics
Company jobs now
Pamela Anderson naked!
Biggest tits arround!
Horny teens ...wow!
Get naked for me
Blow job causes cancer!
Metallica new album!!!
Free concert tickets!
Your new payday is today
Very funny animation
Hotmail Staff needs your help!
Try it now! Totally awsome!
Summer means hot girls!
Meet Angelica Jolie's pussy
Police wanted level
FBI gives reward for criminal
New porn show every day for FREE!
Mission Impossible 3 Stunts Trailer
Just try this!
发送的文件就是病毒。
通过Outlook邮件传播时可能的信息是:
标题: "Hello my friend!
I dont know if you remember me so good. I do and I will never forget you and
Please reply if you want to know who I am!"
正文:
"how you helped me the last time we met. Thats why I wish to make you a gift,
a small sign of my everlasting friendship! Please check it out before its not too late.
With deep friendship,
Your old friend."
附件就是病毒。
网络传播:
此处是网络传播信息
病毒危害:
注:
%SYSDIR% 是可变的WINDOWS系统文件夹,默认为: C:\Windows\System (Windows 95/98/Me),
C:\Winnt\System32 (Windows NT/2000), 或 C:\Windows\System32 (Windows XP).
%WINDIR% 是可变的,是WINDOWS的安装目录(默认为: C:\Windows or C:\Winnt).
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
Windows下的PE病毒。
发现日期:
2004-4-15