病毒名称:
Worm.P2P.Delf.t
类别: 蠕虫
病毒资料:
破坏方法:
Delphi写的蠕虫。在98下会注册为服务,隐藏在后台运行。
将自己拷贝到C:\Windows\lsass_.exe,在注册表
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 下增加一项,使自己能开机自启动。
然后将自己拷贝到以下目录以传播自己:
c:\program files\Kazaa\My Shared Folder\13yr bath.mpg.exe
c:\program files\Kazaa\My Shared Folder\Jenna Jameson - shower scene.mpg.exe
c:\program files\Kazaa\My Shared Folder\Heather - all
gone@deepthroat.com.mpg.exe
c:\program files\Kazaa\My Shared Folder\I Deep Throat - Heather
(bondage).mpg.exe
c:\program files\Kazaa\My Shared Folder\cought on camera -
in kitchen and gets fired.mpg.exe
c:\program files\Kazaa\My Shared Folder\Paris and Nikey Hilton at the
beach.jpg.exe
c:\program files\Kazaa\My Shared Folder\metallica - st. angr.mp3.exe
c:\program files\Kazaa\My Shared Folder\WinZip 9.0.exe
c:\program files\Kazaa\My Shared Folder\Godsend (all).avi.exe
c:\program files\Kazaa\My Shared Folder\Kill Bill2 (all).avi.exe
c:\program files\Kazaa Lite\My Shared Folder\13yr bath.mpg.exe
c:\program files\Kazaa Lite\My Shared Folder\Jenna Jameson - shower
scene.mpg.exe
c:\program files\Kazaa Lite\My Shared Folder\Heather - all
gone@deepthroat.com.mpg.exe
c:\program files\Kazaa Lite\My Shared Folder\I Deep Throat - Heather
(bondage).mpg.exe
c:\program files\Kazaa Lite\My Shared Folder\cought on camera - in kitchen
and gets fired.mpg.exe
c:\program files\Kazaa Lite\My Shared Folder\Paris and Nikey Hilton at the
beach.jpg.exe
c:\program files\Kazaa Lite\My Shared Folder\metallica - st. anger.mp3.exe
....
....
c:\My Downloads\metallica - st. anger.mp3.exe
c:\My Downloads\Winzip 9.0.exe
c:\My Downloads\Godsend (all).avi.exe
c:\My Downloads\Kill Bill2 (all).avi.exe
c:\My Shared Folder\13yr bath.mpg.exe
c:\My Shared Folder\Jenna Jameson - shower scene.mpg.exe
c:\My Shared Folder\Heather - all gone@deepthroat.com.mpg.exe
c:\My Shared Folder\I Deep Throat - Heather(bondage).mpg.exe
c:\My Shared Folder\cought on camera - in kitchen and gets fired.mpg.exe
c:\My Shared Folder\Paris and Nikey Hilton at the beach.jpg.exe
c:\My Shared Folder\metallica - st. anger.mp3.exe
c:\My Shared Folder\Winzip 9.0.exe
c:\My Shared Folder\Godsend (all).avi.exe
c:\My Shared Folder\Kill Bill2 (all).avi.exe
调用命令ping www.jobs4al.com -l 65500 -w 5 -t 以攻击指定网站。
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
Windows下的PE病毒。
发现日期:
2004-8-9