病毒名称:
W32.Poscal.Worm
类别: 蠕虫
病毒资料:
病毒危害:
大量发送邮件:会向Outlook地址簿中的联系人发送大量病毒邮件
删除文件:会删除C:WindowsSystem.ini, C:WindowsEXPlorer.exe C:WindowsRegedit.exe C:WindowsTelnet.exe文件;删除C:AutoExec.bat
病毒传播:
1.邮件
主题:Anti-Virus Programs are corrupting your Software!
正文;Want to know why you get junk mail? Well Here is proof that AV‘s are corrupting your programs and Sell your Private information to Web Company‘s! Why do you think there are so mUCh virus‘s out there? well its these Company‘s
that spread them and then sell you there product to delete them! check it out now... (p.s. its attatched)
附件:FK_AVs.exe
2.共享磁盘:会通过KaZaA文件共享网络传播
技术特征:
蠕虫运行后,会:
将自己复制成如下文件:
C:WindowsActiveX.exe
C:WindowsSCR.exe
C:WindowsMSWord.exe
C:WindowsMixer.exe
C:WindowsFK_AVs.exe
C:WindowsSystemExplorer.exe
C:Windows
egedit.exe
C:WindowsTelnet.exe
C:WindowsExplorer.exe
注意:
(1).C:WindowsFK_AVs.exe及C:WindowsSystemExplorer.exe 文件属性为只读及隐藏。
(2).C:WindowsRegedit.exe, C:WindowsTelnet.exe,及C:WindowsExplorer.exe是有效的Windows程序,在Windows 95/98/Me系统上会被蠕虫覆盖。
3.假如C:Program FilesKaZaaMy Shared Folder文件夹存在,蠕虫会将自己复制到该文件夹下,并命名为:
Norton_crack.exe
UT3_full_crack.exe
Windows_Hack.exe
Sims_Patch.exe
4.用如文字覆盖C:WindowsSystem.ini
[About]
Author = Industry
VXgroup = ANVXgroup (Auxnet)
Virus = ANVX (WIN32.calposa@mm)
Shouts to = Indovirus, mANiAC89, Retro, Iwing, and every one else.
F??k = F??k all AV‘s, we keep you in a job so give us a bit of slack!
To the rest = ANVX the one and only!
技术特征:
该病毒运行后会覆盖Windows文件夹下的文件,被覆盖的文件即已遭至损坏而且不可修复。同时会弹出如下窗口:
假如你点击“OK”的话,病毒就会终止。
若系统日期为2月16日,蠕虫会显示一图片
若系统日期为4月2日,蠕虫会弹出如下窗口:
若系统日期为4月1日,蠕虫首先会删除C:Autoexec.bat及如下文件夹下的随机选取文件:
C:Windows
C:WindowsSystem32
C:WindowsSystem
C:Windowsinf
C:Program FilesKazaa
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
别名: I-Worm.Calposa [AVP], WORM_CALPOSA.A [Trend], W32/Calposa.worm [McAfee]
警惕“Poscal”蠕虫 感染后会删除系统文件。
发现日期:
2002-11-6