病毒名称:
I-Worm.Nevezed (aka Never)
类别: 蠕虫
病毒资料:
简介:通过Microsoft Outlook传播的蠕虫病毒,是一个4K的Java Script文件。
安装:
蠕虫将自己复制到Windows的系统启动目录,命名为StarUp.js,以及系统目录中命名为CmdWsh32.js,并将自己添加到注册表中,做为一个java-class文件,还会在其他磁盘的要目录下保留自己的副本。
传播:电子邮件
通过MS Outlook向所有地址簿中的用户自动发送,主题会变化为:
Hello name
Hey name
Fwd: Hey You!
Fwd: Check this!
Fwd: Just Look
Fwd: Take a look!
Fwd: Loop at this!
Fwd: Check this out!
Fwd: It‘s Free!
Fwd: Look!
Fwd: Free mp3s!
Fwd: Here you go!
Fwd: Have a look!
Look name!
Fwd: Read This!
正文会形如:
Hello!
Check out this great list of mp3 sites that I included in the attachments! I can get any Mp3 file that I want from these sites, and its free! And please don‘t be greedy! forward this email to all the people that you consider friends, and Let them benefit from these Mp3 sites aswell! Enjoy !
另外可能带有以下文件名的附件:
Free_Mp3s.js
Fwd_Mp3s.js
Mp3_Sites.js
Mp3_Web.js
Mp3_List.js
Mp3_Pages.js
Web_Mp3s.js
Mp3-Sites.js
Fwd-Mp3s.js
Mp3-Fwd.js
Fwd-Sites.js
病毒的清除法:
使用光华反病毒软件,彻底删除。
病毒演示:
病毒FAQ:
通过邮件传播 .
发现日期:
2003-3-13