病毒名称(中文):
病毒别名:
威胁级别:
★☆☆☆☆
病毒类型:
蠕虫病毒
病毒长度:
61440
影响系统:
Win9xWinMeWinNTWin2000WinXPWin2003
病毒行为:
该病毒主要利用了微软的漏洞,通过电子邮件传播.因此,会给用户带来些麻烦
1.把自身拷贝到
%win%\Systra.exe
%Sys%\Hxdef.exe
%Sys%\iexplore.exe
%Sys%\RAVMOND.exe
%Sys%\Kernel66.dll
%Sys%Winhelp.exe
2.创建下列文件
%Sys%\ODBC16.dll
%Sys%\Msjdbc11.dll
%Sys%\MSSIGN30.dll
%Sys%\LMMIB20.DLL
3.创建并执行%Sys%\NetMeeting.exe文件,NetMeeting.exe运行时,会
1)拷贝到%Sys%\spollsv.exe
2)添加"ShellExtension"="%system%\spollsv.exe"到
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run中
4.在
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run中
添加
"HardwareProfile"="%System%\hxdef.exe
"MicrosoftNetMeetingAssociates,Inc."="NetMeeting.exe"
"PrograminWindows"="%System%\IEXPLORE.EXE"
"ProtectedStorage"="RUNDLL32.EXEMSSIGN30.DLLondll_reg"
"VFWEncoder/DecoderSettings"="RUNDLL32.exeMSSIGN30.DLLondll_reg"
"WinHelp"="%System%\WinHelp.exe"
5.在
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersionRunServices
中添加
"SystemTra"="%Windir%\Systra.exe"
6.在
HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersionWindows
中添加
"run"="RAVMOND.exe"
7.停止下列服务
RisingRealtimeMonitorService
SymantecAntivirusServer
SymantecClient
8.中止下列进程
KV
KAV
Duba
NAV
kill
RavMon.exe
Rfw.exe
Gate
McAfee
Symantec
SkyNet
rising
9.以下列文件名拷贝到共享文件夹中.
WinRAR.exe
InternetExplorer.bat
DocumentsandSettings.txt.exe
MicrosoftOffice.exe
WindowsMediaPlayer.zip.exe
SupportTools.exe
WindowsUpdate.pif
Cain.pif
MSDN.ZIP.pif
autoexec.bat
findpass.exe
client.exe
i386.exe
winhlp32.exe
xcopy.exe
mmc.exe
10.会用下列密码尝试猜治理员密码
Guest
Administrator
zxcv
yxcv
xxx
win
test123
test
temp123
temp
sybase
super
sex
secret
pwd
pw123
Password
owner
oracle
mypc123
mypc
mypass123
mypass
love
login
Login
Internet
home
godblessyou
god
enable
database
computer
alpha
admin123
Admin
abcd
aaa
88888888
2600
2004
2003
123asd
123abc
123456789
1234567
123123
121212
11111111
110
007
00000000
000000
pass
54321
12345
password
passwd
server
sql
!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
asdfgh
asdf
!@#$
1234
111
root
abc123
12345678
abcdefg
abcdef
abc
888888
666666
111111
admin
administrator
guest
654321
123456
321
123