病毒名称(中文):
病毒别名:
威胁级别:
★☆☆☆☆
病毒类型:
蠕虫病毒
病毒长度:
34816
影响系统:
Win9xWinMeWinNTWin2000WinXPWin2003
病毒行为:
这是一个通过电子邮件和一些文件共享系统(包括:KaZaA、eDonkey2000、Bearshare、Grokster和Morpheus)传播的蠕虫病毒。病毒运行的时候会弹出一个对话框声称系统存在致命错误,希望用户进行系统升级;再将自己的多个副本拷贝到系统目录下和这些文件共享系统的共享目录中,这些副本的扩展名一般为.exe和.scr。该病毒会终止一些常见的反病毒软的进程并删除诺顿反病毒软件的所有文件。病毒会在OutLook的地址薄中收集邮件地址,并伪造发信人地址向这些邮件接收者发送带有病毒的邮件。
1.病毒运行的时候显示如下信息:
标题:
FatalerrorinWindowsKernell
内容:
Pleaseallowa10MINUTESaccesforwindowstosendanerrorreporttomicrosoftinhopetheysolvethiserrorThisoperationcouldtakeafewmomentsbutitwillhelpmicrosofttomakeanWindowsUpdateIfadialogispromptedfromMSOutlookthenpleaseclicktheyesbuttontoallowWindowstosendthee-mail!
2.将自己拷贝到系统目录和共享目录中:
%System%\Cyberwolf.exe
%System%\Rundll32.exe
%System%\System\Explorer.exe
%System%\System\System.exe
%System%\Kernell32.exe
%System%\System32.exe
%System%\Systems.exe
%System%\Service.exe
%System%\Regedit32.exe
%System%\Cyberwolf.exe
%System%\Windows.Scr
%System%\Ms-Dos.Com
%Temp%\WindowsMediaPlayerPlugin.exe
\WindowsSecurityHaches\VisualBasic6.0MsdnPlugin.exe
\WindowsSecurityHaches\HotmailHacker2003-XssExploit.exe
\WindowsSecurityHaches\NetbiosNuker2003.exe
\WindowsSecurityHaches\Winrar3.XxPasswordCracker.exe
\WindowsSecurityHaches\MicrosoftKeygenerator-AllmostAllMicrosoftStuff.exe
\WindowsSecurityHaches\W32.Cyberwolf@MmFix.exe
\WindowsSecurityHaches\KazaaSDK+XbitSpeedupFor2.Xx.exe
\WindowsSecurityHaches\WinzippedVisualC++Tutorial.exe
\WindowsSecurityHaches\Xnuker20032.93b.exe
\WindowsSecurityHaches\Edonkey2000-SpeedMeUpScotty.exe
\WindowsSecurityHaches\ImeshSDK+XbitSpeedUp.exe
\WindowsSecurityHaches\PopupRemover9.25.exe
\WindowsSecurityHaches\CreditCardNumbersGenerator(InclVisa,Mastercard,...).exe
\WindowsSecurityHaches\EAGamesKeygenForAllVersions(OnlyEA).exe
\WindowsSecurityHaches\FreeMem-Games-Speedup.exe
\WindowsSecurityHaches\Security-2003-Update.exe
\WindowsSecurityHaches\StrippingMP3Dancer+Crack.exe
\WindowsSecurityHaches\Crackologic(AllWindowsApps).exe
\WindowsSecurityHaches\TheCyberwolf-Joke.Scr
\WindowsSecurityHaches\MyKissForYou.Scr
\WindowsSecurityHaches\WindowsXpExploit.exe
\WindowsSecurityHaches\Cyberwolf-Patch.exe
C:\ProgramFiles\Edonkey2000\Incoming\Edonkey2000-AdRemover.exe
C:\ProgramFiles\Edonkey2000\Incoming\HotmailHacker2003-XssExploit.exe
C:\ProgramFiles\Edonkey2000\Incoming\NetbiosNuker2003.exe
C:\ProgramFiles\Edonkey2000\Incoming\Winrar3.XxPasswordCracker.exe
C:\ProgramFiles\Edonkey2000\Incoming\EAGamesKeygenForAllVersions(OnlyEA).exe
C:\ProgramFiles\Bearshare\Shared\HotmailHacker2003-XssExploit.exe
C:\ProgramFiles\Bearshare\Shared\BearshareResults:
Thespeedandgraphicalabilitiesareincreasedby35%,soloadinganewgamewilego35%faster!Somoregameplay,lesswaitingandlookingatthatumscreen!
ButitwilltakesometimeforEAandEIDOStoalertallpeopleswhohasEAandEIDOSgames,but...
TheydecidedtomailtheCyberWolf-PatchtouserswhohavegamesfromEAandEIDOSandtopeoplewhovisitedthewebsitewithinthepast18months!
alsotheydecidedtomailthispatchtoworkersincompaniesandtootherpeoplewhoareusingtheinternetregulary
IfyouwanttoenjoythisSpeed-the-hell-out-ya-head-PATCHthenjustinstalltheattachment,restartyou"repcandstartplayinggamesor...
waituntilyoubuyaEAorEIDOSgame,andenjoyitthen!thechoiceisyours!
Beforeiforget:Thispatchseemstoworkonothergamesaswell,itspeedsupthosegamesby15-30%dependingonthegame!
----------------------------------------------
ThisemailisprovidedtoyoubyPacketStorm,pleaseenjoyourservices
ThisproductmayNOTbesoledorcopied!Itmayonlybeusedbytheintendedrecipientandthisonlyforthepurposeforwhichithasbeensent
Ifyouarenottheintendedrecipient,thenpleasecontactEAorEIDOSatEE-CyberWolf.patch@EA-EIDOS.comanddeletethise-mailandattachement
Webelieveandwarrantthatthise-mailandanyattachments,arevirusfree,wetakefullresponsibilityaboutthisattachment
CyberWolf
FormoreinformationpleasecontactusatEE-CyberWolf.patch@EA-EIDOS.comorsufttowww.EA.com/project\cyberwolf.htmandww.eidos.com\cyberwolf.asp
E-mailprovidedtoyoubyElena(Elena@EA-EIDOS.com)
Attachment:CyberWolf-Patch.exe(34,816bytes)
Subject:PacketStorm:WINDOWSXphasseveralexploits
Message:
AccordingtotheredactionofPacketStorm
WindowsXphasseveralexploitswhichcouldnotberemovedbecause
ifthedowanttodeleteitthentheyshouldrewriteKernell!
butthiswouldmeanrewritingeverythingMicrsofthadbuildupoverthelastyears"
BillGatesfrommicrosoftreportedthatthereisnoexploitatall!,itwasjustajokefromahacker
attendingtoscaroffwindowsXPusers
Howeverthewordgoesaroundthatallreadyseveralusersandadminshavebeenhackedbyanmysterioushacker
nicknamed"TheCyberWolf"
ifyouwantmoreinformationaboutthisexploitandtheexploititself,thenopentheincludede-mail
donotforgettovoteforPacktStormwhenrunningtheattachment,Enjoytherestofourservices
ThisemailisprovidedtoyoubyPacketStorm,pleaseenjoyourservices
Attachment:WindowsXpExploit.exe(34,816bytes)
Subject:AVirtualjoke...thefunniestaround!
Message:
hi
haveyouheardabouttheCyberWolf-Joke?
itssoooofunnyyou"lllaughyourselfabunchwhenyouseeandhearthejoke
hahathoselittlebastardsonyourscreenaresoooofunny:D:D
justdownloadandopentheattachedscreensaver(TheCyberWolf-Joke.scr=thisisactuallythejoke)andlookatit
funnyhu!!!
afteryouhaverunthejokeclickctrl+shift+ptoseewhomadeit.
Ihopeyouhavefunwithit
greeetttzzz
***************************************************
Thise-mailispresentedtoyoubyJoking-Soft,adivisionofMicroSoft.
Ifyouhaveanyproblemswiththise-mailorattachmentthenpleasecontactus.
Wetakefullresponsabilityforthise-mailandattachements.
TheyarevirusfreeandarepropertyofJoking-Soft
PleasedonotSellorDistributetheseatachments.
Ithankyou
Attachment:TheCyberWolf-Joke.scr(34,816bytes)
Subject:Akissfrommetoyou...
Message:
DearUser
Someonehasdroppedakissinyou"remailbox!
Check-OuttheattachedKissfromtheanonymousperson,probablyasecretloveroraverygoodfriend
Afteryouhavebeenkissedpleasevisitwww.internetkiss.comandsendthiskisstoallthepersonwhoyouadoreorjustlike
YouareNr.315723625whohasreceivedthisInternet-Kiss.
ThisInternet-Kiss-Letterisstartedon13/01/1997andhopestocontinueuntil13/01/2007.
Attachment:MyKissforyou.scr(34,816bytes)