科技行者

行者学院 转型私董会 科技行者专题报道 网红大战科技行者

知识库

知识库 安全导航

至顶网安全频道MYDOOM最新变种AB(Worm.Mydoom.AB)分析报告

MYDOOM最新变种AB(Worm.Mydoom.AB)分析报告

  • 扫一扫
    分享文章到微信

  • 扫一扫
    关注官方公众号
    至顶头条

该病毒会把自身复制到windows目录下并以服务的形式随计算机启动而运行.;

来源:论坛整理 2008年6月29日

关键字: 木马 病毒查杀 病毒

  • 评论
  • 分享微博
  • 分享邮件
 

病毒名称: Worm.Mydoom.AB

中文名称: 诺维格变种AB

威胁级别: 二级

病毒别名: I-Worm.Mydoom.y[AVP]

发现日期: 2004.09.17

病毒简介:

A、该病毒会把自身复制到windows目录下并以服务的形式随计算机启动而运行.;

B、通过修改注册表禁止使用注册表工具(regedit);

C、修改hosts文件使用户无法登录一些安全或反病毒公司主页;

D、通过ICQ发送带毒链接来传播自身;

E、从指定的网站下载后门木马到用户机器上;

F、结束用户机器上的反病毒软件的进程;

G、向外发送大量的带毒邮件,而造成网络堵塞。

技术特点:

1、把自己复制到%SystemRoot%services.exe

2、修改注册表:

A.Win9x:

在注册表主键"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"下,

添加如下键值:"serv"="%SystemRoot%services.exe"

B.Win2000/xp:

创建服务:

服务名: NetBios Ext

显示名称: NetBios Ext

执行路径: %Windir%\services.exe serv

启动类型: Automatic

增加HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\Type = "0x10"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\Start = "0x2"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\ErrorControl = "0x1"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\ImagePath =

"%SystemRoot%\services.exe serv"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\DisplayName = "NetBios Ext"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\Security\Security

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetBios Ext\ObjectName = "LocalSystem"



3、修改注册表项

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies

\DisableRegistryTools = "0x0"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies

\DisableRegistryTools = "0x0"


4、修改%System%\drivers\etc\hosts文件,使用户不能正常登录反病毒相关网站

127.0.0.1 www.avp.com

127.0.0.1 www.viruslist.com

127.0.0.1 viruslist.com

127.0.0.1 www.symantec.com

127.0.0.1 networkassociates.com

127.0.0.1 secure.nai.com

127.0.0.1 downloads1.kaspersky-labs.com

127.0.0.1 downloads2.kaspersky-labs.com

127.0.0.1 downloads3.kaspersky-labs.com

127.0.0.1 downloads4.kaspersky-labs.com

127.0.0.1 downloads-us1.kaspersky-labs.com

127.0.0.1 downloads-eu1.kaspersky-labs.com

127.0.0.1 kaspersky-labs.com

127.0.0.1 www.networkassociates.com

127.0.0.1 us.mcafee.com

127.0.0.1 f-secure.com

127.0.0.1 avp.com

127.0.0.1 www.sophos.com

127.0.0.1 sophos.com

127.0.0.1 www.ca.com

127.0.0.1 ca.com

127.0.0.1 securityresponse.symantec.com

127.0.0.1 symantec.com

127.0.0.1 mast.mcafee.com

127.0.0.1 my-etrust.com

127.0.0.1 www.kaspersky.com

127.0.0.1 www.f-secure.com

127.0.0.1 dispatch.mcafee.com

127.0.0.1 update.symantec.com

127.0.0.1 nai.com

127.0.0.1 www.nai.com

127.0.0.1 liveupdate.symantec.com

127.0.0.1 customer.symantec.com

127.0.0.1 rads.mcafee.com

127.0.0.1 trendmicro.com

127.0.0.1 liveupdate.symantecliveupdate.com

127.0.0.1 www.mcafee.com

127.0.0.1 mcafee.com

127.0.0.1 viruslist.com

127.0.0.1 www.my-etrust.com

127.0.0.1 download.mcafee.com

127.0.0.1 updates.symantec.com

127.0.0.1 kaspersky.com

127.0.0.1 www.trendmicro.com

5、通过ICQ发送带毒链接来传播自身

funn http:/ /*******/icon/game.exe :-):-):-)

http:/ /******/icon/game.exe :-):-)

http:/ /******/icon/game.exe funny :-);-)

http:/ /******50/icon/game.exe ;-);-);-);-)

best game http:/ /******/icon/game.exe ;-);-);-)

http:/ /******/icon/game.exe LOL!! ;-);-);-)

http:/ /www.******/claroline142/photo.exe i cried :-)

http:/ /www.******/claroline142/photo.exe lol :-):-)

my photos (archived) http:/ /www.******/claroline142/photo.exe

i now play in game http://www.******.com/ajr/game.exe :-):-)

funy game http:/ /www.******.com/ajr/game.exe ;-);-);-)

fun game http:/ /www.******.com/ajr/game.exe :-):-):-)

6、从以下网站下载一后门木马:

http:/ /www.******.com/heyyo/wassup/00000008.cgi

http:/ /www.*******.com/adclik/click.dat

http:/ /www.*******.it/forumBB/postmsg.gif

http:/ /www.*******.de/html/content/guestbook/data/data2.dat

http:/ /www.*******.unibo.it/claroline142/claroline/index.gif

http:/ /www.*******.com/grafix/cover_v3.jpg

http:/ /*******/manual/images/apache.gif

7、查找反病毒软件和其它蠕虫病毒(结束并删除),如下:


F-AGOBOT.EXE

HIJACKTHIS.EXE

_AVPM.EXE

_AVPCC.EXE

_AVP32.EXE

ZONEALARM.EXE

ZONALM2601.EXE

ZATUTOR.EXE

ZAPSETUP3001.EXE

ZAPRO.EXE

XPF202EN.EXE

WYVERNWORKSFIREWALL.EXE

WUPDT.EXE

WUPDATER.EXE

WRCTRL.EXE

WRADMIN.EXE

WNT.EXE

WNAD.EXE

WKUFIND.EXE

WINUPDATE.EXE

WINTSK32.EXE

WINSTART001.EXE

WINSTART.EXE

WINSSK32.EXE

WINRECON.EXE

WINPPR32.EXE

WINMAIN.EXE

WINLOGIN.EXE

WININITX.EXE

WININIT.EXE

WININETD.EXE

WINDOWS.EXE

WINDOW.EXE

WINACTIVE.EXE

WIN32US.EXE

WIN32.EXE

WIN-BUGSFIX.EXE

WIMMUN32.EXE

WHOSWATCHINGME.EXE

WGFE95.EXE

WFINDV32.EXE

WEBTRAP.EXE

WEBSCANX.EXE

WEBDAV.EXE

WATCHDOG.EXE

W9X.EXE

W32DSM89.EXE

VSWINPERSE.EXE

VSWINNTSE.EXE

VSWIN9XE.EXE

VSSTAT.EXE

VSMON.EXE

VSMAIN.EXE

VSISETUP.EXE

VSHWIN32.EXE

VSECOMR.EXE

VSCHED.EXE

VSCENU6.02D30.EXE

VSCAN40.EXE

VPTRAY.EXE

VPFW30S.EXE

VPC42.EXE

VPC32.EXE

VNPC3000.EXE

VNLAN300.EXE

VIRUSMDPERSONALFIREWALL.EXE

VIR-HELP.EXE

VFSETUP.EXE

VETTRAY.EXE

VET95.EXE

VET32.EXE

VCSETUP.EXE

VBWINNTW.EXE

VBWIN9X.EXE

VBUST.EXE

VBCONS.EXE

VBCMSERV.EXE

UTPOST.EXE

UPGRAD.EXE

UPDAT.EXE

UNDOBOOT.EXE

TVTMD.EXE

TVMD.EXE

TSADBOT.EXE

TROJANTRAP3.EXE

TRJSETUP.EXE

TRJSCAN.EXE

TRICKLER.EXE

TRACERT.EXE

TITANINXP.EXE

TITANIN.EXE

TGBOB.EXE

TFAK5.EXE

TFAK.EXE

TEEKIDS.EXE

TDS2-NT.EXE

TDS2-98.EXE

TDS-3.EXE

TCM.EXE

TCA.EXE

TC.EXE

TBSCAN.EXE

TAUMON.EXE

TASKMON.EXE

TASKMO.EXE

SYSUPD.EXE

SYSTEM32.EXE

SYSTEM.EXE

SYSEDIT.EXE

SYMTRAY.EXE

SYMPROXYSVC.EXE

SWEEPNET.SWEEPSRV.SYS.SWNETSUP.EXE

SWEEP95.EXE

SVCHOSTC.EXE

SVC.EXE

SUPPORTER5.EXE

SUPPORT.EXE

SUPFTRL.EXE

STCLOADER.EXE

START.EXE

ST2.EXE

SSG_4104.EXE

SSGRATE.EXE

SS3EDIT.EXE

SRNG.EXE

SREXE.EXE

SPYXX.EXE

SPOOLSV32.EXE

SPOOLCV.EXE

SPHINX.EXE

SPF.EXE

SPERM.EXE

SOFI.EXE

SOAP.EXE

SMSS32.EXE

SMS.EXE

SMC.EXE

SHOWBEHIND.EXE

SHN.EXE

SHELLSPYINSTALL.EXE

SH.EXE

SGSSFW32.EXE

SFC.EXE

SETUP_FLOWPROTECTOR_US.EXE

SETUPVAMEEVAL.EXE

SERVLCES.EXE

SERVLCE.EXE

SERV95.EXE

SD.EXE

SCRSVR.EXE

SCRSCAN.EXE

SCANPM.EXE

SCAN95.EXE

SCAN32.EXE

SCAM32.EXE

SC.EXE

SBSERV.EXE

SAVENOW.EXE

SAVE.EXE

SAHAGENT.EXE

SAFEWEB.EXE

RUXDLL32.EXE

RUNDLL16.EXE

RUNDLL.EXE

RULAUNCH.EXE

RTVSCN95.EXE

RTVSCAN.EXE

RSHELL.EXE

RRGUARD.EXE

RESCUE32.EXE

RESCUE.EXE

REGED.EXE

REALMON.EXE

RCSYNC.EXE

RB32.EXE

RAY.EXE

RAV8WIN32ENG.EXE

RAV7WIN.EXE

RAV7.EXE

RAPAPP.EXE

QSERVER.EXE

QCONSOLE.EXE

PVIEW95.EXE

PUSSY.EXE

PURGE.EXE

PSPF.EXE

PROTECTX.EXE

PROPORT.EXE

PROGRAMAUDITOR.EXE

PROCEXPLORERV1.0.EXE

PROCESSMONITOR.EXE

PROCDUMP.EXE

PRMVR.EXE

PRMT.EXE

PRIZESURFER.EXE

PPVSTOP.EXE

PPTBC.EXE

PPINUPDT.EXE

POWERSCAN.EXE

PORTMONITOR.EXE

PORTDETECTIVE.EXE

POPSCAN.EXE

POPROXY.EXE

POP3TRAP.EXE

PLATIN.EXE

PINGSCAN.EXE

PGMONITR.EXE

PFWADMIN.EXE

PF2.EXE

PERSWF.EXE

PERSFW.EXE

PERISCOPE.EXE

PENIS.EXE

PDSETUP.EXE

PCSCAN.EXE

PCIP10117_0.EXE

PCFWALLICON.EXE

PCDSETUP.EXE

PCCWIN98.EXE

PCCWIN97.EXE

PCCNTMON.EXE

PCCIOMON.EXE

PCC2K_76_1436.EXE

PCC2002S902.EXE

PAVW.EXE

PAVSCHED.EXE

PAVPROXY.EXE

PAVCL.EXE

PATCH.EXE

PANIXK.EXE

PADMIN.EXE

OUTPOSTPROINSTALL.EXE

OUTPOSTINSTALL.EXE

OTFIX.EXE

OSTRONET.EXE

OPTIMIZE.EXE

ONSRVR.EXE

OLLYDBG.EXE

NWTOOL16.EXE

NWSERVICE.EXE

NWINST4.EXE

NVC95.EXE

NVARCH16.EXE

NUI.EXE

NTXconfig.EXE

NTRTSCAN.EXE

NT.EXE

NSUPDATE.EXE

NSTASK32.EXE

NSSYS32.EXE

NSCHED32.EXE

NPSSVC.EXE

NPSCHECK.EXE

NPROTECT.EXE

NPFMESSENGER.EXE

NPF40_TW_98_NT_ME_2K.EXE

NOTSTART.EXE

NORTON_INTERNET_SECU_3.0_407.EXE

NORMIST.EXE

NOD32.EXE

NMAIN.EXE

NISUM.EXE

NISSERV.EXE

NETUTILS.EXE

NETSPYHUNTER-1.2.EXE

NETSCANPRO.EXE

NETMON.EXE

NETINFO.EXE

NETD32.EXE

NETARMOR.EXE

NEOWATCHLOG.EXE

NEOMONITOR.EXE

NDD32.EXE

NCINST4.EXE

NC2000.EXE

NAVWNT.EXE

NAVW32.EXE

NAVSTUB.EXE

NAVNT.EXE

NAVLU32.EXE

NAVENGNAVEX15.NAVLU32.EXE

NAVDX.EXE

NAVAPW32.EXE

NAVAPSVC.EXE

NAVAP.NAVAPSVC.EXE

AUTO-PROTECT.NAV80TRY.EXE

NAV.EXE

N32SCANW.EXE

MWATCH.EXE

MU0311AD.EXE

MSVXD.EXE

MSSYS.EXE

MSSMMC32.EXE

MSMSGRI32.EXE

MSMGT.EXE

MSLAUGH.EXE

MSINFO32.EXE

MSIEXEC16.EXE

MSDOS.EXE

MSDM.EXE

MSCONFIG.EXE

MSCMAN.EXE

MSCCN32.EXE

MSCACHE.EXE

MSBLAST.EXE

MSBB.EXE

MSAPP.EXE

MRFLUX.EXE

MPFTRAY.EXE

MPFSERVICE.EXE

MPFAGENT.EXE

MOSTAT.EXE

MOOLIVE.EXE

MONITOR.EXE

MMOD.EXE

MINILOG.EXE

MGUI.EXE

MGHTML.EXE

MGAVRTE.EXE

MGAVRTCL.EXE

MFWENG3.02D30.EXE

MFW2EN.EXE

MFIN32.EXE

MD.EXE

MCVSSHLD.EXE

MCVSRTE.EXE

MCTOOL.EXE

MCSHIELD.EXE

MCMNHDLR.EXE

MCAGENT.EXE

MAPISVC32.EXE

LUSPT.EXE

LUINIT.EXE

LUCOMSERVER.EXE

LUAU.EXE

LSETUP.EXE

LORDPE.EXE

LOOKOUT.EXE

LOCKDOWN2000.EXE

LOCKDOWN.EXE

LOCALNET.EXE

LOADER.EXE

LNETINFO.EXE

LDSCAN.EXE

LDPROMENU.EXE

LDPRO.EXE

LDNETMON.EXE

LAUNCHER.EXE

KILLPROCESSSETUP161.EXE

KERNEL32.EXE

KERIO-WRP-421-EN-WIN.EXE

KERIO-WRL-421-EN-WIN.EXE

KERIO-PF-213-EN-WIN.EXE

KEENVALUE.EXE

KAVPF.EXE

KAVPERS40ENG.EXE

KAVLITE40ENG.EXE

JEDI.EXE

JDBGMRG.EXE

JAMMER.EXE

ISTSVC.EXE

ISRV95.EXE

ISASS.EXE

IRIS.EXE

IPARMOR.EXE

IOMON98.EXE

INTREN.EXE

INTDEL.EXE

INIT.EXE

INFWIN.EXE

INFUS.EXE

INETLNFO.EXE

IFW2000.EXE

IFACE.EXE

IEDRIVER.EXE

IEDLL.EXE

IDLE.EXE

ICSUPPNT.EXE

ICMON.EXE

ICLOADNT.EXE

ICLOAD95.EXE

IBMAVSP.EXE

IBMASN.EXE

IAMSTATS.EXE

IAMSERV.EXE

IAMAPP.EXE

HXIUL.EXE

HXDL.EXE

HWPE.EXE

HTPATCH.EXE

HTLOG.EXE

HOTPATCH.EXE

HOTACTIO.EXE

HBSRV.EXE

HBINST.EXE

HACKTRACERSETUP.EXE

GUARDDOG.EXE

GUARD.EXE

GMT.EXE

GENERICS.EXE

GBPOLL.EXE

GBMENU.EXE

GATOR.EXE

FSMB32.EXE

FSMA32.EXE

FSM32.EXE

FSGK32.EXE

FSAV95.EXE

FSAV530WTBYB.EXE

FSAV530STBYB.EXE

FSAV32.EXE

FSAV.EXE

FSAA.EXE

FRW.EXE

FPROT.EXE

FP-WIN_TRIAL.EXE

FP-WIN.EXE

FNRB32.EXE

FLOWPROTECTOR.EXE

FIREWALL.EXE

FINDVIRU.EXE

FIH32.EXE

FCH32.EXE

FAST.EXE

FAMEH32.EXE

F-STOPW.EXE

F-PROT95.EXE

F-PROT.EXE

F-AGNT95.EXE

EXPLORE.EXE

EXPERT.EXE

EXE.AVXW.EXE

EXANTIVIRUS-CNET.EXE

EVPN.EXE

ETRUSTCIPE.EXE

ETHEREAL.EXE

ESPWATCH.EXE

ESCANV95.EXE

ESCANHNT.EXE

ESCANH95.EXE

ESAFE.EXE

ENT.EXE

EMSW.EXE

EFPEADM.EXE

ECENGINE.EXE

DVP95_0.EXE

DVP95.EXE

DSSAGENT.EXE

DRWEB32.EXE

DRWATSON.EXE

DPPS2.EXE

DPFSETUP.EXE

DPF.EXE

DOORS.EXE

DLLREG.EXE

DLLCACHE.EXE

DEPUTY.EXE

DEFWATCH.EXE

DEFSCANGUI.EXE

DEFALERT.EXE

DCOMX.EXE

DATEMANAGER.EXE

Claw95.EXE

CWNTDWMO.EXE

CWNB181.EXE

CV.EXE

CTRL.EXE

CPFNT206.EXE

CPF9X206.EXE

CPD.EXE

CONNECTIONMONITOR.EXE

CMON016.EXE

CMGRDIAN.EXE

CMESYS.EXE

CMD32.EXE

CLICK.EXE

CLEANPC.EXE

CLEANER3.EXE

CLEANER.EXE

CLEAN.EXE

CLAW95CF.EXE

CFINET32.EXE

CFINET.EXE

CFIADMIN.EXE

CFGWIZ.EXE

CFD.EXE

CDP.EXE

CCPXYSVC.EXE

CCEVTMGR.EXE

CCAPP.EXE

BVT.EXE

BUNDLE.EXE

BS120.EXE

BRASIL.EXE

BPC.EXE

BORG2.EXE

BOOTWARN.EXE

BOOTCONF.EXE

BLSS.EXE

BLACKICE.EXE

BLACKD.EXE

BISP.EXE

BIPCPEVALSETUP.EXE

BIPCP.EXE

BIDSERVER.EXE

BIDEF.EXE

BELT.EXE

BD_PROFESSIONAL.EXE

BARGAINS.EXE

BACKWEB.EXE

AVXMONITORNT.EXE

AVXMONITOR9X.EXE

AVWUPSRV.EXE

AVWUPD.EXE

AVWINNT.EXE

AVWIN95.EXE

AVSYNMGR.EXE

AVSCHED32.EXE

AVPTC32.EXE

AVPM.EXE

AVPDOS32.EXE

AVPCC.EXE

AVP32.EXE

AVP.EXE

AVNT.EXE

AVLTMAIN.EXE

AVKWCTl9.EXE

AVKSERVICE.EXE

AVKSERV.EXE

AVKPOP.EXE

AVGW.EXE

AVGUARD.EXE

AVGSERV9.EXE

AVGSERV.EXE

AVGNT.EXE

AVGCTRL.EXE

AVGCC32.EXE

AVE32.EXE

AVCONSOL.EXE

AU.EXE

ATWATCH.EXE

ATRO55EN.EXE

ATGUARD.EXE

ATCON.EXE

ARR.EXE

APVXDWIN.EXE

APLICA32.EXE

APIMONITOR.EXE

ANTS.EXE

ANTIVIRUS.EXE

ANTI-TROJAN.EXE

AMON9X.EXE

ALOGSERV.EXE

ALEVIR.EXE

ALERTSVC.EXE

AGENTW.EXE

AGENTSVR.EXE

ADVXDWIN.EXE

ADAWARE.EXE

ACKWIN32.EXE

BEAGLE.EXE

d3dupdate.exe

sysxp.exe

winxp.exe

ssgrate.exe

jammer2nd.exe

fvprotect.exe

hxdef.exe

VisualGuard.exe

GfxAcc.exe

RAVMOND.exe

Systra.exe

MCUPDATE.EXE

CFIAUDIT.EXE

AVXQUAR.EXE

AUTOUPDATE.EXE

AUTOTRACE.EXE

AUTODOWN.EXE

AUPDATE.EXE

NUPGRADE.EXE

UPDATE.EXE

ICSUPP95.EXE

ICSSUPPNT.EXE

DRWEBUPW.EXE

LUALL.EXE

AVPUPD.EXE

AVWUPD32.EXE

ATUPDATER.EXE

wuamga.exe

taskmanagr.exe

wuamgrd.exe

wowpos32.exe

dailin.exe

rasmngr.exe

msssss.exe

backdoor.rbot.gen_(17).exe

backdoor.rbot.gen.exe

RB.EXE

IAOIN.EXE

OUTPOST.EXE

8、用自带的SMTP引擎发送带毒邮件

该邮件具有如下特征:

名称组合FirstName:

Bowers

Carson

FigueroaLloyd

Massey

Huff

Norton

Patrick

Sparks

Abbott

Morton

Park

Wong

Drake

Marsh

Bass

Owen

Logan

Frank

Poole

Holloway

Mccormick

Brady

Pittman

Copeland

Moran

Buchanan

French

Zimmerman

Mclaughlin

Parsons

Briggs

Pratt

Klein

Christensen

Houston

Mcbride

Schwartz

Ballard

Nunez

Waters

Simon

Padilla

Greer

Alvarado

Gill

Colon

Wise

Saunders

Doyle

Stokes

Fitzgerald

Gross

Tyler

Gibbs

Sandoval

Estrada

Lindsey

Guerrero

Mccarthy

Paul

Osborne

Schneider

Wolfe

Ramsey

Lyons

Walsh

Weber

Chandler

Keller

Ball

Munoz

Page

Guzman

Barker

Schultz

Powers

Curry

Steele

Love

Hardy

Norris

Santiago

Dawson

Parks

Vaughn

Bush

Mendez

Mcdaniel

Haynes

Newman

Beck

Pena

Rhodes

Hale

Bates

Watts

Fletcher

Lambert

Holt

Chambers

Rodriquez

Miles

Lucas

Mckinney

Gregory

Sutton

Castro

Obrien

Barrett

Shelton

Horton

Jimenez

Graves

Barnett

Jennings

Lowe

Caldwell

Neal

Walters

Soto

Wade

Herrera

May

Hopkins

Davidson

Byrd

Vargas

Jensen

Fleming

Douglas

Holland

Pearson

Silva

Carlson

Hoffman

Brewer

Fowler

Medina

Bowman

Moreno

Mendoza

Day

Hanson

Burke

Frazier

Larson

Welch

Romero

Garrett

Gilbert

Dean

Lynch

Fuller

Kim

Reid

Jacobs

George

Nguyen

Burton

Little

Harvey

Garza

Fernandez

Hansen

Morrison

Alvarez

Howell

Mccoy

Bishop

Meyer

Banks

Johnston

Williamson

Richards

Montgomery

Chapman

Wheeler

Castillo

Stone

Rose

Ferguson

Knight

Grant

Nichols

Mills

Palmer

Daniels

Black

Hunt

Robertson

Rice

Holmes

Shaw

Gordon

Burns

Reyes

Ramos

Dixon

Warren

Kennedy

Morales

Mason

Boyd

Henry

Crawford

Hicks

Hunter

Porter

Tucker

Stevens

Simpson

Webb

Wells

Freeman

Murray

Gomez

Ortiz

Mcdonald

Gibson

Harrison

Ellis

Fisher

Reynolds

Owens

West

Woods

Sullivan

Graham

Hamilton

Ford

Myers

Hayes

Diaz

Griffin

Alexander

Bryant

Gonzales

Foster

Simmons

Butler

Washington

Flores

Hughes

Patterson

Long

Powell

Perry

Jenkins

Coleman

Henderson

Barnes

Wood

Bennett

Price

Sanders

Brooks

Watson

James

Ramirez

Gray

Peterson

Torres

Cox

Richardson

Cooper

Rivera

Bailey

Murphy

Bell

Morgan

Cook

Rogers

Sanchez

Stewart

Collins

Edwards

Kurtis

Trenton

Carlo

Cleo

Harris

Lane

Marcelino

Charley

Merrill

Merlin

Cruz

Irwin

Kirby

Dick

Frederic

Silas

Johnathon

Delmar

Truman

Isidro

Galen

Weldon

Beau

Linwood

Art

Donny

Stefan

Hollis

Nestor

Barney

Carmelo

Colby

Sanford

Brock

Dudley

Mary

Issac

Bruno

Jarvis

Maxwell

Odell

Coy

Clement

Dante

Dion

Jayson

Romeo

Ward

Emery

Gavin

Davis

Denny

Cole

Donnell

Heriberto

Ulysses

Federico

Sebastian

Eddy

Quincy

Vince

Scot

Maynard

Nickolas

Ollie

Riley

Basil

Donovan

Hiram

Mauricio

Bernardo

Elvis

Jefferson

Reed

Bobbie

Vern

Noe

Rickie

Shelby

Alphonso

Rigoberto

Wiley

Carmen

Stacey

Gerry

Rodrigo

Derick

Gonzalo

Nolan

Williams

Elvin

Norbert

Scotty

Solomon

Anton

Esteban

Roscoe

Kermit

Xavier

Buddy

Gregorio

Ashley

Darwin

Elliot

Desmond

Harlan

Joaquin

Damien

Denis

Vance

Jarrod

Merle

Bradford

Dexter

Percy

Clay

Rolando

Lamar

Cornelius

Phil

Grady

Noah

Pat

Conrad

Ramiro

Elbert

Bert

Devin

Wilson

Sherman

Gregg

Lowell

Cedric

Rodolfo

Cameron

Ernesto

Carlton

Rex

Orlando

Alfonso

Lynn

Matt

Lyle

Shaun

Angelo

Hubert

Kenny

Doug

Gerard

Homer

Luke

Oliver

Trevor

Shannon

Otis

Donnie

Dana

Julius

Marshall

Andy

Virgil

Ross

Daryl

Willard

Clifton

Morris

Isaac

Julian

Byron

Sidney

Johnnie

Ivan

Dave

Alberto

Alfredo

Casey

Jaime

Bob

Ken

Wallace

Ian

Jordan

Everett

Jimmie

Felix

Armando

Dwight

Dwayne

Max

Hugh

Clayton

Guy

Nelson

Allan

Kurt

Kelly

Julio

Cody

Lance

Lonnie

Darren

Tyrone

Mathew

Ted

Clinton

Fernando

Javier

Barry

Randall

Troy

Ricky

Eddie

Don

Edwin

Joel

Ray

Frederick

Herbert

Jesus

Bradley

Francis

Kyle

Alfred

Melvin

Lee

Jacob

Chad

Jeff

Travis

Jeffery

Glenn

Vincent

Marvin

Allen

Norman

Curtis

Rodney

Manuel

Dale

Nathan

Leonard

Stanley

Mike

Luis

Tony

Bryan

Danny

Antonio

Jimmy

Earl

Johnny

Chris

Philip

Sean

Clarence

Shawn

Alan

Craig

Jesse

Todd

Phillip

Ernest

Martin

Victor

Bobby

Russell

Carlos

Eugene

Howard

Randy

Aaron

Jeremy

Louis

Steve

Billy

Wayne

Fred

Harry

Adam

Brandon

Bruce

Benjamin

Roy

Nicholas

Lawrence

Ralph

Willie

Samuel

Keith

Gerald

Terry

Justin

Jonathan

Albert

Jack

Juan

Joe

Roger

RyanLeon

名称组合LastName:

Porter

Tucker

Stevens

Simpson

Webb

Wells

Freeman

Murray

Gomez

Ortiz

Marshall

Cruz

Parker

Campbell

Phillips

Turner

Roberts

Perez

Mitchell

Carter

Nelson

Gonzalez

Baker

Adams

Green

Hill

Lopez

Wright

King

Hernandez

Young

Allen

Hall

Walker

Lee

Lewis

Rodriguez

Clark

Robinson

Martinez

Garcia

Thompson

Martin

Harris

White

Jackson

Anderson

Taylor

Moore

Wilson

Miller

Davis

Brown

Jones

Williams

Johnson

Smith

域名组合:

@ziplink.net

@yahoo.com

@wwc.com

@worldshare.net

@worldcom.com

@wanadoo.com

@verizon.net

@ultimanet.com

@toad.net

@tiscali.com

@t-online.de

@t-online.com

@surfree.com

@ricochet.com

@rcn.com

@pics.com

@peoplepc.com

@pathlink.com

@palm.net

@pacific.net.sg

@netzero.net

@netrox.net

@netcenter.com

@nccw.net

@msn.com

@madriver.com

@macconnect.com

@loa.com

@juno.com

@istep.com

@ispwest.com

@isp.com

@iquest.net

@infoave.net

@inext.fr

@ieway.com

@hiwaay.net

@highstream.net

@globetrotter.net

@globalbiz.net

@gbronline.com

@flex.com

@fcc.net

@fast.net

@excite.com

@ev1.net

@eisa.com

@eclipse.net

@earthlink.net

@dialupnet.com

@cybernex.net

@cox.net

@core.com

@compuserve.com

@chello.com

@ccpc.net

@ccp.com

@cayuse.net

@canada.com

@cais.com

@cableone.net

@att.net

@aristotle.net

@arczip.com

@apci.net

@aol.com

@ameralinx.net

@address.com

@accessus.net

@a1isp.net

@1access.net

@yahoo.co.uk

@gmx.net

@hotmail.com

@mail.com

@dailymail.co.uk

主题:

do you know this girl?

do you know this people?

do you know this ppl?

Is it your photo?

LOOK!

my new photos

with best wishes

a lot of fun.

Hello...Funny pic...hehehe

I've never seen this before. Look at that !

Look :)

Hello!

You've got a postcard. To view this postcard, click on the attached file

have you seen this before?

Loool!! :-)

fun

fun pictures

hi!

look at new photos

Re[2]:fun pictures

Re:fun pictures

FW:fun pictures

Re[2]:COOL!

Re:COOL!

FW:COOL!

Re[2]:cool

Re:cool

FW:cool

Re[2]:

Re:

FW:

:))

FW: Cool

LOOK!

new photos

2 new photos

hi, it's me

it's me

(no subject)

that's me :-D

my photos

hello sweety :>

remember me?..

FW: jenna's photos :)

FW: new photos

FW: 2 new photos

FW: hi, it's me

FW: it's me

FW: (no subject)

FW: that's me :-D

FW: my photos

FW: hello sweety :>

FW: hi

FW: remember me?..


正文:

正文由下面ABC三部分组成

A.(随机选取一条)

-----Original Message-----

From: Jeny K.

Sent: Monday, September 13, 2004 8:57 PM

To: Morpheus

check my new photos

:))

miss you, jeny k

-----Original Message-----

From: Jena K.

Sent: Monday, September 13, 2004 5:23 AM

To: friends

Check Out Archive.. So.. What Do You Think... Am I Hot? :)

Waining For Your Answer

Jena Key

-----Original Message-----

From: jenny k.

Sent: Monday, September 13, 2004 10:23 AM

To: My Tiger (e-mail)

new fotos(archived) you asked

jenny k

-----Original Message-----

From: jenna k. (e-mail)

Sent: Monday, September 13, 2004 11:38 AM

To: Cat

my new fotos archived ))

kiss, jenna k

-----Original Message-----

From: Jeny

Sent: Monday, September 13, 2004 8:57 PM

To: Neo

see the photos in attached archive

:))

kiss you, jeny

-----Original Message-----

From: Jena

Sent: Monday, September 13, 2004 5:23 AM

To: friend

Photos in archive.. So.. Am I Hot? :)

Waining For Your Answer

Jena

-----Original Message-----

From: Jenna Knukles

Sent: Monday, September 13, 2004 9:05 AM

To: Friends Group

in self-extracting archive my photos

Jenna :)

-----Original Message-----

From: jenna (e-mail)

Sent: Monday, September 13, 2004 11:38 AM

To: ma kittie

my photos archived ))

kiss, jenna

fun flash game!

fun flash!

game!

fun game!

Print money at home!

look at atach

-----Original Message-----

From: Jeny K.

Sent: Monday, September 13, 2004 8:57 PM

To: Morpheus

check out the new photos

:))

miss you, jeny k

-----Original Message-----

From: Jena K.

Sent: Monday, September 13, 2004 5:23 AM

To: friends

So.. What Do You Think... Am I Hot? :)

Waining For Your Answer

Jena Key

-----Original Message-----

From: Jenna Knukles

Sent: Monday, September 13, 2004 9:05 AM

in archive my new fotos

Jenna K :)

-----Original Message-----

From: jenny k.

Sent: Monday, September 13, 2004 10:23 AM

To: My Tiger (e-mail)

new fotos you asked

jenny k

-----Original Message-----

From: jenna k. (e-mail)

Sent: Monday, September 13, 2004 11:38 AM

To: Cat

my new fotos zipped ))

kiss, jenna k

-----Original Message-----

From: Jeny

Sent: Monday, September 13, 2004 8:57 PM

To: Neo

see the photos

:))

kiss you, jeny

-----Original Message-----

From: Jena

Sent: Monday, September 13, 2004 5:23 AM

To: friend

So.. Am I Hot? :)

Waining For Your Answer

Jena

-----Original Message-----

From: Jenna Knukles

Sent: Monday, September 13, 2004 9:05 AM

To: Friends Group

in archive my photos

Jenna :)

-----Original Message-----

From: jenny

Sent: Monday, September 13, 2004 10:23 AM

To: Mr.X (e-mail)

photos you asked

jenny

-----Original Message-----

From: jenna (e-mail)

Sent: Monday, September 13, 2004 11:38 AM

To: ma kittie

my photos zipped ))

kiss, jenna

-----Original Message-----

From: Jeny K.

Sent: Tuesday, September 7, 2004 8:57 PM

To: Morpheus

check my new photos

:))

miss you, jeny k

B.

+++ Attachment: No Virus found

+++ [avprod

C.(随机选取一条)

Norton AntiVirus - www.symantec.de

F-Secure AntiVirus - www.f-secure.com

Norman AntiVirus - www.norman.com

Panda AntiVirus - www.pandasoftware.com

Kaspersky AntiVirus - www.kaspersky.com

MC-Afee AntiVirus - www.mcafee.com

Bitdefender AntiVirus - www.bitdefender.com

MessageLabs AntiVirus - www.messagelabs.com

附件:(随机)

myfoto.exe、photos.selfextracting.exe 、photoarchive.exe 、photofile.exe 、arc.exe

my_foto.exe 、fotos.exe 、foto.exe 、photos.exe.safe 、photo_se.exe

new_photos.exe 、newphotos.exe 、myphotos_arc.exe 、my_photos.exe 、photos_arc.exe

myfoto.cpl 、photoarchive.cpl 、photofile.cpl 、arc.cpl 、my_foto.cpl 、fotos.cpl

foto.cpl 、photo_se.cpl 、new_photos.cpl 、newphotos.cpl 、my_photos.cpl

photos_arc.cpl 、arhive.zip 、new_pic.zip 、pic.zip

new_photos.zip 、images.zip 、fotos.zip 、my_photos.zip

myphotos.zip 、photos.zip 、my_photo.jpg .pif 、flowers.jpg .pif 、document.jpg .pif

pic.jpg .pif 、photo.jpg .pif

black.gif .pif 、DCP_0002.JPG .pif 、me_01.jpg .pif 、2004042301.jpg .pif

with_flowers.jpg .pif 、sunny.jpg .pif 、photo08.jpg .pif 、nude_.jpg .pif

marie_dancing.jpg .pif 、julia038.jpg .pif 、dap53 crack.exe 、iMeshV4 crack.exe

icqpro2003b crack.exe 、wrar330 crack.exe 、WinZip 9.0 crack.exe

dap71.exe 、trillian-v2.74h.exe 、wrar330.exe 、LimeWireWin.exe

Morpheus.exe 、zlsSetup_45_538_001.exe 、icqpro2003b.exe 、iMeshV4.exe

WinZip 9.0.exe 、icqlite.exe 、kmd.exe 、trillian 2.0 crack.exe

dap53.exe 、dvdplayer.exe 、opera7.x crack.exe

crazzygirls.scr 、childporno.pif 、opera7.7.exe 、winamp6.exe

eroticgirls2.0.exe 、tropicallagoonss.scr 、nicegirlsshowv12.scr

icq2004-final.exe 、winamp5.exe 、1.exe 、mymusic.pif 、rulezzz.scr

matrix.scr 、newvirus.exe 、mylove.pif 、antibush.scr 、icqcrack.exe

myfack.pif 、hello.pif 、pinguin5.exe 、you the best.scr 、fantasy.scr

coolgame.zip .exe 、mynewphoto.zip .exe 、mult.exe

以上为带毒邮件的特征

但该病毒不会发送邮件到包含以下字符串的邮箱中:

gold-certs 、feste 、submit

help 、service 、privacy 、somebody 、contact

site 、someone 、anyone 、nothing 、nobody 、noreply

noone 、ebmaster 、news 、rating 、postmaster

samples 、info 、root 、www 、upport

abuse 、accoun 、certific 、listserv 、bsd

ntivi 、admin 、icq.com 、mozilla 、utgers.ed

tanford.e 、pgp 、acketst 、secur

isc.o 、isi.e 、ripe. 、arin. 、sendmail 、rfc-ed 、ietf

usenet 、fido 、kernel 、google 、ibm.com

fsf. 、gnu 、mit.e 、math 、berkeley

support 、messagelabs 、antivi 、kasp 、linux

unix 、spam 、@iana 、@foo. 、.mil

gov. 、.gov 、icrosoft 、ruslis 、nodomai

mydomai 、example 、inpris 、borlan

sopho 、panda 、icrosof 、syman 、avp.


    • 评论
    • 分享微博
    • 分享邮件
    邮件订阅

    如果您非常迫切的想了解IT领域最新产品与技术信息,那么订阅至顶网技术邮件将是您的最佳途径之一。

    重磅专题
    往期文章
    最新文章