在线情况
楼主
  • 头像
  • 虔诚的睡教徒
  • 级别
  • 门派
  • 财富3
  • 银两1300
  • 经验6636
  • 文章399
  • 注册2004-03-26
[分享]今日新病毒
蠕虫病毒,
Virus W32/Bagle.bd@MM
危害:email,系统,造成系统速度降低并继续发送给其他用户,危急度高。
专杀工具下载:
http://download.nai.com/products/mcafee-avert/stinger.exe
附Mcafee说明(from swzone)

News pubblicata da Eymerich il 29/10/2004 2747 letture

 
 Categoria: Sicurezza
   
 
Segnaliamo la velocissima diffusione e l'identificazione nell'arco di poche ore di più varianti del virus Bagle.


Bagle.bb [WINGO.EXE]


Bagle.bc [bawindo.exe]


Bagle.bd [WINGO.EXE]

Le caratteristiche sostanziali non differiscono dal suo antenato : arriva come allegato di posta elettronica e se eseguito disabilita i più diffusi antivirus e firewall.

When executed (as an EXE), the worm installs itself to the victim machine with the Windows system folder as WINGO.EXE. For example:

C:\WINNT\SYSTEM32\WINGO.EXE
If the worm is received as a CPL file, when this is executed it serves to drop and execute the worm. The CPL dropper copies itself as CJECTOR.EXE within the Windows directory, for example:

C:\WINNT\CJECTOR.EXE
The following Registry key is added to hook system startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\\

Run "wingo" = C:\WINNT\SYSTEM32\WINGO.EXE
The following Registry key is also added to store data (within a "TimeKey" key):

HKEY_CURRENT_USER\Software\Params
Additionally, the virus may make multiple copies of itself in the Windows system directory, appending the string "open" to the filename. For example:

C:\WINNT\SYSTEM32\WINGO.EXEOPEN
C:\WINNT\SYSTEM32\WINGO.EXEOPENOPEN
etc
A mutex is created to ensure only one instance of the worm is running at a time. One of the following mutex names is used in an attempt to stop particular variants of W32/Netsky running on the infected machine:

{z4wMuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
'D'r'o'p'p'e'd'S'k'y'N'e't'
_-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
[SkyNet.cz]SystemsMutex
AdmSkynetJklS003
____--->>>>U<<<<--____
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
Port 81 (TCP) is also opened on the victim machine.
外表有多规矩,内心就有多不羁
在线情况
2
  • 头像
  • 虔诚的睡教徒
  • 级别
  • 门派
  • 财富3
  • 银两1300
  • 经验6636
  • 文章399
  • 注册2004-03-26
不要轻易打开邮件中的附件(特别是exe、com、pif、bat、scr类型的文件)
建议将邮件中的附件先保存到硬盘上,然后再打开相应类型程序(如DOC文件的附件,就先打开word,然后再从“文件”->“打开”来将该文件打开)
外表有多规矩,内心就有多不羁
在线情况
3
  • 头像
  • 世家子弟
  • 级别
  • 门派
  • 财富1
  • 银两2559
  • 经验19272
  • 文章1209
  • 注册2004-08-10
推荐Symantec的企业版8.1,我觉着最好的杀毒软件。
我不签名,就是最忠心的回贴。
在线情况
4
  • 头像
  • 虔诚的睡教徒
  • 级别
  • 门派
  • 财富3
  • 银两1300
  • 经验6636
  • 文章399
  • 注册2004-03-26
从1年多前开始使用mcafee virusscan7.0企业版,功能强大,占资源小,且无升级烦忧(国产的大部分升级困难<主要因为大家用的是D版居多>,诺顿的产品升级也量较大,速度慢且占用资源太多)。
推荐使用最新版的mcafee virusscan8.0i企业版,可去google搜得下载链接
PS:使用D版软件造成的后果自负!(本人使用的是OEM版^_^)
外表有多规矩,内心就有多不羁
在线情况
5
  • 头像
  • 此人无任何头衔
  • 级别
    • 财富1
    • 银两46
    • 经验7764
    • 文章262
    • 注册2004-07-28
    麦咖啡确实不错!但网上下载的都是直接就可以用啊,装的时候自己随便选个授权时间就可以了,没说明有破解注册码什么的呀!
     
    God helps those who help themselves.

    Also

    Human effort is the decisive factor.
    在线情况
    6
    • 头像
    • =ACE=
    • 级别
    • 门派
    • 财富2
    • 银两102
    • 经验22234
    • 文章1072
    • 注册2004-06-24
    还好没中,这个软件网络搜索到的会不会是地板?
    [img]http://bbS.cga.com.cn/UploadFiles/86/2005-8-14/9271161/20058149274522925.jpg[/img]
    [SHADOW=255,GREEN,2][/SHADOW]
    在线情况
    7
    • 头像
    • 精灵
    • 级别
    • 门派
    • 职务总版主
    • 声望+6
    • 财富996
    • 银两295
    • 经验114963
    • 文章5489
    • 注册2004-03-27
    谢谢imnewer..你这个及时雨及时滴淹死了我电脑里一匹木马!...^-^/~`
                    苦難在何方綻放異彩..那裏必然有著一種天堂...

    [IMG]http://www.binok.com/BBS/images/upload/2007/12/30/003340.jpg[/IMG]
    Powered by LeadBBS 9.2 .
    Page created in 0.1699 seconds with 4 queries.