查看單個文章
舊 2004-02-20, 03:23 PM   #3 (permalink)
babayu
註冊會員
榮譽勳章
UID - 10509
在線等級: 級別:5 | 在線時長:50小時 | 升級還需:10小時級別:5 | 在線時長:50小時 | 升級還需:10小時級別:5 | 在線時長:50小時 | 升級還需:10小時級別:5 | 在線時長:50小時 | 升級還需:10小時級別:5 | 在線時長:50小時 | 升級還需:10小時
註冊日期: 2002-12-12
VIP期限: 2010-06
住址: 天堂
文章: 252
精華: 0
現金: 6621 金幣
資產: 11621 金幣
預設

這是最新的病毒 Copies itself as %Windir%\services.exe.
drives C through Z
Symantec Security Bulletin - Level 4 Virus W32.Netsk.B@mm

W32.Netsky.B@mm 對此病毒發出全球警告Level 4

W32.Netsky.B@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning the hard drives and mapped drives. This worm also searches drives C through Z for folder names containing "Share" or "Sharing," and then copies itself to those folders.

The Subject, Body, and email attachment vary.
說明與解毒 十分繁複 要手動改 自己看仔細了 無法自動 沒太子說的簡單 太子抱歉了
http://securityresponse.symantec.com...tsky.b@mm.html


When W32.Netsky@mm runs, it does the following:

Creates a mutex named "AdmSkynetJKIS003." This mutex allows only one instance of the worm to execute.


Displays the following dialog box:

The file could not be opened!


Copies itself as %Windir%\services.exe.


Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
babayu 目前離線  
送花文章: 0, 收花文章: 2 篇, 收花: 2 次
回覆時引用此帖