¡¡¡¡ÖÐÐÂÍø1ÔÂ14ÈÕµç À´×Ô½Ãñ¿ìËÙ·´²¡¶¾Ð¡×éµÄ×îÐÂÏûÏ¢£¬Ò»ÖÖÃûΪ¡°ºÃ´ó¡±(I-Worm/Sobig)µÄÍøÂçÈä³æ²¡¶¾£¬±»ÂÊÏȳɹ¦½Ø»ñ¡£½Ãñ¹«Ë¾ÒÑÔÚµÚһʱ¼äÄóöÁËÕë¶Ô¸Ã²¡¶¾µÄ½â¾ö·½°¸£¬²¢¼°Ê±Éý¼¶¸üÐÂÁ˲¡¶¾¿â¡£¸Ã²¡¶¾¿É¸ÐȾµÄÓÐЧϵͳΪµ±Ç°Á÷ÐеÄËùÓÐwindows²Ù×÷ƽ̨£¬Ä¿Ç°¸Ã²¡¶¾Õýͨ¹ýÓʼþ½øÐдó¹æÄ£·¢ËÍ´«²¥¡£
¡¡¡¡·´²¡¶¾×¨¼Ò½éÉÜ£¬¸Ã²¡¶¾²ÉÓÃMSVC±àд£¬³¤¶ÈÊÇ65536×Ö½Ú,ÄÜͨ¹ýÓʼþºÍ¾ÖÓòÍøÀ´´«²¥£¬²¡¶¾´«²¥·¢Ë͵ÄÓʼþµØÖ·ÊÇͨ¹ý¶ÁÈ¡Ö¸¶¨µÄ¿ÉÄܺ¬ÓÐEMAILµØÖ·µÄÎļþÄÚÈÝÀ´»ñµÃµÄ£¬¿É¸ÐȾ¾ÖÓòÍøÀïµÄËùÓлúÆ÷£¬Ôì³É¾ÖÓòÍø̱»¾¡£´Ë²¡¶¾µÄÓʼþ·¢Ë͵ØַΪbig@boss.com£¬²¡¶¾ÓʼþµÄ½ÓÊÕÕߵĵØÖ·ÊÇ´ÓÒÔϵÄÎļþÖÐËÑË÷µ½µÄ£ºWAB¡¢DBX¡¢HTM¡¢HTML¡¢EML¡¢TXT ,¿ÉÒÔ˵¸²¸ÇÁËÄÜ´æÓÐEMAILµØÖ·µÄËùÓÐÎļþ¡£
¡¡¡¡ÓʼþµÄÖ÷ÌâÊÇËÄÑ¡Ò»:
¡¡¡¡Re: Movies (»Ø¸´:µçÓ°)Re: Sample (»Ø¸´:Ñù±¾)Re: Document (»Ø¸´:Îĵµ)Re: Here is that sample (»Ø¸´:ÕâÀïÊÇÒ»¸öÑù±¾)
¡¡¡¡ÓʼþµÄ¸½¼þÊÇpifÀ©Õ¹Ãû³ÆµÄ£¬´óС¶¼ÊÇ65536×Ö½Ú£¬¸½¼þµÄÎļþÃû³ÆÒ²ÊÇËÄÑ¡Ò»£ºMovie_0074.mpeg Document003 Untitled1 Sample
¡¡¡¡¸ÃÍøÂçÈä³æ¿ÉÒÔËÑË÷ËùÓеľÖÓòÍøµÄ¹²ÏíĿ¼£¬²¢½«×ÔÉí¿½±´µ½¹²ÏíĿ¼µÄÈçÏÂĿ¼£¬Ê¹µÃµ±¹²ÏíµÄ»úÆ÷ÖØÐÂÆô¶¯Ê±×Ô¶¯¸ÐȾ¡£¿½±´µÄ¹²Ïí»úÆ÷µÄĿ¼Ϊ£º\%WINDOWS%\ALL USERS\STARTMENU\PROGRAMS\STARTUP£¬XPµÈϵͳÏÂÊÇ£º\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP¡£
¡¡¡¡µçÄÔÔÚ¸ÐȾÉϴ˲¡¶¾ºó£¬ÔÚWINDOWSµÄĿ¼Ï´æÔÚ´óСΪ65536×ֽڵĿÉÖ´ÐÐÎļþWINMGM32.EXEÒÔ¼°Á½¸öDATÎļþsntmls.dat,dwn.dat.Á½¸ödatÎļþ¼Ç¼Á˸ò¡¶¾´«²¥¸ÐȾµÄһЩÐÅÏ¢¡£µ±¸ÃÍøÂçÈä³æ²¡¶¾±»Ö´Ðкó£¬ÔÚWINDOWSµÄĿ¼ÏÂÒÔÎļþwinmgm32.exeµÄÎļþ´æÔÚ£¬Í¬Ê±ÐÞ¸ÄϵͳµÄ×¢²á±íÏʹµÃϵͳÿ´ÎÆô¶¯Ê±£¬¸ÃÍøÂçÈä³æ¶¼±»×Ô¶¯ÔËÐС£Ð޸ĵÄϵͳע²á±í°üÀ¨£ºKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunÔö¼ÓµÄ¼üÖµÊÇ£º"WindowsMGM"£¬ÊýÖµÊÇ£º%WINDOWS%winmgm32.exe
¡¡¡¡½ÃñÌáÐÑÓû§£¬KV½Ãñɱ¶¾Íõ2003ÒѾȫÃæÉÏÊУ¬ÇëKVϵÁеÄÀÏÓû§¼°Ê±Éý¼¶µ½KV½Ãñɱ¶¾Íõ2003¡£¶ÔÓڸò¡¶¾Ö»Ð輰ʱÉý¼¶¸üÐÂKV½Ãñɱ¶¾Íõ2003²¡¶¾¿â£¬½«ÁùÌ×ʵʱ¼à¿ØϵͳÖеġ°Óʼþ¼àÊÓ¡¢Îļþ¼àÊÓºÍ×¢²á±í¼àÊÓ¡±ÈýÌ×·À·¶ÏµÍ³£¬¾Í¿É×èÖ¹¸Ã²¡¶¾µÄÈëÇÖ£¬Í¬Ê±KV½Ãñɱ¶¾Íõ2003µÄÄÚ´æ¼àÊÓ¹¦ÄÜ£¬¿ÉÒÔ´ÓÄÚ´æÖÐÇå³ý¸ÃÍøÂçÈä³æ¡£