有效载荷:
大量电子邮件发送: Attempts to reply to incoming email messages and to the email addresses that it finds in HTML files
危及安全设置: Allows unauthorized access to the infected computer
分发
电子邮件主题: Chosen from a predetermined list
附件名称: Chosen from a predetermined list with a .exe, .pif, or .scr file extension
附件大小: 107,008 bytes
端口: TCP 1092, 20168, 6000
共享驱动器: Copies across shared drives
6. 将其本身以下列文件名复制到所有的网络共享文件夹及其子文件夹:
Are you looking for Love.doc.exe
autoexec.bat
The world of lovers.txt.exe
How To Hack Websites.exe
Panda Titanium Crack.zip.exe
Mafia Trainer!!!.exe
100 free essays school.pif
AN-YOU-SUCK-IT.txt.pif
Sex_For_You_Life.JPG.pif
CloneCD + crack.exe
Age of empires 2 crack.exe
MoviezChannelsInstaler.exe
Star Wars II Movie Full Downloader.exe
Winrar + crack.exe
SIMS FullDownloader.zip.exe
MSN Password Hacker and Stealer.exe
主题:主题会是下列其中之一:
Reply to this!
Let's Laugh
Last Update
for you
Great
Help
Attached one Gift for u..
Hi Dear
See the attachement
邮件正文:邮件正文会是下列其中之一:
For further assistance, please contact!
Copy of your message, including all the headers is attached.
This is the last cumulative update.
Tiger Woods had two eagles Friday during his victory over Stephen Leaney. (AP Photo/Denis Poroy)
Send reply if you want to be official beta tester.
This message was created automatically by mail delivery software (Exim).
It's the long-awaited film version of the Broadway hit. Set in the roaring 20's, this is the story of Chicago chorus girl Roxie Hart (Zellweger), who shoots her unfaithful lover (West).
Adult content!!! Use with parental advisory.
Patrick Ewing will give Knick fans something to cheer about Friday night.
Send me your comments...
If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about,don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;
... ... more look to the attachment.
附件:The attachment, which is a copy of the worm, will be one of the following:
the hardcore game-.pif
Sex in Office.rm.scr
Deutsch BloodPatch!.exe
s3msong.MP3.pif
Me_nude.AVI.pif
How to Crack all gamez.exe
Macromedia Flash.scr
SETUP.EXE
Shakira.zip.exe
dreamweaver MX (crack).exe
StarWars2 - CloneAttack.rm.scr
Industry Giant II.exe
DSL Modem Uncapper.rar.exe
joke.pif
Britney spears nude.exe.txt.exe
I am For u.doc.exe
撤消蠕虫对注册表所做的更改
警告: Symantec 强烈建议在更改注册表之前先进行备份。 错误地更改注册表可能导致数据永久丢失或文件损坏。 应只修改指定的键。
a. 单击“开始”,然后单击“运行”。 将出现“运行”对话框。)
b. 键入
regedit
然后单击“确认”。(注册表编辑器打开。)
c. 浏览到注册键:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
d. 在右窗格中,删除下列值:
winhelp %system%\winhelp.exe
WinGate initialize %system%\WinGate.exe -remoteshell
Remote Procedure Call Locator rundll32.exe reg678.dll
Program in Windows %system%\iexplore.exe
e. 浏览到注册键:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
f. 在右窗格中,删除值:
run RAVMOND.EXE
g. 浏览到注册键:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
h. 在右窗格中,双击默认值。
i. 删除当前值,代之以适合你 Windows 版本的正确值。
注意:这个值可依 Windows 版本,并且在某些系统上依据安装路径不同而不同。 你需要到另外一台设置相同并工作正常的计算机察看后输入这个值。一般的情况是:
Windows 98: C:\Windows\Notepad.exe %
Windows NT and 2000: %SystemRoot%\system32\NOTEPAD.EXE %1