基本情况:
这是一个乱发邮件的网络蠕虫及后门特洛伊,它还可以通过打开本地局域网的共享区进行传播。该蠕虫是经过加密
并压缩的可执行文件。它利用网络聊天室及FTP协议进行更新,使蠕虫在当前状态下得到发展。病毒可能作为邮件的附件
被发送,邮件包含下面的信息:
From: support@avx.com
Subject: AVX update notification
Body:
"Hi, We would like to notify you about the newest software designed by SOFTWIN company. This program
constantly monitors the net for the newest viral treats and anti-virus databases. In the case some
new virus is in-the-wild, it will immediatelly ask you to download the newest version of AntiVirus
eXpert 2000 (AVX). It's small, it's efficent, it's secure and powerful. No special licence is needed,
it's freeware. We hope you enjoy AntiVirus eXpert and share it with your friends.
Best regards,
AVX developement team."
Attachment: SERVICES.EXE
执行该附件机器将被感染