一花一世界's profile红尘网事BlogLists Tools Help

Blog


    让我们向这个病毒的编写者致以最高的敬礼

    近日,某公司全球反病毒监测网在国内率先截获一个“冲击波杀手”病毒的变种(W32.Welchia.B)
    病毒。据该反病毒工程师介绍,该病毒是“冲击波杀手”的变种,
    同时利用四个漏洞对WINDOWS 2000或者WINDOWS XP操作系统进行攻击。
    有趣的是,这个病毒只会攻击日文系统,对中、英文系统不光不进行恶意攻击,
    还会帮助这些用户下载微软的补丁程序修补系统漏洞,堪称是一个“爱国”病毒,或者是“仇日”病毒。
    病毒会判断*作系统语种,如果当前系统为日文,则从注册表Virtual Roots及IIS Help folders中读取路径,并尝试用病毒体内带的一个网页文件替换此路径下的文件。
    该文件显示了几个特殊日期,这些日期都是发动侵略战争的标志性日期,
    包括九一八事变纪念日、七七事变、南京大屠杀、珍珠港事变、两颗原子弹的爆炸日期和投降纪念日。
    因为很多小型网站都是利用WINDOWS 2000操作系统和IIS架设,
    如果有人访问受病毒攻击的网站,则会看到这些文件,
    从病毒编写手法和内容来看,该病毒和当初的“冲击波杀手”病毒可能出自同一个人之手,
    而且极其可能是中国人。
    如果操作系统是中文、韩文或者是英文,
    此病毒会试图清除SCO炸弹和SCO炸弹变种病毒,消除病毒留下的后门,
    还会下载微软补丁来弥补系统漏洞。
    该病毒利用DCOM RPC、WebDav vulnerability、Workstation Service vulnerability和Locator service vulnerability四个已知漏洞传播
    ----------------------- ----------------------- -----------------------
    看来我们用中文操作系统的还可以下载这个病毒来维护一下系统,哈哈!

    Comments (2)

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.

    To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


    Don't have a Windows Live ID? Sign up

    tiny cyhwrote:
    小心封了你的网页!我有朋友的空间被封了!
    15 July
    养 王wrote:
    致敬
     
    2 July

    Trackbacks

    The trackback URL for this entry is:
    http://yucolor.spaces.live.com/blog/cns!859FB86EFC0C8BC5!466.trak
    Weblogs that reference this entry
    • None