PCの修理が必要ですか?
専門家に頼む
????Worm/Mydoom.L.2
????19/07/2004
??????
????????
?????
?????????
????????????
?????????????
????????78.756 ???
MD5???????a3026f698ac9b0c575f7ac39f1082e01
VDF???????6.26.00.35

 ???? ????
   • E???
   • P2P(??????)


??
   •  Symantec: W32.Mydoom.L@mm
   •  McAfee: W32/Mydoom.n@MM
   •  Kaspersky: Email-Worm.Win32.Mydoom.m
   •  TrendMicro: WORM_MYDOOM.L
   •  Sophos: W32/MyDoom-N
   •  Grisoft I-Worm/Mydoom.N
   •  VirusBuster: I-Worm.Mydoom.Q
   •  Eset Win32/Mydoom.Q
   •  Bitdefender: Win32.Mydoom.L@mm


????????/OS?
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


???
   • ????????????????????
   • ?????????
   • ????????

 ???? ??????????????????
   • %WINDIR%\lsass.exe



???????????????

– ???????????????????
   • %TEMPDIR%\%????????%.txt

 ????? ??????????????????????????????????????????

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
   • "Traybar" = "%WINDIR%\lsass.exe"

 E??? ???????????SMTP??????????????????????????????????????????????


???
?????????????????(spoof)?
???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????


??:
– ??????????????????????
 ????????????(WAB)????????????????


??
??????
   • say helo to my litl friend
   • click me baby, one more time
   • hello
   • hi
   • error
   • status
   • test
   • report
   • delivery failed
   • Message could not be delivered
   • Mail System Error - Returned Mail
   • Delivery reports about your e-mail
   • Returned mail: see transcript for details
   • Returned mail: Data format error

?????????????????????????


??
???????????????????

   • The original message was included as attachment

   • This Message was undeliverable due to the following reason:
     
     Your message was not delivered because the destination computer was
     not reachable within the allowed queue period. The amount of time
     a message is queued before it is returned depends on local configura-
     tion parameters.
     
     Most likely there is a network problem that prevented delivery, but
     it is also possible that the computer is turned off, or does not
     have a mail system running right now.
     
     Your message was not delivered within %?????% days:
     Host %?????IP ????% is not responding.
     
     The following recipients did not receive this message:
      %???????????%
     
     Please reply to postmaster@%????????%
     if you feel this message to be in error.

   • The original message was received at Tue, %?????% %?????%
     from %????????% [%?????IP ????% ]
     
     ----- The following addresses had permanent fatal errors -----
      %???????????%
     
     ----- Transcript of session follows -----
      while talking to %????????%.:
     >>> MAIL From: %???????????%
     <<< 501 %???????????%... Refused

   • The original message was received at Tue, %?????% %?????%
     from %????????% [%?????IP ????% ]
     
     ----- The following addresses had permanent fatal errors -----
      %???????????%


??????
??????????????????????????

–  ????????????????
   • readme
   • transcript
   • mail
   • letter
   • file
   • text
   • attachment
   • document
   • message

    ????????????????????
   • bat
   • cmd
   • com
   • exe
   • pif
   • scr
   • zip

??????????????????????

?????????????????????????????



???????????????


 ?? ????????
???????????????????????
   • doc
   • txt
   • htm
   • html


FROM???????????
????????????????????????
   • Postmaster
   • Mail Administrator
   • Automatic Email Delivery Software
   • Post Office
   • The Post Office
   • Bounced mail
   • Returned mail
   • MAILER-DAEMON
   • Mail Delivery Subsystem



???????????
??????????????????????????
   • .gov; .mil; abus; accoun; admi; anyone; arin.; avp; bar.; bug;
      contact; crosoft; domain; example; feste; foo.; gmail; gnu.;
      gold-certs; google; gov.; help; hotmail; info; labs; listserv; master;
      math; microsoft; msn.; nobody; noone; not; nothing; ntivi; ophos;
      page; panda; privacycertific; rarsoft; rating; ripe.; root; sample;
      sarc.; seclist; secur; service; sf.net; site; soft; someone;
      sourceforge; spam; spersk; spm; submit; suppor; syma; the.bat; update;
      uslis; winzip; you; your


MX???????????
???????IP???????????????????????????????
   • mx.
   • mail.
   • smtp.

 P2P P2P(??????)?????????????????????????????????????


   ??????????(substring)????????????????
   • incoming
   • ftproot
   • download
   • shar

   ?????????????????????
   • Kazaa Lite
   • Harry Potter
   • ICQ 4 Lite
   • WinRAR.v.3.2.and.key
   • Winamp 5.0 (en) Crack
   • Winamp 5.0 (en)

   ???????????????????????

 ?????? ???????????????????????????
   • IEFrame
   • ATH_Note
   • rctrl_renwnd32


 ????? ?????????????

%?????????????????%\%??????% TCP???? 1042 ??????????

 ??????? ???????:
?????????????MS Visual C++?????????

説明の挿入者 Irina Boldea の 2006年2月28日火曜日
説明の更新者 Robert Harja Iliescu の 2006年9月5日火曜日

戻る . . . .
https:// このウィンドウは暗号化されています。