Need help? Ask the community or hire an expert.
Go to Avira Answers
病毒:Worm/Scano.E.2
发现日期:13/12/2012
类型:蠕虫
广泛传播:
病毒传播个案呈报:低程度
感染/传播能力:中等程度至高程度
破坏 / 损害程度:低程度至中程度
静态文件:
文件大小:18.580 字节
MD5 校检和:c4df0B69138dac777b1a907b16bc4f3b
VDF 版本:7.11.53.216 - 2012년 12월 13일 목요일
IVDF 版本:7.11.53.216 - 2012년 12월 13일 목요일

 况概描述 传播方法:
   • 电子邮件
   • 对等网络


别名:
   •  Symantec: W32.Areses.H@mm
   •  Mcafee: W32/Areses.i@MM
   •  TrendMicro: WORM_ARESES.I
   •  VirusBuster: I-Worm.Scano.I
   •  Eset: Win32/Scano.N
   •  Bitdefender: Win32.Scano.E@mm


平台/操作系统:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


副作用:
   • 下载文件
   • 使用自置的电子邮件引擎
   • 注册表修改

 文件 它将本身复制到以下位置:
   • %WINDIR%\csrss.exe



它会将其本身从存档中复制到以下位置:
   • %TEMPDIR%\Message.zip




它会尝试下载一些文件:

– 该位置如下所示:
   • http://207.46.250.119/g/**********
撰写本文时,此文件并未联机作深入调查。

– 该位置如下所示:
   • http://www.microsoft.com/g/**********
撰写本文时,此文件并未联机作深入调查。

– 该位置如下所示:
   • http://84.22.161.192/s/**********
撰写本文时,此文件并未联机作深入调查。

 注册表 会添加以下注册表项,以便在系统重新引导后运行进程:

– HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
   Image File Execution Options\explorer.exe
   • "Debugger"="%WINDIR%\csrss.exe"



会删除以下注册表项的注册值:

–  HKLM\SYSTEM\ControlSet002\Control\Session Manager\
   PendingFileRenameOperations
–  HKLM\SYSTEM\ControlSet002\Control\Session Manager\BootExecute

 电子邮件 它包含集成的 SMTP 引擎,用于发送电子邮件。 将与目标服务器建立直接连接。 下面说明了它的特征:


发件人:
发件地址是仿冒的。


收件人:
– 在系统上的特定文件中找到的电子邮件地址。
– 从 WAB (Windows 通讯簿) 搜集到的电子邮件地址


主题:
以下某项内容:
   • Hi, what's up?
   • He, where are you?
   • Hi, drop me a line!!!
   • Hi! Please write to me urgently!
   • Hi! I'm waiting you online today!
   • Will you be online today?
   • When you're gonna answer me?
   • Re: write to me!
   • Re: Call me!
   • Re: Where are you?
   • Re: When you're gonna answer me?
   • Hi!!! How's the mood?
   • Re: How's the mood?



正文:
电子邮件的正文如下所示:

   • Hi!!!!! You haven't been writing for a long time. I began to worry) Where have you been? You remember, you've asked a progy from me? I've finally found it, so here it is. Check it out if this is what you've been looking for... bye

   • Hi, what's up? Will you show up online today?
     Drop me a line in ICQ, ok? Btw, I'm sending you the docs you've been looking for, find them attached. Check them out, ok?

   • Hi!
     I'm coming to you tomorrow, ok? When you are going to be home?
     You remember, you've asked some docs. Please find them attached. Check and see what's inside. That's it. Bye, till tomorrow...

   • Hi!
     You disappeared again. If you come online, drop me a line, ok?
     Btw, I sent you those docs that you've been looking for. Check them out. Bye!

   • Hi, give me a call just when you got the message! I'm tired of waiting. Btw, I'm sending that program that you've been looking for. Check it out. Appears to be that one. Bye!

   • Hi, what's up? If you have time tomorrow, please come over. After midday. By the way, don't forget to check the enclosed documents. Bye. See you tomorrow.

   • Hi, I got a free day tomorrow, and I'm waiting for you. Please come after midday. By the way, I'm sending you the documents that you've been asking for. Read them out... Bye!

   • Hi, how are you? What are your plans today? If you have time, please come over, and don't forget to check the program attached. Bye!

   • Hi, what's you gonna do today? I'll come over tonight! By the way, don't give anyone this funny program I'm sending. Check it out. Bye!

   • Hi, I found that program you asked for. Find it attached. Bye.

   • Hi, I saw you around today, but you didn't noticed me ( If you're gonna be at home, give a call, ok? By the way, check this file I'm sending. A very interesting program...

   • What's up! You haven't been writing for a long time
     I got news. I've finally that program you needed
     I'm sending it out. Use it. Bye!

   • Hi, drop me a line today, ok? And see the program I'm sending. Bye!

   • Hi, drop me a line if you can. Btw, I have a new ICQ. Please don't forget to check the attached documents. Bye.

   • Hi! How are you? Drop me a line if you can. I found your documents and I'm emailing them to you. Bye.


附件:
附件的文件名是以下某个名称:
   • Message.zip
   • File.zip
   • Document.zip
   • README.zip
   • Passwords.zip
   • Readme.zip
   • Important.zip
   • New.zip
   • COOL.zip
   • Archive.zip
   • Fotos.zip
   • private.zip
   • confidential.zip
   • secret.zip
   • images.zip
   • your_documents.zip
   • backup.zip

该附件是包含恶意软件本身副本的存档。

 邮件 搜索地址:
它会在以下文件中搜索电子邮件地址:
   • .adb; .asp; .cfg; .cgi; .mra; .dbx; .dhtm; .eml; .htm; .html; .jsp;
      .mbx; .mdx; .mht; .mmf; .msg; .nch; .ods; .oft; .php; .pl; .sht;
      .shtm; .stm; .tbb; .txt; .uin; .wab; .wsh; .xls; .xml; .dhtml


避免地址:
它不会向包含以下某个字符串的地址发送电子邮件:
   • @microsoft; rating@; f-secur; news; update; .qmail; .gif; anyone@;
      bugs@; contract@; feste; gold-certs@; help@; info@; nobody@; noone@;
      0000; Mailer-Daemon@; @subscribe; kasp; admin; icrosoft; support;
      ntivi; unix; bsd; linux; listserv; certific; torvalds@; sopho; @foo;
      @iana; free-av; @messagelab; winzip; google; winrar; samples; spm111@;
      .00; abuse; panda; cafee; spam; pgp; @avp.; noreply; local; root@;
      postmaster@

 P2P 为了感染对等网络社区中的其他系统,会执行以下操作:  


   它会搜索包含以下某个子字符串的目录:
   • bear
   • donkey
   • download
   • ftp
   • htdocs
   • http
   • icq
   • kazaa
   • lime
   • morpheus
   • mule
   • shar
   • source
   • upload
   • pub

   如果成功,会创建以下文件:
   • Britney Spears Song text archive.doc; Britney Spears.jpg; Britney
      Spears.mp3; Clone DVD 6; Cloning.doc; Cracks & Warez Archiv; Dark
      Angels new; Dictionary English 2004 - France.doc; DivX 8.0 final; Doom
      3 release 2; E-Book Archive2.rtf; Eminem blowjob.jpg; Eminem full
      album.mp3; Eminem Poster.jpg; Eminem sex xxx.jpg; Eminem Sexy
      archive.doc; Eminem Spears porn.jpg; Eminem.mp3; Full album all.mp3;
      Gimp 1.8 Full with Key; Harry Potter 1-6 book.txt; Harry Potter 5.mpg;
      Harry Potter all e.book.doc; Harry Potter e book.doc; Harry Potter
      game; Harry Potter.doc; Harry Potter and the Sorcerer's Stone game;
      How to hack new.doc; Internet Explorer 9 setup; Kazaa Lite 4.0 new;
      Kazaa new; Keygen 4 all new; Learn Programming 2004.doc; Lightwave 9
      Update; Magix Video Deluxe 5 beta; Matrix 3 .mpg; Microsoft Office
      2003 Crack best; Microsoft WinXP Crack full; MS Service Pack 6; source
      code; Norton Antivirus 2005 beta; Opera 11 free; Partitionsmagic 10
      beta; Porno Screensaver britney; RFC compilation.doc; Ringtones.doc;
      Nostradamus.doc; World Trade Center last video.mpeg; anthrax.doc;
      Osama Bin Laden.jpg; Taliban; Osama bin Laden.mpg; Yellow Pages;
      Ringtones.mp3; Saddam Hussein.jpg; Screensaver2; Serials edition.txt;
      Smashing the stack full.rtf; Star Office 9; Teen Porn 15.jpg; The Sims
      4 beta; Ulead Keygen 2004; Visual Studio Net Crack all; Vista
      review.doc; WinAmp 13 full with sources; Windows Vista Sourcecode.doc;
      Windows 2003 crack; Windows XP crack; WinXP eBook newest.doc; XXX
      hardcore pics.jpg

   这些文件是恶意软件本身的副本。

 注入进程 –  它会将以下文件注入到进程中: %WINDIR%\csrss.exe

    以下所有进程:
   • services.exe
   • svchost.exe


 文件详细信息 运行时压缩程序:
为了提高检测难度以及减小文件,它已使用运行时压缩程序进行压缩。

설명 삽입자 Irina Boldea   2006년 8월 1일 화요일
설명 업데이트 Irina Boldea   2006년 8월 2일 수요일

뒤로 . . . .
https:// 이 창은 보안을 위해 암호화되었습니다.