Worm.Redesi.b
病毒别名:I-Worm.Redesi.b [AVP],I-Worm/Redesi.b [KV],Worm.Redesi.b[RS]
处理时间:
威胁级别:★★
中文名称:红丝带变种B
病毒类型:蠕虫
影响系统:Win9x / WinNT
病毒行为:
这是一个通过电子邮件传播的蠕虫病毒。该病毒发作的时候弹出一个“[病毒文件名] is not a valid Win32 application.”的虚假警告窗口并在C盘根目录下建立病毒的多个副本;病毒通过Outlook Express的地址薄收集邮件地址,并将病毒做为邮件附件发送到这些邮件接收者,诱骗用户打开附件,从而感染病毒。
1)建立病毒的多个副本(都是隐藏文件):
C:Common.exe
C:Rede.exe
C:Si.exe
C:UserConf.exe
C:disk.exe
2)取下面某一句话做为邮件的主题:
Kev Gives great orgasms to ladeez!! -- Kev
hell is coming for u, u will be sucked into a bottomless pit!!! -- Gaz
Scientists have found traces of the HIV virus in cows milk...here is the proof -- Will
Yay. I caught a fish -- Si
I don't want to write anything but Si is bullying me. -- Jim
I want to live in a wooden house -- Arwel
Michelle still owes me 10 ... shit ! -- Si
Why have I only got cheese and onion crisps ? I hate them !! -- Si
A new type of Lager / Weed variant...... sorted !
My dad not caring about my exam results -- by Michelle
3)邮件的正文:
heh. I tell ya this is nuts ! You gotta check it out !
4)取下面某一个名字做为邮件附件名:
Common.exe
Rede.exe
Si.exe
UserConf.exe
Disk.exe