天极传媒:
天极网
比特网
IT专家网
52PK游戏网
极客修
全国分站

北京上海广州深港南京福建沈阳成都杭州西安长春重庆大庆合肥惠州青岛郑州泰州厦门淄博天津无锡哈尔滨

产品
  • 网页
  • 产品
  • 图片
  • 报价
  • 下载
全高清投影机 净化器 4K电视曲面电视小家电滚筒洗衣机
您现在的位置: 天极网>新闻>

“我爱你”病毒横行 B-H变种详析

熊猫公司 2000-05-20 00:00 我要吐槽
苊ㄎ朗勘ǖ懒巳涑娌《尽拔野恪保? VBS/LoveLetter)的许多新变种。变种与原先病毒的差异包括名称、所带信息、链接的Web页面、感染的文档后缀及是否带有特洛伊木马。 (except VBS/LoveLetter.H携带特洛伊木马).

同时也使熊猫卫士提供的每日病毒更新的服务显得非常重要,熊猫卫士迄今为止,可以抵御所有“爱虫”病毒变种的侵害。用户可以在熊猫卫士国际网站下载最新的升级程序http://www.pandasoftware.com。在熊猫卫士中包含的创新方案有效抵御所有“我爱你”病毒(VBS/LoveLetter)的侵袭。

最新变种的名称及它们不同的特征包括:

“我爱你”B变种(VBS/LoveLetter.B)

不同点:

该电子邮件的主题为“Susitikim shi vakara kavos puodukui....


“我爱你”C变种(VBS/LoveLetter).C ,别称 “Very Funny” :

不同点:

该病毒发送的电子邮件主题为: “fwd: Joke” 但没有任何附属的文档
该电子邮件的附件是VERY FUNNY.VBS
- 当它通过IRC 通道发出时,该文件名称为VERY FUNNY.HTM

“我爱你“D变种, 别称“母亲日爱虫”

不同点:
- 该电子邮件的附件为MOTHERSDAY.vbs
- 当它通过IRC通道被发送时,被发送的文件为MOTHERSDAY.HTM
送出的电子邮件包含以下特征:

主题: “Mothers Day Order Confirmation” 内容: We have proceeded to charge your credit card for the amount of $326.92 for the mothers day diamond special. We have attached a detailed invoice to this 电子邮件. Please print out the attachment and keep it in a safe place.Thanks Again and Have a Happy Mothers Day! mothersday@subdimension.com

病毒试图链接的网址为:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, 主页为 http://www.hackers.com
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, 主页为 http://www.l0pht.com
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, 主页为 http://www.2600.com
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, 主页为 http://www.hackers.com

该病毒不试图在以上任何网址下载特洛伊。

该病毒不感染jpg 及 jpge 文档? 对 “ini” 或 “bat” 文档有效。

“我爱你”病毒E变种(VBS/LoveLetter).E

不同点:
- 该病毒源代码中包含解释

该病毒的新变种及其包含的特征如下:

“我爱你”F变种(VBS/LoveLetter.F)

区别:

1. 发送病毒的电子邮件包含以下特征:

主题: Dangerous Virus Warning

Text: There ia a dangerous virus circulating. Please click attached picture to view it and learn to avoid it

2. 该电子邮件的附件名称为VIRUS_WARNING.JPG.VBS. 当它通过IRC 发送出去时,被发送的文档被称为 URGENT_VIRUS_WARNING.HTM.

3. 该病毒试图将自身链接到以下URL地址:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, URL地址为:
http://www.skycable.tucows.com/files2/setup24.exe
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, URL 地址为:
http://www.skycable.tucows.com/files2/setup24.exe
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, URL 地址为:
http://www.skycable.tucows.com/files2/setup24.exe
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, URL 地址为:
http://www.skycable.tucows.com/files2/setup24.exe

该蠕虫不从以上地址试图下载任何特洛伊木马。

4. 该变种同时感染以下文档后缀:WAV, TXT, GIF, DOC, HTM, HTML ,XLS

“我爱你”G变种VBS/LoveLetter.G

差异:

该病毒发出的电子邮件包含以下特征:

From: support@symantec.com
主题: Virus ALERT!!!

内容: Symantecs AntiVirus Research Center began receiving reports regarding VBS.LoveLetter.A virus early morning on May 4, 2000 GMT. This worm appears to originate from the Asia Pacific region. Distribution of the virus is widespread and hundreds of thousands of machines are reported infected.
The VBS.LoveLetter.A is an Internet worm that uses Microsoft Outlook to e-mail itself as an attachment.
The 主题 line of the e-mail reads ILOVEYOU, with the attachment titled LOVE-LETTER-FOR-YOU.TXT.VBS. Once the attachment is opened, the virus replicates and sends an e-mail to all e-mail addresses listed in the address book. The virus also spreads itself via Internet relay chat and infects files on local and remote drives including files with extensions vbs, vbe, js, sje,css, wsh, sct, hta, jpg, jpeg, mp3, mp2.
Users should exercise caution when opening e-mails with this 主题 line, even if the e-mail is from someone they know, as that is how the virus is spread.
Symantec Corp. today announced availability of the virus definition to detect, repair and protect users against the VBS.LoveLetter.A virus. This definition is available now via Symantecs LiveUpdate and can also be downloaded from the following web sites:

http://www.symantecstore.com/AF74211/promo/loveletter
http://www.digitalriver.com/symantec
Also as a quick solution Symantec Corp. offers Visual Basic Script to protect your PC against this worm. (See attached.)
Note! When executed, this script will protect Your PC from being INFECTED by VBS.LoveLetter.A virus.
To cure already infected PCs download Norton Antivirus Updates mentioned above.
Symantec Corporation - a world leader in internet security technology.

2. 电子邮件附件为 PROTECT.VBS. 当它通过IRC传送时,该文件名称为 PROTECT.HTM

3. 它试图链接的Web 地址为:
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page, URL 地址为:
http://3doc.dailypussy.com/gallery/bunny.html
HKLM\Software\Microsoft\Internet Explorer\Main\Start Page, URL 地址为:
http://3doc.dailypussy.com/gallery/bunny.html
HKLM\Software\Microsoft\Internet Explorer\Main\Search Page, URL 地址为:
http://astalavista.box.sk
HKLM\Software\Microsoft\Internet Explorer\Main\Search Page, URL 地址为:
http://astalavista.box.sk
HKLM\Software\Microsoft\Internet Explorer\Main\Defaul_Page_URL, URL地址为: http://www.persiankitty.com
HKLM\Software\Microsoft\Internet Explorer\Main\Local Page, 赋值给给PROTECT.HTM, 并复制到Windows SYSTEM 文件夹。

该病毒不从以上地址下载任何特洛伊木马。

4. 该变种感染后缀为COM 及BAT的文件.

“我爱你”H变种( VBS/LoveLetter.H)

差异:该变种的程序起始部被清除了。

存在不断出现更多新变种的可能性
作者:不详责任编辑:)
请关注天极网天极新媒体 最酷科技资讯
扫码赢大奖
评论
* 网友发言均非本站立场,本站不在评论栏推荐任何网店、经销商,谨防上当受骗!
笔记本手机数码家电