|
Beagle.24
Beagle 駭蟲急起直追 多種駭蟲信件格式 使用者勿開啟信件內文中有 美女圖 的.vbs附加檔案 勿執行有 "櫻桃" 圖樣的.exe 檔案
Beagle 駭蟲目前又開始進行變種,來跟上Netsky 的變種數目。Beagle.24 駭蟲除了利用Mail大量發送駭蟲信件外,也會透過網路上點對點傳輸軟體進行傳送,它會搜尋系統中有"shar"字樣的目錄,若有,則將病毒本身複製到此目錄中,並命名為一些應用軟體的名稱,讓其他人可進行下載,若使用者下載到的檔案前面的圖樣為"紅櫻桃",而檔案大小為37-39 kb都要小心,勿直接開啟執行。
Beagle.24 駭蟲的駭蟲信件格式多樣,有以.exe, .com, .scr, .cpl或是加密的.zip檔案出現外,也有另一種格式,信件內文中可以見到一美女圖示,而其夾帶為 .vbs 附加檔案。
使用者見到此類似信件勿直接開啟附加檔案。
基本介紹
| 病毒名稱 |
Beagle.24 |
| 病毒別名 |
W32/Bagle.z@MM ,WORM_BAGLE.X |
| 病毒型態 |
Worm , E-Mail , P2P |
| 病毒發現日期 |
2004/04/27 |
| 病毒檔大小 |
37-39kb |
| 影響平台 |
Windows 95/98/ME , Windows 2000/NT/XP/2003 |
風險評估
Beagle.24信件格式:
發信者: < 隨機 >
主旨: < 下列任一個 > %s代表使用者名稱
Hello! Hey! Let's socialize, my friend! Let's talk, my friend! I'm bored with this life Notify from a known person ;-) I like you I just need a friend I'm a sad girl... Re: Msg reply Re: Hello Re: Yahoo! Re: Thank you! Re: Thanks :) RE: Text message Re: Document Incoming message Re: Incoming Message Re: Incoming Fax Hidden message Fax Message Received Protected message RE: Protected message Forum notify Request response Site changes Re: Hi Encrypted document Hello %s, Dear %s, Dear %s, It's me ;-) Hi %s, Hey %s, It's me -> Hi, It's me %s, Hey %s, Hey, Hello, Hi, I Like You! Don't you remember me? Kewl :-) I need a friend... I just want to talk with someone... I like reading the books and socializing, let me talk with you... It's time to find a friend! Ready to accept a new friend? :-) Like me, odore me! ;-)
內文: < 下列任一個 > .I study at school, I like to spend time cheerfully even if not all so well, I hompe and trust, that all bad when nibud will pass and necessarily nastanet there would be a desire. .I like to feel protected, to understand, that near to me the man, which both in sex, and in life knows what to do. It is possible to fall in love with such the man for ever. Cometime I write a poem, play the gitar. I love a traveling, I like a romantice and I want to meet, comeday, my big love! .I am kind, fair, careful, gentle also want to create family. I love animal (cats, dogs), the literature, theatre, cinema, music, walks in park .I very much love productive leisure, to prepare for new exotic dishes, at leisure to leave with friends on the nature, to float, I like to go for a drive on mountain skiing, to visit excursions, travel. Very easy going. .I have recently got demobilize from army and also I am going to act in a higher educational institution Searching for the right person,for real man, who will really cares and love me. .I am a honest, kind,loving,with good sense of humor...etc.,looking for true love... or maybe for pen friend.I like cats .I am looking for a serious relationship. I am NOT interested in flirt and short-term love adventure. .I love, as the good company, and I dream about romantic appointment at candles with loved. I still believe in love. .I like an active life... and interesting people.. .i am honest, responsible, romantic person. iwould like to find my only love,to find my destiny. .I'm a young lady of 20 years old i'd like to find my second part!!! .I am simple girl who are looking for serious relation with responsible and confident man. I am ready to give all my love and carering for a right person who is going to love and respect me .I am a beautiful, sexual girl with very big ambitions and dreams. I can make happy anyone man... .I am a student. I'm studying international relationships. I would .like to find an interesting and active man for serious relations. Sitting at home it is not for me. I like to go out to the theater, cinema, and nightclubs. .I love productive leisure, to travel, communicate with friends. .I very much love new acquaintances, I love music, meetings with friends. I go on night clubs, except for parties I sometimes visit theatres and I love cinema. In general I only shall be glad to new acquaintance and class dialogue... .I'm so bored, let me talk with you... .You are my prince :-) .You are cool :-)
附加檔案: < 下列任一個 > 附檔名可能為 .exe .com .scr .cpl .vbs 或是加密的.zip檔案
檔案名稱: Information Details Readme Document Info Details MoreInfo Message
Beagle.24 行為描述:
駭蟲執行後,會產生一訊息視窗,如圖

透過自己的SMTP大量發送病毒信件。
透病毒執行後,將駭蟲本身複製到%System%
drvsys.exe
病毒執行後,在%System%產生
drvsys.exeopen
drvsys.exeopenopen
若執行信件附加檔案為.vbs格式者,在%System%產生
bbbs.exe
修改登錄檔,如此開機即會啟動駭蟲。
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
名稱=drvsys.exe 值="%System%\drvsys.exe
關掉系統中安全防護軟體的常駐程式,使其失去防護功效,關閉的處理程序如下:
NMAIN.EXE NORTON_INTERNET_SECU_3.0_407.EXE NPF40_TW_98_NT_ME_2K.EXE NPFMESSENGER.EXE NPROTECT.EXE NSCHED32.EXE NTVDM.EXE NVARCH16.EXE KERIO-WRP-421-EN-WIN.EXE KILLPROCESSSETUP161.EXE LDPRO.EXE LOCALNET.EXE LOCKDOWN.EXE LOCKDOWN2000.EXE LSETUP.EXE CLEANPC.EXE AVprotect9x.exe CMGRDIAN.EXE CMON016.EXE CPF9X206.EXE CPFNT206.EXE CV.EXE CWNB181.EXE CWNTDWMO.EXE ICSSUPPNT.EXE DEFWATCH.EXE DEPUTY.EXE DPF.EXE DPFSETUP.EXE DRWATSON.EXE ENT.EXE ESCANH95.EXE AVXQUAR.EXE ESCANHNT.EXE ESCANV95.EXE AVPUPD.EXE EXANTIVIRUS-CNET.EXE FAST.EXE FIREWALL.EXE FLOWPROTECTOR.EXE FP-WIN_TRIAL.EXE FRW.EXE FSAV.EXE AUTODOWN.EXE FSAV530STBYB.EXE FSAV530WTBYB.EXE FSAV95.EXE GBMENU.EXE GBPOLL.EXE GUARD.EXE GUARDDOG.EXE HACKTRACERSETUP.EXE HTLOG.EXE HWPE.EXE IAMAPP.EXE IAMAPP.EXE IAMSERV.EXE ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSUPP95.EXE ICSUPPNT.EXE IFW2000.EXE IPARMOR.EXE IRIS.EXE JAMMER.EXE ATUPDATER.EXE AUPDATE.EXE KAVLITE40ENG.EXE KAVPERS40ENG.EXE KERIO-PF-213-EN-WIN.EXE KERIO-WRL-421-EN-WIN.EXE BORG2.EXE BS120.EXE CDP.EXE CFGWIZ.EXE CFIADMIN.EXE CFIAUDIT.EXE AUTOUPDATE.EXE CFINET.EXE NAVAPW32.EXE NAVDX.EXE NAVSTUB.EXE NAVW32.EXE NC2000.EXE NCINST4.EXE AUTOTRACE.EXE NDD32.EXE NEOMONITOR.EXE NETARMOR.EXE NETINFO.EXE NETMON.EXE NETSCANPRO.EXE NETSPYHUNTER-1.2.EXE NETSTAT.EXE NISSERV.EXE NISUM.EXE CFIAUDIT.EXE LUCOMSERVER.EXE AGENTSVR.EXE ANTI-TROJAN.EXE ANTI-TROJAN.EXE ANTIVIRUS.EXE ANTS.EXE APIMONITOR.EXE APLICA32.EXE APVXDWIN.EXE ATCON.EXE ATGUARD.EXE ATRO55EN.EXE ATWATCH.EXE AVCONSOL.EXE AVGSERV9.EXE AVSYNMGR.EXE BD_PROFESSIONAL.EXE BIDEF.EXE BIDSERVER.EXE BIPCP.EXE BIPCPEVALSETUP.EXE BISP.EXE BLACKD.EXE BLACKICE.EXE BOOTWARN.EXE NWINST4.EXE NWTOOL16.EXE OSTRONET.EXE OUTPOSTINSTALL.EXE OUTPOSTPROINSTALL.EXE PADMIN.EXE PANIXK.EXE PAVPROXY.EXE DRWEBUPW.EXE PCC2002S902.EXE PCC2K_76_1436.EXE PCCIOMON.EXE PCDSETUP.EXE PCFWALLICON.EXE PCFWALLICON.EXE PCIP10117_0.EXE PDSETUP.EXE PERISCOPE.EXE PERSFW.EXE PF2.EXE AVLTMAIN.EXE PFWADMIN.EXE PINGSCAN.EXE PLATIN.EXE POPROXY.EXE POPSCAN.EXE EXE TDS2-NT.EXE TDS-3.EXE TFAK5.EXE TGBOB.EXE TITANIN.EXE TITANINXP.EXE TRACERT.EXE TRJSCAN.EXE TRJSETUP.EXE TROJANTRAP3.EXE UNDOBOOT.EXE VBCMSERV.EXE VBCONS.EXE VBUST.EXE VBWIN9X.EXE VBWINNTW.EXE VCSETUP.EXE VFSETUP.EXE VIRUSMDPERSONALFIREWALL.EXE VNLAN300.EXE VNPC3000.EXE VPC42.EXE VPFW30S.EXE VPTRAY.EXE VSCENU6.02D30.EXE VSECOMR.EXE VSHWIN32.EXE VSISETUP.EXE VSMAIN.EXE VSMON.EXE VSSTAT.EXE VSWIN9XE.EXE VSWINNTSE.EXE VSWINPERSE.EXE W32DSM89.EXE W9X.EXE WATCHDOG.EXE WEBSCANX.EXE CFIAUDIT.EXE CFINET.EXE ICSUPP95.EXE MCUPDATE.EXE CFINET32.EXE CLEAN.EXE CLEANER.EXE LUINIT.EXE MCAGENT.EXE MCUPDATE.EXE MFW2EN.EXE MFWENG3.02D30.EXE MGUI.EXE MINILOG.EXE MOOLIVE.EXE MRFLUX.EXE MSCONFIG.EXE MSINFO32.EXE MSSMMC32.EXE MU0311AD.EXE NAV80TRY.EXE ZAUINST.EXE ZONALM2601.EXE ZONEALARM.EXE
尋找系統中目錄名稱為shar 者,將駭蟲本身複製到此些目錄中,檔案為:
Microsoft Office 2003 Crack, Working!.exe Microsoft Windows XP, WinXP Crack, working Keygen.exe Microsoft Office XP working Crack, Keygen.exe Porno, sex, oral, anal cool, awesome!!.exe Porno Screensaver.scr Serials.txt.exe KAV 5.0 Kaspersky Antivirus 5.0 Porno pics arhive, xxx.exe Windows Sourcecode update.doc.exe Ahead Nero 7.exe Windown Longhorn Beta Leak.exe Opera 8 New!.exe XXX hardcore images.exe WinAmp 6 New!.exe WinAmp 5 Pro Keygen Crack Update.exe Adobe Photoshop 9 full.exe Matrix 3 Revolution English Subtitles.exe
以執行檔格式出現的病毒檔案,其前面讀圖形為 "紅櫻桃",如下圖:

|