“多姿(worm.dozer.a)”病毒:警惕程度★★★☆,蠕病毒,通過郵件傳播,依賴統: win9x/nt/2000/xp。
該病毒會偽裝成微軟的補丁來誘騙用戶點擊,當病毒運行會將自身拷貝到統目錄下為:mscsgs.exe、mscexec.exe、mscsgs32.exe,修改註册進行自啓動,用戶可以此來判斷電腦是否中毒。病毒還會通過郵件統外送大量的帶毒郵件來阻塞網絡,且終止十反病毒軟件的運行。以下是病毒郵件的詳細信息:
病毒郵件使用的虛假郵件送地址為:
winpatch@microsoft.comservices@microsoft.commsnsupport@microsoft.comhelpdesk@microsoft.comsecurity@microsoft.comwindowsupdate@microsoft.com等
病毒郵件的標題為:
windows update
msn messenger update
msn messenger vulnerability等
郵件內容為:
attention all microsoft users: a patch has been issued to correct a
vulnerability in msn messenger which can be performed by a malicious
user in order to gain unauthorized access to compromised computers.
windows users who have msn messenger 4.x and higher versions are
affected by this vulnerability and must download and install the
patch labeled
附件為:msn_inst.exe
反病毒專建議:建立良好的安全習慣,不打開可疑郵件和可疑網站;關閉或刪除統中不需要的服務;很多病毒利用漏洞傳播,一定要及時給統打補丁;安裝專業的防毒軟件進行實時監控,平時上網的時候一定要打開防病毒軟件的實時監控功能。