美国网络协会(Network Associates)的防病毒技术研究机构McAfee AVERT(Anti-Virus Emergency Response Team)将新发现的蠕虫“W32/Netsky.b@MM”的危险程度定为“中”。这是美国网络协会在当地时间2月18日宣布的。美国赛门铁克也将该蠕虫的危险程度定为“3”。
Netsky.b进行自我复制后用随机生成的文件名发送至在感染计算机上找到的电子邮件地址。并将自身以文件名“SERVICES.EXE”复制到系统文件夹%windir%上,随后在注册表上添加'HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows CurrentVersionRun "service"=C:WINNTservices.exe -serv'。
此外,由于可以将自身复制到C至Z驱动器上包含“shared”或“sharing”词语的共享文件夹,所以也有可能通过P2P网络感染。发送邮件时附件为类似“rtf.pif”的双重文件名或“.ZIP”文件。
McAfee AVERT的研究人员自当日发现该蠕虫后,每小时总计接到40~50个客户提供的病毒样本或病毒感染邮件。McAfee AVERT仅当天就收到世界各地客户发来的近200个样本,其中大部分据说都来自荷兰。
用户如果发现以如下词组开头的电子邮件时,就立即将其删除!
I have your password!
about me
anything ok?
do you?
from the chatter
greetings
hello
here
here is the document.
here it is
here, the cheats
here, the introduction
here, the serials
hi
i found this document about you
i hope it is not true!
i wait for a reply!
i'm waiting
information about you
is that from you?
is that true?
is that your account?
is that your name?
kill the writer of this document!
my hero
ok
read it immediately!
read the details.
reply
see you
something about you!
something is fool
something is going wrong
something is going wrong!
stuff about you?
take it easy
that is bad
that's funny
thats wrong why?
what does it mean?
yes, really?
you are a bad writer
you are bad
you earn money
you feel the same
you try to steal
your name is wrong