|
|

§@ªÌ¡G§õ²»
±z¦n
----------------------------------------------------------------
Hi! How are you?
I send you this file in order to have your advice
See you later. Thanks
----------------------------------------------------------------
¥H¤W¬O·P¬V Sircam ¯f¬r©Òµo«H¤º®e¡A³o°¦ Sircam(«ä§¢) ¯f¬rµo§@¤é´Á¬O10¤ë16¤é¡K¡K
¦U¦ìÀ³¸Ó¦¬¨ì¹L§a¡H³o«Ê«H¥óÁÙ¦³ªþ¥[ÀÉ¡A¦³¤£¤Ö¦Ñ¹ê¤H¯uªº¥h°õ¦æªþ¥[ÀÉ®×¾ÉP¤¤¬r¡C¦pªG§A¨ü¦¹¯f¬r©Ò§xÂZ¡A¨ä¹ê¦¹¯f¬rÀ³¸Ó¤£¬O¹ï¤è¬G·Nn±NªþÀɱHµ¹§Aªº¡A¦Ó¬O¹ï¤è¤¤¬r«á¡A¦b¤£ª¾±¡ªºª¬ªp¤U¦Û°Ê±NªþÀɱHµ¹³q°T¿ý¦W³æ¤¤ªº¤H¡K¡K
¡¾ Sircam«ä§¢¯f¬r¤pÀɮסG
¶l¥ó¥D¦®¡G¤£©T©w
ªþ¥[ÀɮסG¤£©T©w¡A¦ý»P¶l¥ó¥D¦®¦P¦W
¶l¥ó¤º®e¡G^¤å©Î¦è¯Z¤ú¤å¡A^¤åª©¥»¦p¤U¡G
----------------------------------------------------------------
Hi! How are you?
I send you this file in order to have your advice
See you later. Thanks
----------------------------------------------------------------
©Î
----------------------------------------------------------------
Hi! How are you?
I hope you can help me with this file that I send
See you later. Thanks
----------------------------------------------------------------
©Î
----------------------------------------------------------------
Hi! How are you?
This is the file with the information that you ask for
See you later. Thanks
----------------------------------------------------------------
µ¥µ¥
¯f¬rªº¼vÅT¡G
¨C¦~ªº10¤ë16¸¹±N¦³¥i¯àµo§@¡Aµo§@«á¥¦·|§R°£Àx¦s¦b¹q¸£ùتº©Ò¦³ÀɮסC
¦b¦¹¦¸ Sircam«ä§¢¯f¬rµo§@¨Æ¥ó¤¤¡A¥i¥Hµyµy©ñ¤ßªº¬OWindows NT/2000§@·~¨t²Îªº¨Ï¥ÎªÌ¡A¦]¬°¦¹¯f¬r¥Ø«e©|¤£¯à¦bWindows
NT©ÎWindows 2000¤U½Æ»s¨ä¦Û¨¡C¤j®a¥i¥H¦bSymantecªººô¯¸¤W§ä¨ì¦³Ãö¦¹¯f¬rªº¸Ô²Ó¸ê°T¡A¦ì§}¬O¡G
http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html¡A¬°¤F¤è«K»´ä¥Î®a¡AµØ³q½Ķ¤F¨ä¤¤¦³Ãö¦p¦ó²¾°£¦¹¯f¬rªº³¡¤À¡A¨Ñ¦U¦ì°Ñ¦Ò¡C
¡¾²¾°£¦¹¯f¬r
1. °õ¦æLiveUpdate¥H¨ú±o³Ì·sªº¯f¬r©w¸qÀɮסA¤]¥i¥H¨ì
¡@¡@http://www.symantec.com/avcenter/defs.download.html¤U¸ü¡C
2. ¶}±ÒNorton AntiVirus(NAV)¡A°õ¦æ¤@½ë§¹¾ãªº¨t²Î±½´y¡A¦b¦¹¤§«e¡A½Ð¥ý³]©wNAV¬°±½´y©Ò¦³ÀɮסC
3. §R°£©Ò¦³·P¬V¤FW32.Sircam.Worm@mm¯f¬rªºÀɮסC
¡¾²MªÅ¦^¦¬µ©¤¤ªº©Ò¦³ÀÉ®×
¦b¸ê·½¦^¦¬µ©¤W«ö¤@¤U·Æ¹«¥kÁä¡A±q¸õ¥Xªº§Ö±¶¿ï³æ¤¤¿ï¡u²M²z¸ê·½¦^¦¬µ©¡v¡C¦pªG§A¯à°÷¦b¡uWindowsÀÉ®×Á`ºÞ¡v¤¤§ä¨ìÀÉ®×C:\recycled\Sircam.sys¡A§A¤]¥i¥Hª½±µ§R°£¦¹ÀɮסC
¡¾½s¿èAutoexec.batÀɮסG
1. ÂI¿ï¡u¶}©l¡v¿ï³æ¤§¡u°õ¦æ¡v¶µ¡C
2.
¦b¡u°õ¦æ¡v¹ï¸Ü¤è¶ôªº¡u¶}±Ò¡v¤å¦r¦C¡A¿é¤J¥H¤U¤å¦r¨Ã«ö[½T©w]¶s¡Gedit
c:\autoexec.bat
¡@¥i¨£¨ì¡uMS-DOS Editor¡vµøµ¡¡C
3. ¦pªGAutoexec.bat¤¤¥]§t¦³¡u@win \recycled\sirc32.exe¡v«h§R°£¦¹¦æ¤å¦r¡C
4. ¥Î·Æ¹«ÂI¿ï¡uMS-DOS Editor¡vµ{¦¡ªº¡uFile¡v¡÷¡uSave¡v¿ï³æ¶µ¡C
5. ÂI¿ï¡uFile¡v¡÷¡uExit¡v¿ï³æ¶µ¡A°h¥X¡uMS-DOS
Editor¡vµ{¦¡¡C
¡¾½s¿èµn¿ý¸ê®Æ®w¡G
¤@¯ë¨Ï¥ÎªÌ¦bWindows¤¤¶}±Òµn¿ý½s¿è¾¹µ{¦¡REGEDIT.EXE¶i¦æ½s¿è¡C
1. ¿ï«ö¡u¶}©l¡v¡÷¡u°õ¦æ(R)...¡v¿ï¶µ¡A¦b¡u¶}±Ò(O)¡v¤å¦r°Ï¡AÁä¤J:¡§REGEDIT.EXE¡¨¡C
2.«ö [½T©w] ¶s¡Aµn¿ý½s¿è¾¹µ{¦¡REGEDIT.EXE·|¦Û°Ê¼u¥X¡C
3.¤p¤ß¶i¦æ¦p¤U¥|³B×§ï¡G
1). ¦b¡uµn¿ý½s¿è¾¹¤¤¡v§ä¨ì¨Ã¿ï¨ú¤U¦C¾÷½X¡G
HKEY_CLASSES_ROOT\exefile\shell\open\command
[ª`·N¨Æ¶µ]
¦bHKEY_CLASSES_ROOT¾÷½X¤U¥]§t³\¦h¤l¾÷½X¡A¤À§O«ü¦V¹ïÀ³ªº°ÆÀɦW¡A½Ð°È¥²§ä¨ì¥¿½Tªº¾÷½X¡C¤£n×§ïHKEY_CLASSES_ROOT\.exe¾÷½X¡C
¦p¤U¡i¹Ï¤@¡j©Ò¥Ü¡A½Ð×§ïHKEY_CLASSES_ROOT\exefile\shell\open\command¾÷½X¡G

2). ¦b¥kÃ䵡®æªº¡u(¹w³])¡vȤW«ö¨â¤U·Æ¹«¥ªÁä¡A¥i¨£¨ì¡u½s¿è¦r¦ê¡v¹ï¸Ü¤è¶ô¡C
3). §R°£¥Ø«eªº³]©wÈ¡A¨Ã¿é¤J"%1" %*¡A¤]´N¬O¨Ì¦¸¿é¤J¡GÂù¤Þ¸¹-¦Ê¤À¸¹-1-Âù¤Þ¸¹-ªÅ®æ-¦Ê¤À¸¹-¬P¸¹¡C
[ª`·N¨Æ¶µ]
µn¿ý½s¿è¾¹·|¦Û°Ê¦b¿é¤JªºÈ«e«á¥[¤WÂù¤Þ¸¹¡A·í§A«ö·Ó¤W±ªº«ü¤Þ¿é¤J¤§«á¡A«ö[½T©w]¶s¡A¡u¡u(¹w³])¡v¡vȹê»Ú¤W·|Åã¥Ü¬°¡G""%1"
%*"¡C
4).
½Ð°È¥²§R°£¦¹¾÷½X¤¤ì¦³ªº¸ê®Æ¨Ã«ö·Ó¤W±ªº«ü¤Þ¿é¤J¥¿½Tªº¸ê®Æ¡C¦pªG¤£¤p¤ß¦b¦¹¦r¦êȪº¶}©l³B¯d¤U¤F¤@ӪŮæ¦r¤¸¡A±N¾ÉP§@·~¨t²ÎµLªk¶}±Ò°õ¦æµ{¦¡ÀɮסA·í§A°õ¦æ¥ô¦ó.EXE°õ¦æÀɮɡAWindows·|Åã¥ÜÃþ¦ü¡uWindows
cannot find .exe.¡v©Î¡uCannot locate C:\ <path and file name>.¡vªº¸ê°T¡C
5). ¦b¡uµn¿ý½s¿è¾¹¤¤¡v§ä¨ì¨Ã¿ï¨ú¤U¦C¾÷½X¡G
HKEY_LOCAL_MACHINE\Software\SirCam
[ª`·N¨Æ¶µ]
§A¤@©wn§ä¨ì¨Ã¿ï¨ú¥¿½TªºSirCam¾÷½X¡A¿ï¤¤«áÃþ¦ü¤U¡i¹Ï¤G¡j©Ò¥Ü¡G

6). ¦p¤W¹Ï©Ò¥Ü¿ï¤¤¦¹¾÷½X«á¡A«ö[Delete]Áä¡A±N¨ä¤Uªº©Ò¦³¾÷½X§R°£¡A¦¹¾÷½X¶È¥ÑSircam¯f¬rµ{¦¡¨Ï¥Î¡A¦]¦¹§R°£¥¦¤£·|¦³¬Æ»ò°ÝÃD¡C
7). ¦b¡uµn¿ý½s¿è¾¹¤¤¡v§ä¨ì¨Ã¿ï¨ú¤U¦C¾÷½X¡G
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
8). ¦b¥kÃ䪺µ¡®æ¡A´M§ä¨Ã¿ï¨ú³]©wÈ¡uDriver32¡v¡C
9). ¿ï©w«á«ö[Delete]Áä¡A¨£¨ì¡u½T»{§R°£È¡v¹ï¸Ü®Ø«á«ö[¬O]«ö¶s§Y¥i¡C
¡¾ ª÷¤s¤½¥q§K¶Oµo©ñ±þ¬rµ{¦¡
¦p¤µ¤¤°êªº¤@¨Ç³n¥ó¤½¥q¦b§Þ³N¬ãµo¤W¤w¸g¯à°÷»P°ê»Ú¤j¤½¥q§Ü¿Å¡A¥H¤µ¦¸Sircam«ä§¢¯f¬rÃzµo¬°¨Ò¡A°ê¤º±þ¬r³nÅé¡uª÷¤s¬rÅQ¡vªº¬ãµo°Óª÷¤s¤½¥q´N¯à°÷¨³³t¦b¨ä¨¾¯f¬r±M¥Îºô¯¸¤Wµo¥¬¤F§K¶OªºSircam«ä§¢¯f¬r±þ¬rµ{¦¡¡C¦¹µ{¦¡¨Ï¥Î¤è«K¡A¥u»Ý«ö¤@¤U·Æ¹«´N¥i²M°£¹q¸£¤¤·P¬V¤F¯f¬rªºÀɮסC¦U¦ì¨Ï¥ÎªÌ¥i¥H¥Ñª÷¤s¤½¥qºô¯¸http://antivirus.kingsoft.net/¤U¸ü¦¹µ{¦¡¡A»´ä¹q¸£¥Î®a¤]¥i¥H«ö¦¹¥ÑµØ³qWeb¦øªA¾¹¤U¸ü¡AÀɮתø«×79.5KB¡C
¨Ï¥Î¦¹µ{¦¡²M°£SirCam¯f¬rªº¨BÆJ¡G
1). ª½±µ°õ¦æ¤U¸üªºÀÉ®×Duba_Sircam.EXE¡AµM¦Z¦b¡uScan
Path¡v³]©w²M°£±ýSirCam¯f¬rªº¸ô®|¡A«ö[Start Scan]¶}©l²M°£¡C¹w³]±¡ªp¤U¡A¦bÀˬdµwºÏºÐ¾÷¤WªºÀɮפ§«e¡ADuba_Sircam·|¥ýÀˬd°O¾ÐÅ餤¬O§_¦s¦bSirCam¯f¬r¡A¦pªG¦s¦b¡A«h·|¥ý²M°£°O¾ÐÅ餤ªº¯f¬r¡]¦pªG°O¾ÐÅ餤³Q·P¬V¦h¥÷SirCam¡A¦¹¹Lµ{¤]³\µyºC¡^¡C
2). ÀH¦Z¡Aµ{¦¡±N®ÚÕu¨Ï¥ÎªÌ¿ï¾Üªº¸ô®|°õ¦æ²M°£¤u§@¡A¹ï¨Ï¥ÎªÌ¿ï¾Üªº¸ô®|¤U©Ò¦³ªºÀÉ®×¶i¦æ¬d¬r¡A¨Ã¦Û°Ê²M°£©Ò§ä¨ìªºSirCam¯f¬r¡C
3). ±½´y¨BÆJµ²§ô«á¡ASirCam¯f¬r´N±q±zªº¹q¸£¨½¹ý©³³Q²M±½¥X¥h¤F¡C
[¦Û¨¥¦Û»y]
¦¹¦¸Sircam«ä§¢¯f¬rÃzµo¨Ó¶Õ¬¤¬¤¡A¥Hµ§ªÌªº¸gÅç¡A¦¹¯f¬r¹ï»´ä¹q¸£¥Î®aªº¼vÅT¤ñ¡u·RÂÎ(ILoveU)¡v¯f¬r§ó¬Æ¡A¦b³oºØ±¡ªp¤U¦pªG±þ¬r³n¥ó¤½¥q¥ú·Q¦p¦óÁÈ¿ú¦Ó¤£¬°±±¨î¯f¬r¶Ç¼½¥X¤O¡A¬O¥Ø¥úµu²Lªº¦æ¬°¡Cª÷¤s¤½¥q¯à°÷§K¶Oµo©ñ±þ¬rµ{¦¡¡AÅý§Ú̹襤°ê³n¥ó·~ªº«e³~¦h¤F¤@¥÷§Æ±æ...
¡¾ ¯¬§g¥¦wµL¨Æ
·s¯f¬rSircam³Ìªñ¦bºô¸ô¤W½¯©µ¡A¨a±¡¦³³vº¥ÂX´²¤§¶Õ¡A¦³¤H¤@¤Ñ¨ì³°³°ÄòÄò¦¬¤F§Ö100MB¦¹Ãþªº«H«H½cÃz±¼¡C«ä§¢¯f¬rÁöè²{¨¤£¤[¡A«o¤w¨³³t«¤É¦Ü¥þ²y¤Q¤j¯f¬r±Æ¦æº]ªº²Ä¤T¦W¤¤´ä¥xµ¥¦a¬Ò¦³·P¬V¨a±¡¶Ç¥X¡A«áÄò«Â¯Ù¤Oȱoª`·N¡C
¥i¥H³]©w¹LÂo±ø¥óÅý¥¦¦bÀˬd«H¥ó®É¦Û°Ê§R°£¯S©w¶l¥ó¡C¬Û«H³oÓ¤èªkÀ³¸Ó¹ï©ó¼Æ¾Ú¾÷¥Î¤á¦³¬Û·í¤jªºÀ°§U¡C
|
|
|
[ªð¦^¤W¶] |
|
|