- 精华
- 0
- 帖子
- 872
- 威望
- 1 点
- 积分
- 1145 点
- 种子
- 0 点
- 注册时间
- 2007-2-21
- 最后登录
- 2015-5-12
|
当前流行的蠕虫病毒变种,以马里奥为主题的worm已被确认。这个病毒名称是「W32/Romario-A」,在游戏被启动的同时感染计算机,并通过电子邮件传播。
被这个病毒侵入的电脑,每天按一定时间被启动和设定。同时,当BAT,COM,PIF,SCR等扩展名的文件被打开的同时也会随之启动。
http://www.sophos.com/security/blog/2007/07/427.html
A mass-mailing worm capitalising on the old Mario game reared its ugly head today in the form of W32/Romario-A.
Sadly aficionados of the Mario game would find themselves in bigger trouble than the much publicised icon of the genre.
When run W32/Romario-A not only runs a Mario game but also attempts to worm itself to other uninfected computers via mass-mailing itself as a file attachment as well as via removable shared drives.
The worm attempts to entrench itself by scheduling a task to ensure the worm runs every day at a specified time.
To further complicate matters, the worm is set to run when files with extensions of BAT, COM, PIF and SCR are opened/launched.
W32/Romario-A belongs to the list of malware pretending to be a game or to run a game. This trick has noticeably been tried many times before by previous malware authors. For example, the W32/Bagle-U worm attempts to start the Microsoft Hearts game (see related news article), the W32/Coconut-A virus starts a Coconut game and the Troj/Gonori-A Trojan plays Minesweeper when run.. |
|