Bagle是一種電腦蠕蟲病毒,會感染Windows系統。首隻Bagle病毒(Bagle.A)的傳播速度不高,但其後出現的變種則比A型的狠得多。
Bagle是靠電郵方式傳播,當使用者下載並執行附件後,病毒會複製到Windows的系統資料夾,並會開啟指定的TCP port作為後門。
此外,Bagle會刪除Netsky的病毒檔案,並隱藏著針對Netsky的字句。例如在Bagle.J病毒中有以下的
*"Hey, NetSky, fuck off you bitch, don't ruine our business, wanna start a war?"
外部連結
- [http://www.trendmicro.com/vinfo/zh-tw/virusencyclo/default5.asp?VName=WORM_BAGLE.A 趨勢科技 Bagle.A]
- [http://www.trendmicro.com/vinfo/zh-tw/virusencyclo/default5.asp?VName=WORM_BAGLE.B 趨勢科技 Bagle.B]
- [https://web.archive.org/web/20070608131950/http://www.hkcert.org/valert/chi_vinfo/w32.bagle.variants%40mm.html HKCERT Bagle.D 至 Bagle.AQ]
- [https://web.archive.org/web/20070213134447/http://www.hkcert.org/valert/chi_vinfo/w32.bagle.at%40mm.html HKCERT Bagle.AT]
- [https://web.archive.org/web/20070617212827/http://www.hkcert.org/valert/chi_vinfo/w32.bagle.az%40mm.html HKCERT Bagle.AZ]
评论 (0)