2008年上半年十大病毒及计算机病毒疫情报告
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><B><SPAN lang=EN-US><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></B></P><P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><B><I><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">参考标题:</SPAN><SPAN lang=EN-US><o:p></o:p></SPAN></I></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm -43.7pt 0pt -35.9pt; TEXT-ALIGN: center; mso-para-margin-top: 0cm; mso-para-margin-right: -4.16gd; mso-para-margin-bottom: .0001pt; mso-para-margin-left: -3.42gd" align=center><B><SPAN style="FONT-SIZE: 18pt; FONT-FAMILY: 宋体">江民发布<SPAN lang=EN-US>2008</SPAN>年上半年十大病毒及计算机病毒疫情报告<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN lang=EN-US style="FONT-SIZE: 14pt; FONT-FAMILY: 宋体"><SPAN style="mso-spacerun: yes"> </SPAN><o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN lang=EN-US style="FONT-FAMILY: 楷体_GB2312; mso-bidi-font-size: 10.5pt; mso-hansi-font-family: 宋体">7</SPAN><SPAN style="FONT-FAMILY: 楷体_GB2312; mso-bidi-font-size: 10.5pt; mso-hansi-font-family: 宋体">月<SPAN lang=EN-US>8</SPAN>日,国内最大的计算机反病毒软件供应商江民科技发布了<SPAN lang=EN-US>2008</SPAN>年上半年十大病毒排行及病毒疫情报告。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN style="FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">据江民反病毒中心统计,从<SPAN lang=EN-US>2008</SPAN>年<SPAN lang=EN-US>1</SPAN>月<SPAN lang=EN-US>1</SPAN>日到<SPAN lang=EN-US>2008</SPAN>年<SPAN lang=EN-US>6</SPAN>月<SPAN lang=EN-US>30</SPAN>日,反病毒中心共截获新病毒</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt; mso-bidi-font-family: 'Microsoft Sans Serif'; mso-ansi-language: ZH-CN">206439</SPAN><SPAN style="FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">种。江民<SPAN lang=EN-US>KV</SPAN>病毒预警系统数据显示,<SPAN lang=EN-US>1</SPAN>至<SPAN lang=EN-US>6</SPAN>月全国共有</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt; mso-bidi-font-family: 'Microsoft Sans Serif'; mso-ansi-language: ZH-CN">9871681</SPAN><SPAN style="FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">台计算机感染了病毒。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; TEXT-ALIGN: center; mso-char-indent-count: 2.0" align=center><SPAN lang=EN-US><?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /><v:shapetype id=_x0000_t75 stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"><v:stroke joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1"></v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f><v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"></v:path><o:lock aspectratio="t" v:ext="edit"></o:lock></v:shapetype><v:shape id=_x0000_i1025 style="WIDTH: 358.5pt; HEIGHT: 208.5pt" type="#_x0000_t75"><v:imagedata o:title="新病毒增长数量" src="file:///C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msohtml1\02\clip_image001.jpg"></v:imagedata></v:shape></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; TEXT-ALIGN: center; mso-char-indent-count: 2.0" align=center><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><SPAN style="mso-spacerun: yes"><FONT face="Times New Roman"> </FONT></SPAN></SPAN><SPAN lang=EN-US style="FONT-FAMILY: 新宋体"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体-方正超大字符集; mso-font-kerning: 36.0pt; mso-hansi-font-family: 新宋体"><SPAN style="mso-spacerun: yes"><FONT face="Times New Roman"> </FONT></SPAN></SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">在<SPAN lang=EN-US>2008</SPAN>年上半年十大病毒中,高居榜首的是“网游窃贼”及其变种病毒。这类病毒</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">会自我插入到被感染计算机系统中的“<SPAN lang=EN-US>explorer.exe</SPAN>”桌面进程以及其它应用程序进程内加载运行,隐藏自我,防止被查杀。这也是上半年来,病毒发展的一大趋势。位居排行榜第二位的是去年就榜上有名的</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">“<SPAN lang=EN-US>U</SPAN>盘寄生虫”病毒,该病毒会利用<SPAN lang=EN-US>U</SPAN>盘等移动存储设备进行</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">自我</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">传播,上半年的发展势头更是有增无减。位居第三位和第四位的“代理木马”与“网游大盗”都是</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">具有盗窃特征的木马,前者可以偷取计算机用户机密信息,后者可盗取网络游戏玩家帐号密码等信息资料。在这次排名中,</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">“网游窃贼”之所以能稳居榜手位置,与排名第五的“机器狗”病毒“功不可没”,因为如果用户计算机中一个“机器狗”病毒,那么它至少会下载数十个“网游窃贼”盗号木马,这是两个典型的带有利益关联的病毒。位居第六、第七、第八位的分别是“<SPAN lang=EN-US>Flash</SPAN>蛀虫”及其变种、“<SPAN lang=EN-US>IE</SPAN>大盗”及其变种、“<SPAN lang=EN-US>QQ</SPAN>大盗”及其变种。曾经显赫一时的“灰鸽子”后门类病毒位居这次排行的第九位。而前不久在互联网上肆虐,给广大电脑用户造成巨大损失的</SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">“</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">千足虫”变种<SPAN lang=EN-US>(</SPAN>又名“磁碟机”<SPAN lang=EN-US>)</SPAN>病毒,由于及时关闭了所有</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">相关的恶意网站,对该病毒进行了封堵,所以这次排名仅居第十位。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt"><SPAN style="mso-spacerun: yes"> </SPAN><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">据<SPAN lang=EN-US>2008</SPAN>年上半年病毒疫情报告显示,<SPAN lang=EN-US>2008</SPAN>年上半年病毒发展的新特征较<SPAN lang=EN-US>2007</SPAN>年有所改变。更多的病毒采用了<SPAN lang=EN-US>Rootkit</SPAN>技术进行自我保护和隐藏,这类病毒首先会利用驱动程序去还原系统<SPAN lang=EN-US>SSDT HOOK</SPAN>,从而使部分安全软件的监控失效,然后将去强行关闭目前几乎所有安全工具软件以及绝大多数的杀毒软件<SPAN lang=EN-US>(</SPAN>当然,江民<SPAN lang=EN-US>KV2008</SPAN>杀毒软件是可以抵御该类病毒的<SPAN lang=EN-US>)</SPAN>。接下来,这类病毒会将恶意<SPAN lang=EN-US>DLL</SPAN>组件插入到被感染计算机系统中几乎所有的用户级权限的进程内加载运行,还包括部分系统级权限的进程。并且利用了重启移动技术,在启动计算机时会把病毒主体文件从指定目录下移动到系统<SPAN lang=EN-US>[</SPAN>启动<SPAN lang=EN-US>]</SPAN>文件夹中,实现开机自启动。病毒启动运行后会将系统<SPAN lang=EN-US>[</SPAN>启动<SPAN lang=EN-US>]</SPAN>文件夹中的病毒主体文件删除掉。这样可以隐蔽启动,而不被用户轻易发现。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt; mso-char-indent-count: 2.0"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt">根据江民全球病毒监测网<SPAN lang=EN-US>(</SPAN>国内部分<SPAN lang=EN-US>)</SPAN>、江民病毒预警中心、客户服务中心等多个部门联合监测统计,综合病毒的破坏能力以及传播范围,江民反病毒中心公布了<SPAN lang=EN-US>2008</SPAN>上半年度十大病毒排行:<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<TABLE class=MsoNormalTable style="MARGIN: auto auto auto 4.65pt; WIDTH: 459pt; BORDER-COLLAPSE: collapse; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" cellSpacing=0 cellPadding=0 width=612 border=0>
<TBODY>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: silver; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; mso-border-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">序号</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: silver; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><B><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒名称</SPAN></B><B><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></B></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: silver; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><B><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">英文名</SPAN></B><B><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></B></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">1</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“网游窃贼”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black">Trojan/PSW.OnLineGames</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">2</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">U</FONT></SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">盘寄生虫”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black">Checker/Autorun</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">3</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“代理木马”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black">Trojan/Agent</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">4</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“网游大盗”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Trojan/PSW.GamePass.Gen <o:p></o:p></FONT></SPAN></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">5</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“机器狗”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Trojan/DogArp<o:p></o:p></FONT></SPAN></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">6</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Flash</FONT></SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">蛀虫”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Exploit.CVE-2007-0071<o:p></o:p></FONT></SPAN></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">7</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">IE</FONT></SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">大盗”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">TrojanSpy.Iespy<o:p></o:p></FONT></SPAN></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">8</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">QQ</FONT></SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">大盗”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; mso-bidi-font-size: 9.0pt">Trojan/PSW.QQPass</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><o:p></o:p></SPAN></FONT></P></TD></TR>
<TR style="HEIGHT: 14.25pt">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">9</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“灰鸽子”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Backdoor/Huigezi<o:p></o:p></FONT></SPAN></P></TD></TR>
<TR style="HEIGHT: 14.25pt; mso-yfti-lastrow: yes">
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: windowtext 1pt solid; WIDTH: 54pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" noWrap width=72>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt">10</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 215pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=287>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">“千足虫”变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">(</FONT></SPAN><SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">又名“磁碟机”</SPAN><FONT face="Times New Roman"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black">)</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体"><o:p></o:p></SPAN></FONT></P></TD>
<TD style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 190pt; PADDING-TOP: 0cm; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 14.25pt; BACKGROUND-COLOR: transparent; mso-border-bottom-alt: solid windowtext .5pt; mso-border-right-alt: solid windowtext .5pt" noWrap width=253>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black"><FONT face="Times New Roman">Win32/Kdcyy<o:p></o:p></FONT></SPAN></P></TD></TR></TBODY></TABLE>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 63pt; mso-layout-grid-align: none; mso-char-indent-count: 6.0"><SPAN style="FONT-FAMILY: 宋体">(<SPAN lang=EN-US>2008</SPAN>年度上半年十大病毒排行<SPAN lang=EN-US><SPAN style="mso-spacerun: yes"> </SPAN></SPAN>数据来源:江民科技)</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-hansi-font-family: 'Times New Roman'"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 63pt; mso-layout-grid-align: none; mso-char-indent-count: 6.0"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-hansi-font-family: 'Times New Roman'"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><B><SPAN lang=EN-US style="FONT-SIZE: 16pt; FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><B><SPAN lang=EN-US style="FONT-SIZE: 16pt; FONT-FAMILY: 宋体">2008</SPAN></B><B><SPAN style="FONT-SIZE: 16pt; FONT-FAMILY: 宋体">年上半年十大病毒档案<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体">一、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“网游窃贼”及其变种</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Trojan/PSW.OnLineGames<o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒中文名:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">网游窃贼</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒类型:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:<SPAN lang=EN-US> Trojan/PSW.OnLineGames“</SPAN>网游窃贼<SPAN lang=EN-US>”</SPAN>是一个盗取网络游戏帐号的木马程序,会在被感染计算机系统的后台秘密****用户运行的所有应用程序窗口标题,然后利用键盘钩子、内存截取或封包截取等技术盗取网络游戏玩家的游戏帐号、游戏密码、所在区服、角色等级、金钱数量、仓库密码等信息资料,并在后台将盗取的所有玩家信息资料发送到骇客指定的远程服务器站点上。致使网络游戏玩家的游戏帐号、装备物品、金钱等丢失,会给游戏玩家带去不同程度的损失。</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体"> </SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">网游窃贼<SPAN lang=EN-US>”</SPAN>会通过在被感染计算机系统注册表中添加启动项的方式,来实现木马开机自启动。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">二、<SPAN style="COLOR: black">“<SPAN lang=EN-US>U</SPAN>盘寄生虫”及其变种</SPAN><SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Checker/Autorun<SPAN style="mso-bidi-font-weight: bold"><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒中文名:</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">U</SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">盘寄生虫<SPAN lang=EN-US style="COLOR: black"> <o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:蠕虫<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003 <o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:<SPAN lang=EN-US>Checker/Autorun“U</SPAN>盘寄生虫<SPAN lang=EN-US>”</SPAN>是一个利用<SPAN lang=EN-US>U</SPAN>盘等移动存储设备进行自我传播的蠕虫病毒。<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>” </SPAN>运行后,会自我复制到被感染计算机系统的指定目录下,并重新命名保存。<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>”</SPAN>会在被感染计算机系统中的所有磁盘根目录下创建<SPAN lang=EN-US>“autorun.inf”</SPAN>文件和蠕虫病毒主程序体,来实现用户双击盘符而启动运行<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>”</SPAN>蠕虫病毒主程序体的目的。<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>”</SPAN>还具有利用<SPAN lang=EN-US>U</SPAN>盘、移动硬盘等移动存储设备进行自我传播的功能。<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>”</SPAN>运行时,可能会在被感染计算机系统中定时弹出恶意广告网页,或是下载其它恶意程序到被感染计算机系统中并调用安装运行,会给用户带去不同程度的损失。<SPAN lang=EN-US>“U</SPAN>盘寄生虫<SPAN lang=EN-US>” </SPAN>会通过在被感染计算机系统注册表中添加启动项的方式,来实现蠕虫开机自启动。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">三、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“代理木马”及其变种<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Trojan/Agent<o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒中文名:代理木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:<SPAN lang=EN-US> Trojan/Agent“</SPAN>代理木马<SPAN lang=EN-US>”</SPAN>是木马家族的最新成员之一,采用高级语言编写,并经过加壳保护处理。<SPAN lang=EN-US>“</SPAN>代理木马<SPAN lang=EN-US>”</SPAN>运行后,会自我复制到被感染计算机系统中的指定目录下,修改注册表,实现开机自启。在被感染计算机的后台秘密窃取用户所使用系统的配置信息,然后从骇客指定的远程服务器站点下载其它恶意程序并安装调用运行。其中,所下载的恶意程序可能为网络游戏盗号木马、远程控制后门和恶意广告程序等等,会给用户带去不同程度的损失。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">四、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“网游大盗”及其变种</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><FONT face="Times New Roman"><B><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black">Trojan/PSW.GamePass.Gen</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></B></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒中文名:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体">网游大盗</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒类型:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:<SPAN lang=EN-US style="mso-bidi-font-weight: bold">Trojan/PSW.GamePass</SPAN><SPAN lang=EN-US>“</SPAN></SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体">网游大盗</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">”</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">是一个盗取网络游戏帐号的木马程序,会在被感染计算机系统的后台秘密****用户运行的所有应用程序窗口标题,然后利用键盘钩子、内存截取或封包截取等技术盗取网络游戏玩家的游戏帐号、游戏密码、所在区服、角色等级、金钱数量、仓库密码等信息资料,并在后台将盗取的所有玩家信息资料发送到骇客指定的远程服务器站点上。致使网络游戏玩家的游戏帐号、装备物品、金钱等丢失,会给游戏玩家带去不同程度的损失。</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体"> </SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体">网游大盗</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">”</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">会通过在被感染计算机系统注册表中添加启动项的方式,来实现木马开机自启动。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">五、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“机器狗”及其变种</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Trojan/DogArp<SPAN style="mso-bidi-font-weight: bold"><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒中文名:机器狗<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:以<SPAN lang=EN-US>Trojan/DogArp. h</SPAN>为例,<SPAN lang=EN-US>Trojan/DogArp.h</SPAN>“机器狗”变种<SPAN lang=EN-US>h</SPAN>是“机器狗”木马家族的最新成员之一,采用高级语言编写,并经过加壳保护处理。“机器狗”变种<SPAN lang=EN-US>h</SPAN>运行后,在指定目录下释放恶意驱动程序并加载运行。通过恶意驱动程序直接挂接磁盘<SPAN lang=EN-US>IO</SPAN>端口进行读写真实磁盘物理地址中的数据和进行监控关机行为等操作,从而达到穿透还原软件的目的。覆盖“<SPAN lang=EN-US>explorer.exe</SPAN>”、“<SPAN lang=EN-US>userinit.exe</SPAN>”或“<SPAN lang=EN-US>regedit.exe</SPAN>”等系统文件,实现“机器狗”变种<SPAN lang=EN-US>h</SPAN>开机自启动。恶意驱动程序还能还原系统“<SPAN lang=EN-US>SSDT</SPAN>”,致使某些安全软件的防御和监控功能失效。恶意破坏注册表,致使注册表编辑器无法运行。遍历当前计算机系统中的进程列表,一旦发现与安全相关的进程,强行将其关闭。修改注册表,利用进程映像劫持功能禁止近百种安全软件及调试工具运行。在被感染计算机系统的后台连接骇客指定站点获取恶意程序列表,下载列表中的所有恶意程序并在被感染计算机上自动调用运行。其中,所下载的恶意程序可能是网游木马、广告程序(流氓软件)、后门等,给被感染计算机用户带去不同程度的损失。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><SPAN style="mso-spacerun: yes"> </SPAN><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">六、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“<SPAN lang=EN-US>Flash</SPAN>蛀虫”</SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">及其<SPAN style="COLOR: black">变种</SPAN></SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Exploit.CVE-2007-0071</SPAN></B><B><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒中文名:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“<SPAN lang=EN-US>Flash</SPAN>蛀虫”变种<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒类型:</SPAN><SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体">脚本病毒</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">危险级别:</SPAN><SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">影响平台:</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体">Win 9X/ME/NT/2000/XP/2003</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">描述</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Exploit.CVE-2007-0071“Flash</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">蛀虫<SPAN lang=EN-US>”</SPAN>是脚本病毒家族的最新成员之一,采用<SPAN lang=EN-US>Flash</SPAN>脚本语言和汇编语言编写而成,并且代码经过加密处理,利用<SPAN lang=EN-US>“Adobe Flash Player”</SPAN>漏洞传播其它病毒。<SPAN lang=EN-US>“Flash</SPAN>蛀虫<SPAN lang=EN-US>”</SPAN>一般内嵌在正常网页中,如果用户计算机没有及时升级安装<SPAN lang=EN-US>“Adobe Flash Player”</SPAN>提供的相应的漏洞补丁,那么当用户使用浏览器访问带有<SPAN lang=EN-US>“Flash</SPAN>蛀虫<SPAN lang=EN-US>”</SPAN>的恶意网页时,就会在当前用户计算机的后台连接骇客指定站点,下载其它恶意程序并在被感染计算机上自动运行。所下载的恶意程序一般多为木马下载器,然后这个木马下载器还会下载更多的恶意程序安装到被感染计算机的系统中,会给用户带去不同程度的损失。</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">七、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“<SPAN lang=EN-US>IE</SPAN>大盗”及其变种</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">TrojanSpy.Iespy<SPAN style="mso-bidi-font-weight: bold"><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒中文名:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">IE</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">大盗</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒类型:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">间谍类木马</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">危险级别:</SPAN><SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">影响平台:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">描述:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">TrojanSpy.Iespy“IE</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">大盗<SPAN lang=EN-US>”</SPAN>是间谍类木马家族的最新成员之一,采用高级语言编写,并经过加壳保护处理,一般以<SPAN lang=EN-US>DLL</SPAN>组件文件的形式存在,利用<SPAN lang=EN-US>“BHO”(Browser Helper Objects)</SPAN>劫持技术在被感染计算机系统中随<SPAN lang=EN-US>IE</SPAN>浏览器的启动而加载运行。<SPAN lang=EN-US>“IE</SPAN>大盗<SPAN lang=EN-US>”</SPAN>运行后,会在被感染计算机系统的后台利用<SPAN lang=EN-US>HOOK</SPAN>和键盘记录等技术盗取用户在<SPAN lang=EN-US>IE</SPAN>浏览器中输入的几乎所有机密信息资料(其中包括:用户名、密码、浏览的网址等),并在被感染计算机后台将窃取到的这些信息资料发送到骇客指定的远程服务器站点上,会给用户带去不同程度的损失。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt"><SPAN style="mso-spacerun: yes"> </SPAN><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">八、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“<SPAN lang=EN-US>QQ</SPAN>大盗”及其变种</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">Trojan/PSW.QQPass</SPAN></B><B><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt"><o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒中文名:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">QQ</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">大盗<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:木马<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win9X/2000/XP/NT/Me<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">描述:</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">Trojan/PSW.QQPass</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">“<SPAN lang=EN-US>QQ</SPAN>大盗”是木马家族的最新成员之一,采用高级语言编写,并经过加壳保护处理。“<SPAN lang=EN-US>QQ</SPAN>大盗”运行时,会在被感染计算机的后台搜索用户系统中有关<SPAN lang=EN-US>QQ</SPAN>注册表项和程序文件的信息,然后强行删除用户计算机中的<SPAN lang=EN-US>QQ</SPAN>医生程序“<SPAN lang=EN-US>QQDoctorMain.exe</SPAN>”、“<SPAN lang=EN-US>QQDoctor.exe</SPAN>”和“<SPAN lang=EN-US>TSVulChk.dat</SPAN>”文件,从而来保护自身不被查杀。“<SPAN lang=EN-US>QQ</SPAN>大盗”运行时,会在后台盗取计算机用户的<SPAN lang=EN-US>QQ</SPAN>帐号、<SPAN lang=EN-US>QQ</SPAN>密码、会员信息、<SPAN lang=EN-US>ip</SPAN>地址、<SPAN lang=EN-US>ip</SPAN>所属区域等信息资料,并且会在被感染计算机后台将窃取到的这些信息资料发送到骇客指定的远程服务器站点上或邮箱里,会给被感染计算机用户带去不同程度的损失。“<SPAN lang=EN-US>QQ</SPAN>大盗”通过在注册表启动项中添加键的方式,来实现开机木马自启动。</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体">九、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“灰鸽子”及其变种</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Backdoor/Huigezi<SPAN style="mso-bidi-font-weight: bold"><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒中文名:灰鸽子<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:后门<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003 <o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:<SPAN lang=EN-US>Backdoor/Huigezi </SPAN>“灰鸽子”是后门家族的最新成员之一,采用<SPAN lang=EN-US>Delphi</SPAN>语言编写,并经过加壳保护处理。“灰鸽子”运行后,会自我复制到被感染计算机系统的指定目录下,并重新命名保存(文件属性设置为:只读、隐藏、存档)。“灰鸽子”是一个反向连接远程控制后门程序,运行后会与骇客指定远程服务器地址进行<SPAN lang=EN-US>TCP/IP</SPAN>网络通讯。中毒后的计算机会变成网络僵尸,骇客可以远程任意控制被感染的计算机,还可以窃取用户计算机里所有的机密信息资料等,会给用户带去</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 9.0pt">不同程度</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">的损失。“灰鸽子”会把自身注册为系统服务,以服务的方式来实现开机自启动运行。“灰鸽子”主安装程序执行完毕后,会自我删除。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 宋体"> </SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体">十、</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">“千足虫”及其变种<SPAN lang=EN-US>(</SPAN>又名“磁碟机”<SPAN lang=EN-US>)</SPAN></SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.0pt">病毒名称:</SPAN></B><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">Win32/Kdcyy<o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒中文名:千足虫(又名<SPAN lang=EN-US>“</SPAN>磁碟机<SPAN lang=EN-US>”</SPAN>)<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">病毒类型:蠕虫<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">危险级别:</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-bidi-font-family: 宋体">★★</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">影响平台:<SPAN lang=EN-US>Win 9X/ME/NT/2000/XP/2003<o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">描述:以<SPAN lang=EN-US>Win32/Kdcyy.cp</SPAN>为例,<SPAN lang=EN-US>Win32/Kdcyy.cp</SPAN>“千足虫”变种<SPAN lang=EN-US>cp</SPAN>是“千足虫”家族的最新成员之一,采用<SPAN lang=EN-US>VC++ 6.0</SPAN>编写, 并经过加壳保护处理。“千足虫”变种<SPAN lang=EN-US>cp</SPAN>运行后,会在被感染计算机系统的“<SPAN lang=EN-US>%SystemRoot%\system32\com\</SPAN>”目录下释放病毒组件文件“<SPAN lang=EN-US>lsass.exe</SPAN>”、“<SPAN lang=EN-US>smss.exe</SPAN>”、“<SPAN lang=EN-US>netcfg.000</SPAN>”和“<SPAN lang=EN-US>netcfg.dll</SPAN>”,还会在被感染计算机系统的“<SPAN lang=EN-US>%SystemRoot%\system32\</SPAN>”目录下释放病毒组件文件“<SPAN lang=EN-US>dnsq.dll</SPAN>”。利用驱动程序来恢复<SPAN lang=EN-US>SSDT Hook</SPAN>,使某些安全软件的监控失效。强行关闭大部分杀毒软件和安全工具软件。被感染计算机系统会经常死机或长时间卡住不动。利用“<SPAN lang=EN-US>ARP</SPAN>病毒”在局域网中进行自我传播。感染除系统盘外所有盘符下的<SPAN lang=EN-US>EXE</SPAN>可执行文件、网页文件、<SPAN lang=EN-US>RAR</SPAN>和<SPAN lang=EN-US>ZIP</SPAN>压缩包中的文件等<SPAN lang=EN-US>(</SPAN>加密感染<SPAN lang=EN-US>)</SPAN>,感染后的程序变为<SPAN lang=EN-US>16</SPAN>位的图标,图标变模糊,类似于马赛克。一旦发现与安全相关的窗口存在,强行将其关闭。在所有盘符下生成“<SPAN lang=EN-US>autorun.inf</SPAN>”和病毒体,并且对这些文件进行实时检测保护,利用移动设备进行传播。破坏注册表,致使用户无法进入“安全模式”、无法查看隐藏的系统文件,致使注册表启动项失效。修改注册表,实现开启自动播放的功能。强行删除所有安全软件的关联注册表项,使其无法开启监控。利用进程守护技术,将病毒的“<SPAN lang=EN-US>lsass.exe</SPAN>”、“<SPAN lang=EN-US>smss.exe</SPAN>”进程主体和<SPAN lang=EN-US>DLL</SPAN>组件进行关联,实现进程守护,一旦病毒文件被删除或被关闭,便马上生成并重新运行。以系统级权限运行,部分进程使用了进程保护技术。利用控制台命令来设置病毒程序文件的访问运行权限。利用了重启移动文件的技术,在重新启动计算机时会把病毒主程序体移动存在到系统<SPAN lang=EN-US>[</SPAN>启动<SPAN lang=EN-US>]</SPAN>文件夹中,实现开机自启动。“千足虫”变种<SPAN lang=EN-US>cp</SPAN>会在被感染计算机系统的后台访问骇客指定的广告站点,进行提升访问量,刷网络排名等操作。另外,“千足虫”变种<SPAN lang=EN-US>cp</SPAN>还可以自升级。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36.15pt; mso-char-indent-count: 3.0"><B><SPAN lang=EN-US style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-size: 18.0pt"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36.15pt; TEXT-ALIGN: center; mso-char-indent-count: 2.0" align=center><STRONG><SPAN lang=EN-US style="FONT-SIZE: 18pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">2008</SPAN></STRONG><STRONG><SPAN style="FONT-SIZE: 18pt; COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">年计算机病毒整体情况及特征<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></STRONG></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 10.5pt; TEXT-ALIGN: center; mso-char-indent-count: 1.0" align=center><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 31.5pt; mso-char-indent-count: 3.0"><SPAN style="FONT-FAMILY: 楷体_GB2312; mso-hansi-font-family: 宋体">据江民反病毒中心监测分析,<SPAN lang=EN-US>2008</SPAN>年上半年,病毒主要呈现以下特征:<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US><SPAN style="mso-spacerun: yes"><FONT face="Times New Roman"> </FONT></SPAN></SPAN><B><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">一、木马数量持续猛增,新变种层出不穷</SPAN><SPAN lang=EN-US><o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><FONT face="Times New Roman"><SPAN lang=EN-US style="COLOR: black"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US style="COLOR: black; mso-bidi-font-size: 10.5pt"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: ˎ̥; mso-bidi-font-size: 10.5pt"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN></FONT><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">2008</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">年上半年,江民反病毒中心共截获新病毒</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 新宋体; mso-bidi-font-size: 10.5pt; mso-font-kerning: 36.0pt; mso-bidi-font-family: 'Microsoft Sans Serif'; mso-ansi-language: ZH-CN">206439</SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">种,另据江民病毒预警中心不完全统计,<SPAN lang=EN-US>1</SPAN>至<SPAN lang=EN-US>6</SPAN>月全国共有<SPAN lang=EN-US>9871681</SPAN>台计算机感染了病毒,其中感染木马病毒电脑<SPAN lang=EN-US>7749269</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>78.5%</SPAN>,比去年同期增长<SPAN lang=EN-US>11</SPAN>个百分点。感染广告程序电脑<SPAN lang=EN-US>3849955</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>3.9%</SPAN>,感染后门程序电脑<SPAN lang=EN-US>4540973</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>4.6%</SPAN>,蠕虫病毒<SPAN lang=EN-US>2764070</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>2.8%</SPAN>,监测发现漏洞攻击代码感染<SPAN lang=EN-US>1184601</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>1.2%</SPAN>,脚本病毒感<SPAN lang=EN-US>888451</SPAN>台,占病毒感染电脑总数的<SPAN lang=EN-US>0.9%</SPAN>。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt 35.9pt; mso-para-margin-left: 3.42gd"><SPAN lang=EN-US><v:shape id=_x0000_i1026 style="WIDTH: 339.75pt; HEIGHT: 187.5pt" type="#_x0000_t75"><v:imagedata o:title="病毒种类分析" src="file:///C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msohtml1\02\clip_image002.jpg"></v:imagedata></v:shape></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><SPAN style="mso-spacerun: yes"><FONT face="Times New Roman"> </FONT></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B style="mso-bidi-font-weight: normal"><SPAN style="FONT-FAMILY: 宋体">二、病毒发作区域性特征显著<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">江民<SPAN lang=EN-US>KV</SPAN>病毒预警系统监测数据显示,<SPAN lang=EN-US>2008</SPAN>年病毒疫情比较严重的地区排前十位的分别是:北京、山东、江苏、河南、四川、广东、湖南、辽宁、江西、河北。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">北京近半年被病毒感染的计算机总数为<SPAN lang=EN-US>4774123</SPAN>台,从去年同期的第四位跃居全国之首,占全国被感染计算机总数的<SPAN lang=EN-US>51.3%</SPAN>。而历年来,病毒疫情比较严重的山东、江苏和广东地区,在今年上半年的地区疫情排行榜中,退居第二、第三和第六位,上海今年则退出了全国排行的前十位。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center" align=center><SPAN lang=EN-US><v:shape id=_x0000_i1027 style="WIDTH: 351pt; HEIGHT: 198pt" type="#_x0000_t75"><v:imagedata o:title="地区疫情排行" src="file:///C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msohtml1\02\clip_image003.jpg"></v:imagedata></v:shape></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="FONT-FAMILY: 宋体">三、<SPAN lang=EN-US>U</SPAN>盘成病毒传播主要途径<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><SPAN style="mso-spacerun: yes"> </SPAN></SPAN><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">由于<SPAN lang=EN-US>U</SPAN>盘本身不会防毒,病毒很容易就会感染<SPAN lang=EN-US>U</SPAN>盘,而当<SPAN lang=EN-US>U</SPAN>盘插入电脑时还会自动播放,病毒就会即刻被自动运行。加之<SPAN lang=EN-US>U</SPAN>盘的广泛应用也为病毒的传播提供了温床,由于众多电脑用户在通过接入<SPAN lang=EN-US>U</SPAN>盘进行电脑数据互换时,并没有先扫描病毒后操作运行的习惯,病毒也就瞄准了这一空档藏身其中,“<SPAN lang=EN-US>U</SPAN>盘寄生虫”病毒一出现就以高感染率的排名常居病毒榜前三甲。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-font-kerning: 36.0pt">这类病毒会关闭大部分安全软件<SPAN lang=EN-US>(</SPAN>包括杀毒软件<SPAN lang=EN-US>)</SPAN>进程,降低系统安全性,同时还会自动连接网络下载其它恶意程序并自动安装运行。利用它们来远程控制用户电脑,窃取用户的网络游戏帐号、银行卡密码等私密信息资料,利用<SPAN lang=EN-US>“net stop”</SPAN>命令关闭防火墙、各种杀毒软件的安全服务等,使用户电脑中的安全保护程序瘫痪,给用户的财产和隐私带来严重的威胁。<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B style="mso-bidi-font-weight: normal"><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">四、<SPAN style="mso-bidi-font-weight: bold">经济利益驱使,病毒魔爪伸向网游帐号</SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US><SPAN style="mso-spacerun: yes"><FONT face="Times New Roman"> </FONT></SPAN></SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体">2008</SPAN><SPAN style="FONT-FAMILY: 宋体">年上半年,网游盗号类病毒疫情大幅上升,此类病毒占据了病毒排行榜前四,此类病毒无一例外的把目标对准目前流行的网络游戏,盗取目标除了帐号密码外,还包括游戏分值、虚拟装备、游戏币、游戏点卡、仓库密码、角色等级、金钱数量、所在区服、计算机名称等所有的信息资料。包括“征途”“天堂”“魔兽世界”“完美世界<SPAN lang=EN-US>Online</SPAN>”“剑侠情缘<SPAN lang=EN-US>IIOnline</SPAN>”等几乎所有的流行网游都被病毒盯上,严重威胁广大网络游戏玩家的帐号、密码安全。江民反病毒专家提醒广大电脑用户和网络游戏玩家,务必使用杀毒软件的“系统诊断”功能,对电脑做全面的安全检查,打好系统漏洞补丁,关闭不必要的端口和服务,关闭电脑中的所有共享。网络游戏玩家可以配合使用“密保”软件,将游戏帐号密码输入密保,配合杀毒软件给电脑加上双重保险,减少帐号、密码被盗的风险。</SPAN><SPAN lang=EN-US><FONT face="Times New Roman"> </FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="FONT-FAMILY: 宋体">五、病毒综合利用系统漏洞和应用软件漏洞传播<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">年以来,据江民反病毒中心监测,病毒除了利用</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">WINDOWS</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">系统漏洞传播病毒外,还综合利用了应用软件漏洞,多数病毒已经很少使用单一漏洞传播病毒,而是综合利用两个及两个以上的漏洞。研究表明,</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">年</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">1</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">月至</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">6</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">月,利用微软</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">MS06</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">-</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">014</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">漏洞、百度搜霸不安全方法漏洞、</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">RealPlayer Import</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">缓冲溢出漏洞,</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">90%</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">以上的挂马网页至少使用它们当中的一个。而</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">5</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">月底被发现的</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">FLASH</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">远程代码执行漏洞,在短短的一周内,就有数万人受到了利用该漏洞的恶意代码攻击。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B style="mso-bidi-font-weight: normal"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 18.05pt; TEXT-ALIGN: center; mso-char-indent-count: 1.0" align=center><B style="mso-bidi-font-weight: normal"><SPAN style="FONT-SIZE: 18pt; FONT-FAMILY: 宋体">计算机病毒未来发展趋势<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-weight: bold"><SPAN style="mso-spacerun: yes"> </SPAN><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 31.5pt; mso-char-indent-count: 3.0"><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-weight: bold">根据江民反病毒中心对上半年所截获的大量病毒样本的分析,综合病毒的破坏能力、传播手段以及传播目标和范围,以及对目前互联网的安全形势和应用环境的判断,江民反病毒中心认为未来病毒发展主要将呈现以下五大特征:<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 10.5pt; mso-char-indent-count: 1.0"><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-weight: bold"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="FONT-FAMILY: 宋体">一、综合利用多种编程新技术的病毒将成为主流<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; LAYOUT-GRID-MODE: char; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">从</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">Rootkit</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">技术到映象劫持技术,磁盘过滤驱动到还原系统</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">SSDT HOOK</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">和还原其它内核</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">HOOK</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">技术,病毒为达到目的所采取的手段已经无所不用其极。通过</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">Rootkit</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">技术和映象劫持技术隐藏自身的进程、注册表键值,通过插入进程、线程避免被杀毒软件查杀,通过实时监测对自身进程进行回写,避免被杀毒软件查杀,通过还原系统</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">SSDT HOOK</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">和还原其它内核</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">HOOK</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">技术破坏反病毒软件,其中仅映象劫持技术就包括“进程映像劫持”、“磁盘映像劫持”、“域名映像劫持”、“系统</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">DLL</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">动态连接库映像劫持”等多种方式。目前几乎所有的盗取网络游戏帐号的木马病毒都具备了以上一种以上的技术特征,几乎所有最新的程序应用技术都被病毒一一应用,电脑一旦感染病毒,普通用户根本无能力彻底清除,只能求助专业技术人员。未来的计算机病毒将综合利用以上新技术,使得杀毒软件查杀难度更大。</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN style="FONT-FAMILY: 宋体">二、<B><SPAN lang=EN-US>ARP</SPAN>病毒仍将成为局域网最大祸害<SPAN lang=EN-US><o:p></o:p></SPAN></B></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; LAYOUT-GRID-MODE: char; TEXT-INDENT: 31.5pt; mso-char-indent-count: 3.0"><SPAN lang=EN-US style="mso-bidi-font-size: 10.5pt"><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒已经成为近年来企业、网吧、校园网络等局域网的最大威胁。此类病毒</SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">采用</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">局域网挂马攻击技术,利用</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">MAC</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">地址欺骗,传播恶意广告或病毒程序,使得</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒猖獗一时。</SPAN><SPAN lang=EN-US style="mso-bidi-font-size: 10.5pt"><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒发作时,通常会造成网络掉线,但网络连接正常,内网的部分电脑不能上网,或者所有电脑均不能上网,无法打开网页或打开网页慢以及局域网连接时断时续并且网速较慢等现象。更为严重的是,</SPAN><SPAN lang=EN-US style="mso-bidi-font-size: 10.5pt"><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒新变种能够把自身伪装成网关,在所有用户请求访问的网页添加恶意代码,导致杀毒软件在用户访问任意网站均发出病毒警报,用户下载任何可执行文件,均被替换为病毒,严重影响到企业网络、网吧、校园网络等局域网的正常运行。</SPAN><SPAN lang=EN-US style="mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; LAYOUT-GRID-MODE: char; TEXT-INDENT: 31.5pt; mso-char-indent-count: 3.0"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"> <o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; LAYOUT-GRID-MODE: char; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">虽然在各大安全厂商的努力下,</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">ARP</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒得到了有效遏制,但由于众多中小企业用户没有足够重视病毒的危害,没有采取相应的防范措施,因此给此类病毒提供了生存空间,预计此类病毒仍将在很长一段时间内成为祸害局域网的主要类型病毒。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="FONT-FAMILY: 宋体">三、网游病毒仍将大行其道,逐利成此类病毒唯一目标<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">受经济利益驱使,利用键盘钩子、内存截取或封包截取等技术盗取网络游戏玩家的游戏帐号、游戏密码、所在区服、角色等级、金钱数量、仓库密码等信息资料的病毒今年上半年十分活跃。</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">年上半年截获的新木马病毒中,</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">80</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">%以上都与盗取网络游戏帐号密码有关。病毒作者的牟利目标十分明确,就是盗取互联网上有价值的信息和资料,特别是网络游戏帐号密码、以及虚拟装备等,转卖后获取利益。逐利已成为此类病毒的唯一动机和目标,随着网络游戏的火爆和兴盛,此类病毒仍然有着庞大的市场和生存空间,仍将成为未来病毒的主流。</SPAN><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt"><SPAN lang=EN-US style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN style="COLOR: black; FONT-FAMILY: 宋体; mso-bidi-font-size: 10.5pt">四</SPAN></B><B><SPAN style="FONT-FAMILY: 宋体">、病毒将全面进入驱动级<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"><B><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">进入</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">以来,大部分主流病毒技术都进入了驱动级,病毒已经不再一味逃避杀毒软件追杀,而是开始与杀毒软件争抢系统驱动的控制权,在争抢系统驱动控制权后,转而控制杀毒软件,使杀毒软件功能失效。病毒通过生成驱动程序,与杀毒软件争抢系统控制权限,通过修改</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">SSDT</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">表等技术实现</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">WINDOWS API HOOK</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">,从而使得杀毒软件监控功能失效。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><B><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">五、奥运或成病毒借机传播新目标</SPAN><SPAN lang=EN-US><o:p></o:p></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-INDENT: 27pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">每次重大事件都会成为病毒传播的良机,</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">北京奥运会全球瞩目,更可能成为病毒作者瞄准的目标。北京奥运即将在</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">8</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">月</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">8</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">日正式召开,根据以往的经验,奥运期间病毒可能通过以下几种形式传播或发作:</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 45pt; TEXT-INDENT: -18pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt list 45.0pt; mso-list: l0 level1 lfo1" align=left><SPAN lang=EN-US style="mso-fareast-font-family: 'Times New Roman'"><SPAN style="mso-list: Ignore"><FONT face="Times New Roman">1、<SPAN style="FONT: 7pt 'Times New Roman'"> </SPAN></FONT></SPAN></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">通过即时通讯工具群发奥运相关信息,诱使用户点击带毒链接或接受带毒文件。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 45pt; TEXT-INDENT: -18pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt list 45.0pt; mso-list: l0 level1 lfo1" align=left><SPAN lang=EN-US style="mso-fareast-font-family: 'Times New Roman'"><SPAN style="mso-list: Ignore"><FONT face="Times New Roman">2、<SPAN style="FONT: 7pt 'Times New Roman'"> </SPAN></FONT></SPAN></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">通过发送主题或内容与奥运相关信息的电子邮件,在邮件附件中夹带病毒。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 45pt; TEXT-INDENT: -18pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt list 45.0pt; mso-list: l0 level1 lfo1" align=left><SPAN lang=EN-US style="mso-fareast-font-family: 'Times New Roman'"><SPAN style="mso-list: Ignore"><FONT face="Times New Roman">3、<SPAN style="FONT: 7pt 'Times New Roman'"> </SPAN></FONT></SPAN></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">在论坛或贴吧发布带毒的奥运比赛现场图片或视频链接,诱使用户点击。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 45pt; TEXT-INDENT: -18pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt list 45.0pt; mso-list: l0 level1 lfo1" align=left><SPAN lang=EN-US style="mso-fareast-font-family: 'Times New Roman'"><SPAN style="mso-list: Ignore"><FONT face="Times New Roman">4、<SPAN style="FONT: 7pt 'Times New Roman'"> </SPAN></FONT></SPAN></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">攻破传播奥运新闻的相关网站,在相关网页挂马传播病毒。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 27pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-INDENT: 27pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">病毒作者通过以上几种形式传播病毒,主要目标还是瞄准经济利益。一旦用户电脑染毒后,染毒电脑中所有的有价值的信息,包括网络游戏帐号密码、网上银行帐号密码、网上证券交易帐号密码都面临着被盗的危险,因此需要引起用户的足够重视。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 0cm; TEXT-INDENT: 27pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt" align=left><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt"><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">计算机病毒表现出的众多新特征以及发展趋势表明,目前我国计算机网络安全形势仍然十分严峻,反病毒业者面临的挑战十分艰巨,需要不断地研发推出更加先进的计算机反病毒技术,才能应对和超越计算机病毒的发展,为电脑和网络用户提供切实的安全保障。作为电脑用户,更应当增强安全意识,多学习和了解基本的计算机和网络安全防范知识和技术,做到最基本的不登陆和点击不明网站和链接,每日升级杀毒软件病毒库和修复操作系统漏洞,尽量使用最新版本的应用软件等安全防范措施。特别是在奥运期间,更需要提高警惕,首先要确保自身电脑不染毒不传毒,为</SPAN><SPAN lang=EN-US><FONT face="Times New Roman">2008</FONT></SPAN><SPAN style="FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'">北京奥运的顺利召开尽自己的一份力量。</SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN lang=EN-US><o:p><FONT face="Times New Roman"> </FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p> </o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21.1pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><B><SPAN style="FONT-FAMILY: 宋体">延伸阅读:<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 18.0pt">江民<SPAN lang=EN-US>2007</SPAN>年度十大病毒及计算机病毒疫情报告<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 20pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN lang=EN-US style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana">http://www.jiangmin.com/News/jiangmin/index/important/200812155811.htm</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 18.0pt">江民<SPAN lang=EN-US>2007</SPAN>年上半年十大病毒及计算机病毒疫情报告<SPAN lang=EN-US><o:p></o:p></SPAN></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN lang=EN-US style="FONT-FAMILY: 宋体; mso-bidi-font-size: 18.0pt">http://www.jiangmin.com/News/jiangmin/index/important/20077515449.htm<o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0" align=left><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-size: 18.0pt">江民<SPAN lang=EN-US>2006</SPAN>年上半年十大病毒及计算机病毒疫情报告</SPAN><SPAN lang=EN-US style="FONT-FAMILY: 宋体"><o:p></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0.9pt 0pt 13.85pt; TEXT-INDENT: 21pt; TEXT-ALIGN: left; mso-layout-grid-align: none; tab-stops: 36.0pt; mso-para-margin-top: 0cm; mso-para-margin-right: .9pt; mso-para-margin-bottom: .0001pt; mso-para-margin-left: 1.32gd; mso-char-indent-count: 2.0"