|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
W32/Bube |
¹ÙÀÌ·¯½º
Á¾·ù |
Window File Virus |
½ÇÇà
ȯ°æ |
Windows |
Á¦ÀÛÁö |
ºÒºÐ¸í |
¹ß°ßÀÏ |
20050405 |
¹ÙÀÌ·¯½ºÅ©±â |
4,900 Bytes |
¸ÞÀÏ
Á¦¸ñ |
|
÷ºÎÆÄÀÏ |
|
¹ÙÀÌ·¯½º Áõ»ó |
À©µµ¿ìÁî Æú´õÀÇ explorer.exe ÆÄÀÏ¿¡¸¸ °¨¿°µÇ¸ç, °¨¿°µÈ ÆÄÀÏÅ©±â´Â ¾à 4,900 Byte ´Ã¾î³´Ù.
°¨¿°´ë»óÀÎ explorer.exe ÆÄÀÏÀÌ Á¸Àç ÇÏ´Â ´ÙÀ½ Æú´õ¸¦ °¨¿° ´ë»óÀ¸·Î ÇÑ´Ù.
* windows 98, me, xp
c:\windows, c:\windows\servicepackFiles\i386, c:\windows\dllcache
* windows 2000
c:\winnt, c:\winnt\servicepackFiles\i386, c:\winnt\dllcache
±×¸®°í WININIT.INI ¸¦ ´ÙÀ½ ó·³ º¯°æÇÏ¿© explorer.exe ¸¦ °¨¿°½ÃŲ´Ù.
[rename]
c:\windows\explorer.exe=c:\windows\explorer.new
¾Æ·¡¿Í °°ÀÌ ·¹Áö½ºÆ®¸®¸¦ º¯°æÇÑ´Ù.
HKEY_CURRENT_USER\Software\Microsoft\Security Center
AntiVirusDisableNotify = ¡°dword:00000001¡±
FirewallDisableNotify = ¡°dword:00000001¡±
UpdatesDisableNotify = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
SelfLimit = dword:00000001
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\SystemRestore
DisableSR = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
Windows\WindowsUpdate\AU
AUOptions = ¡°dword:00000001¡±
NoAutoUpdate = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Microsoft\
Security Center
AntiVirusDisableNotify = ¡°dword:00000001¡±
FirewallDisableNotify = ¡°dword:00000001¡±
UpdatesDisableNotify = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Microsoft\
Internet Explorer\Main
SelfLimit = dword:00000001
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\SystemRestore
DisableSR = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
Windows\WindowsUpdate\AU
AUOptions = ¡°dword:00000001¡±
NoAutoUpdate = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
WindowsFirewall\DomainProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
WindowsFirewall\StandardProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
WindowsFirewall\DomainProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
WindowsFirewall\StandardProfile
EnableFirewall = ¡°dword:00000001¡±
¸¶Áö¸·À¸·Î http://advXXXin.biz/tasks ¿¡ Á¢¼ÓÀ» ½ÃµµÇϸç
¼º°øÇßÀ» °æ¿ì ¹ÙÅÁȸ鿡 tasks ÆÄÀÏÀÌ »ý±ä´Ù. |
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.
|
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|