|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
W32/Zafi@mm |
¹ÙÀÌ·¯½º
Á¾·ù |
Worm |
½ÇÇà
ȯ°æ |
Windows |
Á¦ÀÛÁö |
ºÒºÐ¸í |
¹ß°ßÀÏ |
20040612 |
¹ÙÀÌ·¯½ºÅ©±â |
12,800 bytes |
¸ÞÀÏ
Á¦¸ñ |
Don`t worry, be happy! ¿Ü ´Ù¼ö |
÷ºÎÆÄÀÏ |
www.ecard.com.funny.picture.index.nude.php356.pif ¿Ü ´Ù¼ö |
¹ÙÀÌ·¯½º Áõ»ó |
ÀÌ ¿úÀº ÀÚü smtp¸¦ ÀÌ¿ëÇÑ À̸ÞÀÏÀ» ÅëÇØ ÀüÆĵǸç, °¨¿¬µÈ ¸ÞÀϳ»¿ëÀÇ ¾ð¾î°¡ ´Ù¾ç ÇÏ´Ù.
¿úÀº °¨¿°µÈ ÆÄÀÏ¿¡ °ãÃľ²±â ÇÏ¿© Á¤»ó ÆÄÀÏÀ» ¼Õ»ó½ÃÅ°±âµµ Çϸç,
ƯÁ¤ ÇÁ·Î¼¼½º¸¦ ÀÚµ¿À¸·Î Á¾·á ½ÃÅ°±âµµ ÇÑ´Ù.
´ÙÀ½Àº ½Å°íµÈ ¸ÞÀÏÀÇ ÇÑ ¿¹ÀÌ´Ù.
[¸ÞÀÏ Á¦¸ñ]
Don`t worry, be happy!
[¸ÞÀÏ ³»¿ë]
Hi Honey!
I`m in hurry, but i still love ya...
(as you can see on the picture)
Bye - Bye:
[÷ºÎÆÄÀÏ]
www.ecard.com.funny.picture.index.nude.php356.pif
[Ư¡]
÷ºÎµÈ ÆÄÀÏÀÌ ½ÇÇàµÇ¸é
À©µµ¿ìÀÇ ½Ã½ºÅÛ Æú´õ(win 2000, NT : c:\Winnt\system32, Win XP : c;\windows\system32)¿¡
(·£´ý ÆÄÀϸí).exe, (·£´ý ÆÄÀϸí).dll ¿ú ÆÄÀÏÀÌ ¸¸µé¾î Áø´Ù.
¶ÇÇÑ, ´ÙÀ½Ã³·³ ·¹Áö½ºÆ®¸¦ ¼öÁ¤ÇÏ¿© ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛÇÑ´Ù.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Ç׸ñ¿¡
(win2000, NTÀÇ °æ¿ì)
_Hazafibb = c:\winnt\system32\(·£´ý ÆÄÀϸí).exe
(WinXPÀÇ °æ¿ì)
_Hazafibb = c:\windows\(·£´ý ÆÄÀϸí).exe
HKEY_LOCAL_MACHINE\Software\Microsoft\_Hazafibb
¿úÀÌ ½ÇÇà µÇ¸é regedit(·¹Áö½ºÆ®¸® ÆíÁý±â), msconfig(½Ã½ºÅÛ ±¸¼º À¯Æ¿¸®Æ¼),task
µîÀÇ ÇÁ·Î±×·¥ ½ÇÇàÀ» ¹æÇØ Çϸç
fvprotect.exe
winlogon.exe
jammer2nd.exe
services.exe
ÆÄÀÏ¹× ÇÁ·Î¼¼½º°¡ ÀÖ´Ù¸é Á¾·á ÈÄ »èÁ¦ ÇÑ´Ù.
±×¸®°í °¨¿°µÈ ÄÄÇ»ÅÍ¿¡ share, upload ¶ó´Â Æú´õ¸¦ ¹ß°ßÇϸé, ´ÙÀ½°ú °°Àº À̸§À¸·Î
¿úÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
winamp 7.0 full_install.exe
Total Commander 7.0 full_install.exe
¿úÀÌ °¨¿°µÈ ÆÄÀÏÀ» º¸³»±â À§ÇØ ´ÙÀ½°ú °°Àº È®ÀåÀÚ¸¦ °¡Áø ÆÄÀÏ¿¡¼ ¸ÞÀÏÁÖ¼Ò¸¦ ¼öÁýÇÑ´Ù.
adb
asp
dbx
eml
htm
mbx
php
pmr
sht
tbb
txt
wab
¸¶Áö¸·À¸·Î ¼öÁýµÈ À̸ÞÀÏ ÁÖ¼Ò¿¡¼ ´ÙÀ½°ú °°Àº ¹®ÀÚ¿À» ¹ß°ßÇÏ¸é ¿úÆÄÀÏÀ» º¸³»Áö ¾Ê´Â´Ù.
admi
cafee
google
help
hotm
info
kasper
micro
msn
panda
sopho
suppor
syma
trend
use
vir
webm
win
yaho |
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½ÅAi, Åͺ¸¹é½Å Online, Åͺ¸¹é½Å 2001 Á¦Ç°±ºÀ¸·Î Ä¡·á°¡´É. |
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|