|
|
|
|
¹ÙÀÌ·¯½º
À̸§ |
X97M/Bonker |
¹ÙÀÌ·¯½º
Á¾·ù |
Macro Virus |
½ÇÇà
ȯ°æ |
Win9x, 2000, XP (office °¡´Éȯ°æ) |
Á¦ÀÛÁö |
|
¹ß°ßÀÏ |
|
¹ÙÀÌ·¯½ºÅ©±â |
|
¸ÞÀÏ
Á¦¸ñ |
|
÷ºÎÆÄÀÏ |
|
¹ÙÀÌ·¯½º Áõ»ó |
ÀÌ ¹ÙÀÌ·¯½º´Â Exclel 97 ¹®¼¿¡ °¨¿°µÇ´Â ¹ÙÀÌ·¯½º ÀÌ´Ù.
ÀÌ ¹ÙÀÌ·¯½º´Â ÇÑ°³ÀÇ ¸ðµâ·Î ±¸¼ºµÈ´Ù.
workbook ¿¡ °¨¿°µÇ¸ç, XM97.BoNK ¶ó´Â »óŹ٠¸Þ½ÃÁö¸¦ Ç¥½ÃÇÑ´Ù.
ÀÌ ¹ÙÀÌ·¯½º´Â Excel ÇÁ·Î±×·¥ÀÇ Á¦¸ñÀ» º¯°æÇÑ´Ù.
ÀÌ ¹ÙÀÌ·¯½º´Â B32o2nk.sys ¶ó´Â ÆÄÀÏ(c:\windows\system\)¿¡¼ ÀÚ½ÅÀÇ Äڵ带 °¡Á®¿Â´Ù.
B32o2nk.sys ÆÄÀÏ ÀÚü´Â °¨¿°µÇÁö ¾Ê´Â´Ù.
°¨¿°µÇ¸é, View/Toolbars, Tools/Auditing, Tools/Add-Ins, Window/Hide and Window/Unhide. ±â´ÉÀ̵¿ÀÛÇÏÁö ¾Ê°Ô µÈ´Ù.
B32o2nk.reg ¶ó´Â ÆÄÀÏ(c:\windows\system\) ÀÌ »ý¼ºµÇ¸ç, ¿ª½Ã °¨¿°µÇÁö ¾Ê´Â´Ù.
·¹Áö½ºÆ²¿¡ ´ÙÀ½ÀÇ °ªµéÀ» ³²±ä´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Winlogon\LegalNoticeCaption=""XM97.BoNK"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Winlogon\LegalNoticeText ="This is B©ªNKeRs of the .BoNK-family by Jack Twoflower -=[Lz¨ª]=-"
¶Ç´Ù¸¥ ÆÄÀÏÀÎ c:\start.bat ÆÄÀÏÀÌ »ý¼ºµÇ¸ç, B32NK.REG ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù.
ÀÌ ÆÄÀÏÀÌ ½ÇÇàµÇ¸é ·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ÀÇ Å°°ªÀ» ³²±ä´Ù.
HKEY_CURRENT _USER/Software/VB and VBA Program Settings/VBA/XM97_BoNK/BKCounter"
HKEY_CURRENT _USER/Software/VB and VBA Program Settings/
VBA/XM97_BoNK/Creator = "jack twoflower -=[Lz¨ª]=-"
HKEY_CURRENT _USER/Software/VB and VBA Program Settings/
VBA/XM97_BoNK/Address = "jack_twoflower@hotmail.com"
If counter = 100, the virus will create and execute the file c:\format.bat,
which formats the c:\ and a:\ drive.
Æ÷¸äÀÌ µÉ ¼ö ÀÖ´Â ÄÚµåÀ̹ǷΠÀ§ÇèÇÏ´Ù.
|
Ä¡·á ¹æ¹ý |
Åͺ¸¹é½Å Ai À¸·Î Ä¡·á °¡´É. |
Á÷Á¢Ä¡·á¹æ¹ý |
|
|
|
|
|