°¨¿°
°æ·Î
°¨¿°µÈ
½Ã½ºÅÛ¿¡¼
¸ÞÀÏ
ÁÖ¼Ò¸¦
¼öÁýÇÏ¿©
ÇØ´ç¿úÀ»
÷ºÎÇÏ¿©
¸ÞÀÏ·Î
ÀüÆÄ
µÈ´Ù.
*Áõ»ó
- ÆÄÀÏ
»ý¼º
À©µµ¿ì
Æú´õ¿¡
KesenjanganSosial.exe ¶ó´Â
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
-
À©µµ¿ì
Æú´õ
?
- À©µµ¿ì
95/98/ME/XP -
C:\Windows,
- À©µµ¿ì
NT/2000
- C:\WinNT
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ¿¡
»ç¿ëÀÚÀ̸§''s Setting.scr
,cmd-brontok.exe ¶ó´Â
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
-
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ?
- À©µµ¿ì
95/98/ME/XP -
C:\Windows\System
- À©µµ¿ì
NT/2000
- C:\WinNT\System32
- À©µµ¿ì
XP
- C:\Windows\System32
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\½ÃÀÛ
¸Þ´º\ÇÁ·Î±×·¥\½ÃÀÛÇÁ·Î±×·¥\
Æú´õ¿¡
Empty.pif ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
services.exe
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
inetinfo.exe
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
lsass.exe ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
csrss.exe ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
winlogon.exe ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Local
Settings\Application Data\ Æú´õ¿¡
smss.exe ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
Documents
and Settings\»ç¿ëÀÚ
°èÁ¤\Templates\
Æú´õ¿¡
Brengkolang.com
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
À©µµ¿ì
Æú´õ\ShellNew
Æú´õ¿¡
RakyatKelaparan.exe ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
À©µµ¿ì
Æú´õ\Tasks
Æú´õ¿¡
At1.job ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù
-·¹Áö½ºÆ®¸®
µî·Ï
·¹Áö½ºÆ®¸®¿¡
´ÙÀ½
value¸¦
µî·ÏÇØ
À©µµ¿ì
±¸µ¿½Ã
ÀÚµ¿
½ÇÇàµÇµµ·Ï
¸¸µç´Ù.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Tok-Cirrhatus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Tok-Cirrhatus-123 = documents and
settings\»ç¿ëÀÚ °èÁ¤\local settings\application
data\smss.e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Bron-Spizaetus = À©µµ¿ì Æú´õ\shellnew\rakyatkelaparan.exe
°¨¿°µÈ
½Ã½ºÅÛÀº
ƯÁ¤
·¹Áö½ºÆ®¸®
°ªÀ»
º¯°æÇÏ¿©
À©µµ¿ì
Ž»ö±âÀÇ
Æú´õ
¿É¼Ç
¸Þ´º,
¼û±è
ÆÄÀÏ
¼Ó¼º
ÄܼÖ
¸í·Éâ,
·¹Áö½ºÆ®¸®
ÆíÁý±â
µîÀ»
½ÇÇàµÇÁö
¾Êµµ·Ï
¸¸µç´Ù.
|