PC¼¼ÀÌÆÛ ºü¸¥ ¸Þ´º


 PC¼¼ÀÌÆÛ ¸Þ´º ¾È³»
PC¼¼ÀÌÆÛ È¨
·Î±×ÀÎ (À¯·á»ç¿ëÀÚ)
ÇÁ·Î±×·¥ ¼Ò°³
ÇÁ·Î±×·¥ °¡À̵å
 - ±¸¸Å¹æ¹ý
 - »óÇ°±Ç°áÁ¦
 - ÀÚµ¿°áÁ¦ Ãë¼Ò
 - °Ë»ç¤ýÄ¡·á¹æ¹ý
 - ȯ°æ¼³Á¤
 - ÆÄÀϺ¹¿ø
¾Ç¼ºÄÚµå? ¹ÙÀÌ·¯½º?
 - ¾Ç¼ºÄÚµå¶õ?
 - ¹ÙÀÌ·¯½º¶õ?
 - ºÒÇÊ¿äÇÑ Á¤º¸¶õ?
º¸¾ÈÁ¤º¸
 - º¸¾ÈÄ®·³
 - MSº¸¾È±Ç°í¹®
°í°´Áö¿ø
 - °øÁö»çÇ×
 - ÀǽɵǴ ÆÄÀϽŰí
 - ÀæÀº Áú¹®¤ý´äº¯
 - 1:1»ó´ã

¹ÙÀÌ·¯½º À̸§ W32/WhBoy.C ¹ÙÀÌ·¯½º Á¾·ù Window File Virus
½ÇÇà ȯ°æ Windows Á¦ÀÛÁö ºÒºÐ¸í
¹ß°ßÀÏ 20070101 ¹ÙÀÌ·¯½ºÅ©±â 68,733Byte
¸ÞÀÏ Á¦¸ñ
÷ºÎÆÄÀÏ
¹ÙÀÌ·¯½º Áõ»ó

*°¨¿° °æ·Î

³×Æ®¿öÅ© °øÀ¯¸¦ ÅëÇؼ­ ÀüÆĵȴÙ.

 


*Áõ»ó

°¨¿°µÇ¸é ½Ã½ºÅÛÆú´õ¸¦ Á¦¿ÜÇÑ exeÆÄÀÏÀº °¨¿°ÀÌ µÇ¸ç, °¨¿°µÈ µð·ºÅ丮¾È¿¡ desktop_.ini¸¦ »ý¼ºÇÑ´Ù.  

¶ÇÇÑ ½Ã½ºÅÛ Æú´õ¿¡ ÀÚ½ÅÀ» º¹Á¦ÇÏ¸ç ·¹Áö½ºÅ͸®¿¡ µî·ÏÇÏ¿© ÀçºÎÆýà ÀÚµ¿ ½ÇÇàµÇµµ·Ï ÇÑ´Ù.

±×¸®°í Á¤»ó HTML ¹®¼­¿¡ iframe »ðÀÔÇÏ¿© ¾Ç¼ºÄڵ带 ´Ù¿î·ÎµåÇÑ´Ù.

 

-ÆÄÀÏ »ý¼º

 

À©µµ¿ì ½Ã½ºÅÛ Æú´õ\drivers\ Æú´õ¿¡ spoclsv.exe¶ó´Â ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.

        -À©µµ¿ì ½Ã½ºÅÛ Æú´õ¶õ?

-          À©µµ¿ì 95/98/ME/XP  - C:\Windows\System,

-          À©µµ¿ì NT/2000      -C:\WinNT\System32

-          À©µµ¿ì XP           - C:\Windows\System32

       

-·¹Áö½ºÆ®¸® µî·Ï 

 

·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ value¸¦ µî·ÏÇØ À©µµ¿ì ±¸µ¿½Ã ÀÚµ¿ ½ÇÇàµÇµµ·Ï ¸¸µç´Ù.  

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
svcshare =
À©µµ¿ì ½Ã½ºÅÛ Æú´õ\drivers\spoclsv.exe

 

-´ÙÀ½ ·¹Áö½ºÆ®¸®°ª º¯°æ

¾Æ·¡ ·¹Áö½ºÆ®¸®°ªÀ» º¯°æÇÏ¿© ¼û±è ÆÄÀÏÀ» º¼ ¼ö ¾ø°Ô ¸¸µç´Ù.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

CheckedValue=0

 

-·¹Áö½ºÆ®¸® »èÁ¦

¾Æ·¡¿¡ ÇØ´çÇÏ´Â ·¹Áö½ºÆ®¸® Å°¸¦ »èÁ¦ÇÑ´Ù.

sharedaccess
RsCCenter RsRavMon KVWSC
KVSrvXP
kavsvc
McAfeeFramework
McShield
McTaskManager
McAfeeFramework
McShield
McTaskManager
navapsvc
wscsvc
KPfwSvc
SNDSrvc
ccProxy
ccEvtMgr
ccSetMgr
SPBBCSvc
Symantec Core LC
NPFMntor
MskService
FireSvc

SOFTWARE\
Microsoft\Windows\CurrentVersion\Run\RavTask

SOFTWARE\
Microsoft\Windows\CurrentVersion\R
un\KvMonXP

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
kav

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KAVPersonal50

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
McAfeeUpdaterUI

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Network Associates Error Reporting Service

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ShStatEXE

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YLive.exe

SOFTWARE\Microsoft\Windows\CurrentVersion\Run
yassistse


-ÇÁ·Î¼¼½º Á¾·á


´ÙÀ½ ½ÇÇà ÁßÀÎ ÇÁ·Î¼¼½º¸¦ °­Á¦ Á¾·á ½ÃŲ´Ù.

Mcshield.exe
VsTskMgr.exe
naPrdMgr.exe
UpdaterUI.exe
TBMon.exe
scan32.exe
Ravmond.exe
CCenter.exe
RavTask.exe
Rav.exe
Ravmon.exe
RavmonD.exe
RavStub.exe
KVXP.kxp
KvMonXP.kxp
KVCenter.kxp
KVSrvXP.exe
KRegEx.exe
UIHost.exe
TrojDie.kxp
FrogAgent.exe

-ÆÄÀÏ ´Ù¿î·Îµå

¾Æ·¡ÀÇ ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÑ µÚ   À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡ ÀúÀå ÇÑ´Ù.


- cimemli.exe
- cimemost.dll
- dllf.dll

Ä¡·á ¹æ¹ý Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

Á÷Á¢Ä¡·á¹æ¹ý