|
|
|
|
|
 |
 |
 |
| Ãֽо÷µ¥ÀÌÆ® ÇöȲ
document.write("2018.07.06.0");
|
|
 |
|
 |
 |
 |
|
| W32/Bube |
| ¹ÙÀÌ·¯½º Á¾·ù |
Window File Virus |
½ÇÇàȯ°æ |
Windows |
| ¹ß°ßÀÏ |
2005³â04¿ù05ÀÏ |
Á¦ÀÛÁö |
ºÒºÐ¸í |
| À§Çèµî±Þ |
³·À½ |
È®»ê¹æ¹ý |
ÀͽºÇ÷η¯ |
| ¹ÙÀÌ·¯½º Å©±â |
4,900 Bytes |
÷ºÎÆÄÀÏ |
|
| ¸ÞÀÏÁ¦¸ñ |
|
| Áõ»ó¿ä¾à |
ƯÁ¤½ÎÀÌÆ®¿¡ Á¢¼ÓÇÏ¿© TrojanÀ» ´Ù¿î·Îµå ¹Þ´Â´Ù. |
| Ä¡·á¹æ¹ý |
Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.
 |
 |
À©µµ¿ìÁî Æú´õÀÇ explorer.exe ÆÄÀÏ¿¡¸¸ °¨¿°µÇ¸ç, °¨¿°µÈ ÆÄÀÏÅ©±â´Â ¾à 4,900 Byte ´Ã¾î³´Ù.
°¨¿°´ë»óÀÎ explorer.exe ÆÄÀÏÀÌ Á¸Àç ÇÏ´Â ´ÙÀ½ Æú´õ¸¦ °¨¿° ´ë»óÀ¸·Î ÇÑ´Ù.
* windows 98, me, xp
c:\windows, c:\windows\servicepackFiles\i386, c:\windows\dllcache
* windows 2000
c:\winnt, c:\winnt\servicepackFiles\i386, c:\winnt\dllcache
±×¸®°í WININIT.INI ¸¦ ´ÙÀ½ ó·³ º¯°æÇÏ¿© explorer.exe ¸¦ °¨¿°½ÃŲ´Ù.
[rename]
c:\windows\explorer.exe=c:\windows\explorer.new
¾Æ·¡¿Í °°ÀÌ ·¹Áö½ºÆ®¸®¸¦ º¯°æÇÑ´Ù.
HKEY_CURRENT_USER\Software\Microsoft\Security Center
AntiVirusDisableNotify = ¡°dword:00000001¡±
FirewallDisableNotify = ¡°dword:00000001¡±
UpdatesDisableNotify = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
SelfLimit = dword:00000001
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\SystemRestore
DisableSR = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
Windows\WindowsUpdate\AU
AUOptions = ¡°dword:00000001¡±
NoAutoUpdate = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Microsoft\
Security Center
AntiVirusDisableNotify = ¡°dword:00000001¡±
FirewallDisableNotify = ¡°dword:00000001¡±
UpdatesDisableNotify = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Microsoft\
Internet Explorer\Main
SelfLimit = dword:00000001
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows NT\CurrentVersion\SystemRestore
DisableSR = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
Windows\WindowsUpdate\AU
AUOptions = ¡°dword:00000001¡±
NoAutoUpdate = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
WindowsFirewall\DomainProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_CURRENT_USER\Software\Policies\Microsoft\
WindowsFirewall\StandardProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
WindowsFirewall\DomainProfile
EnableFirewall = ¡°dword:00000001¡±
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\
WindowsFirewall\StandardProfile
EnableFirewall = ¡°dword:00000001¡±
¸¶Áö¸·À¸·Î http://advXXXin.biz/tasks ¿¡ Á¢¼ÓÀ» ½ÃµµÇϸç
¼º°øÇßÀ» °æ¿ì ¹ÙÅÁȸ鿡 tasks ÆÄÀÏÀÌ »ý±ä´Ù.
|
 |
|
|
 |
| ¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö |
- ¿¡ºê¸®Á¸¿¡¼ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com |
|
|