• Åͺ¸¹é½Å
¿£Áø¾÷µ¥ÀÌÆ®
º¸¾È±Ç°í¹®
½ÅÁ¾ ¹ÙÀÌ·¯½º
½ÅÁ¾¾Ç¼ºÄÚµå
¹®ÀÇÇϱâ
¿À´ÃÀÇ º¸¾È°æº¸
Level3 : ÁÖÀÇ
Ãֽо÷µ¥ÀÌÆ® ÇöȲ   document.write("2018.07.06.0");
¹ÙÀÌ·¯½º ½Å°íÇϱâ
½ÅÁ¾¹ÙÀÌ·¯½º
   
¸ñ·Ï¤Ó ÀÎ¼â  
W32/Mimail.13856@mm
¹ÙÀÌ·¯½º Á¾·ù Worm ½ÇÇàȯ°æ Windows
¹ß°ßÀÏ 2003³â11¿ù18ÀÏ Á¦ÀÛÁö ºÒºÐ¸í
À§Çèµî±Þ È®»ê¹æ¹ý
¹ÙÀÌ·¯½º Å©±â 13,856 Byte ÷ºÎÆÄÀÏ www.paypal.com.pif ¶Ç´Â InfoUpdate.exe
¸ÞÀÏÁ¦¸ñ IMPORTANT ¶Ç´Â Problems with your PayPal account.
Áõ»ó¿ä¾à
Ä¡·á¹æ¹ý Åͺ¸¹é½ÅAi, Åͺ¸¹é½Å Online, Åͺ¸¹é½Å 2001 Á¦Ç°±ºÀ¸·Î Ä¡·á°¡´É.

Åͺ¸¹é½Å Ai¸¦ »ç¿ëÇÏ½Ã°í ¾Æ¿ô·èÀ» »ç¿ëÇϽŠ´Ù¸é ¹Ýµå½Ã À̸ÞÀÏ °¨½Ã±â¸¦
½ÇÇàÇϽñ⠹ٶø´Ï´Ù.
Åͺ¸¹é½Å IS üÇè°ü  Åͺ¸¹é½Å IS ±¸¸Å
»ó¼¼¼³¸í
ÀÌ ¿úÀº À̸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆÄµÇ¸ç, ¹Ì±¹ÀÇ °áÀç ´ëÇà ¼­ºñ½º ȸ»çÀÎ paypal·Î À§ÀåÇϰí ÀÖ´Ù.
W32/Mimail.12832.B@mmÀÇ º¯Á¾À¸·Î ¿úÀ» Æ÷ÇÔÇÑ À̸ÞÀÏÀº ¾Æ·¡¿Í °°Àº º»¹® ³»¿ëÀ» °¡Áö°í ÀÖ´Ù.

º¸³½»ç¶÷ PayPal.com[Do_Not_Reply@paypal.com]

Dear PayPal member,

We regret to inform you that your account is about to be expired in next five business days.
To avoid suspension of your account you have to reactivate it by providing us with your personal information.

To update your personal profile and continue using PayPal services you have to run the attached application to this email.
Just run it and follow the instructions.

IMPORTANT! If you ignore this alert, your account will be suspended in next five business days and you will not be able to use
PayPal anymore.

Thank you for using PayPal.

ÀÓÀÇÀÇ ¹®ÀÚ¿­


ÇØ´ç ÆÄÀÏÀÌ ½ÇÇà µÇ¸é À©µµ¿ì Æú´õ(win9x, XP: c:\windows, win2000: c:\winnt)¿¡
svchost32.exe ¿Í ee98af.tmp, el388.tmp(¿úÀÌ ÃßÃâÇÑ ¸ÞÀÏÁÖ¼Ò ÀúÀå)¸¦ »ý¼ºÇÑ´Ù.

¶ÇÇÑ C: ¿¡ ´ÙÀ½ÀÇ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.

pp.gif  (PayPal ±×¸²ÆÄÀÏ)->¼öµ¿À¸·Î »èÁ¦
pp.hta (PayPal Ä«µå¹øÈ£ ÀÔ·Ââ)->¼öµ¿À¸·Î »èÁ¦
index2.hta (°³ÀÎÁ¤º¸ÀÔ·Ââ)->¼öµ¿À¸·Î »èÁ¦


À§ÀÇ Á¤º¸´Â c:ÀÇ ppinfo.sys ÆÄÀÏ¿¡ ÀúÀåµÇ¾î ¿ÜºÎ·Î À¯Ã⠵ȴÙ.


±×·± ´ÙÀ½ ´ÙÀ½Ã³·³ ·¹Áö½ºÆ®¸¦ ¼öÁ¤ÇÏ¿© ´ÙÀ½ ºÎÆÃ½Ã ½ÇÇàµÇµµ·Ï Á¶ÀÛÇÑ´Ù.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Ç׸ñ¿¡

(win9x, XpÀÇ °æ¿ì)
SvcHost32  = c:\windows\svchost32.exe

(win2000, NTÀÇ °æ¿ì)
SvcHost32  = c:\winnt\svchost32.exe
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¸ñ·Ïº¸±â
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
- ¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com