• Åͺ¸¹é½Å
¿£Áø¾÷µ¥ÀÌÆ®
º¸¾È±Ç°í¹®
½ÅÁ¾ ¹ÙÀÌ·¯½º
½ÅÁ¾¾Ç¼ºÄÚµå
¹®ÀÇÇϱâ
¿À´ÃÀÇ º¸¾È°æº¸
Level3 : ÁÖÀÇ
Ãֽо÷µ¥ÀÌÆ® ÇöȲ   document.write("2018.07.06.0");
¹ÙÀÌ·¯½º ½Å°íÇϱâ
½ÅÁ¾¹ÙÀÌ·¯½º
   
¸ñ·Ï¤Ó ÀÎ¼â  
X97M/Bonker
¹ÙÀÌ·¯½º Á¾·ù Macro Virus ½ÇÇàȯ°æ Win9x, 2000, XP (office °¡´Éȯ°æ)
¹ß°ßÀÏ - Á¦ÀÛÁö
À§Çèµî±Þ È®»ê¹æ¹ý
¹ÙÀÌ·¯½º Å©±â ÷ºÎÆÄÀÏ
¸ÞÀÏÁ¦¸ñ
Áõ»ó¿ä¾à
Ä¡·á¹æ¹ý Åͺ¸¹é½Å Ai À¸·Î Ä¡·á °¡´É.
Åͺ¸¹é½Å IS üÇè°ü  Åͺ¸¹é½Å IS ±¸¸Å
»ó¼¼¼³¸í
ÀÌ ¹ÙÀÌ·¯½º´Â Exclel 97 ¹®¼­¿¡ °¨¿°µÇ´Â ¹ÙÀÌ·¯½º ÀÌ´Ù.
ÀÌ ¹ÙÀÌ·¯½º´Â ÇѰ³ÀÇ ¸ðµâ·Î ±¸¼ºµÈ´Ù.
workbook ¿¡ °¨¿°µÇ¸ç, XM97.BoNK ¶ó´Â »óŹ٠¸Þ½ÃÁö¸¦ Ç¥½ÃÇÑ´Ù.
ÀÌ ¹ÙÀÌ·¯½º´Â Excel ÇÁ·Î±×·¥ÀÇ Á¦¸ñÀ» º¯°æÇÑ´Ù.

ÀÌ ¹ÙÀÌ·¯½º´Â B32o2nk.sys ¶ó´Â ÆÄÀÏ(c:\windows\system\)¿¡¼­ ÀÚ½ÅÀÇ Äڵ带 °¡Á®¿Â´Ù.
B32o2nk.sys ÆÄÀÏ ÀÚü´Â °¨¿°µÇÁö ¾Ê´Â´Ù.
°¨¿°µÇ¸é, View/Toolbars, Tools/Auditing, Tools/Add-Ins, Window/Hide and Window/Unhide. ±â´ÉÀ̵¿ÀÛÇÏÁö ¾Ê°Ô µÈ´Ù.
B32o2nk.reg ¶ó´Â ÆÄÀÏ(c:\windows\system\) ÀÌ »ý¼ºµÇ¸ç, ¿ª½Ã °¨¿°µÇÁö ¾Ê´Â´Ù.

·¹Áö½ºÆ²¿¡ ´ÙÀ½ÀÇ °ªµéÀ» ³²±ä´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Winlogon\LegalNoticeCaption=""XM97.BoNK"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Winlogon\LegalNoticeText ="This is B©ªNKeRs of the .BoNK-family by Jack Twoflower -=[Lz¨ª]=-"

¶Ç´Ù¸¥ ÆÄÀÏÀÎ c:\start.bat ÆÄÀÏÀÌ »ý¼ºµÇ¸ç, B32NK.REG ÆÄÀÏÀ» ½ÇÇàÇÑ´Ù.
ÀÌ ÆÄÀÏÀÌ ½ÇÇàµÇ¸é ·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ÀÇ Å°°ªÀ» ³²±ä´Ù.
HKEY_CURRENT _USER/Software/VB and VBA Program Settings/VBA/XM97_BoNK/BKCounter"

HKEY_CURRENT _USER/Software/VB and VBA Program Settings/
VBA/XM97_BoNK/Creator = "jack twoflower -=[Lz¨ª]=-"
HKEY_CURRENT _USER/Software/VB and VBA Program Settings/
VBA/XM97_BoNK/Address = "jack_twoflower@hotmail.com"
If counter = 100, the virus will create and execute the file c:\format.bat,
which formats the c:\ and a:\ drive.

Æ÷¸äÀÌ µÉ ¼ö ÀÖ´Â ÄÚµåÀ̹ǷΠÀ§ÇèÇÏ´Ù.
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¸ñ·Ïº¸±â
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
- ¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com