• Åͺ¸¹é½Å
¿£Áø¾÷µ¥ÀÌÆ®
º¸¾È±Ç°í¹®
½ÅÁ¾ ¹ÙÀÌ·¯½º
½ÅÁ¾¾Ç¼ºÄÚµå
¹®ÀÇÇϱâ
¿À´ÃÀÇ º¸¾È°æº¸
Level3 : ÁÖÀÇ
Ãֽо÷µ¥ÀÌÆ® ÇöȲ   document.write("2018.07.06.0");
¹ÙÀÌ·¯½º ½Å°íÇϱâ
½ÅÁ¾¹ÙÀÌ·¯½º
   
¸ñ·Ï¤Ó ÀÎ¼â  
W32/PiBi.B@mm
¹ÙÀÌ·¯½º Á¾·ù Worm ½ÇÇàȯ°æ Win9x, Win2000, NT
¹ß°ßÀÏ 2002³â11¿ù01ÀÏ Á¦ÀÛÁö ºÒºÐ¸í
À§Çèµî±Þ È®»ê¹æ¹ý
¹ÙÀÌ·¯½º Å©±â 32,256 Bytes ÷ºÎÆÄÀÏ install.exe
¸ÞÀÏÁ¦¸ñ Re:hya, WindowsXP Service Release Pack 2.002
Áõ»ó¿ä¾à
Ä¡·á¹æ¹ý Åͺ¸¹é½Å Ai, Åͺ¸¹é½Å 2001 ¶Ç´Â Åͺ¸¹é½Å OnlineÀ¸
·Î Ä¡·á°¡´ÉÇÕ´Ï´Ù.


< Outlook Express >
-
http://www.microsoft.com/windows/ie/downloads/crit
ical/q323759ie/defau
lt.asp

< Outlook 2000 >
-
http://office.microsoft.com/korea/downloads/2000/O
ut2ksec.aspx

< Outlook 2002(Office XP) >
-
http://office.microsoft.com/korea/Downloads/2002/o
xpsp2.aspx

Åͺ¸¹é½Å IS üÇè°ü  Åͺ¸¹é½Å IS ±¸¸Å
»ó¼¼¼³¸í
W32/Pibi@mmÀÇ º¯ÇüÀ¸·Î °¨¿°µÈ À̸ÞÀÏÀÇ Ã·ºÎ ÆÄÀÏ
°ú, KazaA, IRC¸¦ ÅëÇØ ÀüÆÄ µÈ´Ù.
¸¶ÀÌÅ©·Î ¼ÒÇÁÆ® ºñÁÖ¾ó C++·Î ÄÚµùµÇ¾î ÀÖÀ¸¸ç, UPX
¾ÐÃàÇÁ·Î±×·¥À¸·Î ¾ÐÃàµÇ ÀÖ´Ù.
ºÎÁ¤È®ÇÑ MIME Çì´õ¸¦ ÀÌ¿ëÇÏ¿© E-mail÷ºÎÆÄÀÏÀ» ½Ç
ÇàÇϵµ·Ï ¾ß±âÇÏ´Â º¸¾È ¹ö±×¸¦ ÀÌ¿ëÇϹǷΠ¸ÞÀÏÀ» Ŭ
¸¯ ÇÏ´Â °Í¸¸À¸·Î °¨¿°µÉ ¼ö ÀÖ´Ù.

¸ÞÀÏ º»¹®Àº ´ÙÀ½°ú °°´Ù.

Istall the program in the attachment.


ÆÄÀÏÀÌ ½ÇÇàµÇ¸é À©µµ¿ìÀÇ ½Ã½ºÅÛ Æú´õ(win9x :
c:\windows\system,
Win2000 : c:\Winnt\system32)¿¡
WSYXXX.exe¸¦ »ý¼ºÇÑ´Ù.(XXX : ·£´ýÇÑ ¼ýÀÚ)

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre
ntVersion\Run
Ç׸ñ¿¡

Win9x ÀÎ °æ¿ì : Kernel32.dll module  =
c:\windows\system\WSYSXXX.EXE
Win2000 Àΰæ¿ì: Kernel32.dll module  =
c:\winnt\system32\WSYSXXX.EXE
(XXX : ·£´ýÇÑ ¼ýÀÚ)

HKEY_LOCAL_MACHINEN\Software\PieceByPieceB\inf
Ç׸ñ¿¡ yep

¶ÇÇÑ C:\ ·çÆ®¿¡ boot64.binÀ» »ý¼º Çϱ⵵ Çϴµ¥
ÀÌ ÆÄÀÏÀº base64·Î ¾Ð
ÃàµÇ¾î ÀÖ´Â ¹ÙÀÌ·¯½º º»Ã¼ ÆÄÀÏ·Î °¨¿°µÈ ¸ÞÀÏÀ» º¸
³¾¶§ »ç¿ëÇÑ´Ù.


÷ºÎµÈ ÆÄÀÏÀ» ½ÇÇà ÇÏ¸é ´ÙÀ½°ú °°Àº ¿¡·¯ ¸Þ½ÃÁö¸¦
¶ç¿ì¸ç, ½ÇÇàÇÒ¼ö ¾ø
´Â °Íó·³ À§ÀåÇÑ´Ù.

  Error! This process will be terminated.


10¿ù 18ÀÏ¿¡ ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö âÀ» ¶ç¿î´Ù.


  "Sucking back a cigarette
  Thinking about new regrets
  Trying to be someone you'd like to be
  Passing faces on the road
  Where the hell can we still go?
  Leaves us open to temptation..."
           -Feeder


¶ÇÇÑ ´ÙÀ½ ¹®ÀÚ¿­À» °¡Áø ƯÁ¤ ¾ÈƼ ¹ÙÀÌ·¯½ºÀÇ ÇÁ·Î
¼¼½º¸¦ ÁßÁö½ÃŰ´Â ±â
´ÉÀ» °¡Áö°í ÀÖ´Â °ÍÀ¸·Î º¸ÀδÙ.

AV
F-
av
NOD32
SCAN
MON
ALERT
ANTIVIR
PCCW
PCC
FP-
TRAP
TDS2-
VET
SWEEP
MCAFEE
FIREW
DVP
CFI
ICL
VSHW
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¸ñ·Ïº¸±â
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
- ¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com