Home | Data Center | Contact US | Login

Á¦¸ñ ´ë·®ÀÇ ½ºÆÔ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ÇãÀ§¹é½Å À¯Æ÷»ç·Ê ºÐ¼®
÷ºÎÆÄÀÏ 200808.pdf ÀÛ¼ºÀÏ 2008-09-18 12:45:47
´ë·®ÀÇ ½ºÆÔ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ÇãÀ§¹é½Å À¯Æ÷»ç·Ê ºÐ¼®

1. °³¿ä
ÃÖ±Ù ¾Ç¼ºÄÚµå ÀüÆĸ¦ ¸ñÀûÀ¸·Î ¹ß¼ÛµÇ´Â ½ºÆÔ¸ÞÀÏÀÌ Áö¼ÓÀûÀ¸·Î Áõ°¡ÇÏ°í ÀÖ´Ù. ¹ß°ßµÈ ½ºÆÔ¸ÞÀϵéÀº ÇØ¿Ü À¯¸í ¿¬¿¹Àΰú °ü·ÃµÈ ³»¿ëÀ̳ª ÃÖ±Ù »çȸÀûÀ¸·Î À̽´°¡ µÇ°í ÀÖ´Â ³»¿ë°ú ÇÔ²² Ãß°¡ÀûÀÎ Á¤º¸¸¦ Á¦°øÇÏ´Â ¸µÅ©¸¦ Æ÷ÇÔÇÏ°í ÀÖ´Ù. ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇÔµÈ ³»¿ëÀº ´ëºÎºÐ ÇãÀ§ »ç½Ç·Î ¸ÞÀÏ ¼ö½ÅÀÚµéÀÌ °ü·Ã ¸µÅ©¸¦ Ŭ¸¯Çϵµ·Ï À¯µµÇÏ°í ÀÖ´Ù. ÇØ´ç ¸µÅ©¸¦ Ŭ¸¯ÇÒ °æ¿ì, ¾Ç¼ºÄڵ尡 Á÷Á¢ ´Ù¿î·Îµå µÇ°Å³ª ¾Ç¼º Äڵ带 À¯Æ÷ÇÏ´Â »çÀÌÆ®·Î ¿¬°áµÈ´Ù. ÀÌ·¯ÇÑ ¾Ç¼ºÄÚµå À¯Æ÷ ¹æ¹ýÀ» »çȸ°øÇÐÀû ±â¹ýÀ̶ó ÇÑ´Ù.

ÃÖ±Ù ¹ß¼ÛµÈ ½ºÆÔ¸ÞÀÏÀ» ÅëÇØ ´Ù¿î·ÎµåµÈ ¾Ç¼ºÄÚµåµéÀº Á÷Á¢ ½ÇÇàµÇÁö´Â ¾ÊÀ¸³ª ½ºÆÔ¸ÞÀÏ°ú °ü·ÃµÈ ³»¿ëÀÇ µ¿¿µ»ó ÆÄÀÏÀ̳ª ÄÚµ¦À¸·Î À§ÀåÇÏ¿© »ç¿ëÀÚµéÀÇ ½ÇÇàÀ» À¯µµÇÑ´Ù. ½ºÆиӵéÀº ½ºÆÔ¸ÞÀÏ¿¡ Æ÷ÇÔµÈ ³»¿ëÀ̳ª ¾Ç¼ºÄÚµå ¹× ¾Ç¼ºÄÚµå À¯Æ÷Áö¸¦ °è¼Ó º¯°æÇÏ¿©, ½ºÆÔÇÊÅ͸¦ ÀÌ¿ëÇÑ ½ºÆÔ¸ÞÀÏ Â÷´ÜÀ̳ª ¹é½ÅÀ» ÀÌ¿ëÇÑ ¾Ç¼ºÄÚµå Áø´Ü/Ä¡·á¸¦ ¾î·Æ°Ô ÇÏ°í ÀÖ´Ù.

´Ù¿î·ÎµåµÈ ¾Ç¼ºÄÚµåµéÀº ´Ù¾çÇϳª ÁÖ·Î ´Ù¿î·Î´õµé·Î¼­ Á÷Á¢ÀûÀÎ ¾Ç¼ºÇàÀ§´Â ¼öÇàÇÏÁö ¾ÊÁö¸¸ Ãß°¡ ¾Ç¼ºÄÚµå À¯Æ÷Áö·ÎºÎÅÍ ¶Ç ´Ù¸¥ ¾Ç¼ºÄڵ带 ´Ù¿î·ÎµåÇÏ¿© °¨¿° PC¿¡ ¼³Ä¡ÇÑ´Ù. ¼³Ä¡µÈ Ãß°¡ ¾Ç¼ºÄÚµåµéÀº °¨¿° PCÀÇ ¹ÙÅÁÈ­¸é°ú È­¸éº¸È£±â¸¦ º¯°æÇÏ°í ÇãÀ§¹é½ÅÀ» ¼³Ä¡ÇÏ´Â ±×·¹ÀÌ¿þ¾î (Grayware)·Î¼­ »ç¿ëÀÚÀÇ ºÒ¾È ½É¸®¸¦ Á¶ÀåÇÏ¿© ±ÝÀ¶ °áÁ¦¸¦ À¯µµÇÑ´Ù.

À̸ÞÀÏ »ç¿ëÀÚµéÀº ½Å·ÚÇÒ ¼ö ¾ø´Â À̸ÞÀÏÀ̳ª »çÀÌÆ®¸¦ ÅëÇØ ÀǽÉÀÌ °¡´Â ÆÄÀÏÀ» ´Ù¿î·ÎµåÇϰųª ½ÇÇà ÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ, ¿î¿µÃ¼Á¦¿Í ¹é½ÅÇÁ·Î±×·¥ÀÇ ¾÷µ¥ÀÌÆ® ¼­ºñ½º¸¦ ÅëÇÏ¿© ÄÄÇ»ÅÍÀÇ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÃֽŠ»óÅ·ΠÀ¯ÁöÇÏ°í ¹é½ÅÇÁ·Î±×·¥ÀÇ ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ­ÇÏ¿© ¾Ç¼ºÄڵ忡 °¨¿°µÇÁö ¾Êµµ·Ï ¿¹¹æÇÏ´Â °ÍÀÌ Áß¿äÇÏ´Ù.

2. ¾Ç¼ºÄÚµå À¯Æ÷»ç·Ê »ó¼¼
°¡. ¾Ç¼ºÄÚµå À¯Æ÷ °³¿äµµ
À̹ø ¾Ç¼ºÄÚµå À¯Æ÷»ç·Ê¿¡ ´ëÇÑ ÀüüÀûÀÎ °³¿ä´Â ¾Æ·¡ ±×¸²°ú °°ÀÌ ¾Ç¼ºÄÚµå À¯Æ÷ ¼­¹ö, Ãß°¡
¾Ç¼ºÄÚµå ¸ñ·Ï À¯Æ÷ ¼­¹ö, Ãß°¡ ¾Ç¼ºÄÚµå À¯Æ÷ ¼­¹ö ±×¸®°í SMTP ¼­¹ö ¹× °¨¿° PC·Î ÀÌ·ç¾îÁø´Ù.


(±×¸²) ¾Ç¼ºÄÚµå À¯Æ÷ °³¿äµµ

³ª. À¯Æ÷»ç·Ê ´ëÀÀ
À̹ø ´ë·®ÀÇ ½ºÆÔ¸ÞÀÏÀ» ÀÌ¿ëÇÑ ¾Ç¼ºÄÚµå À¯Æ÷»ç·Ê´Â 8¿ù 5ÀÏ ±¹¿Ü º¸¾È »çÀÌÆ®¿¡¼­ ÃÖÃÊ·Î °ü·Ã ³»¿ëÀÌ °ø°³µÇ¾úÀ¸¸ç, ÀÎÅͳÝħÇØ»ç°í´ëÀÀÁö¿ø¼¾ÅÍ¿¡¼­µµ °ü·Ã ¾Ç¼ºÄÚµå ÀÔ¼ö ¹× À¯Æ÷»çÀÌÆ® Â÷´Ü µîÀ» ÅëÇÏ¿© ÇÇÇظ¦ ÃÖ¼ÒÈ­ÇÏ¿´´Ù.

´Ù. ½ºÆÔ¸ÞÀÏ À¯Çü ºÐ¼®

o ½ºÆÔ¸ÞÀÏ Á¦¸ñ ¹× ³»¿ë
½ºÆÔ¸ÞÀÏ Á¦¸ñ¿¡´Â¡®CNN ¼Óº¸¡¯¡®, º£ÀÌ¡ ¿Ã¸²ÇÈ¡¯¡®, ¼¼°è 3Â÷´ëÀü ½ÃÀÛ¡¯µî ÀÎÅÍ³Ý »ç¿ëÀÚµéÀ» ÇöȤÇÏ´Â ¹®±¸°¡ Æ÷ÇԵǾî ÀÖÀ¸¸ç ¸ÞÀÏ ³»¿ë¿¡´Â ÇØ¿Ü¿¬¿¹ÀÎ, µ¿¿µ»ó, Ç÷¹½Ã Ç÷¹À̾î, ÀÎÅÍ³Ý ÀͽºÇ÷η¯ (IE7) ÃֽŹöÀüµîÀ»¾ð±ÞÇÏ¿©¸ÞÀϼö½ÅÀÚµé·ÎÇÏ¿©±Ý¸ÞÀÏ¿¡Æ÷ÇԵȸµÅ©¸¦Å¬¸¯Çϵµ·ÏÀ¯µµÇÔÀ¸·Î½á ¾Ç¼ºÄڵ带 °¨¿°½ÃŲ´Ù.


(±×¸²) ½ºÆÔ¸ÞÀÏ Á¦¸ñ ¹× ³»¿ë

ÀÌ·¯ÇÑ ½ºÆÔ¸ÞÀÏÀÇ Á¦¸ñÀº ¸ÞÀϸ¶´Ù ´Ù¸£°í °è¼Ó º¯°æµÇ³ª ÁÖ·Î ´ÙÀ½°ú °°´Ù.
ÁÖÁ¦
¸ÞÀÏÁ¦¸ñ
CNN CNN Alerts: My Custom Alert
CNN.com Daily Top 10
CNN Alerts: Breaking news
CNN Daily Top 10
Angelina Jolie Angelina Jolie Free Video
Angelina Jolie¡¯s Free Video
Angelina Jolie nude movie
Angelina naked video
Angelina Jolie gives birth to triplets
Angelina Jolie dies in miscarriage
McCain & Obama McCain supports idea that Obama is muslim
Obama admits extra-marital affair
World War Bush unveils Iran invasion plan
US Army invades southern Iran
Olympics Beijing Olympics cancelled
etc We congratulate!

o ¸ÞÀÏ¿¡ ÷ºÎµÈ ¾Ç¼ºÄÚµå ¹× ¾Ç¼ºÄÚµå À¯Æ÷ »çÀÌÆ® ¸µÅ©
¸ÞÀÏ ¼ö½ÅÀÚ´Â ½ºÆÔ¸ÞÀÏ¿¡ ÷ºÎµÈ ¸µÅ©¸¦ Ŭ¸¯ÇÔÀ¸·Î½á ¾Ç¼ºÄڵ尡 Á÷Á¢ ´Ù¿î·Îµå µÇ°Å³ª ¾Ç¼º Äڵ带 À¯Æ÷ÇÏ´Â »çÀÌÆ®·Î ¿¬°áµÈ´Ù.


(±×¸²) À¯Æ÷»çÀÌÆ®¸¦ ÀÌ¿ëÇÏ´Â °æ¿ì¿Í Á÷Á¢ ´Ù¿î·Îµå µÇ´Â °æ¿ì

ÀÌ·¯ÇÑ ¾Ç¼ºÄڵ峪 ¾Ç¼ºÄÚµå À¯Æ÷Áö ÁÖ¼Ò°¡ ¸ÞÀϸ¶´Ù ´Ù¸£³ª ¸ÞÀÏ º»¹®°ú °ü·ÃµÈ ÆÄÀÏÀ̳ª »çÀÌÆ®·Î À§ÀåÇÏ¿© ¾Ç¼ºÄÚµåÀÇ ´Ù¿î·Îµå ¹× ½ÇÇàÀ» À¯µµÇÑ´Ù. ¾Ç¼ºÄÚµå À¯Æ÷Áö¸¦ ÅëÇÏ¿© ¾Ç¼º Äڵ尡 ´Ù¿î·Îµå µÇ´Â °æ¿ì¿¡´Â »çÀÌÆ®¿¡¼­ Á¦°øÇÏ´Â µ¿¿µ»óÀ» °¨»óÇϱâ À§ÇØ ÇÊ¿äÇÑ ÄÚµ¦ÀÇ ¼³Ä¡ ÆÄÀÏ·Î ¾Ç¼ºÄڵ带 À§ÀåÇÏ°í ÀÖ´Ù. ´Ù¿î·Îµå µÇ´Â ¾Ç¼ºÄÚµåµéÀº ÁÖ·Î ´ÙÀ½°ú °°Àº ÆÄÀϸíÀ» °¡Áö°í ÀÖ´Ù.
xvideo.avi.exe, update.exe, Paris-nude-video.avi.exe, video.avi.exe, flash.exe,
video54582.exe, video9865565.exe, video-anjelina.avi.exe, windows_media.exe, videonude-
anjelia.avi.exe, video435ki.exe, flashupdate.exe, shok_video.exe,
flashcodecinstall_13_31.exe, watch.exe, codecinst.exe, video1.exe, video.exe,
hot_video.exe, video_film.exe, xxx.exe, videousa.exe, video6.exe, video12.exe,
watchmovie.mpg.exe, msvideoc.exe

¶ó. ¾Ç¼ºÄÚµå ºÐ¼®
o ¾Ç¼ºÄÚµå °¨¿° ÀýÂ÷
¨ç ¾Ç¼ºÄÚµå À¯Æ÷ ¼­¹ö·ÎºÎÅÍ ´Ù¿î·ÎµåµÈ get_flash_update.exe¸¦ ½ÇÇà½ÃÅ°¸é C:\WINDOWS\ system32\CbEvtSvc.exeÀÇ °æ·Î·Î Àڱ⠺¹Á¦¸¦ ÇÏ°í ½ÇÇà½ÃÅ´À¸·Î½á ¾Ç¼ºÇàÀ§¸¦ ½ÃÀÛÇÑ´Ù.

(±×¸²) ¾Ç¼ºÄÚµå º¹»ç

¨è CbEvtSvc.exe¸¦ ´ÙÀ½°ú °°Àº ¼­ºñ½º·Î µî·ÏÇÏ¿© ½Ã½ºÅÛ ½ÃÀÛ ½Ã ÀÚµ¿ ½ÇÇàµÇµµ·Ï ÇÑ´Ù.
Name: CbEvtSvc
Display Name: CbEvtSvc
Description: (¾øÀ½)
Module: C:\WINDOWS\system32\CbEvtSvc.exe


(±×¸²) ¼­ºñ½º µî·Ï

¨é CbEvtSvc.exe´Â ¿ì¼± Ãß°¡ ¾Ç¼ºÄÚµå ¸ñ·Ï À¯Æ÷ÁöÀÎ https://66.199.xxx.xxx¿¡ Á¢¼ÓÇÏ¿© Ãß°¡ ¾Ç¼ºÄÚµå ¸ñ·ÏÀÎ /ldrctl/ldrtcl.php¸¦ ¹Þ¾Æ¿Í ÀÌ¿¡ Æ÷ÇԵǾî ÀÖ´Â ÁÖ¼Ò¸¦ ÅëÇØ Ãß°¡ ¾Ç¼ºÄÚµåµéÀÇ À§Ä¡¸¦ ÆľÇÇÑ´Ù. Ãß°¡ ¾Ç¼ºÄÚµå ¸ñ·Ï À¯Æ÷Áö ÁÖ¼Ò ¹× ¸ñ·Ï ÆÄÀϸíÀº CbEvtSvc.exe¿¡ ÇϵåÄÚµù µÇ¾îÀÖ´Ù.

¨ê CbEvtSvc.exe´Â Ãß°¡ ¾Ç¼ºÄÚµå ¸ñ·Ï¿¡ Æ÷ÇԵǾî ÀÖ´Â Ãß°¡ ¾Ç¼ºÄÚµåµéÀ» ´Ù¿î·ÎµåÇÏ¿© ½ÇÇà ½ÃŲ´Ù. Ãß°¡ ´Ù¿î·Îµå ¹× ½ÇÇàµÈ ¾Ç¼ºÄÚµåµéÀº ´ÙÀ½°ú °°´Ù.
http://78.109.xxx.xxx/04scan.exe
http://78.109.xxx.xxx/install.exe


¨ë Ãß°¡·Î ´Ù¿î·Îµå µÈ 04scan.exe°¡ ½ÇÇàµÇ¸é PCÀÇ ¹ÙÅÁÈ­¸é, È­¸éº¸È£±â µîÀ» º¯°æÇÏ°í ÇãÀ§¹é½ÅÀ» ¼³Ä¡ÇÑ´Ù.

¨ì Ãß°¡·Î ´Ù¿î·Îµå µÈ install.exe°¡ ½ÇÇàµÇ¸é google, yahoo, aol, microsoft, frontbridge µîÀÇ SMTP ¼­¹ö·Î Á¢¼ÓÀ» ½ÃµµÇÏ°í ±× °á°ú¸¦ ƯÁ¤ »çÀÌÆ®·Î Àü´ÞÇÑ´Ù.

o ¾Ç¼ºÄڵ忡 °¨¿°µÈ PC¿¡¼­ ¹ß»ýÇÏ´Â ÇÇÇØ Áõ»ó
- ¾Ç¼ºÄڵ尡 ½ÇÇàµÇ¸é ¿ì¼± ¹ÙÅÁÈ­¸éÀ» ´ÙÀ½°ú °°ÀÌ º¯°æÇÏ¿© PC°¡ ½ºÆÄÀÌ¿þ¾î¿¡ °¨¿°µÇ¾úÀ¸´Ï ¹é½ÅÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù°í »ç¿ëÀÚ¿¡°Ô °æ°íÇÑ´Ù.

(±×¸²) ¹ÙÅÁÈ­¸é º¯°æ

- ¶ÇÇÑ, ´ÙÀ½°ú °°Àº À©µµ¿ìÁî ¿À·ù È­¸éÀ¸·Î È­¸éº¸È£±â¸¦ º¯°æÇÏ¿© ½ÇÁ¦·Î »ç¿ëÀÚ PC¿¡ ¾Ç¼ºÄڵ尡 °¨¿°µÇ¾î ÀÖ´Â °Íó·³ º¸À̵µ·Ï ÇÑ´Ù.

(±×¸²) È­¸éº¸È£±â º¯°æ

- ÀÌ¿Í °°Àº ¾Ç¼ºÇàÀ§µéÀº »ç¿ëÀÚ·Î ÇÏ¿©±Ý ´ÙÀ½°ú °°ÀÌ "Antivirus XP 2008"À̶ó´Â ÇãÀ§¹é½ÅÀ» ¼³Ä¡Çϵµ·Ï À¯µµÇϱâ À§ÇÔÀÌ´Ù.

(±×¸²) ÇãÀ§¹é½Å ¼³Ä¡ µ¿ÀÇ È­¸é

- ¾Ç¼ºÄڵ忡 ÀÇÇØ ½ÇÇàµÈ ¼³Ä¡ ÇÁ·Î±×·¥ÀÌ »ç¿ëÀÚ·Î ÇÏ¿©±Ý ÇãÀ§¹é½ÅÀÇ ¼³Ä¡ µ¿ÀǸ¦ ¾ò°í´Â ÀÖÀ¸³ª »ç¿ëÀÚ°¡ ¼³Ä¡¸¦ °ÅºÎÇÒ ¼ö´Â ¾øµµ·Ï ¸¸µé¾î ÇãÀ§¹é½ÅÀ» °­Á¦·Î ¼³Ä¡Çϵµ·Ï ÇÏ°í ÀÖ´Ù. ¼³Ä¡µÈ ÇãÀ§¹é½ÅÀº »ç¿ëÀÚ PC¸¦ Áø´ÜÇÑ µÚ, ´Ù·®ÀÇ ¾Ç¼ºÄڵ尡 °¨¿°µÇ¾î Àִٸ鼭 Ä¡·áÇÒ °ÍÀ» ±ÇÀ¯ÇÏ°í ÀÖ´Ù.

(±×¸²) ÇãÀ§¹é½ÅÀÇ ÇãÀ§Áø´Ü °á°ú

- ¾Ç¼ºÄÚµå Ä¡·á¸¦ À§ÇØ¡°¿¹(Y)¡±¹öÆ°À» ´©¸£¸é ´ÙÀ½°ú °°ÀÌ µî·ÏµÇÁö ¾ÊÀº Á¦Ç°ÀÌ´Ï Ä¡·á¸¦ À§Çؼ­´Â ¶óÀ̼¾½º Å°¸¦ ±¸ÀÔÇ϶ó°í ÇÑ´Ù. ½ÇÁ¦, ÇãÀ§¹é½Å¿¡¼­ Áø´ÜÇÑ ¾Ç¼ºÄÚµåµéÀº »ç¿ëÀÚ PC¿¡ Á¸ÀçÇÏÁö ¾ÊÀ¸¸ç »ç¿ëÀÚ°¡ ÇãÀ§¹é½ÅÀ» ±¸ÀÔÇϵµ·Ï À¯µµÇϱâ À§ÇØ Á¦°øÇÑ °ÅÁþ Á¤º¸ÀÌ´Ù.


(±×¸²) ÇãÀ§¹é½Å µî·Ï È­¸é

- Á¦Ç° µî·ÏÀ» À§ÇØ ÇÏ´Ü¿¡ À§Ä¡ÇÑ "Click here to switch to the Full Mode." ¹öÆ°À̳ª "Get license" ¹öÆ°À» ´©¸¦ °æ¿ì, ´ÙÀ½°ú °°Àº ¶óÀ̼¾½º ±¸ÀÔ »çÀÌÆ®·Î ¿¬°áµÈ´Ù.

(±×¸²) ÇãÀ§¹é½Å ±¸¸Å »çÀÌÆ®

- ¶óÀ̼¾½º ±¸ÀÔÀ» À§ÇØ "Pay by creadit card" ¹öÆ°À» ´­·¶À» °æ¿ì, ´ÙÀ½°ú °°Àº ½Å¿ëÄ«µå °áÁ¦ »çÀÌÆ®°¡ ¿­¸°´Ù. ÇØ´ç °áÁ¦ »çÀÌÆ®´Â »ç¿ëÀÚ°¡ °³ÀÎÁ¤º¸ ¹× ½Å¿ëÄ«µå Á¤º¸¸¦ ÀÔ·ÂÇÏ°í ¡°Process transaction¡±¹öÆ°À» ´©¸£¸é °áÁ¦°¡ ÁøÇàµÇµµ·Ï µÇ¾î ÀÖ´Ù. ÇØ´ç °áÁ¦ »çÀÌÆ®´Â ÇÇ½Ì »çÀÌÆ®°¡ ¾Æ´Ñ ½ÇÁ¦·Î ½Å¿ëÄ«µå °áÁ¦°¡ ÀÌ·ç¾îÁö´Â »çÀÌÆ®·Î¼­ »ç¿ëÀÚµéÀÌ °áÁ¦¸¦ ÁøÇàÇÒ °æ¿ì¿¡´Â ±ÝÀüÀûÀÎ ÇÇÇظ¦ ÀÔÀ» À§Ç輺ÀÌ ÀÖ´Ù.

(±×¸²) ÇãÀ§¹é½Å °áÁ¦ »çÀÌÆ®

ÀÌó·³ ¾Ç¼ºÄÚµå À¯Æ÷ÀÚ´Â ½ºÆÔ¸ÞÀÏ°ú ¾Ç¼ºÄڵ带 ÀÌ¿ëÇÏ¿© »ç¿ëÀÚ PC¿¡ ÇãÀ§¹é½ÅÀ» ¼³Ä¡ÇÏ°í À̸¦ ÅëÇÏ¿© À߸øµÈ Áø´Ü °á°ú¸¦ »ç¿ëÀÚ¿¡°Ô Á¦°øÇÏ´Â ¹æ½ÄÀ¸·Î, Ä¡·á¸¦ À§ÇÑ »ç¿ëÀÚ °áÀ縦 À¯µµÇÏ°í ÀÖ´Ù. »ç¿ëÀÚ´Â ±ÝÀüÀûÀÎ ÇÇÇظ¦ ¿¹¹æÇϱâ À§ÇÏ¿© ÀÎÅÍ³Ý »ó¿¡¼­ ÀÌ¿Í µ¿ÀÏÇϰųª À¯»çÇÑ ¹æ½ÄÀ¸·Î ±ÝÀ¶ °áÁ¦¸¦ ¿ä±¸ÇÏ´Â »óȲÀ» Á¢ÇÏ°Ô µÉ °æ¿ì °¢º°È÷ ÁÖÀÇÇØ¾ß ÇÑ´Ù.

¸¶. Ä¡·á ¹æ¹ý
¨ç ºÎÆà ½Ã F8À» ´­·¯ ¾ÈÀü¸ðµå¸¦ ¼±ÅÃÇÑ´Ù.
¨è ¾Æ·¡ÀÇ Æú´õ¿Í ÆÄÀϵéÀÌ Á¸ÀçÇÏ¸é »èÁ¦ÇÑ´Ù. (*Àº ÀÓÀÇÀÇ ¼ýÀÚ È¤Àº ¹®ÀÚ)

- C:\WINDOWS\system32\CbEvtSvc.exe
- C:\WINDOWS\system32\lphc***j0e***.exe
- C:\WINDOWS\system32\pphc***j0e***.exe
- C:\WINDOWS\system32\phc***j0e***.bmp
- C:\WINDOWS\system32\blphc***j0e***.scr
- C:\WINDOWS\system32\drivers\54c70b2e.sys
- C:\WINDOWS\qegbdmwf.dll
- C:\WINDOWS\pntqkflv.dll
- C:\Program Files\rhc***j0e***
- C:\Program Files\rhc***j0e***\database.dat
- C:\Program Files\rhc***j0e***\license.txt
- C:\Program Files\rhc***j0e***\MFC71.dll
- C:\Program Files\rhc***j0e***\MFC71ENU.DLL
- C:\Program Files\rhc***j0e***\msvcp71.dll
- C:\Program Files\rhc***j0e***\msvcr71.dll
- C:\Program Files\rhc***j0e***\rhc***j0e***.exe
- C:\Program Files\rhc***j0e***\rhc***j0e***.exe.local
- C:\Program Files\rhc***j0e***\rhc***j0e***Skin.dll
- C:\Program Files\rhc***j0e***\Uninstall.exe
- C:\Documents and Settings\All Users\¹ÙÅÁ È­¸é\Antivirus XP 2008.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008\Antivirus XP 2008.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008\License Agreement.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008\Register Antivirus XP 2008.lnk
- C:\Documents and Settings\All Users\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Antivirus XP 2008\Uninstall.lnk
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
- %UserProfile%\Application Data\rhc***j0e***
- %UserProfile%\Application Data\rhc***j0e***\Quarantine
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\HKCU
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\HKCU\RunOnce
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\HKLM
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\HKLM\RunOnce
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\StartMenuAllUsers
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Autorun\StartMenuCurrentUser
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\BrowserObjects
- %UserProfile%\Application Data\rhc***j0e***\Quarantine\Packages

¨é¡°½ÃÀÛ¡±?¡° ½ÇÇࡱ¿¡¼­ regedit¸¦ ÀÔ·ÂÇÏ°í È®ÀÎ ¹öÆ°À» ´©¸¥´Ù.

¨ê ¾Æ·¡ÀÇ ·¹Áö½ºÆ®¸® Ç׸ñµéÀÌ Á¸ÀçÇÏ¸é »èÁ¦ÇÑ´Ù. (*Àº ÀÓÀÇÀÇ ¼ýÀÚ È¤Àº ¹®ÀÚ)

- HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE
- HKEY_CURRENT_USER\Control Panel\Desktop\ConvertedWallpaper
- HKEY_CURRENT_USER\Control Panel\Desktop\OriginalWallpaper
- HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage
- HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc
- HKEY_LOCAL_MACHINE\SOFTWARE\rhc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rhc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pphc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SMrhc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc***j0e***
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\
Post Platform\AntivirXP08

¨ë ÀçºÎÆÃÇÑ´Ù

¹Ù. ¿¹¹æ ¹æ¹ý
¿ì¼±, À̸ÞÀÏ »ç¿ëÀÚµéÀº ½Å·ÚÇÒ ¼ö ¾ø´Â À̸ÞÀÏÀ̳ª ÷ºÎµÈ ¸µÅ©¸¦ ÅëÇØ Á¢¼ÓÇÑ »çÀÌÆ®ÀÇ ¹®±¸¿¡ ÇöȤµÇ¾î ÀǽÉÀÌ °¡´Â ÆÄÀÏÀ» ´Ù¿î·ÎµåÇϰųª ½ÇÇàÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇØ¾ß ÇÑ´Ù.
¶ÇÇÑ, ¿î¿µÃ¼Á¦¿Í ¹é½ÅÇÁ·Î±×·¥ÀÇ ¾÷µ¥ÀÌÆ® ¼­ºñ½º¸¦ »ç¿ëÇÏ¿© ÄÄÇ»ÅÍÀÇ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÃֽŠ»óÅ·ΠÀ¯ÁöÇÏ°í ¹é½ÅÇÁ·Î±×·¥ÀÇ ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ­ÇÏ¿© ¾Ç¼ºÄڵ忡 °¨¿°µÇÁö ¾Êµµ·Ï ¿¹¹æÇÑ´Ù.

3. °á·Ð
ÃÖ±Ù ´ë·® ¹ß¼ÛµÈ ½ºÆÔ¸ÞÀϵéÀº ÇØ¿Ü À¯¸í ¿¬¿¹Àΰú °ü·ÃµÈ ³»¿ëÀ̳ª ÃÖ±Ù »çȸÀûÀ¸·Î À̽´°¡ µÇ°í ÀÖ´Â ³»¿ëÀ» Æ÷ÇÔÇÏ¿© ¸ÞÀÏ ¼ö½ÅÀÚ·Î ÇÏ¿©±Ý ¾Ç¼ºÄڵ带 ´Ù¿î·ÎµåÇϵµ·Ï À¯µµÇÏ°í ÀÖ´Ù. ´Ù¿î·Îµå µÈ ¾Ç¼ºÄڵ峪 ¾Ç¼ºÄÚµå À¯Æ÷ÁöÀÇ ÁÖ¼Ò´Â ´Ù¾çÇϳª ´ëºÎºÐÀÇ ¾Ç¼ºÄÚµåµéÀÌ »ç¿ëÀÚ PC¿¡ °¨¿°µÈ ÈÄ¿¡ ¡°Antivirus XP 2008¡°À̶ó´Â ÇãÀ§¹é½ÅÀ» ¼³Ä¡ÇÏ°í ÀÖ´Ù. °¨¿°µÈ ¾Ç¼ºÄÚµå´Â ¼³Ä¡ÇÑ ÇãÀ§¹é½ÅÀ» ÅëÇØ À߸øµÈ Áø´Ü °á°ú¸¦ Á¦°øÇÔÀº ¹°·Ð, °¨¿° PCÀÇ ¹ÙÅÁÈ­¸é°ú È­¸éº¸È£±â±îÁö º¯°æÇÔÀ¸·Î½á Àû±ØÀûÀ¸·Î »ç¿ëÀÚÀÇ ÇãÀ§¹é½Å ±¸ÀÔÀ» À¯µµÇÏ°í ÀÖ´Ù.

ÀÌ¿Í °°Àº ½ºÆÔ¸ÞÀÏ·Î ÀÎÇÑ ÇÇÇظ¦ ¿¹¹æÇϱâ À§Çؼ­´Â À̸ÞÀÏ »ç¿ëÀÚµéÀº ½Å·ÚÇÒ ¼ö ¾ø´Â À̸ÞÀÏÀÇ ³»¿ëÀ̳ª °ü·Ã ¸µÅ©¸¦ ÅëÇØ Á¢¼ÓÇÑ »çÀÌÆ®ÀÇ ¹®±¸¿¡ ÇöȤµÇ¾î ÀǽÉÀÌ °¡´Â ÆÄÀÏÀ» ´Ù¿î·ÎµåÇϰųª ½ÇÇàÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ, ¾Ç¼ºÄÚµåÀÇ °¨¿°À» ¸·±â À§Çؼ­´Â ¿î¿µÃ¼Á¦¿Í ¹é½ÅÇÁ·Î±×·¥ÀÇ ¾÷µ¥ÀÌÆ® ¼­ºñ½º¸¦ »ç¿ëÇÏ¿© ÄÄÇ»ÅÍÀÇ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÃֽŠ»óÅ·ΠÀ¯ÁöÇÏ°í ¹é½ÅÇÁ·Î±×·¥ÀÇ ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ­ÇÏ¿©¾ß ÇÑ´Ù. ¸¶Áö¸·À¸·Î, ½Å·ÚÇÒ ¼ö ¾ø´Â »çÀÌÆ®¸¦ ÅëÇÏ¿© °³ÀÎ Á¤º¸³ª ½Å¿ëÄ«µå Á¤º¸¸¦ Á¦°øÇÏÁö ¾Êµµ·Ï ÁÖÀÇÇÔÀ¸·Î½á ±ÝÀüÀûÀÎ ÇÇÇظ¦ ¸·µµ·Ï ÇÑ´Ù.


[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
  MYSQL ¸¹ÀÌ »ç¿ëÇÏ´Â ¸í·É¾î
  ASP À¥½© »ó¼¼ ºÐ¼® ¹× ŽÁö ¹æ¾È





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ