W32.Netsky.B@mm |
|
| ¹ß°ßµÈ ½Ã±â: 2004/02/18 | | ÃÖ±Ù ¾÷µ¥ÀÌÆ® ½Ã±â: 2004/02/25 |
W32.Netsky.B@mmÀº ÀÚü SMTP ¿£ÁøÀ» »ç¿ëÇÏ¿© ·ÎÄà µå¶óÀÌºê ¹× °øÀ¯ µå¶óÀ̺꿡¼ ¼öÁýÇÑ ¸ÞÀÏ ÁÖ¼Ò·Î ¸ÞÀÏÀ» ´ë·®À¸·Î ¹ß¼ÛÇÏ´Â ¿ú ÀÔ´Ï´Ù. ¶ÇÇÑ µå¶óÀÌºê ¹®ÀÚ(C:- Z:) °Ë»öÇÏ¿© "Share" ¶Ç´Â "Sharing"À» Æ÷ÇÔÇÏ´Â Æú´õ À̸§À» ¹ß°ßÇÏ¸é ±× °÷¿¡ ÀÚ½ÅÀ» º¹Á¦ÇÕ´Ï´Ù.
¿úÀÌ ¹ß¼ÛÇÑ ¸ÞÀÏÀÇ Á¦¸ñ ¹× ÷ºÎ ÆÄÀÏÀÇ ÇüÅ´ ´Ù¾çÇÕ´Ï´Ù.
Âü°í:
- º£Å¸ ¹ÙÀÌ·¯½º Á¤ÀÇ 27994, 2¿ù 18ÀÏ ¿ÀÀü 3½Ã 30ºÐ(¹Ì±¹ ¼ºÎ ½Ã°£), ¶Ç´Â ÀÌÈÄ¿¡ Á¦ÀÛµÈ ¹ÙÀÌ·¯½º Á¤ÀÇ´Â ¿úÀ» ŽÁöÇÒ ¼ö ÀÖ½À´Ï´Ù.
- ½Ã¸¸ÅØ º¸¾È ¿¬±¸¼Ò(Symantec Security Response)¿¡¼ W32.Netsky.B@mm °¨¿°À» Á¦°ÅÇÒ ¼ö ÀÖ´Â Àü¿ë Á¦°Å µµ±¸¸¦ Á¦ÀÛ ¹èÆ÷Çϰí ÀÖ½À´Ï´Ù. µµ±¸¸¦ ÀÌ¿ëÇÏ½Ã¸é ¼Õ½±°Ô °¨¿°À» Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.
|
´Ù¸¥ À̸§: | W32/Netsky.b@MM [McAfee], W32/Netsky.B.worm [Panda], WORM_NETSKY.B [Trend Micro], Moodown.B [F-Secure], I-Worm.Moodown.b [Kaspersky] |
|
º¯Á¾: | W32.Netsky@mm |
|
¹ÙÀÌ·¯½º Á¾·ù: | Worm |
|
°¨¿° ±æÀÌ: | 22,016 bytes |
|
| |
|
| |
|
| |
|
¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ: | Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP |
|
¿µÇâÀ» ¹ÞÁö ¾Ê´Â ½Ã½ºÅÛ: | Linux, Macintosh, UNIX, Windows 3.x |
|
| |
|
| |
|
| |

ÇÇÇØµµ
¹èÆ÷

W32.Netsky@mm ¿úÀÌ ½ÇÇà µÉ ¶§, ´ÙÀ½°ú °°Àº Çö»óÀÌ ¹ß»ýÇÕ´Ï´Ù.
- "AdmSkynetJKIS003" ¹ÂÅØ½º(mutex)¸¦ »ý¼ºÇÕ´Ï´Ù. ÀÌ ¹ÂÅØ½º´Â ¿úÀÌ Çѹø ¸¸ ½ÇÇàµÇµµ·Ï ÇÕ´Ï´Ù.
- ¾Æ·¡ÀÇ ¸Þ½ÃÁö¸¦ ´ãÀº ´ëÈâÀÌ ³ªÅ¸³¯ ¼öµµ ÀÖ½À´Ï´Ù.
The file could not be opened!
- %Windows Æú´õ%\services.exeÀ¸·Î º¹Á¦ÇÕ´Ï´Ù.
Âü°í: %Windows Æú´õ% Àº º¯¼öÀÔ´Ï´Ù. ¿úÀº Windows ¼³Ä¡ Æú´õ(±âº» ¼³Á¤: C:\Windows ¶Ç´Â C:\Winnt)ÀÇ À§Ä¡¸¦ ÆÄ¾ÇÇÏ°í ±× °÷¿¡ ÀÚ½ÅÀ» º¹Á¦ÇØ ³õ½À´Ï´Ù.
- ´ÙÀ½ ·¹Áö½ºÆ®¸®¿¡
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¾Æ·¡ÀÇ °ªÀ» Ãß°¡ÇÕ´Ï´Ù.
"service" = "%Windir%\services.exe -serv"
ÀÌ·¸°Ô Çϸé Windows¸¦ ´Ù½Ã ½ÃÀÛÇÒ ¶§ ¿úÀÌ ½ÇÇàµË´Ï´Ù.
- ´ÙÀ½ ·¹Áö½ºÆ®¸®¿¡¼
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
¾Æ·¡ÀÇ °ªÀ» »èÁ¦ÇÕ´Ï´Ù.
- "Taskmon"
- "Explorer"
- ´ÙÀ½ ·¹Áö½ºÆ®¸®¿¡¼
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¾Æ·¡ÀÇ °ªÀ» »èÁ¦ÇÕ´Ï´Ù.
- "KasperskyAV"
- "System."
- ´ÙÀ½ ·¹Áö½ºÆ®¸® ۸¦ »èÁ¦ÇÕ´Ï´Ù.
HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
- ´ÙÀ½°ú °°Àº È®ÀåÀÚ·Î µÈ ÆÄÀÏ¿¡¼ ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ ¼öÁýÇÕ´Ï´Ù.
- .msg
- .oft
- .sht
- .dbx
- .tbb
- .adb
- .doc
- .wab
- .asp
- .uin
- .rtf
- .vbs
- .html
- .htm
- .pl
- .php
- .txt
- .eml
- µå¶óÀÌºê ¹®ÀÚ(C:ºÎÅÍ Z:±îÁö)¸¦ °Ë»öÇÏ¿© "Share" ¶Ç´Â "Sharing" ¹®ÀÚ¸¦ µå¶óÀ̺ê À̸§¿¡ Æ÷ÇÔÇϰí ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
¹®ÀÚ¸¦ Æ÷ÇÔÇϰí ÀÖ´Â µå¶óÀ̺ê(CD-ROM Á¦¿Ü)¿Í ÇÏÀ§ Æú´õ¿¡ ÀÚ½ÅÀ» ¾Æ·¡¿¡ ³ª¿µÈ ÆÄÀÏ·Î º¹»çÇÕ´Ï´Ù.
- doom2.doc.pif
- sex sex sex sex.doc.exe
- rfc compilation.doc.exe
- dictionary.doc.exe
- win longhorn.doc.exe
- e.book.doc.exe
- programming basics.doc.exe
- how to hack.doc.exe
- max payne 2.crack.exe
- e-book.archive.doc.exe
- virii.scr
- nero.7.exe
- eminem - lick my pussy.mp3.pif
- cool screensaver.scr
- serial.txt.exe
- office_crack.exe
- hardcore porn.jpg.exe
- angels.pif
- porno.scr
- matrix.scr
- photoshop 9 crack.exe
- strippoker.exe
- dolly_buster.jpg.pif
- winxp_crack.exe
- ÀÚü SMTP ¿£ÁøÀ» »ç¿ëÇÏ¿© ¼öÁýÇÑ ¸ÞÀÏ ÁÖ¼Ò·Î ½º½º·Î º¹Á¦ Àü¼ÛÇÕ´Ï´Ù.
ÀÌ ÀüÀÚ ¸ÞÀÏÀº ´ÙÀ½°ú °°Àº Ư¡À» Áö³æ½À´Ï´Ù.
¹ß½ÅÀÚ: (À§ÀåµÈ ¹ß½Å ÁÖ¼Ò)
Á¦¸ñ: ´ÙÀ½ Áß Çϳª°¡ ÇØ´çµË´Ï´Ù.
- hi
- hello
- read it immediately
- something for you
- warning
- information
- stolen
- fake
- unknown
¸Þ½ÃÁö: ´ÙÀ½ Áß Çϳª°¡ ÇØ´çµË´Ï´Ù.
- anything ok?
- what does it mean?
- ok
- i'm waiting
- read the details.
- here is the document.
- read it immediately!
- my hero
- here
- is that true?
- is that your name?
- is that your account?
- i wait for a reply!
- is that from you?
- you are a bad writer
- I have your password!
- something about you!
- kill the writer of this document!
- i hope it is not true!
- your name is wrong
- i found this document about you
- yes, really?
- that is bad
- here it is
- see you
- greetings
- stuff about you?
- something is going wrong!
- information about you
- about me
- from the chatter
- here, the serials
- here, the introduction
- here, the cheats
- that's funny
- do you?
- reply
- take it easy
- why?
- thats wrong
- misc
- you earn money
- you feel the same
- you try to steal
- you are bad
- something is going wrong
- something is fool
÷ºÎ ÆÄÀÏ À̸§: ´ÙÀ½ Áß Çϳª°¡ ÇØ´çµË´Ï´Ù.
- document
- msg
- doc
- talk
- message
- creditcard
- details
- attachment
- me
- stuff
- posting
- textfile
- concert
- information
- note
- bill
- swimmingpool
- product
- topseller
- ps
- shower
- aboutyou
- nomoney
- found
- story
- mails
- website
- friend
- jokes
- location
- final
- release
- dinner
- ranking
- object
- mail2
- part2
- disco
- party
- misc
÷ºÎ ÆÄÀÏ È®ÀåÀÚ¸í 1: ´ÙÀ½ Áß Çϳª°¡ ÇØ´çµË´Ï´Ù.
- .txt
- .rtf
- .doc
- .htm
÷ºÎ ÆÄÀÏ È®ÀåÀÚ¸í 2: ´ÙÀ½ Áß Çϳª°¡ ÇØ´çµË´Ï´Ù.
- .exe
- .scr
- .com
- .pif
- %Windows Æú´õ% Æú´õ¿¡ ¿úÀ» Æ÷ÇÔÇÏ´Â 40°³ÀÇ ¾ÐÃà ÆÄÀÏ(.zip)À» »ý¼ºÇÕ´Ï´Ù. »ý¼ºµÈ ¾ÐÃà ÆÄÀÏ À̸§Àº À§¿¡¼ ¾ð±ÞÇÑ Ã·ºÎ ÆÄÀÏ Á¤º¸¸¦ ÂüÁ¶ÇϽʽÿÀ.

½Ã¸¸ÅØ º¸¾È ¿¬±¸¼Ò´Â ¸ðµç »ç¿ëÀÚ ¹× °ü¸®ÀÚ°¡ ´ÙÀ½ ±âº» º¸¾ÈÀ» "ÃÖ»óÀÇ ¼º´É"À» ÁؼöÇϵµ·Ï ±ÇÀåÇÕ´Ï´Ù.
- ÇÊ¿äÇÏÁö ¾ÊÀº ¼ºñ½º´Â ²ô°í Á¦°ÅÇϽʽÿÀ. ±âº» ¼³Á¤À¸·Î, ¸¹Àº ¿î¿µ üÁ¦´Â FTP Ŭ¶óÀ̾ðÆ®, ÅÚ³Ý ¹× À¥ ºê¶ó¿ìÀú¿Í °°ÀÌ Áß¿äÇÏÁö ¾ÊÀº Ãß°¡ ¼ºñ½º¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ¼ºñ½º´Â °ø°Ý¿¡ Ãë¾àÇÕ´Ï´Ù. ÀÌµé ¼ºñ½º°¡ Á¦°ÅµÇ¸é È¥ÇÕµÈ À§ÇùÀÇ °¡´É¼ºÀÌ ÁÙ¾îµé°í ÆÐÄ¡ ¾÷µ¥ÀÌÆ®¸¦ ÅëÇØ À¯Áö º¸¼öÇØ¾ß ÇÏ´Â ¼ºñ½º°¡ ÁÙ¾îµé°Ô µË´Ï´Ù.
- È¥ÇÕµÈ À§ÇèÀÌ ¿©·¯°³ÀÇ ³×Æ®¿öÅ© ¼ºñ½º¸¦ ÀÌ¿ëÇÏ´Â °æ¿ì, ÆÐÄ¡¸¦ Àû¿ëÇÒ ¶§±îÁö ÀÌµé ¼ºñ½ºÀÇ ½ÇÇàÀ» ÁßÁöÇϰųª ¾×¼¼½º¸¦ Â÷´ÜÇϽʽÿÀ.
- ƯÈ÷ HTTP, FTP, ¸ÞÀÏ ¹× DNS ¼ºñ½º¿Í °°Àº °ø¿ë ¼ºñ½º¸¦ È£½ºÆ® ¿¬°áÇÏ°í ¹æÈº®À» ÅëÇØ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛÀÇ ÆÐÄ¡ ¼öÁØÀ» ÃÖ½ÅÀ¸·Î À¯ÁöÇϽʽÿÀ.
- ¾ÏÈ£ Á¤Ã¥À» ½ÇÇàÇϽʽÿÀ. º¹ÀâÇÑ ¾ÏÈ£¸¦ »ç¿ëÇÏ¸é °¨¿°µÈ ½Ã½ºÅÛ¿¡¼ ¾ÏÈ£ ÆÄÀÏÀÇ ÆÄ±«°¡ ¾î·Á¿ö Áý´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ½Ã½ºÅÛÀÌ °¨¿°µÇ¾úÀ» ¶§ ¼Õ»óÀ» ¹æÁö ¶Ç´Â Á¦ÇÑÇÏ´Â µ¥ µµ¿òÀÌ µË´Ï´Ù.
- .vbs, .bat, .exe, .pif and .scr ÆÄÀϰú °°ÀÌ ¹ÙÀÌ·¯½º¸¦ È®»êÇÏ´Â µ¥ ÀϹÝÀûÀ¸·Î »ç¿ëµÇ´Â ÷ºÎ ÆÄÀÏÀ» Æ÷ÇÔÇÏ´Â ÀüÀÚ ¸ÞÀÏÀ» Â÷´ÜÇϰųª Á¦°ÅÇϵµ·Ï ÀüÀÚ ¸ÞÀÏ ¼¹ö¸¦ ¼³Á¤ÇϽʽÿÀ.
- °¨¿°µÈ ½Ã½ºÅÛÀ» Áï½Ã ºÐ¸®½Ã۸é ÀÌÈÄ¿¡ »ç¿ëÀÚ Á¶Á÷ÀÇ ¼Õ»óÀ» ¹æÁöÇÕ´Ï´Ù. ³í¸®ÀûÀÎ ºÐ¼®À» ¼öÇàÇÏ°í ½Å·Ú¹Þ´Â ¹Ìµð¾î¸¦ »ç¿ëÇÏ´Â ½Ã½ºÅÛÀ» ÀúÀåÇϽʽÿÀ.
- ³»¿ëÀÌ ¿¹»óµÇ´Â ÷ºÎ ÆÄÀÏÀÌ ¾Æ´Ñ °æ¿ì, Á÷¿øµéÀÌ ÀÌ·¯ÇÑ ÆÄÀÏÀ» ¿Áö ¾Êµµ·Ï ÇϽʽÿÀ. ¶ÇÇÑ ¹ÙÀÌ·¯½º °Ë»ç¸¦ ¿Ï·áÇÏÁö ¾ÊÀº °æ¿ì, ÀÎÅͳݿ¡¼ ´Ù¿î·ÎµåÇÑ ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÏÁö ¸¶½Ê½Ã¿À. ƯÁ¤ ºê¶ó¿ìÀú Ãë¾à¼ºÀÌ º¸¾ÈµÇÁö ¾ÊÀº °æ¿ì, ¼Õ»óµÈ À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇÏ´Â °Í ¸¸À¸·Î °¨¿°À» À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù.

½Ã¸¸ÅØ º¸¾È ¿¬±¸¼Ò(Security Response)¿¡¼´Â W32.Netsky.B@mmÀ» Á¦°ÅÇÒ ¼ö ÀÖ´Â Àü¿ë Á¦°Å µµ±¸¸¦ Á¦ÀÛÇÏ¿´½À´Ï´Ù. µµ±¸¸¦ »ç¿ëÇÏ´Â °ÍÀÌ °¡Àå ½±°Ô ¿úÀ» Á¦°ÅÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀÔ´Ï´Ù.
¼öµ¿ Á¦°Å ¹æ¹ý
Á¦°Å µµ±¸¸¦ »ç¿ëÇÏÁö ¾Ê°í ¼öµ¿À¸·Î Á¦°ÅÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ´ÙÀ½ ´Ü°è¸¦ Áö½Ã¿¡ ¸Â°Ô µû¸£½Ê½Ã¿À.
Âü°í: ³×Æ®¿öÅ©¿¡ ¿¬°áµÇ¾î Àְųª ÀÎÅͳݿ¡ Ç×»ó ¿¬°áµÇ¾î ÀÖ´Â °æ¿ì ³×Æ®¿öÅ© ¹× ÀÎÅÍ³Ý ¿¬°áÀ» ²÷À¸½Ê½Ã¿À. ³×Æ®¿öÅ©¿¡ ¿¬°áµÈ ¸ðµç ½Ã½ºÅÛ¿¡¼ ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇϱâ Àü¿¡´Â ½Ã½ºÅÛÀ» ³×Æ®¿öÅ©¿¡ ¿¬°áÇÏÁö ¸¶½Ê½Ã¿À.
³×Æ®¿öÅ©³ª ÀÎÅͳݿ¡ ½Ã½ºÅÛÀ» ´Ù½Ã ¿¬°áÇϱâ Àü¿¡ ÆÄÀÏ °øÀ¯¸¦ ÇØÁ¦Çϰųª ¾ÏÈ£·Î º¸È£ÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº Windows Âü°í Àڷᳪ ÃÖ´ë ³×Æ®¿öÅ© º¸È£¸¦ À§ÇØ °øÀ¯ Windows Æú´õ¸¦ ¼³Á¤ÇÏ´Â ¹æ¹ýÀ» ÂüÁ¶ÇϽʽÿÀ.
ÁÖÀÇ: ÀÌ ´Ü°è¸¦ »ý·«ÇÏÁö ¸¶½Ê½Ã¿À. ÀÌ ¿úÀ» Á¦°ÅÇϱâ Àü¿¡ ³×Æ®¿öÅ© ¿¬°áÀ» ²÷¾î¾ß ÇÕ´Ï´Ù.
ÀÌ ÁöħÀº Symantec AntiVirus ¹× Norton AntiVirus Á¦Ç°±ºÀ» Æ÷ÇÔÇÑ ¸ðµç ½Ã¸¸ÅØ ¹ÙÀÌ·¯½º ¹æÁö Á¦Ç°¿¡ ÇØ´çµË´Ï´Ù.
- Windows Me/XP ½Ã½ºÅÛ º¹¿ø ±â´É ÁßÁö
- ¹ÙÀÌ·¯½º Á¤ÀÇ ¾÷µ¥ÀÌÆ®
- ½Ã½ºÅÛ ¾ÈÀü ¸ðµå ¶Ç´Â VGA ¸ðµå ½ÃÀÛ
- Àüü ½Ã½ºÅÛ °Ë»ç¸¦ ½ÇÇàÇϰí W32.Netsky.B@mm·Î ŽÁöµÈ ¸ðµç ÆÄÀÏ »èÁ¦
- ·¹Áö½ºÆ®¸®¿¡ Ãß°¡µÈ °ªÀ» Á¦°Å ¹× ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛ
°¢ ´Ü°èÀÇ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½À» ÂüÁ¶ÇϽʽÿÀ.
1. ½Ã½ºÅÛ º¹¿ø ±â´É ÁßÁö (Windows Me/XP)
Windows Me ¶Ç´Â Windows XP¸¦ »ç¿ëÇÏ´Â °æ¿ì, [½Ã½ºÅÛ º¹¿ø]±â´É Àá½Ã ÁßÁöÇÒ °ÍÀ» ±ÇÀåÇÕ´Ï´Ù. ÀÌ ±â´ÉÀº ±âº»°ªÀ¸·Î Ȱ¼ºÈµÇ¾î ÀÖÀ¸¸ç ÆÄÀÏÀÌ ¼Õ»óµÈ °æ¿ì Windows¿¡¼ ÀÌ ÆÄÀÏÀ» º¹¿øÇÏ´Â µ¥ »ç¿ëµË´Ï´Ù. ¹ÙÀÌ·¯½º, ¿ú, ¶Ç´Â Æ®·ÎÀÌ ¸ñ¸¶ °¨¿°À» Ä¡·áÇÑ ÈÄ, [½Ã½ºÅÛ º¹¿ø] ±â´ÉÀÌ À̸¦ ´Ù½Ã º¹¿ø ½Ãų ¼öµµ ÀÖ½À´Ï´Ù.
Windows´Â ¹ÙÀÌ·¯½º ¹æÁö ÇÁ·Î±×·¥À» Æ÷ÇÔÇÑ ¿ÜºÎÀÇ ÇÁ·Î±×·¥ÀÌ [½Ã½ºÅÛ º¹¿ø]À» º¯°æÇÏ´Â °ÍÀ» ¹æÁöÇÕ´Ï´Ù. ±×·¯¹Ç·Î, ¹ÙÀÌ·¯½º ¹æÁö ÇÁ·Î±×·¥Àº [½Ã½ºÅÛ º¹¿ø]Æú´õ¿¡ ÀÖ´Â À§ÇØÇÑ ÇÁ·Î±×·¥À» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù. ÀÌ·Î ÀÎÇØ, [½Ã½ºÅÛ º¹¿ø]Àº ¹ÙÀÌ·¯½º °¨¿° Ä¡·áÈÄ, °¨¿°µÈ ÆÄÀÏÀ» ½Ã½ºÅÛ¿¡ ´Ù½Ã º¹±¸ÇÒ °¡´É¼ºÀÌ ÀÖ½À´Ï´Ù.
¶ÇÇÑ, ¿úÀ» Á¦°ÅÇÑ ÀÌÈÄ¿¡µµ ¹ÙÀÌ·¯½º °Ë»ç¿¡¼ ½Ã½ºÅÛ º¹¿ø Æú´õ¿¡ ÀÖ´Â ¿úÀ» ŽÁöÇÒ ¼öµµ ÀÖ½À´Ï´Ù.
[½Ã½ºÅÛ º¹¿ø]±â´ÉÀ» ÁßÁöÇÏ´Â ¹æ¹ý¿¡ °üÇÑ ¼³¸íÀº ´ÙÀ½ ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
2. ¹ÙÀÌ·¯½º Á¤ÀÇ ¾÷µ¥ÀÌÆ®
¸ðµç ¹ÙÀÌ·¯½º Á¤ÀÇ´Â ½Ã¸¸ÅØ º¸¾È ¿¬±¸¼Ò(Symantec Security Response)ÀÇ Ã¶ÀúÇÑ Å×½ºÆ®¸¦ °ÅÄ£ ÈÄ ¼¹ö¸¦ ÅëÇØ Á¦°øµË´Ï´Ù. ÃֽйÙÀÌ·¯½º Á¤ÀǸ¦ ¾òÀ» ¼ö ÀÖ´Â µÎ °¡Áö ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- LiveUpdate´Â ¹ÙÀÌ·¯½º Á¤ÀǸ¦ ¾÷µ¥ÀÌÆ® ÇÏ´Â °¡Àå ½¬¿î ¹æ¹ýÀÔ´Ï´Ù. ¹ÙÀÌ·¯½º Á¤ÀÇ´Â À§±ÞÇÑ ¹ÙÀÌ·¯½º È®»êÀÌ ¹ß»ýÇÏÁö ¾Ê´Â ÇÑ LiveUpdate ¼¹ö¿¡ ¸ÅÁÖ ¸ñ¿äÀÏ¿¡ °Ô½ÃµË´Ï´Ù. ÀÌ ¹ÙÀÌ·¯½º¿¡ °üÇÑ Á¤Àǰ¡ LiveUpdate¿¡ Æ÷ÇԵǾî ÀÖ´ÂÁö È®ÀÎÇÏ·Á¸é ¹®¼ ù ºÎºÐÀÇ ¹ÙÀÌ·¯½º Á¤ÀÇ(LiveUpdate)¸¦ ÂüÁ¶ÇϽʽÿÀ.
- Intelligent Updater¸¦ ÅëÇØ ¹ÙÀÌ·¯½º Á¤ÀǸ¦ ´Ù¿î·Îµå ÇÏ´Â ¹æ¹ý: Intelligent Updater ¹ÙÀÌ·¯½º Á¤ÀÇ´Â ÆòÀÏ(¿ù – ±Ý)¿¡ °Ô½ÃµË´Ï´Ù. Intelligent Updater ¹ÙÀÌ·¯½º Á¤ÀÇ´Â ½Ã¸¸ÅØ º¸¾È ¿¬±¸¼Ò(Symantec Security Response) À¥ »çÀÌÆ®¸¦ ÅëÇØ ´Ù¿î·Îµå ¹Þ¾Æ¾ß ÇÏ¸ç »ç¿ëÀÚ°¡ Á÷Á¢ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ¹ÙÀÌ·¯½º¿¡ °üÇÑ Á¤Àǰ¡ Intelligent Updater¿¡ Æ÷ÇԵǾî ÀÖ´ÂÁö¸¦ È®ÀÎÇÏ·Á¸é ¹ÙÀÌ·¯½º Á¤ÀÇ(Intelligent Updater)¸¦ ÂüÁ¶ÇϽʽÿÀ.
Intelligent Updater ¹ÙÀÌ·¯½º Á¤ÀÇ´Â ¿©±â¿¡¼ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Intelligent Updater¸¦ »ç¿ëÇÏ¿© ¹ÙÀÌ·¯½º Á¤ÀÇ ÆÄÀÏÀ» ¾÷µ¥ÀÌÆ®ÇÏ´Â ¹æ¹ýÀ» ÂüÁ¶ÇϽʽÿÀ.
3. ½Ã½ºÅÛÀ» ¾ÈÀü ¸ðµå ¶Ç´Â VGA ¸ðµå·Î ´Ù½Ã ½ÃÀÛ
½Ã½ºÅÛÀ» Á¾·áÇϰí Àü¿øÀ» ²ô½Ê½Ã¿À. ÃÖ¼ÒÇÑ 30ÃÊ ÀÌ»ó ±â´Ù¸° ÈÄ, ½Ã½ºÅÛÀ» ¾ÈÀü ¸ðµå ¶Ç´Â VGA ¸ðµå·Î ½ÃÀÛÇϽʽÿÀ.
- Windows 95/98/Me/2000/XP: ½Ã½ºÅÛÀ» ¾ÈÀü ¸ðµå·Î ´Ù½Ã ½ÃÀÛÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº ½Ã¸¸ÅØ ±â¼ú ÀÚ·á ½Ã½ºÅÛÀ» ¾ÈÀü¸ðµå·Î ½ÃÀÛÇÏ´Â ¹æ¹ýÀ» ÂüÁ¶ÇϽʽÿÀ.
- Windows NT 4: ¡°VGA ¸ðµå¡±·Î ´Ù½Ã ½ÃÀÛÇϽʽÿÀ.
4. °¨¿° ÆÄÀÏ °Ë»ç ¹× »èÁ¦
- ½Ã¸¸ÅØ ¾ÈƼ¹ÙÀÌ·¯½º ¼ÒÇÁÆ®¿þ¾î¸¦ ½ÃÀÛÇÏ°í ¸ðµç ÆÄÀÏÀ» °Ë»çÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
- Àüü ½Ã½ºÅÛ °Ë»ç¸¦ ½ÇÇàÇϽʽÿÀ.
- W32.Netsky.B@mm¿¡ °¨¿°µÈ °ÍÀ¸·Î ŽÁöµÈ ÆÄÀÏÀÌ ÀÖÀ¸¸é [»èÁ¦]¸¦ ´©¸£½Ê½Ã¿À.
5. ·¹Áö½ºÆ®¸® °ª Á¦°Å ¹× ½Ã½ºÅÛ Àç ½ÃÀÛ
ÁÖÀÇ: ·¹Áö½ºÆ®¸®¸¦ º¯°æÇϱâ Àü¿¡ ¹é¾÷ÇÒ °ÍÀ» ±ÇÀåÇÕ´Ï´Ù. ·¹Áö½ºÆ®¸®¸¦ À߸ø º¯°æÇÏ¸é µ¥ÀÌÅͰ¡ ¿µ±¸È÷ ¼Õ½ÇµÇ°Å³ª ÆÄÀÏÀÌ ¼Õ»óµÉ ¼ö ÀÖ½À´Ï´Ù. ÁöÁ¤µÈ ۸¸ ¼öÁ¤ÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº Windows ·¹Áö½ºÆ®¸® ¹é¾÷ ¹æ¹ý ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
- Windows ÀÛ¾÷ ¸Þ´º¿¡¼ [½ÃÀÛ] > [½ÇÇà]À» ´©¸£½Ê½Ã¿À. ( [½ÇÇà] ´ëÈ »óÀÚ°¡ ³ªÅ¸³³´Ï´Ù.)
- ½ÇÇà ´ëÈâ¿¡ ¾Æ·¡ÀÇ ¸í·É¾î¸¦ ÀÔ·ÂÇϽʽÿÀ.
regedit
±×·± ´ÙÀ½ [È®ÀÎ]À» ´©¸£½Ê½Ã¿À. [·¹Áö½ºÆ®¸® ÆíÁý±â]°¡ ¿¸³´Ï´Ù.
- ´ÙÀ½ ۸¦ ãÀ¸½Ê½Ã¿À.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- ¿À¸¥ÂÊ Ã¢¿¡¼ ¾Æ·¡ÀÇ °ªÀ» »èÁ¦ÇϽʽÿÀ.
"service" = "%Windir%\services.exe -serv"
- ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ´ÝÀ¸½Ê½Ã¿À.
- ½Ã½ºÅÛÀ» ´Ù½Ã ½ÃÀÛÇϽʽÿÀ.
ÀÛ¼ºÀÚ: Fergal Ladley
|