|
|
 |
|
| ³»¿ë |
[Àüü ¿ä¾à]
ÀÚ½ÅÀÇ º¹»çº»À» ¼û±è¼Ó¼ºÀ¸·Î »ý¼ºÇϸç, ƯÁ¤ ÆÄÀÏ»ý¼º°ú ÇÔ²² ·¹Áö½ºÆ®¸® °ªÀ» ¼öÁ¤ÇÏ¿© À©µµ¿ì ½ÃÀ۽à ÀÚµ¿½ÇÇàµÇ°Ô ÇÑ´Ù. ¶ÇÇÑ, ¿ø°Ý¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÑ´Ù.
[È®»ê ¹æ¹ý]
°øÀ¯µÈ ³×Æ®¿öÅ© Æú´õ¸¦ ÅëÇØ À¯Æ÷µÉ ¼ö ÀÖÀ¸¸ç, OS³ª ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ º¸¾È Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© À¯Æ÷µÇ±âµµ ÇÑ´Ù.
[°¨¿° ÈÄ Áõ»ó]
1. ´ÙÀ½°ú °°ÀÌ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
- (µå¶óÀÌºê ·çÆ®)\RECYCLER\blazewrm.vmx ( 11 ¹ÙÀÌÆ® ) - (»ç¿ëÀÚ Æú´õ)\WinNT\winlogon.exe (112,128 ¹ÙÀÌÆ®, Trojan/W32.Agent.112128.AC) - (À©µµ¿ì ½Ã½ºÅÛ Æú´õ)\drivers\blazedworm.sys (4,608 ¹ÙÀÌÆ®, Trojan/W32.BlazeBot.4608)
2. ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸®¸¦ »ý¼ºÇÏ¿© À©µµ¿ì ½ÃÀ۽à ÀÚµ¿ ½ÇÇà µÇµµ·Ï ÇÑ´Ù.
- HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ policies\ Explorer\ Run\ - ÀÌ ¸§ : Windows Logon Servicer - µ¥ÀÌÅÍ : (»ç¿ëÀÚ Æú´õ)\WinNT\winlogon.exe
- HKEY_LOCAL_MACHINE\ SYSTEM\ CurrentControlSet\ Services\ blazedworm\
- ÀÌ ¸§ : ImagePath - µ¥ÀÌÅÍ : "\??\C:\WINDOWS\system32\drivers\blazedworm.sys"
3. ¼û±è¼Ó¼ºÀÇ ÆÄÀϵéÀ» »ç¿ëÀÚ°¡ º¸Áö ¸øÇÏ°Ô Çϱâ À§ÇØ ´ÙÀ½°ú °°ÀÌ ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÑ´Ù.
- HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced\
- ÀÌ ¸§ : Hidden - µ¥ÀÌÅÍ : 2
- ÀÌ ¸§ : ShowSuperHidden - µ¥ÀÌÅÍ : 0
- HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced\ Folder\ Hidden\ SHOWALL\
- ÀÌ ¸§ : CheckedValue - µ¥ÀÌÅÍ : 0
4. ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸® °ªÀ» »ý¼ºÇÏ¿© "µµ±¸" -> "Æú´õ¿É¼Ç"ÀÇ »ç¿ëÀ» ¸·¾Æ »ç¿ëÀÚ°¡ ¼û±è¼Ó¼º ÆÄÀÏÀ» ã±â ¾î·Æ°Ô ÇÑ´Ù.
- HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ policies\ Explorer\
- ÀÌ ¸§ : NoFolderOptions - µ¥ÀÌÅÍ : 1
5. ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸® °ªÀ» »ý¼ºÇÏ¿© "½ÃÀÛ" -> "½ÇÇà"ÀÇ »ç¿ëÀ» ¸·´Â´Ù.
- HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ policies\ Explorer\
- ÀÌ ¸§ : NoRun - µ¥ÀÌÅÍ : 1
6. ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸® °ªÀ» »ý¼º ¹× ¼öÁ¤ÇÏ¿© ½Ã½ºÅÛ µî·ÏÁ¤º¸¿¡¼ ½Ã½ºÅÛ º¹¿øÅÇÀ» Á¦°ÅÇÑ´Ù.
- HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ SystemRestore\
- ÀÌ ¸§ : DisableConfig - µ¥ÀÌÅÍ : 1
- ÀÌ ¸§ : DisableSR - µ¥ÀÌÅÍ : 1
7. ¾Æ·¡¿Í °°Àº ÁÖ¼ÒÀÇ ¿ø°ÝÁö ¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÑ´Ù.
- http://(»ý·«)/s/(»ý·«) - http://www.(»ý·«).(»ý·«)
[Âü°í »çÇ×]
- (µå¶óÀÌºê ·çÆ®)¶õ µå¶óÀ̺êÀÇ ÃÖ»óÀ§ Æú´õÀÌ´Ù. (¿¹. C:\, D:\)
- (»ç¿ëÀÚ Àӽà Æú´õ)¶õ ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Local Settings\Temp ÀÌ´Ù.
- (ÀÎÅÍ³Ý Àӽà Æú´õ)¶õ ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Local Settings\\Temporary Internet Files ÀÌ´Ù.
- (À©µµ¿ì Æú´õ)¶õ ÀϹÝÀûÀ¸·Î 95,98,ME¿¡¼´Â C:\WINDOWS À̰í, 2000, NT¿¡¼´Â C:\WINNT, À©µµ¿ìXP¿¡¼´Â C:\WINDOWS ÀÌ´Ù.
- (À©µµ¿ì ½Ã½ºÅÛ Æú´õ)¶õ ÀϹÝÀûÀ¸·Î 95,98,ME¿¡¼´Â C:\WINDOWS\SYSTEM À̰í, 2000, NT¿¡¼´ÂC:\WINNT\SYSTEM32, À©µµ¿ìXP¿¡¼´Â C:\WINDOWS\SYSTEM32 ÀÌ´Ù.
- (»ç¿ëÀÚ Æú´õ)¶õ C:\Documents and Settings\admin\Application Data ÀÌ´Ù.
- (ÁÖ)À×Ä«ÀÎÅͳÝÀÇ ¾Ç¼ºÄÚµå ¸í¸í¹ýÀ» È®ÀÎÇÏ·Á¸é ¾Æ·¡ ¹öưÀ» Ŭ¸¯ÇÑ´Ù.

|
|
| Ä¡·á ¹æ¹ý |
1. »ç¿ë Á¦Ç° ½ÇÇà ÈÄ ÃֽŠ¿£Áø ¹× ÆÐÄ¡ ÆÄÀÏ·Î ¾÷µ¥ÀÌÆ® ÇÑ´Ù.(¸ÞÀÎȸé. Æ®·¹ÀÌ ¾ÆÀÌÄÜ, ½ÃÀÛ¸Þ´º Ȱ¿ë) 2. ¸ÞÀÎȸ鿡¼ ¹ÙÀÌ·¯½º °Ë»ç ¼±Åà ÈÄ °Ë»çÇÒ ¹üÀ§À» ÁöÁ¤ÇÏ°í °Ë»ç ½ÃÀÛ ¹öưÀ» Ŭ¸¯ÇÏ¿© °Ë»ç¸¦ ½ÃÀÛÇÑ´Ù. 3. °Ë»ç Á¾·á ÈÄ ¾Ç¼ºÄڵ尡 Áø´ÜµÇ¸é Áø´ÜµÈ Ç׸ñÀ» È®ÀÎÇϰí Ä¡·á ¹öưÀ» Ŭ¸¯ÇÏ¿© Ä¡·áÇÑ´Ù. 4. Ä¡·áµÈ Ç׸ñÀ» È®ÀÎÇÑ´Ù.
 |
 |
|
 |
| |
ÄÁÅÙÃ÷
ÀúÀÛ±Ç ÁÖÀÇ »çÇ× |
º»
ºÐ¼®ÀÚ·áÀÇ ¸ðµç ÀúÀÛ±ÇÀº ISARC(INCA Internet Security Analysis & Response
Center)¿¡ ÀÖÀ¸¹Ç·Î ¹«´Ü »ç¿ë ¹× µµ¿ëÀ» ±ÝÁöÇÕ´Ï´Ù.
´Ü, ºñ¿µ¸® ¶Ç´Â °³ÀÎÀÌ º» ÄÁÅÙÃ÷¸¦
»ç¿ëÇÏ´Â °ÍÀº Çã¿ëµÇ°í ÀÖÀ¸³ª, ÀÌ °æ¿ì¿¡´Â Á¤º¸ÀÇ Ãâó¸¦ ¹Ýµå½Ã ¹àÇô¾ß Çϸç, »ó¾÷ÀûÀÎ ¸ñÀû
¶Ç´Â ±â¾÷ÀÌ º» ÄÁÅÙÃ÷¸¦ »ç¿ë½Ã¿¡´Â ¹Ýµå½Ã º»»ç ÄÁÅÙÃ÷ ´ã´ç¿¡°Ô »ç¿ë ¹®ÀǸ¦ ÇØ¾ßÇÕ´Ï´Ù.
Á¤º¸ ÄÁÅÙÃ÷ ÀÌ¿ë ¹®ÀÇ : sale@inca.co.kr |
|
|
 |
|
 |
ÃÖÃÊ
Á¤º¸ ÀÔ·Â ½Ã°£ | 2009.09.09 13:35 (GMT+9) |
¸¶Áö¸·
Á¤º¸ ¼öÁ¤ ½Ã°£ | 2009.09.09 14:16 (GMT+9) |
|
|