ÀÛ³â 12¿ù°æ¿¡ µîÀåÇÑ ±¹³»¿¡¼ Á¦ÀÛµÈ ¡®¸Þ¸ð¸® OO¡¯¶ó´Â ¸Þ¸ð¸® ÃÖÀûÈ ÇÁ·Î±×·¥ÀÌ ÃÖ±Ù ºí·Î±×, À¯¸í ÀÎÅÍ³Ý ¼ºñ½º ½ºÆù¼ ÇÁ·Î±×·¥, ÆÄÀÏ °ø°³ ÀÚ·á½Ç µîÀ» ÅëÇØ ¹èÆ÷°¡ ÀÌ·ç¾îÁö´Â °úÁ¤¿¡¼ »ç¿ëÀÚ ¸ô·¡ ¾Ç¼º ÆÄÀÏÀ» µî·ÏÇÏ¿© Ãß°¡ÀûÀÎ ±¤°í ÇÁ·Î±×·¥À» ¼³Ä¡ÇÏ´Â »ç·Ê¸¦ È®ÀÎÇÏ¿´½À´Ï´Ù.
ƯÈ÷ À̹ø¿¡ È®ÀÎµÈ ¹èÆ÷ ¹æ½ÄÀº ÀÏ¹Ý »ç¿ëÀÚ°¡ ÀÚ½ÅÀÇ PC¿¡ ¾î´À³¯ °©Àڱ⠼³Ä¡µÇ´Â ¹ÙÅÁÈ¸é ¹Ù·Î°¡±â, À¥ ºê¶ó¿ìÀú »ó¿¡¼ µ¿ÀÛÇÏ´Â »çÀ̵å¹ÙÇü ±¤°í ÇÁ·Î±×·¥ÀÌ ¾î¶² °æ·Î¸¦ ÅëÇØ ¼³Ä¡µÇ´ÂÁö ÀüÇô ÀÎÁöÇÒ ¼ö ¾ø´Ù´Â Á¡¿¡¼ ÀÚ¼¼È÷ »ìÆ캸µµ·Ï ÇÏ°Ú½À´Ï´Ù.
ÇØ´ç ¸Þ¸ð¸® ÃÖÀûÈ ÇÁ·Î±×·¥ ÀÚü´Â Á¤»óÀûÀÎ ÇÁ·Î±×·¥À¸·Î »ç¿ëÀÚ°¡ ´Ù¾çÇÑ °æ·Î¸¦ ÅëÇØ ¼³Ä¡ÇÏ´Â °úÁ¤¿¡¼ Ãß°¡ÀûÀ¸·Î »ç¿ëÀÚ ¸ô·¡ ´ÙÀ½ÀÇ ÆÄÀÏ°ú ·¹Áö½ºÆ®¸®¸¦ µî·ÏÇÏ¿© ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿ ½ÇÇàÀ» Çϵµ·Ï ÇÕ´Ï´Ù.
C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\facialer\facialer.exe C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\tissuee\tissuee.exe
HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\Windows\CurrentVersion\Run - facialer = C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\facialer\facialer.exe - tissuee = C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\tissuee\tissuee.exe |
ÃÖÃÊ ¼³Ä¡°¡ ¿Ï·áµÈ ½ÃÁ¡¿¡¼ ÇØ´ç facialer.exe / tissuee.exe ÆÄÀÏÀº ½Ã½ºÅÛ ÀçºÎÆà °úÁ¤¿¡¼ »ç¿ëÀÚ ¸ô·¡ ƯÁ¤ ±¹³» ´Ù¼öÀÇ ¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÏ¿© ´ÙÀ½°ú °°Àº ÃÑ 6°³ÀÇ exe ÆÄÀϵéÀ» "C:\Documents and Settings\LocalService\Application Data" Æú´õ¿¡ ´Ù¿î·Îµå ½Ãµµ¸¦ ÇÕ´Ï´Ù.
1. h**p://down.strong**.kr/apocalyps.exe :: %SystemRoot%\System32\apocalyps.dll 2. h**p://down.servicednls****.org/dpsvu.exe :: %SystemRoot%\System32\dpsvu.dll 3. h**p://down.window***.kr/inpescv.exe :: %SystemRoot%\System32\inpescv.dll 4. h**p://down.servicednls****.org/meansptr.exe :: %SystemRoot%\System32\meansptr.dll 5. h**p://down.window***.kr/nexroser.exe :: %SystemRoot%\System32exroser.dll 6. h**p://down.servicednls****.org/sumsv.exe :: %SystemRoot%\System32\sumsv.dll |
´Ù¿î·ÎµåµÈ ÇØ´ç ÆÄÀϵéÀº "%SystemRoot%\System32" Æú´õ ³»¿¡ ÃÑ 6°³ÀÇ dll ÆÄÀÏÀ» Ãß°¡ÇÏ¿© ¼ºñ½º Ç׸ñÀ¸·Î µî·ÏÀ» ÇÏ¿© ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿À¸·Î ½ÇÇàµÇµµ·Ï ±¸¼ºÀ» ÇÕ´Ï´Ù.
ÇØ´ç ¼ºñ½º µî·Ï Ç׸ñ¿¡ ´ëÇÑ ¼¼ºÎÀûÀÎ ³»¿ëÀº ´ÙÀ½°ú °°½À´Ï´Ù.
¼ºñ½º À̸§ : apocalyps ¼³¸í : Aapocalypse World ÆÄÀÏ : %SystemRoot%\System32\apocalyps.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\apocalyps
¼ºñ½º À̸§ : Dpsvu ¼³¸í : Direct User Provide Service ÆÄÀÏ : %SystemRoot%\System32\dpsvu.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dpsvu
¼ºñ½º À̸§ : Inpe Scv ¼³¸í : inpe scv ÆÄÀÏ : %SystemRoot%\System32\inpescv.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inpe Scv
¼ºñ½º À̸§ : MeansPtr ¼³¸í : meansptr ÆÄÀÏ : %SystemRoot%\System32\meansptr.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MeansPtr
¼ºñ½º À̸§ : Nexroser ¼³¸í : Network Zero Service ÆÄÀÏ : %SystemRoot%\System32exroser.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nexroser
¼ºñ½º À̸§ : SumSv ¼³¸í : User Support Manager Service ÆÄÀÏ : %SystemRoot%\System32\sumsv.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SumSv |
¼ºñ½º Ç׸ñ¿¡ µî·ÏÇÏ´Â ÀÌÀ¯´Â ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿À¸·Î ½ÃÀÛÇϵµ·Ï ±¸ÇöÇÒ ¸ñÀûÀε¥, ÀÌ·± ´Ù¼öÀÇ ¼ºñ½º¸¦ µî·ÏÇÒ °æ¿ì svchost.exe ÇÁ·Î¼¼½º°¡ ´Ù¼ö »ý¼ºµÇ¾î ¸Þ¸ð¸®¿¡ »óÁÖÇÏ´Â ¹®Á¦·Î ½±°Ô ³ëÃâµÇ´Â ¹®Á¦¸¦ °¡Áö°Ô µË´Ï´Ù.
ÇÏÁö¸¸ ÇØ´ç ¾Ç¼º ÆÄÀÏÀº ¼ºñ½º µ¿ÀÛ ¹æ½ÄÀ» ½Ã½ºÅÛ ºÎÆÃÀ» ÅëÇÑ Windows ½ÃÀÛ °úÁ¤¿¡¼ µî·ÏµÈ ¼ºñ½º Ç׸ñÀ» ÀÚµ¿ ½ÇÇàÇÏ¿© ƯÁ¤ ¼¹ö¿¡¼ ¾÷µ¥ÀÌÆ® üũ ¹× ´Ù¿î·Îµå ÈÄ, ÀÚµ¿À¸·Î ¼ºñ½º¸¦ ÁßÁöÇÏ¿© »ç¿ëÀÚ°¡ ÇÁ·Î¼¼½º¸¦ È®ÀÎÇÒ °æ¿ì ÇØ´ç ¼ºñ½º°¡ µî·ÏµÈ svchost.exe ÇÁ·Î¼¼½º´Â ³ëÃâÀÌ µÇÁö ¾Êµµ·Ï ±¸¼ºÇÏ¿´½À´Ï´Ù.
À̸¦ ÅëÇØ ºÐ¼®À» ¸ñÀûÀ¸·Î Çϰųª º¸¾È Á¦Ç°¿¡¼ Áø´ÜÇÏÁö ¾ÊÀ» °æ¿ì ½±°Ô È®ÀÎÀÌ ¾î·Á¿ì¸ç, ¹èÆ÷ ´ç½Ã ±âÁØ¿¡¼ ÇØ´ç ¼ºñ½º µî·Ï ÆÄÀϵéÀº ±¹³»¿Ü º¸¾È Á¦Ç°¿¡¼ °ÅÀÇ Áø´ÜµÇÁö ¾Ê´Â ¼öÁØÀ̾ú½À´Ï´Ù.
ƯÈ÷ ÇØ´ç ¾Ç¼º ÆÄÀÏÀÌ »ç¿ëÀÚ PC¿¡ ¼³Ä¡µÇ¾î ½Ã½ºÅÛ ½ÃÀ۽ø¶´Ù ¾÷µ¥ÀÌÆ®¸¦ üũ¸¦ ÇÏ´Â µ¿ÀÛ¿¡¼µµ ¸î Àϵ¿¾È Ãß°¡ÀûÀÎ ±¤°í ÇÁ·Î±×·¥À» ´Ù¿î·ÎµåÇÏÁö ¾Ê°í ±â´Ù¸®´Â Àγ»½ÉÀ» º¸¿©ÁÖ¾ú½À´Ï´Ù.
ÃÖÁ¾ÀûÀ¸·Î ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ°¡ ÀǵµÇÑ ±¤°í ÇÁ·Î±×·¥Àº ½Ã½ºÅÛ ½ÃÀ۽à ÀÌµé ¼ºñ½º µî·Ï ÆÄÀϵéÀÌ ¡®C:\Documents and Settings\LocalService\Application Data¡¯ Æú´õ¿¡ ±¤°í ¼³Ä¡ ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ¿© ¹Ù·Î ¼³Ä¡ÇÏ´Â °ÍÀÌ ¾Æ´Ï¶ó, ´Ù½Ã ½Ã½ºÅÛ Àç½ÃÀÛ °úÁ¤¿¡¼ ¼³Ä¡¸¦ Çϵµ·Ï ±¸¼ºÇÏ°í ÀÖ½À´Ï´Ù.
¶ÇÇÑ ±¤°í ÇÁ·Î±×·¥ ¼³Ä¡¿Í ÇÔ²² Ãß°¡ÀûÀ¸·Î 2°³ÀÇ ¼ºñ½º µî·ÏÀ» À§ÇÑ ¾Ç¼º ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ´Â µ¿ÀÛµµ È®ÀÎÇÒ ¼ö ÀÖ¾ú½À´Ï´Ù.
1. h**p://down.program****.kr/lbnaprt.exe :: %SystemRoot%\System32\lbnaprt.dll 2. h**p://down.servicednls****.org/spltry.exe :: %SystemRoot%\System32\spltry.dll |
ÇØ´ç ¹æ½Äµµ ÀÌÀü°ú µ¿ÀÏÇÏ°Ô exe ÆÄÀÏ ´Ù¿î·Îµå¸¦ ÅëÇØ ½Ã½ºÅÛ Æú´õ ³»¿¡ dll ÆÄÀÏÀ» »ý¼ºÇÏ¿© ´ÙÀ½°ú °°Àº ¼ºñ½º Ç׸ñÀ» µî·ÏÇÏ°í ÀÖ½À´Ï´Ù.
¼ºñ½º À̸§ : LbnAprt ¼³¸í : Applet Support Net Use Library ÆÄÀÏ : %SystemRoot%\System32\lbnaprt.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LbnAprt
¼ºñ½º À̸§ : Spltry ¼³¸í : Service Pack Utility Library ÆÄÀÏ : %SystemRoot%\System32\spltry.dll ·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SPltry |
ÀÌ·± ¹æ½ÄÀ» ÅëÇØ ±¤°í ÇÁ·Î±×·¥ ¶Ç´Â ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ°¡ ÀǵµÇϴ ƯÁ¤ ÇÁ·Î±×·¥À» »ç¿ëÀÚ ¸ô·¡ ¼³Ä¡ÇÒ ¼ö ÀÖ´Â ÀÏÁ¾ÀÇ Á»ºñPC¸¦ ±¸¼ºÇÏ¿© ¹èÆ÷ÀÚ°¡ ¿øÇÏ´Â ½Ã°£¿¡ ¿øÇÏ´Â ÇÁ·Î±×·¥À» ¸ô·¡ ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÇöÀç±îÁö È®ÀÎµÈ ±¤°í ÇÁ·Î±×·¥Àº OneClickService, PlusTab, SideTab, ÀÎÅÍ³Ý ¼îÇθô °ü·Ã ¹ÙÅÁÈ¸é ¹Ù·Î°¡±â, °Ë»ö °ø±ÞÀÚ ±âº»°ª º¯°æ°ú °°Àº ±¤°í ÇÁ·Î±×·¥ ¼³Ä¡¸¦ ÅëÇÏ¿© »ç¿ëÀÚ°¡ ÀÎÅͳÝÀ» ÀÌ¿ëÇÏ´Â °úÁ¤¿¡¼ ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ¿¡°Ô ±ÝÀüÀû ¼öÀÍÀ» À¯¹ßÇÒ ¼ö ÀÖµµ·Ï ÇÏ°í ÀÖ½À´Ï´Ù.
ÇöÀç ÇØ´ç ÇÁ·Î±×·¥ÀÌ ¼³Ä¡ÇÑ ¾Ç¼º ÆÄÀÏÀ» Á¦°ÅÇϱâ À§Çؼ´Â ½Ã½ºÅÛ Æú´õ(%SystemRoot%\System32)¿¡ ¼³Ä¡µÈ dll ÆÄÀÏÀ» ã¾Æ ¼öµ¿À¸·Î »èÁ¦¸¦ ÇϽñ⠹ٶó¸ç, ·¹Áö½ºÆ®¸® Ç׸ñ¿¡¼ °¢ ¼ºñ½º µî·Ï°ªÀ» ã¾Æ »èÁ¦¸¦ ÇϽñ⠹ٶø´Ï´Ù.
À̹ø »ç·Ê¿Í °°ÀÌ Á¤»óÀûÀÎ ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÏ´Â °úÁ¤¿¡¼ »ç¿ëÀÚ ¸ô·¡ ¼³Ä¡µÈ ¾Ç¼º ÆÄÀÏ·Î ÀÎÇÏ¿© Àڽŵµ ¸ð¸£°Ô ´Ù¾çÇÑ ±¤°í ÇÁ·Î±×·¥ µîÀÌ ¼³Ä¡µÇ´Â °ÍÀ» ÅëÇØ »ç¿ëÀÚ°¡ ÁÖÀǸ¦ ÇÑ´Ù°í °¨¿°À¸·ÎºÎÅÍ ¾ÈÀüÇÏÁö ¾ÊÀº ÀÎÅÍ³Ý Çö½ÇÀ» ¿³º¼ ¼ö ÀÖÁö ¾Ê¾Ò³ª »ý°¢µË´Ï´Ù.
[±Û _ º¸¾ÈÄ÷³´Ï½ºÆ® ¿ïÁö ¾Ê´Â ¹ú»õ(haslian@naver.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>