Home > Àüü±â»ç

[º¸¾È Ä÷³] ÃÖÀûÈ­ ÇÁ·Î±×·¥À» ÅëÇÑ ±¤°í ÇÁ·Î±×·¥ À¯Æ÷ »ç·Ê

ÀÔ·Â : 2011-02-17 14:59
ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â Ä«Ä«¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â
±¹³» Á¦ÀÛ ¸Þ¸ð¸® ÃÖÀûÈ­ ÇÁ·Î±×·¥, ±¤°í ¼³Ä¡ ¾Ç¼º±â´É È®ÀÎ


ÀÛ³â 12¿ù°æ¿¡ µîÀåÇÑ ±¹³»¿¡¼­ Á¦ÀÛµÈ ¡®¸Þ¸ð¸® OO¡¯¶ó´Â ¸Þ¸ð¸® ÃÖÀûÈ­ ÇÁ·Î±×·¥ÀÌ ÃÖ±Ù ºí·Î±×, À¯¸í ÀÎÅÍ³Ý ¼­ºñ½º ½ºÆù¼­ ÇÁ·Î±×·¥, ÆÄÀÏ °ø°³ ÀÚ·á½Ç µîÀ» ÅëÇØ ¹èÆ÷°¡ ÀÌ·ç¾îÁö´Â °úÁ¤¿¡¼­ »ç¿ëÀÚ ¸ô·¡ ¾Ç¼º ÆÄÀÏÀ» µî·ÏÇÏ¿© Ãß°¡ÀûÀÎ ±¤°í ÇÁ·Î±×·¥À» ¼³Ä¡ÇÏ´Â »ç·Ê¸¦ È®ÀÎÇÏ¿´½À´Ï´Ù.

 


ƯÈ÷ À̹ø¿¡ È®ÀÎµÈ ¹èÆ÷ ¹æ½ÄÀº ÀÏ¹Ý »ç¿ëÀÚ°¡ ÀÚ½ÅÀÇ PC¿¡ ¾î´À³¯ °©Àڱ⠼³Ä¡µÇ´Â ¹ÙÅÁÈ­¸é ¹Ù·Î°¡±â, À¥ ºê¶ó¿ìÀú »ó¿¡¼­ µ¿ÀÛÇÏ´Â »çÀ̵å¹ÙÇü ±¤°í ÇÁ·Î±×·¥ÀÌ ¾î¶² °æ·Î¸¦ ÅëÇØ ¼³Ä¡µÇ´ÂÁö ÀüÇô ÀÎÁöÇÒ ¼ö ¾ø´Ù´Â Á¡¿¡¼­ ÀÚ¼¼È÷ »ìÆ캸µµ·Ï ÇÏ°Ú½À´Ï´Ù.


ÇØ´ç ¸Þ¸ð¸® ÃÖÀûÈ­ ÇÁ·Î±×·¥ ÀÚü´Â Á¤»óÀûÀÎ ÇÁ·Î±×·¥À¸·Î »ç¿ëÀÚ°¡ ´Ù¾çÇÑ °æ·Î¸¦ ÅëÇØ ¼³Ä¡ÇÏ´Â °úÁ¤¿¡¼­ Ãß°¡ÀûÀ¸·Î »ç¿ëÀÚ ¸ô·¡ ´ÙÀ½ÀÇ ÆÄÀÏ°ú ·¹Áö½ºÆ®¸®¸¦ µî·ÏÇÏ¿© ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿ ½ÇÇàÀ» Çϵµ·Ï ÇÕ´Ï´Ù.

 

C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\facialer\facialer.exe

C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\tissuee\tissuee.exe

 

HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\Windows\CurrentVersion\Run

 - facialer = C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\facialer\facialer.exe

 - tissuee = C:\Documents and Settings\(»ç¿ëÀÚ °èÁ¤)\Application Data\tissuee\tissuee.exe


ÃÖÃÊ ¼³Ä¡°¡ ¿Ï·áµÈ ½ÃÁ¡¿¡¼­ ÇØ´ç facialer.exe / tissuee.exe ÆÄÀÏÀº ½Ã½ºÅÛ ÀçºÎÆà °úÁ¤¿¡¼­ »ç¿ëÀÚ ¸ô·¡ ƯÁ¤ ±¹³» ´Ù¼öÀÇ ¼­¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÏ¿© ´ÙÀ½°ú °°Àº ÃÑ 6°³ÀÇ exe ÆÄÀϵéÀ» "C:\Documents and Settings\LocalService\Application Data" Æú´õ¿¡ ´Ù¿î·Îµå ½Ãµµ¸¦ ÇÕ´Ï´Ù.


1. h**p://down.strong**.kr/apocalyps.exe :: %SystemRoot%\System32\apocalyps.dll

2. h**p://down.servicednls****.org/dpsvu.exe :: %SystemRoot%\System32\dpsvu.dll

3. h**p://down.window***.kr/inpescv.exe :: %SystemRoot%\System32\inpescv.dll

4. h**p://down.servicednls****.org/meansptr.exe :: %SystemRoot%\System32\meansptr.dll

5. h**p://down.window***.kr/nexroser.exe :: %SystemRoot%\System32exroser.dll

6. h**p://down.servicednls****.org/sumsv.exe :: %SystemRoot%\System32\sumsv.dll


´Ù¿î·ÎµåµÈ ÇØ´ç ÆÄÀϵéÀº "%SystemRoot%\System32" Æú´õ ³»¿¡ ÃÑ 6°³ÀÇ dll ÆÄÀÏÀ» Ãß°¡ÇÏ¿© ¼­ºñ½º Ç׸ñÀ¸·Î µî·ÏÀ» ÇÏ¿© ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿À¸·Î ½ÇÇàµÇµµ·Ï ±¸¼ºÀ» ÇÕ´Ï´Ù.


ÇØ´ç ¼­ºñ½º µî·Ï Ç׸ñ¿¡ ´ëÇÑ ¼¼ºÎÀûÀÎ ³»¿ëÀº ´ÙÀ½°ú °°½À´Ï´Ù.


¼­ºñ½º À̸§ : apocalyps

¼³¸í : Aapocalypse World

ÆÄÀÏ : %SystemRoot%\System32\apocalyps.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\apocalyps

 

¼­ºñ½º À̸§ : Dpsvu

¼³¸í : Direct User Provide Service

ÆÄÀÏ : %SystemRoot%\System32\dpsvu.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dpsvu

 

¼­ºñ½º À̸§ : Inpe Scv

¼³¸í : inpe scv

ÆÄÀÏ : %SystemRoot%\System32\inpescv.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Inpe Scv

 

¼­ºñ½º À̸§ : MeansPtr

¼³¸í : meansptr

ÆÄÀÏ : %SystemRoot%\System32\meansptr.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MeansPtr

 

¼­ºñ½º À̸§ : Nexroser

¼³¸í : Network Zero Service

ÆÄÀÏ : %SystemRoot%\System32exroser.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Nexroser

 

¼­ºñ½º À̸§ : SumSv

¼³¸í : User Support Manager Service

ÆÄÀÏ : %SystemRoot%\System32\sumsv.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SumSv

 


¼­ºñ½º Ç׸ñ¿¡ µî·ÏÇÏ´Â ÀÌÀ¯´Â ½Ã½ºÅÛ ½ÃÀ۽à ÀÚµ¿À¸·Î ½ÃÀÛÇϵµ·Ï ±¸ÇöÇÒ ¸ñÀûÀε¥, ÀÌ·± ´Ù¼öÀÇ ¼­ºñ½º¸¦ µî·ÏÇÒ °æ¿ì svchost.exe ÇÁ·Î¼¼½º°¡ ´Ù¼ö »ý¼ºµÇ¾î ¸Þ¸ð¸®¿¡ »óÁÖÇÏ´Â ¹®Á¦·Î ½±°Ô ³ëÃâµÇ´Â ¹®Á¦¸¦ °¡Áö°Ô µË´Ï´Ù.


ÇÏÁö¸¸ ÇØ´ç ¾Ç¼º ÆÄÀÏÀº ¼­ºñ½º µ¿ÀÛ ¹æ½ÄÀ» ½Ã½ºÅÛ ºÎÆÃÀ» ÅëÇÑ Windows ½ÃÀÛ °úÁ¤¿¡¼­ µî·ÏµÈ ¼­ºñ½º Ç׸ñÀ» ÀÚµ¿ ½ÇÇàÇÏ¿© ƯÁ¤ ¼­¹ö¿¡¼­ ¾÷µ¥ÀÌÆ® üũ ¹× ´Ù¿î·Îµå ÈÄ, ÀÚµ¿À¸·Î ¼­ºñ½º¸¦ ÁßÁöÇÏ¿© »ç¿ëÀÚ°¡ ÇÁ·Î¼¼½º¸¦ È®ÀÎÇÒ °æ¿ì ÇØ´ç ¼­ºñ½º°¡ µî·ÏµÈ svchost.exe ÇÁ·Î¼¼½º´Â ³ëÃâÀÌ µÇÁö ¾Êµµ·Ï ±¸¼ºÇÏ¿´½À´Ï´Ù.


À̸¦ ÅëÇØ ºÐ¼®À» ¸ñÀûÀ¸·Î Çϰųª º¸¾È Á¦Ç°¿¡¼­ Áø´ÜÇÏÁö ¾ÊÀ» °æ¿ì ½±°Ô È®ÀÎÀÌ ¾î·Á¿ì¸ç, ¹èÆ÷ ´ç½Ã ±âÁØ¿¡¼­ ÇØ´ç ¼­ºñ½º µî·Ï ÆÄÀϵéÀº ±¹³»¿Ü º¸¾È Á¦Ç°¿¡¼­ °ÅÀÇ Áø´ÜµÇÁö ¾Ê´Â ¼öÁØÀ̾ú½À´Ï´Ù.


ƯÈ÷ ÇØ´ç ¾Ç¼º ÆÄÀÏÀÌ »ç¿ëÀÚ PC¿¡ ¼³Ä¡µÇ¾î ½Ã½ºÅÛ ½ÃÀ۽ø¶´Ù ¾÷µ¥ÀÌÆ®¸¦ üũ¸¦ ÇÏ´Â µ¿ÀÛ¿¡¼­µµ ¸î Àϵ¿¾È Ãß°¡ÀûÀÎ ±¤°í ÇÁ·Î±×·¥À» ´Ù¿î·ÎµåÇÏÁö ¾Ê°í ±â´Ù¸®´Â Àγ»½ÉÀ» º¸¿©ÁÖ¾ú½À´Ï´Ù.


ÃÖÁ¾ÀûÀ¸·Î ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ°¡ ÀǵµÇÑ ±¤°í ÇÁ·Î±×·¥Àº ½Ã½ºÅÛ ½ÃÀ۽à ÀÌµé ¼­ºñ½º µî·Ï ÆÄÀϵéÀÌ ¡®C:\Documents and Settings\LocalService\Application Data¡¯ Æú´õ¿¡ ±¤°í ¼³Ä¡ ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ¿© ¹Ù·Î ¼³Ä¡ÇÏ´Â °ÍÀÌ ¾Æ´Ï¶ó, ´Ù½Ã ½Ã½ºÅÛ Àç½ÃÀÛ °úÁ¤¿¡¼­ ¼³Ä¡¸¦ Çϵµ·Ï ±¸¼ºÇÏ°í ÀÖ½À´Ï´Ù.


¶ÇÇÑ ±¤°í ÇÁ·Î±×·¥ ¼³Ä¡¿Í ÇÔ²² Ãß°¡ÀûÀ¸·Î 2°³ÀÇ ¼­ºñ½º µî·ÏÀ» À§ÇÑ ¾Ç¼º ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ´Â µ¿ÀÛµµ È®ÀÎÇÒ ¼ö ÀÖ¾ú½À´Ï´Ù.

 

1. h**p://down.program****.kr/lbnaprt.exe :: %SystemRoot%\System32\lbnaprt.dll

2. h**p://down.servicednls****.org/spltry.exe :: %SystemRoot%\System32\spltry.dll


ÇØ´ç ¹æ½Äµµ ÀÌÀü°ú µ¿ÀÏÇÏ°Ô exe ÆÄÀÏ ´Ù¿î·Îµå¸¦ ÅëÇØ ½Ã½ºÅÛ Æú´õ ³»¿¡ dll ÆÄÀÏÀ» »ý¼ºÇÏ¿© ´ÙÀ½°ú °°Àº ¼­ºñ½º Ç׸ñÀ» µî·ÏÇÏ°í ÀÖ½À´Ï´Ù.

¼­ºñ½º À̸§ : LbnAprt

¼³¸í : Applet Support Net Use Library

ÆÄÀÏ : %SystemRoot%\System32\lbnaprt.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LbnAprt

 

¼­ºñ½º À̸§ : Spltry

¼³¸í : Service Pack Utility Library

ÆÄÀÏ : %SystemRoot%\System32\spltry.dll

·¹Áö½ºÆ®¸® : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SPltry


ÀÌ·± ¹æ½ÄÀ» ÅëÇØ ±¤°í ÇÁ·Î±×·¥ ¶Ç´Â ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ°¡ ÀǵµÇϴ ƯÁ¤ ÇÁ·Î±×·¥À» »ç¿ëÀÚ ¸ô·¡ ¼³Ä¡ÇÒ ¼ö ÀÖ´Â ÀÏÁ¾ÀÇ Á»ºñPC¸¦ ±¸¼ºÇÏ¿© ¹èÆ÷ÀÚ°¡ ¿øÇÏ´Â ½Ã°£¿¡ ¿øÇÏ´Â ÇÁ·Î±×·¥À» ¸ô·¡ ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.


ÇöÀç±îÁö È®ÀÎµÈ ±¤°í ÇÁ·Î±×·¥Àº OneClickService, PlusTab, SideTab, ÀÎÅÍ³Ý ¼îÇθô °ü·Ã ¹ÙÅÁÈ­¸é ¹Ù·Î°¡±â, °Ë»ö °ø±ÞÀÚ ±âº»°ª º¯°æ°ú °°Àº ±¤°í ÇÁ·Î±×·¥ ¼³Ä¡¸¦ ÅëÇÏ¿© »ç¿ëÀÚ°¡ ÀÎÅͳÝÀ» ÀÌ¿ëÇÏ´Â °úÁ¤¿¡¼­ ÇÁ·Î±×·¥ ¹èÆ÷ÀÚ¿¡°Ô ±ÝÀüÀû ¼öÀÍÀ» À¯¹ßÇÒ ¼ö ÀÖµµ·Ï ÇÏ°í ÀÖ½À´Ï´Ù.

 


ÇöÀç ÇØ´ç ÇÁ·Î±×·¥ÀÌ ¼³Ä¡ÇÑ ¾Ç¼º ÆÄÀÏÀ» Á¦°ÅÇϱâ À§Çؼ­´Â ½Ã½ºÅÛ Æú´õ(%SystemRoot%\System32)¿¡ ¼³Ä¡µÈ dll ÆÄÀÏÀ» ã¾Æ ¼öµ¿À¸·Î »èÁ¦¸¦ ÇϽñ⠹ٶó¸ç, ·¹Áö½ºÆ®¸® Ç׸ñ¿¡¼­ °¢ ¼­ºñ½º µî·Ï°ªÀ» ã¾Æ »èÁ¦¸¦ ÇϽñ⠹ٶø´Ï´Ù.


À̹ø »ç·Ê¿Í °°ÀÌ Á¤»óÀûÀÎ ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÏ´Â °úÁ¤¿¡¼­ »ç¿ëÀÚ ¸ô·¡ ¼³Ä¡µÈ ¾Ç¼º ÆÄÀÏ·Î ÀÎÇÏ¿© Àڽŵµ ¸ð¸£°Ô ´Ù¾çÇÑ ±¤°í ÇÁ·Î±×·¥ µîÀÌ ¼³Ä¡µÇ´Â °ÍÀ» ÅëÇØ »ç¿ëÀÚ°¡ ÁÖÀǸ¦ ÇÑ´Ù°í °¨¿°À¸·ÎºÎÅÍ ¾ÈÀüÇÏÁö ¾ÊÀº ÀÎÅÍ³Ý Çö½ÇÀ» ¿³º¼ ¼ö ÀÖÁö ¾Ê¾Ò³ª »ý°¢µË´Ï´Ù.

[±Û _ º¸¾ÈÄ÷³´Ï½ºÆ® ¿ïÁö ¾Ê´Â ¹ú»õ(haslian@naver.com)]


<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>

  •  
  • 2
  • ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â Ä«Ä«¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â

Å«Àϳ¯»· 2011.02.19 00:10

¿À´Ã ÄÄÇ»Å͸¦ ÄѺ¸´Ï µü ÀÌ°Ô ±ò·ÁÀÖ´õ¶ó°í¿ä ¸Þ¸ð¸® kxxpxx;; Å«Àϳ¯»· Çߴµ¥ ´öºÐ¿¡ »ì¾Ò½À´Ï´Ù


  • ¡°
  •  SNS¿¡¼­µµ º¸¾È´º½º¸¦ ¹Þ¾Æº¸¼¼¿ä!! 
  • ¡±
¾Æ½ºÆ®·Ð½ÃÅ¥¸®Æ¼ ÆÄ¿öºñÁî 2023³â2¿ù23ÀÏ ½ÃÀÛ ³Ý¾Øµå ÆÄ¿öºñÁî ÁøÇà 2020³â1¿ù8ÀÏ ½ÃÀÛ~2021³â 1¿ù8ÀϱîÁö À§Áîµð¿£¿¡½º 2018
¼³¹®Á¶»ç
³»³â ȸ»ç¿¡ ²À µµÀÔÇÏ°í ½ÍÀº º¸¾È ¼Ö·ç¼Ç ¶Ç´Â Ç÷§ÆûÀº ¹«¾ùÀΰ¡¿ä?
XDR
EDR
AI º¸¾È
Á¦·ÎÆ®·¯½ºÆ®
°ø±Þ¸Á º¸¾È ü°è(SBOM)
Ŭ¶ó¿ìµå º¸¾È ¼Ö·ç¼Ç
±âŸ(´ñ±Û·Î)