°Ç°­ÇÑ ³» PC¸¦ À§ÇÑ ¼±Åà ViRobotÀÔ´Ï´Ù.

º¸¾È ¹× ¹ÙÀÌ·¯½º Á¤º¸

º¸¾ÈÀ§Çù DB Á¤º¸

PSWTool.SnadBoy

´Ù¸¥À̸§  [Kaspersky Lab]not-a-virus:PSWTool.Win32.SnadBoy.2011
´ëÇ¥Àû Áõ»ó  ¾ÇÀÇÀûÀÎ »ç¿ë°¡´É
¹ß°ßÀÏ  ±¹³» : 2000-12-15   ÇØ¿Ü : 2000-12-15
ºÐ·ù  PSWTool Ȱµ¿ ¹üÀ§  
À§Çèµµ/È®»êµµ / ƯÁ¤ Ȱµ¿ÀÏ --
Á¦ÀÛ±¹°¡  ºÒºÐ¸í ¾Ïȣȭ ¿©ºÎ  ºñ¾Ïȣȭ
°¨¿°À§Ä¡  ÆÄÀϽÇÇà ½Ã½ºÅÛ ¸Þ¸ð¸®
»óÁÖ¿©ºÎ
 
¹ÙÀ̷κ¿
´ëÀÀÁ¤º¸
2007-10-18 [Áø´ÜÄ¡·á°¡´É]
  • ¿£Áø ¾÷µ¥ÀÌÆ®
  • ¹ÙÀÌ·¯½º ¹«·á°Ë»ç
  • ¹ÙÀ̷κ¿ üÇèÆÇ
  • Áõ»ó ¹× Á¤º¸
  • ½ºÅ©¸°¼¦
  • µ¿¿µ»ó ¸®ºä
  • Ä¡·á¹æ¹ý
Áõ»ó ¹× Á¤º¸

 

[PSWTool.SnadBoy] ´Â »ç¿ëÀÚÀÇ À©µµ¿ì¿¡ ÀúÀåµÇ¾î ÀÖ´Â ºñ¹Ð¹øÈ£¸¦ Å©·¢ÇÏ¿© º¼ ¼ö ÀÖ°Ô ÇØÁÖ´Â À¯Çذ¡´É ÇÁ·Î±×·¥ÀÌ´Ù.

 

[±×¸² 1.] SnadBoy ½ÇÇà È­¸é.


 




InternetExplorer ÀÇ °¢Á¾ »çÀÌÆ® °èÁ¤ Á¢¼Ó Á¤º¸, À©µµ¿ì¿¡¼­ µ¿ÀÛÇÏ´Â °¢Á¾ ¾îÇø®ÄÉÀ̼ÇÀÇ ·Î±×ÀÎ Á¤º¸¸¦ º¼ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.

 

[±×¸² 2.] A Æ÷ÅÐ »çÀÌÆ® °¡ÀÔ Á¤º¸ ÀÔ·Â ÆäÀÌÁöÀÇ ºñ¹Ð¹øÈ£ Å©·¢.

 

[±×¸² 3.] B Æ÷ÅÐ »çÀÌÆ® ·Î±×ÀÎ ºñ¹Ð¹øÈ£ Å©·¢.

 

[±×¸² 4.] À¥µð½ºÅ© ·Î±×ÀÎ Á¤º¸ Å©·¢.

 

[±×¸² 5.] FTP ·Î±×ÀÎ Á¤º¸ Å©·¢.

 

 



 

< °ü·Ã URL >

http://www.snadboy.com/


< ÆÄÀÏ >

[PSWTool.SnadBoy] ÀÌ(°¡) »ý¼ºÇÏ´Â ÆÄÀÏÀº ¾Æ·¡¿Í °°´Ù.

(ÇÁ·Î±×·¥ Æú´õ)\SnadBoy's Revelation v2\Revelation.lnk
(ÇÁ·Î±×·¥ ÆÄÀÏÁî Æú´õ)\SnadBoy's Revelation v2\INSTALL.LOG
(ÇÁ·Î±×·¥ ÆÄÀÏÁî Æú´õ)\SnadBoy's Revelation v2\Revelation.exe
(ÇÁ·Î±×·¥ ÆÄÀÏÁî Æú´õ)\SnadBoy's Revelation v2\RevelationHelper.dll
(ÇÁ·Î±×·¥ ÆÄÀÏÁî Æú´õ)\SnadBoy's Revelation v2\UNWISE.EXE


< ·¹Áö½ºÆ®¸® >

[PSWTool.SnadBoy] ÀÌ(°¡) »ý¼ºÇÏ´Â ·¹Áö½ºÆ®¸®´Â ¾Æ·¡¿Í °°´Ù.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\DisplayName: "SnadBoy's Revelation v2"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\UninstallString: "C:\PROGRA~1\SNADBO~1\UNWISE.EXE C:\PROGRA~1\SNADBO~1\INSTALL.LOG"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\DisplayVersion: "2.0.1.100"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\HelpLink: "http://www.snadboy.com"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\Publisher: "SnadBoy Software"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnadBoy's Revelation v2\URLInfoAbout: "http://www.snadboy.com"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\FanqObl'f Eriryngvba i2\Eriryngvba.yax: 04 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00
HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrator\¹ÙÅÁ È­¸é\tdesk30b-zzezil\SetupRevelationV2.exe: "SnadBoy's Revelation v2"


< Ç¥±â¹ý >

"(¸ðµç »ç¿ëÀÚ°èÁ¤ Æú´õ)" ¶õ »ç¿ëÀÚ ¼³Á¤¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Documents and Settings\(¸ðµç »ç¿ëÀÚ°èÁ¤) ÀÌ´Ù

"(¹ÙÅÁÈ­¸é Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\¹ÙÅÁ È­¸é ÀÌ´Ù.

"(ºü¸¥½ÇÇà Æú´õ)" ¶õ ¿î¿µÃ¼Á¦(ȤÀº »ç¿ëÀÚ)¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\Application Data\Microsoft\Internet Explorer\Quick Launch ÀÌ´Ù.

"(Àӽà Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\Local Settings\Temp ÀÌ´Ù.

"(ÇÁ·Î±×·¥ Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Program Files ÀÌ´Ù.

¡°(À©µµ¿ì Æú´õ)¡± ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Windows ÀÌ´Ù.

¡°(½Ã½ºÅÛ Æú´õ)¡± ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î
C:\Windows\System32 ÀÌ´Ù.


¸ñ·Ïº¸±â