°Ç°­ÇÑ ³» PC¸¦ À§ÇÑ ¼±Åà ViRobotÀÔ´Ï´Ù.

º¸¾È ¹× ¹ÙÀÌ·¯½º Á¤º¸

º¸¾ÈÀ§Çù DB Á¤º¸

Trojan.Win32.PSWIGames.142848

´Ù¸¥À̸§  
´ëÇ¥Àû Áõ»ó  ¾Ç¼ºÄÚµå ¼³Ä¡,Á¤º¸À¯Ãâ,ƯÁ¤ ÆÄÀÏ ´Ù¿î·Îµå
¹ß°ßÀÏ  ±¹³» : 2010-01-21   ÇØ¿Ü : 2010-01-21
ºÐ·ù  Æ®·ÎÀ̸ñ¸¶ Ȱµ¿ ¹üÀ§  À©32
ÆÄ±«µµ/È®»êµµ / ƯÁ¤ Ȱµ¿ÀÏ --
Á¦ÀÛ±¹°¡  Áß±¹ ¾Ïȣȭ ¿©ºÎ  ºñ¾Ïȣȭ
°¨¿°À§Ä¡  ¾øÀ½ ½Ã½ºÅÛ ¸Þ¸ð¸®
»óÁÖ¿©ºÎ
 ºñ»óÁÖ
¹ÙÀ̷κ¿
´ëÀÀÁ¤º¸
2010-01-20 [Áø´ÜÄ¡·á°¡´É]
  • ¿£Áø ¾÷µ¥ÀÌÆ®
  • ¹ÙÀÌ·¯½º ¹«·á°Ë»ç
  • ¹ÙÀ̷κ¿ üÇèÆÇ
  • Áõ»ó ¹× Á¤º¸
  • ½ºÅ©¸°¼¦
  • µ¿¿µ»ó ¸®ºä
  • Ä¡·á¹æ¹ý
Áõ»ó ¹× Á¤º¸

1.     ¾Ç¼ºÄڵ忡 °¨¿°µÇ¸é ´ÙÀ½°ú °°Àº °æ·Î¿¡ ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.

(½Ã½ºÅÛÆú´õ)\cyban.exe

(½Ã½ºÅÛÆú´õ)\ieban0.dll ¶Ç´Â ieban1.dll

(½Ã½ºÅÛÆú´õ)\cyban0.dll ¶Ç´Â cyban1.dll

(·çÆ®)\wmebm.exe

(·çÆ®)\autorun.inf

 

2.     ¾Ç¼ºÄÚµå´Â ¾Æ·¡¿Í °°ÀÌ ·¹Áö½ºÆ®¸®¸¦ Ãß°¡ ¹× ¼öÁ¤ÇÕ´Ï´Ù.

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

- cybansos : (½Ã½ºÅÛÆú´õ)\cyban.exe

 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}

- (½Ã½ºÅÛÆú´õ)\ieban.dll À» BHO ¿¡ µî·Ï

 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

- CheckedValue : 0

 

HKU\(SID)\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\

- Hidden : 2

 

HKU\(SID)\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\

- ShowSuperHidden : 0

 

3.     »ý¼ºµÈ ieban0.dll ¶Ç´Â ieban1.dll Àº iexplorer.exe ¿¡ ÀÎÁ§¼ÇµÇ¾î µ¿ÀÛÇϸç, »ç¿ëÀÚ °èÁ¤À» °¡·Îä´Â ¸ñÀûÀ¸·Î Á¦À۵Ǿú½À´Ï´Ù. ¸ñÇ¥·Î ÇÏ´Â »çÀÌÆ®´Â ´ÙÀ½°ú °°½À´Ï´Ù.

12sky2.paran.com

aion.plaync.co.kr

c9.hangame.com

df.nexon.com

dho.netmarble.net

fifaonline.pmang.com

hangame.com

id.hangame.com

karos.paran.com

knight.mgame.com

lotro.hangame.com

maplestory.nexon.com

netmarble.net

sp1.nexon.com

tz.kr.gameclub.com

wffm.mgame.com

www.champagnemania.co.kr

www.gptem.com

www.hangame.com

www.nate.com

www.on3.co.kr

www.pmang.com

yulgang.mgame.com

 

4.     »ý¼ºµÈ cyban0.dll ¶Ç´Â cyban1.dll Àº ¸ðµç ÇÁ·Î¼¼½º¿¡ ÀÎ젹¼ÇµÇ¾î µ¿ÀÛÇϸç, »ç¿ëÀÚ °èÁ¤À» °¡·Îä´Â ¸ñÀûÀ¸·Î Á¦À۵Ǿú½À´Ï´Ù. ¸ñÇ¥·Î ÇÏ´Â ÇÁ·Î¼¼½º´Â ´ÙÀ½°ú °°½À´Ï´Ù.

amo.exe : Ä«·Î½º¿Â¶óÀÎ

c9.exe : C9

darkeden.exe : ´ÙÅ©¿¡µ§

dnf.exe : ´øÀü ¾Ø ÆÄÀÌÅÍ

ge.exe : ±×¶ó³ªµµ¿¡½ºÆÄ´Ù

gersang.exe : °Å»ó

goonzu.exe : ±ºÁÖ

InphaseNXD.EXE : Å×ÀÏÁîÀ§¹ö

maplestory.exe : ¸ÞÀÌÇýºÅ丮

Mir3Game.exe : ¹Ì¸£ÀÇ Àü¼³ 3

pleione.dll : ¸¶ºñ³ë±â

so3d.exe : ¾Á¿Â¶óÀÎ

TwelveSky2.exe : ½ÊÀÌÁöõ 2

winbaram.exe : ¹Ù¶÷ÀÇ ³ª¶ó

wow.exe : ¿ùµå ¿Àºê ¿öÅ©·¹ÇÁÆ®

 

5.     ¶ÇÇÑ cyban0.dll ¶Ç´Â cyban1.dll Àº ƯÁ¤ÇÁ·Î¼¼½ºÀÇ µ¿ÀÛÀ» ¹æÇØÇÕ´Ï´Ù. ¸ñÇ¥·Î ÇÏ´Â ÇÁ·Î¼¼½º´Â ´ÙÀ½°ú °°½À´Ï´Ù.

ALUSCHEDULERSVC.EXE

ASHDISP.EXE

avast.setup

AVGNT.EXE

AVGRSX.EXE

avgupd.exe

AVP.EXE

AYAGENT.AYE

AYUpdate.aye

CCSVCHST.EXE

eguiEmon.dll

eguiEpfw.dll

EKRN.EXE

ekrnEmon.dll

ekrnEpfw.dll

luall.exe

mcupdate.exe

preupd.exe

prupdate.ppl

setup.ovr

SfFnUp.exe

UFSEAGNT.EXE

UfUpdUi.exe

update.exe

updater.dll

VCRMON.EXE

VSTSKMGR.EXE

vsupdate.dll

 

6.     ¾Ç¼ºÄÚµå´Â À¥»çÀÌÆ® http://www.yxhxo.x7x.com (2x2.1x1.1x5.1x7) ¿¡¼­ ƯÁ¤ÆÄÀÏÀ» ´Ù¿î·Îµå ÇÕ´Ï´Ù.

     1hg/ah1.rar

     1hg/ah.rar

 

 


¸ñ·Ïº¸±â