°Ç°­ÇÑ ³» PC¸¦ À§ÇÑ ¼±Åà ViRobotÀÔ´Ï´Ù.

º¸¾È ¹× ¹ÙÀÌ·¯½º Á¤º¸

º¸¾ÈÀ§Çù DB Á¤º¸

Adware.XP2010.R.345088

´Ù¸¥À̸§  
´ëÇ¥Àû Áõ»ó  ½Ã½ºÅÛ ¿À·ù¹ß»ý,¾ÇÀÇÀûÀÎ »ç¿ë°¡´É,ÀçºÎÆÃ½Ã ÀÚµ¿½ÇÇà,Á¤»ó ÇÁ·Î±×·¥ ¼³Ä¡/¿î¿µ ¹æÇØ,ƯÁ¤ À¥»çÀÌÆ® À̵¿,ÆÄÀÏ »èÁ¦ºÒ°¡,ÆË¾÷â Ãâ·Â,ÇÁ·Î±×·¥ »èÁ¦ ºÒ°¡
¹ß°ßÀÏ  ±¹³» : 2010-02-02   ÇØ¿Ü : 2010-02-02
ºÐ·ù  Adware Ȱµ¿ ¹üÀ§  
À§Çèµµ/È®»êµµ / ƯÁ¤ Ȱµ¿ÀÏ --
Á¦ÀÛ±¹°¡  ºÒºÐ¸í ¾Ïȣȭ ¿©ºÎ  ºñ¾Ïȣȭ
°¨¿°À§Ä¡  À¥ÆäÀÌÁö,ÀÀ¿ëÇÁ·Î±×·¥°ú ÇÔ²² ¼³Ä¡,ÆÄÀϽÇÇà ½Ã½ºÅÛ ¸Þ¸ð¸®
»óÁÖ¿©ºÎ
 
¹ÙÀ̷κ¿
´ëÀÀÁ¤º¸
2010-02-03 [Áø´ÜÄ¡·á°¡´É]
  • ¿£Áø ¾÷µ¥ÀÌÆ®
  • ¹ÙÀÌ·¯½º ¹«·á°Ë»ç
  • ¹ÙÀ̷κ¿ üÇèÆÇ
  • Áõ»ó ¹× Á¤º¸
  • ½ºÅ©¸°¼¦
  • µ¿¿µ»ó ¸®ºä
  • Ä¡·á¹æ¹ý
Áõ»ó ¹× Á¤º¸

> [µ¿¿µ»ó ¸®ºä] ÅÇÀ¸·Î À̵¿ÇÏ¿© È®ÀÎ ÇÒ ¼ö ÀÖÀ¸¸ç, ¾à 8ºÐ 41ÃÊÀÇ ¿µ»óÀÔ´Ï´Ù. <

 

 

[Adware.XP2010.R.345088] Àº(´Â) ¹æÈ­º®À» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤À» º¯°æÇϰí, À©µµ¿ì ¾÷µ¥ÀÌÆ® È­¸é°ú À¯»çÇÑ UI¸¦ ÅëÇØ ¼³Ä¡µÈ´Ù.

 

      - ´Ù·®ÀÇ °æ°í¹®±¸¿Í ÇÔ²² ÇãÀ§ °¨¿°·Î±×¸¦ º¸¿©ÁÖ¸ç µî·Ï/°áÁ¦¸¦ ¿ä±¸ÇÑ´Ù.

 

¶ÇÇÑ, Internet Explorer ½ÇÇà ½Ã ¹«Á¶°Ç µî·Ï/°áÁ¦¸¦ ¿ä±¸Çϰí, µî·Ï/°áÁ¦¸¦ Ãë¼ÒÇÒ °æ¿ì Internet Explorer¸¦ ÀÌ¿ëÇÒ ¼ö ¾ø´Ù.

 

-     ÇãÀ§¹é½ÅÀÇ À̸§Àº XP (¹é½Å°ú À¯»çÇÑ À̸§ = ·£´ý¸í) 2010 ÀÌ´Ù. 

-     ÇØ´ç ÇÁ·Î±×·¥À» »èÁ¦ ½Ã exe °ü·Ã ÆÄÀÏÀ» Á¤»óÀûÀ¸·Î ÀÌ¿ëÇÒ ¼ö ¾ø´Ù.

 

 

[±×¸² 1.] ¹æÈ­º® º¯°æ È­¸é ½ÇÇà ½Ã ¹æÈ­º®À» ºñȰ¼ºÈ­ ½ÃŲ´Ù.

 

[±×¸² 2.] ¼³Ä¡ È­¸é ¿Ïº® ÀçÇöÀ» ÅëÇØ ¼³Ä¡ ½Ã ÀǽÉÀ» »çÁö ¾Ê´Â´Ù.

 

[±×¸² 3.] ½ºÄµ È­¸é – 99% ÇѱÛÈ­°¡ µÇ¾îÀÖ´Ù.

 

[±×¸² 3-1.] ¼³Ä¡ ½Ã ´Þ¶óÁö´Â À̸§ - °°Àº ÆÄÀÏÀÌ¶óµµ ¼³Ä¡ ½Ã UI°¡ ¹Ù²ï´Ù.

 

[±×¸² 3-2.] ¼³Ä¡ ½Ã ´Þ¶óÁö´Â À̸§ - °°Àº ÆÄÀÏÀÌ¶óµµ ¼³Ä¡ ½Ã UI°¡ ¹Ù²ï´Ù.

 

[±×¸² 4.] ÇãÀ§ ½Ã½ºÅÛ º¸¾È °æ°í ½ºÄµÀÌ ³¡³ªÀÚ È°¼ºÈ­¸¦ ¿ä±¸ÇÑ´Ù.

 

[±×¸² 5.] µî·Ï¿ä±¸ È­¸é ÇöȤµÈ ¹®±¸·Î µî·ÏÀ» ¿ä±¸ÇÑ´Ù.

 

[±×¸² 6.] °áÁ¦¿ä±¸ È­¸é - 6°³¿ù¿¡ $49.95ÀÌ´Ù. (2/3ÀÏ È¯À²·Î´Â ¾à 57,500¿ø)

 

[±×¸² 7.] ÀÏÁ¤½Ã°£¸¶´Ù ³ªÅ¸³ª´Â °æº¸ È­¸é ·£´ýÇÑ IPÁÖ¼Ò/Æ÷Æ®¸¦ ¶ç¿ì¸ç ´Ù½Ã ÇÑ ¹ø °áÁ¦¸¦ ¿ä±¸ÇÑ´Ù.

 

[±×¸² 8.] Internet Explorer ½ÇÇà ½Ã È­¸é ¶Ç!! °áÁ¦¸¦ ¿ä±¸ÇÑ´Ù.

 

[±×¸² 9.] Internet Explorer ¿À·ù °áÁ¦¸¦ °ÅºÎÇϸ顦 ¹«¼·°Ôµµ ÀÎÅͳÝÀ» ÀÌ¿ëÇÒ ¼ö ¾ø´Ù.

 

[±×¸² 10.] ´Ù¾çÇÑ °æ°í È­¸é 1

 

[±×¸² 11.] ´Ù¾çÇÑ °æ°í È­¸é 2

 

[±×¸² 12.] ´Ù¾çÇÑ °æ°í È­¸é 3

 

[±×¸² 13.] ´Ù¾çÇÑ °æ°í È­¸é 4

 

[±×¸² 14.] ´Ù¾çÇÑ °æ°í È­¸é 5

 

[±×¸² 15.] ´Ù¾çÇÑ °æ°í È­¸é 6

 

 

< °ü·Ã URL >

 

hxxp://(»ý·«).com/1054001112

 

 

< ÆÄÀÏ >

 

[Adware.XP2010.R.345088] ÀÌ(°¡) »ý¼ºÇÏ´Â ÆÄÀÏÀº ¾Æ·¡¿Í °°´Ù.

 

(»ç¿ëÀÚ°èÁ¤ Æú´õ)\Local Settings\Application Data\av.exe

(»ç¿ëÀÚ°èÁ¤ Æú´õ)\Local Settings\Application Data\PQyt

 

 

< ·¹Áö½ºÆ®¸® >

 

[Adware.XP2010.R.345088] ÀÌ(°¡) »ý¼ºÇÏ´Â ·¹Áö½ºÆ®¸®´Â ¾Æ·¡¿Í °°´Ù.

 

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

À̸§ : EnableFirewall

°ª    : 0x00000000

HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

À̸§ : EnableFirewall

°ª    : 0x00000000

HKCU\Software\Classes\.exe\shell\open\command

°ª    :  ""(»ç¿ëÀÚ°èÁ¤ Æú´õ)\Local Settings\Application Data\av.exe" /START "%1" %*"

HKCU\Software\Classes\.exe\shell\open\command

À̸§ : IsolatedCommand

°ª    : ""%1" %*"

HKCU\Software\Classes\.exe\shell\runas\command

°ª    : ""%1" %*"

HKCU\Software\Classes\.exe\shell\runas\command

À̸§ : IsolatedCommand

°ª    : ""%1" %*"

HKCU\Software\Classes\.exe\shell\start\command

°ª    : ""%1" %*"

HKCU\Software\Classes\.exe\shell\start\command

À̸§ : IsolatedCommand

°ª    : ""%1" %*"

HKCU\Software\Classes\.exe\DefaultIcon

°ª    : "%1"

HKCU\Software\Classes\.exe

À̸§ : Content Type

°ª    : "application/x-msdownload"

HKCU\Software\Classes\secfile\shell\open\command

°ª    : ""(»ç¿ëÀÚ°èÁ¤ Æú´õ)\Local Settings\Application Data\av.exe" /START "%1" %*"

HKCU\Software\Classes\secfile\shell\open\command

À̸§ : IsolatedCommand

°ª : ""%1" %*"

HKCU\Software\Classes\secfile\shell\runas\command

°ª    : ""%1" %*"

HKCU\Software\Classes\secfile\shell\runas\command

À̸§ : IsolatedCommand

°ª    : ""%1" %*"

HKCU\Software\Classes\secfile\shell\start\command

°ª    : ""%1" %*"

HKCU\Software\Classes\secfile\shell\start\command

À̸§ : IsolatedCommand

°ª    : ""%1" %*"

HKCU\Software\Classes\secfile\DefaultIcon

°ª    : "%1"

HKCU\Software\Classes\secfile

°ª    : "Application"

HKCU\Software\Classes\secfile

À̸§ : Content Type

°ª    : "application/x-msdownload"

 

-      º¯°æ Àü ·¹Áö½ºÆ®¸®

HKCU\Software\Classes\.exe

°ª : "exefile"

HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command

°ª : ""(ÇÁ·Î±×·¥ Æú´õ)\Internet Explorer\iexplore.exe""

 

-      º¯°æ ÈÄ ·¹Áö½ºÆ®¸®

HKCU\Software\Classes\.exe

°ª : "secfile"

HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command

°ª : ""(»ç¿ëÀÚ°èÁ¤ Æú´õ)\Local Settings\Application Data\av.exe" /START "(ÇÁ·Î±×·¥Æú´õ)\Internet Explorer\iexplore.exe""

 

 

< Ç¥±â¹ý >

 

"(»ç¿ëÀÚ°èÁ¤ Æú´õ)" ¶õ »ç¿ëÀÚ ¼³Á¤¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î

C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤) ÀÌ´Ù.

 

"(ÇÁ·Î±×·¥ Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î

C:\Program Files ÀÌ´Ù.

 


¸ñ·Ïº¸±â