
| ´Ù¸¥À̸§ | [Kaspresky] Trojan-Downloader.Win32.FraudLoad.wytd | ||
|---|---|---|---|
| ´ëÇ¥Àû Áõ»ó | ¹ÙÅÁÈ¸é ¾ÆÀÌÄÜ ¼³Ä¡,ÀçºÎÆÃ½Ã ÀÚµ¿½ÇÇà,ÆË¾÷â Ãâ·Â,ÇãÀ§ ¾ÈƼ½ºÆÄÀÌ¿þ¾î ¼³Ä¡ À¯µµ | ||
| ¹ß°ßÀÏ | ±¹³» : 2010-02-24 ÇØ¿Ü : 2010-02-24 | ||
| ºÐ·ù | Adware | Ȱµ¿ ¹üÀ§ | |
| À§Çèµµ/È®»êµµ | / ![]() |
ƯÁ¤ Ȱµ¿ÀÏ | -- |
| Á¦ÀÛ±¹°¡ | ºÒºÐ¸í | ¾ÏÈ£È ¿©ºÎ | ºñ¾ÏÈ£È |
| °¨¿°À§Ä¡ | ¾Ç¼ºÄڵ忡 ÀÇÇØ ´Ù¿î·Îµå,ÀÀ¿ëÇÁ·Î±×·¥°ú ÇÔ²² ¼³Ä¡,ÆÄÀϽÇÇà | ½Ã½ºÅÛ ¸Þ¸ð¸® »óÁÖ¿©ºÎ |
|
| ¹ÙÀ̷κ¿ ´ëÀÀÁ¤º¸ |
2010-02-25 [Áø´ÜÄ¡·á°¡´É]
|
||
> [µ¿¿µ»ó ¸®ºä] ÅÇÀ¸·Î À̵¿ÇÏ¿© È®ÀÎ ÇÒ ¼ö ÀÖÀ¸¸ç, ¾à 11ºÐ 28ÃÊÀÇ ¿µ»óÀÔ´Ï´Ù. < [Spyware.FraudLoad.Do] Àº(´Â) »ç¿ëÀÚ µ¿ÀÇ ¾øÀÌ ¼³Ä¡µÇ¸ç, Paladin Antivirus¸¦ ´Ù¿î·ÎµåÇÏ¿© ½ÇÇà½ÃŲ´Ù. ´Ù¿î·Îµå µÈ Paladin Antivirus´Â ÀÏÁ¤½Ã°£¸¶´Ù °æ°í¸¦ ¶ç¿ì¸ç, ÇØ´ç °æ°í´Â Ãâ·ÂµÇ¸é¼ ¹ÙÅÁȸéÀ» ºñȰ¼ºÈ ½ÃŲ´Ù.
- ºÎÆÃ ½Ã ÀÚµ¿ ½ÇÇà µÉ ¼ö ÀÖµµ·Ï ·¹Áö½ºÆ®¸®¿¡ ÀÚ½ÅÀ» µî·ÏÇÑ´Ù. [±×¸² 1.] ¼³Ä¡µÇ´Â ¸ð½À
[±×¸² 2.] ½ºÄµ ȸé
[±×¸² 3.] MS»çÀÇ º¸¾È¼¾ÅÍ¿Í µ¿ÀÏÇÑ UI
[±×¸² 4.] ÀÏÁ¤½Ã°£¸¶´Ù ¹ÙÅÁÈ¸é ºñȰ¼ºÈ ¸ð½À1
[±×¸² 5.] ÀÏÁ¤½Ã°£¸¶´Ù ¹ÙÅÁÈ¸é ºñȰ¼ºÈ ¸ð½À2
[±×¸² 6.] ÀÏÁ¤½Ã°£¸¶´Ù ¹ÙÅÁÈ¸é ºñȰ¼ºÈ ¸ð½À3
[±×¸² 7.] °æ°í ȸé1
[±×¸² 8.] °æ°í ȸé2
[±×¸² 9.] °æ°í ȸé3
[±×¸² 10.] °æ°í ȸé4
[±×¸² 11.] ¾ÆÀÌÄÜ »ý¼º
[±×¸² 12.] °áÁ¦ ¿ä±¸ ȸé
< °ü·Ã URL > hxxp://(»ý·«).cn/readdatagateway.php?type=(»ý·«) hxxp://(»ý·«).cn/pav_db hxxp://(»ý·«).cn/readdatagateway.php?type=(»ý·«)&version=3.0 hxxp://(»ý·«).cn/pav_ext hxxp://(»ý·«).cn/pav_hook hxxp://(»ý·«).cn/pav_un hxxp://(»ý·«).cn/pav_main < ÆÄÀÏ > [Spyware.FraudLoad.Do] ÀÌ(°¡) »ý¼ºÇÏ´Â ÆÄÀÏÀº ¾Æ·¡¿Í °°´Ù. (ºü¸¥½ÇÇà Æú´õ)\Paladin Antivirus.lnk (Àӽà Æú´õ)\4otjesjty.mof (Àӽà Æú´õ)\pav.dat (Àӽà Æú´õ)\pavr.dat (Àӽà Æú´õ)\(·£´ý¸í).tmp (Àӽà Æú´õ)\(·£´ý¸í).tmp (Àӽà Æú´õ)\(·£´ý¸í).tmp (Àӽà Æú´õ)\(·£´ý¸í).tmp (Àӽà Æú´õ)\(·£´ý¸í).tmp (¹ÙÅÁÈ¸é Æú´õ)\Paladin Antivirus Support.lnk (¹ÙÅÁÈ¸é Æú´õ)\Paladin Antivirus.lnk (¸ðµç »ç¿ëÀÚ°èÁ¤ Æú´õ)\¹ÙÅÁ ȸé\nudetube.com.lnk (¸ðµç »ç¿ëÀÚ°èÁ¤ Æú´õ)\¹ÙÅÁ ȸé\pornotube.com.lnk (¸ðµç »ç¿ëÀÚ°èÁ¤ Æú´õ)\¹ÙÅÁ ȸé\youporn.com.lnk (Àӽà Æú´õ)\1.ico (Àӽà Æú´õ)\2.ico (Àӽà Æú´õ)\3.ico (Àӽà Æú´õ)\dhdhtrdhdrtr5y (Àӽà Æú´õ)\eventcreatexp.exe < ·¹Áö½ºÆ®¸® > [Spyware.FraudLoad.Do] ÀÌ(°¡) »ý¼ºÇÏ´Â ·¹Áö½ºÆ®¸®´Â ¾Æ·¡¿Í °°´Ù. HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SimpleShlExt HKLM\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus HKLM\SOFTWARE\Paladin Antivirus HKCU\Software À̸§ : eee0bd2f-ff2e-46ef-83fb-d4fda84462a3 HKCU\Software\Microsoft\Windows\CurrentVersion\Run À̸§ : eventcreatexp.exe °ª : "(Àӽà Æú´õ)\eventcreatexp.exe" HKCU\Software\Microsoft\Windows\CurrentVersion\Run À̸§ : Paladin Antivirus °ª : ""(ÇÁ·Î±×·¥ Æú´õ)\Paladin Antivirus\pav.exe" -noscan" < Æú´õ > [Spyware.FraudLoad.Do] ÀÌ(°¡) »ý¼ºÇÏ´Â Æú´õ´Â ¾Æ·¡¿Í °°´Ù. (»ç¿ëÀÚ°èÁ¤ Æú´õ)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥\Paladin Antivirus (ÇÁ·Î±×·¥ Æú´õ)\Paladin Antivirus < Ç¥±â¹ý > "(ºü¸¥½ÇÇà Æú´õ)" ¶õ ¿î¿µÃ¼Á¦(ȤÀº »ç¿ëÀÚ)¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\Application Data\Microsoft\Internet Explorer\Quick Launch ÀÌ´Ù. "(Àӽà Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\Local Settings\Temp ÀÌ´Ù. "(¹ÙÅÁÈ¸é Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤)\¹ÙÅÁ ȸé ÀÌ´Ù. "(¸ðµç »ç¿ëÀÚ°èÁ¤ Æú´õ)" ¶õ »ç¿ëÀÚ ¼³Á¤¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(¸ðµç »ç¿ëÀÚ°èÁ¤) ÀÌ´Ù. "(»ç¿ëÀÚ°èÁ¤ Æú´õ)" ¶õ »ç¿ëÀÚ ¼³Á¤¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Documents and Settings\(»ç¿ëÀÚ°èÁ¤) ÀÌ´Ù. "(ÇÁ·Î±×·¥ Æú´õ)" ¶õ ¿î¿µÃ¼Á¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖÀ¸¸ç ÀϹÝÀûÀ¸·Î C:\Program Files ÀÌ´Ù. |
|||
|
|
|||
|
|
|||
|
1. WinXP / ME »ç¿ëÀÚ¶ó¸é ½Ã½ºÅÛ º¹¿ø ±â´ÉÀ» ºñȰ¼ºÈ ÇÑ´Ù. a. ½Ã½ºÅÛ º¹¿ø ºñȰ¼ºÈ ¹æ¹ý (WInXP) b. ½Ã½ºÅÛ º¹¿ø ºñȰ¼ºÈ ¹æ¹ý (WinME) ½Ã½ºÅÛ º¹¿ø ±â´ÉÀ» ºñȰ¼ºÈ ÇÏ´Â ÀÌÀ¯´Â ±ú²ýÇÏ°Ô ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇϱâ À§ÇؼÀÌ´Ù. °ü·Ã Á¤º¸´Â MS ȨÆäÀÌÁö ±â¼ú¹®¼(Q263455) ¿¡¼ È®ÀÎ ÇÒ ¼ö ÀÖ´Ù. 2. ¹é½Å ¿£ÁøÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ® ÇÑ´Ù. ÀÌ ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇϱâ À§Çؼ´Â ÃÖ½ÅÀÇ ¹é½Å ¿£ÁøÀÌ ÇÊ¿äÇÏ´Ù. a. ¹ÙÀ̷κ¿ Á¤½Ä »ç¿ëÀÚÀÇ °æ¿ì : - Á¦Ç°±ºÀ» ÅëÇØ ¾÷µ¥ÀÌÆ® b. ¹ÙÀ̷κ¿À» »ç¿ëÇÏÁö ¾Ê´Â ÀÏ¹Ý °í°´ - ¶óÀ̺êÄÝ(¹«·á°Ë»ç) »çÀÌÆ®¸¦ ÀÌ¿ëÇÑ ¹ÙÀÌ·¯½º °Ë»ç - ¹ÙÀ̷κ¿ 7ÀÏ Æò°¡ÆÇ ¼³Ä¡ ÈÄ ¹ÙÀÌ·¯½º °Ë»ç 3. ½ºÆÄÀÌ¿þ¾î °Ë»ç¸¦ ÇÑ´Ù. a. ¹ÙÀ̷κ¿À» ½ÇÇàÇÏ¿©, ȯ°æ ¼³Á¤¿¡¼ ½ºÆÄÀÌ / ¾Öµå¿þ¾î °Ë»ç¸¦ ÇÑ´Ù. - Desktop 5.X : [µµ±¸]-[ȯ°æ¼³Á¤]-[½ºÆÄÀÌ¿þ¾î °Ë»ç] ¸ðµç ÆÄÀÏ Ã¼Å© - ¶óÀ̺êÄÝ(¹«·á°Ë»ç) : [°í±Þ°Ë»ç] üũ b. ¹ß°ßµÇ´Â ¸ðµç ½ºÆÄÀÌ¿þ¾î¿¡ ´ëÇØ¼ Ä¡·áÇÑ´Ù. c. [ÀçºÎÆÃ ÈÄ ÀÚµ¿ Ä¡·á] ¸Þ½ÃÁö°¡ ³ªÅ¸³µ´Ù¸é ÀçºÎÆÃÀ» ÇÑ ÈÄ¿¡ ´Ù½Ã °Ë»çÇÑ´Ù. |

