¸ÞÀÏ Á¦¸ñÀÌ Happy New Year ÀÌ°í, Christmas.exeÆÄÀÏÀÌ Ã·ºÎµÇ¾î ÀÖ´Â ¸ÞÀÏÀº ¹Ù·Î »èÁ¦ÇϽñ⠹ٶø´Ï´Ù.
¡Ù °³¿ä
KERZAC.A, W32.Zacker.C@mm, W32.zeeeak.A@mm µîÀ¸·Îµµ ºÒ¸®¸ç 12¿ù 19ÀÏ ¿Ü±¹¿¡¼ ÃÖÃÊ ¹ß°ßµÇ¾î 20ÀÏ ÇöÀç±îÁö ±¹³»¿¡´Â À¯ÀÔµÇÁö ¾ÊÀº W32/Maldal.c@MMÀº Å©¸®½º¸¶½º Ä«µåÀÎ °Íó·³ °¡ÀåÇÏ¿© ÆÄÀϸí "Christmas.exe"À» ÀÌ¿ëÇÑ´Ù. ºñÁÖ¾ó º£ÀÌÁ÷ ½ºÅ©¸³Æ®·Î ÀÛ¼ºµÇ¾úÀ¸¸ç ¸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆĵǸç ÀϺΠ¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥°ú ½Ã½ºÅÛ ÆÄÀÏÀ» »èÁ¦, Å°º¸µåÀÇ ÀÛµ¿ÀÌ µÇÁö ¾Ê´Â ÇÇÇØÁõ»óÀ» °®´Â´Ù.
¡Ù ÀüÆÄ¿ø¸® ¹× ÇÇÇØÁõ»ó
⼔ °¨¿°¿ø¸®
¾Æ¿ô·è ÁÖ¼Ò·Ï¿¡ ÀÖ´Â ¸ðµÎ¿¡°Ô ´ÙÀ½°ú °°Àº Çü½ÄÀÇ ¸ÞÀÏÀ» º¸³½´Ù.
Á¦ ¸ñ : Happy New Year
º» ¹® : Hii ,
I can't describe my feelings
But all I can say is
Happy new year :-)
bye
÷ ºÎ : Christmas.exe v
⼔ ÇÇÇØÁõ»ó
¿úÀÌ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°Àº Å©¸®½º¸¶½º Ä«µå ȸéÀÌ ³ªÅ¸³ª°í
´ÙÀ½°ú °°Àº ·¹Áö½ºÆ®¸® °ªÀ» ÀÌ¿ëÇÏ¿© ÄÄÇ»ÅÍÀÇ À̸§À» "Zacker"·Î º¯°æÇϸç
HKEY_LOCAL_MACHINESystemCurrentControlSetControlComputerNameZacker
´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸® °ªÀ» Ãß°¡ÇÏ°í
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunZacker
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunZaCker = À©µµ¿ìÆú´õCHRISTMAS.EXE
À©µµ¿ì Æú´õ¿¡ Christmas.exe ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
ÀÎÅÍ³Ý ÀͽºÇ÷η¯ÀÇ ½ÃÀÛ ÆäÀÌÁö¸¦ º¯°æÇÏ°í
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMainStart page = //xxx .com//ZaCker.htm
ÇØ´ç ÆäÀÌÁö¿¡ Á¢¼ÓÇÏ´Â °æ¿ì Microsoft virtual machine Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ÀÚ¹Ù ½ºÅ©¸³Æ® Äڵ尡 ½ÇÇàµÇ¾î VBS/Rols ¿úÀ» º¹»çÇÏ°í ´ÙÀ½°ú °°Àº ¹é½Å ÇÁ·Î±×·¥À» »èÁ¦ÇÑ´Ù. (ÇöÀç ÇØ´ç À¥ÆäÀÌÁö´Â ÁßÁöµÇ¾ú´Ù.)
Program FilesZone Labs
Program FilesAntiViral Toolkit Pro*.*
Program FilesCommand SoftwareF-PROT95*.*
eSafeProtect*.*
PC-Cillin 95*.*
PC-Cillin 97*.*
Program FilesQuick Heal*.*
Program FilesFWIN32*.*
Program FilesFindVirus*.*
ToolkitFindVirus*.*
f-macro*.*
Program FilesMcAfeeVirusScan95*.*
Program FilesNorton AntiVirus*.*
TBAVW95*.*
VS95*.*
rescue*.*
Program FilesZone Labs*.*
Microsoft virtual machine Ãë¾àÁ¡Àº ´ÙÀ½ »çÀÌÆ®¿¡¼ ÆÐÄ¡ÇÑ´Ù.
//www.microsoft.com/technet/treeview/default.asp?url=/TechNet/security/bulletin/ms00-081.asp
¶ÇÇÑ Å°º¸µå°¡ ÀÛµ¿ÇÏÁö ¾Ê°Ô µÇ¸ç ½Ã½ºÅÛ µð·ºÅ丮¿¡ ÀÖ´Â DLL, .DRV, .VXD, .TSP¿Í °°Àº È®ÀåÀÚÀÇ ¸ðµç ÆÄÀÏÀ» »èÁ¦ÇÑ´Ù.
¡Ù ´ëÀÀ¹æ¹ý
¸ÞÀÏ ¼ö½Å½Ã Ãâó ¹× ¿ëµµ°¡ ºÒºÐ¸íÇÑ ¸ÞÀÏÀ» ¹ÞÀº °æ¿ì, ƯÈ÷ Å©¸®½º¸¶½º Ä«µåÀÎ °Íó·³ º¸ÀÌ´Â À§¿¡¼ ³ª¿µÈ ÇüÅÂÀÇ ¸ÞÀÏÀº ¹Ù·Î »èÁ¦ÇÑ´Ù. ÀÌ¹Ì Ã·ºÎÆÄÀÏÀ» ½ÇÇàÇÑ °æ¿ì À©µµ¿ì µð·ºÅ丮¿¡¼ cristmas.exe ÆÄÀÏÀ» »èÁ¦ÇÏ°í ·¹Áö½ºÆ®¸®ÆíÁý±â ( ½ÃÀÛ->½ÇÇà -> regedit)¸¦ ½ÇÇàÇÏ¿© »õ·Î »ý¼ºµÈ ·¹Áö½ºÆ®¸® °ªµéÀ» »èÁ¦ÇÑ´Ù. ¿ú¿¡ ÀÇÇØ »èÁ¦µÇ°Å³ª º¯°æµÈ ºÎºÐÀº º¹±¸ÇÏÁö ¸øÇÒ ¼ö ÀÖ´Ù. ÃֽŠ¹é½ÅÀ» ÀÌ¿ëÇÏ¿© ´Ù½Ã °Ë»çÇÏ°í Ä¡·áÇÑ´Ù.