|
À©µµ¿ìÀÇ ½Ã½ºÅÛ Æú´õ¿¡ Bot·ù¿Í ±¤°í¼º ¹èÆ÷ ÇÁ·Î±×·¥µîÀ¸·Î ¼³Ä¡µÈ´Ù.
ÇØ´ç Æ®·ÎÀ̾áÀÌ ½ÇÇà µÇ¸é, ÀϹÝÀûÀ¸·Î À©µµ¿ì ½Ã½ºÅÛ Æú´õ
(win9x: C:\Windows\System, win XP: C:\Windows\System32, win2000, NT : C:\WinNT\System32)
¿¡ RDRIV.SYS ¶Ç´Â hpdriver.sys, orans.sys, et54fg.sys ÆÄÀÏÀÌ ¼³Ä¡µÈ´Ù.
¹èÆ÷µÇ´Â trojanÀÇ º¯Á¾¿¡ µû¶ó À§ÀÇ ÆÄÀϵéÀÌ ¼±ÅõǸç,
¾Ë·ÁÁø Trojan Àº MCSECURE.EXE, ntfsprotect.exe µîÀÌ´Ù.
À̶§ ÇØ´ç ÆÄÀÏÀÌ µ¿ÀÛÇÏ°Ô µÇ¸é ÀÚ½ÅÀ» ´ÙÀ½°ú °°ÀÌ ·¹Áö½ºÆ®¸®¿¡
µî·ÏµÇ¾î ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛ ÇÑ´Ù.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv
Ç׸ñ¿¡
(windows xp ÀÇ °æ¿ì)
ImagePath = C:\Windows\system32\Hpdriver.SYS
(windows NT, 2000 ÀÇ °æ¿ì)
ImagePath = C:\WinNT\system32\Hpdriver.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mcsecure
Ç׸ñ¿¡
ImagePath = C:\Windows\MCSECURE.EXE
DisplayName = Mcsecure
¸¦ »ý¼º ÇÑ´Ù.
º¸¾ÈÆÐÄ¡°¡ ¾ÈµÈ ÄÄÇ»ÅÍ´Â °¨¿°½Ã ƯÁ¤ ½ÎÀÌÆ®¿¡¼
ÆÄÀÏÀ» ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖÀ¸¹Ç·Î ´ÙÀ½ º¸¾ÈÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù.
* MS03-007 º¸¾ÈÆÐÄ¡(5¿ù º¸¾ÈÆÐÄ¡)
http://www.microsoft.com/korea/technet/security/bulletin/MS03-007.asp
* MS04-011 º¸¾ÈÆÐÄ¡(4¿ù º¸¾ÈÆÐÄ¡)
http://www.microsoft.com/korea/technet/security/bulletin/MS04-011.asp |
|
|