|
W32/Pibi@mmÀÇ º¯ÇüÀ¸·Î °¨¿°µÈ À̸ÞÀÏÀÇ Ã·ºÎ ÆÄÀÏ
°ú, KazaA, IRC¸¦ ÅëÇØ ÀüÆÄ µÈ´Ù.
¸¶ÀÌÅ©·Î ¼ÒÇÁÆ® ºñÁÖ¾ó C++·Î ÄÚµùµÇ¾î ÀÖÀ¸¸ç, UPX
¾ÐÃàÇÁ·Î±×·¥À¸·Î ¾ÐÃàµÇ ÀÖ´Ù.
ºÎÁ¤È®ÇÑ MIME Çì´õ¸¦ ÀÌ¿ëÇÏ¿© E-mail÷ºÎÆÄÀÏÀ» ½Ç
ÇàÇϵµ·Ï ¾ß±âÇÏ´Â º¸¾È ¹ö±×¸¦ ÀÌ¿ëÇϹǷΠ¸ÞÀÏÀ» Ŭ
¸¯ ÇÏ´Â °Í¸¸À¸·Î °¨¿°µÉ ¼ö ÀÖ´Ù.
¸ÞÀÏ º»¹®Àº ´ÙÀ½°ú °°´Ù.
Istall the program in the attachment.
ÆÄÀÏÀÌ ½ÇÇàµÇ¸é À©µµ¿ìÀÇ ½Ã½ºÅÛ Æú´õ(win9x :
c:\windows\system,
Win2000 : c:\Winnt\system32)¿¡
WSYXXX.exe¸¦ »ý¼ºÇÑ´Ù.(XXX : ·£´ýÇÑ ¼ýÀÚ)
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre
ntVersion\Run
Ç׸ñ¿¡
Win9x ÀÎ °æ¿ì : Kernel32.dll module =
c:\windows\system\WSYSXXX.EXE
Win2000 Àΰæ¿ì: Kernel32.dll module =
c:\winnt\system32\WSYSXXX.EXE
(XXX : ·£´ýÇÑ ¼ýÀÚ)
HKEY_LOCAL_MACHINEN\Software\PieceByPieceB\inf
Ç׸ñ¿¡ yep
¶ÇÇÑ C:\ ·çÆ®¿¡ boot64.binÀ» »ý¼º Çϱ⵵ Çϴµ¥
ÀÌ ÆÄÀÏÀº base64·Î ¾Ð
ÃàµÇ¾î ÀÖ´Â ¹ÙÀÌ·¯½º º»Ã¼ ÆÄÀÏ·Î °¨¿°µÈ ¸ÞÀÏÀ» º¸
³¾¶§ »ç¿ëÇÑ´Ù.
÷ºÎµÈ ÆÄÀÏÀ» ½ÇÇà ÇÏ¸é ´ÙÀ½°ú °°Àº ¿¡·¯ ¸Þ½ÃÁö¸¦
¶ç¿ì¸ç, ½ÇÇàÇÒ¼ö ¾ø
´Â °Íó·³ À§ÀåÇÑ´Ù.
Error! This process will be terminated.
10¿ù 18ÀÏ¿¡ ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö âÀ» ¶ç¿î´Ù.
"Sucking back a cigarette
Thinking about new regrets
Trying to be someone you'd like to be
Passing faces on the road
Where the hell can we still go?
Leaves us open to temptation..."
-Feeder
¶ÇÇÑ ´ÙÀ½ ¹®ÀÚ¿À» °¡Áø ƯÁ¤ ¾ÈƼ ¹ÙÀÌ·¯½ºÀÇ ÇÁ·Î
¼¼½º¸¦ ÁßÁö½ÃÅ°´Â ±â
´ÉÀ» °¡Áö°í ÀÖ´Â °ÍÀ¸·Î º¸ÀδÙ.
AV
F-
av
NOD32
SCAN
MON
ALERT
ANTIVIR
PCCW
PCC
FP-
TRAP
TDS2-
VET
SWEEP
MCAFEE
FIREW
DVP
CFI
ICL
VSHW
|
|
|