¿¡ºê¸®Á¸¼Ò°³ | Á¦Ç°¼Ò°³ | °í°´¼¾ÅÍ | »çÀÌÆ®¸Ê | Home
°³ÀÎ°í°´ ¿©¼º°í°´ eº¸¾È¸¶ÄÏ À̺¥Æ®
°³ÀÎ°í°´±â¾÷°í°´
º¸¾ÈÁ¢¼Ó IDÀúÀå
AD ¹«·á·Î Ã¥¹Þ¾Æ°¡¼¼¿ä!


 ¸ñ·Ï |  À­±Û |  ¾Æ·§±Û  
W32/PiBi.B@mm
 ¹ÙÀÌ·¯½º Á¾·ù
Worm
 ½ÇÇàȯ°æ
Win9x, Win2000, NT
 ¹ß°ßÀÏ
2002³â11¿ù01ÀÏ
 Á¦ÀÛÁö
ºÒºÐ¸í
 À§Çèµî±Þ
 È®»ê¹æ¹ý
 ¹ÙÀÌ·¯½º Å©±â
32,256 Bytes
 Ã·ºÎÆÄÀÏ
install.exe
 ¸ÞÀÏÁ¦¸ñ
  Re:hya, WindowsXP Service Release Pack 2.002
 Áõ»ó¿ä¾à
  
 Ä¡·á¹æ¹ý

Åͺ¸¹é½Å Ai, Åͺ¸¹é½Å 2001 ¶Ç´Â Åͺ¸¹é½Å OnlineÀ¸
·Î Ä¡·á°¡´ÉÇÕ´Ï´Ù.


< Outlook Express >
-
http://www.microsoft.com/windows/ie/downloads/crit
ical/q323759ie/defau
lt.asp

< Outlook 2000 >
-
http://office.microsoft.com/korea/downloads/2000/O
ut2ksec.aspx

< Outlook 2002(Office XP) >
-
http://office.microsoft.com/korea/Downloads/2002/o
xpsp2.aspx


  
 
»ó¼¼¼³¸í
W32/Pibi@mmÀÇ º¯ÇüÀ¸·Î °¨¿°µÈ À̸ÞÀÏÀÇ Ã·ºÎ ÆÄÀÏ
°ú, KazaA, IRC¸¦ ÅëÇØ ÀüÆÄ µÈ´Ù.
¸¶ÀÌÅ©·Î ¼ÒÇÁÆ® ºñÁÖ¾ó C++·Î ÄÚµùµÇ¾î ÀÖÀ¸¸ç, UPX
¾ÐÃàÇÁ·Î±×·¥À¸·Î ¾ÐÃàµÇ ÀÖ´Ù.
ºÎÁ¤È®ÇÑ MIME Çì´õ¸¦ ÀÌ¿ëÇÏ¿© E-mail÷ºÎÆÄÀÏÀ» ½Ç
ÇàÇϵµ·Ï ¾ß±âÇÏ´Â º¸¾È ¹ö±×¸¦ ÀÌ¿ëÇϹǷΠ¸ÞÀÏÀ» Ŭ
¸¯ ÇÏ´Â °Í¸¸À¸·Î °¨¿°µÉ ¼ö ÀÖ´Ù.

¸ÞÀÏ º»¹®Àº ´ÙÀ½°ú °°´Ù.

Istall the program in the attachment.


ÆÄÀÏÀÌ ½ÇÇàµÇ¸é À©µµ¿ìÀÇ ½Ã½ºÅÛ Æú´õ(win9x :
c:\windows\system,
Win2000 : c:\Winnt\system32)¿¡
WSYXXX.exe¸¦ »ý¼ºÇÑ´Ù.(XXX : ·£´ýÇÑ ¼ýÀÚ)

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre
ntVersion\Run
Ç׸ñ¿¡

Win9x ÀÎ °æ¿ì : Kernel32.dll module =
c:\windows\system\WSYSXXX.EXE
Win2000 Àΰæ¿ì: Kernel32.dll module =
c:\winnt\system32\WSYSXXX.EXE
(XXX : ·£´ýÇÑ ¼ýÀÚ)

HKEY_LOCAL_MACHINEN\Software\PieceByPieceB\inf
Ç׸ñ¿¡ yep

¶ÇÇÑ C:\ ·çÆ®¿¡ boot64.binÀ» »ý¼º Çϱ⵵ Çϴµ¥
ÀÌ ÆÄÀÏÀº base64·Î ¾Ð
ÃàµÇ¾î ÀÖ´Â ¹ÙÀÌ·¯½º º»Ã¼ ÆÄÀÏ·Î °¨¿°µÈ ¸ÞÀÏÀ» º¸
³¾¶§ »ç¿ëÇÑ´Ù.


÷ºÎµÈ ÆÄÀÏÀ» ½ÇÇà ÇÏ¸é ´ÙÀ½°ú °°Àº ¿¡·¯ ¸Þ½ÃÁö¸¦
¶ç¿ì¸ç, ½ÇÇàÇÒ¼ö ¾ø
´Â °Íó·³ À§ÀåÇÑ´Ù.

Error! This process will be terminated.


10¿ù 18ÀÏ¿¡ ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö âÀ» ¶ç¿î´Ù.


"Sucking back a cigarette
Thinking about new regrets
Trying to be someone you'd like to be
Passing faces on the road
Where the hell can we still go?
Leaves us open to temptation..."
-Feeder


¶ÇÇÑ ´ÙÀ½ ¹®ÀÚ¿­À» °¡Áø ƯÁ¤ ¾ÈƼ ¹ÙÀÌ·¯½ºÀÇ ÇÁ·Î
¼¼½º¸¦ ÁßÁö½ÃÅ°´Â ±â
´ÉÀ» °¡Áö°í ÀÖ´Â °ÍÀ¸·Î º¸ÀδÙ.

AV
F-
av
NOD32
SCAN
MON
ALERT
ANTIVIR
PCCW
PCC
FP-
TRAP
TDS2-
VET
SWEEP
MCAFEE
FIREW
DVP
CFI
ICL
VSHW
 
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
                                                                 * ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
 ¸ñ·Ï