¿¡ºê¸®Á¸¼Ò°³ | Á¦Ç°¼Ò°³ | °í°´¼¾ÅÍ | »çÀÌÆ®¸Ê | Home
°³ÀÎ°í°´ ¿©¼º°í°´ eº¸¾È¸¶ÄÏ À̺¥Æ®
°³ÀÎ°í°´±â¾÷°í°´
º¸¾ÈÁ¢¼Ó IDÀúÀå
AD ¹«·á·Î Ã¥¹Þ¾Æ°¡¼¼¿ä!


 
Adware/StartPage.Ebben
 Á¾·ù
adware
 °¨¿°°æ·Î
active X
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Adware/StartPage.Ebben´Â ActiveX Çü½ÄÀ» ÃëÇØ »ç¿ëÀÚ¿¡°Ô ¼³Ä¡¸¦ À¯µµÇÏ°í,
¼³Ä¡ ÈÄ ÀÚ½ÅÀÇ ½ÎÀÌÆ®¸¦ ȨÀ¸·Î °íÁ¤ ÈÄ º¯°æÀÌ ¾ÈµÇµµ·Ï ¸·´Â ¾Ç¼ºÄÚµå ÀÌ´Ù.


ÀÌ´Â
1) À¥ºê¶ó¿ìÀúÀÇ È¨ÆäÀÌÁö ¼³Á¤À̳ª °Ë»ö ¼³Á¤À» º¯°æ ¶Ç´Â ½Ã½ºÅÛ ¼³Á¤ º¯°æÇÏ´Â ÇàÀ§
¿¡ ÇØ´çÇÏ¿©, ¾Ç¼ºÄÚµå·Î ±¸ºÐ µÈ´Ù.

[»ý¼º ÆÄÀÏ]
%prog%\Ebben\Ebben.exe



[»ý¼º ·¹Áö]
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main Start Page http://www.Ebben.co.kr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Ebben
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Ebben


°æ·Î´Â ¾Æ·¡¸¦ ÂüÁ¶ ÇÑ´Ù.
%windows%
c:\windows
%program%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥
%system%
C:\windows\system32
%prog%
C:\Program Files
%currentuser%
C:\Documents and Settings\(username)
%startmenu%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º
 
 
Adware/StartPage.boome
 Á¾·ù
adware
 °¨¿°°æ·Î
active X
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Adware/StartPage.boome´Â ActiveX Çü½ÄÀ» ÃëÇØ »ç¿ëÀÚ¿¡°Ô ¼³Ä¡¸¦ À¯µµÇÏ°í,
¼³Ä¡ ÈÄ ÀÚ½ÅÀÇ ½ÎÀÌÆ®¸¦ ȨÀ¸·Î °íÁ¤ ÈÄ º¯°æÀÌ ¾ÈµÇµµ·Ï ¸·´Â ¾Ç¼ºÄÚµå ÀÌ´Ù.


ÀÌ´Â
1) À¥ºê¶ó¿ìÀúÀÇ È¨ÆäÀÌÁö ¼³Á¤À̳ª °Ë»ö ¼³Á¤À» º¯°æ ¶Ç´Â ½Ã½ºÅÛ ¼³Á¤ º¯°æÇÏ´Â ÇàÀ§
¿¡ ÇØ´çÇÏ¿©, ¾Ç¼ºÄÚµå·Î ±¸ºÐ µÈ´Ù.

[»ý¼º ÆÄÀÏ]
%prog%\boome\boome.exe



[»ý¼º ·¹Áö]
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main Start Page http://www.boome.co.kr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run boome
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run boome


°æ·Î´Â ¾Æ·¡¸¦ ÂüÁ¶ ÇÑ´Ù.
%windows%
c:\windows
%program%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥
%system%
C:\windows\system32
%prog%
C:\Program Files
%currentuser%
C:\Documents and Settings\(username)
%startmenu%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º
 
 
Trojan/Downloader.run
 Á¾·ù
Hijacker
 °¨¿°°æ·Î
¹ÙÀÌ·¯½º·Î ÀÎÇÑ ´Ù¿î·Îµå
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Trojan/Downloader.run´Â ´ëÇ¥ÀûÀ¸·Î ´ÙÀ½ µÎ Ç׸ñ¿¡ µî·ÏµÇ´Â ¹ÙÀÌ·¯½ºÀÇ ºÎ»ê¹°µéÀ» ŽÁöÇÏ´Â ÄÚµåÀÌ´Ù.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

½ÅÁ¾/º¯Á¾ ¹ÙÀÌ·¯½º ¹ß»ý ½Ã °øÅëÀûÀ¸·Î ¹ß»ýµÇ´Â ºÎ»ê¹°µéÀ» ŽÁöÇÏ°í Ä¡·á °Ë»ç Çϵµ·Ï À¯µµÇÏ°í ÀÖ´Â ÄÚµå·Î¼­, Á¤»ó Ä¡·á°¡ ¾ÈµÈ´Ù¸é »ç¿ëÀÚ PC¿¡ ½ÅÁ¾/º¯Á¾ Äڵ尡 ¹ß»ýÇß´Ù´Â ¶æÀÌ´Ï ½Å°íó¸® ÀÌÈÄ ÀÚ»çÀÇ ´Éµ¿ÀûÀÎ Ä¡·á ¼­ºñ½º¸¦ ¹ÞÀ» ¼ö ÀÖ´Ù.

http://www.everyzone.com/pub/premium_singo.exe

À§ ÇÁ·Î±×·¥À¸·Î Á¤»ó Ä¡·á¾ÈµÇ´Â À¯ÇØÄڵ忡 ´ëÇÑ Á¤º¸¸¦ ½Å°íó¸® ÇÒ¼ö ÀÖ´Ù.
 
 
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
                                                                 * ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
   | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40