Ä¿¹Â´ÏƼ
 
 
 
 
 
 
 
»ç¿ë±â/ÇÊÅ×±â

·çƮŶÀ» °ø°Ý ·çÆ®·Î °¡Áö´Â °­·ÂÇÑ Storm ¿ú Á¤º¸


¿¬¹æ´ëÃÑÅë[4±º´Ü] ¹Ìµð¾î·Î±×°¡±â

Á¶È¸ : 1883
ÀÛ¼ºÀÏ : 2007/04/17 00:43
°£Æí URL : http://www.bodnara.co.kr/bbs/bbs.html?D=20&num=96376
Æ®À§ÅÍ    ÆäÀ̽ººÏ
¾Æ¸¶ Storm ¿ú¿¡ ´ëÇØ µé¾îº» ÀûÀÌ ÀÖ½À´Ï±î? ¾Æ¸¶µµ ±¹¾î¸¦ ¾Ö¿ëÇÏ´Â »ç¶÷À̶ó¸é Àß ¸ð¸£´Â °æ¿ì°¡ ´ëºÎºÐÀÔ´Ï´Ù. ÀÌ ¿úÀº ÁÖ·Î Á¦¸ñ¿¡ Áß¿äÇÑ »ç½Ç/´º½º µîÀ» ´ãÀº ½ºÆÔ ¸Þ½ÃÁö¸¦ ÅëÇØ Àü¿°µÇÁö¸¸ ¿µ¾îÀÎ °ü°è·Î Çѱ¹ ȯ°æ¿¡¼­´Â ±×¸® Å©°Ô ÁÖ¸ñÀ» ¹ÞÁö ¸øÇÏ¿´½À´Ï´Ù.

Àá½Ã ÀÌ ¿ú¿¡ ´ëÇؼ­ ¼Ò°³ÇØ µå¸³´Ï´Ù. Storm ¿úÀº Áö³­ 1¿ù ´Þ¿¡ ÃÖÃÊ ¹ß°ßµÈ °ÍÀ¸·Î ¾Ë·ÁÁö°í ÀÖÀ¸¸ç, ÁÖ·Î ¿µ¾î±Ç ±¹°¡ÀÎ À¯·´ÂÊ¿¡ ¸¹ÀÌ °¨¿°µÇ¾ú½À´Ï´Ù. ƯÈ÷, Storm ¿úÀº ½ºÆÔ ¸Þ½ÃÁöÀÇ Á¦¸ñ¿¡ "230 dead as storm batters europe"¿Í °°ÀÌ Áß¿äÇÑ ´º½º°Å¸® Áï, ³¬½ÃÁú Á¦¸ñÀ¸·Î ¸¹Àº »ç¶÷µéÀÌ °¨¿°µÇ¾ú½À´Ï´Ù. 2¿ù ´Þ¿¡´Â ¹ß·»Å¸ÀÎ µ¥ÀÌ¿¡ °üÇؼ­, ÃÖ±Ù 3¿ù¿¡´Â Á¦ 3Â÷ ¼¼°è ´ëÀü¿¡ ´ëÇÑ ¼Ò½ÄÀ¸·Î Çѹø ´õ Àü¼¼°èÀûÀ¸·Î ÀüÆÄ°¡ µÇ¾ú½À´Ï´Ù.

ÀÌ ½ºÆÔ ¸Þ½ÃÁöÀÇ ÇüÅ´ ´ÙÀ½°ú °°½À´Ï´Ù.

Á¦¸ñ

Worm Detected!
Virus Detected!ected!
Virus Activity Detected!
ATTN!
Spyware Alert!
Spyware Detected!
Warning!
Trojan Alert!
Trojan Detected!
Worm Activity Detected!
Virus Alert!


º»¹®

From: Customer Support

Dear Customer,
Our robot has detected an abnormal activity from your IP address on sending e-mails.

Probably it is connected with the last epidemic of a worm which does not have official patches at the moment. We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked. We had archived the patch because the worm can modify unpacked exe files. You should open the archive file, enter the password and run the patch immediately.

Password: {Random}

Customer Support Center Robot.

Attachment: Patch-{Random}.zip



÷ºÎ ÆÄÀÏ
º¸Åë 2°³ÀÇ Ã·ºÎÆÄÀÏÀ» Æ÷ÇÔÇÏ°í ÀÖ½À´Ï´Ù. Çϳª´Â ÀÏ¹Ý ±×¸² ÆÄÀÏ(*.gif)ÀÌ°í ³ª¸ÓÁö Çϳª°¡ ºñ¹Ð¹øÈ£·Î ¾ÐÃàµÈ zip ÆÄÀÏÀÔ´Ï´Ù. º¸Åë ´ÙÀ½ÀÇ À̸§À» °¡Áý´Ï´Ù.

patch-[RANDOM 4 DIGITS].zip
removal-[5 RANDOM DIGITS].zip
hotfix-[5 RANDOM DIGITS].zip
bugfix-[5 RANDOM DIGITS].zip

Stom ¿úÀÌ »õ·Ó°Ô ¼±º¸ÀÎ ±â¼úÀÌ ¹Ù·Î ÀÌ ºñ¹Ð¹øÈ£·Î º¸È£ÇÏ´Â zip ÆÄÀÏÀÔ´Ï´Ù. ÷ºÎ ÆÄÀÏÀÇ ºñ¹Ð¹øÈ£´Â ±ÛÀÚ¿Í ¼ýÀÚ·Î ¼¯¿© ·£´ýÇÏ°Ô Á¶Çյ˴ϴÙ. ¹°·Ð, À̸ÞÀÏ¿¡´Â ºñ¹Ð¹øÈ£°¡ Æ÷ÇԵǾî ÀÖ¾î ½±°Ô ¾Ë ¼ö´Â ÀÖ½À´Ï´Ù.

¸¸¾à zip ÆÄÀÏ¿¡ ºñ¹Ð¹øÈ£¸¦ ³Ö¾î¼­ ¿­¾î¼­ ½ÇÇàÀ» Çϸé, Storm ¿úÀ» PC¿¡ ¼³Ä¡ÇÏ°í ¹ÙÀÌ·¯½º ½ºÄ³³Ê·ÎºÎÅÍ ÀÚ½ÅÀ» º¸È£Çϱâ À§ÇØ ·çƮŶÀ» ÀÌ¿ëÇÏ¿© ¼û±é´Ï´Ù. ·çƮŶ¿¡ »ç¿ëµÇ´Â ´ëÇ¥ÀûÀÎ ÆÄÀÏÀº wincom32.sysÀÌ°í ´ÙÀ½°ú °°ÀÌ ·çƮŶ ŽÁö ÇÁ·Î±×·¥À» ã¾Æ ³¾ ¼ö ÀÖ½À´Ï´Ù.


·çƮŶ ±¸¼º¿ä¼Ò

SSDT
ZwEnumerateKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwEnumerateValueKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwQueryDirectoryFile
C:\WINDOWS\system32\wincom32.sys

IRP
\Driver\Tcpip->IRP_MJ_DEVICE_CONTROL
\\??\C:\WINDOWS\system32\wincom32.sys

¡¡ 3
¡¡
¿¬¹æ´ëÃÑÅë[4±º´Ü] ´ÔÀÇ ´Ù¸¥±Û º¸±â
ÁÁÀº ³»¿ëÀÇ ±ÛÀ̶ó¸é ÃßõÇØÁÖ¼¼¿ä.
·Î±×ÀÎÀ» ÇÏÁö ¾Ê¾Æµµ Ãßõ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
211.229.163.xxx
ºÒ¹ý ±¤°í±Û ½Å°íÇϱâ
I
   ÀÌ °Ô½Ã¹°ÀÇ ´ñ±Û º¸±â
ÃßõÁ¦¾È³»
ÁÁÀº °Ô½Ã¹°¿¡´Â ÃßõÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù.ÃßõÀÌ 5 ÀÌ»óÀÌ¸é ¸ÞÀÎÆäÀÌÁö Çìµå¶óÀο¡ °Ô½Ã¹°À» °É¾î µå¸³´Ï´Ù.
Àû¸³µÈ Æ÷ÀÎÆ®·Î ÁøÇàÁßÀÎ À̺¥Æ®¿¡ Âü¿©ÇÏ½Ã¾î °æÇ°À» ¹Þ¾Æ°¡½Ç ¼ö ÀÖ½À´Ï´Ù.

Æ÷ÀÎÆ®¾È³» ±ÛÀÛ¼º : 20Á¡, ÃßõŬ¸¯ : 2Á¡, Ãßõ¹ÞÀº»ç¶÷ 2Á¡, ´ñ±ÛÀÛ¼º : 4Á¡ (2008.12.29ÀϺÎÅÍ)
  ´ç½Å±â¾ï (bluemun) bluemun´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-17 08:56 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  Á¦ PCÇØÅ·Çصµ °¡Á®°¥ °Í ¾ø¾î¼­..
  ´Ï ¾Ö¹Ì (pmicro) pmicro´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-17 23:36 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  Á»ºñ°¡ ¸¹¾Æ Áö°Ú±º¿ä.^^
  Noir (iamafool) iamafool´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-18 01:12 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  ÀÌ»óÇÑ ¸ÞÀÏÀº ¿ª½Ã ¾Èº¸´Â°Ô »óÃ¥À̱º¿ä.
  ¹ö¸²¹ÞÀºÃµ»ç (ljhhjw) ljhhjw´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-21 17:24 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  À§ÇèÇÑ ³à¼®À̱º¿ä
  blasty (ID) blasty´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-22 22:15 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  ¹ÙÀÌ·¯½º·Î Â÷´ÜÀÌ µÇ´Â°¡¿ä?
»ç¿ë±â/ÇÊÅ×±â
9982 ÇʵåÅ×½ºÆ®   GMC Ç÷¡Æ¼´½ V22 SY-500A Dual 7 µ¿³×¾Æ´ÂÇü 2 07.04.20 1863
9981 ÇʵåÅ×½ºÆ®   ¿¤Åõ¿¥ ·°¼Å¸® ºí·¢ ÄÉÀ̽º 7 Àεà¾î·±½º 1 07.04.20 1425
9980 °³Àλç¿ë±â   ±¹³» , ÀÎÅÚ ÀÎÇÏµÈ °¡°Ý Àû¿ë °³½Ã!! 13 °øºÎÇÏÀÚ 1 07.04.20 2747
9979 ÇʵåÅ×½ºÆ®   ÀÎÅÚ ÄÚ¾î2µà¿ÀÀÇ ´º ÆäÀ̽º E6320 »ìÆ캸±â 19 ŽÀÌ 1 07.04.20 2259
9978 ÇʵåÅ×½ºÆ®   ³ÐÀº ¹æ¿­ÆÇ¿¡ Á¶¿ëÇÔ APACK ZEROtherm GT650M 8 ¸ù´ç¿¬ÇÊ 3 07.04.20 2911
9977 ÇʵåÅ×½ºÆ®   ÀÛ¼ºÀÚ°¡ °Ô½Ã¹°À» »èÁ¦ ÇÏ¿´½À´Ï´Ù 7 Áö³ç2Áö·Õ 2 07.04.20 1674
9976 ÇʵåÅ×½ºÆ®   Æ÷ÅäÇÁ¸°ÅÍÀÇ ´ëÁßÈ­ ¼±¾ð¿¡ ¾ÕÀå¼± ij³í PIXMA iP4300 2ºÎ 7 ÃÝÄÚ¿ìÀ¯ 3 07.04.20 2026
9975 ÇʵåÅ×½ºÆ®   Æ÷ÅäÇÁ¸°ÅÍÀÇ ´ëÁßÈ­ ¼±¾ð¿¡ ¾ÕÀå¼± ij³í PIXMA iP4300 1ºÎ 7 ÃÝÄÚ¿ìÀ¯ 2 07.04.20 1979
9974 ÇʵåÅ×½ºÆ®   ÀÛ¼ºÀÚ°¡ °Ô½Ã¹°À» »èÁ¦ ÇÏ¿´½À´Ï´Ù Áö³ç2Áö·Õ 3 07.04.20 988
9973 ÇʵåÅ×½ºÆ®   DIVICO FusionHDTV5 USB nano ¸®ºä -¿ÜÇüÆí 7 ±è½ÅÀÇ 2 07.04.20 1672
9972 ÇʵåÅ×½ºÆ®   À×Å©Á¬ ÇÁ¸°Å͸¦ ¸®´õÇÑ´Ù!!! Canon Pixma iP4300 7 OBlueSkyO 2 07.04.19 1344
9971 ÇʵåÅ×½ºÆ®   7600GTÀÇ ÁöÁ¸! À¯´ÏÅØ 7600GT ÁöÁ¸ 256MB À߸¸VF7 8 À̵µÁØ 2 07.04.19 2319
9970 ÇʵåÅ×½ºÆ®   Àú°¡Çü ÆÄ¿öÀÇ ¹Ý¶õ!! 1st 450Light 8 ·ù°æ¹ü 1 07.04.19 1646
9969 ÇʵåÅ×½ºÆ®   HD ¹æ¼ÛÀ» ³» ¼Õ¾È¿¡ µðºñÄÚ FusionHDTV USB nano 8 setiguy 3 07.04.19 1561
9968 ´º½ºÅ¬¸³   ±¹³» PSP 20% ÀÎÇÏ.. 9 Æù»ýÆù»ç 1 07.04.19 1272
9967 ´º½ºÅ¬¸³   4¿ù 18ÀÏÀÚ·Î ¸±¸®ÁîµÈ ATI Catalyst v7.4 7 ¿¬¹æ´ëÃÑÅë[4±º´Ü] 2 07.04.19 1356
9966 ÇʵåÅ×½ºÆ®   <º¥Ä¡Å¬·´>400Wd ±×Á߽ɿ¡ ¼­´Ù 1ST 400LIGHT 8 ºÎ»ê»ç¶û 4 07.04.19 1887
9965 ÇʵåÅ×½ºÆ®   »õ·Î¿î Äð·¯~! APACK Á¦·Î½æ GT650M VGAÄð·¯ 8 ¿°Å¼· 2 07.04.18 1487
9964 ÇʵåÅ×½ºÆ®   1ST POWER 450LIGHT 8 ±è°©ºÀ 3 07.04.18 1555
9963 ÇʵåÅ×½ºÆ®   GMCÀÇ »õ·Î¿î ¸í¼º!~ Ç÷¡Æ¼´½ V22 SY-500A Dual ÆÄ¿ö¼­ÇöóÀÌ!~ 8 ±èÀçÀÀ 1 07.04.18 1499
9962 ÇʵåÅ×½ºÆ®   º¸±ÞÇü ÃÖ°­ 8600GT ·º½ºÅØ 8600GT °­Ãß ¿À¹öŬ·° À߸¸ 9 ŽÀÌ 1 07.04.18 1619
9961 ´º½ºÅ¬¸³   ÀÛ¼ºÀÚ°¡ °Ô½Ã¹°À» »èÁ¦ ÇÏ¿´½À´Ï´Ù napalri 1 07.04.18 1329
[921][922][923][924][925][926] 927 [928][929][930]