Ä¿¹Â´ÏƼ
 
 
 
 
 
Ä¿¹Â´ÏƼ Ãßõ°Ô½Ã¹°       ¿î¿µÁø ¼±Á¤ | Ãßõ¼ø | ÃÖ±Ù´ñ±Û´Þ¸°¼ø | °¶·¯¸®(Æ÷Åä)

 
 
 
»ç¿ë±â/ÇÊÅ×±â

·çƮŶÀ» °ø°Ý ·çÆ®·Î °¡Áö´Â °­·ÂÇÑ Storm ¿ú Á¤º¸


¿¬¹æ´ëÃÑÅë[4±º´Ü] ¹Ìµð¾î·Î±×°¡±â

Á¶È¸ : 2502
ÀÛ¼ºÀÏ : 2007/04/17 00:43
°£Æí URL : http://www.bodnara.co.kr/bbs/bbs.html?D=20&num=96376
Æ®À§ÅÍ    ÆäÀ̽ººÏ
¾Æ¸¶ Storm ¿ú¿¡ ´ëÇØ µé¾îº» ÀûÀÌ ÀÖ½À´Ï±î? ¾Æ¸¶µµ ±¹¾î¸¦ ¾Ö¿ëÇÏ´Â »ç¶÷À̶ó¸é Àß ¸ð¸£´Â °æ¿ì°¡ ´ëºÎºÐÀÔ´Ï´Ù. ÀÌ ¿úÀº ÁÖ·Î Á¦¸ñ¿¡ Áß¿äÇÑ »ç½Ç/´º½º µîÀ» ´ãÀº ½ºÆÔ ¸Þ½ÃÁö¸¦ ÅëÇØ Àü¿°µÇÁö¸¸ ¿µ¾îÀÎ °ü°è·Î Çѱ¹ ȯ°æ¿¡¼­´Â ±×¸® Å©°Ô ÁÖ¸ñÀ» ¹ÞÁö ¸øÇÏ¿´½À´Ï´Ù.

Àá½Ã ÀÌ ¿ú¿¡ ´ëÇØ¼­ ¼Ò°³ÇØ µå¸³´Ï´Ù. Storm ¿úÀº Áö³­ 1¿ù ´Þ¿¡ ÃÖÃÊ ¹ß°ßµÈ °ÍÀ¸·Î ¾Ë·ÁÁö°í ÀÖÀ¸¸ç, ÁÖ·Î ¿µ¾î±Ç ±¹°¡ÀÎ À¯·´ÂÊ¿¡ ¸¹ÀÌ °¨¿°µÇ¾ú½À´Ï´Ù. ƯÈ÷, Storm ¿úÀº ½ºÆÔ ¸Þ½ÃÁöÀÇ Á¦¸ñ¿¡ "230 dead as storm batters europe"¿Í °°ÀÌ Áß¿äÇÑ ´º½º°Å¸® Áï, ³¬½ÃÁú Á¦¸ñÀ¸·Î ¸¹Àº »ç¶÷µéÀÌ °¨¿°µÇ¾ú½À´Ï´Ù. 2¿ù ´Þ¿¡´Â ¹ß·»Å¸ÀÎ µ¥ÀÌ¿¡ °üÇØ¼­, ÃÖ±Ù 3¿ù¿¡´Â Á¦ 3Â÷ ¼¼°è ´ëÀü¿¡ ´ëÇÑ ¼Ò½ÄÀ¸·Î Çѹø ´õ Àü¼¼°èÀûÀ¸·Î ÀüÆÄ°¡ µÇ¾ú½À´Ï´Ù.

ÀÌ ½ºÆÔ ¸Þ½ÃÁöÀÇ ÇüÅ´ ´ÙÀ½°ú °°½À´Ï´Ù.

Á¦¸ñ

Worm Detected!
Virus Detected!ected!
Virus Activity Detected!
ATTN!
Spyware Alert!
Spyware Detected!
Warning!
Trojan Alert!
Trojan Detected!
Worm Activity Detected!
Virus Alert!


º»¹®

From: Customer Support

Dear Customer,
Our robot has detected an abnormal activity from your IP address on sending e-mails.

Probably it is connected with the last epidemic of a worm which does not have official patches at the moment. We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked. We had archived the patch because the worm can modify unpacked exe files. You should open the archive file, enter the password and run the patch immediately.

Password: {Random}

Customer Support Center Robot.

Attachment: Patch-{Random}.zip



÷ºÎ ÆÄÀÏ
º¸Åë 2°³ÀÇ Ã·ºÎÆÄÀÏÀ» Æ÷ÇÔÇϰí ÀÖ½À´Ï´Ù. Çϳª´Â ÀÏ¹Ý ±×¸² ÆÄÀÏ(*.gif)ÀÌ°í ³ª¸ÓÁö Çϳª°¡ ºñ¹Ð¹øÈ£·Î ¾ÐÃàµÈ zip ÆÄÀÏÀÔ´Ï´Ù. º¸Åë ´ÙÀ½ÀÇ À̸§À» °¡Áý´Ï´Ù.

patch-[RANDOM 4 DIGITS].zip
removal-[5 RANDOM DIGITS].zip
hotfix-[5 RANDOM DIGITS].zip
bugfix-[5 RANDOM DIGITS].zip

Stom ¿úÀÌ »õ·Ó°Ô ¼±º¸ÀÎ ±â¼úÀÌ ¹Ù·Î ÀÌ ºñ¹Ð¹øÈ£·Î º¸È£ÇÏ´Â zip ÆÄÀÏÀÔ´Ï´Ù. ÷ºÎ ÆÄÀÏÀÇ ºñ¹Ð¹øÈ£´Â ±ÛÀÚ¿Í ¼ýÀÚ·Î ¼¯¿© ·£´ýÇÏ°Ô Á¶Çյ˴ϴÙ. ¹°·Ð, À̸ÞÀÏ¿¡´Â ºñ¹Ð¹øÈ£°¡ Æ÷ÇԵǾî ÀÖ¾î ½±°Ô ¾Ë ¼ö´Â ÀÖ½À´Ï´Ù.

¸¸¾à zip ÆÄÀÏ¿¡ ºñ¹Ð¹øÈ£¸¦ ³Ö¾î¼­ ¿­¾î¼­ ½ÇÇàÀ» Çϸé, Storm ¿úÀ» PC¿¡ ¼³Ä¡ÇÏ°í ¹ÙÀÌ·¯½º ½ºÄ³³Ê·ÎºÎÅÍ ÀÚ½ÅÀ» º¸È£Çϱâ À§ÇØ ·çƮŶÀ» ÀÌ¿ëÇÏ¿© ¼û±é´Ï´Ù. ·çƮŶ¿¡ »ç¿ëµÇ´Â ´ëÇ¥ÀûÀÎ ÆÄÀÏÀº wincom32.sysÀÌ°í ´ÙÀ½°ú °°ÀÌ ·çƮŶ ŽÁö ÇÁ·Î±×·¥À» ã¾Æ ³¾ ¼ö ÀÖ½À´Ï´Ù.


·çƮŶ ±¸¼º¿ä¼Ò

SSDT
ZwEnumerateKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwEnumerateValueKey
C:\WINDOWS\system32\wincom32.sys

SSDT
ZwQueryDirectoryFile
C:\WINDOWS\system32\wincom32.sys

IRP
\Driver\Tcpip->IRP_MJ_DEVICE_CONTROL
\\??\C:\WINDOWS\system32\wincom32.sys

¡¡ 3
¡¡
¿¬¹æ´ëÃÑÅë[4±º´Ü] ´ÔÀÇ ´Ù¸¥±Û º¸±â
ÁÁÀº ³»¿ëÀÇ ±ÛÀ̶ó¸é ÃßÃµÇØÁÖ¼¼¿ä.
·Î±×ÀÎÀ» ÇÏÁö ¾Ê¾Æµµ Ãßõ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
211.229.163.xxx
ºÒ¹ý ±¤°í±Û ½Å°íÇϱâ
I
   ÀÌ °Ô½Ã¹°ÀÇ ´ñ±Û º¸±â
ÃßõÁ¦¾È³»
ÁÁÀº °Ô½Ã¹°¿¡´Â ÃßõÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù.ÃßõÀÌ 5 ÀÌ»óÀÌ¸é ¸ÞÀÎÆäÀÌÁö Çìµå¶óÀο¡ °Ô½Ã¹°À» °É¾î µå¸³´Ï´Ù.
Àû¸³µÈ Æ÷ÀÎÆ®·Î ÁøÇàÁßÀÎ À̺¥Æ®¿¡ Âü¿©ÇÏ½Ã¾î °æÇ°À» ¹Þ¾Æ°¡½Ç ¼ö ÀÖ½À´Ï´Ù.

Æ÷ÀÎÆ®¾È³» ±ÛÀÛ¼º : 20Á¡, ÃßõŬ¸¯ : 2Á¡, Ãßõ¹ÞÀº»ç¶÷ 2Á¡, ´ñ±ÛÀÛ¼º : 4Á¡ (2008.12.29ÀϺÎÅÍ)
  ´ç½Å±â¾ï (bluemun) bluemun´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-17 08:56 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  Á¦ PCÇØÅ·ÇØµµ °¡Á®°¥ °Í ¾ø¾î¼­..
  ´Ï ¾Ö¹Ì (pmicro) pmicro´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-17 23:36 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  Á»ºñ°¡ ¸¹¾Æ Áö°Ú±º¿ä.^^
  Noir (iamafool) iamafool´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-18 01:12 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  ÀÌ»óÇÑ ¸ÞÀÏÀº ¿ª½Ã ¾Èº¸´Â°Ô »óÃ¥À̱º¿ä.
  ¹ö¸²¹ÞÀºÃµ»ç (ljhhjw) ljhhjw´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-21 17:24 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  À§ÇèÇÑ ³à¼®À̱º¿ä
  blasty (ID) blasty´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  /  2007-04-22 22:15 / IP/ ½Å°í/ ÀÌ´ñ±Û¿¡´ñ±Û´Þ±â
  ¹ÙÀÌ·¯½º·Î Â÷´ÜÀÌ µÇ´Â°¡¿ä?
»ç¿ë±â/ÇÊÅ×±â
  ¾ÆÆ²¶õ/ÆÄÀεå¶óÀÌºê ¿Ü ¹ÙÀÌ·² ÀÇ½É °Ô½Ã¹°Àº ¸ðµÎ »èÁ¦Á¶Ä¡ÇÕ´Ï´Ù. 2 °¨ÀÚ³ª¹« 7 14.01.22 89345
  µ¿¿µ»ó ¾÷·Îµå ¹æ¹ý ¾È³» 1 °¨ÀÚ³ª¹« 3 10.02.10 98715
  Á¤º¸°øÀ¯ ÅëÇÕ°Ô½ÃÆÇ ÀÌ¿ë¾È³» (09.09.02 ¼öÁ¤) 2 °¨ÀÚ³ª¹« 2 08.08.12 95405
31792 ÇʵåÅ×½ºÆ®   ¿ÍÀÌÆÄÀÌ À¯¹«¼± °øÀ¯±â Ãßõ netis MEX601 µ¿°íµ¿¶ô 0 26.04.18 246
31791 ÇʵåÅ×½ºÆ®   °ÔÀÌ¹Ö ½º¸¶Æ®Æù POCO X8 Pro Max »ç¿ë Èı⠿Àº£¸£´ºÅ©·Î³ª 0 26.04.16 274
31790 ÇʵåÅ×½ºÆ®   »þ¿À¹Ì¿¡¼­ ÃÊ´ë¿ë·® ¹èÅ͸®·Î Ãâ½ÃµÈ Æ÷ÄÚ X8 ÇÁ·Î ¸Æ½º POCO X8 Pro Max ¾ÆÀ̸¶ 0 26.04.15 323
31789 ÇʵåÅ×½ºÆ®   °¡¼ººñ PCÄÉÀ̽º ¿¡µðÄÉÀ̽º EDDY G0 BLACK ÇÕ¸®ÀûÀÎ °¡°ÝÀÇ ¼Ö·ç¼Ç ¾ßÄÞ 0 26.04.15 265
31788 ÇʵåÅ×½ºÆ®   ALSEYE i12B (ºí·¢) ÄÉÀ̽º Äð¸µÆÒ µ¿°íµ¿¶ô 0 26.04.14 262
31787 ÇʵåÅ×½ºÆ®   PoE Áö¿ø Omada ES208GP °ü¸®Çü ½ºÀ§Ä¡ µ¿°íµ¿¶ô 0 26.04.08 301
31786 ÇʵåÅ×½ºÆ®   µà¾óŸ¿ö CPUÄð·¯ OH'S CV-620 (È­ÀÌÆ®) µ¿°íµ¿¶ô 0 26.04.08 245
31785 ÇʵåÅ×½ºÆ®   darkFlash DS950V ARGB µð½ºÇ÷¹ÀÌ PC ÄÉÀ̽º »ç¿ë±â ¿Àº£¸£´ºÅ©·Î³ª 0 26.04.04 294
31784 ÇʵåÅ×½ºÆ®   ÀÎÅÚ 270K Plus ±â°¡¹ÙÀÌÆ® B860M AORUS ELITE WIFI6E ICE È­ÀÌÆ® ¸ÞÀκ¸µå¶ó¸é .. ¾Æ¸®¸¶ÆþÆþ 0 26.04.01 335
31783 ÇʵåÅ×½ºÆ®   ·¹³ë¹ö LEGION PRO 27UD-10 OLED °ÔÀÌ¹Ö ¸ð´ÏÅÍ »ç¿ë±â ¿Àº£¸£´ºÅ©·Î³ª 0 26.04.01 365
31782 ÇʵåÅ×½ºÆ®   ÀÎÅÚ ¸®ÇÁ·¹½Ã ¿Ïº®Áö¿ø ±¹¹Î ¸ÞÀκ¸µå MSI MAG Z890 Å丶ȣũ WIFI µ¿°íµ¿¶ô 0 26.03.30 451
31781 ÇʵåÅ×½ºÆ®   µð½ºÇ÷¹ÀÌ PCÄÉÀ̽º ´ÙÅ©Ç÷¡½¬ DS950V ARGB °³¼ºÀÖ´Â º»Ã¼¸¸µé±â ¾ßÄÞ 0 26.03.29 468
31780 ÇʵåÅ×½ºÆ®   ÄÄÇ»Å͸ÞÀκ¸µå Ãßõ ±â°¡¹ÙÀÌÆ® B850M AORUS ELITE WIFI6E ICE ¼º´É ¹× ½ºÆå ºÐ.. ¾ßÄÞ 0 26.03.27 450
31779 ÇʵåÅ×½ºÆ®   EPZ G10 2¼¼´ë À¯¼± °ÔÀÌ¹Ö À̾îÆù »ç¿ë±â ¿Àº£¸£´ºÅ©·Î³ª 0 26.03.27 469
31778 ÇʵåÅ×½ºÆ®   ³ª¸¸ÀÇ ¿¬ÃâÀÌ °¡´ÉÇÑ TRYX STAGE ARGB 360 °í¼º´É ¼ö·©Äð·¯ ¾ÆÀ̸¶ 0 26.03.23 464
31777 ÇʵåÅ×½ºÆ®   TDP270W Áö¿øÇÏ´Â 3¸¸¿ø´ë µà¾óŸ¿ö CPU Äð·¯ ALSEYE Q120DT Plus ¾ÆÀ̸¶ 0 26.03.23 476
31776 ÇʵåÅ×½ºÆ®   ½ºÆ¿½Ã¸®Áî QcK Pro XL - Control °ÔÀÌ¹Ö ¸¶¿ì½ºÆÐµå µ¿°íµ¿¶ô 0 26.03.22 499
31775 ÇʵåÅ×½ºÆ®   PC ¾îÇ×ÄÉÀ̽º ¸®¾È¸® Vector V100 ARGB MINI »ç¿ë±â ¿Àº£¸£´ºÅ©·Î³ª 0 26.03.21 533
31774 ÇʵåÅ×½ºÆ®   µð½ºÇ÷¹ÀÌ ÀåÂøµÈ TRYX STAGE 3¿­ ¼ö·©Äð·¯ °¡Áö°í ½ÍÀ»²¨¾ß ¾Æ¸®¸¶ÆþÆþ 0 26.03.20 519
 1 [2][3][4][5][6][7][8][9][10]