|
|
[¹ÙÀÌ·¯½º] HTML/Reality.Kr |
|
2002³â 10¿ù 29ÀÏ 00:00:00 |
¾Èö¼ö¿¬±¸¼Ò
|
|
|
|
°¨¿°½Ã À§Çèµµ : 5µî±Þ(ÁÖÀÇ)
À¯Çü : ½ºÅ©¸³Æ®
ÃÖÃʹ߰ßÀÏ : 2001-07-06
±¹³»¹ß°ßÀÏ : 2001-07-06
ƯÁ¤È°µ¿ÀÏ : ¸Å´Þ 5, 15, 30ÀÏ
Á¦ÀÛ±¹ : Çѱ¹
Áõ»ó : * ¸Å´Þ 5, 15, 30ÀÏ À©µµ¿ì »ç¿ëÀÚ Á¤º¸¿Í ÀͽºÇ÷η¯ Ãʱâ ÆäÀÌÁö¸¦ º¯°æÇÑ´Ù.
HTML/Reality.Kr Àº VBS_Reality(McAfee), VBS.Voodoo.b (Kasperskylabs)·Î ºÒ¸®´Â ½ºÅ©¸³Æ® ¹ÙÀÌ·¯½º·Î ±¹³»¿¡¼´Â 2001³â 7¿ù óÀ½ ±¹³»¿¡¼ ¸¸µç º¯Á¾ÀÌ ¹ß°ßµÇ¾ú´Ù.
ÆÄÀÏÀ» óÀ½ ½ÇÇà ÇÏ°Ô µÇ¸é Active X âÀÌ ¶ß°Ô µÇ¸ç »ç¿ëÀÚ°¡ "¿¹" À» ´¸£¸é ½ºÅ©¸³Æ® ¹ÙÀÌ·¯½º°¡ ½ÇÇàµÈ´Ù.
½ÇÇàµÉ¶§ ·¹Áö½ºÆ®¸®ÀÇ ´ÙÀ½ÀÇ °ªÀ» ¼öÁ¤ ÇϰԵǴµ¥
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
1201 = 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows \CurrentVersion\Internet Settings\Zones\0
1201 = 0
À§ÀÇ Ç׸ñÀÌ 0 À¸·Î ¼öÁ¤µÇ¸é (ÀÏ¹Ý »ç¿ëÀÚÀÇ °æ¿ì 1·Î µÇ¾î ÀÖÀ½) Activex X ÀÇ °æ°íâÀÌ ¶ßÁö ¾Ê°Ô µÇ±â ¶§¹®¿¡ »ç¿ëÀÚ´Â ½ºÅ©¸³Æ® ¹ÙÀÌ·¯½º°¡ ½ÇÇàµÇ´ÂÁö ¾Ë¼ö¾ø°ÔµÈ´Ù. ¶ÇÇÑ Active X °¡ »ç¿ëÀÚ µ¿ÀÇ ¾øÀÌ ½ÇÇàµÇ±â ¶§¹®¿¡ ±âŸ ´Ù¸¥ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö µµ ÀÖ´Ù.
ÆÄÀÏÀ» ½ÇÇà ÇÏ°Ô µÇ¸é ÇöÀç Æú´õ¿Í ƯÁ¤ Æú´õ¿¡¼ È®ÀåÀÚ°¡ htt, htm, html, aspÀÎ ÆÄÀÏÀ» °Ë»öÇؼ °¨¿° ½ÃÅ°°Ô µÈ´Ù. °¨¿°µÇ´Â ÆÄÀÏÀº ÆÄÀÏ ¼±µÎ¿¡ ¶ó´Â Ç׸ñÀÌ µé¾î °¡°Ô µÇ¸ç Çѹø °¨¿°µÈ ÆÄÀÏÀº ´Ù½Ã °¨¿°µÇÁö ¾Ê´Â´Ù.
°¨¿°µÇ´Â ƯÁ¤ Æú´õ´Â ´ÙÀ½°ú °°´Ù.
C:\My Documents
C:\Windows\¹ÙÅÁ ȸé
C:\Windows\Desktop
C:\Windows\Web
C:\Windows\Web\Wallpaper
C:\Windows\Help
C:\Windows\Temp
C:\Program Files\Internet Explorer\Connection Wizard
C:\Program Files\Microsoft Office\Office\Headers
C:\Inetpub\wwwroot
½ÇÇà½Ã 1/2 È®·ü·Î À©µµ¿ì½Ã½ºÅÛ Æú´õ(ÀϹÝÀûÀ¸·Î C:\WINDOWS\SYSTEM)¿¡ system.dll ÆÄÀÏÀ» »ý¼ºÇÏ°í WinStart.bat ÆÄÀÏÀ» ºÎÆýà µµ½º¿ë ¹ÙÀÌ·¯½º°¡ ½ÇÇàµÇµµ·Ï ¼öÁ¤ÇÏ°Ô µÈ´Ù. ±×¸®°í ÀçºÎÆýà C:\ ¿Í C:\WINDOWS\COMMAND Æú´õ¿¡ Command32.COM ÆÄÀÏÀ» »ý¼º ÇÏ°Ô µÇ´Âµ¥ ÀÌ ÆÄÀÏÀÇ °æ¿ì µµ½º¿ë ¹ÙÀÌ·¯½º ÆÄÀÏ·Î À©µµ¿ì ºÎÆýà ¸¶´Ù ½ÇÇàÀÌ µÇ°Ô µÈ´Ù. ÇÏÁö¸¸ ÀÌ ÆÄÀÏÀÇ ¹ö±×·Î ÀÎÇØ »ý¼ºµÇÁö ¾ÊÀ¸¸ç »ý¼ºµÇµµ ½ÇÇàµÇÁö ¾Ê´Â´Ù.
¶ÇÇÑ ½ºÅ©¸³Æ® ¹ÙÀÌ·¯½º°¡ ½ÇÇàµÈÈÄ, ±×³¯ÀÇ ³¯Â¥°¡ 5, 15, 30ÀÏ ÀÎ °æ¿ì ·¹Áö½ºÆ®¸® ´ÙÀ½ÀÇ °ªÀ» ¼öÁ¤ ÇÏ°Ô µÈ´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Ç׸ñ¿¡¼
ProductName = Windogs Fuck!
RegisteredOwner = Kil13r
RegisteredOrganization = in Korea, DLSoft
±×¸®°í ÀÎÅÍ³Ý ÀͽºÇ÷η¯ÀÇ ½ÃÀÛ ÆäÀÌÁö¸¦ ¼öÁ¤ ÇÑ´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main Ç׸ñ¿¡¼
Start Page = http://fxxk-jxxxn.com
* V3 Á¦Ç°±º »ç¿ëÀÚ
1. V3¸¦ Ãֽſ£ÁøÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÑ ÈÄ °Ë»çÇÏ¿© HTML/Reality.KrÀ̶ó°í Áø´ÜµÇ´Â ¹ÙÀÌ·¯½º´Â ¸ðµÎ Ä¡·áÇÑ´Ù.
2. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ½ÇÇàÇÏ¿© À©µµ¿ì »ç¿ëÀÚ Á¤º¸¸¦ º¯°æÇÏ°í ÀÎÅÍ³Ý ÀͽºÇ÷η¯ Ãʱâ ÆäÀÌÁöµµ ¼öÁ¤ÇØÁØ´Ù.
* V3 Á¦Ç°±º ¹Ì»ç¿ëÀÚ
1. È®ÀεÇÁö ¾ÊÀº Active X ´Â ½ÇÇà½ÃÅ°Áö ¾Ê´Â´Ù.
2. ´ÙÀ½ÀÇ Æú´õ¿¡¼ È®ÀåÀÚ°¡ htt, htm, html, asp ÆÄÀÏÀ» ã¾Æ ÅؽºÆ® ÆíÁý±âµîÀ¸·Î ¿ÀÇÂÀ» ÇÑ µÚ (i--Thrower--) ¶óÀκÎÅÍ (/body)(/html) ±îÁö »èÁ¦ÈÄ ÀúÀåÇÑ´Ù.
C:\My Documents
C:\Windows\¹ÙÅÁ ȸé
C:\Windows\Desktop
C:\Windows\Web
C:\Windows\Web\Wallpaper
C:\Windows\Help
C:\Windows\Temp
C:\Program Files\Internet Explorer\Connection Wizard
C:\Program Files\Microsoft Office\Office\Headers
C:\Inetpub\wwwroot (ÀÌ Æú´õ´Â À©µµ¿ì¸¦ ÀÌ¿ëÇÏ¿© À¥ ¼¹ö¸¦ ¿î¿µÇÏ´Â ½Ã½ºÅÛ¿¡¸¸ Á¸ÀçÇÑ´Ù.)
3. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ½ÇÇàÇÏ¿© ´ÙÀ½ÀÇ °ªÀ» ¼öÁ¤ÇØÁØ´Ù.
HKEY_CURRENT_USER\
Software\
Microsoft\
Windows\
CurrentVersion\
Internet Settings\
Zones\
0
1201 = 0 -> 1·Î ¼öÁ¤ÇÑ´Ù.
HKEY_LOCAL_MACHINE\
Software\
Microsoft\
Windows\
CurrentVersion\
Internet Settings\
Zones\
0
1201 = 0 -> 1·Î ¼öÁ¤ÇÑ´Ù.
Âü°í»çÇ×
¹ÙÀÌ·¯½º°¡ ¸ÞÀÏ·Î ÆÛÁö´Â °¨¿°Áõ»óÀº ¾øÁö¸¸ À©µµ¿ì¿¡¼ À¥¼¹ö¸¦ ¿î¿µÇÏ´Â »ç¿ëÀÚµéÀÇ »çÀÌÆ® HTML ÆÄÀÏÀ» ÀüºÎ °¨¿° ½ÃÅ°±â ¶§¹®¿¡ À©µµ¿ì¿¡¼ À¥¼¹ö¸¦ ¿î¿µÇÏ´Â »ç¿ëÀÚµéÀº ÁÖÀ§¸¦ ÇØ¾ß ÇÑ´Ù. |
|
|
|
|
|
|
¨Ï µ¥ÀÌÅͳÝ(http://t564.ndsoftnews.com) ¹«´ÜÀüÀç ¹× Àç¹èÆ÷±ÝÁö | ÀúÀ۱ǹ®ÀÇ |
|
|
|
|
|
| |
°¡Àå ¸¹ÀÌ º» ±â»ç |
|
|
|