*°¨¿°
°æ·Î
À©µµ¿ì
º¸¾È
Ãë¾àÁ¡À»
ÅëÇØ
°¨¿°
*Áõ»ó
Worm-W32/AgoBot.119808.E
°¡
½ÇÇàµÇ¸é
´ÙÀ½
ÀÛ¾÷À»
¼öÇàÇÑ´Ù
-ÆÄÀÏ
»ý¼º
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ¿¡
cmd.exe.tmp
¶ó´Â
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ |
95/98/ME |
C:\Windows\System |
NT/2000 |
C\WinNT\System32 |
XP |
Windows\System32 |
.
-·¹Áö½ºÆ®¸®
µî·Ï ·¹Áö½ºÆ®¸®¿¡
´ÙÀ½
value¸¦
µî·ÏÇØ
À©µµ¿ì
±¸µ¿½Ã
ÀÚµ¿
½ÇÇàµÇµµ·Ï
¸¸µç´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¡°cmd¡±
= À©µµ¿ì
½Ã½ºÅÛ
Æú´õ\cmd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices ¡°cmd¡±
= À©µµ¿ì
½Ã½ºÅÛ
Æú´õ\cmd.exe
°¨¿°µÈ
½Ã½ºÅÛÀº
TCP ÀÓÀÇÀÇ
Æ÷Æ®¸¦
LISTENING »óÅ·Î
¿¾îµÐ´Ù.
(»ó´ë·ÎºÎÅÍ
Á¢¼ÓÀ»
±â´Ù¸®´Â
»óÅÂ)
±×
ÈÄ
»ç¿ëÀÚ
¸ô·¡
Á¢¼Ó
ÇØ
½ºÆÔ
¸ÞÀÏ
¹ß¼Û,
¾Öµå¿þ¾î
¼³Ä¡,
µ¥ÀÌÅÍ
»èÁ¦,
±×¸®°í
°³ÀÎÀÇ
ÄÄÇ»ÅÍ
»ç¿ë
³»¿ªÀ»
ÈÉÃĺ¸°Å³ª
°¢Á¾
ÆÄÀÏ(°³ÀÎ
¹®¼,
±â¹Ð
¹®¼
µî)À»
¿ÜºÎ·Î
»©°¡´Â
º¸¾È»ó
¹®Á¦µµ
¹ß»ýÇÒ
¼ö
ÀÖÀ½
-hosts
ÆÄÀÏ º¯°æ
HOSTS
ÆÄÀÏÀ» ¼öÁ¤ÇØ °¨¿°µÈ ½Ã½ºÅÛÀÌ º¸¾È »çÀÌÆ® ȨÆäÀÌÁö
Á¢¼ÓÀ̳ª ¾ÈƼ ¹ÙÀÌ·¯½º ¿£Áø ¾÷µ¥ÀÌÆ®¸¦ ¹æÇØÇÏ¿© Á¤º¸¸¦ ¾ò°Å³ª Ä¡·á¸¦ ¹æÇØÇÑ´Ù.
ÁÖ)
HOSTS ÆÄÀÏÀº »ç¿ë À©µµ¿ì¿¡ µû¶ó ´Ù¸¥ Æú´õ¿¡ Á¸ÀçÇÑ´Ù.
95/98/ME
C:\Windows\System
NT/2000 C:\WinNT\System32\Drivers\ETC
XP C:\Windows\System32\Drivers\ETC
Á¢¼ÓÀÌ Â÷´ÜµÇ´Â ÁÖ¼Ò´Â ´ÙÀ½°ú °°´Ù.
www.symantec.com securityresponse.symantec.com
symantec.com www.sophos.com sophos.com
www.mcafee.com mcafee.com
liveupdate.symantecliveupdate.com www.viruslist.com
viruslist.com viruslist.com f-secure.com
www.f-secure.com kaspersky.com www.avp.com
www.kaspersky.com avp.com
www.networkassociates.com networkassociates.com
www.ca.com ca.com mast.mcafee.com
my-etrust.com www.my-etrust.com
download.mcafee.com dispatch.mcafee.com
secure.nai.com nai.com www.nai.com
update.symantec.com updates.symantec.com
us.mcafee.com liveupdate.symantec.com
customer.symantec.com rads.mcafee.com
trendmicro.com www.trendmicro.com |