*°¨¿° °æ·Î 
ÀÚü ÀüÆÄ ±â´ÉÀº ¾øÀ¸¸ç »ç¿ëÀÚ°¡ ¸ÞÀÏ, ¸Þ½ÅÀú, °Ô½ÃÆÇ, ÀÚ·á½Ç µî¿¡¼ ½ÇÇà ÆÄÀÏÀ» ´Ù¿î·Îµå ÇØ ½ÇÇàÇϰųª ´Ù¸¥ ¾Ç¼ºÄÚµå(¿ú, ¹ÙÀÌ·¯½º, Æ®·ÎÀ̸ñ¸¶)¿¡¼ ¼³Ä¡ÇÏ´Â °ÍÀ¸·Î º¸ÀδÙ.
 
  
  
 *Áõ»ó 
- ÆÄÀÏ»ý¼º 
À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡ ´ÙÀ½ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.  
 - ahnfgss0.dll  
- ahnsbsb.exe 
- ·¹Áö½ºÆ®¸® µî·Ï 
1. À©µµ¿ì ½ÃÀÛ ½Ã ÀÚµ¿À¸·Î ½ÇÇàµÇµµ·Ï Çϱâ À§ÇØ ·¹Áö½ºÆ®¸®Å°¸¦ »ý¼ºÇÑ´Ù.
  - HKEY_CURRENT_USER\       Software\           Microsoft\               Windows\                   CurrentVersion\                       Run\ - ÀÌ   ¸§ : anhsoft - µ¥ÀÌÅÍ : (À©µµ¿ì ½Ã½ºÅÛ Æú´õ)\ahnsbsb.exe 2. ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏ¿© ¼û±è ¼Ó¼ºÀÇ ÆÄÀϵéÀÌ Ç¥½ÃµÇÁö ¾Ê°ÔÇÑ´Ù.
  - HKEY_LOCAL_MACHINE\       SOFTWARE\           Microsoft\               Windows\                   CurrentVersion\                       Explorer\                           Advanced\                               Folder\                                   Hidden\                                       SHOWALL\
  - ÀÌ   ¸§ : CheckedValue - µ¥ÀÌÅÍ : 0x00000000
  - »ý¼ºµÈ dllÆÄÀϵéÀº ½ÇÇàÁßÀÎ ¸ðµç ÇÁ·Î¼¼½º¿¡ »ðÀÔ¿¬µ¿(Injection)ÇÏ¿© µ¿ÀÛÇÑ´Ù. °¨¿°µÈ ½Ã½ºÅÛÀÇ »ç¿ëÀÚ°¡ ƯÁ¤ ¿Â¶óÀÎ °ÔÀÓ¿¡ Á¢¼ÓÇÏ¿© »ç¿ëÀÚ ¾ÆÀ̵ð¿Í ¾ÏÈ£¸¦ ÀÔ·ÂÇÏ°Ô µÉ °æ¿ì ÇØ´ç °ªµéÀ» °¡·Îä¾î ƯÁ¤ ¸ÞÀÏÁÖ¼Ò·Î Àü¼ÛÇÑ´Ù.
 
  |