|
|
º¸¾ÈÅë½Å
 |
º¸¾È Åë½Å |
¾çÀÇ Å»À» ¾´ ´Á´ë Ahnurl.sys, olesau32.dll ¹ÙÀÌ·¯½º |
52367 |
 |
amoxicillin price without prescription amoxicillin price without prescription online buy amoxicillin without prescription abortion pill side effects abortion pill 50mg sertraline can you drink on sertraline 50mg redirect progesterone effet progesterone basse abortion pill where to buy buy the abortion pill ru486 online benadryl pregnancy congestion benadryl and pregnancy nausea go viagra prodej brno viagra cena dr max redirect coupon levitra free coupon for levitra read
ÁÖ¸»À» ÀÌ¿ëÇÏ¿© º¯Á¶µÈ »çÀÌÆ®¸¦ Á¢¼ÓÇϸé ÀÚµ¿À¸·Î ¾Ç¼º ÆÄÀÏÀ» ¼³Ä¡ÇÏ´Â µîÀÇ ¾Ç¼ºÄڵ尡 À¯Çàó·³ ¹øÁö°í ÀÖ½À´Ï´Ù.
°¢Á¾ ¿Â¶óÀÎ °ÔÀÓ »çÀÌÆ®ÀÇ ¾ÆÀ̵ð ¹× ºñ¹Ð¹øÈ£°¡ À¯ÃâµÉ ¼ö ÀÖ´Â Ahnurl.sys, Olesau32.dll ¹ÙÀÌ·¯½º¿¡ ´ëÇØ ¼Ò°³ÇϰíÀÚ ÇÕ´Ï´Ù.
¾Ç¼ºÄÚµåÀÇ À̸§(Ahnurl.sys)À» º¸½Ã¸é ¾Ë ¼ö ÀÖµíÀÌ ±¹³» À¯¸í ¹é½Å »çÀÎ A »çÀÇ ÆÄÀÏÀÎ °Íó·³ µÐ°©ÇÏ¿© ¸¶Ä¡ ¾çÀÇ Å»À» ¾´ ´Á´ëó·³ Ȱµ¿ÇÏ´Â ±³È°ÇÑ(?) ¼º°ÝÀÇ ¾Ç¼ºÄÚµå ÀÔ´Ï´Ù.
»ý¼ºÆÄÀÏ ¹× º¯Á¶µÈ ÆÄÀÏ
»ý¼ºÆÄÀÏ
- C:\Documents and Settings\[»ç¿ëÀÚ °èÁ¤]\Local Settings\TEmp\ddd.exe
(PC¸¦ °¨¿° ½ÃŲ ÈÄ ÀÚµ¿À¸·Î »èÁ¦ µË´Ï´Ù.)
- C:\WINDOWS\olesau32.dll
(PC¸¦ °¨¿° ½ÃŲ ÈÄ ÀÚµ¿À¸·Î »èÁ¦ µË´Ï´Ù.)
- C:\WINDOWS\winurl.dat »ç¿ëÀÚ Á¤º¸¸¦ Àü´Þ ÇÒ ¼¹öÀÇ on/off À¯¹«
- C:\WINDOWS\version.dat ¼³Ä¡µÉ ¾Ç¼ºÆÄÀÏ ¹öÀüÁ¤º¸
- C:\WINDOWS\system32\olesau32.dll
(ºñ½ÁÇÑ À̸§À¸·Î olesau32(2).dll À¸·Î »ý¼ºµÇ±âµµ ÇÕ´Ï´Ù)
- C:\WINDOWS\olesau32.dll
- C:\WINDOWS\system32\drivers\ahnurl.sys
»ý¼º·¹Áö½ºÆ®¸®
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ahnurl
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AHNURL
¹ÙÀÌ·¯½º °¨¿° ½Ã Áõ»óÀº?
-
º¸¾È ÇÁ·Î±×·¥À»Á¾·á ½ÃŰ°Å³ª ºñÁ¤»ó ÀûÀÎ µ¿ÀÛÀ» ¸í·ÉÇÕ´Ï´Ù.
- ¾Ë¾à (AYUpdsRv.aye, AYRTSrv.aye, AYAgent.aye, ALYac.aye)
- ³×À̹ö¹é½Å (NVCUpgrader.exe, NaverAgent.exe, NVCAgent.exe.. etc)
-
DLL ÆÄÀÏÀ»ÀÎÁ§¼Ç ÇÕ´Ï´Ù.
- ÇöÀç µ¿ÀÛÁßÀÎ °¨¿° PC¿¡ C:\WINDOWS\system32\conime.exe ÇÁ·Î¼¼½º¸¦Ã£°í, ¸¸¾à µ¿ÀÛ Áß ÀÌÁö ¾ÊÀ» ½Ã »õ·Ó°Ô »ý¼º½ÃŲ ÈÄ »ý¼ºÇÑ ¾Ç¼ºolesau32.dll ÆÄÀÏÀ» ÀÎÁ§¼Ç ½Ãŵ´Ï´Ù.
(conime.exe-> ¸í·ÉÇÁ·ÒÇÁƮâ¿¡¼, ¾Æ½Ã¾Æ °è¿ÀÇ ¾ð¾î¸¦ ÄÜ¼Ö Ã¢¿¡ ÀÔ·ÂÇÒ ¶§ ¾²ÀÌ´Â ÇÁ·Î¼¼½ºÀÔ´Ï´Ù. Á¤»óÆÄÀÏÀÌÁö¸¸, ÇØÅ· Åø¿¡ ¸¹ÀÌ »ç¿ëµË´Ï´Ù.)
-
SSDTÀ» ÈÄÅ· ÇÕ´Ï´Ù.
- ZwEnumerateKey : ·¹Áö½ºÆ®¸® °Ë»ö º¸È£
- ZwEnumerateValueKey : ·¹Áö½ºÆ®¸® º¯°æ º¸È£
- ZwQueryDirectoryFile : ÆÄÀÏ º¸È£
(SSDT{systemService Dispatch Table} ÈÄÅ·À̶õ, SSDT³»ÀÇ ÇÔ¼ö ÁÖ¼Ò¸¦ ¹Ù²Ù¾î¼, ÈÄÅ· ·çƾÀ» ½ÇÇàÇϵµ·Ï À¯µµÇÏ´Â °ÍÀ» ¸»ÇÕ´Ï´Ù.
¿¹ : ƯÁ¤ °¨¿°µÈ ÆÄÀÏÀÌÁ¤»ó »èÁ¦µÇÁö ¸øÇϵµ·Ï º¸È£ ÇÒ ¼ö ÀÖ½À´Ï´Ù.)
-
»ç¿ëÀÚ Á¤º¸¸¦À¯ÃâÇÕ´Ï´Ù.
- ÀͽºÇ÷η¯·Î´ÙÀ½ »çÀÌÆ®¿¡ Á¢¼Ó ½Ã »ç¿ëÀÚÁ¤º¸¸¦ Àü¼ÛÇÕ´Ï´Ù.
tera.hangame.com
hangame.com
poker.hangame.com
pmang.com
lineage.plaync.co.kr
netmarble.net
df.nexon.com
- ´ÙÀ½ÇÁ·Î¼¼½º°¡ ½ÇÇà ÁßÀÏ °æ¿ì »ç¿ëÀÚ Á¤º¸¸¦ Àü¼ÛÇÕ´Ï´Ù.
PMangAgent.exe
dnf.exe
- ¸®´ÏÁö, ¸ÞÀÌÇýºÅ丮, ´øÀü¾Ø ÆÄÀÌÅÍ, ÇǸÁ, ÇѰÔÀÓ ³Ý¸¶ºí µîÀÇ °ÔÀÓ Á¤º¸¸¦ À¯ÃâÇÕ´Ï´Ù.
-
ÀÌ ¹ÙÀÌ·¯½ºÀÇ ½É°¢¼º!!!!!! (ÁÖÀÇ!!)
- ÇØ´ç¾Ç¼ºÆÄÀÏÀ» »ç¿ëÀÚ°¡ ¼öµ¿À¸·Î »èÁ¦ ÇÏ·Á°í ÇØµµ, 5ÃÊ ´ÜÀ§·Î ÀÚ½ÅÀ»Write(¾²±â) ÇÏ´Â ÀÚü º¸È£±â´ÉÀ» °¡Áö°í ÀÖ¾î¼, »èÁ¦µÈ ÆÄÀÏÀÌ Àç»ý¼º µË´Ï´Ù
¾î¶»°Ô Á¶Ä¡ ÇØ¾ß ÇÒ±î¿ä?
ÇØ´ç ¹ÙÀÌ·¯½º´Â ÀÚü º¸È£±â´ÉÀ» °¡Áö°í Àֱ⠶§¹®¿¡ ¹Ýµå½Ã ¾ÈÀü¸ðµå ¿¡¼ ¼öµ¿»èÁ¦¸¦ ÁøÇàÇØÁּžßÇÕ´Ï´Ù.
-
·çƮŶ (Root kit) Áø´Ü ÇÁ·Î±×·¥ GMER ÇÁ·Î±×·¥À» ´Ù¿î·Îµå ÇÕ´Ï´Ù.
(www.gmer.net ¿¡¼ ´Ù¿î·Îµå °¡´É)
-
¾ÈÀü¸ðµå·ÎºÎÆÃÇÕ´Ï´Ù. - ÄÄÇ»ÅÍ Àü¿øÀ» ´©¸£½Ã°í F8À» °è¼Ó´·¯ÁÖ½Ã¸é µË´Ï´Ù.
(¹Ýµå½Ã ³×Æ®¿öÅ· »ç¿ëÀÌ ºÒ°¡´ÉÇÑ “¾ÈÀü¸ðµå”·Î ºÎÆÃÇØÁÖ¼¼¿ä)
-
GMER¸¦ ½ÇÇàÇÕ´Ï´Ù.
-
GMER ȸéÀÇ ¿ÞÂÊ »ó´Ü¿¡ >>> ¹öưÀ» ´·¯ÁÖ¼¼¿ä

-
À§ÂÊ¿¡ Service ÅÇÀ» ´·¯ÁÖ½Ã°í ¸ñ·Ï¿¡¼ “ahnurl”¶ó´Â À̸§À»°¡Áø Ç׸ñÀ» ã¾Æ ¼±ÅÃÇÑ ÈÄ ¸¶¿ì½º ¿ìŬ¸¯À» ÅëÇØ Delete …” °ªÀ» ¼±ÅÃÇϤ±¿© µî·ÏµÈ ¼ºñ½º¸¦ »èÁ¦ÇØÁÖ¼¼¿ä

( Are you sure you want to delete service file “ahnurl” – “C:\WINDOWS\system \drivers\ahnurl.sys” ¶ó´Â âÀÌ ³ª¿À¸é “¿¹” ¸¦ ´·¯ÁÖ¼¼¿ä)
-
À§ÂÊ File ÅÇÀ» ´·¯ÁÖ½Ã°í ¿ÞÂÊ °æ·Î¿¡¼ C;\WINDOWS\system32 °æ·Î¿¡¼ Olesau32.dll À» ´·¯Áֽðí¿À¸¥ÂÊ¿¡ delete ¹öưÀ» ´·¯ÁÖ¼¼¿ä.
-
Á¤»óÀûÀ¸·Î»èÁ¦°¡ µÇ¼ÌÀ¸¸é, ½Ã½ºÅÛÀ» Àç ºÎÆÃ ÇϽŠÈÄ Á¤»ó¸ðµå·Î À©µµ¿ì¿¡ ÁøÀÔÇÏ¿© C:\WINDOWS\version.dat, C:\WINDOWS\winurl.dat ÆÄÀÏÀ» Ãß°¡ÀûÀ¸·Î »èÁ¦ÇØÁÖ¼¼¿ä.
-
¸ðµç ÀÛ¾÷ÀÌ ³¡³ª½Å °æ¿ì ¹Ýµå½Ã Åͺ¸¹é½Å ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© Á¤¹Ð °Ë»ç¸¦ ¼öÇàÇÏ¿©Ãß°¡ÀûÀÎ °Ë»ç¸¦ ÇÏ´Â °ÍÀÌ ¾ÈÀüÇÕ´Ï´Ù.
¶ÇÇÑ, À̹ø ¹ÙÀÌ·¯½ºÀÇ °æ¿ì Adobe Flash Player, Oracle Java ÇÁ·Î±×·¥ÀÌ ÃֽйöÀüÀÌ ¾Æ´Ñ ȯ°æ¿¡¼ À¯Æ÷ »çÀÌÆ®¿¡ Á¢¼ÓÇÏ¿© ÀÚµ¿À¸·Î °¨¿°µÈ »ç·ÊÀ̹ǷÎ, ¹Ýµå½Ã ¸ðµç º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÃÖ½ÅÀ¸·Î À¯ÁöÇϽô °ÍÀÌ °¡Àå Áß¿äÇÕ´Ï´Ù.
±ú²ýÇÑ PC¸¦ À§Çؼ´Â??
-
À©µµ¿ì ¾÷µ¥ÀÌÆ®¸¦ÁÖ±âÀûÀ¸·Î ÇÑ´Ù.
-
Ç÷¡½Ã Ç÷¹À̾îÆÐÄ¡¸¦ ÃֽйöÀüÀ¸·Î À¯ÁöÇÑ´Ù.
-
Åͺ¸¹é½ÅÀÇ ½Ç½Ã°£ °¨½Ã ±â´ÉÀ» ÄѵдÙ.
-
Åͺ¸¹é½ÅÀÇ ¾÷µ¥ÀÌÆ®¸¦ Ç×»ó ÃÖ½ÅÀ¸·Î À¯ÁöÇÑ´Ù.
-
ÀÎÅÍ³Ý »ç¿ë±â·Ï, ÄíŰ µîÀº ÀÚÁÖ »èÁ¦ ÇØÁØ´Ù.
-
ÄÄÇ»ÅÍ »ç¿ëÀÚ°èÁ¤ÀÌ ºñ¹Ð¹øÈ£´Â 9ÀÚ ÀÌ»ó (¿µ¹®ÀÚ, Ư¼ö¹®ÀÚ, ¼ýÀÚÀÇ Á¶ÇÕ)À¸·ÎÇÑ´Ù.
|
 |
|
|
|
|