head_sub02
   
¹ÙÀÌ·¯½º
¾Öµå¤ý½ºÆÄÀÌ¿þ¾î
À¯Çذ¡´É¼ºÇÁ·Î±×·¥
Á¾ÇÕÁ¤º¸
º¸¾ÈTIP!
¹ÙÀÌ·¯½º»çÀü
VOD HOT À̽´
 
¹ÙÀÌ·¯½º¸í
 Trojan.PWS.Snap
ÇüÅÂ
 Æ®·ÎÀÌ ¸ñ¸¶
ÀüÆÄ¹æ¹ý
 ¾Ç¼º¾Öµå¿þ¾î ȤÀº ¾×Ƽºê¾×½º ÄÁÆ®·Ñ¿¡ ÀÇÇØ ´Ù¿î·Îµå µÇ¾îÁö´Â°ÍÀ¸·Î º¸ÀδÙ.
¿î¿µÃ¼Á¦
 Windows Ç÷§Æû
Á¤º¸ÀÛ¼ºÀÏ
 2006-08-29
ÆÐÅÏ ¾÷µ¥ÀÌÆ®ÀÏ
 2006-07-27
º°Äª
 Trojan-PSW.Win32.Sinowal, Trojan.Anserin
°£·«È÷
¤· °¨¿°½Ã½ºÅÛÀÇ ½Ã½ºÅÛ Á¤º¸ ¹× »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ ÀÎÅÍ³Ý ¹ðÅ· »çÀÌÆ®ÀÇ Á¢¼ÓID ¹× ÆÐ½º¿öµå µîÀÇ Á¤º¸¸¦ ¿ÜºÎ·Î À¯Ãâ½ÃŲ´Ù.

¤· °¨¿°½Ã½ºÅÛ¿¡¼­ ½ÇÇàÁßÀÎ ¸ðµç ÇÁ·Î¼¼½º¿¡ ÀÎÁ§Æ® µÇ¾î µ¿ÀÛÇÑ´Ù.

¤· °¨¿°½Ã½ºÅÛ¿¡ Á¸ÀçÇÏ´Â ¸ÞÀÏ Å¬¶óÀÌ¾ðÆ® ¹× FTP Ŭ¶óÀÌ¾ðÆ®¸¦ ÅëÇØ ¿ÜºÎ·Î Á¤º¸¸¦ À¯Ãâ½ÃŲ´Ù.

¤· ƯÁ¤ Æ÷Æ®¸¦ ¿­°í Àΰ¡µÇÁö ¾ÊÀº ¿ÜºÎÀÇ Á¢±Ù¿¡ ´ë±âÇÑ´Ù. (TCP 8886, TCP 8906)
Á¶Ä¡¹æ¹ý
[»çÀü¿¹¹æ]
- ¹ÙÀÌ·¯½º üÀ̼­ ½Ç½Ã°£ °¨½Ã±â¸¦ Ȱ¼ºÈ­ ½ÃŲ´Ù.

[¼öµ¿Ä¡·á]
A. ´ÙÀ½°ú °°Àº ·¹Áö½ºÆ®¸® °ªÀ» ¼öÁ¤ÇÏ¿© Trojan.PWS.SnapÀÌ ÀÚµ¿À¸·Î ½ÇÇàµÇÁö ¸øÇϵµ·Ï ÇÑ´Ù.
[HKLM\SYSTEM32\CurrentControlSet\Winlogon]
"shell" = "Explorer.exe, <°ø¹é»ý·«> "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe""¸¦
"shell" = "Explorer.exe"·Î ¼öÁ¤

[HKLM\SOFTWARE\Microsoft\Windows\CurruntVersion\Run]
"shell"= "%ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe" °ª »ý·«

B. ÄÄÇ»ÅÍ Àç½ÃÀÛ

C. Trojan.PWS.SnapÀÇ ±¸¼ºÆÄÀÏ »èÁ¦
´ÙÀ½ÀÇ À§Ä¡¿¡ Á¸ÀçÇÏ´Â Trojan.PWS.SnapÀÇ ±¸¼ºÆÄÀϵéÀ» »èÁ¦ÇÑ´Ù.
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.exe
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00001.dll
- %ProgramFiles%\Common Files\Microsoft Shared\Web Folder\ibm00002.dll
- %systemroot%\kl1.exe
- %systemroot%\temp\$_2341233.TMP
ÀÌÀü±Û
 ¾øÀ½
´ÙÀ½±Û
 ¾øÀ½