¿¡ºê¸®Á¸¼Ò°³ | Á¦Ç°¼Ò°³ | °í°´¼¾ÅÍ | »çÀÌÆ®¸Ê | Home
°³ÀÎ°í°´ ¿©¼º°í°´ eº¸¾È¸¶ÄÏ À̺¥Æ®
°³ÀÎ°í°´±â¾÷°í°´
º¸¾ÈÁ¢¼Ó IDÀúÀå
AD ¹«·á·Î Ã¥¹Þ¾Æ°¡¼¼¿ä!


 
Adware/IERCash
 Á¾·ù
adware
 °¨¿°°æ·Î
ActiveX
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Adware/IERCash´Â ActiveX Çü½ÄÀ» ÃëÇØ »ç¿ëÀÚ¿¡°Ô ¼³Ä¡¸¦ À¯µµÇÏ°í,
¼³Ä¡ °úÁ¤¿¡¼­µµ ¼³Ä¡°úÁ¤À» Ç¥½Ã ÇÏÁö ¾Ê´Â µî ÀºÆóÀûÀ¸·Î ¼³Ä¡µÈ ÈÄ ¹ÙÀÌ·¯½º¸¦ ´Ù¿î ÇÏ´Â ¾Ç¼ºÄÚµåÀÌ´Ù.
¼³Ä¡ ÀÌÈÄ, ÃÖ¼ÒÇÑÀÇ Ç¥½Ã ÀÌ¿Ü¿¡´Â ÇÁ·Î±×·¥ ¼³Ä¡¸¦ ¾Ë¾Æº¼¼ö ¾øµµ·Ï Çϸç,
»ç¿ëÀÚ µ¿ÀÇ ¾øÀÌ À¥»çÀÌÆ®ÀÇ ¼³Á¤¹× ±âº» ±â´ÉÀ» º¯°æ ÇÏ´Â ¾Ç¼ºÄÚµåÀÌ´Ù.

ÀÌ´Â
- À¥ ºê¶ó¿ìÀúÀÇ È¨ÆäÀÌÁö ¼³Á¤À̳ª °Ë»ö ¼³Á¤À» º¯°æ ¶Ç´Â ½Ã½ºÅÛ ¼³Á¤À» º¯°æÇÏ´Â ÇàÀ§
- Á¤»ó ÇÁ·Î±×·¥ÀÇ ¿î¿µÀ» ¹æÇØ, ÁßÁö ¶Ç´Â »èÁ¦ ÇÏ´Â ÇàÀ§
- Á¤»ó ÇÁ·Î±×·¥ÀÇ ¼³Ä¡¸¦ ¹æÇØÇÏ´Â ÇàÀ§
- ´Ù¸¥ ÇÁ·Î±×·¥À» ´Ù¿î·Îµå ÇÏ¿© ¼³Ä¡ÇÏ°Ô ÇÏ´Â ÇàÀ§
- ¿î¿µÃ¼°è ¶Ç´Â Ÿ ÇÁ·Î±×·¥ÀÇ º¸¾È¼³Á¤À» Á¦°ÅÇϰųª ³·°Ô º¯°æÇÏ´Â ÇàÀ§
- ÀÌ¿ëÀÚ°¡ ÇÁ·Î±×·¥À» Á¦°ÅÇϰųª Á¾·á½ÃÄѵµ ÇÁ·Î±×·¥(´çÇØ ÇÁ·Î±×·¥ÀÇ º¯Á¾ ÇÁ·Î±×·¥µµ Æ÷ÇÔ)ÀÌ Á¦°Å µÇ°Å³ª Á¾·áµÇÁö ¾Ê´Â ÇàÀ§
- »ç¿ëÀÚÀÇ Àǵµ¿Í »ó°ü¾ø´Â ±¤°í È¿°ú¸¦ ¹ß»ý½ÃÅ°´Â °æ¿ì

[»ý¼º ÆÄÀÏ]
%prog%\????\IEexeRCash.exe (ÀÓÀÇÀÇ Æú´õ¸í)
%prog%\????\IEBhoRCash.dll
%prog%\????\rcash.exe
%windows%\\????\IEexeRCash.exe (ÀÓÀÇÀÇ Æú´õ¸í)
%windows%\\????\IEBhoRCash.dll
%windows%\RCashV2.exe
%system%\RCashUserData.dll
%system%\????.EXE (ÀÓÀÇÀÇ Æú´õ°ú µ¿ÀÏ)



[»ý¼º ·¹Áö]
HKEY_CURRENT_USER\software\Rcash v1.0
HKEY_CLASSES_ROOT\CLSID\{0CD26485-A4D9-4cf2-80B6-F0B02E8B7A2B}
HKEY_CLASSES_ROOT\TypeLib\{BF1631E6-98EE-4AFC-8519-0B4AE6FAB6F6}
HKEY_CLASSES_ROOT\Interface\{0DE73186-CEB2-4C3A-BA2B-2EBC0306F47F}
HKEY_CLASSES_ROOT\IERCash.BHO
HKEY_CLASSES_ROOT\IERCash.BHO.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-cash v1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rcash v2.0
HKEY_*_*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Rcash v1.0
HKEY_*_*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Rcash v2.0
HKEY_*_*\SOFTWARE\Microsoft\Windows\CurrentVersion\???? (ÀÓÀÇÀÇ Æú´õ°ú µ¿ÀÏ)


°æ·Î´Â ¾Æ·¡¸¦ ÂüÁ¶ ÇÑ´Ù.
%windows%
c:\windows
%program%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥
%system%
C:\windows\system32
%prog%
C:\Program Files
%currentuser%
C:\Documents and Settings\(username)
%startmenu%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º
»ç¿ëÀÚ µ¿ÀǾøÀÌ BHO·Î ¼³Ä¡µÇ¾î »ç¿ëÀÚ Å°¿öµå¸¦ °¨½ÃÇÏ´Â ¾Öµå¿þ¾îÀÌ´Ù.
 
 
Adware/Shortcut.Truck4989
 Á¾·ù
adware
 °¨¿°°æ·Î
ActiveX
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Adware/Shortcut.Truck4989´Â ActiveX Çü½ÄÀ» ÃëÇØ »ç¿ëÀÚ¿¡°Ô ¼³Ä¡¸¦ À¯µµÇÏ°í,
¼³Ä¡ °úÁ¤¿¡¼­µµ ¼³Ä¡°úÁ¤À» Ç¥½Ã ÇÏÁö ¾Ê´Â µî ÀºÆóÀûÀ¸·Î ¼³Ä¡µÇ´Â ¾Ç¼ºÄÚµåÀÌ´Ù.
¼³Ä¡ ÀÌÈÄ, ±¤°í¼º ¾ÆÀÌÄÜ »ý¼º°ú ±¤°í Çö»óÀ» ¹ß»ý½ÃÅ°´Â ¾Ç¼ºÄÚµåÀÌ´Ù.

ÀÌ´Â
- »ç¿ëÀÚÀÇ Àǵµ¿Í »ó°ü¾ø´Â ±¤°í È¿°ú¸¦ ¹ß»ý½ÃÅ°´Â °æ¿ì


[»ý¼º ÆÄÀÏ]
%dpf%\truck4989.ocx
%desktop%\Æ®·°4989.url
%currentuser%\My Documents\Æ®·°4989.ico
%currentuser%\Favorites\Æ®·°4989.url



[»ý¼º ·¹Áö]
HKEY_CURRENT_USER\software\1111111111
HKEY_CLASSES_ROOT\CLSID\{CE549399-D44C-47BA-B1EC-2FA7C42CBA5D}
HKEY_CLASSES_ROOT\TypeLib\{4F6403EC-7F53-4848-8ACA-222B669C4360}
HKEY_CLASSES_ROOT\Interface\{A4056592-D1D8-45A4-BE65-2350E5DB3BDE}
HKEY_CLASSES_ROOT\Interface\{C7793880-23ED-4178-A763-64AB11FECFD7}
HKEY_CLASSES_ROOT\InbeeShortcutProj.InbeeShortcut
HKEY_CLASSES_ROOT\InbeeShortcutProj.InbeeShortcut.1


°æ·Î´Â ¾Æ·¡¸¦ ÂüÁ¶ ÇÑ´Ù.
%windows%
c:\windows
%program%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥
%system%
C:\windows\system32
%prog%
C:\Program Files
%currentuser%
C:\Documents and Settings\(username)
%startmenu%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º
»ç¿ëÀÚ µ¿ÀǾøÀÌ BHO·Î ¼³Ä¡µÇ¾î »ç¿ëÀÚ Å°¿öµå¸¦ °¨½ÃÇÏ´Â ¾Öµå¿þ¾îÀÌ´Ù.
 
 
Adware/Toolbar.Webpie
 Á¾·ù
adware
 °¨¿°°æ·Î
ActiveX
 Ä¡·á¹æ¹ý

¿¡ºê¸®Á¸ Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.

 
Áõ»ó
Adware/Toolbar.Webpie´Â ActiveX Çü½ÄÀ» ÃëÇØ »ç¿ëÀÚ¿¡°Ô ¼³Ä¡¸¦ À¯µµÇÏ°í,
¼³Ä¡ °úÁ¤¿¡¼­µµ ¼³Ä¡°úÁ¤À» Ç¥½Ã ÇÏÁö ¾Ê´Â µî ÀºÆóÀûÀ¸·Î ¼³Ä¡µÇ´Â ¾Ç¼ºÄÚµåÀÌ´Ù.
¼³Ä¡ ÀÌÈÄ, ÁÖ¼Ò Ç¥½ÃÁÙ ´ëüµî °í°´ÀÇ °Ë»ö¾î¸¦ ŽÁöÇØ ¾ÇÀÇÀûÀÎ ¸ñÀûÀ¸·Î »ç¿ëÇÏ´Â ¾Ç¼ºÄÚµåÀÌ´Ù.

ÀÌ´Â
- À¥ ºê¶ó¿ìÀúÀÇ È¨ÆäÀÌÁö ¼³Á¤À̳ª °Ë»ö ¼³Á¤À» º¯°æ ¶Ç´Â ½Ã½ºÅÛ ¼³Á¤À» º¯°æÇÏ´Â ÇàÀ§
- Á¤»ó ÇÁ·Î±×·¥ÀÇ ¿î¿µÀ» ¹æÇØ, ÁßÁö ¶Ç´Â »èÁ¦ ÇÏ´Â ÇàÀ§
- ´Ù¸¥ ÇÁ·Î±×·¥À» ´Ù¿î·Îµå ÇÏ¿© ¼³Ä¡ÇÏ°Ô ÇÏ´Â ÇàÀ§


[»ý¼º ÆÄÀÏ]
%prog%\webpie\¸ðµç ÆÄÀÏ
%prog%\webpie
%dpf%\webpie.ocx
%dpf%\webpie.inf


[»ý¼º ·¹Áö]
HKEY_CURRENT_USER\software\webpie
HKEY_CLASSES_ROOT\CLSID\{311D9C58-7E58-4746-B8FA-4390477AC1B5}
HKEY_CLASSES_ROOT\CLSID\{8D613DB2-E06C-4806-9A6B-6DF57A115622}
HKEY_CLASSES_ROOT\CLSID\{986190C9-E466-42B6-8509-A01CCF44AC20}
HKEY_CLASSES_ROOT\TypeLib\{080DF491-9021-4FBD-AB56-06F137EFFFAF}
HKEY_CLASSES_ROOT\TypeLib\{1CEB861A-ADF0-4C02-8161-2994F58D4901
HKEY_CLASSES_ROOT\Interface\{508EC2B1-D616-47B2-AA01-CE0FD6D6DFBE}
HKEY_CLASSES_ROOT\Interface\{C4256AC4-4B00-4FE0-8929-0D43F560E48C}
HKEY_CLASSES_ROOT\Interface\{E65589B3-BA28-4D06-976B-26331A4141F9}
HKEY_CLASSES_ROOT\WEBPIE.WebpieCtrl
HKEY_CLASSES_ROOT\WEBPIE.WebpieCtrl.1
HKEY_CLASSES_ROOT\Webpie.Webpie
HKEY_CLASSES_ROOT\Webpie.Webpie.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webpie
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webpie uninstall
HKEY_*_*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run webpie toolbar


°æ·Î´Â ¾Æ·¡¸¦ ÂüÁ¶ ÇÑ´Ù.
%windows%
c:\windows
%program%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º\ÇÁ·Î±×·¥
%system%
C:\windows\system32
%prog%
C:\Program Files
%currentuser%
C:\Documents and Settings\(username)
%startmenu%
C:\Documents and Settings\(username)\½ÃÀÛ ¸Þ´º
»ç¿ëÀÚ µ¿ÀǾøÀÌ BHO·Î ¼³Ä¡µÇ¾î »ç¿ëÀÚ Å°¿öµå¸¦ °¨½ÃÇÏ´Â ¾Öµå¿þ¾îÀÌ´Ù.
 
 
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
                                                                 * ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
   | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30