º¸¾ÈIT´º½º º¸¾È±Ç°í¹® º¸¾ÈTip º¸¾Èó¹æ º¸¾ÈÅë½Å º¸¾È¿ë¾î º¸¾È¹é½Å¸ÞÀÏ º¸¾ÈĶ¸°´õ
º¸¾ÈÀ§ÇùDB ã±â
º¸¾ÈÄ®·³
¿¡ºê¸®Á¸ Zip¿¡ºê¸®Á¸ See¿¡ºê¸®Á¸ FTP

  º¸¾ÈIT´º½º
  º¸¾È±Ç°í¹®
  º¸¾ÈTip
  º¸¾Èó¹æ
  º¸¾ÈÅë½Å
  º¸¾È¿ë¾î
  º¸¾È¹é½Å¸ÞÀÏ
  º¸¾ÈĶ¸°´õ
  º¸¾ÈÀ§ÇùDBã±â
  º¸¾ÈÄ®·³

   º¸¾ÈÀ§ÇùDBã±â
   
  
 ¸ñ·Ï |  À­±Û |  ¾Æ·§±Û  
W32/Sober.42496@mm
 ¹ÙÀÌ·¯½º Á¾·ù
Worm
 ½ÇÇàȯ°æ
Windows
 ¹ß°ßÀÏ
2004³â04¿ù04ÀÏ
 Á¦ÀÛÁö
ºÒºÐ¸í
 À§Çèµî±Þ
 È®»ê¹æ¹ý
 ¹ÙÀÌ·¯½º Å©±â
42,496byte
 Ã·ºÎÆÄÀÏ
attachment.pif ¿Ü ´Ù¼ö
 ¸ÞÀÏÁ¦¸ñ
  Oh my God ¿Ü ´Ù¼ö
 Áõ»ó¿ä¾à
  
 Ä¡·á¹æ¹ý

Åͺ¸¹é½ÅAi, Åͺ¸¹é½Å Online, Åͺ¸¹é½Å 2001 Á¦Ç°±ºÀ¸·Î Ä¡·á°¡´É.

*Åͺ¸¹é½Å Ai¸¦ »ç¿ëÇÏ½Ã°í ¾Æ¿ô·èÀ» »ç¿ëÇϽŠ´Ù¸é ¹Ýµå½Ã À̸ÞÀÏ °¨½Ã±â¸¦
½ÇÇàÇϽñ⠹ٶø´Ï´Ù.

  
 
»ó¼¼¼³¸í
ÀÌ ¿úÀº À̸ÞÀÏÀ» ÅëÇÏ¿© ÀüÆĵǸç, ºñÁÖ¾ó º£ÀÌÁ÷À¸·Î Á¦À۵Ǿú´Ù.

¿úÀ» Æ÷ÇÔÇÑ À̸ÞÀÏÀº ¾Æ·¡¿Í °°Àº Á¦¸ñ°ú º»¹® ÷ºÎÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀüÆĵȴÙ.


[¸ÞÀÏ Á¦¸ñ]

(µ¶ÀϾî)
Besttigung
Datenbank-Fehler
Einzelheiten
Fehler
Fehler in E-Mail
Fehlerhafte Mailzustellung
Hallo Du!
Hallo!
Hey Du
Ich bin es .-)
Ich bin''s
Ihr Passwort
Ihr neues Passwort
Illegale Zeichen in Mail-Routing
Info
Information
Mailzustellung fehlgeschlagen
Na, berrascht?!
Registrierungs-Besttigung
Verbindung fehlgeschlagen
Verdammt
Warnung!

(¿µ¾î)
Bad Gateway
Confirmation Required
Connection failed
Faulty mail delivery
Hey- Hi, it''s me
Hi!- hey you
Illegal signs in Mail-Routing
Invalid mail sentence length
Mail Delivery failure
Mail Error
Message Error
Oh my God
Warning!
Well, surprise?!
Your document
damn!
elivery failed
mail delivery status

[¸ÞÀÏ ³»¿ë]

(µ¶ÀϾî)
Ich war auch ein wenig
Wer konnte so etwas ahnen!? Lese selbst
Oh-Mann

Alles klaro bei dir?
Schau mal was Ich gefunden habe

Meinst Du das wirklich?

(¿µ¾î)
I was surprised, too! :-(
Who could suspect something like that?

All OK  :)
see, what i''ve found!

hi its me
i''ve found a shity virus on my pc. check your pc, too!
follow the steps in this article.
bye

I ''ve told you!:-) sometime I grab your passwords!

I hope you accept the result!
Follow the instructions to read the message.
Please read the document

[÷ºÎÆÄÀÏ]

÷ºÎÆÄÀÏÀÇ È®ÀåÀÚ´Â zip, pif·Î ÀÌ·ç¾îÁ® ÀÖ´Ù.

attachment
AMD-System.txt
Anleitung
AntiVirus-Text
Benutzer-Daten
Block-Lists
Datenbank-Fehler
Dokument
KurzText
Oh-Mann
Passwoerter.txt
Text-Inhalt
Textdocument
_attach
abuse-liste
anitv_text
attach
attach-message
corrected_text-file
instructions
messagedoc
pass-message
schwarze-listen
text
your_article
your_passwords




[Ư¡]

¿úÀÌ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°ÀÌ À©µµ¿ì ½Ã½ºÅÛ Æú´õ(win 2000, NT : c:\Wint\system32, win XP : c:\windows\system32)
¿¡  zmndpgwf.kxx, zhcarxxi.vvx, bcegfds.lll, syst32win.dll, winsys32xx.zzp, winhex32xx.wrm, spoofed_recips.ocx
ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
½Ã½ºÅÛ¿¡ »ý¼ºÇÏ´Â ¿ú ÆÄÀÏÀº ƯÁ¤ ¹®ÀÚ¿­À» ·£´ýÇÏ°Ô Á¶ÇÕÇÏ¿© »ý¼ºÇÑ´Ù.

*·£´ý¹®ÀÚ :
sys, host,dir,expolrer,win,run,log,32,disc,crypt,data,diag,spool,service,smss32,


¶ÇÇÑ, ´ÙÀ½Ã³·³ ·¹Áö½ºÆ®¸¦ ¼öÁ¤ÇÏ¿© ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛÇÑ´Ù.


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Ç׸ñ¿¡

(win9xÀÇ °æ¿ì)
·£´ý ¹®ÀÚ = c:\windows\system\(·£´ý¹®ÀÚ).exe

(win2000, NTÀÇ °æ¿ì)
·£´ý¹®ÀÚ = c:\winnt\system32\(·£´ý¹®ÀÚ).exe

(WinXPÀÇ °æ¿ì)
·£´ý¹®ÀÚ = c:\windows\system32\(·£´ý¹®ÀÚ).exe

¸¦ ±â·ÏÇÑ´Ù.

´ÙÀ½À¸·Î  .HTM, .HTML,, .TXT, .WAB, .PHP, .XLS, XML, .MSG, .mbx, .mdx,
.jsp, .eml, .cgi µîµîÀÇ È®ÀåÀÚ¸¦ Áö´Ñ ÆÄÀÏ¿¡¼­ ¸ÞÀÏ ÁÖ¼Ò¸¦ ¼öÁýÇÏ¿©
Áöü SMTP¸¦ ÀÌ¿ëÇÏ¿© ¿úÀÌ Ã·ºÎµÈ ¸ÞÀÏÀ» ¹ß¼ÛÇÏÁö¸¸ ´ÙÀ½ µµ¸ÞÀÎÀ¸·Î´Â
°¨¿°µÈ ¸ÞÀÏÀÌ ¹ß¼ÛµÇÁö ¾Ê´Â´Ù.

@microsoft
mailer-daemon
office
redaktion
support
variabel
password
time
postmas
service
freeav
@ca.
abuse
winrar
domain.
host.
viren
ewido.
emsisoft
linux
google
@foo.
winzip
@arin
mozilla
@iana
@avp
@msn
microsoft.
@sophos
@panda
symant
ntp-
ntp@
@ntp.
@kaspers
free-av
antivir
virus
verizon.
@ikarus.
@nai.
@messagelab
clock
 
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
 ¸ñ·Ï