¿£ÅÍÇÁ¶óÀÌÁî ȯ°æ¿¡¼­ Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸ ¹èÆ÷

±â¼ú ÀÚ·á: 891716
Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸´Â "º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù." Àý¿¡ ³ª¿­µÈ ¿î¿µ üÁ¦¿¡ »ç¿ëÇϱâ À§ÇÑ °ÍÀÔ´Ï´Ù. ¸ñ·Ï¿¡ Æ÷ÇÔµÇÁö ¾ÊÀº ¿î¿µ üÁ¦´Â Å×½ºÆ®µÇÁö ¾Ê¾ÒÀ¸¹Ç·Î Áö¿øµÇÁö ¾Ê½À´Ï´Ù. Áö¿øµÇÁö ¾Ê´Â ÀÌ·¯ÇÑ ¿î¿µ üÁ¦¿¡´Â Windows Embedded ¿î¿µ üÁ¦ÀÇ ¸ðµç ¹öÀüÀÌ Æ÷ÇԵ˴ϴÙ.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¼Ò°³

Microsoft´Â ÄÄÇ»ÅÍ¿¡¼­ ³Î¸® ¾Ë·ÁÁø ƯÁ¤ ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î¸¦ Á¦°ÅÇÏ´Â µ¥ µµ¿òÀÌ µÇ´Â Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸¸¦ ¹ßÇ¥Çß½À´Ï´Ù.

¼¼ºÎ Á¤º¸ °Ç³Ê¶Ù±â ¹× µµ±¸ ´Ù¿î·Îµå

ÀÌ µµ±¸ ´Ù¿î·Îµå ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://www.microsoft.com/ko-kr/security/default.aspx
ÀÌ ¹®¼­¿¡ Æ÷ÇÔµÈ Á¤º¸´Â µµ±¸ÀÇ ¿£ÅÍÇÁ¶óÀÌÁî ¹èÆ÷¿¡¸¸ ÇØ´çµË´Ï´Ù. ´ÙÀ½ Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ °ËÅäÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ ¹®¼­¿¡´Â µµ±¸ ¹× ´Ù¿î·Îµå À§Ä¡¿¡ ´ëÇÑ ÀÏ¹Ý Á¤º¸°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.


ÀÌ µµ±¸´Â ÁÖ·Î ÄÄÇ»ÅÍ¿¡ ÃֽйÙÀÌ·¯½º ¹é½Å Á¦Ç°ÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀº °³ÀÎ »ç¿ëÀÚ¸¦ À§ÇÑ °ÍÀÔ´Ï´Ù. ÇÏÁö¸¸ ¿£ÅÍÇÁ¶óÀÌÁî ȯ°æ¿¡¼­ ±âÁ¸ÀÇ º¸È£ ±â´ÉÀ» Çâ»ó½ÃŰ°í ½ÉÃþ ¹æ¾î(defense-in-depth) Àü·«ÀÇ ÀÏȯÀ¸·Î ÀÌ µµ±¸¸¦ ¼³Ä¡ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ¿£ÅÍÇÁ¶óÀÌÁî ȯ°æ¿¡¼­´Â ´ÙÀ½ ¹æ¹ý Áß Çϳª ÀÌ»óÀ» »ç¿ëÇÏ¿© ÀÌ µµ±¸¸¦ ¹èÆ÷ÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • Windows Server Update Services
  • SMS(Microsoft Systems Management Software) ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö
  • ±×·ì Á¤Ã¥ ±â¹Ý ÄÄÇ»ÅÍ ½ÃÀÛ ½ºÅ©¸³Æ®
  • ±×·ì Á¤Ã¥ ±â¹Ý »ç¿ëÀÚ ·Î±×¿Â ½ºÅ©¸³Æ®
Windows Update ¹× ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ÅëÇØ ÀÌ µµ±¸¸¦ ¹èÆ÷ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
890830 Áö¿øµÇ´Â Windows ¹öÀüÀÌ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿¡¼­ ƯÁ¤ ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î°¡ È®»êµÇÁö ¾Êµµ·Ï µµ¿ÍÁÖ´Â Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸
´ÙÀ½°ú °°Àº ¹èÆ÷ ±â¼úÀº ÀÌ µµ±¸ÀÇ ÇöÀç ¹öÀü¿¡¼­ Áö¿øµÇÁö ¾Ê½À´Ï´Ù.
  • Windows Update īŻ·Î±×
  • ¿ø°Ý ÄÄÇ»Å͸¦ ´ë»óÀ¸·Î µµ±¸ ½ÇÇà
  • SUS(Software Update Services)
¶ÇÇÑ MBSA(Microsoft Baseline Security Analyzer)µµ µµ±¸ ½ÇÇàÀ» °Ë»öÇÏÁö ¸øÇÕ´Ï´Ù. ÀÌ ¹®¼­¿¡´Â ¹èÆ÷ÇÏ´Â µ¿¾È µµ±¸ ½ÇÇàÀ» È®ÀÎÇÒ ¼ö ÀÖ´Â ¹æ¹ý¿¡ ´ëÇÑ Á¤º¸°¡ ³ª¿Í ÀÖ½À´Ï´Ù.

ÄÚµå »ùÇÃ

¿©±â¿¡ ³ª¿Í ÀÖ´Â ½ºÅ©¸³Æ®¿Í ´Ü°è´Â ´ÜÁö ¿¹Á¦ÀÏ »ÓÀÔ´Ï´Ù. °í°´Àº ÀÌ·¯ÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®¿Í ¿¹Á¦ ½Ã³ª¸®¿À¸¦ Å×½ºÆ®Çؼ­ ÀÚ½ÅÀÇ È¯°æ¿¡¼­ ÀÛµ¿Çϵµ·Ï ÀûÀýÇÏ°Ô ¼öÁ¤ÇØ¾ß ÇÕ´Ï´Ù. »ç¿ë ÁßÀΠȯ°æ ¼³Á¤¿¡ µû¶ó ServerName ¹× ShareNameÀ» º¯°æÇØ¾ß ÇÕ´Ï´Ù.

¾Æ·¡ÀÇ ÄÚµå ¿¹Á¦´Â ´ÙÀ½°ú °°Àº ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.
  • ÀÚµ¿ ¸ðµå·Î µµ±¸¸¦ ½ÇÇàÇÕ´Ï´Ù.
  • ¹Ì¸® ±¸¼ºÇÑ ³×Æ®¿öÅ© °øÀ¯¿¡ ·Î±× ÆÄÀÏÀ» º¹»çÇÕ´Ï´Ù.
  • µµ±¸¸¦ ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ À̸§°ú ÇöÀç »ç¿ëÀÚÀÇ »ç¿ëÀÚ À̸§À» ·Î±× ÆÄÀÏ À̸§ ¾Õ¿¡ Ãß°¡ÇÕ´Ï´Ù. Ãʱ⠼³Á¤ ¹× ±¸¼º ÀýÀÇ Áöħ¿¡ µû¶ó °øÀ¯¿¡ ´ëÇØ ÀûÀýÇÑ »ç¿ë ±ÇÇÑÀ» ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù.
REM In this example, the script is named RunMRT.cmd.
REM The Sleep.exe utility is used to delay the execution of the tool when used as a  
REM startup script. See the "Known issues" section for details.
@echo off
call \\ServerName\ShareName\Sleep.exe 5
Start /wait \\ServerName\ShareName\Windows-KB890830-V4.20.exe /q

copy %windir%\debug\mrt.log \\ServerName\ShareName\Logs\%computername%_%username%_mrt.log
Âü°í ÀÌ ÄÚµå »ùÇÿ¡¼­ ServerNameÀº ÇØ´ç ¼­¹ö À̸§ÀÇ ÀÚ¸® Ç¥½ÃÀÚÀ̰í ShareNameÀº ÇØ´ç °øÀ¯ À̸§ÀÇ ÀÚ¸® Ç¥½ÃÀÚÀÔ´Ï´Ù.

Ãʱ⠼³Á¤ ¹× ±¸¼º

ÀÌ ÀýÀº ½ÃÀÛ ½ºÅ©¸³Æ®³ª ·Î±×¿Â ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¿© ÀÌ µµ±¸¸¦ ¹èÆ÷ÇÏ´Â °ü¸®ÀÚ¸¦ À§ÇÑ °ÍÀÔ´Ï´Ù. SMS¸¦ »ç¿ëÇÏ´Â °æ¿ì¿¡´Â "¹èÆ÷ ¹æ¹ý" Àý·Î ÁøÇàÇϽʽÿÀ.

¼­¹ö¿Í °øÀ¯¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ±¸¼º¿ø ¼­¹ö¿¡¼­ °øÀ¯¸¦ ¼³Á¤ÇÕ´Ï´Ù. ±×·± ´ÙÀ½ °øÀ¯ÀÇ À̸§À» ShareNameÀ¸·Î ¼³Á¤ÇÕ´Ï´Ù.
  2. µµ±¸¿Í ¿¹Á¦ ½ºÅ©¸³Æ® RunMRT.cmd¸¦ °øÀ¯¿¡ º¹»çÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ÄÚµå ¿¹Á¦ ÀýÀ» ÂüÁ¶ÇϽʽÿÀ.
  3. ´ÙÀ½ °øÀ¯ »ç¿ë ±ÇÇѰú NTFS ÆÄÀÏ ½Ã½ºÅÛ ±ÇÇÑÀ» ¾Æ·¡¿Í °°ÀÌ ±¸¼ºÇÕ´Ï´Ù.
    • °øÀ¯ »ç¿ë ±ÇÇÑ
      1. ÀÌ °øÀ¯¸¦ °ü¸®Çϰí ÀÖ´Â »ç¿ëÀÚÀÇ µµ¸ÞÀÎ »ç¿ëÀÚ °èÁ¤À» Ãß°¡ÇÏ°í ¸ðµç ±ÇÇÑÀ» Ŭ¸¯ÇÕ´Ï´Ù.
      2. Everyone ±×·ìÀ» Á¦°ÅÇÕ´Ï´Ù.
      3. ÄÄÇ»ÅÍ ½ÃÀÛ ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì¿¡´Â º¯°æ ¹× Àб⠱ÇÇÑÀ» °®°í ÀÖ´Â Domain Computers ±×·ìÀ» Ãß°¡ÇÕ´Ï´Ù.
      4. ·Î±×¿Â ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì¿¡´Â º¯°æ ¹× Àб⠱ÇÇÑÀ» °®°í ÀÖ´Â Authenticated Users ±×·ìÀ» Ãß°¡ÇÕ´Ï´Ù.
    • NTFS ±ÇÇÑ
      1. ÀÌ °øÀ¯¸¦ °ü¸®Çϰí ÀÖ´Â »ç¿ëÀÚÀÇ µµ¸ÞÀÎ »ç¿ëÀÚ °èÁ¤À» Ãß°¡ÇÏ°í ¸ðµç ±ÇÇÑÀ» Ŭ¸¯ÇÕ´Ï´Ù.
      2. Everyone ±×·ìÀÌ ¸ñ·Ï¿¡ ÀÖÀ¸¸é Á¦°ÅÇÕ´Ï´Ù.

        Âü°í Everyone ±×·ìÀ» Á¦°ÅÇÒ ¶§ ¿À·ù ¸Þ½ÃÁö°¡ ³ªÅ¸³ª¸é º¸¾È ÅÇÀÇ °í±Þ ´ÜÃ߸¦ Ŭ¸¯ÇÑ ´ÙÀ½ »ó¼Ó °¡´ÉÇÑ ±ÇÇÑÀ» ºÎ¸ð °³Ã¼¿¡¼­ ÀÌ °³Ã¼ ¹× ¸ðµç ÀÚ½Ä °³Ã¼¿¡ ÀüÆÄÇÒ ¼ö ÀÖÀ½ È®ÀζõÀÇ ¼±ÅÃÀ» Ãë¼ÒÇϽʽÿÀ.
      3. ÄÄÇ»ÅÍ ½ÃÀÛ ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì Domain Computers ±×·ì¿¡ ÀÐ±â ¹× ½ÇÇà ±ÇÇÑ, Æú´õ ³»¿ë º¸±â ±ÇÇÑ ¹× Àб⠱ÇÇÑÀ» ºÎ¿©ÇÕ´Ï´Ù.
      4. ·Î±×¿Â ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì Authenticated Users ±×·ì¿¡ ÀÐ±â ¹× ½ÇÇà ±ÇÇÑ, Æú´õ ³»¿ë º¸±â ±ÇÇÑ ¹× Àб⠱ÇÇÑÀ» ºÎ¿©ÇÕ´Ï´Ù.
  4. ShareName Æú´õ¿¡¼­ "Logs"¶ó´Â Æú´õ¸¦ ¸¸µì´Ï´Ù.

    Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅÍ¿¡¼­ µµ±¸¸¦ ½ÇÇàÇϸé ÃÖÁ¾ ·Î±× ÆÄÀÏÀÌ ÀÌ Æú´õ¿¡ ÀúÀåµË´Ï´Ù.
  5. ´ÙÀ½°ú °°ÀÌ Logs Æú´õ¿¡¼­ NTFS ±ÇÇÑÀ» ±¸¼ºÇÕ´Ï´Ù.

    Âü°í ÀÌ ´Ü°è¿¡¼­´Â °øÀ¯ »ç¿ë ±ÇÇÑÀ» º¯°æÇÏÁö ¸¶½Ê½Ã¿À.
    1. ÀÌ °øÀ¯¸¦ °ü¸®Çϰí ÀÖ´Â »ç¿ëÀÚÀÇ µµ¸ÞÀÎ »ç¿ëÀÚ °èÁ¤À» Ãß°¡ÇÏ°í ¸ðµç ±ÇÇÑÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    2. ÄÄÇ»ÅÍ ½ÃÀÛ ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì Domain Computers ±×·ì¿¡ ¼öÁ¤ ±ÇÇÑ, "ÀÐ±â ¹× ½ÇÇà" ±ÇÇÑ, Æú´õ ³»¿ë º¸±â ±ÇÇÑ, Àб⠱ÇÇÑ ¹× ¾²±â ±ÇÇÑÀ» ºÎ¿©ÇÕ´Ï´Ù.
    3. ·Î±×¿Â ½ºÅ©¸³Æ® ¹æ¹ýÀ» »ç¿ëÇÏ´Â °æ¿ì Authenticated Users ±×·ì¿¡ ¼öÁ¤ ±ÇÇÑ, "ÀÐ±â ¹× ½ÇÇà" ±ÇÇÑ, Æú´õ ³»¿ë º¸±â ±ÇÇÑ, Àб⠱ÇÇÑ ¹× ¾²±â ±ÇÇÑÀ» ºÎ¿©ÇÕ´Ï´Ù.

¹èÆ÷ ¹æ¹ý

Âü°í ÀÌ µµ±¸¸¦ ½ÇÇàÇÏ·Á¸é ¼±ÅÃÇÑ ¹èÆ÷ ¿É¼Ç¿¡ °ü°è¾øÀÌ Administrator ±ÇÇÑ ¶Ç´Â SYSTEM ±ÇÇÑÀÌ ÀÖ¾î¾ß ÇÕ´Ï´Ù.

SMS ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö »ç¿ë ¹æ¹ý

´ÙÀ½ ¿¹Á¦¿¡¼­´Â SMS 2003À» »ç¿ëÇÏ´Â ´Ü°èº° ÁöħÀÌ ³ª¿Í ÀÖ½À´Ï´Ù. SMS 2.0À» »ç¿ëÇÏ´Â ´Ü°è´Â ´ÙÀ½ ´Ü°è¿Í ºñ½ÁÇÕ´Ï´Ù.
  1. Windows-KB890830-V1.34-KOR.exe ÆÐŰÁö¿¡¼­ Mrt.exe ÆÄÀÏÀÇ ¾ÐÃàÀ» DZ´Ï´Ù.
  2. Mrt.exe¸¦ ½ÃÀÛÇϰí ISMIF32.exe¸¦ »ç¿ëÇÏ¿© ¹Ýȯ Äڵ带 ĸóÇϱâ À§ÇÑ .bat ÆÄÀÏÀ» ¸¸µì´Ï´Ù.

    ¿¹Á¦´Â ´ÙÀ½°ú °°½À´Ï´Ù.
    @echo off
    Mrt.exe /q
    If errorlevel 13 goto error13
    If errorlevel 12 goto error12
    Goto end
    
    :error13
    Ismif32.exe ?f MIFFILE ?p MIFNAME ?d ¡±text about error 13¡±
    Goto end
    
    :error12
    Ismif32.exe ?f MIFFILE ?p MIFNAME ?d ¡°text about error 12¡±
    Goto end
    
    :end
    
    Ismif32.exe¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
    268791 SMS 2.0¿¡¼­ ISMIF32.exe ÆÄÀÏ¿¡¼­ »ý¼ºÇÑ »óÅ MIF(°ü¸® Á¤º¸ Çü½Ä) ÆÄÀÏÀ» ó¸®ÇÏ´Â ¹æ¹ý
    186415 »óÅ MIF ÀÛ¼º ÇÁ·Î±×·¥ÀÎ Ismif32.exe¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ½
  3. ´ÙÀ½°ú °°ÀÌ SMS 2003 Äֿܼ¡¼­ ÆÐŰÁö¸¦ ¸¸µì´Ï´Ù.
    1. SMS °ü¸®ÀÚ ÄܼÖÀ» ¿±´Ï´Ù.
    2. Packages ³ëµå¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ Package¸¦ Ŭ¸¯ÇÕ´Ï´Ù.

      Package Properties ´ëÈ­ »óÀÚ°¡ Ç¥½ÃµË´Ï´Ù.
    3. General ÅÇ¿¡¼­ ÆÐŰÁö À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
    4. Data Source ÅÇ¿¡¼­ This package contains source files È®ÀζõÀ» ¼±ÅÃÇÕ´Ï´Ù.
    5. Set¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ µµ±¸°¡ Æ÷ÇԵǾî ÀÖ´Â ¿øº» µð·ºÅ͸®¸¦ ¼±ÅÃÇÕ´Ï´Ù.
    6. Distribution Settings ÅÇ¿¡¼­ Sending priority¸¦ High·Î ¼³Á¤ÇÕ´Ï´Ù.
    7. Reporting ÅÇ¿¡¼­ Use these fields for status MIF matchingÀ» Ŭ¸¯ÇÑ ´ÙÀ½ MIF file name Çʵå¿Í Name ÇʵåÀÇ À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.

      Version°ú Publisher´Â ¿É¼ÇÀÔ´Ï´Ù.
    8. È®ÀÎÀ» Ŭ¸¯ÇÏ¿© ÆÐŰÁö¸¦ ¸¸µì´Ï´Ù.
  4. ´ÙÀ½°ú °°ÀÌ ÆÐŰÁö¿¡ DP(¹èÆ÷ ÁöÁ¡)¸¦ ÁöÁ¤ÇÕ´Ï´Ù.
    1. SMS 2003 ÄܼÖÀÇ Packages ³ëµå¿¡¼­ »õ ÆÐŰÁö¸¦ ã½À´Ï´Ù.
    2. ÀÌ ÆÐŰÁö¸¦ È®ÀåÇÕ´Ï´Ù. Distribution Points¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ Distribution Points¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    3. New Distribution Points Wizard¸¦ ½ÃÀÛÇÏ°í ±âÁ¸ÀÇ ¹èÆ÷ ÁöÁ¡À» ¼±ÅÃÇÕ´Ï´Ù.
    4. ¸¶Ä§À» Ŭ¸¯ÇÏ¿© ¸¶¹ý»ç¸¦ ´Ý½À´Ï´Ù.
  5. ´ÙÀ½°ú °°ÀÌ ¾Õ¿¡¼­ ¸¸µç ¹èÄ¡ ÆÄÀÏÀ» »õ ÆÐŰÁö¿¡ Ãß°¡ÇÕ´Ï´Ù.
    1. »õ ÆÐŰÁö ³ëµå¿¡¼­ Programs ³ëµå¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    2. Programs¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í »õ·Î ¸¸µé±â¸¦ °¡¸®Å² ´ÙÀ½ ProgramÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. General ÅÇÀ» Ŭ¸¯ÇÑ ´ÙÀ½ ¿Ã¹Ù¸¥ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.
    4. Command line¿¡¼­ Browse¸¦ Ŭ¸¯ÇÏ¿© Mrt.exe¸¦ ½ÃÀÛÇϱâ À§ÇØ ¸¸µç ¹èÄ¡ ÆÄÀÏÀ» ¼±ÅÃÇÕ´Ï´Ù.
    5. RunÀ» HiddenÀ¸·Î º¯°æÇÕ´Ï´Ù. After runningÀ» No action required·Î º¯°æÇÕ´Ï´Ù.
    6. Requirements ÅÇÀ» Ŭ¸¯ÇÑ ´ÙÀ½ This program can run only on specified client platforms¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    7. All x86 Windows Server 2003 ¹× All x86 Windows XP¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    8. Environment ÅÇÀ» Ŭ¸¯Çϰí Program can run ¸ñ·Ï¿¡¼­ Whether or not a user is logged¸¦ Ŭ¸¯ÇÕ´Ï´Ù. Run mode¸¦ Run with administrative rights·Î ¼³Á¤ÇÕ´Ï´Ù.
    9. È®ÀÎÀ» Ŭ¸¯ÇÏ¿© ´ëÈ­ »óÀÚ¸¦ ´Ý½À´Ï´Ù.
  6. ´ÙÀ½°ú °°ÀÌ º¸±Þ ¾Ë¸²À» ¸¸µé¾î Ŭ¶óÀÌ¾ðÆ®¿¡ ÇÁ·Î±×·¥À» º¸±ÞÇÕ´Ï´Ù.
    1. Advertisements ³ëµå¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ Advertisement¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    2. General ÅÇ¿¡¼­ ÇØ´ç º¸±Þ ¾Ë¸²ÀÇ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. Package Çʵ忡¼­ ¾Õ¿¡¼­ ¸¸µç ÆÐŰÁö¸¦ ¼±ÅÃÇÕ´Ï´Ù. ±×·± ´ÙÀ½ Program Çʵ忡¼­ ¾Õ¿¡¼­ ¸¸µç ÇÁ·Î±×·¥À» ¼±ÅÃÇÕ´Ï´Ù. Browse¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ All Systems Ä÷º¼ÇÀ» Ŭ¸¯Çϰųª Microsoft Windows XP ÀÌ»ó ¹öÀü¸¸ Æ÷ÇԵǾî ÀÖ´Â ÄÄÇ»ÅÍ Ä÷º¼ÇÀ» ¼±ÅÃÇÕ´Ï´Ù.
    3. Schedule ÅÇ¿¡¼­ ÇÁ·Î±×·¥À» ÇÑ ¹ø¸¸ ½ÇÇàÇÒ °æ¿ì¿¡´Â ±âº» ¿É¼ÇÀ» ±×´ë·Î »ç¿ëÇϰí ÀÏÁ¤¿¡ µû¶ó ÇÁ·Î±×·¥À» ½ÇÇàÇÏ·Á¸é ÀÏÁ¤ °£°ÝÀ» ÁöÁ¤ÇÕ´Ï´Ù.
    4. Priority¸¦ High·Î ¼³Á¤ÇÕ´Ï´Ù.
    5. È®ÀÎÀ» Ŭ¸¯ÇÏ¿© º¸±Þ ¾Ë¸²À» ¸¸µì´Ï´Ù.

±×·ì Á¤Ã¥ ±â¹Ý ÄÄÇ»ÅÍ ½ÃÀÛ ½ºÅ©¸³Æ® »ç¿ë ¹æ¹ý

ÀÌ ¹æ¹ýÀ» »ç¿ëÇÏ·Á¸é ½ºÅ©¸³Æ®¸¦ ¼³Á¤ÇÏ°í ±×·ì Á¤Ã¥ ¼³Á¤À» Àû¿ëÇÑ ÈÄ¿¡ Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
  1. °øÀ¯¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é Ãʱ⠼³Á¤ ¹× ±¸¼º ÀýÀÇ ´Ü°è¸¦ ¼öÇàÇϽʽÿÀ.
  2. ½ÃÀÛ ½ºÅ©¸³Æ®¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»ÅÍ MMC ½º³ÀÀο¡¼­ µµ¸ÞÀÎ À̸§À» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼Ó¼ºÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    2. ±×·ì Á¤Ã¥ ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÏ¿© GPO(±×·ì Á¤Ã¥ °³Ã¼)¸¦ »õ·Î ¸¸µé°í Á¤Ã¥¿¡ MRT Deployment¶ó´Â À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
    4. »õ Á¤Ã¥À» Ŭ¸¯ÇÑ ´ÙÀ½ ÆíÁýÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    5. ÄÄÇ»ÅÍ ±¸¼º¿¡ Windows ¼³Á¤À» Â÷·Ê·Î È®ÀåÇÑ ´ÙÀ½ ½ºÅ©¸³Æ®¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    6. ·Î±×¿ÂÀ» µÎ ¹ø Ŭ¸¯ÇÑ ´ÙÀ½ Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.

      ½ºÅ©¸³Æ® Ãß°¡ ´ëÈ­ »óÀÚ°¡ ³ªÅ¸³³´Ï´Ù.
    7. ½ºÅ©¸³Æ® À̸§ »óÀÚ¿¡ \\ServerName\ShareName\RunMRT.cmd¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    8. È®ÀÎÀ» Ŭ¸¯ÇÑ ´ÙÀ½ Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  3. ÀÌ µµ¸ÞÀÎÀÇ ±¸¼º¿ø¿¡ ÇØ´çÇϴ Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.

±×·ì Á¤Ã¥ ±â¹Ý »ç¿ëÀÚ ·Î±×¿Â ½ºÅ©¸³Æ® »ç¿ë ¹æ¹ý

ÀÌ ¹æ¹ýÀ» »ç¿ëÇÏ·Á¸é ·Î±×¿Â »ç¿ëÀÚ °èÁ¤ÀÌ µµ¸ÞÀÎ °èÁ¤À̰í ÇØ´ç Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅÍ¿¡¼­ ·ÎÄà °ü¸®ÀÚ ±×·ìÀÇ ±¸¼º¿øÀ̾î¾ß ÇÕ´Ï´Ù.
  1. °øÀ¯¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é Ãʱ⠼³Á¤ ¹× ±¸¼º ÀýÀÇ ´Ü°è¸¦ ¼öÇàÇϽʽÿÀ.
  2. ·Î±×¿Â ½ºÅ©¸³Æ®¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»ÅÍ MMC ½º³ÀÀο¡¼­ µµ¸ÞÀÎ À̸§À» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼Ó¼ºÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    2. ±×·ì Á¤Ã¥ ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÏ¿© GPO¸¦ »õ·Î ¸¸µé°í Á¤Ã¥¿¡ MRT Deployment¶ó´Â À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
    4. »õ Á¤Ã¥À» Ŭ¸¯ÇÑ ´ÙÀ½ ÆíÁýÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    5. »ç¿ëÀÚ ±¸¼ºÀÇ Windows ¼³Á¤À» Â÷·Ê·Î È®ÀåÇÑ ´ÙÀ½ ½ºÅ©¸³Æ®¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    6. ·Î±×¿ÂÀ» µÎ ¹ø Ŭ¸¯ÇÑ ´ÙÀ½ Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù. ½ºÅ©¸³Æ® Ãß°¡ ´ëÈ­ »óÀÚ°¡ ³ªÅ¸³³´Ï´Ù.
    7. ½ºÅ©¸³Æ® À̸§ »óÀÚ¿¡ \\ServerName\ShareName\RunMRT.cmd¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    8. È®ÀÎÀ» Ŭ¸¯ÇÑ ´ÙÀ½ Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  3. ·Î±×¿ÀÇÁÇÑ ´ÙÀ½ Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅÍ¿¡ ·Î±×¿ÂÇÕ´Ï´Ù.
ÀÌ ½Ã³ª¸®¿À¿¡¼­´Â ½ºÅ©¸³Æ®¿Í µµ±¸°¡ ·Î±×¿ÂÇÑ »ç¿ëÀÚÀÇ ÄÁÅØ½ºÆ®¿¡¼­ ½ÇÇàµË´Ï´Ù. ÀÌ »ç¿ëÀÚ°¡ ·ÎÄà °ü¸®ÀÚ ±×·ì¿¡ ¼ÓÇØ ÀÖÁö ¾Ê°Å³ª ÀÌ »ç¿ëÀÚ¿¡°Ô ÃæºÐÇÑ »ç¿ë ±ÇÇÑÀÌ ¾øÀ¸¸é µµ±¸°¡ ½ÇÇàµÇÁö ¾Ê°í ÀûÀýÇÑ ¹Ýȯ Äڵ带 ¹ÝȯÇÏÁö ¾Ê½À´Ï´Ù. ½ÃÀÛ ½ºÅ©¸³Æ®¿Í ·Î±×¿Â ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
198642 Windows 2000ÀÇ ·Î±×¿Â, ·Î±×¿ÀÇÁ, ½ÃÀÛ ¹× Á¾·á ½ºÅ©¸³Æ®¿¡ ´ëÇÑ °³¿ä
322241 Windows 2000¿¡¼­ ½ºÅ©¸³Æ®¸¦ ÇÒ´çÇÏ´Â ¹æ¹ý

¿£ÅÍÇÁ¶óÀÌÁî ¹èÆ÷ °ü·Ã Ãß°¡ Á¤º¸

¹Ýȯ ÄÚµå °Ë»ç ¹æ¹ý

¹èÆ÷ ·Î±×¿Â ½ºÅ©¸³Æ® ¶Ç´Â ¹èÆ÷ ½ÃÀÛ ½ºÅ©¸³Æ®¿¡ ÀÖ´Â µµ±¸ÀÇ ¹Ýȯ Äڵ带 °Ë»çÇÏ¿© ½ÇÇà °á°ú¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ÀÛ¾÷À» ¼öÇàÇÏ´Â ¹æ¹ýÀÇ ¿¹Á¦¿¡ ´ëÇØ¼­´Â ÄÚµå ¿¹Á¦ ÀýÀ» ÂüÁ¶ÇϽʽÿÀ.

´ÙÀ½ ¸ñ·Ï¿¡´Â ¿Ã¹Ù¸¥ ¹Ýȯ Äڵ尡 ³ª¿Í ÀÖ½À´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
0=°¨¿°µÇÁö ¾ÊÀ½
1=OS ȯ°æ ¿À·ù
2=Administrator·Î ½ÇÇàÇÏÁö ¾ÊÀ½
3=Áö¿øµÇÁö ¾Ê´Â OS
4=½ºÄ³³Ê ÃʱâÈ­ ¿À·ù. µµ±¸ÀÇ »õ º¹»çº»À» ´Ù¿î·ÎµåÇϽʽÿÀ.
5=»ç¿ëµÇÁö ¾ÊÀ½
6=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾ú½À´Ï´Ù. ¿À·ù´Â ¾ø½À´Ï´Ù.
7=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾úÁö¸¸ ¿À·ù°¡ ¹ß»ýÇß½À´Ï´Ù.
8=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ Á¦°Å¸¦ ¿Ï·áÇϱâ À§ÇØ ¼öµ¿ ´Ü°è¸¦ ¼öÇàÇØ¾ß ÇÕ´Ï´Ù.
9=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ Á¦°Å¸¦ ¿Ï·áÇϱâ À§ÇØ ¼öµ¿ ´Ü°è¸¦ ¼öÇàÇØ¾ß ÇÏ°í ¿À·ù°¡ ¹ß»ýÇß½À´Ï´Ù.
10=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ Á¦°Å¸¦ ¿Ï·áÇϱâ À§ÇØ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
11=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ Á¦°Å¸¦ ¿Ï·áÇϱâ À§ÇØ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÏ°í ¿À·ù°¡ ¹ß»ýÇß½À´Ï´Ù.
12=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ Á¦°Å¸¦ ¿Ï·áÇϱâ À§ÇØ ¼öµ¿ ´Ü°è¸¦ ¼öÇàÇØ¾ß ÇÏ°í ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
13=Çϳª ÀÌ»óÀÇ °¨¿°ÀÌ °Ë»öµÇ¾î Á¦°ÅµÇ¾úÁö¸¸ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ¿À·ù´Â ¹ß»ýÇÏÁö ¾Ê¾Ò½À´Ï´Ù.

·Î±× ÆÄÀÏ ±¸¹® ºÐ¼® ¹æ¹ý

¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸´Â ½ÇÇà °á°ú¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸¸¦ %windir%\debug\mrt.log ·Î±× ÆÄÀÏ¿¡ ±â·ÏÇÕ´Ï´Ù.

Âü°í
  • ÀÌ ·Î±× ÆÄÀÏÀº ¿µ¾î·Î¸¸ Á¦°øµË´Ï´Ù.
  • Á¦°Å µµ±¸ ¹öÀü 1.2(2005³â 3¿ù)ºÎÅÍ ÀÌ ·Î±×´Â À¯´ÏÄÚµå ÅØ½ºÆ®¸¦ »ç¿ëÇÕ´Ï´Ù. ¹öÀü 1.2 ÀÌÀü¿¡´Â ·Î±× ÆÄÀÏ¿¡¼­ ANSI ÅØ½ºÆ®¸¦ »ç¿ëÇß½À´Ï´Ù.
  • ·Î±× ÆÄÀÏ Çü½ÄÀÌ ¹öÀü 1.2·Î º¯°æµÇ¾úÀ¸¹Ç·Î ÃֽйöÀüÀÇ µµ±¸¸¦ ´Ù¿î·ÎµåÇÏ¿© »ç¿ëÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

    ÀÌ ·Î±× ÆÄÀÏÀÌ ÀÌ¹Ì ÀÖÀ» °æ¿ì ÀÌ ÆÄÀÏ¿¡ Á¤º¸°¡ Ãß°¡µË´Ï´Ù.
  • ¾ÕÀÇ ¿¹Á¦¿Í À¯»çÇÑ ¸í·É ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¸é ¹Ýȯ Äڵ带 ĸóÇÏ°í ³×Æ®¿öÅ© °øÀ¯·Î ÆÄÀÏÀ» ¼öÁýÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • ANSI¿¡¼­ À¯´ÏÄÚµå·Î ÀüȯµÇ¾ú±â ¶§¹®¿¡ Á¦°Å µµ±¸ ¹öÀü 1.2´Â %windir%\debug¿¡ ÀÖ´Â Mrt.log ÆÄÀÏÀÇ ANSI ¹öÀüÀ» °°Àº µð·ºÅ͸®ÀÇ Mrt.log.old·Î º¹»çÇÏ°í µ¿ÀÏÇÑ µð·ºÅ͸®¿¡ Mrt.log ÆÄÀÏÀÇ »õ À¯´ÏÄÚµå ¹öÀüÀ» ¸¸µì´Ï´Ù. ANSI ¹öÀüó·³ ÀÌ ·Î±× ÆÄÀϵµ ¸Å´Þ Á¦°øµÇ´Â ¸±¸®½º¿¡ Ãß°¡µË´Ï´Ù.
¾Æ·¡ÀÇ ¿¹Á¦´Â Sasser.A ¿ú¿¡ °¨¿°µÇ¾ú´ø ÄÄÇ»ÅÍÀÇ Mrt.log ÆÄÀÏÀÔ´Ï´Ù.
Microsoft Windows Malicious Software Removal Tool v1.28, April 2007 Started On Mon Mar 19 13:15:07 2007
 
Quick Scan Results: ---------------- Found virus: Win32/Sasser.A.worm in file://C:\WINDOWS\avserve.exe Found virus: Win32/Sasser.A.worm in regkey://HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\avserve.exe Found virus: Win32/Sasser.A.worm in runkey://HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\avserve.exe Found virus: Win32/Sasser.A.worm in file://C:\WINDOWS\avserve.exe
 
Quick Scan Removal Results ---------------- Start 'remove' for regkey://HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\avserve.exe Operation succeeded !
 
Start 'remove' for runkey://HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\avserve.exe Operation succeeded !
 
Start 'remove' for file://\\?\C:\WINDOWS\avserve.exe Operation succeeded !
 
Results Summary: ---------------- Found Win32/Sasser.A.worm and Removed!
 
Return code: 6 Microsoft Windows Malicious Software Removal Tool Finished On Mon Mar 19 13:15:57 2007

´ÙÀ½Àº ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î°¡ ¹ß°ßµÇÁö ¾ÊÀº ¿¹Á¦ ·Î±× ÆÄÀÏÀÔ´Ï´Ù.
Microsoft Windows Malicious Software Removal Tool v1.2, March 2005 Started On Wed May 01 21:19:01 2002
 
Results Summary: ---------------- No infection found.
 
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished On Wed May 01 21:19:05 2002

´ÙÀ½Àº ¿À·ù°¡ ¹ß°ßµÈ ¿¹Á¦ ·Î±× ÆÄÀÏÀÔ´Ï´Ù.

µµ±¸·Î ÀÎÇØ ³ªÅ¸³ª´Â °æ°í ¹× ¿À·ù¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
891717 Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸¸¦ ½ÇÇàÇÒ ¶§ ¹ß»ýÇÏ´Â ¿À·ù¸¦ ÇØ°áÇÏ´Â ¹æ¹ý
Microsoft Windows Malicious Software Removal Tool v1.2, March 2005 Started On Wed May 01 21:27:57 2002
 
Scanning Results: ---------------- Found virus: Win32/HLLW.Gaobot.ZF in process 1880 Found virus: Win32/HLLW.Gaobot.ZF in process 1880 Found virus: Win32/HLLW.Gaobot.ZF in file C:\WINDOWS\System32\winsec16.exe Found virus: Win32/HLLW.Gaobot.ZF in process 1880 Found virus: Win32/HLLW.Gaobot.ZF in process 1880 Found virus: Win32/HLLW.Gaobot.ZF in file C:\WINDOWS\System32\winsec16.exe Found virus: Win32/HLLW.Gaobot.ZF in file C:\WINDOWS\System32\winsec16.exe
 
Removal Results: ---------------- Terminating process with pid 1880 ->Sysclean ERROR: Failed to kill process with PID: 1880 (Win32 Error Code: 0x00000102 (258):The wait operation timed out.) [697] Operation failed !
 
Terminating process with pid 1880 Operation had previously completed.
 
Terminating process with pid 1880 Operation had previously completed.
 
Deleting registry value HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, entry: WinSec Operation succeeded !
 
Terminating process with pid 1880 Operation had previously completed.
 
Deleting registry value HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, entry: WinSec Operation succeeded !
 
Writing in file C:\WINDOWS\system32\drivers\etc\hosts Operation succeeded !
 
Deleting file C:\WINDOWS\System32\winsec16.exe Operation succeeded !
 
Deleting file C:\WINDOWS\System32\winsec16.exe Operation had previously completed.
 
Deleting file C:\WINDOWS\System32\winsec16.exe Operation had previously completed.
 

Results Summary: ---------------- For cleaning Win32/HLLW.Gaobot.ZF, the system must be restarted. Found Win32/HLLW.Gaobot.ZF, partially removed.

¾Ë·ÁÁø ¹®Á¦

¾Ë·ÁÁø ¹®Á¦ 1

½ÃÀÛ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¿© µµ±¸¸¦ ½ÇÇàÇÒ °æ¿ì Mrt.log ÆÄÀÏ¿¡ ´ÙÀ½°ú À¯»çÇÑ ¿À·ù ¸Þ½ÃÁö°¡ ³ªÅ¸³¯ ¼ö ÀÖ½À´Ï´Ù.
¿À·ù: MemScanGetImagePathFromPid(pid: 552)°¡ ½ÇÆÐÇß½À´Ï´Ù.
0x00000005: ¾×¼¼½º°¡ °ÅºÎµÇ¾ú½À´Ï´Ù.
Âü°í PID ¹øÈ£´Â ÀÌ¿Í ´Ù¸¦ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ ¿À·ù ¸Þ½ÃÁö´Â ÇÁ·Î¼¼½º°¡ ¹æ±Ý ½ÃÀ۵Ǿú°Å³ª ÃÖ±Ù¿¡ ÁßÁöµÈ °æ¿ì¿¡ ³ªÅ¸³³´Ï´Ù. ³ªÅ¸³ª´Â °á°ú´Â ÇØ´ç PID·Î ÁöÁ¤µÈ ÇÁ·Î¼¼½º°¡ °Ë»öµÇÁö ¾Ê´Â´Ù´Â °Í»ÓÀÔ´Ï´Ù.

¾Ë·ÁÁø ¹®Á¦ 2

µå¹® °æ¿ìÁö¸¸ °ü¸®ÀÚ°¡ quiet ½ºÀ§Ä¡ /q¸¦ »ç¿ëÇÏ¿© MSRT¸¦ ¹èÆ÷Çϵµ·Ï ¼±ÅÃÇϸé(¹«ÀÎ ¸ðµå·Îµµ ¾Ë·ÁÁ® ÀÖÀ½) ºÎºÐÀûÀÎ °¨¿°ÀÌ ¿ÏÀüÈ÷ ÇØ°áµÇÁö ¸øÇÏ¿© ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛ ÀÌÈÄ¿¡ Ãß°¡ Á¤¸®°¡ ÇÊ¿äÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ »óȲÀº ƯÁ¤ ·çƮŶ º¯ÇüÀ» Á¦°ÅÇÒ ¶§¸¸ È®ÀεǾú½À´Ï´Ù.

FAQ

Q1. µµ±¸ ¹èÆ÷¿ë ½ÃÀÛ ¶Ç´Â ·Î±×¿Â ½ºÅ©¸³Æ®¸¦ Å×½ºÆ®ÇÒ ¶§ ¼³Á¤ÇÑ ³×Æ®¿öÅ© °øÀ¯¿¡ ·Î±× ÆÄÀÏÀÌ º¹»çµÇÁö ¾Ê½À´Ï´Ù. ±× ÀÌÀ¯´Â ¹«¾ùÀԴϱî?

´ë´ä 1. ÀÌ ¹®Á¦´Â ÈçÈ÷ »ç¿ë ±ÇÇÑ ¹®Á¦ ¶§¹®¿¡ ¹ß»ýÇÕ´Ï´Ù. ¿¹¸¦ µé¾î, Á¦°Å µµ±¸°¡ ½ÇÇàµÇ´Â °èÁ¤¿¡ °øÀ¯¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀÌ ¾øÀ» ¼ö ÀÖ½À´Ï´Ù. À̸¦ ÇØ°áÇÏ·Á¸é ¸ÕÀú ·¹Áö½ºÆ®¸® ۸¦ °Ë»çÇÏ¿© µµ±¸°¡ ½ÇÇàµÇ¾ú´ÂÁö È®ÀÎÇϰųª Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅÍ¿¡ ·Î±× ÆÄÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. µµ±¸°¡ ¼º°øÀûÀ¸·Î ½ÇÇàµÇ¾úÀ¸¸é °£´ÜÇÑ ½ºÅ©¸³Æ®¸¦ Å×½ºÆ®ÇÏ¿© Á¦°Å µµ±¸¿Í µ¿ÀÏÇÑ º¸¾È ÄÁÅØ½ºÆ®¿¡¼­ ½ÇÇàÇÒ °æ¿ì ³×Æ®¿öÅ© °øÀ¯¿¡ ¾µ ¼ö ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

Áú¹® 2: Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅÍ¿¡¼­ Á¦°Å µµ±¸°¡ ½ÇÇàµÇ¾ú´ÂÁö È®ÀÎÇÏ´Â ¹æ¹ýÀº ¹«¾ùÀԴϱî?

´ë´ä 2. ´ÙÀ½ ·¹Áö½ºÆ®¸® Ç׸ñÀÇ °ª µ¥ÀÌÅ͸¦ °Ë»çÇÏ¸é µµ±¸ ½ÇÇàÀ» È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ½ÃÀÛ ½ºÅ©¸³Æ®³ª ·Î±×¿Â ½ºÅ©¸³Æ®ÀÇ ÀϺηΠÀÌ·¯ÇÑ È®ÀÎ ÀÛ¾÷À» ±¸ÇöÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ ÇÁ·Î¼¼½º°¡ ÁøÇàµÇ¸é µµ±¸¸¦ ¿©·¯ ¹ø ½ÇÇàÇÏÁö ¾Ê¾Æµµ µË´Ï´Ù.
ÇÏÀ§ Ű:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemovalTools\MRT

Ç׸ñ À̸§: ¹öÀü
µµ±¸¸¦ ½ÇÇàÇÒ ¶§¸¶´Ù µµ±¸´Â ·¹Áö½ºÆ®¸®¿¡ µµ±¸°¡ ½ÇÇàµÇ¾úÀ½À» ³ªÅ¸³»´Â GUID¸¦ ±â·ÏÇÕ´Ï´Ù. ÀÌ GUID´Â ½ÇÇà °á°ú¿¡ °ü°è¾øÀÌ ±â·ÏµË´Ï´Ù. ´ÙÀ½ Ç¥¿¡´Â °¢ ¸±¸®½º¿¡ ÇØ´çÇÏ´Â GUID°¡ ³ª¿Í ÀÖ½À´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
¸±¸®½º°ª µ¥ÀÌÅÍ
2005³â 1¿ùE5DD9936-C147-4CD1-86D3-FED80FAADA6C
2005³â 2¿ù 805647C6-E5ED-4F07-9E21-327592D40E83
2005³â 3¿ùF8327EEF-52AA-439A-9950-CE33CF0D4FDD
2005³â 4¿ùD89EBFD1-262C-4990-9927-5185FED1F261
2005³â 5¿ù08112F4F-11BF-4129-A90A-9C8DD0104005
2005³â 6¿ù63C08887-00BE-4C9B-9EFC-4B9407EF0C4C
2005³â 7¿ù2EEAB848-93EB-46AE-A3BF-9F1A55F54833
2005³â 8¿ù3752278B-57D3-4D44-8F30-A98F957EC3C8
2005³â 8¿ù A4066DA74-2DDE-4752-8186-101A7C543C5F
2005³â 9¿ù33B662A4-4514-4581-8DD7-544021441C89
2005³â 10¿ù08FFB7EB-5453-4563-A016-7DBC4FED4935
2005³â 11¿ù1F5BA617-240A-42FF-BE3B-14B88D004E43
2005³â 12¿ùF8FEC144-AA00-48B8-9910-C2AE9CCE014A
2006³â 1¿ù250985ee-62e6-4560-b141-997fc6377fe2
2006³â 2¿ù99cb494b-98bf-4814-bff0-cf551ac8e205
2006³â 3¿ùb5784f56-32ca-4756-a521-ca57816391ca
2006³â 4¿ùd0f3ea76-76c8-4287-8cdf-bdfee5e446ec
2006³â 5¿ùce818d5b-8a25-47c0-a9cd-7169da3f9b99
2006³â 6¿ù7cf4b321-c0dd-42d9-afdf-edbb85e59767
2006³â 7¿ù5df61377-4916-440f-b23f-321933b0afd3
2006³â 8¿ù37949d24-63f1-4fdc-ad24-5dc3eb3ad265
2006³â 9¿ùac3fa517-20f0-4a42-95ca-6383f04773c8
2006³â 10¿ù79e385d0-5d28-4743-aeb3-ed101c828abd
2006³â 11¿ù1d21fa19-c296-4020-a7c2-c5a9ba4f2356
2006³â 12¿ù621498ca-889b-48ef-872b-84b519365c76
2007³â 1¿ù2F9BC264-1980-42b6-9EE3-2BE36088BB57
2007³â 2¿ùFFCBCFA5-4EA1-4d66-A3DC-224C8006ACAE
2007³â 3¿ù5ABA0A63-8B4C-4197-A6AB-A1035539234D
2007³â 4¿ù57FA0F48-B94C-49ea-894B-10FDA39A7A64
2007³â 5¿ù15D8C246-6090-450f-8261-4BA8CA012D3C
2007³â 6¿ù234C3382-3B87-41ca-98D1-277C2F5161CC
2007³â 7¿ù4AD02E69-ACFE-475C-9106-8FB3D3695CF8
2007³â 8¿ù0CEFC17E-9325-4810-A979-159E53529F47
2007³â 9¿ùA72DDD48-8356-4D06-A8E0-8D9C24A20A9A
2007³â 10¿ù52168AD3-127E-416C-B7F6-068D1254C3A4
2007³â 11¿ùEFC91BC1-FD0D-42EE-AA86-62F59254147F
2007³â 12¿ù73D860EC-4829-44DD-A064-2E36FCC21D40
2008³â 1¿ù330FCFD4-F1AA-41D3-B2DC-127E699EEF7D
2008³â 2¿ù0E918EC4-EE5F-4118-866A-93f32EC73ED6
2008³â 3¿ù24A92A45-15B3-412D-9088-A3226987A476
2008³â 4¿ùF01687B5-E3A4-4EB6-B4F7-37D8F7E173FA
2008³â 5¿ù0A1A070A-25AA-4482-85DD-DF69FF53DF37
2008³â 6¿ù0D9785CC-AEEC-49F7-81A8-07B225E890F1
2008³â 7¿ùBC308029-4E38-4D89-85C0-8A04FC9AD976
2008³â 8¿ùF3889559-68D7-4AFB-835E-E7A82E4CE818
2008³â 9¿ù7974CF06-BE58-43D5-B635-974BD92029E2
2008³â 10¿ù131437DE-87D3-4801-96F0-A2CB7EB98572
2008³â 11¿ùF036AE17-CD74-4FA5-81FC-4FA4EC826837
2008³â 12¿ù9BF57AAA-6CE6-4FC4-AEC7-1B288F067467
2008³â 12¿ù9BF57AAA-6CE6-4FC4-AEC7-1B288F067467
2009³â 1¿ù2B730A83-F3A6-44F5-83FF-D9F51AF84EA0
2009³â 2¿ùC5E3D402-61D9-4DDF-A8F5-0685FA165CE8
2009³â 3¿ùBDEB63D0-4CEC-4D5B-A360-FB1985418E61
2009³â 4¿ù276F1693-D132-44EF-911B-3327198F838B
2009³â 5¿ùAC36AF73-B1E8-4CC1-9FF3-5A52ABB90F96
2009³â 6¿ù8BD71447-AAE4-4B46-B652-484001424290
2009³â 7¿ùF530D09B-F688-43D1-A3D5-49DC1A8C9AF0
2009³â 8¿ù91590177-69E5-4651-854D-9C95935867CE
2009³â 9¿ùB279661B-5861-4315-ABE9-92A3E26C1FF4
2009³â 10¿ù4C64200A-6786-490B-9A0C-DEF64AA03934
2009³â 11¿ù78070A38-A2A9-44CE-BAB1-304D4BA06F49
2009³â 12¿ùA9A7C96D-908E-413C-A540-C43C47941BE4
2010³â 1¿ùED3205FC-FC48-4A39-9FBD-B0035979DDFF
2010³â 2¿ù76D836AA-5D94-4374-BCBF-17F825177898
2010³â 3¿ù076DF31D-E151-4CC3-8E0A-7A21E35CF679
2010³â 4¿ùD4232D7D-0DB6-4E8B-AD19-456E8D286D67
2010³â 5¿ù18C7629E-5F96-4BA8-A2C8-31810A54F5B8
2010³â 6¿ù308738D5-18B0-4CB8-95FD-CDD9A5F49B62
2010³â 7¿ùA1A3C5AF-108A-45FD-ABEC-5B75DF31736D
2010³â 8¿ùE39537F7-D4B8-4042-930C-191A2EF18C73
2010³â 9¿ù 0916C369-02A8-4C3D-9AD0-E72AF7C46025
2010³â 10¿ù32F1A453-65D6-41F0-A36F-D9837A868534
2010³â 11¿ù5800D663-13EA-457C-8CFD-632149D0AEDD
2010³â 12¿ù4E28B496-DD95-4300-82A6-53809E0F9CDA
2011³â 1¿ù258FD3CF-9C82-4112-B1B0-18EC1ECFED37
2011³â 2¿ùB3458687-D7E4-4068-8A57-3028D15A7408
2011³â 3¿ùAF70C509-22C8-4369-AEC6-81AEB02A59B7
2011³â 4¿ù0CB525D5-8593-436C-9EB0-68C6D549994D
2011³â 5¿ù852F70C7-9C9E-4093-9184-D89D5CE069F0
2011³â 6¿ùDDE7C7DD-E76A-4672-A166-159DA2110CE5
2011³â 7¿ù3C009D0B-2C32-4635-9B34-FFA7F4CB42E7
2011³â 8¿ùF14DDEA8-3541-40C6-AAC7-5A0024C928A8
2011³â 9¿ùE775644E-B0FF-44FA-9F8B-F731E231B507
2011³â 10¿ùC0177BCC-8925-431B-AC98-9AC87B8E9699
2011³â 11¿ùBEB9D90D-ED88-42D7-BD71-AE30E89BBDC9
2011³â 12¿ù79B9D6F6-2990-4C15-8914-7801AD90B4D7
2012³â 1¿ù634F47CA-D7D7-448E-A7BE-0371D029EB32
2012³â 2¿ù 23B13CB9-1784-4DD3-9504-7E58427307A7
2012³â 3¿ù 84C44DD1-20C8-4542-A1AF-C3BA2A191E25
2012³â 4¿ù 3C1A9787-5E87-45E3-9B0B-21A6AB25BF4A
2012³â 5¿ù D0082A21-13E4-49F7-A31D-7F752F059DE9
2012³â 6¿ù 4B83319E-E2A4-4CD0-9AAC-A0AB62CE3384
2012³â 7¿ù 3E9B6E28-8A74-4432-AD2A-46133BDED728
2012³â 8¿ù C1156343-36C9-44FB-BED9-75151586227B
2012³â 9¿ù 02A84536-D000-45FF-B71E-9203EFD2FE04
2012³â 10¿ù 8C1ACB58-FEE7-4FF0-972C-A09A058667F8
2012³â 11¿ù7D0B34BB-97EB-40CE-8513-4B11EB4C1BD6
2012³â 12¿ùAD64315C-1421-4A96-89F4-464124776078
2013³â 1¿ùA769BB72-28FC-43C7-BA14-2E44725FED20
2013³â 2¿ù?ED5E6E45-F92A-4096-BF7F-F84ECF59F0DB
2013³â 3¿ù147152D2-DFFC-4181-A837-11CB9211D091
2013³â 4¿ù7A6917B5-082B-48BA-9DFC-9B7034906FDC
2013³â 5¿ù3DAA6951-E853-47E4-B288-257DCDE1A45A
Áú¹® 3: º¸°í¼­°¡ Microsoft·Î Àü¼ÛµÇÁö ¾Êµµ·Ï µµ±¸ÀÇ °¨¿° º¸°í ±¸¼º ¿ä¼Ò¸¦ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤ÇÏ´Â ¹æ¹ýÀº ¹«¾ùÀԴϱî?

´ë´ä 3. °ü¸®ÀÚ´Â ÄÄÇ»ÅÍ¿¡ ´ÙÀ½ ·¹Áö½ºÆ®¸® Ű °ªÀ» Ãß°¡ÇÏ¿© µµ±¸ÀÇ °¨¿° º¸°í ±¸¼º ¿ä¼Ò¸¦ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ·¹Áö½ºÆ®¸® Ű °ªÀ» ¼³Á¤ÇÏ¸é µµ±¸°¡ Microsoft¿¡ °¨¿° Á¤º¸¸¦ º¸°íÇÏÁö ¾Ê½À´Ï´Ù.
ÇÏÀ§ Ű:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT

Ç׸ñ À̸§: \DontReportInfectionInformation
Á¾·ù: REG_DWORD
°ª µ¥ÀÌÅÍ: 1


Áú¹® 4: 2005³â 3¿ù ¸±¸®½º¿¡¼­ Mrt.log ÆÄÀÏÀÇ µ¥ÀÌÅͰ¡ ¾ø´Â °ÍÀ¸·Î ³ªÅ¸³³´Ï´Ù. ÀÌ µ¥ÀÌÅͰ¡ Á¦°ÅµÈ ÀÌÀ¯´Â ¹«¾ùÀ̸ç, ÀÌ µ¥ÀÌÅ͸¦ °Ë»öÇÏ´Â ¹æ¹ýÀÌ ÀÖ½À´Ï±î?

´ë´ä 4. 2005³â 3¿ù ¸±¸®½ººÎÅÍ Mrt.log ÆÄÀÏÀº À¯´ÏÄÚµå ÆÄÀÏ·Î ÀÛ¼ºµË´Ï´Ù. µµ±¸ÀÇ 2005³â 3¿ù ¹öÀüÀ» ½ÇÇàÇÒ °æ¿ì ȣȯ¼ºÀ» À§ÇØ ·Î±× ÆÄÀÏÀÇ ANSI ¹öÀüÀÌ ½Ã½ºÅÛ¿¡ ÀÖÀ¸¸é %WINDIR%\debug¿¡ ÀÖ´Â Mrt.log.old·Î ÀÌ ·Î±×ÀÇ ³»¿ëÀÌ º¹»çµÇ°í Mrt.logÀÇ À¯´ÏÄÚµå ¹öÀüÀÌ »õ·Î ¸¸µé¾îÁý´Ï´Ù. ANSI ¹öÀü°ú ¸¶Âù°¡Áö·Î ÀÌ À¯´ÏÄÚµå ¹öÀüµµ µµ±¸¸¦ ½ÇÇàÇÒ ¶§¸¶´Ù Ãß°¡µË´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 891716 - ¸¶Áö¸· °ËÅä: 2013³â 5¿ù 14ÀÏ È­¿äÀÏ - ¼öÁ¤: 106.0
Ű¿öµå:?
kbinfo KB891716

Çǵå¹é º¸³»±â