Win32/Conficker ¿ú¿¡ ´ëÇÑ ¹ÙÀÌ·¯½º °æ°í

±â¼ú ÀÚ·á: 962007 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
Windows Vista SP1(¼­ºñ½º ÆÑ 1)ÀÇ Áö¿øÀÌ 2011³â 7¿ù 12ÀÏ ÀÚ·Î Á¾·áµË´Ï´Ù. Windows¿ë º¸¾È ¾÷µ¥ÀÌÆ®¸¦ °è¼Ó ¹ÞÀ¸·Á¸é Windows Vista SP2(¼­ºñ½º ÆÑ2)¸¦ ½ÇÇàÇϰí ÀÖ¾î¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ. ÀϺΠWindows ¹öÀü¿¡ ´ëÇÑ Áö¿øÀÌ Á¾·áµÉ ¿¹Á¤ÀÔ´Ï´Ù.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¿ä¾à

ÀÌ ±â¼ú ÀÚ·á ¹®¼­ÀÇ Á¤º¸´Â ÀÌ ¹®¼­ÀÇ ¼¼ºÎ Á¤º¸¸¦ ±¸ÇöÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ÀÖ´Â ºñÁî´Ï½º ȯ°æÀ» ´ë»óÀ¸·Î ÇÕ´Ï´Ù. ¹ÙÀÌ·¯½º ¹é½Å ÇÁ·Î±×·¥À¸·Î ¹ÙÀÌ·¯½º¸¦ ¿Ã¹Ù¸£°Ô Ä¡·áÇϰí ÀÖ´Â °æ¿ì ¹× ½Ã½ºÅÛÀÌ ¿ÏÀüÈ÷ ¾÷µ¥ÀÌÆ®µÈ °æ¿ì¿¡´Â ÀÌ ¹®¼­¸¦ »ç¿ëÇÒ Çʿ䰡 ¾ø½À´Ï´Ù. ½Ã½ºÅÛ¿¡ Conficker ¹ÙÀÌ·¯½º°¡ ¾ø´ÂÁö È®ÀÎÇÏ·Á¸é ´ÙÀ½ À¥ ÆäÀÌÁö¿¡¼­ ºü¸¥ °Ë»ç¸¦ ¼öÇàÇÕ´Ï´Ù. http://www.microsoft.com/security/scanner/ko-kr/ Conficker ¹ÙÀÌ·¯½º¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fConficker

°¨¿° Çö»ó

ÄÄÇ»ÅͰ¡ ÀÌ ¿ú¿¡ °¨¿°µÈ °æ¿ì ¾î¶°ÇÑ Çö»óµµ ¹ß»ýÇÏÁö ¾Ê°Å³ª ´ÙÀ½ Çö»óÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • °èÁ¤ Àá±Ý Á¤Ã¥ÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù.
  • ÀÚµ¿ ¾÷µ¥ÀÌÆ®, BITS(Background Intelligent Transfer Service), Windows Defender ¹× ¿À·ù º¸°í ¼­ºñ½º°¡ »ç¿ëµÇÁö ¾Ê°Ô ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù.
  • µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯°¡ Ŭ¶óÀÌ¾ðÆ® ¿äû¿¡ ´À¸®°Ô ÀÀ´äÇÕ´Ï´Ù.
  • ³×Æ®¿öÅ©°¡ Á¤Ã¼µÇ¾î ÀÖ½À´Ï´Ù.
  • ´Ù¾çÇÑ º¸¾È °ü·Ã À¥ »çÀÌÆ®¿¡ ¾×¼¼½ºÇÒ ¼ö ¾ø½À´Ï´Ù.
  • ´Ù¾çÇÑ º¸¾È °ü·Ã µµ±¸°¡ ½ÇÇàµÇÁö ¾Ê½À´Ï´Ù. ¾Ë·ÁÁø µµ±¸ ¸ñ·ÏÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ. ±×·± ´ÙÀ½ Win32/Conficker.D¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é Analysis ÅÇÀ» Ŭ¸¯ÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.
    http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.D
Win32/Conficker¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft Malware Protection Center À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker

ÀüÆÄ ¹æ¹ý

Win32/Conficker´Â ´ÙÀ½°ú °°Àº ¿©·¯ °¡Áö ¹æ¹ýÀ¸·Î ÀüÆÄµË´Ï´Ù.
  • º¸¾È ¾÷µ¥ÀÌÆ® 958644(MS08-067)¿¡ ÀÇÇØ ÆÐÄ¡µÇ´Â Ãë¾à¼º ÀÌ¿ë
  • ³×Æ®¿öÅ© °øÀ¯ »ç¿ë
  • ÀÚµ¿ Àç»ý ±â´É »ç¿ë
µû¶ó¼­ ³×Æ®¿öÅ©¸¦ Á¤¸®ÇÒ ¶§´Â ÀÌÀü¿¡ Á¤¸®ÇÑ ½Ã½ºÅÛ¿¡ À§Çù ¿ä¼Ò°¡ ´Ù½Ã ħÅõµÇÁö ¾Êµµ·Ï ÁÖÀÇÇØ¾ß ÇÕ´Ï´Ù.

Âü°í Win32/Conficker.D º¯Á¾Àº ³×Æ®¿öÅ©¸¦ ÅëÇØ À̵¿½Ä µå¶óÀÌºê ¶Ç´Â °øÀ¯ Æú´õ·Î È®»êµÇÁö ¾Ê½À´Ï´Ù. Win32/Conficker.D´Â Win32/ConfickerÀÇ ÀÌÀü º¯Á¾¿¡ ÀÇÇØ ¼³Ä¡µË´Ï´Ù.

¿¹¹æ Á¶Ä¡

  • ¸ðµç ÄÄÇ»ÅÍ¿¡ °íÀ¯ÇÏ°í °­·ÂÇÑ °ü¸®ÀÚ ¾ÏÈ£¸¦ »ç¿ëÇÕ´Ï´Ù.
  • µµ¸ÞÀÎ °ü¸®ÀÚ ÀÚ°Ý Áõ¸í ¶Ç´Â ¸ðµç ÄÄÇ»ÅÍ¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ÀÚ°Ý Áõ¸íÀ» »ç¿ëÇÏ¿© ÄÄÇ»ÅÍ¿¡ ·Î±×¿ÂÇÏÁö ¸¶½Ê½Ã¿À.
  • ¸ðµç ½Ã½ºÅÛ¿¡ ÃֽŠº¸¾È ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
  • ÀÚµ¿ ½ÇÇà ±â´ÉÀ» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº "±×·ì Á¤Ã¥ °³Ã¼ ¸¸µé±â" ¼½¼ÇÀÇ 3´Ü°è¸¦ ÂüÁ¶ÇϽʽÿÀ.
  • °øÀ¯ À§Ä¡¿¡ ´ëÇÑ °úµµÇÑ ±ÇÇÑÀ» Á¦°ÅÇÕ´Ï´Ù. ¿¹¸¦ µé¾î ¸ðµç °øÀ¯ ·çÆ®¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» Á¦°ÅÇÕ´Ï´Ù.

¿ÏÈ­ ´Ü°è

±×·ì Á¤Ã¥ ¼³Á¤À» »ç¿ëÇÏ¿© Win32/Conficker È®»ê ¹æÁö

Âü°í
  • Áß¿ä ÀÌ ¹®¼­¿¡ Á¦¾ÈµÈ ´ë·Î º¯°æÇϱâ Àü¿¡ ÇöÀç ¼³Á¤À» ¹®¼­È­ÇØ¾ß ÇÕ´Ï´Ù.
  • ´ÙÀ½ ÀýÂ÷¸¦ ¼öÇàÇØµµ ½Ã½ºÅÛ¿¡¼­ Conficker ¸È¿þ¾î°¡ Á¦°ÅµÇÁö´Â ¾ÊÀ¸¸ç ¸È¿þ¾îÀÇ È®»êÀ» ¹æÁöÇÒ »ÓÀÔ´Ï´Ù. ½Ã½ºÅÛ¿¡¼­ Conficker ¸È¿þ¾î¸¦ Á¦°ÅÇÏ·Á¸é ¹ÙÀÌ·¯½º ¹é½Å Á¦Ç°À» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. ¶Ç´Â ÀÌ ±â¼ú ÀÚ·á ¹®¼­ÀÇ "Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è" ¼½¼ÇÀÇ ´Ü°è¸¦ µû¶ó ½Ã½ºÅÛ¿¡¼­ ¸È¿þ¾î¸¦ ¼öµ¿À¸·Î Á¦°ÅÇϽʽÿÀ.
  • ´ÙÀ½ ´Ü°è¿¡¼­ ±ÇÀåµÇ´Â ´ë·Î »ç¿ë ±ÇÇÑÀ» º¯°æÇÏ´Â µ¿¾È ÀÀ¿ë ÇÁ·Î±×·¥, ¼­ºñ½º ÆÑ ¶Ç´Â ±âŸ ¾÷µ¥ÀÌÆ®¸¦ ¿Ã¹Ù¸£°Ô ¼³Ä¡ÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î Windows Update, Microsoft WSUS(Windows Server Update Services) ¼­¹ö ¹× System Center Configuration Manager(Configuration Manager 2007)Àº ÀÚµ¿ ¾÷µ¥ÀÌÆ®ÀÇ ±¸¼º ¿ä¼Ò¸¦ »ç¿ëÇϱ⠶§¹®¿¡ ÀÌ·¯ÇÑ Á¦Ç°À» »ç¿ëÇÏ¿© ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÒ ¼ö ¾øÀ¸¸ç À̿ܿ¡µµ ´Ù¸¥ ¼³Ä¡ ¹®Á¦°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. ½Ã½ºÅÛÀ» Á¤¸®ÇÑ ÈÄ »ç¿ë ±ÇÇÑÀ» ´Ù½Ã ±âº» ¼³Á¤À¸·Î º¯°æÇØ¾ß ÇÕ´Ï´Ù.
  • "±×·ì Á¤Ã¥ °³Ã¼ ¸¸µé±â" ¼½¼Ç¿¡ ¼³¸íµÈ Tasks Æú´õ ¹× SVCHOST ·¹Áö½ºÆ®¸® ŰÀÇ ±âº» »ç¿ë ±ÇÇÑ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ÀÌ ¹®¼­ ÈĹݺÎÀÇ ±âº» »ç¿ë ±ÇÇÑ Ç¥¸¦ ÂüÁ¶ÇϽʽÿÀ.

±×·ì Á¤Ã¥ °³Ã¼ ¸¸µé±â

ÀÛ¾÷ ȯ°æÀÇ ¿ä±¸¿¡ µû¶ó ƯÁ¤ OU(Á¶Á÷ ±¸¼º ´ÜÀ§), »çÀÌÆ® ¶Ç´Â µµ¸ÞÀÎÀÇ ¸ðµç ÄÄÇ»ÅÍ¿¡ Àû¿ëµÇ´Â »õ GPO(±×·ì Á¤Ã¥ °³Ã¼)¸¦ ¸¸µì´Ï´Ù.

ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ Ű¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» Á¦°ÅÇÏ´Â Á¤Ã¥À» ¼³Á¤ÇÕ´Ï´Ù.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
    ÀÌ·¸°Ô Çϸé ÀÓÀÇ·Î ¸í¸íµÈ ¸È¿þ¾î ¼­ºñ½º°¡ netsvcs ·¹Áö½ºÆ®¸® °ª¿¡ »ý¼ºµÇ´Â °ÍÀ» ¸·À» ¼ö ÀÖ½À´Ï´Ù.

    ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. GPMC(±×·ì Á¤Ã¥ °ü¸® ÄܼÖ)¸¦ ¿±´Ï´Ù.
    2. »õ GPO¸¦ ¸¸µì´Ï´Ù. °³Ã¼¿¡ ¿øÇÏ´Â À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
    3. »õ GPO¸¦ ¿­°í ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
      ÄÄÇ»ÅÍ ±¸¼º\Windows ¼³Á¤\º¸¾È ¼³Á¤\·¹Áö½ºÆ®¸®
    4. ·¹Áö½ºÆ®¸®¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ Ű Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    5. ·¹Áö½ºÆ®¸® Ű ¼±Åà ´ëÈ­ »óÀÚ¿¡¼­ MachineÀ» È®ÀåÇÑ ÈÄ ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
      Software\Microsoft\Windows NT\CurrentVersion
    6. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    7. ¿­¸®´Â ´ëÈ­ »óÀÚ¿¡¼­ Administrators ¹× System µÑ ´Ù¿¡ ´ëÇØ ¸ðµç ±ÇÇÑ È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±Åà Ãë¼ÒÇÕ´Ï´Ù.
    8. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    9. °³Ã¼ Ãß°¡ ´ëÈ­ »óÀÚ¿¡¼­ ¸ðµç ÇÏÀ§ ŰÀÇ ±âÁ¸ »ç¿ë ±ÇÇÑÀ» »ó¼Ó °¡´ÉÇÑ »ç¿ë ±ÇÇÑÀ¸·Î ¹Ù²Ù±â¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    10. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  2. %windir%\Tasks Æú´õ¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» Á¦°ÅÇÏ´Â Á¤Ã¥À» ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô Çϸé Conficker ¸È¿þ¾î°¡ ½Ã½ºÅÛÀ» Àç°¨¿°½Ãų ¼ö ÀÖ´Â ¿¹¾àµÈ ÀÛ¾÷À» ¸¸µé ¼ö ¾ø½À´Ï´Ù.

    ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. ¾Õ¿¡¼­ ¸¸µç GPO¿¡¼­ ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
      ÄÄÇ»ÅÍ ±¸¼º\Windows ¼³Á¤\º¸¾È ¼³Á¤\ÆÄÀÏ ½Ã½ºÅÛ
    2. ÆÄÀÏ ½Ã½ºÅÛÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í ÆÄÀÏ Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    3. ÆÄÀÏÀ̳ª Æú´õ Ãß°¡ ´ëÈ­ »óÀÚ¿¡¼­ %windir%\Tasks Æú´õ¸¦ ã½À´Ï´Ù. Æú´õ ´ëÈ­ »óÀÚ¿¡¼­ Tasks Æú´õ°¡ ¼±ÅÃµÈ Ã¤·Î ³ª¿­µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
    4. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    5. ¿­·Á ÀÖ´Â ´ëÈ­ »óÀÚ¿¡¼­ °ü¸®ÀÚ¿Í ½Ã½ºÅÛ ¸ðµÎ¿¡ ´ëÇØ ¸ðµç ±ÇÇÑ, ¼öÁ¤ ¹× ¾²±â È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±ÅÃÀ» Ãë¼ÒÇÕ´Ï´Ù.
    6. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    7. °³Ã¼ Ãß°¡ ´ëÈ­ »óÀÚ¿¡¼­ ¸ðµç ÇÏÀ§ ŰÀÇ ±âÁ¸ »ç¿ë ±ÇÇÑÀ» »ó¼Ó °¡´ÉÇÑ »ç¿ë ±ÇÇÑÀ¸·Î ¹Ù²Ù±â¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    8. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  3. ÀÚµ¿ ½ÇÇà ±â´ÉÀÌ »ç¿ëµÇÁö ¾Êµµ·Ï ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô Çϸé Conficker ¸È¿þ¾î°¡ Windows¿¡ ±âº» Á¦°øµÈ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» »ç¿ëÇÏ¿© È®»êµÉ ¼ö ¾ø½À´Ï´Ù.

    Âü°í »ç¿ë ÁßÀÎ Windows ¹öÀü¿¡ µû¶ó ÀÚµ¿ ½ÇÇà ±â´ÉÀ» Á¦´ë·Î ºñȰ¼ºÈ­Çϱâ À§ÇØ ¼³Ä¡ÇØ¾ß ÇÏ´Â ¾÷µ¥ÀÌÆ®°¡ µû·Î ÀÖ½À´Ï´Ù.
    • Windows Vista ¶Ç´Â Windows Server 2008¿¡¼­ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈ­ÇÏ·Á¸é º¸¾È ¾÷µ¥ÀÌÆ® 950582¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù(º¸¾È °øÁö MS08-038¿¡ ¼³¸íµÊ).
    • Windows XP, Windows Server 2003 ¶Ç´Â Windows 2000¿¡¼­ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈ­ÇÏ·Á¸é º¸¾È ¾÷µ¥ÀÌÆ® 950582, ¾÷µ¥ÀÌÆ® 967715 ¶Ç´Â ¾÷µ¥ÀÌÆ® 953252¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù.
    ÀÚµ¿ ½ÇÇà ±â´ÉÀÌ »ç¿ëµÇÁö ¾Êµµ·Ï ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.
    1. ¾Õ¿¡¼­ ¸¸µç GPO¿¡¼­ ´ÙÀ½ Æú´õ Áß Çϳª·Î À̵¿ÇÕ´Ï´Ù.
      • Windows Server 2003 µµ¸ÞÀÎÀÇ °æ¿ì ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
        ÄÄÇ»ÅÍ ±¸¼º\°ü¸® ÅÛÇø´\½Ã½ºÅÛ
      • Windows 2008 µµ¸ÞÀÎÀÇ °æ¿ì ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
        ÄÄÇ»ÅÍ ±¸¼º\°ü¸® ÅÛÇø´\Windows ±¸¼º ¿ä¼Ò\ÀÚµ¿ ½ÇÇà Á¤Ã¥
    2. ÀÚµ¿ ½ÇÇà »ç¿ë ¾È ÇÔ Á¤Ã¥À» ¿±´Ï´Ù.
    3. ÀÚµ¿ ½ÇÇà »ç¿ë ¾È ÇÔ ´ëÈ­ »óÀÚ¿¡¼­ »ç¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    4. µå·Ó´Ù¿î ¸Þ´º¿¡¼­ ¸ðµç µå¶óÀ̺긦 Ŭ¸¯ÇÕ´Ï´Ù.
    5. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  4. ±×·ì Á¤Ã¥ °ü¸® ÄܼÖÀ» ´Ý½À´Ï´Ù.
  5. »õ·Î ¸¸µç GPO¸¦ Àû¿ëÇÏ·Á´Â À§Ä¡¿¡ ÇØ´ç GPO¸¦ ¿¬°áÇÕ´Ï´Ù.
  6. ±×·ì Á¤Ã¥ ¼³Á¤ÀÌ ¸ðµç ÄÄÇ»ÅÍ·Î ¾÷µ¥ÀÌÆ®µÉ ¶§±îÁö ÃæºÐÈ÷ ´ë±âÇÕ´Ï´Ù. ÀϹÝÀûÀ¸·Î ±×·ì Á¤Ã¥ º¹Á¦°¡ °¢ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯·Î º¹Á¦¸¦ ¼öÇàÇÏ´Â µ¥ 5ºÐ Á¤µµ °É¸®°í ½Ã½ºÅÛÀÇ ³ª¸ÓÁö ºÎºÐÀ¸·Î º¹Á¦¸¦ ¼öÇàÇÏ´Â µ¥ 90ºÐ Á¤µµ °É¸³´Ï´Ù. µû¶ó¼­ µÎ ½Ã°£ Á¤µµ¸é ÃæºÐÇÕ´Ï´Ù. ±×·¯³ª ÀÛ¾÷ ȯ°æ¿¡ µû¶ó ´õ ¸¹Àº ½Ã°£ÀÌ ¼Ò¿äµÉ ¼öµµ ÀÖ½À´Ï´Ù.
  7. ±×·ì Á¤Ã¥ ¼³Á¤À» ÀüÆÄÇÑ ÈÄ¿¡´Â ½Ã½ºÅÛ¿¡¼­ ¸È¿þ¾î¸¦ Á¦°ÅÇϽʽÿÀ.

    ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. ¸ðµç ÄÄÇ»ÅÍ¿¡¼­ Àüü ¹ÙÀÌ·¯½º ¹é½Å °Ë»öÀ» ½ÇÇàÇϽʽÿÀ.
    2. ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î°¡ Conficker¸¦ °Ë»öÇÏÁö ¸øÇϸé Microsoft Safety Scanner¸¦ »ç¿ëÇÏ¿© ¸È¿þ¾î¸¦ Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ. http://www.microsoft.com/security/scanner/ko-kr/Âü°í ¸È¿þ¾î·Î ÀÎÇÑ ¸ðµç ¿µÇâÀ» Á¦°ÅÇϱâ À§ÇØ ¸î °¡Áö ¼öµ¿ ´Ü°è¸¦ ¼öÇàÇØ¾ß ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­ÀÇ "Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è" ¼½¼Ç¿¡ ³ª¿­µÈ ´Ü°è¸¦ °ËÅäÇÏ¿© ¸È¿þ¾îÀÇ ¿µÇâÀ» ¸ðµÎ Á¦°ÅÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

º¹±¸

Microsoft Safety Scanner ½ÇÇà

Microsoft Malware Protection Center¿¡¼­´Â Microsoft Safety Scanner¸¦ ¾÷µ¥ÀÌÆ®Çß½À´Ï´Ù. ÀÌ µµ±¸´Â ÀÚÁÖ ¹ß»ýÇÏ´Â ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î¸¦ Á¦°ÅÇÏ´Â µ¥ À¯¿ëÇÑ µ¶¸³ ½ÇÇàÇü ÀÌÁø ÆÄÀÏ·Î, Win32/Conficker ¸È¿þ¾î Á¦Ç°±ºÀ» Á¦°ÅÇÏ´Â µ¥ µµ¿òÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.

Âü°í Microsoft Safety Scanner´Â ½Ç½Ã°£ ¹ÙÀÌ·¯½º ¹é½Å ÇÁ·Î±×·¥ÀÌ ¾Æ´Ï±â ¶§¹®¿¡ Àç°¨¿°À» ¹æÁöÇÏÁö ¾Ê½À´Ï´Ù.

Microsoft Safety Scanner´Â ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¿¡¼­ ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.
http://www.microsoft.com/security/scanner/ko-kr/

Âü°í µ¶¸³ ½ÇÇàÇü ½Ã½ºÅÛ ½ºÀ§ÆÛ µµ±¸·Îµµ ÀÌ °¨¿°À» Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ µµ±¸´Â Microsoft Desktop Optimization Pack 6.0ÀÇ ±¸¼º ¿ä¼Ò·Î »ç¿ëÇϰųª °í°´ Áö¿ø ¼­ºñ½º¸¦ ÅëÇØ Á¦°ø ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. Microsoft Desktop Optimization PackÀ» ±¸ÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/ko-kr/windows/enterprise/products-and-technologies/mdop/default.aspx
½Ã½ºÅÛ¿¡¼­ Microsoft Security Essentials ¶Ç´Â Microsoft Forefront Client Security°¡ ½ÇÇàµÇ°í ÀÖÀ¸¸é À§Çù ¿ä¼Ò°¡ ħÅõÇϱâ Àü¿¡ Â÷´ÜµË´Ï´Ù.

Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è

Âü°í
  • ÀÌ ¼öµ¿ ´Ü°è´Â ´õ ÀÌ»ó ÇÊ¿äÇÏÁö ¾ÊÀ¸¸ç, Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î°¡ ¾øÀ» °æ¿ì¿¡¸¸ »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
  • ÄÄÇ»ÅÍ¿¡ ħÅõÇÑ Win32/Conficker º¯Á¾¿¡ µû¶ó ÀÌ ¼½¼Ç¿¡ ÂüÁ¶µÈ ÀÌ °ª Áß ÀϺδ ¹ÙÀÌ·¯½º¿¡ ÀÇÇØ º¯°æµÇÁö ¾Ê¾ÒÀ» ¼ö ÀÖ½À´Ï´Ù.
´ÙÀ½ ¼¼ºÎ ´Ü°è¸¦ ¼öÇàÇÏ¿© ½Ã½ºÅÛ¿¡¼­ Conficker¸¦ ¼öµ¿À¸·Î Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.
  1. ·ÎÄà °èÁ¤À» »ç¿ëÇÏ¿© ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÕ´Ï´Ù.

    Áß¿ä °¡´ÉÇÑ °æ¿ì¿¡µµ µµ¸ÞÀÎ °èÁ¤À» »ç¿ëÇÏ¿© ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÏÁö ¸¶½Ê½Ã¿À. ƯÈ÷, µµ¸ÞÀÎ °ü¸®ÀÚ °èÁ¤À» »ç¿ëÇÏ¿© ·Î±×¿ÂÇÏ´Â °æ¿ì´Â ÇÇÇϽʽÿÀ. ¸È¿þ¾î´Â ·Î±×¿ÂµÈ »ç¿ëÀÚ ÀÚ°Ý Áõ¸íÀ» »ç¿ëÇÏ¿© ·Î±×¿ÂÇÑ »ç¿ëÀÚ¸¦ °¡ÀåÇÏ°í ³×Æ®¿öÅ© ¸®¼Ò½º¿¡ ¾×¼¼½ºÇϱ⠶§¹®ÀÔ´Ï´Ù. ÀÌ·¯ÇÑ µ¿ÀÛÀ¸·Î ÀÎÇØ ¸È¿þ¾î°¡ È®»êµÉ ¼ö ÀÖ½À´Ï´Ù.
  2. ¼­¹ö ¼­ºñ½º¸¦ ÁßÁöÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ½Ã½ºÅÛ¿¡¼­ °ü¸® °øÀ¯°¡ Á¦°ÅµÇ¹Ç·Î ¸È¿þ¾î°¡ °ü¸® °øÀ¯¸¦ ÅëÇØ È®»êµÉ ¼ö ¾ø°Ô µË´Ï´Ù.

    Âü°í ¼­¹ö ¼­ºñ½º´Â »ç¿ëÀÚ È¯°æ¿¡¼­ ¸È¿þ¾î¸¦ Á¤¸®ÇÏ´Â µ¿¾È¿¡¸¸ ÀϽÃÀûÀ¸·Î ºñȰ¼ºÈ­ÇØ¾ß ÇÕ´Ï´Ù. ¼­¹ö ¼­ºñ½º¸¦ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤ÇÏ¸é ³×Æ®¿öÅ© ¸®¼Ò½ºÀÇ °¡¿ë¼º¿¡ ¿µÇâÀ» ÁֹǷΠÇÁ·Î´ö¼Ç ¼­¹ö¿¡¼­´Â Áï½Ã ´Ù½Ã ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ȯ°æÀÌ Á¤¸®µÇ¸é ¼­¹ö ¼­ºñ½º¸¦ »ç¿ë °¡´ÉÇÏ°Ô ´Ù½Ã ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ¼­¹ö ¼­ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ¼­ºñ½º MMC(Microsoft Management Console)¸¦ »ç¿ëÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. »ç¿ë ÁßÀÎ ½Ã½ºÅÛ¿¡ µû¶ó ´ÙÀ½À» ¼öÇàÇϽʽÿÀ.
      • Windows Vista ¹× Windows Server 2008¿¡¼­ ½ÃÀÛÀ» Ŭ¸¯ÇÏ°í °Ë»ö ½ÃÀÛ »óÀÚ¿¡ services.msc¸¦ ÀÔ·ÂÇÑ ÈÄ ÇÁ·Î±×·¥ ¸ñ·Ï¿¡¼­ services.msc¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
      • Windows 2000, Windows XP ¹× Windows Server 2003ÀÇ °æ¿ì ½ÃÀÛ, ½ÇÇàÀ» Â÷·Ê·Î Ŭ¸¯ÇÑ ÈÄ services.msc¸¦ ÀÔ·ÂÇϰí È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    2. ¼­¹ö¸¦ µÎ ¹ø Ŭ¸¯ÇÕ´Ï´Ù.
    3. ÁßÁö¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
    4. ½ÃÀÛ À¯Çü »óÀÚ¿¡¼­ »ç¿ë ¾È ÇÔÀ» ¼±ÅÃÇÕ´Ï´Ù.
    5. Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  3. ¸ðµç AT »ý¼º ¿¹¾à ÀÛ¾÷À» Á¦°ÅÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡ AT /Delete /Yes¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  4. ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼­ºñ½º¸¦ ÁßÁöÇÕ´Ï´Ù.
    • Windows 2000, Windows XP ¹× Windows Server 2003¿¡¼­ ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼­ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ¼­ºñ½º MMC(Microsoft Management Console) ¶Ç´Â SC.exe À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÕ´Ï´Ù.
    • Windows Vista ¶Ç´Â Windows Server 2008¿¡¼­ ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼­ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ µû¸£½Ê½Ã¿À.

      Áß¿ä ÀÌ Àý, ¹æ¹ý ¶Ç´Â ÀÛ¾÷¿¡´Â ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ´Ü°è°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ±×·¯³ª ·¹Áö½ºÆ®¸®¸¦ À߸ø ¼öÁ¤ÇÏ¸é ½É°¢ÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ ¼öµµ ÀÖÀ¸¹Ç·Î ´ÙÀ½ ´Ü°è¸¦ ÁÖÀÇÇÏ¿© ¼öÇàÇØ¾ß ÇÕ´Ï´Ù. Ãß°¡ º¸È£ Á¶Ä¡·Î ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤Çϱâ Àü¿¡ ÇØ´ç ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ¹®Á¦°¡ ¹ß»ýÇÏ´Â °æ¿ì ·¹Áö½ºÆ®¸®¸¦ º¹¿øÇÒ ¼ö ÀÖ½À´Ï´Ù. ·¹Áö½ºÆ®¸® ¹é¾÷ ¹× º¹¿ø ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
      322756 Windows¿¡¼­ ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ ¹× º¹¿øÇÏ´Â ¹æ¹ý
      1. ½ÃÀÛÀ» Ŭ¸¯ÇÏ°í °Ë»ö ½ÃÀÛ »óÀÚ¿¡ regedit¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ ÇÁ·Î±×·¥ ¸ñ·Ï¿¡¼­ regedit.exe¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
      2. ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ¼­ Ŭ¸¯ÇÕ´Ï´Ù.
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
      3. ¼¼ºÎ Á¤º¸ â¿¡¼­ Start DWORD Ç׸ñÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼öÁ¤À» Ŭ¸¯ÇÕ´Ï´Ù.
      4. °ª µ¥ÀÌÅÍ »óÀÚ¿¡ 4À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
      5. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.

        Âü°í ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼­ºñ½º´Â »ç¿ëÀÚ È¯°æ¿¡¼­ ¸È¿þ¾î¸¦ Á¤¸®ÇÏ´Â µ¿¾È¿¡¸¸ ÀϽÃÀûÀ¸·Î ºñȰ¼ºÈ­ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ´Ü°è´Â ´Ù¾çÇÑ ±âº» ¿¹¾àµÈ ÀÛ¾÷¿¡ ¿µÇâÀ» ÁֹǷΠWindows Vista ¹× Windows Server 2008¿¡¼­´Â ƯÈ÷ ÀÌ ¼­ºñ½º¸¦ ºñȰ¼ºÈ­ÇØ¾ß ÇÕ´Ï´Ù. ȯ°æÀÌ Á¤¸®µÇ¸é ¼­¹ö ¼­ºñ½º¸¦ »ç¿ëÇϵµ·Ï ´Ù½Ã ¼³Á¤ÇÕ´Ï´Ù.
  5. º¸¾È ¾÷µ¥ÀÌÆ® 958644(MS08-067)¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ¼öµ¿À¸·Î ¼³Ä¡ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
    http://www.microsoft.com/korea/technet/security/bulletin/Ms08-067.mspx
    Âü°í ÀÌ »çÀÌÆ®´Â ¸È¿þ¾î °¨¿° ¶§¹®¿¡ Â÷´ÜµÉ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ½Ã³ª¸®¿À¿¡¼­´Â °¨¿°µÇÁö ¾ÊÀº ÄÄÇ»ÅÍ¿¡¼­ ¾÷µ¥ÀÌÆ®¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ¾÷µ¥ÀÌÆ® ÆÄÀÏÀ» °¨¿°µÈ ½Ã½ºÅÛÀ¸·Î Àü¼ÛÇØ¾ß ÇÕ´Ï´Ù. ±¸¿î CD´Â ¾²±â ºÒ°¡´ÉÇϹǷΠ¾÷µ¥ÀÌÆ®¸¦ CD·Î ±¸¿ï °ÍÀ» ±ÇÀåÇÕ´Ï´Ù. µû¶ó¼­ ÀÌ CD´Â °¨¿°µÉ ¼ö ¾ø½À´Ï´Ù. ±â·Ï °¡´É CD µå¶óÀ̺ê´Â »ç¿ëÇÒ ¼ö ¾øÀ¸¹Ç·Î À̵¿½Ä USB ¸Þ¸ð¸® µå¶óÀ̺갡 °¨¿°µÈ ½Ã½ºÅÛÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ º¹»çÇÏ´Â À¯ÀÏÇÑ ¹æ¹ýÀÏ ¼ö ÀÖ½À´Ï´Ù. À̵¿½Ä µå¶óÀ̺긦 »ç¿ëÇÒ °æ¿ì ¸È¿þ¾î°¡ Autorun.inf ÆÄÀÏÀÌ ÀÖ´Â µå¶óÀ̺꿡 °¨¿°µÉ ¼ö ÀÖ´Ù´Â »ç½ÇÀ» ¾Ë¾Æ¾ß ÇÕ´Ï´Ù. À̵¿½Ä µå¶óÀ̺꿡 ¾÷µ¥ÀÌÆ®¸¦ º¹»çÇÑ ÈÄ¿¡´Â µå¶óÀ̺긦 Àбâ Àü¿ë ¸ðµå·Î º¯°æÇÏ´Â ¿É¼ÇÀÌ ÀÖ´Â °æ¿ì ÀÌ ¿É¼ÇÀ» ½ÇÇàÇØ¾ß ÇÕ´Ï´Ù. Àбâ Àü¿ë ¸ðµå¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Â °æ¿ì ÀϹÝÀûÀ¸·Î ÀåÄ¡ÀÇ ½ÇÁ¦ ½ºÀ§Ä¡¸¦ »ç¿ëÇÏ¿© ¼³Á¤ÇÕ´Ï´Ù. ±×·± ÈÄ ¾÷µ¥ÀÌÆ® ÆÄÀÏÀ» °¨¿°µÈ ÄÄÇ»ÅÍ¿¡ º¹»çÇϰí À̵¿½Ä µå¶óÀ̺긦 È®ÀÎÇÏ¿© Autorun.inf ÆÄÀÏÀÌ µå¶óÀ̺꿡 ±â·ÏµÇ¾ú´ÂÁö °ËÅäÇÕ´Ï´Ù. Autorun.inf ÆÄÀÏÀÌ ±â·ÏµÇ¾úÀ¸¸é À̵¿½Ä µå¶óÀ̺갡 ÄÄÇ»ÅÍ¿¡ ¿¬°áµÉ ¶§ ½ÇÇàµÉ ¼ö ¾øµµ·Ï Autorun.bad¿Í °°Àº ´Ù¸¥ À̸§À¸·Î ¹Ù²Ù½Ê½Ã¿À.
  6. Local Admin ¹× Domain Admin ¾ÏÈ£¸¦ ´Ù½Ã ¼³Á¤ÇÏ¿© °­·ÂÇÑ »õ ¾ÏÈ£¸¦ »ç¿ëÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
    http://technet.microsoft.com/ko-kr/library/cc875814.aspx
  7. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
  8. ¼¼ºÎ Á¤º¸ â¿¡¼­ netsvcs Ç׸ñÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼öÁ¤À» Ŭ¸¯ÇÕ´Ï´Ù.
  9. ÄÄÇ»ÅͰ¡ Win32/Conficker ¹ÙÀÌ·¯½º¿¡ °¨¿°µÈ °æ¿ì ¹«ÀÛÀ§ ¼­ºñ½º À̸§ÀÌ ³ª¿­µË´Ï´Ù.

    Âü°í Win32/Conficker.B¿¡ °¨¿°µÈ °æ¿ì ¼­ºñ½º À̸§ÀÌ ¹«ÀÛÀ§ ¹®ÀÚ·Î ¸ñ·Ï ¸Ç ¾Æ·¡¿¡ Ç¥½ÃµÇ¾ú½À´Ï´Ù. ±× ÀÌÈÄ º¯Á¾ÀÇ °æ¿ì ¼­ºñ½º À̸§ÀÌ ¸ñ·ÏÀÇ ¾î´À À§Ä¡¿¡³ª ÀÖÀ» ¼ö ÀÖÀ¸¸ç ´õ ÇÕ¹ýÀûÀ¸·Î º¸ÀÏ ¼ö ÀÖ½À´Ï´Ù. ¹«ÀÛÀ§ ¼­ºñ½º À̸§ÀÌ ¸Ç ¾Æ·¡¿¡ ÀÖÁö ¾ÊÀ» °æ¿ì ÀÌ ÀýÂ÷ÀÇ "¼­ºñ½º Ç¥"¿Í »ç¿ëÀÚ ½Ã½ºÅÛÀ» ºñ±³ÇÏ¿© Win32/Conficker¿¡ ÀÇÇØ Ãß°¡µÇ¾úÀ» ¼ö ÀÖ´Â ¼­ºñ½º À̸§À» È®ÀÎÇÕ´Ï´Ù. È®ÀÎÇÏ·Á¸é "¼­ºñ½º Ç¥"ÀÇ ¸ñ·Ï°ú °¨¿°µÇÁö ¾ÊÀº °ÍÀ¸·Î ¾Ë·ÁÁø À¯»ç ½Ã½ºÅÛÀ» ºñ±³ÇÕ´Ï´Ù.

    ¸È¿þ¾î ¼­ºñ½º À̸§À» Àû¾îµÎ½Ê½Ã¿À. ÀÌ ÀýÂ÷ µÞºÎºÐ¿¡¼­ ÀÌ Á¤º¸°¡ ÇÊ¿äÇÕ´Ï´Ù.
  10. ¸È¿þ¾î ¼­ºñ½º¿¡ ´ëÇÑ ÂüÁ¶¸¦ Æ÷ÇÔÇÏ´Â ÁÙÀ» »èÁ¦ÇÕ´Ï´Ù. ¸¶Áö¸·¿¡ ³ª¿­µÈ Àû¹ýÇÑ Ç׸ñ ¾Æ·¡¿¡ ºó ÁÙ ¹Ù²ÞÀ» ³ÖÀº ÈÄ È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.

    ¼­ºñ½º Ç¥¿¡ ´ëÇÑ Âü°í »çÇ×
    • ±½°Ô °­Á¶ Ç¥½ÃµÈ Ç׸ñÀ» Á¦¿ÜÇÏ°í ¼­ºñ½º Ç¥ÀÇ ¸ðµç Ç׸ñÀº À¯È¿ÇÑ Ç׸ñÀÔ´Ï´Ù.
    • ±½°Ô °­Á¶ Ç¥½ÃµÈ Ç׸ñÀº Win32/Conficker ¹ÙÀÌ·¯½º·Î ÀÎÇØ SVCHOST ·¹Áö½ºÆ®¸® ŰÀÇ netsvcs °ª¿¡ Ãß°¡µÉ ¼ö ÀÖ´Â Ç׸ñÀÇ ¿¹ÀÔ´Ï´Ù.
    • ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ Ç׸ñ¿¡ µû¶ó ÀÌ ¸ñ·ÏÀº Àüü ¼­ºñ½º ¸ñ·ÏÀÌ ¾Æ´Ò ¼ö ÀÖ½À´Ï´Ù.
    • ÀÌ ¼­ºñ½º Ç¥´Â ±âº» Windows ¼³Ä¡¿¡ ÇØ´çÇÏ´Â ¼­ºñ½º Ç¥ÀÔ´Ï´Ù.
    • Win32/Conficker ¹ÙÀÌ·¯½º·Î ÀÎÇØ ¸ñ·Ï¿¡ Ãß°¡µÇ´Â Ç׸ñÀº È¥¶õÈ­ ±â¼úÀÔ´Ï´Ù. ù ¹øÂ° ¹®ÀÚ°¡ ºñ½ÁÇØ º¸ÀÌ´Â, °­Á¶ Ç¥½ÃµÈ ¾Ç¼º Ç׸ñÀº "L"ÀÇ ¼Ò¹®ÀÚÀÔ´Ï´Ù. ±×·¯³ª »ç½Ç ÀÌ ¹®ÀÚ´Â ´ë¹®ÀÚ "I"ÀÔ´Ï´Ù. ¿î¿µ üÁ¦¿¡¼­ »ç¿ëµÇ´Â ±Û²Ã ¶§¹®¿¡ ´ë¹®ÀÚ "I"´Â "L"ÀÇ ¼Ò¹®ÀÚó·³ º¸ÀÔ´Ï´Ù.

    ¼­ºñ½º Ç¥

    Ç¥ Ãà¼ÒÇ¥ È®´ë
    Windows Server 2008Windows VistaWindows Server 2003Windows XPWindows 2000
    AeLookupSvcAeLookupSvcAppMgmt6to4EventSystem
    wercplsupportwercplsupportAudioSrvAppMgmtIas
    ThemesThemesBrowserAudioSrvIprip
    CertPropSvcCertPropSvcCryptSvcBrowserIrmon
    SCPolicySvcSCPolicySvcDMServerCryptSvcNetman
    lanmanserverlanmanserverEventSystemDMServerNwsapagent
    gpsvcgpsvcHidServDHCPRasauto
    IKEEXTIKEEXTIasERSvcIaslogon
    AudioSrvAudioSrvIpripEventSystemRasman
    FastUserSwitchingCompatibilityFastUserSwitchingCompatibilityIrmonFastUserSwitchingCompatibilityRemoteaccess
    IasIasLanmanServerHidServSENS
    IrmonIrmonLanmanWorkstationIasSharedaccess
    NlaNlaMessengerIpripNtmssvc
    NtmssvcNtmssvcNetmanIrmonwzcsvc
    NWCWorkstationNWCWorkstationNlaLanmanServer
    NwsapagentNwsapagentNtmssvcLanmanWorkstation
    RasautoRasautoNWCWorkstationMessenger
    RasmanRasmanNwsapagentNetman
    IaslogonIaslogonIaslogonIaslogon
    RemoteaccessRemoteaccessRasautoNla
    SENSSENSRasmanNtmssvc
    SharedaccessSharedaccessRemoteaccessNWCWorkstation
    SRServiceSRServiceSacsvrNwsapagent
    TapisrvTapisrvScheduleRasauto
    WmiWmiSeclogonRasman
    WmdmPmSpWmdmPmSpSENSRemoteaccess
    TermServiceTermServiceSharedaccessSchedule
    wuauservwuauservThemesSeclogon
    BITSBITSTrkWksSENS
    ShellHWDetectionShellHWDetectionTrkSvrSharedaccess
    LogonHoursLogonHoursW32TimeSRService
    PCAuditPCAuditWZCSVCTapisrv
    helpsvchelpsvcWmiThemes
    uploadmgruploadmgrWmdmPmSpTrkWks
    iphlpsvciphlpsvcwinmgmtW32Time
    seclogonseclogonwuauservWZCSVC
    AppInfoAppInfoBITSWmi
    msiscsimsiscsiShellHWDetectionWmdmPmSp
    MMCSSMMCSSuploadmgrwinmgmt
    browserProfSvcWmdmPmSNTermService
    winmgmtEapHostxmlprovwuauserv
    SessionEnvwinmgmtAeLookupSvcBITS
    ProfSvcschedulehelpsvcShellHWDetection
    EapHostSessionEnvhelpsvc
    hkmsvcbrowserxmlprov
    schedulehkmsvcwscsvc
    AppMgmtAppMgmtWmdmPmSN
    sacsvrhkmsvc
  11. ÀÌÀü ÀýÂ÷¿¡¼­ ¸È¿þ¾î ¼­ºñ½º À̸§À» Àû¾îµÎ¾ú½À´Ï´Ù. ÀÌ ¿¹¿¡¼­ ¸È¿þ¾î Ç׸ñ À̸§Àº "Iaslogon"¿´½À´Ï´Ù. ÀÌ Á¤º¸¸¦ »ç¿ëÇÏ¿© ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ Ŭ¸¯ÇÕ´Ï´Ù. ¿©±â¼­ BadServiceNameÀº ¸È¿þ¾î ¼­ºñ½ºÀÇ À̸§ÀÔ´Ï´Ù.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BadServiceName
      ¿¹¸¦ µé¾î ´ÙÀ½ ·¹Áö½ºÆ®¸® ۸¦ ã¾Æ¼­ Ŭ¸¯ÇÕ´Ï´Ù.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Iaslogon
    2. Ž»ö â¿¡¼­ ¸È¿þ¾î ¼­ºñ½º À̸§¿¡ ´ëÇÑ ÇÏÀ§ ۸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ÈÄ »ç¿ë ±ÇÇÑÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. SvcHostÀÇ »ç¿ë ±ÇÇÑ ´ëÈ­ »óÀÚ¿¡¼­ °í±ÞÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    4. º¸¾È °í±Þ ¼³Á¤ ´ëÈ­ »óÀÚ¿¡¼­
      ºÎ¸ð °³Ã¼°¡ °¡Áø »ç¿ë ±ÇÇÑÀ» ÀÚ½Ä °³Ã¼¿¡ Àû¿ë (¿©±â¿¡¼­ »õ·Î ¼³Á¤ÇÑ ±ÇÇÑ Æ÷ÇÔ) È®Àζõ°ú

      ¿©±â¿¡ Ç¥½ÃµÈ ±ÇÇÑÀ¸·Î ÀÚ½Ä °³Ã¼ ±ÇÇÑ ¹Ù²Ù±â È®ÀζõÀ» ¸ðµÎ Ŭ¸¯ÇÏ¿© ¼±ÅÃÇÕ´Ï´Ù.
  12. F5 ۸¦ ´­·¯ ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. ÀÌÁ¦ ¼¼ºÎ Á¤º¸ â¿¡¼­ "ServiceDll"·Î ·ÎµåµÈ ¸È¿þ¾î DLLÀ» º¸°í ÆíÁýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. ServiceDll Ç׸ñÀ» µÎ ¹ø Ŭ¸¯ÇÕ´Ï´Ù.
    2. ÂüÁ¶µÈ DLLÀÇ °æ·Î¸¦ Àû¾îµÓ´Ï´Ù. ÀÌ ÀýÂ÷ µÞºÎºÐ¿¡¼­ ÀÌ Á¤º¸°¡ ÇÊ¿äÇÕ´Ï´Ù. ¿¹¸¦ µé¾î ÂüÁ¶µÈ DLLÀÇ °æ·Î´Â ´ÙÀ½°ú À¯»çÇÒ ¼ö ÀÖ½À´Ï´Ù.
       %SystemRoot%\System32\doieuln.dll
      ´ÙÀ½°ú °°ÀÌ ÂüÁ¶ À̸§À» ¹Ù²ß´Ï´Ù.
       %SystemRoot%\System32\doieuln.old
    3. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  13. ·¹Áö½ºÆ®¸®ÀÇ Run ÇÏÀ§ Ű¿¡¼­ ¸È¿þ¾î ¼­ºñ½º Ç׸ñÀ» Á¦°ÅÇÕ´Ï´Ù.
    1. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    2. µÎ ÇÏÀ§ Ű¿¡¼­ "rundll32.exe"·Î ½ÃÀÛÇϰí 12b´Ü°è¿¡¼­ ½Äº°ÇÑ "ServiceDll"·Î ·ÎµåµÈ ¸È¿þ¾î DLLÀ» ÂüÁ¶ÇÏ´Â Ç׸ñÀ» ã½À´Ï´Ù. ÀÌ Ç׸ñÀ» »èÁ¦ÇÕ´Ï´Ù.
    3. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  14. ½Ã½ºÅÛÀÇ µå¶óÀ̺꿡 Autorun.inf ÆÄÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ¸Þ¸ðÀåÀ» »ç¿ëÇÏ¿© °¢ ÆÄÀÏÀ» ¿¬ ÈÄ À¯È¿ÇÑ Autorun.inf ÆÄÀÏÀÎÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½Àº ÀüÇüÀûÀÎ À¯È¿ÇÑ Autorun.inf ÆÄÀÏÀÇ ¿¹ÀÔ´Ï´Ù.
    [autorun]
    shellexecute=Servers\splash.hta *DVD*
    icon=Servers\autorun.ico
    À¯È¿ÇÑ Autorun.infÀÇ Å©±â´Â ÀϹÝÀûÀ¸·Î 1-2KBÀÔ´Ï´Ù.
  15. ¿Ã¹Ù¸£Áö ¾ÊÀº °ÍÀ¸·Î º¸ÀÌ´Â Autorun.inf ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.
  16. ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  17. ¼û±è ÆÄÀÏÀ» º¸ÀÌ°Ô ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
    reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 0x1 /f
  18. ÀÌ ÆÄÀÏÀÌ º¸À̵µ·Ï ¼û±è ÆÄÀÏ ¹× Æú´õ Ç¥½Ã¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. 12b´Ü°è¿¡¼­ ¸È¿þ¾î¿¡ ´ëÇÑ ÂüÁ¶µÈ .dll ÆÄÀÏÀÇ °æ·Î¸¦ Àû¾î µÎ¾ú½À´Ï´Ù. ¿¹¸¦ µé¾î ´ÙÀ½°ú ºñ½ÁÇÑ °æ·Î¸¦ Àû¾î µÎ¾úÀ» °ÍÀÔ´Ï´Ù.
      %systemroot%\System32\doieuln.dll
      Windows Ž»ö±â¿¡¼­ %systemroot%\System32 µð·ºÅ͸® ¶Ç´Â ¸È¿þ¾î°¡ µé¾î ÀÖ´Â µð·ºÅ͸®¸¦ ¿±´Ï´Ù.
    2. µµ±¸¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ Æú´õ ¿É¼ÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. º¸±â ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    4. ¼û±è ÆÄÀÏ ¹× Æú´õ Ç¥½Ã È®ÀζõÀ» ¼±ÅÃÇÕ´Ï´Ù.
    5. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  19. .dll ÆÄÀÏÀ» ¼±ÅÃÇÕ´Ï´Ù.
  20. Everyone¿¡ ´ëÇØ ¸ðµç ±ÇÇÑÀ» Ãß°¡ÇÏ·Á¸é ÆÄÀÏ¿¡ ´ëÇÑ »ç¿ë ±ÇÇÑÀ» ÆíÁýÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. .dll ÆÄÀÏÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼Ó¼ºÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    2. º¸¾È ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
    3. EveryoneÀ» Ŭ¸¯ÇÑ ÈÄ Çã¿ë ¿­¿¡¼­ ¸ðµç ±ÇÇÑ È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±ÅÃÇÕ´Ï´Ù.
    4. È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  21. ¸È¿þ¾î¿¡ ´ëÇÑ ÂüÁ¶µÈ .dll ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù. ¿¹¸¦ µé¾î %systemroot%\System32\doieuln.dll ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.
  22. ¼­ºñ½º MMC(Microsoft Management Console)¸¦ »ç¿ëÇÏ¿© BITS, ÀÚµ¿ ¾÷µ¥ÀÌÆ®, ¿À·ù º¸°í ¹× Windows Defender ¼­ºñ½º¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤ÇÕ´Ï´Ù.
  23. AutorunÀ» ÇØÁ¦ÇÏ¿© Àç°¨¿° °¡´É¼ºÀ» ÁÙÀÔ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
    1. »ç¿ë ÁßÀÎ ½Ã½ºÅÛ¿¡ µû¶ó ´ÙÀ½ ¾÷µ¥ÀÌÆ® Áß Çϳª¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
      • Windows 2000, Windows XP ¶Ç´Â Windows Server 2003À» ½ÇÇà ÁßÀÎ °æ¿ì ¾÷µ¥ÀÌÆ® 967715¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
        967715 Windows¿¡¼­ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈ­ÇÏ´Â ¹æ¹ý
      • Windows Vista ¶Ç´Â Windows Server 2008À» ½ÇÇà ÁßÀÎ °æ¿ì º¸¾È ¾÷µ¥ÀÌÆ® 950582¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
        950582 MS08-038: Windows ExplorerÀÇ Ãë¾à¼ºÀ¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦
      Âü°í ¾÷µ¥ÀÌÆ® 967715 ¹× º¸¾È ¾÷µ¥ÀÌÆ® 950582´Â ÀÌ ¸È¿þ¾î ¹®Á¦¿Í °ü·ÃÀÌ ¾ø½À´Ï´Ù. 23b´Ü°è¿¡¼­ ·¹Áö½ºÆ®¸® ±â´ÉÀ» »ç¿ëÇϵµ·Ï ¼³Á¤Çϱâ À§ÇØ ÀÌ·¯ÇÑ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù.
    2. ¸í·É ÇÁ·ÒÇÁÆ®¿¡ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
      reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoDriveTypeAutoRun /t REG_DWORD /d 0xff /f
  24. ½Ã½ºÅÛ¿¡¼­ Windows Defender¸¦ ½ÇÇà ÁßÀÎ °æ¿ì Windows Defender ÀÚµ¿ ½ÃÀÛ À§Ä¡¸¦ ´Ù½Ã »ç¿ë °¡´ÉÇÏ°Ô ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
    reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Windows Defender" /t REG_EXPAND_SZ /d "%ProgramFiles%\Windows Defender\MSASCui.exe ?hide" /f
  25. Windows Vista ÀÌ»ó ¿î¿µ üÁ¦ÀÇ °æ¿ì ¸È¿þ¾î´Â TCP ¼ö½Å â ÀÚµ¿ Á¶Á¤¿¡ ´ëÇÑ Àü¿ª ¼³Á¤À» »ç¿ë ºÒ°¡´ÉÇÏ°Ô º¯°æÇÕ´Ï´Ù. ÀÌ ¼³Á¤À» ´Ù½Ã º¯°æÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
    netsh interface tcp set global autotuning=normal
ÀÌ ÀýÂ÷¸¦ ¿Ï·áÇÑ ÈÄ¿¡ ÄÄÇ»ÅͰ¡ Àç°¨¿°µÈ °Íó·³ ³ªÅ¸³¯ °æ¿ì ´ÙÀ½ »óȲ Áß ÇϳªÀÏ ¼ö ÀÖ½À´Ï´Ù.
  • ÀÚµ¿ ½ÃÀÛ À§Ä¡ Áß Çϳª°¡ Á¦°ÅµÇÁö ¾Ê¾Ò½À´Ï´Ù. ¿¹¸¦ µé¾î AT ÀÛ¾÷ÀÌ Á¦°ÅµÇÁö ¾Ê¾Ò°Å³ª Autorun.inf ÆÄÀÏÀÌ Á¦°ÅµÇÁö ¾Ê¾Ò½À´Ï´Ù.
  • MS08-067¿ë º¸¾È ¾÷µ¥ÀÌÆ®°¡ Á¦´ë·Î ¼³Ä¡µÇÁö ¾Ê¾Ò½À´Ï´Ù.
ÀÌ ¸È¿þ¾î´Â ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾ÊÀº ´Ù¸¥ ¼³Á¤À» º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù. Win32/Conficker¿¡ ´ëÇÑ Ãֽм¼ºÎ Á¤º¸¸¦ º¸·Á¸é ´ÙÀ½ Microsoft Malware Protection Center À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker

½Ã½ºÅÛÀÌ Á¤¸®µÇ¾ú´ÂÁö È®ÀÎ

´ÙÀ½ ¼­ºñ½º°¡ ½ÃÀ۵Ǿú´ÂÁö È®ÀÎÇϽʽÿÀ.
  • ÀÚµ¿ ¾÷µ¥ÀÌÆ®(wuauserv)
  • BITS(Background Intelligent Transfer Service)
  • Windows Defender(windefend)(Àû¿ë °¡´ÉÇÑ °æ¿ì)
  • Windows ¿À·ù º¸°í ¼­ºñ½º
ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÑ ´ÙÀ½ °¢ ¸í·É ´ÙÀ½¿¡ Enter ۸¦ ´©¸¨´Ï´Ù.

Sc.exe query wuauserv
Sc.exe query bits
Sc.exe query windefend
Sc.exe query ersvc

°¢ ¸í·ÉÀÌ ½ÇÇàµÈ ÈÄ¿¡ ´ÙÀ½°ú ºñ½ÁÇÑ ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
SERVICE_NAME: wuauserv
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 4 RUNNING
(STOPPABLE,NOT_PAUSABLE,ACCEPTS_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
ÀÌ ¿¹¿¡¼­ "STATE : 4 RUNNING"Àº ¼­ºñ½º°¡ ½ÇÇàµÇ°í ÀÖÀ½À» ³ªÅ¸³À´Ï´Ù.

SvcHost ·¹Áö½ºÆ®¸® ÇÏÀ§ ŰÀÇ »óŸ¦ È®ÀÎÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
  2. ¼¼ºÎ Á¤º¸ â¿¡¼­ netsvcs¸¦ µÎ ¹ø Ŭ¸¯ÇÑ ÈÄ ³ª¿­µÈ ¼­ºñ½º À̸§À» °ËÅäÇÕ´Ï´Ù. ¸ñ·Ï ¸Ç ¾Æ·¡·Î ½ºÅ©·ÑÇÕ´Ï´Ù. ÄÄÇ»ÅͰ¡ Conficker¿¡ Àç°¨¿°µÈ °æ¿ì ¹«ÀÛÀ§ ¼­ºñ½º À̸§ÀÌ ³ª¿­µË´Ï´Ù. ¿¹¸¦ µé¾î ÀÌ ÀýÂ÷¿¡¼­´Â ¸È¿þ¾î ¼­ºñ½º À̸§ÀÌ "Iaslogon"ÀÔ´Ï´Ù.
ÀÌ·¯ÇÑ ÀÛ¾÷À¸·Î ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ¾øÀ¸¸é ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü¿¡ ¹®ÀÇÇϽʽÿÀ. ÀÌ ¹®Á¦¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
49500 ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü ¸ñ·Ï
¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü°¡ ¾ø°Å³ª ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü°¡ µµ¿òÀ» ÁÙ ¼ö ¾ø´Â °æ¿ì Microsoft ±â¼ú Áö¿ø ¼­ºñ½º¿¡ ¹®ÀÇÇϽʽÿÀ.

ȯ°æ Á¤¸®°¡ ¿Ï·áµÈ °æ¿ì

ȯ°æ Á¤¸® ÀÛ¾÷ÀÌ ¿Ï·áµÇ¾úÀ¸¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.
  1. ¼­¹ö ¼­ºñ½º ¹× ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼­ºñ½º¸¦ ´Ù½Ã »ç¿ëÇϵµ·Ï ¼³Á¤ÇÕ´Ï´Ù.
  2. SVCHOST ·¹Áö½ºÆ®¸® Ű ¹× Tasks Æú´õ¿¡ ´ëÇÑ ±âº» »ç¿ë ±ÇÇÑÀ» º¹¿øÇÕ´Ï´Ù. ±âº» »ç¿ë ±ÇÇÑÀº ±×·ì Á¤Ã¥ ¼³Á¤À» »ç¿ëÇÏ¿© ±âº» ¼³Á¤À¸·Î µÇµ¹·Á¾ß ÇÕ´Ï´Ù. Á¤Ã¥ÀÌ Á¦°ÅµÈ °æ¿ì¿¡´Â ±âº» »ç¿ë ±ÇÇÑÀ» º¹¿øÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº "¿ÏÈ­ ´Ü°è" ¼½¼ÇÀÇ ±âº» »ç¿ë ±ÇÇÑ Ç¥¸¦ ÂüÁ¶ÇϽʽÿÀ.
  3. ´©¶ôµÈ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÏ¿© ÄÄÇ»Å͸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é Windows Update, WSUS(Microsoft Windows Server Update Services) ¼­¹ö, SMS(Systems Management Server), System Center Configuration Manager(Configuration Manager 2007) ¶Ç´Â Ÿ»ç ¾÷µ¥ÀÌÆ® °ü¸® Á¦Ç°À» »ç¿ëÇÕ´Ï´Ù. SMS ¶Ç´Â Configuration Manager 2007À» »ç¿ëÇÒ °æ¿ì ¸ÕÀú ¼­¹ö ¼­ºñ½º¸¦ ´Ù½Ã »ç¿ëÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ±×·¸Áö ¾ÊÀº °æ¿ì ½Ã½ºÅÛÀ» ¾÷µ¥ÀÌÆ®Çϱâ À§ÇØ SMS ¶Ç´Â Configuration Manager 2007À» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

°¨¿°µÈ ½Ã½ºÅÛ ½Äº°

Conficker¿¡ °¨¿°µÈ ½Ã½ºÅÛÀ» ½Äº°ÇÏ´Â µ¥ ¹®Á¦°¡ ÀÖÀ» °æ¿ì ´ÙÀ½ TechNet ºí·Î±×¿¡ Á¦°øµÈ ¼¼ºÎ Á¤º¸¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://blogs.technet.com/kfalde/archive/2009/01/28/using-logparser-eventcomb-to-find-malware.aspx

±âº» »ç¿ë ±ÇÇÑ Ç¥

´ÙÀ½ Ç¥¿¡¼­´Â °¢ ¿î¿µ üÁ¦¿¡ ´ëÇÑ ±âº» »ç¿ë ±ÇÇÑÀ» º¸¿© ÁÝ´Ï´Ù. ÀÌ ¹®¼­¿¡¼­ ±ÇÀåÇÏ´Â º¯°æ ³»¿ëÀ» Àû¿ëÇϱâ Àü¿¡ ±âº»ÀûÀ¸·Î ÀÌ·¯ÇÑ »ç¿ë ±ÇÇÑÀÌ ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù. ±×·¯³ª ÀÌ »ç¿ë ±ÇÇÑÀº »ç¿ëÀÚ È¯°æ¿¡ ¼³Á¤µÇ¾î ÀÖ´Â »ç¿ë ±ÇÇѰú ´Ù¸¦ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¹Ç·Î º¯°æÇϱâ Àü¿¡ »ç¿ëÀÚÀÇ ¼³Á¤À» Àû¾î µÎ¾î¾ß ÇÕ´Ï´Ù. ½Ã½ºÅÛÀ» Á¤¸®ÇÑ ÈÄ »ç¿ëÀÚÀÇ ¼³Á¤À» º¹¿øÇÒ ¼ö ÀÖµµ·Ï Àû¾î µÎ´Â °ÍÀÔ´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
¿î¿µ üÁ¦ Windows Server 2008Windows VistaWindows Server 2003Windows XPWindows 2000
¼³Á¤Svchost ·¹Áö½ºÆ®¸®Tasks Æú´õSvchost ·¹Áö½ºÆ®¸®Tasks Æú´õSvchost ·¹Áö½ºÆ®¸®Tasks Æú´õSvchost ·¹Áö½ºÆ®¸®Tasks Æú´õSvchost ·¹Áö½ºÆ®¸®Tasks Æú´õ
°èÁ¤
Administrators(·ÎÄà ±×·ì)¸ðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇÑ
System¸ðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇѸðµç ±ÇÇÑ
Power Users(·ÎÄà ±×·ì)ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½
Users(·ÎÄà ±×·ì)Ư¼ö ÇØ´ç »çÇ× ¾øÀ½Æ¯¼öÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½ÀбâÇØ´ç »çÇ× ¾øÀ½
Àû¿ë ´ë»ó: ÀÌ Å° ¹× ÇÏÀ§ ŰÀû¿ë ´ë»ó: ÀÌ Å° ¹× ÇÏÀ§ Ű
°ª Äõ¸®°ª Äõ¸®
ÇÏÀ§ Ű ¿­°ÅÇÏÀ§ Ű ¿­°Å
¾Ë¸²¾Ë¸²
Àбâ Á¦¾îÀбâ Á¦¾î
ÀÎÁõµÈ »ç¿ëÀÚÇØ´ç »çÇ× ¾øÀ½Æ¯¼öÇØ´ç »çÇ× ¾øÀ½Æ¯¼öÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½
Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸
Æú´õ Æ®·¡¹ö½ºÆú´õ Æ®·¡¹ö½º
Æú´õ ¿­°ÅÆú´õ ¿­°Å
Ư¼º ÀÐ±âÆ¯¼º Àбâ
È®Àå Æ¯¼º ÀбâÈ®Àå Æ¯¼º Àбâ
ÆÄÀÏ ¸¸µé±âÆÄÀÏ ¸¸µé±â
»ç¿ë ±ÇÇÑ Àбâ»ç¿ë ±ÇÇÑ Àбâ
Backup Operators(·ÎÄà ±×·ì)ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½Æ¯¼öÇØ´ç »çÇ× ¾øÀ½Æ¯¼ö
Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸
Æú´õ Æ®·¡¹ö½ºÆú´õ Æ®·¡¹ö½º
Æú´õ ¿­°ÅÆú´õ ¿­°Å
Ư¼º ÀÐ±âÆ¯¼º Àбâ
È®Àå Æ¯¼º ÀбâÈ®Àå Æ¯¼º Àбâ
ÆÄÀÏ ¸¸µé±âÆÄÀÏ ¸¸µé±â
»ç¿ë ±ÇÇÑ Àбâ»ç¿ë ±ÇÇÑ Àбâ
¸ðµç »ç¶÷ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½ÇØ´ç »çÇ× ¾øÀ½Æ¯¼ö
Àû¿ë ´ë»ó: ÀÌ Æú´õ, ÇÏÀ§ Æú´õ ¹× ÆÄÀÏ
Æú´õ Æ®·¡¹ö½º
Æú´õ ¿­°Å
Ư¼º Àбâ
È®Àå Æ¯¼º Àбâ
ÆÄÀÏ ¸¸µé±â
Æú´õ ¸¸µé±â
Ư¼º ¾²±â
È®Àå Æ¯¼º ¾²±â
»ç¿ë ±ÇÇÑ Àбâ

Ãß°¡ µµ¿ò¸»

? ÀÌ ¹®Á¦¿¡ ´ëÇØ µµ¿òÀÌ ÇÊ¿äÇÑ °æ¿ì ¹Ì±¹¿¡ °ÅÁÖÇÏ´Â °í°´Àº Answer Desk¿¡¼­ Á÷Á¢ ´ã´çÀÚ¿Í ´ëÈ­ÇÒ ¼ö ÀÖ½À´Ï´Ù.?
Answer Desk
Âü°í À̰ÍÀº Microsoft ±â¼ú Áö¿ø ¼­ºñ½º ³»¿¡¼­ Á÷Á¢ ÀÛ¼ºÇÑ ¡°ºü¸¥ °Ô½Ã¡± ¹®¼­ÀÔ´Ï´Ù. ¿©±â¿¡ Æ÷ÇÔµÈ Á¤º¸´Â ¹ß»ýÇÑ ¹®Á¦¿¡ ´ëÇØ ÀÖ´Â ±×´ë·Î Á¦°øµË´Ï´Ù. ÀÌ ¹®¼­´Â Áï½Ã ÂüÁ¶ÇÒ ¼ö ÀÖµµ·Ï ºü¸£°Ô ÀÛ¼ºµÇ¾î¼­ Ç¥±â»óÀÇ ¿À·ù°¡ Æ÷ÇԵǾî ÀÖÀ» ¼ö ÀÖ°í ¾ðÁ¦µçÁö ¿¹°í ¾øÀÌ ¼öÁ¤µÉ ¼ö ÀÖ½À´Ï´Ù. ±âŸ °í·Á »çÇ×Àº»ç¿ë ¾à°üÀ» ÂüÁ¶ÇϽʽÿÀ. Á¤º¸

¼Ó¼º

±â¼ú ÀÚ·á: 962007 - ¸¶Áö¸· °ËÅä: 2013³â 1¿ù 16ÀÏ ¼ö¿äÀÏ - ¼öÁ¤: 1.0
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Windows Server 2008 Datacenter without Hyper-V
  • Windows Server 2008 Enterprise without Hyper-V
  • Windows Server 2008 for Itanium-Based Systems
  • Windows Server 2008 Standard without Hyper-V
  • Windows Server 2008 Datacenter
  • Windows Server 2008 Enterprise
  • Windows Server 2008 Standard
  • Windows Web Server 2008
  • Windows Vista Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit edition
    • Windows Vista Home Basic 64-bit edition
    • Windows Vista Home Premium 64-bit edition
    • Windows Vista Ultimate 64-bit edition
    • Windows Vista Business 64-bit edition
  • Windows Vista Business
  • Windows Vista Enterprise
  • Windows Vista Home Basic
  • Windows Vista Home Premium
  • Windows Vista Starter
  • Windows Vista Ultimate
  • Windows Vista Enterprise 64-bit edition
  • Windows Vista Home Basic 64-bit edition
  • Windows Vista Home Premium 64-bit edition
  • Windows Vista Ultimate 64-bit edition
  • Windows Vista Business 64-bit edition
  • Microsoft Windows Server 2003 Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows Server 2003, Datacenter x64 Edition
  • Microsoft Windows Server 2003, Enterprise x64 Edition
  • Microsoft Windows Server 2003, Standard x64 Edition
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows Server 2003 Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows XP Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
  • Microsoft Windows XP Service Pack 3?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 4?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows 2000 Advanced Server
    • Microsoft Windows 2000 Professional Edition
    • Microsoft Windows 2000 Server
Ű¿öµå:?
kbsccm kbregistry kbexpertiseinter kbsecurity kbsecvulnerability kbsurveynew KB962007

Çǵå¹é º¸³»±â