ÀÌ ±â¼ú ÀÚ·á ¹®¼ÀÇ Á¤º¸´Â ÀÌ ¹®¼ÀÇ ¼¼ºÎ Á¤º¸¸¦ ±¸ÇöÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ÀÖ´Â ºñÁî´Ï½º ȯ°æÀ» ´ë»óÀ¸·Î ÇÕ´Ï´Ù. ¹ÙÀÌ·¯½º ¹é½Å ÇÁ·Î±×·¥À¸·Î ¹ÙÀÌ·¯½º¸¦ ¿Ã¹Ù¸£°Ô Ä¡·áÇϰí ÀÖ´Â °æ¿ì ¹× ½Ã½ºÅÛÀÌ ¿ÏÀüÈ÷ ¾÷µ¥ÀÌÆ®µÈ °æ¿ì¿¡´Â ÀÌ ¹®¼¸¦ »ç¿ëÇÒ Çʿ䰡 ¾ø½À´Ï´Ù. ½Ã½ºÅÛ¿¡ Conficker ¹ÙÀÌ·¯½º°¡ ¾ø´ÂÁö È®ÀÎÇÏ·Á¸é ´ÙÀ½ À¥ ÆäÀÌÁö¿¡¼ ºü¸¥ °Ë»ç¸¦ ¼öÇàÇÕ´Ï´Ù.
http://www.microsoft.com/security/scanner/ko-kr/
(http://www.microsoft.com/security/scanner/ko-kr/)
Conficker ¹ÙÀÌ·¯½º¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.
ÄÄÇ»ÅͰ¡ ÀÌ ¿ú¿¡ °¨¿°µÈ °æ¿ì ¾î¶°ÇÑ Çö»óµµ ¹ß»ýÇÏÁö ¾Ê°Å³ª ´ÙÀ½ Çö»óÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
- °èÁ¤ Àá±Ý Á¤Ã¥ÀÌ ½ÇÇàµÇ°í ÀÖ½À´Ï´Ù.
- ÀÚµ¿ ¾÷µ¥ÀÌÆ®, BITS(Background Intelligent Transfer Service), Windows Defender ¹× ¿À·ù º¸°í ¼ºñ½º°¡ »ç¿ëµÇÁö ¾Ê°Ô ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù.
- µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯°¡ Ŭ¶óÀÌ¾ðÆ® ¿äû¿¡ ´À¸®°Ô ÀÀ´äÇÕ´Ï´Ù.
- ³×Æ®¿öÅ©°¡ Á¤Ã¼µÇ¾î ÀÖ½À´Ï´Ù.
- ´Ù¾çÇÑ º¸¾È °ü·Ã À¥ »çÀÌÆ®¿¡ ¾×¼¼½ºÇÒ ¼ö ¾ø½À´Ï´Ù.
- ´Ù¾çÇÑ º¸¾È °ü·Ã µµ±¸°¡ ½ÇÇàµÇÁö ¾Ê½À´Ï´Ù. ¾Ë·ÁÁø µµ±¸ ¸ñ·ÏÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ. ±×·± ´ÙÀ½ Win32/Conficker.D¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é Analysis ÅÇÀ» Ŭ¸¯ÇϽʽÿÀ. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.
Win32/Conficker¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft Malware Protection Center À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ.
Win32/Conficker´Â ´ÙÀ½°ú °°Àº ¿©·¯ °¡Áö ¹æ¹ýÀ¸·Î ÀüÆÄµË´Ï´Ù.
- º¸¾È ¾÷µ¥ÀÌÆ® 958644(MS08-067)¿¡ ÀÇÇØ ÆÐÄ¡µÇ´Â Ãë¾à¼º ÀÌ¿ë
- ³×Æ®¿öÅ© °øÀ¯ »ç¿ë
- ÀÚµ¿ Àç»ý ±â´É »ç¿ë
µû¶ó¼ ³×Æ®¿öÅ©¸¦ Á¤¸®ÇÒ ¶§´Â ÀÌÀü¿¡ Á¤¸®ÇÑ ½Ã½ºÅÛ¿¡ À§Çù ¿ä¼Ò°¡ ´Ù½Ã ħÅõµÇÁö ¾Êµµ·Ï ÁÖÀÇÇØ¾ß ÇÕ´Ï´Ù.
Âü°í Win32/Conficker.D º¯Á¾Àº ³×Æ®¿öÅ©¸¦ ÅëÇØ À̵¿½Ä µå¶óÀÌºê ¶Ç´Â °øÀ¯ Æú´õ·Î È®»êµÇÁö ¾Ê½À´Ï´Ù. Win32/Conficker.D´Â Win32/ConfickerÀÇ ÀÌÀü º¯Á¾¿¡ ÀÇÇØ ¼³Ä¡µË´Ï´Ù.
±×·ì Á¤Ã¥ ¼³Á¤À» »ç¿ëÇÏ¿© Win32/Conficker È®»ê ¹æÁö
Âü°í- Áß¿ä ÀÌ ¹®¼¿¡ Á¦¾ÈµÈ ´ë·Î º¯°æÇϱâ Àü¿¡ ÇöÀç ¼³Á¤À» ¹®¼ÈÇØ¾ß ÇÕ´Ï´Ù.
- ´ÙÀ½ ÀýÂ÷¸¦ ¼öÇàÇØµµ ½Ã½ºÅÛ¿¡¼ Conficker ¸È¿þ¾î°¡ Á¦°ÅµÇÁö´Â ¾ÊÀ¸¸ç ¸È¿þ¾îÀÇ È®»êÀ» ¹æÁöÇÒ »ÓÀÔ´Ï´Ù. ½Ã½ºÅÛ¿¡¼ Conficker ¸È¿þ¾î¸¦ Á¦°ÅÇÏ·Á¸é ¹ÙÀÌ·¯½º ¹é½Å Á¦Ç°À» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. ¶Ç´Â ÀÌ ±â¼ú ÀÚ·á ¹®¼ÀÇ "Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è" ¼½¼ÇÀÇ ´Ü°è¸¦ µû¶ó ½Ã½ºÅÛ¿¡¼ ¸È¿þ¾î¸¦ ¼öµ¿À¸·Î Á¦°ÅÇϽʽÿÀ.
- ´ÙÀ½ ´Ü°è¿¡¼ ±ÇÀåµÇ´Â ´ë·Î »ç¿ë ±ÇÇÑÀ» º¯°æÇÏ´Â µ¿¾È ÀÀ¿ë ÇÁ·Î±×·¥, ¼ºñ½º ÆÑ ¶Ç´Â ±âŸ ¾÷µ¥ÀÌÆ®¸¦ ¿Ã¹Ù¸£°Ô ¼³Ä¡ÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î Windows Update, Microsoft WSUS(Windows Server Update Services) ¼¹ö ¹× System Center Configuration Manager(Configuration Manager 2007)Àº ÀÚµ¿ ¾÷µ¥ÀÌÆ®ÀÇ ±¸¼º ¿ä¼Ò¸¦ »ç¿ëÇϱ⠶§¹®¿¡ ÀÌ·¯ÇÑ Á¦Ç°À» »ç¿ëÇÏ¿© ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÒ ¼ö ¾øÀ¸¸ç À̿ܿ¡µµ ´Ù¸¥ ¼³Ä¡ ¹®Á¦°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. ½Ã½ºÅÛÀ» Á¤¸®ÇÑ ÈÄ »ç¿ë ±ÇÇÑÀ» ´Ù½Ã ±âº» ¼³Á¤À¸·Î º¯°æÇØ¾ß ÇÕ´Ï´Ù.
-
"±×·ì Á¤Ã¥ °³Ã¼ ¸¸µé±â" ¼½¼Ç¿¡ ¼³¸íµÈ Tasks Æú´õ ¹× SVCHOST ·¹Áö½ºÆ®¸® ŰÀÇ ±âº» »ç¿ë ±ÇÇÑ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ÀÌ ¹®¼ ÈĹݺÎÀÇ ±âº» »ç¿ë ±ÇÇÑ Ç¥¸¦ ÂüÁ¶ÇϽʽÿÀ.
±×·ì Á¤Ã¥ °³Ã¼ ¸¸µé±â
ÀÛ¾÷ ȯ°æÀÇ ¿ä±¸¿¡ µû¶ó ƯÁ¤ OU(Á¶Á÷ ±¸¼º ´ÜÀ§), »çÀÌÆ® ¶Ç´Â µµ¸ÞÀÎÀÇ ¸ðµç ÄÄÇ»ÅÍ¿¡ Àû¿ëµÇ´Â »õ GPO(±×·ì Á¤Ã¥ °³Ã¼)¸¦ ¸¸µì´Ï´Ù.
ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ Ű¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» Á¦°ÅÇÏ´Â Á¤Ã¥À» ¼³Á¤ÇÕ´Ï´Ù.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
ÀÌ·¸°Ô Çϸé ÀÓÀÇ·Î ¸í¸íµÈ ¸È¿þ¾î ¼ºñ½º°¡ netsvcs ·¹Áö½ºÆ®¸® °ª¿¡ »ý¼ºµÇ´Â °ÍÀ» ¸·À» ¼ö ÀÖ½À´Ï´Ù.
ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- GPMC(±×·ì Á¤Ã¥ °ü¸® ÄܼÖ)¸¦ ¿±´Ï´Ù.
- »õ GPO¸¦ ¸¸µì´Ï´Ù. °³Ã¼¿¡ ¿øÇÏ´Â À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
- »õ GPO¸¦ ¿°í ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
ÄÄÇ»ÅÍ ±¸¼º\Windows ¼³Á¤\º¸¾È ¼³Á¤\·¹Áö½ºÆ®¸®
- ·¹Áö½ºÆ®¸®¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ Ű Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- ·¹Áö½ºÆ®¸® Ű ¼±Åà ´ëÈ »óÀÚ¿¡¼ MachineÀ» È®ÀåÇÑ ÈÄ ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
Software\Microsoft\Windows NT\CurrentVersion
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¿¸®´Â ´ëÈ »óÀÚ¿¡¼ Administrators ¹× System µÑ ´Ù¿¡ ´ëÇØ ¸ðµç ±ÇÇÑ È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±Åà Ãë¼ÒÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- °³Ã¼ Ãß°¡ ´ëÈ »óÀÚ¿¡¼ ¸ðµç ÇÏÀ§ ŰÀÇ ±âÁ¸ »ç¿ë ±ÇÇÑÀ» »ó¼Ó °¡´ÉÇÑ »ç¿ë ±ÇÇÑÀ¸·Î ¹Ù²Ù±â¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- %windir%\Tasks Æú´õ¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» Á¦°ÅÇÏ´Â Á¤Ã¥À» ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô Çϸé Conficker ¸È¿þ¾î°¡ ½Ã½ºÅÛÀ» Àç°¨¿°½Ãų ¼ö ÀÖ´Â ¿¹¾àµÈ ÀÛ¾÷À» ¸¸µé ¼ö ¾ø½À´Ï´Ù.
ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ¾Õ¿¡¼ ¸¸µç GPO¿¡¼ ´ÙÀ½ Æú´õ·Î À̵¿ÇÕ´Ï´Ù.
ÄÄÇ»ÅÍ ±¸¼º\Windows ¼³Á¤\º¸¾È ¼³Á¤\ÆÄÀÏ ½Ã½ºÅÛ
- ÆÄÀÏ ½Ã½ºÅÛÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í ÆÄÀÏ Ãß°¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- ÆÄÀÏÀ̳ª Æú´õ Ãß°¡ ´ëÈ »óÀÚ¿¡¼ %windir%\Tasks Æú´õ¸¦ ã½À´Ï´Ù. Æú´õ ´ëÈ »óÀÚ¿¡¼ Tasks Æú´õ°¡ ¼±ÅÃµÈ Ã¤·Î ³ª¿µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¿·Á ÀÖ´Â ´ëÈ »óÀÚ¿¡¼ °ü¸®ÀÚ¿Í ½Ã½ºÅÛ ¸ðµÎ¿¡ ´ëÇØ ¸ðµç ±ÇÇÑ, ¼öÁ¤ ¹× ¾²±â È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±ÅÃÀ» Ãë¼ÒÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- °³Ã¼ Ãß°¡ ´ëÈ »óÀÚ¿¡¼ ¸ðµç ÇÏÀ§ ŰÀÇ ±âÁ¸ »ç¿ë ±ÇÇÑÀ» »ó¼Ó °¡´ÉÇÑ »ç¿ë ±ÇÇÑÀ¸·Î ¹Ù²Ù±â¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ÀÚµ¿ ½ÇÇà ±â´ÉÀÌ »ç¿ëµÇÁö ¾Êµµ·Ï ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô Çϸé Conficker ¸È¿þ¾î°¡ Windows¿¡ ±âº» Á¦°øµÈ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» »ç¿ëÇÏ¿© È®»êµÉ ¼ö ¾ø½À´Ï´Ù.
Âü°í »ç¿ë ÁßÀÎ Windows ¹öÀü¿¡ µû¶ó ÀÚµ¿ ½ÇÇà ±â´ÉÀ» Á¦´ë·Î ºñȰ¼ºÈÇϱâ À§ÇØ ¼³Ä¡ÇØ¾ß ÇÏ´Â ¾÷µ¥ÀÌÆ®°¡ µû·Î ÀÖ½À´Ï´Ù.
- Windows Vista ¶Ç´Â Windows Server 2008¿¡¼ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈÇÏ·Á¸é º¸¾È ¾÷µ¥ÀÌÆ® 950582
(http://support.microsoft.com/kb/950582/ko)
¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù(º¸¾È °øÁö MS08-038¿¡ ¼³¸íµÊ). - Windows XP, Windows Server 2003 ¶Ç´Â Windows 2000¿¡¼ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈÇÏ·Á¸é º¸¾È ¾÷µ¥ÀÌÆ® 950582
(http://support.microsoft.com/kb/950582/ko)
, ¾÷µ¥ÀÌÆ® 967715
(http://support.microsoft.com/kb/967715/ko)
¶Ç´Â ¾÷µ¥ÀÌÆ® 953252
(http://support.microsoft.com/kb/953252/ko)
¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù.
ÀÚµ¿ ½ÇÇà ±â´ÉÀÌ »ç¿ëµÇÁö ¾Êµµ·Ï ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.
- ¾Õ¿¡¼ ¸¸µç GPO¿¡¼ ´ÙÀ½ Æú´õ Áß Çϳª·Î À̵¿ÇÕ´Ï´Ù.
- ÀÚµ¿ ½ÇÇà »ç¿ë ¾È ÇÔ Á¤Ã¥À» ¿±´Ï´Ù.
- ÀÚµ¿ ½ÇÇà »ç¿ë ¾È ÇÔ ´ëÈ »óÀÚ¿¡¼ »ç¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- µå·Ó´Ù¿î ¸Þ´º¿¡¼ ¸ðµç µå¶óÀ̺긦 Ŭ¸¯ÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ±×·ì Á¤Ã¥ °ü¸® ÄܼÖÀ» ´Ý½À´Ï´Ù.
- »õ·Î ¸¸µç GPO¸¦ Àû¿ëÇÏ·Á´Â À§Ä¡¿¡ ÇØ´ç GPO¸¦ ¿¬°áÇÕ´Ï´Ù.
- ±×·ì Á¤Ã¥ ¼³Á¤ÀÌ ¸ðµç ÄÄÇ»ÅÍ·Î ¾÷µ¥ÀÌÆ®µÉ ¶§±îÁö ÃæºÐÈ÷ ´ë±âÇÕ´Ï´Ù. ÀϹÝÀûÀ¸·Î ±×·ì Á¤Ã¥ º¹Á¦°¡ °¢ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯·Î º¹Á¦¸¦ ¼öÇàÇÏ´Â µ¥ 5ºÐ Á¤µµ °É¸®°í ½Ã½ºÅÛÀÇ ³ª¸ÓÁö ºÎºÐÀ¸·Î º¹Á¦¸¦ ¼öÇàÇÏ´Â µ¥ 90ºÐ Á¤µµ °É¸³´Ï´Ù. µû¶ó¼ µÎ ½Ã°£ Á¤µµ¸é ÃæºÐÇÕ´Ï´Ù. ±×·¯³ª ÀÛ¾÷ ȯ°æ¿¡ µû¶ó ´õ ¸¹Àº ½Ã°£ÀÌ ¼Ò¿äµÉ ¼öµµ ÀÖ½À´Ï´Ù.
-
±×·ì Á¤Ã¥ ¼³Á¤À» ÀüÆÄÇÑ ÈÄ¿¡´Â ½Ã½ºÅÛ¿¡¼ ¸È¿þ¾î¸¦ Á¦°ÅÇϽʽÿÀ.
ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ¸ðµç ÄÄÇ»ÅÍ¿¡¼ Àüü ¹ÙÀÌ·¯½º ¹é½Å °Ë»öÀ» ½ÇÇàÇϽʽÿÀ.
- ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î°¡ Conficker¸¦ °Ë»öÇÏÁö ¸øÇϸé Microsoft Safety Scanner¸¦ »ç¿ëÇÏ¿© ¸È¿þ¾î¸¦ Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ. http://www.microsoft.com/security/scanner/ko-kr/
(http://www.microsoft.com/security/scanner/ko-kr/)
Âü°í ¸È¿þ¾î·Î ÀÎÇÑ ¸ðµç ¿µÇâÀ» Á¦°ÅÇϱâ À§ÇØ ¸î °¡Áö ¼öµ¿ ´Ü°è¸¦ ¼öÇàÇØ¾ß ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®¼ÀÇ "Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è" ¼½¼Ç¿¡ ³ª¿µÈ ´Ü°è¸¦ °ËÅäÇÏ¿© ¸È¿þ¾îÀÇ ¿µÇâÀ» ¸ðµÎ Á¦°ÅÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.
Microsoft Safety Scanner ½ÇÇà
Microsoft Malware Protection Center¿¡¼´Â Microsoft Safety Scanner¸¦ ¾÷µ¥ÀÌÆ®Çß½À´Ï´Ù. ÀÌ µµ±¸´Â ÀÚÁÖ ¹ß»ýÇÏ´Â ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î¸¦ Á¦°ÅÇÏ´Â µ¥ À¯¿ëÇÑ µ¶¸³ ½ÇÇàÇü ÀÌÁø ÆÄÀÏ·Î, Win32/Conficker ¸È¿þ¾î Á¦Ç°±ºÀ» Á¦°ÅÇÏ´Â µ¥ µµ¿òÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
Âü°í Microsoft Safety Scanner´Â ½Ç½Ã°£ ¹ÙÀÌ·¯½º ¹é½Å ÇÁ·Î±×·¥ÀÌ ¾Æ´Ï±â ¶§¹®¿¡ Àç°¨¿°À» ¹æÁöÇÏÁö ¾Ê½À´Ï´Ù.
Microsoft Safety Scanner´Â ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¿¡¼ ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.
Âü°í µ¶¸³ ½ÇÇàÇü ½Ã½ºÅÛ ½ºÀ§ÆÛ µµ±¸·Îµµ ÀÌ °¨¿°À» Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ µµ±¸´Â Microsoft Desktop Optimization Pack 6.0ÀÇ ±¸¼º ¿ä¼Ò·Î »ç¿ëÇϰųª °í°´ Áö¿ø ¼ºñ½º¸¦ ÅëÇØ Á¦°ø ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. Microsoft Desktop Optimization PackÀ» ±¸ÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
½Ã½ºÅÛ¿¡¼ Microsoft Security Essentials ¶Ç´Â Microsoft Forefront Client Security°¡ ½ÇÇàµÇ°í ÀÖÀ¸¸é À§Çù ¿ä¼Ò°¡ ħÅõÇϱâ Àü¿¡ Â÷´ÜµË´Ï´Ù.
Win32/Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¼öµ¿ ´Ü°è
Âü°í- ÀÌ ¼öµ¿ ´Ü°è´Â ´õ ÀÌ»ó ÇÊ¿äÇÏÁö ¾ÊÀ¸¸ç, Conficker ¹ÙÀÌ·¯½º¸¦ Á¦°ÅÇÏ´Â ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î°¡ ¾øÀ» °æ¿ì¿¡¸¸ »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
- ÄÄÇ»ÅÍ¿¡ ħÅõÇÑ Win32/Conficker º¯Á¾¿¡ µû¶ó ÀÌ ¼½¼Ç¿¡ ÂüÁ¶µÈ ÀÌ °ª Áß ÀϺδ ¹ÙÀÌ·¯½º¿¡ ÀÇÇØ º¯°æµÇÁö ¾Ê¾ÒÀ» ¼ö ÀÖ½À´Ï´Ù.
´ÙÀ½ ¼¼ºÎ ´Ü°è¸¦ ¼öÇàÇÏ¿© ½Ã½ºÅÛ¿¡¼ Conficker¸¦ ¼öµ¿À¸·Î Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.
- ·ÎÄà °èÁ¤À» »ç¿ëÇÏ¿© ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÕ´Ï´Ù.
Áß¿ä °¡´ÉÇÑ °æ¿ì¿¡µµ µµ¸ÞÀÎ °èÁ¤À» »ç¿ëÇÏ¿© ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÏÁö ¸¶½Ê½Ã¿À. ƯÈ÷, µµ¸ÞÀÎ °ü¸®ÀÚ °èÁ¤À» »ç¿ëÇÏ¿© ·Î±×¿ÂÇÏ´Â °æ¿ì´Â ÇÇÇϽʽÿÀ. ¸È¿þ¾î´Â ·Î±×¿ÂµÈ »ç¿ëÀÚ ÀÚ°Ý Áõ¸íÀ» »ç¿ëÇÏ¿© ·Î±×¿ÂÇÑ »ç¿ëÀÚ¸¦ °¡ÀåÇÏ°í ³×Æ®¿öÅ© ¸®¼Ò½º¿¡ ¾×¼¼½ºÇϱ⠶§¹®ÀÔ´Ï´Ù. ÀÌ·¯ÇÑ µ¿ÀÛÀ¸·Î ÀÎÇØ ¸È¿þ¾î°¡ È®»êµÉ ¼ö ÀÖ½À´Ï´Ù. -
¼¹ö ¼ºñ½º¸¦ ÁßÁöÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ½Ã½ºÅÛ¿¡¼ °ü¸® °øÀ¯°¡ Á¦°ÅµÇ¹Ç·Î ¸È¿þ¾î°¡ °ü¸® °øÀ¯¸¦ ÅëÇØ È®»êµÉ ¼ö ¾ø°Ô µË´Ï´Ù.
Âü°í ¼¹ö ¼ºñ½º´Â »ç¿ëÀÚ È¯°æ¿¡¼ ¸È¿þ¾î¸¦ Á¤¸®ÇÏ´Â µ¿¾È¿¡¸¸ ÀϽÃÀûÀ¸·Î ºñȰ¼ºÈÇØ¾ß ÇÕ´Ï´Ù. ¼¹ö ¼ºñ½º¸¦ »ç¿ëÇÒ ¼ö ¾ø°Ô ¼³Á¤ÇÏ¸é ³×Æ®¿öÅ© ¸®¼Ò½ºÀÇ °¡¿ë¼º¿¡ ¿µÇâÀ» ÁֹǷΠÇÁ·Î´ö¼Ç ¼¹ö¿¡¼´Â Áï½Ã ´Ù½Ã ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ȯ°æÀÌ Á¤¸®µÇ¸é ¼¹ö ¼ºñ½º¸¦ »ç¿ë °¡´ÉÇÏ°Ô ´Ù½Ã ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.
¼¹ö ¼ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ¼ºñ½º MMC(Microsoft Management Console)¸¦ »ç¿ëÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- »ç¿ë ÁßÀÎ ½Ã½ºÅÛ¿¡ µû¶ó ´ÙÀ½À» ¼öÇàÇϽʽÿÀ.
- Windows Vista ¹× Windows Server 2008¿¡¼ ½ÃÀÛÀ» Ŭ¸¯ÇÏ°í °Ë»ö ½ÃÀÛ »óÀÚ¿¡ services.msc¸¦ ÀÔ·ÂÇÑ ÈÄ ÇÁ·Î±×·¥ ¸ñ·Ï¿¡¼ services.msc¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- Windows 2000, Windows XP ¹× Windows Server 2003ÀÇ °æ¿ì ½ÃÀÛ, ½ÇÇàÀ» Â÷·Ê·Î Ŭ¸¯ÇÑ ÈÄ services.msc¸¦ ÀÔ·ÂÇϰí È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¼¹ö¸¦ µÎ ¹ø Ŭ¸¯ÇÕ´Ï´Ù.
- ÁßÁö¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- ½ÃÀÛ À¯Çü »óÀÚ¿¡¼ »ç¿ë ¾È ÇÔÀ» ¼±ÅÃÇÕ´Ï´Ù.
- Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¸ðµç AT »ý¼º ¿¹¾à ÀÛ¾÷À» Á¦°ÅÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡ AT /Delete /Yes¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
-
ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼ºñ½º¸¦ ÁßÁöÇÕ´Ï´Ù.
- Windows 2000, Windows XP ¹× Windows Server 2003¿¡¼ ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ¼ºñ½º MMC(Microsoft Management Console) ¶Ç´Â SC.exe À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÕ´Ï´Ù.
- Windows Vista ¶Ç´Â Windows Server 2008¿¡¼ ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼ºñ½º¸¦ ÁßÁöÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ µû¸£½Ê½Ã¿À.
Áß¿ä ÀÌ Àý, ¹æ¹ý ¶Ç´Â ÀÛ¾÷¿¡´Â ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ´Ü°è°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ±×·¯³ª ·¹Áö½ºÆ®¸®¸¦ À߸ø ¼öÁ¤ÇÏ¸é ½É°¢ÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ ¼öµµ ÀÖÀ¸¹Ç·Î ´ÙÀ½ ´Ü°è¸¦ ÁÖÀÇÇÏ¿© ¼öÇàÇØ¾ß ÇÕ´Ï´Ù. Ãß°¡ º¸È£ Á¶Ä¡·Î ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤Çϱâ Àü¿¡ ÇØ´ç ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ¹®Á¦°¡ ¹ß»ýÇÏ´Â °æ¿ì ·¹Áö½ºÆ®¸®¸¦ º¹¿øÇÒ ¼ö ÀÖ½À´Ï´Ù. ·¹Áö½ºÆ®¸® ¹é¾÷ ¹× º¹¿ø ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ. 322756
(http://support.microsoft.com/kb/322756/ko/
)
Windows¿¡¼ ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ ¹× º¹¿øÇÏ´Â ¹æ¹ý
- ½ÃÀÛÀ» Ŭ¸¯ÇÏ°í °Ë»ö ½ÃÀÛ »óÀÚ¿¡ regedit¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ ÇÁ·Î±×·¥ ¸ñ·Ï¿¡¼ regedit.exe¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ¼ Ŭ¸¯ÇÕ´Ï´Ù.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
- ¼¼ºÎ Á¤º¸ â¿¡¼ Start DWORD Ç׸ñÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼öÁ¤À» Ŭ¸¯ÇÕ´Ï´Ù.
- °ª µ¥ÀÌÅÍ »óÀÚ¿¡ 4À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
Âü°í ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼ºñ½º´Â »ç¿ëÀÚ È¯°æ¿¡¼ ¸È¿þ¾î¸¦ Á¤¸®ÇÏ´Â µ¿¾È¿¡¸¸ ÀϽÃÀûÀ¸·Î ºñȰ¼ºÈÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ´Ü°è´Â ´Ù¾çÇÑ ±âº» ¿¹¾àµÈ ÀÛ¾÷¿¡ ¿µÇâÀ» ÁֹǷΠWindows Vista ¹× Windows Server 2008¿¡¼´Â ƯÈ÷ ÀÌ ¼ºñ½º¸¦ ºñȰ¼ºÈÇØ¾ß ÇÕ´Ï´Ù. ȯ°æÀÌ Á¤¸®µÇ¸é ¼¹ö ¼ºñ½º¸¦ »ç¿ëÇϵµ·Ï ´Ù½Ã ¼³Á¤ÇÕ´Ï´Ù.
- º¸¾È ¾÷µ¥ÀÌÆ® 958644(MS08-067)¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ¼öµ¿À¸·Î ¼³Ä¡ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ. Âü°í ÀÌ »çÀÌÆ®´Â ¸È¿þ¾î °¨¿° ¶§¹®¿¡ Â÷´ÜµÉ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ½Ã³ª¸®¿À¿¡¼´Â °¨¿°µÇÁö ¾ÊÀº ÄÄÇ»ÅÍ¿¡¼ ¾÷µ¥ÀÌÆ®¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ¾÷µ¥ÀÌÆ® ÆÄÀÏÀ» °¨¿°µÈ ½Ã½ºÅÛÀ¸·Î Àü¼ÛÇØ¾ß ÇÕ´Ï´Ù. ±¸¿î CD´Â ¾²±â ºÒ°¡´ÉÇϹǷΠ¾÷µ¥ÀÌÆ®¸¦ CD·Î ±¸¿ï °ÍÀ» ±ÇÀåÇÕ´Ï´Ù. µû¶ó¼ ÀÌ CD´Â °¨¿°µÉ ¼ö ¾ø½À´Ï´Ù. ±â·Ï °¡´É CD µå¶óÀ̺ê´Â »ç¿ëÇÒ ¼ö ¾øÀ¸¹Ç·Î À̵¿½Ä USB ¸Þ¸ð¸® µå¶óÀ̺갡 °¨¿°µÈ ½Ã½ºÅÛÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ º¹»çÇÏ´Â À¯ÀÏÇÑ ¹æ¹ýÀÏ ¼ö ÀÖ½À´Ï´Ù. À̵¿½Ä µå¶óÀ̺긦 »ç¿ëÇÒ °æ¿ì ¸È¿þ¾î°¡ Autorun.inf ÆÄÀÏÀÌ ÀÖ´Â µå¶óÀ̺꿡 °¨¿°µÉ ¼ö ÀÖ´Ù´Â »ç½ÇÀ» ¾Ë¾Æ¾ß ÇÕ´Ï´Ù. À̵¿½Ä µå¶óÀ̺꿡 ¾÷µ¥ÀÌÆ®¸¦ º¹»çÇÑ ÈÄ¿¡´Â µå¶óÀ̺긦 Àбâ Àü¿ë ¸ðµå·Î º¯°æÇÏ´Â ¿É¼ÇÀÌ ÀÖ´Â °æ¿ì ÀÌ ¿É¼ÇÀ» ½ÇÇàÇØ¾ß ÇÕ´Ï´Ù. Àбâ Àü¿ë ¸ðµå¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Â °æ¿ì ÀϹÝÀûÀ¸·Î ÀåÄ¡ÀÇ ½ÇÁ¦ ½ºÀ§Ä¡¸¦ »ç¿ëÇÏ¿© ¼³Á¤ÇÕ´Ï´Ù. ±×·± ÈÄ ¾÷µ¥ÀÌÆ® ÆÄÀÏÀ» °¨¿°µÈ ÄÄÇ»ÅÍ¿¡ º¹»çÇϰí À̵¿½Ä µå¶óÀ̺긦 È®ÀÎÇÏ¿© Autorun.inf ÆÄÀÏÀÌ µå¶óÀ̺꿡 ±â·ÏµÇ¾ú´ÂÁö °ËÅäÇÕ´Ï´Ù. Autorun.inf ÆÄÀÏÀÌ ±â·ÏµÇ¾úÀ¸¸é À̵¿½Ä µå¶óÀ̺갡 ÄÄÇ»ÅÍ¿¡ ¿¬°áµÉ ¶§ ½ÇÇàµÉ ¼ö ¾øµµ·Ï Autorun.bad¿Í °°Àº ´Ù¸¥ À̸§À¸·Î ¹Ù²Ù½Ê½Ã¿À.
- Local Admin ¹× Domain Admin ¾ÏÈ£¸¦ ´Ù½Ã ¼³Á¤ÇÏ¿© °·ÂÇÑ »õ ¾ÏÈ£¸¦ »ç¿ëÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
- ¼¼ºÎ Á¤º¸ â¿¡¼ netsvcs Ç׸ñÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼öÁ¤À» Ŭ¸¯ÇÕ´Ï´Ù.
- ÄÄÇ»ÅͰ¡ Win32/Conficker ¹ÙÀÌ·¯½º¿¡ °¨¿°µÈ °æ¿ì ¹«ÀÛÀ§ ¼ºñ½º À̸§ÀÌ ³ª¿µË´Ï´Ù.
Âü°í Win32/Conficker.B¿¡ °¨¿°µÈ °æ¿ì ¼ºñ½º À̸§ÀÌ ¹«ÀÛÀ§ ¹®ÀÚ·Î ¸ñ·Ï ¸Ç ¾Æ·¡¿¡ Ç¥½ÃµÇ¾ú½À´Ï´Ù. ±× ÀÌÈÄ º¯Á¾ÀÇ °æ¿ì ¼ºñ½º À̸§ÀÌ ¸ñ·ÏÀÇ ¾î´À À§Ä¡¿¡³ª ÀÖÀ» ¼ö ÀÖÀ¸¸ç ´õ ÇÕ¹ýÀûÀ¸·Î º¸ÀÏ ¼ö ÀÖ½À´Ï´Ù. ¹«ÀÛÀ§ ¼ºñ½º À̸§ÀÌ ¸Ç ¾Æ·¡¿¡ ÀÖÁö ¾ÊÀ» °æ¿ì ÀÌ ÀýÂ÷ÀÇ "¼ºñ½º Ç¥"¿Í »ç¿ëÀÚ ½Ã½ºÅÛÀ» ºñ±³ÇÏ¿© Win32/Conficker¿¡ ÀÇÇØ Ãß°¡µÇ¾úÀ» ¼ö ÀÖ´Â ¼ºñ½º À̸§À» È®ÀÎÇÕ´Ï´Ù. È®ÀÎÇÏ·Á¸é "¼ºñ½º Ç¥"ÀÇ ¸ñ·Ï°ú °¨¿°µÇÁö ¾ÊÀº °ÍÀ¸·Î ¾Ë·ÁÁø À¯»ç ½Ã½ºÅÛÀ» ºñ±³ÇÕ´Ï´Ù.
¸È¿þ¾î ¼ºñ½º À̸§À» Àû¾îµÎ½Ê½Ã¿À. ÀÌ ÀýÂ÷ µÞºÎºÐ¿¡¼ ÀÌ Á¤º¸°¡ ÇÊ¿äÇÕ´Ï´Ù. -
¸È¿þ¾î ¼ºñ½º¿¡ ´ëÇÑ ÂüÁ¶¸¦ Æ÷ÇÔÇÏ´Â ÁÙÀ» »èÁ¦ÇÕ´Ï´Ù. ¸¶Áö¸·¿¡ ³ª¿µÈ Àû¹ýÇÑ Ç׸ñ ¾Æ·¡¿¡ ºó ÁÙ ¹Ù²ÞÀ» ³ÖÀº ÈÄ È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
¼ºñ½º Ç¥¿¡ ´ëÇÑ Âü°í »çÇ×- ±½°Ô °Á¶ Ç¥½ÃµÈ Ç׸ñÀ» Á¦¿ÜÇÏ°í ¼ºñ½º Ç¥ÀÇ ¸ðµç Ç׸ñÀº À¯È¿ÇÑ Ç׸ñÀÔ´Ï´Ù.
- ±½°Ô °Á¶ Ç¥½ÃµÈ Ç׸ñÀº Win32/Conficker ¹ÙÀÌ·¯½º·Î ÀÎÇØ SVCHOST ·¹Áö½ºÆ®¸® ŰÀÇ netsvcs °ª¿¡ Ãß°¡µÉ ¼ö ÀÖ´Â Ç׸ñÀÇ ¿¹ÀÔ´Ï´Ù.
- ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ Ç׸ñ¿¡ µû¶ó ÀÌ ¸ñ·ÏÀº Àüü ¼ºñ½º ¸ñ·ÏÀÌ ¾Æ´Ò ¼ö ÀÖ½À´Ï´Ù.
- ÀÌ ¼ºñ½º Ç¥´Â ±âº» Windows ¼³Ä¡¿¡ ÇØ´çÇÏ´Â ¼ºñ½º Ç¥ÀÔ´Ï´Ù.
- Win32/Conficker ¹ÙÀÌ·¯½º·Î ÀÎÇØ ¸ñ·Ï¿¡ Ãß°¡µÇ´Â Ç׸ñÀº È¥¶õÈ ±â¼úÀÔ´Ï´Ù. ù ¹øÂ° ¹®ÀÚ°¡ ºñ½ÁÇØ º¸ÀÌ´Â, °Á¶ Ç¥½ÃµÈ ¾Ç¼º Ç׸ñÀº "L"ÀÇ ¼Ò¹®ÀÚÀÔ´Ï´Ù. ±×·¯³ª »ç½Ç ÀÌ ¹®ÀÚ´Â ´ë¹®ÀÚ "I"ÀÔ´Ï´Ù. ¿î¿µ üÁ¦¿¡¼ »ç¿ëµÇ´Â ±Û²Ã ¶§¹®¿¡ ´ë¹®ÀÚ "I"´Â "L"ÀÇ ¼Ò¹®ÀÚó·³ º¸ÀÔ´Ï´Ù.
¼ºñ½º Ç¥
Ç¥ Ãà¼ÒÇ¥ È®´ë
| Windows Server 2008 | Windows Vista | Windows Server 2003 | Windows XP | Windows 2000 |
|---|
| AeLookupSvc | AeLookupSvc | AppMgmt | 6to4 | EventSystem |
| wercplsupport | wercplsupport | AudioSrv | AppMgmt | Ias |
| Themes | Themes | Browser | AudioSrv | Iprip |
| CertPropSvc | CertPropSvc | CryptSvc | Browser | Irmon |
| SCPolicySvc | SCPolicySvc | DMServer | CryptSvc | Netman |
| lanmanserver | lanmanserver | EventSystem | DMServer | Nwsapagent |
| gpsvc | gpsvc | HidServ | DHCP | Rasauto |
| IKEEXT | IKEEXT | Ias | ERSvc | Iaslogon |
| AudioSrv | AudioSrv | Iprip | EventSystem | Rasman |
| FastUserSwitchingCompatibility | FastUserSwitchingCompatibility | Irmon | FastUserSwitchingCompatibility | Remoteaccess |
| Ias | Ias | LanmanServer | HidServ | SENS |
| Irmon | Irmon | LanmanWorkstation | Ias | Sharedaccess |
| Nla | Nla | Messenger | Iprip | Ntmssvc |
| Ntmssvc | Ntmssvc | Netman | Irmon | wzcsvc |
| NWCWorkstation | NWCWorkstation | Nla | LanmanServer | |
| Nwsapagent | Nwsapagent | Ntmssvc | LanmanWorkstation | |
| Rasauto | Rasauto | NWCWorkstation | Messenger | |
| Rasman | Rasman | Nwsapagent | Netman | |
| Iaslogon | Iaslogon | Iaslogon | Iaslogon | |
| Remoteaccess | Remoteaccess | Rasauto | Nla | |
| SENS | SENS | Rasman | Ntmssvc | |
| Sharedaccess | Sharedaccess | Remoteaccess | NWCWorkstation | |
| SRService | SRService | Sacsvr | Nwsapagent | |
| Tapisrv | Tapisrv | Schedule | Rasauto | |
| Wmi | Wmi | Seclogon | Rasman | |
| WmdmPmSp | WmdmPmSp | SENS | Remoteaccess | |
| TermService | TermService | Sharedaccess | Schedule | |
| wuauserv | wuauserv | Themes | Seclogon | |
| BITS | BITS | TrkWks | SENS | |
| ShellHWDetection | ShellHWDetection | TrkSvr | Sharedaccess | |
| LogonHours | LogonHours | W32Time | SRService | |
| PCAudit | PCAudit | WZCSVC | Tapisrv | |
| helpsvc | helpsvc | Wmi | Themes | |
| uploadmgr | uploadmgr | WmdmPmSp | TrkWks | |
| iphlpsvc | iphlpsvc | winmgmt | W32Time | |
| seclogon | seclogon | wuauserv | WZCSVC | |
| AppInfo | AppInfo | BITS | Wmi | |
| msiscsi | msiscsi | ShellHWDetection | WmdmPmSp | |
| MMCSS | MMCSS | uploadmgr | winmgmt | |
| browser | ProfSvc | WmdmPmSN | TermService | |
| winmgmt | EapHost | xmlprov | wuauserv | |
| SessionEnv | winmgmt | AeLookupSvc | BITS | |
| ProfSvc | schedule | helpsvc | ShellHWDetection | |
| EapHost | SessionEnv | | helpsvc | |
| hkmsvc | browser | | xmlprov | |
| schedule | hkmsvc | | wscsvc | |
| AppMgmt | AppMgmt | | WmdmPmSN | |
| sacsvr | | | hkmsvc | |
- ÀÌÀü ÀýÂ÷¿¡¼ ¸È¿þ¾î ¼ºñ½º À̸§À» Àû¾îµÎ¾ú½À´Ï´Ù. ÀÌ ¿¹¿¡¼ ¸È¿þ¾î Ç׸ñ À̸§Àº "Iaslogon"¿´½À´Ï´Ù. ÀÌ Á¤º¸¸¦ »ç¿ëÇÏ¿© ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ Ŭ¸¯ÇÕ´Ï´Ù. ¿©±â¼ BadServiceNameÀº ¸È¿þ¾î ¼ºñ½ºÀÇ À̸§ÀÔ´Ï´Ù.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BadServiceName
¿¹¸¦ µé¾î ´ÙÀ½ ·¹Áö½ºÆ®¸® ۸¦ ã¾Æ¼ Ŭ¸¯ÇÕ´Ï´Ù. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Iaslogon
- Ž»ö â¿¡¼ ¸È¿þ¾î ¼ºñ½º À̸§¿¡ ´ëÇÑ ÇÏÀ§ ۸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ÈÄ »ç¿ë ±ÇÇÑÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- SvcHostÀÇ »ç¿ë ±ÇÇÑ ´ëÈ »óÀÚ¿¡¼ °í±ÞÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- º¸¾È °í±Þ ¼³Á¤ ´ëÈ »óÀÚ¿¡¼
ºÎ¸ð °³Ã¼°¡ °¡Áø »ç¿ë ±ÇÇÑÀ» ÀÚ½Ä °³Ã¼¿¡ Àû¿ë (¿©±â¿¡¼ »õ·Î ¼³Á¤ÇÑ ±ÇÇÑ Æ÷ÇÔ) È®Àζõ°ú
¿©±â¿¡ Ç¥½ÃµÈ ±ÇÇÑÀ¸·Î ÀÚ½Ä °³Ã¼ ±ÇÇÑ ¹Ù²Ù±â È®ÀζõÀ» ¸ðµÎ Ŭ¸¯ÇÏ¿© ¼±ÅÃÇÕ´Ï´Ù.
- F5 ۸¦ ´·¯ ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. ÀÌÁ¦ ¼¼ºÎ Á¤º¸ â¿¡¼ "ServiceDll"·Î ·ÎµåµÈ ¸È¿þ¾î DLLÀ» º¸°í ÆíÁýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ServiceDll Ç׸ñÀ» µÎ ¹ø Ŭ¸¯ÇÕ´Ï´Ù.
- ÂüÁ¶µÈ DLLÀÇ °æ·Î¸¦ Àû¾îµÓ´Ï´Ù. ÀÌ ÀýÂ÷ µÞºÎºÐ¿¡¼ ÀÌ Á¤º¸°¡ ÇÊ¿äÇÕ´Ï´Ù. ¿¹¸¦ µé¾î ÂüÁ¶µÈ DLLÀÇ °æ·Î´Â ´ÙÀ½°ú À¯»çÇÒ ¼ö ÀÖ½À´Ï´Ù.
%SystemRoot%\System32\doieuln.dll
´ÙÀ½°ú °°ÀÌ ÂüÁ¶ À̸§À» ¹Ù²ß´Ï´Ù. %SystemRoot%\System32\doieuln.old
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ·¹Áö½ºÆ®¸®ÀÇ Run ÇÏÀ§ Ű¿¡¼ ¸È¿þ¾î ¼ºñ½º Ç׸ñÀ» Á¦°ÅÇÕ´Ï´Ù.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- µÎ ÇÏÀ§ Ű¿¡¼ "rundll32.exe"·Î ½ÃÀÛÇϰí 12b´Ü°è¿¡¼ ½Äº°ÇÑ "ServiceDll"·Î ·ÎµåµÈ ¸È¿þ¾î DLLÀ» ÂüÁ¶ÇÏ´Â Ç׸ñÀ» ã½À´Ï´Ù. ÀÌ Ç׸ñÀ» »èÁ¦ÇÕ´Ï´Ù.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
- ½Ã½ºÅÛÀÇ µå¶óÀ̺꿡 Autorun.inf ÆÄÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ¸Þ¸ðÀåÀ» »ç¿ëÇÏ¿© °¢ ÆÄÀÏÀ» ¿¬ ÈÄ À¯È¿ÇÑ Autorun.inf ÆÄÀÏÀÎÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½Àº ÀüÇüÀûÀÎ À¯È¿ÇÑ Autorun.inf ÆÄÀÏÀÇ ¿¹ÀÔ´Ï´Ù.
[autorun]
shellexecute=Servers\splash.hta *DVD*
icon=Servers\autorun.ico
À¯È¿ÇÑ Autorun.infÀÇ Å©±â´Â ÀϹÝÀûÀ¸·Î 1-2KBÀÔ´Ï´Ù. - ¿Ã¹Ù¸£Áö ¾ÊÀº °ÍÀ¸·Î º¸ÀÌ´Â Autorun.inf ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.
- ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
- ¼û±è ÆÄÀÏÀ» º¸ÀÌ°Ô ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 0x1 /f
- ÀÌ ÆÄÀÏÀÌ º¸À̵µ·Ï ¼û±è ÆÄÀÏ ¹× Æú´õ Ç¥½Ã¸¦ ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- 12b´Ü°è¿¡¼ ¸È¿þ¾î¿¡ ´ëÇÑ ÂüÁ¶µÈ .dll ÆÄÀÏÀÇ °æ·Î¸¦ Àû¾î µÎ¾ú½À´Ï´Ù. ¿¹¸¦ µé¾î ´ÙÀ½°ú ºñ½ÁÇÑ °æ·Î¸¦ Àû¾î µÎ¾úÀ» °ÍÀÔ´Ï´Ù.
%systemroot%\System32\doieuln.dll
Windows Ž»ö±â¿¡¼ %systemroot%\System32 µð·ºÅ͸® ¶Ç´Â ¸È¿þ¾î°¡ µé¾î ÀÖ´Â µð·ºÅ͸®¸¦ ¿±´Ï´Ù. - µµ±¸¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ Æú´õ ¿É¼ÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- º¸±â ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¼û±è ÆÄÀÏ ¹× Æú´õ Ç¥½Ã È®ÀζõÀ» ¼±ÅÃÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- .dll ÆÄÀÏÀ» ¼±ÅÃÇÕ´Ï´Ù.
- Everyone¿¡ ´ëÇØ ¸ðµç ±ÇÇÑÀ» Ãß°¡ÇÏ·Á¸é ÆÄÀÏ¿¡ ´ëÇÑ »ç¿ë ±ÇÇÑÀ» ÆíÁýÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- .dll ÆÄÀÏÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÑ ´ÙÀ½ ¼Ó¼ºÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- º¸¾È ÅÇÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- EveryoneÀ» Ŭ¸¯ÇÑ ÈÄ Çã¿ë ¿¿¡¼ ¸ðµç ±ÇÇÑ È®ÀζõÀ» Ŭ¸¯ÇÏ¿© ¼±ÅÃÇÕ´Ï´Ù.
- È®ÀÎÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- ¸È¿þ¾î¿¡ ´ëÇÑ ÂüÁ¶µÈ .dll ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù. ¿¹¸¦ µé¾î %systemroot%\System32\doieuln.dll ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.
- ¼ºñ½º MMC(Microsoft Management Console)¸¦ »ç¿ëÇÏ¿© BITS, ÀÚµ¿ ¾÷µ¥ÀÌÆ®, ¿À·ù º¸°í ¹× Windows Defender ¼ºñ½º¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤ÇÕ´Ï´Ù.
- AutorunÀ» ÇØÁ¦ÇÏ¿© Àç°¨¿° °¡´É¼ºÀ» ÁÙÀÔ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- »ç¿ë ÁßÀÎ ½Ã½ºÅÛ¿¡ µû¶ó ´ÙÀ½ ¾÷µ¥ÀÌÆ® Áß Çϳª¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
- Windows 2000, Windows XP ¶Ç´Â Windows Server 2003À» ½ÇÇà ÁßÀÎ °æ¿ì ¾÷µ¥ÀÌÆ® 967715¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
967715
(http://support.microsoft.com/kb/967715/ko/
)
Windows¿¡¼ ÀÚµ¿ ½ÇÇà ±â´ÉÀ» ºñȰ¼ºÈÇÏ´Â ¹æ¹ý
- Windows Vista ¶Ç´Â Windows Server 2008À» ½ÇÇà ÁßÀÎ °æ¿ì º¸¾È ¾÷µ¥ÀÌÆ® 950582¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
950582
(http://support.microsoft.com/kb/950582/ko/
)
MS08-038: Windows ExplorerÀÇ Ãë¾à¼ºÀ¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦
Âü°í ¾÷µ¥ÀÌÆ® 967715 ¹× º¸¾È ¾÷µ¥ÀÌÆ® 950582´Â ÀÌ ¸È¿þ¾î ¹®Á¦¿Í °ü·ÃÀÌ ¾ø½À´Ï´Ù. 23b´Ü°è¿¡¼ ·¹Áö½ºÆ®¸® ±â´ÉÀ» »ç¿ëÇϵµ·Ï ¼³Á¤Çϱâ À§ÇØ ÀÌ·¯ÇÑ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. - ¸í·É ÇÁ·ÒÇÁÆ®¿¡ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoDriveTypeAutoRun /t REG_DWORD /d 0xff /f
- ½Ã½ºÅÛ¿¡¼ Windows Defender¸¦ ½ÇÇà ÁßÀÎ °æ¿ì Windows Defender ÀÚµ¿ ½ÃÀÛ À§Ä¡¸¦ ´Ù½Ã »ç¿ë °¡´ÉÇÏ°Ô ¼³Á¤ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Windows Defender" /t REG_EXPAND_SZ /d "%ProgramFiles%\Windows Defender\MSASCui.exe ?hide" /f
-
Windows Vista ÀÌ»ó ¿î¿µ üÁ¦ÀÇ °æ¿ì ¸È¿þ¾î´Â TCP ¼ö½Å â ÀÚµ¿ Á¶Á¤¿¡ ´ëÇÑ Àü¿ª ¼³Á¤À» »ç¿ë ºÒ°¡´ÉÇÏ°Ô º¯°æÇÕ´Ï´Ù. ÀÌ ¼³Á¤À» ´Ù½Ã º¯°æÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
netsh interface tcp set global autotuning=normal
ÀÌ ÀýÂ÷¸¦ ¿Ï·áÇÑ ÈÄ¿¡ ÄÄÇ»ÅͰ¡ Àç°¨¿°µÈ °Íó·³ ³ªÅ¸³¯ °æ¿ì ´ÙÀ½ »óȲ Áß ÇϳªÀÏ ¼ö ÀÖ½À´Ï´Ù.
- ÀÚµ¿ ½ÃÀÛ À§Ä¡ Áß Çϳª°¡ Á¦°ÅµÇÁö ¾Ê¾Ò½À´Ï´Ù. ¿¹¸¦ µé¾î AT ÀÛ¾÷ÀÌ Á¦°ÅµÇÁö ¾Ê¾Ò°Å³ª Autorun.inf ÆÄÀÏÀÌ Á¦°ÅµÇÁö ¾Ê¾Ò½À´Ï´Ù.
- MS08-067¿ë º¸¾È ¾÷µ¥ÀÌÆ®°¡ Á¦´ë·Î ¼³Ä¡µÇÁö ¾Ê¾Ò½À´Ï´Ù.
ÀÌ ¸È¿þ¾î´Â ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾ÊÀº ´Ù¸¥ ¼³Á¤À» º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù. Win32/Conficker¿¡ ´ëÇÑ Ãֽм¼ºÎ Á¤º¸¸¦ º¸·Á¸é ´ÙÀ½ Microsoft Malware Protection Center À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇϽʽÿÀ.
½Ã½ºÅÛÀÌ Á¤¸®µÇ¾ú´ÂÁö È®ÀÎ
´ÙÀ½ ¼ºñ½º°¡ ½ÃÀ۵Ǿú´ÂÁö È®ÀÎÇϽʽÿÀ.
- ÀÚµ¿ ¾÷µ¥ÀÌÆ®(wuauserv)
- BITS(Background Intelligent Transfer Service)
- Windows Defender(windefend)(Àû¿ë °¡´ÉÇÑ °æ¿ì)
- Windows ¿À·ù º¸°í ¼ºñ½º
ÀÌ·¸°Ô ÇÏ·Á¸é ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÑ ´ÙÀ½ °¢ ¸í·É ´ÙÀ½¿¡ Enter ۸¦ ´©¸¨´Ï´Ù.
Sc.exe query wuauservSc.exe query bitsSc.exe query windefendSc.exe query ersvc
°¢ ¸í·ÉÀÌ ½ÇÇàµÈ ÈÄ¿¡ ´ÙÀ½°ú ºñ½ÁÇÑ ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
SERVICE_NAME: wuauserv
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 4 RUNNING
(STOPPABLE,NOT_PAUSABLE,ACCEPTS_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
ÀÌ ¿¹¿¡¼ "STATE : 4 RUNNING"Àº ¼ºñ½º°¡ ½ÇÇàµÇ°í ÀÖÀ½À» ³ªÅ¸³À´Ï´Ù.
SvcHost ·¹Áö½ºÆ®¸® ÇÏÀ§ ŰÀÇ »óŸ¦ È®ÀÎÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
- ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼ ´ÙÀ½ ·¹Áö½ºÆ®¸® ÇÏÀ§ ۸¦ ã¾Æ ¼±ÅÃÇÕ´Ï´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
- ¼¼ºÎ Á¤º¸ â¿¡¼ netsvcs¸¦ µÎ ¹ø Ŭ¸¯ÇÑ ÈÄ ³ª¿µÈ ¼ºñ½º À̸§À» °ËÅäÇÕ´Ï´Ù. ¸ñ·Ï ¸Ç ¾Æ·¡·Î ½ºÅ©·ÑÇÕ´Ï´Ù. ÄÄÇ»ÅͰ¡ Conficker¿¡ Àç°¨¿°µÈ °æ¿ì ¹«ÀÛÀ§ ¼ºñ½º À̸§ÀÌ ³ª¿µË´Ï´Ù. ¿¹¸¦ µé¾î ÀÌ ÀýÂ÷¿¡¼´Â ¸È¿þ¾î ¼ºñ½º À̸§ÀÌ "Iaslogon"ÀÔ´Ï´Ù.
ÀÌ·¯ÇÑ ÀÛ¾÷À¸·Î ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ¾øÀ¸¸é ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü¿¡ ¹®ÀÇÇϽʽÿÀ.
ÀÌ ¹®Á¦¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
49500
(http://support.microsoft.com/kb/49500/ko/
)
¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü ¸ñ·Ï
¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü°¡ ¾ø°Å³ª ¹ÙÀÌ·¯½º ¹é½Å ¼ÒÇÁÆ®¿þ¾î °ø±Þ¾÷ü°¡ µµ¿òÀ» ÁÙ ¼ö ¾ø´Â °æ¿ì Microsoft ±â¼ú Áö¿ø ¼ºñ½º¿¡ ¹®ÀÇÇϽʽÿÀ.
ȯ°æ Á¤¸®°¡ ¿Ï·áµÈ °æ¿ì
ȯ°æ Á¤¸® ÀÛ¾÷ÀÌ ¿Ï·áµÇ¾úÀ¸¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.
- ¼¹ö ¼ºñ½º ¹× ÀÛ¾÷ ½ºÄÉÁÙ·¯ ¼ºñ½º¸¦ ´Ù½Ã »ç¿ëÇϵµ·Ï ¼³Á¤ÇÕ´Ï´Ù.
- SVCHOST ·¹Áö½ºÆ®¸® Ű ¹× Tasks Æú´õ¿¡ ´ëÇÑ ±âº» »ç¿ë ±ÇÇÑÀ» º¹¿øÇÕ´Ï´Ù. ±âº» »ç¿ë ±ÇÇÑÀº ±×·ì Á¤Ã¥ ¼³Á¤À» »ç¿ëÇÏ¿© ±âº» ¼³Á¤À¸·Î µÇµ¹·Á¾ß ÇÕ´Ï´Ù. Á¤Ã¥ÀÌ Á¦°ÅµÈ °æ¿ì¿¡´Â ±âº» »ç¿ë ±ÇÇÑÀ» º¹¿øÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº "¿ÏÈ ´Ü°è" ¼½¼ÇÀÇ ±âº» »ç¿ë ±ÇÇÑ Ç¥¸¦ ÂüÁ¶ÇϽʽÿÀ.
- ´©¶ôµÈ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÏ¿© ÄÄÇ»Å͸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é Windows Update, WSUS(Microsoft Windows Server Update Services) ¼¹ö, SMS(Systems Management Server), System Center Configuration Manager(Configuration Manager 2007) ¶Ç´Â Ÿ»ç ¾÷µ¥ÀÌÆ® °ü¸® Á¦Ç°À» »ç¿ëÇÕ´Ï´Ù. SMS ¶Ç´Â Configuration Manager 2007À» »ç¿ëÇÒ °æ¿ì ¸ÕÀú ¼¹ö ¼ºñ½º¸¦ ´Ù½Ã »ç¿ëÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ±×·¸Áö ¾ÊÀº °æ¿ì ½Ã½ºÅÛÀ» ¾÷µ¥ÀÌÆ®Çϱâ À§ÇØ SMS ¶Ç´Â Configuration Manager 2007À» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Conficker¿¡ °¨¿°µÈ ½Ã½ºÅÛÀ» ½Äº°ÇÏ´Â µ¥ ¹®Á¦°¡ ÀÖÀ» °æ¿ì ´ÙÀ½ TechNet ºí·Î±×¿¡ Á¦°øµÈ ¼¼ºÎ Á¤º¸¸¦ ÂüÁ¶ÇϽʽÿÀ.
´ÙÀ½ Ç¥¿¡¼´Â °¢ ¿î¿µ üÁ¦¿¡ ´ëÇÑ ±âº» »ç¿ë ±ÇÇÑÀ» º¸¿© ÁÝ´Ï´Ù. ÀÌ ¹®¼¿¡¼ ±ÇÀåÇÏ´Â º¯°æ ³»¿ëÀ» Àû¿ëÇϱâ Àü¿¡ ±âº»ÀûÀ¸·Î ÀÌ·¯ÇÑ »ç¿ë ±ÇÇÑÀÌ ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù. ±×·¯³ª ÀÌ »ç¿ë ±ÇÇÑÀº »ç¿ëÀÚ È¯°æ¿¡ ¼³Á¤µÇ¾î ÀÖ´Â »ç¿ë ±ÇÇѰú ´Ù¸¦ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¹Ç·Î º¯°æÇϱâ Àü¿¡ »ç¿ëÀÚÀÇ ¼³Á¤À» Àû¾î µÎ¾î¾ß ÇÕ´Ï´Ù. ½Ã½ºÅÛÀ» Á¤¸®ÇÑ ÈÄ »ç¿ëÀÚÀÇ ¼³Á¤À» º¹¿øÇÒ ¼ö ÀÖµµ·Ï Àû¾î µÎ´Â °ÍÀÔ´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
| ¿î¿µ üÁ¦ | Windows Server 2008 | | Windows Vista | | Windows Server 2003 | | Windows XP | | Windows 2000 | |
|---|
| ¼³Á¤ | Svchost ·¹Áö½ºÆ®¸® | Tasks Æú´õ | Svchost ·¹Áö½ºÆ®¸® | Tasks Æú´õ | Svchost ·¹Áö½ºÆ®¸® | Tasks Æú´õ | Svchost ·¹Áö½ºÆ®¸® | Tasks Æú´õ | Svchost ·¹Áö½ºÆ®¸® | Tasks Æú´õ |
| °èÁ¤ | | | | | | | | | | |
| Administrators(·ÎÄà ±×·ì) | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ |
| System | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ | ¸ðµç ±ÇÇÑ |
| Power Users(·ÎÄà ±×·ì) | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ |
| Users(·ÎÄà ±×·ì) | Ư¼ö | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ | Àбâ | ÇØ´ç »çÇ× ¾øÀ½ |
| Àû¿ë ´ë»ó: ÀÌ Å° ¹× ÇÏÀ§ Ű | | Àû¿ë ´ë»ó: ÀÌ Å° ¹× ÇÏÀ§ Ű | | | | | | | |
| °ª Äõ¸® | | °ª Äõ¸® | | | | | | | |
| ÇÏÀ§ Ű ¿°Å | | ÇÏÀ§ Ű ¿°Å | | | | | | | |
| ¾Ë¸² | | ¾Ë¸² | | | | | | | |
| Àбâ Á¦¾î | | Àбâ Á¦¾î | | | | | | | |
| ÀÎÁõµÈ »ç¿ëÀÚ | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ |
| | Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸ | | Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸ | | | | | | |
| | Æú´õ Æ®·¡¹ö½º | | Æú´õ Æ®·¡¹ö½º | | | | | | |
| | Æú´õ ¿°Å | | Æú´õ ¿°Å | | | | | | |
| | Ư¼º Àбâ | | Ư¼º Àбâ | | | | | | |
| | È®Àå Æ¯¼º Àбâ | | È®Àå Æ¯¼º Àбâ | | | | | | |
| | ÆÄÀÏ ¸¸µé±â | | ÆÄÀÏ ¸¸µé±â | | | | | | |
| | »ç¿ë ±ÇÇÑ Àбâ | | »ç¿ë ±ÇÇÑ Àбâ | | | | | | |
| Backup Operators(·ÎÄà ±×·ì) | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö | | |
| | | | | | Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸ | | Àû¿ë ´ë»ó: ÀÌ Æú´õ¸¸ | | |
| | | | | | Æú´õ Æ®·¡¹ö½º | | Æú´õ Æ®·¡¹ö½º | | |
| | | | | | Æú´õ ¿°Å | | Æú´õ ¿°Å | | |
| | | | | | Ư¼º Àбâ | | Ư¼º Àбâ | | |
| | | | | | È®Àå Æ¯¼º Àбâ | | È®Àå Æ¯¼º Àбâ | | |
| | | | | | ÆÄÀÏ ¸¸µé±â | | ÆÄÀÏ ¸¸µé±â | | |
| | | | | | »ç¿ë ±ÇÇÑ Àбâ | | »ç¿ë ±ÇÇÑ Àбâ | | |
| ¸ðµç »ç¶÷ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | ÇØ´ç »çÇ× ¾øÀ½ | Ư¼ö |
| | | | | | | | | | Àû¿ë ´ë»ó: ÀÌ Æú´õ, ÇÏÀ§ Æú´õ ¹× ÆÄÀÏ |
| | | | | | | | | | Æú´õ Æ®·¡¹ö½º |
| | | | | | | | | | Æú´õ ¿°Å |
| | | | | | | | | | Ư¼º Àбâ |
| | | | | | | | | | È®Àå Æ¯¼º Àбâ |
| | | | | | | | | | ÆÄÀÏ ¸¸µé±â |
| | | | | | | | | | Æú´õ ¸¸µé±â |
| | | | | | | | | | Ư¼º ¾²±â |
| | | | | | | | | | È®Àå Æ¯¼º ¾²±â |
| | | | | | | | | | »ç¿ë ±ÇÇÑ Àбâ |
? ÀÌ ¹®Á¦¿¡ ´ëÇØ µµ¿òÀÌ ÇÊ¿äÇÑ °æ¿ì ¹Ì±¹¿¡ °ÅÁÖÇÏ´Â °í°´Àº Answer Desk¿¡¼ Á÷Á¢ ´ã´çÀÚ¿Í ´ëÈÇÒ ¼ö ÀÖ½À´Ï´Ù.?
Answer Desk
(https://answerdesk.support.microsoft.com/default.aspx?mkt=en-us&skuid=4&partnerid=smc&rejoin=0&psrc=ms_smc&entryid=kb_962007_inline&prodcat=virus&productkey=awasaoffervirusremoval)
Âü°í À̰ÍÀº Microsoft ±â¼ú Áö¿ø ¼ºñ½º ³»¿¡¼ Á÷Á¢ ÀÛ¼ºÇÑ ¡°ºü¸¥ °Ô½Ã¡± ¹®¼ÀÔ´Ï´Ù. ¿©±â¿¡ Æ÷ÇÔµÈ Á¤º¸´Â ¹ß»ýÇÑ ¹®Á¦¿¡ ´ëÇØ ÀÖ´Â ±×´ë·Î Á¦°øµË´Ï´Ù. ÀÌ ¹®¼´Â Áï½Ã ÂüÁ¶ÇÒ ¼ö ÀÖµµ·Ï ºü¸£°Ô ÀÛ¼ºµÇ¾î¼ Ç¥±â»óÀÇ ¿À·ù°¡ Æ÷ÇԵǾî ÀÖÀ» ¼ö ÀÖ°í ¾ðÁ¦µçÁö ¿¹°í ¾øÀÌ ¼öÁ¤µÉ ¼ö ÀÖ½À´Ï´Ù. ±âŸ °í·Á »çÇ×Àº
»ç¿ë ¾à°ü
(http://go.microsoft.com/fwlink/?LinkId=151500)
À» ÂüÁ¶ÇϽʽÿÀ.
Á¤º¸
±â¼ú ÀÚ·á: 962007 - ¸¶Áö¸· °ËÅä: 2013³â 1¿ù 16ÀÏ ¼ö¿äÀÏ - ¼öÁ¤: 1.0
º» ¹®¼ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
- Windows Server 2008 Datacenter without Hyper-V
- Windows Server 2008 Enterprise without Hyper-V
- Windows Server 2008 for Itanium-Based Systems
- Windows Server 2008 Standard without Hyper-V
- Windows Server 2008 Datacenter
- Windows Server 2008 Enterprise
- Windows Server 2008 Standard
- Windows Web Server 2008
- Windows Vista Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Windows Vista Business
- Windows Vista Enterprise
- Windows Vista Home Basic
- Windows Vista Home Premium
- Windows Vista Starter
- Windows Vista Ultimate
- Windows Vista Enterprise 64-bit edition
- Windows Vista Home Basic 64-bit edition
- Windows Vista Home Premium 64-bit edition
- Windows Vista Ultimate 64-bit edition
- Windows Vista Business 64-bit edition
- Windows Vista Business
- Windows Vista Enterprise
- Windows Vista Home Basic
- Windows Vista Home Premium
- Windows Vista Starter
- Windows Vista Ultimate
- Windows Vista Enterprise 64-bit edition
- Windows Vista Home Basic 64-bit edition
- Windows Vista Home Premium 64-bit edition
- Windows Vista Ultimate 64-bit edition
- Windows Vista Business 64-bit edition
- Microsoft Windows Server 2003 Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Web Edition
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Web Edition
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Microsoft Windows XP Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional
- Microsoft Windows XP Service Pack 3?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional
- Microsoft Windows 2000 ¼ºñ½º ÆÑ 4?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional Edition
- Microsoft Windows 2000 Server
| kbsccm kbregistry kbexpertiseinter kbsecurity kbsecvulnerability kbsurveynew KB962007 |