´äÀåÇϱ⠵¹¾Æ°¡±â

   ¿î¿µÀÚ´Ô Win32/MTX¿¡ °¨¿°µÇ¾î ÀÖ½À´Ï´Ù. õÀç¸Ç on 02/05/01
¿î¿µÀÚ´Ô Win32/MTX¿¡ °¨¿°µÇ¾î ÀÖ½À´Ï´Ù.
http://home.ahnlab.com/download/v3neo.html
¿©±â¼­ V3 ÃֽŹöÁ¯À¸·Î ²À °Ë»çÇϽñæ...

Win32/MTX ¹ÙÀÌ·¯½º´Â I-Worm.MTX, I-Worm.Win32.MTX, PE_MTX.A, W95.MTX.dr, W32/MTX@MM, W32/Apology µîÀ¸·Î ºÒ¸®´Â ¹ÙÀÌ·¯½º·Î ÀڽŵéÀ» '[MATRix]'·Î ºÎ¸£´Â ¹ÙÀÌ·¯½º Á¦ÀÛ ±×·ì¿¡¼­ Á¦ÀÛÇÑ °ÍÀ¸·Î ÃßÁ¤µÈ´Ù.
2000³â 8¿ù 23ÀÏ ¹ß°ßµÇ¾úÀ¸¸ç ±¹³»¿¡´Â 9¿ù 9ÀÏ ¹ß°ßµÇ¾ú´Ù.

»ç¿ëÀÚ°¡ °¨¿°µÈ ÆÄÀÏÀ» ½ÇÇàÇϸé À©µµ¿ì µð·ºÅ丮( ÀϹÝÀûÀ¸·Î
C:\Windows Æú´õ )¿¡ ´ÙÀ½ ÆÄÀÏÀÌ »ý¼ºµÈ´Ù. ´Ü, ¸î¸î ÆÄÀÏÀº ¼û±è ¼Ó¼ºÀ¸·Î Windows Ž»ö±â·Î ãÁö ¸øÇÒ ¼öµµ ÀÖ´Ù.

IE_PACK.EXE ( ¹ÙÀÌ·¯½º º»Ã¼ - 18483 ¹ÙÀÌÆ® )
WIN32.DLL ( ¹ÙÀÌ·¯½º º»Ã¼ - 18483 ¹ÙÀÌÆ® )
MTX_.EXE ( ¹éµµ¾î ÇÁ·Î±×·¥ - 6144 ¹ÙÀÌÆ® )

·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ÀÇ Ç׸ñµéÀÌ Ãß°¡µÇ¸ç, ºÎÆÃ½Ã¸¶´Ù ¹éµµ¾î ÇÁ·Î±×·¥À» ½ÇÇàÇÏ°Ô µÈ´Ù.

HKEY_LOCAL_MACHINE\Software\[MATRix]
: ¾Æ¹« ¿ªÇÒµµ ÇÏÁö ¾ÊÀ½

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run Ç׸ñ¿¡
SystemBackup = "C:\WINDOWS\MTX_.EXE"

À©µµ¿ì ½Ã½ºÅÛ Æú´õ ( ÀϹÝÀûÀ¸·Î C:\Windows\System ) Æú´õ¿¡ WSOCK32.MTX ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ÀÌ ÆÄÀÏÀº, WSOCK32.DLL ÆÄÀÏÀ» °¨¿°½ÃŲ °ÍÀ¸·Î ´ÙÀ½¹ø ºÎÆÃ¶§ WSOCK32.MTX ÆÄÀÏÀÌ WSOCK32.DLL ÆÄÀÏ·Î ´ëüµÈ´Ù.

ÀÌÈÄ »ç¿ëÀÚ°¡ ¿ÜºÎ ¸ÞÀÏ ¼­¹ö (SMTP)¸¦ »ç¿ëÇØ¼­ ¸ÞÀÏÀ» º¸³¾
°æ¿ì »ç¿ëÀÚ°¡ º¸³½ ¸ÞÀÏ ¿Ü¿¡ ¹ÙÀÌ·¯½º ÆÄÀÏÀÌ Ã·ºÎµÈ ¸ÞÀÏÀÌ
º°µµ·Î Àü¼ÛµÈ´Ù.

¸ÞÀÏÀÇ Á¦¸ñÀº ¾øÀ¸¸ç ÷ºÎ ÆÄÀÏÀº ´ÙÀ½ Áß Çϳª°¡ µÈ´Ù.

ALANIS_Screen_Saver.SCR
ANTI_CIH.EXE
AVP_Updates.EXE
BILL_GATES_PIECE.JPG.pif
BLINK_182.MP3.pif
' FEITICEIRA_NUA.JPG.pif
FREE_xxx_sites.TXT.pif
FUCKING_WITH_DOGS.SCR
Geocities_Free_sites.TXT.pif
HANSON.SCR
I_am_sorry.DOC.pif
I_wanna_see_YOU.TXT.pif
INTERNET_SECURITY_FORUM.DOC.pif
IS_LINUX_GOOD_ENOUGH!.TXT.pif
JIMI_HMNDRIX.MP3.pif
LOVE_LETTER_FOR_YOU.TXT.pif
MATRiX_2_is_OUT.SCR
MATRiX_Screen_Saver.SCR
Me_nude.AVI.pif
METALLICA_SONG.MP3.pif
NEW_NAPSTER_site.TXT.pif
NEW_playboy_Screen_saver.SCR
Protect_your_credit.HTML.pif
QI_TEST.EXE
READER_DIGEST_LETTER.TXT.pif
SEICHO-NO-IE.EXE
Sorry_about_yesterday.DOC.pif
TIAZINHA.JPG.pif
WIN_$100_NOW.DOC.pif
YOU_are_FAT!.TXT.pif
zipped_files.EXE

¸î¸î ¹é½Å ¾÷ü·Î´Â ¸ÞÀÏÀ» º¸³¾ ¼ö ¾ø°ÔÇØ ¹ÙÀÌ·¯½º ¹ß°ß ½Ã±â¸¦ ´ÊÃá´Ù.

´ÙÀ½°ú °°Àº ¹®ÀÚ¿­À» Æ÷ÇÔÇϰí ÀÖ´Ù.

"Software provied by [MATRiX] VX team:
Ultras, Mort, Nbk, LOrd DArk, Del_Armg0, Anaktos
Greetz:
All VX guy on #virus channel and Vecna
Visit us : ( Matrix ±×·ì À¥»çÀÌÆ® )
"

¹éµµ¾î ¿ªÇÒÀ» ÇÏ´Â MTX_.EXE ÆÄÀÏÀº V3 Á¦Ç°±º¿¡¼±
'Win-Trojan/MTX.6144'·Î Áø´ÜÇÑ´Ù.

¹éµµ¾î´Â ´ÙÀ½°ú °°Àº ¹®ÀÚ¿­À» Æ÷ÇÔÇϰí ÀÖ´Ù

"Software provide by [MATRiX] team:
Ultras, Mort, Nbk, LOrd DArk, Del_Armg0, Anaktos
Greetz:
Vecna 4 source codes and ideas,"

<Ä¡·á¹æ¹ý>
Win32/MTX ¹ÙÀÌ·¯½º´Â ´ÙÀ½ÀÇ ¹æ¹ýÀ¸·Î Ä¡·áÇÒ ¼ö ÀÖ½À´Ï´Ù.


¡Ø Ä¡·á½Ã ÁÖÀÇÁ¡

È®ÀåÀÚ°¡ SCR, PIF·Î ÷ºÎµÈ ÆÄÀÏÀÇ °æ¿ì V3 Á¦Ç°¿¡¼­ °Ë»ç
ÆÄÀÏ ´ë»óÀÌ '½ÇÇà ÆÄÀÏ °Ë»ç'·Î ¼³Á¤µÇ¾î ÀÖ´Ù¸é SCR, PIF ÆÄ
ÀÏÀ» ±âº»À¸·Î Áø´ÜÇÏÁö ¾ÊÀ¸¹Ç·Î °Ë»ç ´ë»óÀ» '¸ðµç ÆÄÀÏ'·Î
º¯°æÇϰųª ½ÇÇà ÆÄÀϰú ÇÔ²² ȯ°æ¼³Á¤ÀÇ ¼öµ¿°Ë»ç¿¡¼­
'»ç¿ëÀÚ Á¤ÀÇ Çü½Ä °Ë»ç'¿¡ PIF, SCR È®ÀåÀÚ¸¦ Ãß°¡½ÃÄÑ °Ë»çÇÕ
´Ï´Ù. ¶ÇÇÑ V3+ Neo »ç¿ëÀÚ °æ¿ì °Ë»ç½Ã /A ¿É¼Ç (¸ðµçÆÄÀϰË
»ç)À» ÁÖ¾î °Ë»çÇÕ´Ï´Ù.

¡Ø Ä¡·á½Ã Âü°í »çÇ×

¿£Áø¾÷µ¥ÀÌÆ®½Ã 'ÆÐÄ¡ÆÄÀÏ' ±îÁö üũ¸¦ ÇϽÅÈÄ ¾÷µ¥ÀÌÆ®
ÇϽøé Win32/MTX ¿¡ °¨¿°µÇ¾ú´ø WSOCK32.DLL ÆÄÀÏÀ»
´Ù¸¥ PC¿¡¼­ º¹»çÇÏÁö ¾Ê¾Æµµ V3Pro 2000 Deluxe°¡ Ä¡·á½Ã
¼öÁ¤À» Çϸç V3+ Neo »ç¿ëÀںР¿ª½Ã ȨÆäÀÌÁö¿¡¼­ ÃֽŹöÀüÀ»
´Ù¿î¹Þ¾Æ Ä¡·áÇÏ½Ã¸é µË´Ï´Ù.

- V3+ Neo »ç¿ëÀÚ

1. Ãֽг¯Â¥ÀÇ ¿£ÁøÀ» »ç¿ëÇÑ V3+ Neo¸¦ ´Ù¿î·Îµå ¹Þ¾Æ ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇÕ´Ï´Ù.

2. À©µµ¿ì ºÎÆÃ½Ã¿¡ (F8)۸¦ ´­·¯ Command Prompt Only Mode·Î
ºÎÆÃÇϰųª ½Ã½ºÅÛ Á¾·á½Ã¿¡ 'MS-DOS¿¡¼­ ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛ'À¸
·Î ½Ã½ºÅÛÀ» Á¾·áÇØ¼­ µµ½º ¸ðµå·Î ºÎÆÃÇÕ´Ï´Ù.

(¿¹) v3 c: /a

´ÙÀ½ÀÇ ÆÄÀÏÀÌ Áø´ÜµÈ´Ù¸é »èÁ¦ÇÕ´Ï´Ù.

IE_PACK.EXE / WIN32.DLL / MTX_.EXE / WSOCK32.MTX

3. À©µµ¿ì ÀçºÎÆÃÈÄ¿¡ ¹ÙÅÁÈ­¸é¿¡¼­ '½ÃÀÛ' -> '½ÇÇà' ÀԷ â¿¡
¼­ regedit¸¦ ÀÔ·ÂÇØ¼­ ½ÇÇàÇÑ ÈÄ¿¡ ´ÙÀ½ÀÇ Å°¸¦ ã¾Æ »èÁ¦ÇÕ´Ï
´Ù.

HKEY_LOCAL_MACHINE
\Software
\Microsoft
\Windows
\CurrentVersion
\Run

SystemBackup = "C:\WINDOWS\MTX_.EXE" <- »èÁ¦

- V3Pro 2000 Deluxe »ç¿ëÀÚ

1. Ãֽг¯Â¥ÀÇ ¿£ÁøÀ¸·Î ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.(À̶§ ¿£Áø ¾÷µ¥ÀÌÆ®
¿Í ÇÁ·Î±×·¥ ÆÐÄ¡±îÁö ÇØÁÖ¾î¾ß ÇÕ´Ï´Ù.)

2. V3Pro 2000 Deluxe¸¦ ½ÇÇàÇØ¼­ ȯ°á¼³Á¤ - ¼öµ¿°Ë»ç, ÀÎÅͳÝ
/½Ã½ºÅÛ °¨½Ã ºÎºÐ¿¡¼­ 'ÆÄÀÏÇü½Ä'À» '¸ðµç ÆÄÀÏ °Ë»ç'·Î ¼³Á¤
ÇØ ½Ã½ºÅÛÀ» ¹ÙÀÌ·¯½º °Ë»ç / Ä¡·áÇÕ´Ï´Ù.

3. ¹ÙÀÌ·¯½º Áø´ÜÁß¿¡ ÀÎÅͳÝÀÌ »ç¿ëÁßÀ̶ó¸é WSOCK32.DLL ÆÄÀÏ
À» Ä¡·áÇϱâ À§ÇØ ½Ã½ºÅÛÀ» ÀçºÎÆÃÇϸç ÀÎÅͳÝÀ» »ç¿ëÁßÀÌ ¾Æ´Ï
¶ó¸é ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÏÁö ¾Ê°í Ä¡·áµË´Ï´Ù.

  
Follow Ups:

    ¾È³çÇϼ¼¿ä? ¿î¿µÀÚÀÔ´Ï´Ù.

    ¿ì¼± Win32/MTX¿¡ °¨¿°µÇ¾ú´Ù´Â ±ÛÀ» ¿Ã¸®½Å õÀç¸Ç´Ô¿¡°Ô °¨»ç¸¦ µå¸³´Ï´Ù. ³ª¸§´ë·Î anti-virusÇÁ·Î±×·¥À» ¼³Ä¡ÇÏ¿© ¿î¿µÇϰí ÀÖÀ¸³ª ÁöÀûÇϽŠ´ë·Î Win32/MTX¿¡ °¨¿°µÇ¾úÀ½ÀÌ È®ÀεǾú½À´Ï´Ù.

    ¾Æ¸¶µµ ÀúÈñ°¡ »ó´ãÀ» ÇÏ´Â °úÁ¤¿¡¼­ Win32/MTX ÀÌ °¨¿°µÈ emailÀÌ ÀúÈñ¿¡°Ô Àü´ÞµÈ °Í °°À¸¸ç °°Àº ÀÌÀ¯·Î ÀúÈñ°¡ »ó´ãÇÏ¿© µå¸° ´äº¯À» ¹ÞÀ¸½Å ºÐµéÁß¿¡¼­µµ Win32/MTX ÀÌ °¨¿°µÇ¾úÀ» °¡´É¼ºÀÌ ÀÖÀ» °ÍÀ¸·Î »ý°¢µË´Ï´Ù.

    Win32/MTX ÀÌ °¨¿°µÇ¾úÀ» °ÍÀ¸·Î »ý°¢µÇ½Ã°Å³ª ÇѹøÂë ÀÚ½ÅÀÇ ÄÄÇ»Å͸¦ virus¸¦ üũÇϽðíÀÚ ÇϽô ºÐÀº õÀç¸Ç´ÔÀÌ ¾Ë·ÁÁֽйæ¹ý´ë·Î http://home.ahnlab.com/download/v3neo.html ¸¦ Ŭ¸¯Çϼż­ V3+ Neo À» ´Ù¿î·Îµå ¹ÞÀ¸½ÅÈÄ ÄÄÇ»Å͸¦ ½ÃÀÛ->½Ã½ºÅÛÁ¾·á->MS-MOD¿¡¼­ ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛÀ» ´©·ç½Ã°Å³ª (ÀçºÎÆÃÇϸ鼭 À©µµ¿ìÁî°¡ ½ÃÀ۵DZâÀü F8¸¦ ´©·ç½ÅÈÄ Command Prompt Only Mode ·Î °¡¼Å¼­) v3 c:/a ´­·¯ virus¸¦ È®ÀÎ/Á¦°ÅÇϽñ⠹ٶø´Ï´Ù.

    õÀç¸Ç´ÔÀÇ emailÀÌ ¸ô¶ó¼­ ÀÌ·¸°Ô °Ô½ÃÆÇ¿¡ ´äÀåÀÇ Çü½ÄÀ¸·Î °¨»çÀÇ ±ÛÀ» ´ë½ÅÇÕ´Ï´Ù. Çѹø ¿¬¶ôÀ» Áֽʽÿä. ±×¸®°í À̰÷À» ¹æ¹®ÇϽô ¿©·¯ºÐµé²²µµ ÁÖÀǸ¦ ±â¿ïÀ̽ñ⸦ ºÎʵ叮¸ç, ÀúÈñ·Î ÀÎÇØ Ȥ½Ã virus¿¡ °¨¿°µÇ¼Ì´Ù¸é »ç°ú¿Í ÇÔ²² ÀÌÇØ¸¦ ±¸ÇÕ´Ï´Ù. °¨»çÇÕ´Ï´Ù.




    Re: ¿î¿µÀÚ´Ô Win32/MTX¿¡ °¨¿°µÇ¾î ÀÖ½À´Ï´Ù. ¿î¿µÀÚ   on: 02/06/01


Post a Followup

Name:
E-Mail:
Home page:
Subject:

Message to Post