¿î¿µÀÚ´Ô Win32/MTX¿¡ °¨¿°µÇ¾î ÀÖ½À´Ï´Ù.
http://home.ahnlab.com/download/v3neo.html
¿©±â¼ V3 ÃֽŹöÁ¯À¸·Î ²À °Ë»çÇϽñæ...Win32/MTX ¹ÙÀÌ·¯½º´Â I-Worm.MTX, I-Worm.Win32.MTX, PE_MTX.A, W95.MTX.dr, W32/MTX@MM, W32/Apology µîÀ¸·Î ºÒ¸®´Â ¹ÙÀÌ·¯½º·Î ÀڽŵéÀ» '[MATRix]'·Î ºÎ¸£´Â ¹ÙÀÌ·¯½º Á¦ÀÛ ±×·ì¿¡¼ Á¦ÀÛÇÑ °ÍÀ¸·Î ÃßÁ¤µÈ´Ù.
2000³â 8¿ù 23ÀÏ ¹ß°ßµÇ¾úÀ¸¸ç ±¹³»¿¡´Â 9¿ù 9ÀÏ ¹ß°ßµÇ¾ú´Ù.
»ç¿ëÀÚ°¡ °¨¿°µÈ ÆÄÀÏÀ» ½ÇÇàÇϸé À©µµ¿ì µð·ºÅ丮( ÀϹÝÀûÀ¸·Î
C:\Windows Æú´õ )¿¡ ´ÙÀ½ ÆÄÀÏÀÌ »ý¼ºµÈ´Ù. ´Ü, ¸î¸î ÆÄÀÏÀº ¼û±è ¼Ó¼ºÀ¸·Î Windows Ž»ö±â·Î ãÁö ¸øÇÒ ¼öµµ ÀÖ´Ù.
IE_PACK.EXE ( ¹ÙÀÌ·¯½º º»Ã¼ - 18483 ¹ÙÀÌÆ® )
WIN32.DLL ( ¹ÙÀÌ·¯½º º»Ã¼ - 18483 ¹ÙÀÌÆ® )
MTX_.EXE ( ¹éµµ¾î ÇÁ·Î±×·¥ - 6144 ¹ÙÀÌÆ® )
·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ÀÇ Ç׸ñµéÀÌ Ãß°¡µÇ¸ç, ºÎÆÃ½Ã¸¶´Ù ¹éµµ¾î ÇÁ·Î±×·¥À» ½ÇÇàÇÏ°Ô µÈ´Ù.
HKEY_LOCAL_MACHINE\Software\[MATRix]
: ¾Æ¹« ¿ªÇÒµµ ÇÏÁö ¾ÊÀ½
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run Ç׸ñ¿¡
SystemBackup = "C:\WINDOWS\MTX_.EXE"
À©µµ¿ì ½Ã½ºÅÛ Æú´õ ( ÀϹÝÀûÀ¸·Î C:\Windows\System ) Æú´õ¿¡ WSOCK32.MTX ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ÀÌ ÆÄÀÏÀº, WSOCK32.DLL ÆÄÀÏÀ» °¨¿°½ÃŲ °ÍÀ¸·Î ´ÙÀ½¹ø ºÎÆÃ¶§ WSOCK32.MTX ÆÄÀÏÀÌ WSOCK32.DLL ÆÄÀÏ·Î ´ëüµÈ´Ù.
ÀÌÈÄ »ç¿ëÀÚ°¡ ¿ÜºÎ ¸ÞÀÏ ¼¹ö (SMTP)¸¦ »ç¿ëÇØ¼ ¸ÞÀÏÀ» º¸³¾
°æ¿ì »ç¿ëÀÚ°¡ º¸³½ ¸ÞÀÏ ¿Ü¿¡ ¹ÙÀÌ·¯½º ÆÄÀÏÀÌ Ã·ºÎµÈ ¸ÞÀÏÀÌ
º°µµ·Î Àü¼ÛµÈ´Ù.
¸ÞÀÏÀÇ Á¦¸ñÀº ¾øÀ¸¸ç ÷ºÎ ÆÄÀÏÀº ´ÙÀ½ Áß Çϳª°¡ µÈ´Ù.
ALANIS_Screen_Saver.SCR
ANTI_CIH.EXE
AVP_Updates.EXE
BILL_GATES_PIECE.JPG.pif
BLINK_182.MP3.pif
' FEITICEIRA_NUA.JPG.pif
FREE_xxx_sites.TXT.pif
FUCKING_WITH_DOGS.SCR
Geocities_Free_sites.TXT.pif
HANSON.SCR
I_am_sorry.DOC.pif
I_wanna_see_YOU.TXT.pif
INTERNET_SECURITY_FORUM.DOC.pif
IS_LINUX_GOOD_ENOUGH!.TXT.pif
JIMI_HMNDRIX.MP3.pif
LOVE_LETTER_FOR_YOU.TXT.pif
MATRiX_2_is_OUT.SCR
MATRiX_Screen_Saver.SCR
Me_nude.AVI.pif
METALLICA_SONG.MP3.pif
NEW_NAPSTER_site.TXT.pif
NEW_playboy_Screen_saver.SCR
Protect_your_credit.HTML.pif
QI_TEST.EXE
READER_DIGEST_LETTER.TXT.pif
SEICHO-NO-IE.EXE
Sorry_about_yesterday.DOC.pif
TIAZINHA.JPG.pif
WIN_$100_NOW.DOC.pif
YOU_are_FAT!.TXT.pif
zipped_files.EXE
¸î¸î ¹é½Å ¾÷ü·Î´Â ¸ÞÀÏÀ» º¸³¾ ¼ö ¾ø°ÔÇØ ¹ÙÀÌ·¯½º ¹ß°ß ½Ã±â¸¦ ´ÊÃá´Ù.
´ÙÀ½°ú °°Àº ¹®ÀÚ¿À» Æ÷ÇÔÇϰí ÀÖ´Ù.
"Software provied by [MATRiX] VX team:
Ultras, Mort, Nbk, LOrd DArk, Del_Armg0, Anaktos
Greetz:
All VX guy on #virus channel and Vecna
Visit us : ( Matrix ±×·ì À¥»çÀÌÆ® )
"
¹éµµ¾î ¿ªÇÒÀ» ÇÏ´Â MTX_.EXE ÆÄÀÏÀº V3 Á¦Ç°±º¿¡¼±
'Win-Trojan/MTX.6144'·Î Áø´ÜÇÑ´Ù.
¹éµµ¾î´Â ´ÙÀ½°ú °°Àº ¹®ÀÚ¿À» Æ÷ÇÔÇϰí ÀÖ´Ù
"Software provide by [MATRiX] team:
Ultras, Mort, Nbk, LOrd DArk, Del_Armg0, Anaktos
Greetz:
Vecna 4 source codes and ideas,"
<Ä¡·á¹æ¹ý>
Win32/MTX ¹ÙÀÌ·¯½º´Â ´ÙÀ½ÀÇ ¹æ¹ýÀ¸·Î Ä¡·áÇÒ ¼ö ÀÖ½À´Ï´Ù.
¡Ø Ä¡·á½Ã ÁÖÀÇÁ¡
È®ÀåÀÚ°¡ SCR, PIF·Î ÷ºÎµÈ ÆÄÀÏÀÇ °æ¿ì V3 Á¦Ç°¿¡¼ °Ë»ç
ÆÄÀÏ ´ë»óÀÌ '½ÇÇà ÆÄÀÏ °Ë»ç'·Î ¼³Á¤µÇ¾î ÀÖ´Ù¸é SCR, PIF ÆÄ
ÀÏÀ» ±âº»À¸·Î Áø´ÜÇÏÁö ¾ÊÀ¸¹Ç·Î °Ë»ç ´ë»óÀ» '¸ðµç ÆÄÀÏ'·Î
º¯°æÇϰųª ½ÇÇà ÆÄÀϰú ÇÔ²² ȯ°æ¼³Á¤ÀÇ ¼öµ¿°Ë»ç¿¡¼
'»ç¿ëÀÚ Á¤ÀÇ Çü½Ä °Ë»ç'¿¡ PIF, SCR È®ÀåÀÚ¸¦ Ãß°¡½ÃÄÑ °Ë»çÇÕ
´Ï´Ù. ¶ÇÇÑ V3+ Neo »ç¿ëÀÚ °æ¿ì °Ë»ç½Ã /A ¿É¼Ç (¸ðµçÆÄÀϰË
»ç)À» ÁÖ¾î °Ë»çÇÕ´Ï´Ù.
¡Ø Ä¡·á½Ã Âü°í »çÇ×
¿£Áø¾÷µ¥ÀÌÆ®½Ã 'ÆÐÄ¡ÆÄÀÏ' ±îÁö üũ¸¦ ÇϽÅÈÄ ¾÷µ¥ÀÌÆ®
ÇϽøé Win32/MTX ¿¡ °¨¿°µÇ¾ú´ø WSOCK32.DLL ÆÄÀÏÀ»
´Ù¸¥ PC¿¡¼ º¹»çÇÏÁö ¾Ê¾Æµµ V3Pro 2000 Deluxe°¡ Ä¡·á½Ã
¼öÁ¤À» Çϸç V3+ Neo »ç¿ëÀںР¿ª½Ã ȨÆäÀÌÁö¿¡¼ ÃֽŹöÀüÀ»
´Ù¿î¹Þ¾Æ Ä¡·áÇÏ½Ã¸é µË´Ï´Ù.
- V3+ Neo »ç¿ëÀÚ
1. Ãֽг¯Â¥ÀÇ ¿£ÁøÀ» »ç¿ëÇÑ V3+ Neo¸¦ ´Ù¿î·Îµå ¹Þ¾Æ ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇÕ´Ï´Ù.
2. À©µµ¿ì ºÎÆÃ½Ã¿¡ (F8)۸¦ ´·¯ Command Prompt Only Mode·Î
ºÎÆÃÇϰųª ½Ã½ºÅÛ Á¾·á½Ã¿¡ 'MS-DOS¿¡¼ ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛ'À¸
·Î ½Ã½ºÅÛÀ» Á¾·áÇØ¼ µµ½º ¸ðµå·Î ºÎÆÃÇÕ´Ï´Ù.
(¿¹) v3 c: /a
´ÙÀ½ÀÇ ÆÄÀÏÀÌ Áø´ÜµÈ´Ù¸é »èÁ¦ÇÕ´Ï´Ù.
IE_PACK.EXE / WIN32.DLL / MTX_.EXE / WSOCK32.MTX
3. À©µµ¿ì ÀçºÎÆÃÈÄ¿¡ ¹ÙÅÁȸ鿡¼ '½ÃÀÛ' -> '½ÇÇà' ÀԷ â¿¡
¼ regedit¸¦ ÀÔ·ÂÇØ¼ ½ÇÇàÇÑ ÈÄ¿¡ ´ÙÀ½ÀÇ Å°¸¦ ã¾Æ »èÁ¦ÇÕ´Ï
´Ù.
HKEY_LOCAL_MACHINE
\Software
\Microsoft
\Windows
\CurrentVersion
\Run
SystemBackup = "C:\WINDOWS\MTX_.EXE" <- »èÁ¦
- V3Pro 2000 Deluxe »ç¿ëÀÚ
1. Ãֽг¯Â¥ÀÇ ¿£ÁøÀ¸·Î ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.(À̶§ ¿£Áø ¾÷µ¥ÀÌÆ®
¿Í ÇÁ·Î±×·¥ ÆÐÄ¡±îÁö ÇØÁÖ¾î¾ß ÇÕ´Ï´Ù.)
2. V3Pro 2000 Deluxe¸¦ ½ÇÇàÇØ¼ ȯ°á¼³Á¤ - ¼öµ¿°Ë»ç, ÀÎÅͳÝ
/½Ã½ºÅÛ °¨½Ã ºÎºÐ¿¡¼ 'ÆÄÀÏÇü½Ä'À» '¸ðµç ÆÄÀÏ °Ë»ç'·Î ¼³Á¤
ÇØ ½Ã½ºÅÛÀ» ¹ÙÀÌ·¯½º °Ë»ç / Ä¡·áÇÕ´Ï´Ù.
3. ¹ÙÀÌ·¯½º Áø´ÜÁß¿¡ ÀÎÅͳÝÀÌ »ç¿ëÁßÀ̶ó¸é WSOCK32.DLL ÆÄÀÏ
À» Ä¡·áÇϱâ À§ÇØ ½Ã½ºÅÛÀ» ÀçºÎÆÃÇϸç ÀÎÅͳÝÀ» »ç¿ëÁßÀÌ ¾Æ´Ï
¶ó¸é ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÏÁö ¾Ê°í Ä¡·áµË´Ï´Ù.