°Ô½ÃÆÇȨ / À©µµ¿ì / regsvr32.exe¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù.»õ±Û¾²±â ´ä±Û¾²±â
 À̵¿: 1 | 2
ÀúÀÚ regsvr32.exe¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-11-24 11:52||
½ÃÀÛ ÇÁ·Î±×·¥¿¡¼­µµ Áö¿ì¼Ì´Âµ¥ °è¼Ó ³ªÅ¸³­´Ù¸é..

·¹Áö½ºÆ®¸®¿¡¼­ regsvr32.exe ¸¦ °Ë»öÇØ¼­ ³ª¿À´Â Ű¿Í °æ·Î¸¦ È®ÀÎÇØ º¸½Ã°í
¿Ã·Áº¸¼¼¿ä.

±×¸®°í, Win Patrol (À© ÆÐÆ®·Ñ)
ÀÌ ÇÁ·Î±×·¥À» ¼³Ä¡Çؼ­ Ȥ½Ã Ãâó°¡ ºÒºÐ¸íÇØ º¸ÀÌ´Â È­ÀÏÀ̳ª services °¡ ÀÖ´ÂÁö È®ÀÎÇØ º¸¼¼¿ä.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-11-24 14:19||
Àοë
·¹Áö½ºÆ®¸®¿¡¼­ regsvr32.exe ¸¦ °Ë»öÇØ¼­ ³ª¿À´Â Ű¿Í °æ·Î¸¦ È®ÀÎÇØ º¸½Ã°í
¿Ã·Áº¸¼¼¿ä.

[HKEY_CLASSES_ROOT\scriptletfile\Shell\Register\command]
""="\"C:\\WINDOWS\\system32\\REGSVR32.EXE\" /i:\"%1\" \"C:\\WINDOWS\\system32\\scrobj.dll\""

[HKEY_CLASSES_ROOT\scriptletfile\Shell\Unregister\command]
""="\"C:\\WINDOWS\\system32\\REGSVR32.EXE\" /u /n /i:\"%1\" \"C:\\WINDOWS\\system32\\scrobj.dll\""

[HKEY_CLASSES_ROOT\Installer\Features\7D2F387510309040002000060BECB6AB]
"H_RDF_COMP_regsvr32.exe"="System_Files"

·¹Áö½ºÆ®¸® °Ë»ö¿¡¼­ À§¿Í °°ÀÌ °Ë»öµÇ¾î »èÁ¦ ÇÏ¿´½À´Ï´Ù. ÇÏÁö¸¸...¿ª½Ã³ª regsvr32.exe´Â ½ÇÇàµÇ´Â±º¿ä...

**ÇöÀç regsvr32.exe¸¦ »èÁ¦Çß½À´Ï´Ù. ±×·¨´õ´Ï (´ç¿¬ÇϰÚÁö¸¸) Űº¸¾ÈÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ´Â ÀÎÅÍ³ÝÆäÀÌÁö¿¡ °¡µµ regsvr32.exe°¡ ÀÛ¾÷°ü¸®ÀÚ¿¡ ³ªÅ¸³ªÁö ¾Ê³×¿ä..±×·¡¼­ ´À·ÁÁö´Â Çö»óµµ ¾ø±â´Â ÇÕ´Ï´Ù.
´çºÐ°£ ÀÌ·¸°Ô ½á¾ß ÇÒ°Í °°Àºµ¥....Àúó·³ regsvr32.exe¸¦ Áö¿ö¹ö¸®¸é ¾î¶»°Ô µÇ´Â °Ç°¡¿ä?

[Regsvr32.exe ´Â ƯÁ¤ ActiveX ÄÁÆ®·ÑÀ» ½Ã½ºÅÛ¿¡ µî·Ï½ÃÄÑÁÖ´Â À¯¿ëÇÑ À¯Æ¿¸®Æ¼ÀÔ´Ï´Ù. ±×·±µ¥, Regsvr32.exe ÆÄÀÏÀ» µî·ÏÇϱâ À§Çؼ­ ocx ³ª dllÀÌ À§Ä¡ÇÑ °÷¿¡¼­ regsvr32.exe ÆÄÀÏÀ» ½ÇÇàÇÒ °æ¿ì ocx ³ª dllÀÇ À§Ä¡¿¡ µû¶ó¼­ µî·ÏµÇ´Â °ÍÀÌ ´Ù¸¥ °æ¿ì°¡ ÀÖ½À´Ï´Ù. - Ãâó-³×À̹ö http://blog.naver.com/ajumany02/60016212910
ahnshy¶õ ºÐÀÇ À̾߱â·Ð :" COM LIBRARY DLL (°°Àº ÇÁ·Î¼¼½º¿¡¼­ µ¹°í ÀÖ´Â COM ¶óÀ̺귯¸®)¸¦ ·¹Áö½ºÆ®¸®¿¡ À¯´ÏÅ©ÇÑ °ª(CLSIDµî)ÀÌ¿ëÇÏ¿© ·¹Áö½ºÆ®¸®¿¡ À§Ä¡¹× ¹öÀüµîÀÇ Á¤º¸¸¦ µî·ÏÇØÁÖ´Â ÆÄÀÏÀÔ´Ï´Ù. "

À§ÀÇ ³»¿ëÀ» Âü°í ÇØ Á¦ °æ¿ì¸¦ º¸ÀÚ¸é, Á¦°¡ µé¾î°¡°íÀÚ Çß´ø ƯÁ¤»çÀÌÆ®(¿îÀü¸éÇã½ÃÇè°ü¸®´Ü)ÀÇ À¥ÆäÀÌÁö°¡ ·ÎµùµÉ¶§ ÀÚµ¿À¸·Î ¼³Ä¡µÇ¾îÁö´Â ActiveX ÄÁÆ®·Ñ(Űº¸¾È Á¾·ùÀεí..nprotect)°ú ¹®Á¦ÀÎ°Í °°Àºµ¥.... (taskinfo»ó¿¡¼­ º¸¿©Áö´Â regsvr32.exeÀÇ °æ·Î´Â ¹ÙÅÁÈ­¸éÀ¸·Î ³ª¿À´õ±º¿ä...)
...¼­ºñ½ºÁß..COM°ü·ÃµÈ ¼­ºñ½º¿Í ¿¬°üµÇ¾îÁø°Ô ¾Æ´ÒÁö....(ÃßÃøÀÔ´Ï´Ù...¼±¹«´ç..^^)

ÀúÀÇ ÃßÃø 2¹øÂ°... ƯÁ¤»çÀÌÆ®ÀÇ ActiveXÄÁÆ®·ÑÀÌ ¼³Ä¡µÇ¸é¼­ ƯÁ¤ *.dll¸¦ µî·Ï½Ãų·Á°í Çϴµ¥
±× ƯÁ¤ dll¸¦ ãÀ»¼ö ¾ø¾î¼­ °è¼ÓÇØ¼­ regsvr32.exe¸¦ È£ÃâÇϴ°ÍÀº ¾Æ´ÑÁö....regsvr32.exe°¡ ¿äûµÈ dll¸¦ ã±âÀ§ÇØ °Ë»öÇÏ´Ùº¸´Ï ½Ã½ºÅÛÀÇ ¼º´ÉÀÌ ÀúÇϵǴ°ÍÀº ¾Æ´ÑÁö....ÃßÃøÇØ º¸³×¿ä.


[ ¸Þ½ÃÁö¼öÁ¤: mikawang ÀϽÃ: 2005-11-24 17:21 ]
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-11-25 15:05||
¿¡±Ã âÇÇÇÕ´Ï´Ù. (-_-;;)

dllhost´Â ¹«Á¶°Ç ¿ú¹ÙÀÌ·¯½º´Ù. ¶õ »ý°¢ÀÌ »Ñ¸®±í°Ô ÀÚ¸®Àâ°í ÀÖ¾ú´Âµ¥
±×·¡µµ ´Ô ´öºÐ¿¡ ÇѼö ¹è¿ü½À´Ï´Ù. ^^

Àúµµ ´Ô ÃßÃø¿¡ ÇÑÇ¥~ È÷È÷.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-11-26 21:03||
Àοë

±Û¾´ÀÌ: mikawang ³¯ÀÚ:2005-11-24 14:19
[HKEY_CLASSES_ROOTscriptletfileShellRegistercommand]
""="\"C:WINDOWSsystem32REGSVR32.EXE\" /i:\"%1\" \"C:WINDOWSsystem32scrobj.dll\""

[HKEY_CLASSES_ROOTscriptletfileShellUnregistercommand]
""="\"C:WINDOWSsystem32REGSVR32.EXE\" /u /n /i:\"%1\" \"C:WINDOWSsystem32scrobj.dll\""

·¹Áö½ºÆ®¸® °Ë»ö¿¡¼­ À§¿Í °°ÀÌ °Ë»öµÇ¾î »èÁ¦ ÇÏ¿´½À´Ï´Ù. ÇÏÁö¸¸...¿ª½Ã³ª regsvr32.exe´Â ½ÇÇàµÇ´Â±º¿ä...

»èÁ¦ÇÏ¸é ¾ÈµÇ´Â ·¹Áö½ºÆ®¸®ÀÔ´Ï´Ù. ½ºÅ©¸³Æ® ÆÄÀÏÀÌ µ¿ÀÛÇÏÁö ¾ÊÀ» °¡´É¼ºÀÌ ÀÖ½À´Ï´Ù.

Àοë

**ÇöÀç regsvr32.exe¸¦ »èÁ¦Çß½À´Ï´Ù. ±×·¨´õ´Ï (´ç¿¬ÇϰÚÁö¸¸) Űº¸¾ÈÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ´Â ÀÎÅÍ³ÝÆäÀÌÁö¿¡ °¡µµ regsvr32.exe°¡ ÀÛ¾÷°ü¸®ÀÚ¿¡ ³ªÅ¸³ªÁö ¾Ê³×¿ä..±×·¡¼­ ´À·ÁÁö´Â Çö»óµµ ¾ø±â´Â ÇÕ´Ï´Ù.
´çºÐ°£ ÀÌ·¸°Ô ½á¾ß ÇÒ°Í °°Àºµ¥....Àúó·³ regsvr32.exe¸¦ Áö¿ö¹ö¸®¸é ¾î¶»°Ô µÇ´Â °Ç°¡¿ä?

ÇÁ·Î±×·¥À» µî·ÏÇÒÀÌ ¾øÀ¸¸é ¸ð¸£Áö¸¸ µî·ÏÇÒ ÀÏÀÌ ÀÖ´Ù¸é ¹«Ã´ ºÒÆíÇÕ´Ï´Ù.

Àοë

[Regsvr32.exe ´Â ƯÁ¤ ActiveX ÄÁÆ®·ÑÀ» ½Ã½ºÅÛ¿¡ µî·Ï½ÃÄÑÁÖ´Â À¯¿ëÇÑ À¯Æ¿¸®Æ¼ÀÔ´Ï´Ù. ±×·±µ¥, Regsvr32.exe ÆÄÀÏÀ» µî·ÏÇϱâ À§Çؼ­ ocx ³ª dllÀÌ À§Ä¡ÇÑ °÷¿¡¼­ regsvr32.exe ÆÄÀÏÀ» ½ÇÇàÇÒ °æ¿ì ocx ³ª dllÀÇ À§Ä¡¿¡ µû¶ó¼­ µî·ÏµÇ´Â °ÍÀÌ ´Ù¸¥ °æ¿ì°¡ ÀÖ½À´Ï´Ù. - Ãâó-³×À̹ö http://blog.naver.com/ajumany02/60016212910
ahnshy¶õ ºÐÀÇ À̾߱â·Ð :" COM LIBRARY DLL (°°Àº ÇÁ·Î¼¼½º¿¡¼­ µ¹°í ÀÖ´Â COM ¶óÀ̺귯¸®)¸¦ ·¹Áö½ºÆ®¸®¿¡ À¯´ÏÅ©ÇÑ °ª(CLSIDµî)ÀÌ¿ëÇÏ¿© ·¹Áö½ºÆ®¸®¿¡ À§Ä¡¹× ¹öÀüµîÀÇ Á¤º¸¸¦ µî·ÏÇØÁÖ´Â ÆÄÀÏÀÔ´Ï´Ù. "

RegsvrÀ̶ó´Â À̸§¿¡¼­ ¾Ë ¼ö ÀÖµíÀÌ ÇÁ·Î±×·¥À» ·¹Áö½ºÆ®¸® ¼­¹ö¿¡ µî·ÏÇØÁÖ´Â ÇÁ·Î±×·¥ÀÔ´Ï´Ù.

Àοë

À§ÀÇ ³»¿ëÀ» Âü°í ÇØ Á¦ °æ¿ì¸¦ º¸ÀÚ¸é, Á¦°¡ µé¾î°¡°íÀÚ Çß´ø ƯÁ¤»çÀÌÆ®(¿îÀü¸éÇã½ÃÇè°ü¸®´Ü)ÀÇ À¥ÆäÀÌÁö°¡ ·ÎµùµÉ¶§ ÀÚµ¿À¸·Î ¼³Ä¡µÇ¾îÁö´Â ActiveX ÄÁÆ®·Ñ(Űº¸¾È Á¾·ùÀεí..nprotect)°ú ¹®Á¦ÀÎ°Í °°Àºµ¥.... (taskinfo»ó¿¡¼­ º¸¿©Áö´Â regsvr32.exeÀÇ °æ·Î´Â ¹ÙÅÁÈ­¸éÀ¸·Î ³ª¿À´õ±º¿ä...)
...¼­ºñ½ºÁß..COM°ü·ÃµÈ ¼­ºñ½º¿Í ¿¬°üµÇ¾îÁø°Ô ¾Æ´ÒÁö....(ÃßÃøÀÔ´Ï´Ù...¼±¹«´ç..^^)

ÀúÀÇ ÃßÃø 2¹øÂ°... ƯÁ¤»çÀÌÆ®ÀÇ ActiveXÄÁÆ®·ÑÀÌ ¼³Ä¡µÇ¸é¼­ ƯÁ¤ *.dll¸¦ µî·Ï½Ãų·Á°í Çϴµ¥
±× ƯÁ¤ dll¸¦ ãÀ»¼ö ¾ø¾î¼­ °è¼ÓÇØ¼­ regsvr32.exe¸¦ È£ÃâÇϴ°ÍÀº ¾Æ´ÑÁö....regsvr32.exe°¡ ¿äûµÈ dll¸¦ ã±âÀ§ÇØ °Ë»öÇÏ´Ùº¸´Ï ½Ã½ºÅÛÀÇ ¼º´ÉÀÌ ÀúÇϵǴ°ÍÀº ¾Æ´ÑÁö....ÃßÃøÇØ º¸³×¿ä.

±×°ÍÀº ¾Æ´Ñ °Í °°½À´Ï´Ù. DLLÀÌ ¾ø´Ù°íÇØ¼­ °è¼Ó È£ÃâµÇÁö´Â ¾Ê½À´Ï´Ù.

½ÇÁ¦ ¿îÀü¸éÇã½ÃÇè °ü¸®´Ü¿¡ Á¢¼ÓÇØ¼­ È®ÀÎÇØº¸´Ï º¸¾È ÇÁ·Î±×·¥À» ¼¼°³(MagicAgent.exe, MagicLine.exe, npkagt.exe)³ª ¼³Ä¡ÇÏ´õ±º¿ä. ÀÌ ¼¼°³¸¦ ¼³Ä¡Çϸé ÇØ´ç »çÀÌÆ®ÀÇ Á¢¼Ó ¼Óµµ°¡ ÇöÀúÈ÷ ÀúÇϵǸç, ±×¸²À» ¹Þ¾Æ¿ÀÁö ¸øÇÏ´Â °æ¿ìµµ ¹ß»ýÇÕ´Ï´Ù.

MagicAgent.exe, MagicLine.exe¸¦ ¼³Ä¡Çϸé npkagt.exe(nProtect Keyboard Agent)°¡ °¡²û Á×À¸¸ç À̶§ regsvr32.exe°¡ °¡²û ½ÇÇàµË´Ï´Ù. Á¦°¡ º¸±â¿¡´Â º¸¾È ÇÁ·Î±×·¥µé(ActiveX)ÀÇ Ãæµ¹ ¶§¹®¿¡ ¹ß»ýÇÑ Çö»ó°°½À´Ï´Ù.

ÇÏ¿©°£ º¸¾ÈÀÇ °³³äÀÌ ¾ø´Â ¾ÖµéÀÌ ÇÁ·Î±×·¥À» ¸¸µé´Ù º¸´Ï ¸¶±¸ ÀâÀÌ ActiveX¸¦ ¼³Ä¡ÇÏ°í ¼³Ä¡µÈ ActiveX³¢¸® Ãæµ¹ÀÌ ³ª¼­ ¹®Á¦°¡µÇ´Â °æ¿ì°¡ Á¾Á¾ ¹ß»ýÇÏ´õ±º¿ä.

C:\Windows\Downloaded Program FilesÀÇ ¸ðµç ÆÄÀÏÀ» »èÁ¦ÇÏ°í ´Ù½Ã ½ÃµµÇØ º¸°Å³ª ¾Ë ¼ö ¾ø´Â ActiveX Á¦°ÅÇϱ⸦ ÀÌ¿ëÇØ¼­ ºÒÇÊ¿äÇÑ ActiveX¸¦ Á¦°ÅÇØº¸±â ¹Ù¶ø´Ï´Ù.

P.S. MagicAgent.exe, MagicLine.exe´Â IE¸¦ Á¾·áÇØµµ »ç¶óÁöÁö ¾Ê´Â±º¿ä. OTL

[ ¸Þ½ÃÁö¼öÁ¤: artech ÀϽÃ: 2005-11-26 21:18 ]
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2005-11-30 12:17||
¿îÀü¸éÇã½ÃÇè°ü¸®´ÜÀÇ ActiveX ¹®Á¦¶ó´Â ±ÛÀ» ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.
´ÙÀ½±Û: À©µµ¿ì xpÀÇ ³»Àå °ÔÀÓ º¹±¸. (0)4419werty332006-02-10
ÀÌÀü±Û: ·¡Áö½ºÆ®¸®¿¡ ´ëÇØ ¿©Âã´Ï´Ù. (0)4408alligator2005-11-01

 À̵¿: 1 | 2
»õ±Û¾²±â ´ä±Û¾²±â
À̵¿:

¼¼»ó»ç´Â À̾߱â



RSS ±¸µ¶ (À͸í | ȸ¿ø | °­Á | Æ÷·³)
(C) 1996 ~ 2017 QAOS.com All rights reserved.