2 002. 1. 3 1, ryuni@c e rtc c.o r.kr.,,.....,.,. 1. ini INI initia lize 64 KB. ini win.ini, syste m.ini. ini. W in.in i
C:\WINDOWS( 98 ) Win.ini load run. "loa d=" run=". win.ini. 2000 12 Hybris win.ini [windows] run=. run =C:\ W in dow s\ Sy stem\ amiaamia.ex e <ami aami a. exe. > S ys te m.in i C:\WINDOWS( 98 ) Syste m.ini boot.
. syste m.ini. 2001 9Nimda syste m.ini. Sh ell = ex plorer.ex e load.ex e - dontrunold < Ni mda l oad. exe. > w in in it.in i C:\WINDOWS\( 98 ) wininit.ini. wininit.ini [Ren am e] NUL =c:\ w in dow s\ picture.ex e NUL=c:\windows\picture.exe c:\windows\picture.exe NUL..
2001 Nimda wininit.ini. [Ren am e] NUL = \.EXE <. 2... 1). 3.x INI 95 INI. 64KB PC win.ini. 32KB 64KB ini 32KB. INI. INI., INI INI INI. Windows 3.1 Windows 3.1 O LE.
PC,,,. regedit". 98 6 2000 HKEY_DYN_DATA 5. (key)..
HKEY_ C LAS S ES _ RO OT OLE,. HKEY_CLASSES_ROOT,. HKEY_ C URRENT_ US ER, ID. HKEY_USER. HKEY_ LO CAL_ MAC HINE.,,,. HKEY_ US E R HKEY_CURRENT_USER, USER.DAT., HKEY_CURRENT_US ER. HKEY_ C URRENT_ CO NF IG HKEY_LOCAL_MACHINE Config.,. HKEY_ DYN_ DATA 2000.
2). [HKEY_ LO C AL_ MAC HINE\ S o ftw a re \ Mic ro s o ft\w ind o ws \ C u rre ntve rs io n\ Ru n S e rv ic e s ] [HKEY_LOCAL_MACHINE\Softwa re\ Microsoft\Windows\CurrentVe rsion\ RunSe rvicesonce] [HKEY_ LOCAL_ MACHINE\ Softwa re\ Microsoft\Windows\Curre ntve rs ion\ Run] [HKEY_ LOCAL_ MACHINE\ Softwa re\ Microsoft\Windows\Curre ntve rs ion\ RunOnce] [HKEY_CURRENT_ US ER\ Softwa re\ Microsoft\Windows\Curre ntve rs ion\ Run] [HKEY_CURRENT_ US ER\ Softwa re\ Microsoft\Windows\Curre ntve rs ion\ RunOnce ] [HKEY_CURRENT_ US ER\ Softwa re\ Microsoft\Windows\Curre ntve rs ion\ RunSe rvices]. [HKEY_CLASS ES_ROOT\exefile\s he ll\ope n\comma nd] @="\"% 1\" %*" [HKEY_CLASS ES_ROOT\comfile\s he ll\ope n\comma nd] @="\"% 1\" %*" [HKEY_CLASS ES_ROOT\batfile\s he ll\ope n\comma nd] @="\"% 1\" %*" [HKEY_CLASS ES_ROOT\htafile\She ll\ope n\comma nd] @="\"% 1\" %*" [HKEY_CLASS ES_ROOT\piffile\s he ll\ope n\comma nd] @="\"% 1\" %*" [HKEY_LOCAL_MACHINE\Softwa re\classes\batfile\she ll\open\command] @="\"% 1\" %*" [HKEY_LOCAL_MACHINE\Softwa re\classes\comfile\shell\open\command] @="\"%1\" %*" [HKEY_LOCAL_MACHINE\Softwa re\classes\exefile\shell\open\command] @="\"%1\" %*" [HKEY_LOCAL_MACHINE\Softwa re\classes\htafile\shell\open\command] @="\"%1\" %*" [HKEY_LOCAL_MACHINE\Softwa re\classes\piffile\s hell\ope n\comma nd] @="\"% 1\" %*" % 1 %* "se rve r.exe % 1 %*" exe, com, bat, hta, pif se rve r.exe. 2001 7 Sirca m exe. H KEY_LOCAL_MA CHINE\ Softw are\ Microsoft\ W in dow s\ CurrentV er sion\ RunS er vices Driv er32=c:\ W in dow s\ Sy stem\ scam32.ex e
exe. HKEY_CLA SSES_ROOT \ ex efile\ sh ell\ open\ comm and C:\ recy cled\ sirc32.ex e "% 1" % *" Sirca m. 3... Win 98 : C:\WINDOWS\ \\ : C:\windows\sta rt me nu\progra ms\sta rtup. Win 2000 : C:\Docume nts a nd Settings\Administrator\ \\ : C:\Docume nts a nd Settings\Administrator\sta rt me nu\progra ms\sta rtup. HKEY_CURRENT_US ER\Softwa re\microsoft\windows\curre ntve rs ion\explore r\she ll Folde rs
Sta rtupc:\windows\ \\.. 4. bat,.,. bat a utoexec.bat. Auto e xe c.bat C:\ BAT Autoexec.bat. BAT. C a utoexec.bat. 2002 1 Gigge r C a utoexe c.bat. C. ECH O y format c: W ins ta rt.bat C:\WINDOWS( 98 ) winsta rt.bat BAT.
2001 8 Cue rpo winsta rt.bat 2001 7 Rea lity. @echo off debug < c:\ W indow s\ Sy stem\ Sy stem.dll > nul copy c:\ Comm an d32.com c :\ W in dow s\ Cammand\ Comm an d32.com c:\ W indow s\ Camm an d\ Comm and32.com 5. ICQ. ICQ. ICQ ICQNET.. [HKEY_CURRENT_ US ER\ Softwa re\ Mira bilis\ ICQ\Age nt\apps\test] "Path"="test.exe " "Sta rtup"="c:\\test" "Pa ra mete rs "="" "Ena ble "="Yes " 2001 1 Leave. H KEY_CURRENT _USER\ Softw are\ Mirabilis\ ICQ\ A gent\ App s\ icqrun C:\ W INDOW S\ reg sv.ex e 6.
... [HKEY_ LOCAL_ MACHINE\ Softwa re\c LAS S ES\ She llscra p] ( )=" " "Neve rshowext"= S HS. Neve rshowext.shs. Girl.jpg.s hs Girl.jpg. Neve rshowext....
2001 2 Anna Kournikova Anna Kournikova.jpg.vbs. Anna Kournikova.jpg. 7. http://www.tlse curity.net/a uto.html http://www.ce rt.org/incide nt_notes/in- 2000-07.html http://www.nbins ide.com/study/090.htm http://mya ng2.hihome.com/right3.htm http://me mbe rs.tripod.lycos.co.kr/j28 14/exte ntion.htm http://my.drea mwiz.com/bicte r/study/boot/boot_9.htm http://v3.netpia.com/newvirusdeta il.as p?virus_id=652 http://se curityres ponse.syma ntec.com/avce nte r/ve nc/data/pwstea l.coced240b.tro.html