u3uvew6.bat ,ierdfgh.exefiles size : 105,098 bytes
MD5: 16B3D5192BFD9077EF60B17D0CB12589SHA-1: A64D3E01C4EFE17535383C0621BD6CC65A6BCF71==================================================
Files createdC:\WINDOWS\system32\ierdfgh.exe
C:\WINDOWS\system32\pytdfse1.dll
C:\Documents and Settings\[UserName]\Local Settings\Temp\xvassdf.exe
C:\Documents and Settings\[UserName]\Local Settings\Temp\4tddfwq0.dll(0-9)
C:\u3uvew6.bat
C:\autorun.inf
File deleted
C:\WINDOWS\system32\drivers\cdaudio.sys
Remote Host221.1.204.245 port 80
URL identifiedhttp://fgtrtyuo.com/xrbv/uu1.rar
http://sfdght.com/xrbv/uu.rar
Registry Modifications
Keys AddedHKLM\SOFTWARE\Classes\CLSID\MADOWN
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Values AddedHKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo : "qaswee.e"
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Enum
Count : 0x00000000
NextInstance : 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\ControlSet001\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\ControlSet001\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath : "%System%\drivers\cdaudio.sys"
DisplayName = "AVPsys"
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Count : 0x00000000
NextInstance = 0x00000000
INITSTARTFAILED : 0x00000001
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys\Security
Security : 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM \SYSTEM\CurrentControlSet\Services\AVPsys
Type : 0x00000001
Start : 0x00000003
ErrorControl : 0x00000001
ImagePath :"%System%\drivers\cdaudio.sys"
DisplayName : "AVPsys"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kxswsoft : "%System%\ierdfgh.exe"
54dfsger : "%Temp%\xvassdf.exe"
Values ModifiedHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
------------------------------------------------------------------------
วิธีกำจัด virus : u3uvew6.bat , ierdfgh.exe------------------------------------------------------------------------
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames 2.0.51. Run PeeTechFix-Win32/PSW.OnlineGames 2.0.5
2. ใช้
HijackThis fix checked ที่บรรทัดนี้
O4 - HKCU\..\Run: [
kxswsoft ] "%System%\ierdfgh.exe"
O4 - HKCU\..\Run: [
54dfsger ] "%Temp%\xvassdf.exe"
3. Delete file
u3uvew6.bat , ทุก root drive (C:\- Z:\)
4. Restart 1 ครั้ง
หมายเหตุ: จะ Update Fix ให้ใน Fix-NVDB-006 ครับ