k2d8j3wa.bat
File size : 321,024 bytes
MD5: 64D35A19ABB5796C2643F4B3A28AA89A
SHA-1: E13A51D550D5BF273D7907D0DA8F713E9ED576C8
===================================================
Files created
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll (0-9)
X:\k2d8j3wa.bat
X:\autorun.inf
URL to be downloaded
http://www.vjccc.com/hp/zz.rar > %Temp%\zz.rar
Registry Modifications
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kava : "%System%\kavo.exe"
Values Modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
------------------------------------------------------------------------
วิธีกำจัด virus : k2d8j3wa.bat
------------------------------------------------------------------------
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames 2.0.5
1. Run PeeTechFix-Win32/PSW.OnlineGames 2.0.5
2. Delete ไฟล์ k2d8j3wa.bat ทุก Root Drive (C:\ - Z:\)
ไม่มีความคิดเห็น:
แสดงความคิดเห็น