Update 05/06/2010
Loikaw.exeFilesize: 244,675 bytes
MD5: EABB037DF4126080B26D2ABFEA51CE9B
SHA-1: F6C1A824B27FCB81976088308900426265DADED4
===================================================
ตัวอย่าง message box หลังจากติด Virus loikaw
Welcome to loikaw in kayah
chi thu loikaw kola par nor
write by comput5r3razygirl@gmail.com
"loikaw hacking day" 3D virus for jan
ข้อความใน
Virus Information.txt
Hi fri “Administrator”
It is nice to meet you . . . .
I ko thi lar, see yin kaw kin mar lar, i ka talk khin tat tal nor . . . .
I ka girl nor, chit mar lar . . . . .
I ka u computer ko bar ma, ma loat par buu khin lo Virus write pi talk sa tar ko , he` he` . . .
Sate so ya buu nor i ka di lo pae` . . . . ya tal ma hote lar I name ko thi chin lar? pyaw pya par buu; bar lo pyaw pya ya mar lae` u ka boy lar, age ka kaw?
i ka 18age girl i gamil ka comput5r3razygirl@gmail.com bye bye . . . luu soe . . . fly kiss . .
------------------------------------------------------------------------
Files created
C:\autorun.inf
C:\Temp.pif
C:\Documents and Settings\[UserName]\Application Data\control.exe
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\Mp3.exe
C:\Windows\Loikaw.exe
C:\autorun.inf
C:\Temp.pif
C:\Documents and Settings\[UserName]\Application Data\control.exe
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\Mp3.exe
C:\Windows\Loikaw.exe
C:\Windows\Jan.exe
C:\Windows\System32\extramain.exe
C:\Windows\System32\Iexplorer.exe
C:\Windows\%UserName%.exe
MD5: EABB037DF4126080B26D2ABFEA51CE9B
SHA-1: F6C1A824B27FCB81976088308900426265DADED4
------------------------------------------------------------------------
C:\Documents and Settings\[UserName]\Desktop\Virus Information.txt
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\autorun.inf
Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\soesoe
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
Values Added:
HKUM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
\DefaultIcon :(Default) = "%System%\winlogon.exe,0"
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
Default = "%System%\mshearts.exe,0"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load = "%Windir%\Loikaw.exe"
* = "%AppData%\control.exe"
Values Midified
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind = 0x00000001
NoFolderOptions = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
DisableTaskMgr = 0x00000001
DisableRegistryTools = 0x00000001
Value deleted:
HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon:(Default) = "%SystemRoot%\Explorer.exe,0"
(C:\WINDOWS\System32\shell32.dll,15)
------------------------------------------------------------------------
วิธีกำจัด Virus : Loikaw.exe (update 05/06/2010)
------------------------------------------------------------------------
Download Fix Tool : PeeTechFix-Loikaw 1.2
C:\Windows\System32\extramain.exe
C:\Windows\System32\Iexplorer.exe
C:\Windows\%UserName%.exe
MD5: EABB037DF4126080B26D2ABFEA51CE9B
SHA-1: F6C1A824B27FCB81976088308900426265DADED4
------------------------------------------------------------------------
C:\Documents and Settings\[UserName]\Desktop\Virus Information.txt
C:\Documents and Settings\[UserName]\Application Data\Microsoft\CD Burning\autorun.inf
Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\soesoe
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
Values Added:
HKUM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
\DefaultIcon :(Default) = "%System%\winlogon.exe,0"
HKLM\SOFTWARE\Classes\soesoe\DefaultIcon
Default = "%System%\mshearts.exe,0"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load = "%Windir%\Loikaw.exe"
* = "%AppData%\control.exe"
Values Midified
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFind = 0x00000001
NoFolderOptions = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system
DisableTaskMgr = 0x00000001
DisableRegistryTools = 0x00000001
Value deleted:
HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon:(Default) = "%SystemRoot%\Explorer.exe,0"
(C:\WINDOWS\System32\shell32.dll,15)
------------------------------------------------------------------------
วิธีกำจัด Virus : Loikaw.exe (update 05/06/2010)
------------------------------------------------------------------------
Download Fix Tool : PeeTechFix-Loikaw 1.2
หมายเหตุ :
version 1.2
- แก้ไขการกำจัดไฟล์ Jan.exe
version 1.1
- แก้ไขคำสั่ง delete ไฟล์ %Username%.exe
- แก้ไขการ Modifoed Registry ส่วนของ .bat และ .cmd
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat > (default) = batfile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd > (default) = cmdfile
โหลดไปแล้วนะคะ
ตอบลบขอบคุนมากค่ะ
โหลดมาแล้วค่ะ ขอบคุณมากๆนะคะิ ไวรัสตัวนี้น่ารำคาญมากเลยค่ะ
ตอบลบThank you........
ตอบลบworks fine.
ตอบลบThanks a lot.
ไหว้งามๆ 1 ทีครับ ดูคนอวดผีอยู่แม่งขึ้น
ตอบลบตกใจคิดว่าผีหลอก = =
how do u get rid of this ? -.-
ตอบลบDownload Fix Tool : PeeTechFix-Loikaw 1.2
ตอบลบhttp://www.mediafire.com/download.php?lydzndmznmz