jm3cx96.bat , olhrwef.exe
Files size 109,141 bytes
MD5: 9F1DBC69E3FDA5B689FB85A05192E383
SHA-1: 4EDCE675520EB72A044EA84BE12704A4647841E7
===================================================
Files Created
%System%\olhrwef.exe
%System%\nmdfgds0.dll
X:\jm3cx96.bat
X:\autorun.inf
%System% = C:\Windows\System32
X:\ C:\ - Z:\
Registry Modifications
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
cdoosoft = "%System%\olhrwef.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091
=======================================================
วิธีกำจัด/แก้ virus : jm3cx96.bat , olhrwef.exe
=======================================================
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames
หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เช่น
Panda USB Vaccine
http://www.pandasecurity.com/homeusers/downloads/usbvaccine/
or
KB971029, KB967715 (Disable AutoRun)
http://hotzone-it.blogspot.com/2009/08/kb971029-fix-autorun-microsoft.html
ไม่มีความคิดเห็น:
แสดงความคิดเห็น