E6zxc.exe
...
Antivirus | Version | Last update | Result |
---|---|---|---|
AhnLab-V3 | 2011.09.04.01 | 2011.09.05 | Dropper/Win32.OnlineGameHack |
AntiVir | 7.11.14.93 | 2011.09.05 | TR/Crypt.ASPM.Gen2 |
Antiy-AVL | 2.0.3.7 | 2011.09.05 | - |
Avast | 4.8.1351.0 | 2011.09.05 | - |
Avast5 | 5.0.677.0 | 2011.09.05 | - |
AVG | 10.0.0.1190 | 2011.09.05 | - |
BitDefender | 7.2 | 2011.09.05 | - |
ByteHero | 1.0.0.1 | 2011.09.01 | Trojan.Win32.Heur.Gen |
CAT-QuickHeal | 11.00 | 2011.09.05 | - |
ClamAV | 0.97.0.0 | 2011.09.05 | PUA.Packed.ASPack |
Commtouch | 5.3.2.6 | 2011.09.04 | - |
Comodo | 9997 | 2011.09.05 | TrojWare.Win32.Trojan.Agent.Gen |
DrWeb | 5.0.2.03300 | 2011.09.05 | - |
Emsisoft | 5.1.0.11 | 2011.09.05 | Gen.Variant.Taterf!IK |
eSafe | 7.0.17.0 | 2011.09.04 | - |
eTrust-Vet | 36.1.8540 | 2011.09.05 | - |
F-Prot | 4.6.2.117 | 2011.09.04 | - |
F-Secure | 9.0.16440.0 | 2011.09.05 | - |
Fortinet | 4.3.370.0 | 2011.09.05 | - |
GData | 22 | 2011.09.05 | - |
Ikarus | T3.1.1.107.0 | 2011.09.05 | Gen.Variant.Taterf |
Jiangmin | 13.0.900 | 2011.09.04 | - |
K7AntiVirus | 9.111.5090 | 2011.09.05 | - |
Kaspersky | 9.0.0.837 | 2011.09.05 | - |
McAfee | 5.400.0.1158 | 2011.09.05 | - |
McAfee-GW-Edition | 2010.1D | 2011.09.05 | - |
Microsoft | 1.7604 | 2011.09.05 | - |
NOD32 | 6437 | 2011.09.05 | a variant of Win32/Kryptik.SKB |
nProtect | 2011-09-05.01 | 2011.09.05 | - |
Panda | 10.0.3.5 | 2011.09.04 | Suspicious file |
PCTools | 8.0.0.5 | 2011.09.05 | - |
Prevx | 3.0 | 2011.09.05 | - |
Rising | 23.73.01.03 | 2011.08.30 | - |
Sophos | 4.69.0 | 2011.09.05 | - |
SUPERAntiSpyware | 4.40.0.1006 | 2011.09.04 | - |
Symantec | 20111.2.0.82 | 2011.09.05 | - |
TheHacker | 6.7.0.1.290 | 2011.09.03 | - |
TrendMicro | 9.500.0.1008 | 2011.09.03 | - |
TrendMicro-HouseCall | 9.500.0.1008 | 2011.09.05 | - |
VBA32 | 3.12.16.4 | 2011.09.05 | - |
VIPRE | 10376 | 2011.09.05 | - |
ViRobot | 2011.9.5.4657 | 2011.09.05 | - |
VirusBuster | 14.0.200.0 | 2011.09.03 | - |
MD5: 9de2e0deb0edca0edfac2d19c6f27891 |
SHA1: 0848703ba9a611dc74ae56e144a32373991bced9 |
SHA256: 396bedd604a199c1fd2c4359c8a24ed40751dc15800ebe71dba5f83c317f4410 |
File size: 285696 bytes |
Scan date: 2011-09-05 09:41:15 (UTC) |
...
Files Added
%System%\E6zxc.exe
%System%\E6szxc10.dll
%System%\E6szxc11.dll
%System%\E6szxc20.dll
%UserProfile%\Microsoft\strFree.dll
Keys Added
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\ProgID
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\Programmable
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
Values Added
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\VersionIndependentProgID
(Default) = "IEHlprObj.IEHlprObj"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\ProgID
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\InprocServer32
(Default) = "%System%\E6szxc20.dll"
ThreadingModel = "Apartment"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\TypeLib
(Default) = "{D3DBA9D8-4657-44BC-B9FF-485C026FA281}"
Version = "1.0"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid32
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}
(Default) = "IIEHlprObj"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0\win32
(Default) = "%System%\E6szxc20.dll"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\HELPDIR
(Default) = "%System%\"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\FLAGS
(Default) = "0"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0
(Default) = "IEHelper 1.0 Type Library"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
(Default) = "{D3DBA9D2-4657-44BC-B9FF-485C026FA281}"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
(Default) = "IEHlprObj Class"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E6sos = "%System%\E6zxc.exe"
strFree = "rundll32.exe "%UserProfile%\Microsoft\strFree.dll", CreLcfAchF"
...
Effect : MSN /Windows live messenger error and disconnect
=======================================================
วิธีกำจัด/แก้ virus : E6zxc.exe
=======================================================
Download Fix Tool :
ใชัโปรแกรม Hijack This Fix check บรรทัดนี้
O4 - HKCU\..\Run: [E6sos] %System%\E6zxc.exe
O4 - HKCU\..\Run: [rundll32.exe] %UserProfile%\Microsoft\strFree.dll", CreLcfAchF"
หมายเหตุ : ท่านใดที่ได้รับผลกระทบจากไวรัสตัวนี้ โืดย MSN จะ Error และ Disconnect
ก็ลองเอาไปแก้ดูนะครับ
------------------------------------------------------------------------------
หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เพื่อป้องกันการเรียกใช้ autorun
เช่น
Program Advice (Stop AutoRun function/autorun.inf)
Microsoft path : Fix autorun function
or
NoAutoRun (.REG)
ไม่มีความคิดเห็น:
แสดงความคิดเห็น