"Malware Fix รวมวิธีแก้ปัญหา virus computer โครงการทำดีเพื่อสังคม" "เนื่องจากภาระหน้าที่ทางการงาน ต้องขออภัยผู้เยี่ยมชมทุกท่านนะครับ ที่เ้ข้ามาแล้ว ไม่มีการ update virus ตัวใหม่ นะครับ"

Information

http://malwarefighting.blogspot.com


Photobucket
แจ้งเตือนภัย ! Crypt0L0cker (Ransomware)
เข้ารหัสข้อมูลใน คอมพิวเตอร์ กำลังระบาดในไทย
และกำลังระบาดหนักในเกาหลี
ThaiCERT , Crytpo Prevention Tool

*ห้ามจ่ายเงินโดยเด็ดขาด เพราะจะเสียทั่้งเงินและกู้ข้อมูลไม่ได้
รบกวนคนที่เข้ามาอ่านช่วยแชร์ด้วยนะครับ
http://hotzone-it.blogspot.com/2015/07/how-to-remove-crypt0l0cker-not.html
==============================================
PeeTechFix >> JupiterFix
==============================================
Photobucket

วิธีใช้งาน : JupiterFix-Win32.PSW.OnlineGames
ท่านสามารถตรวจสอบรายชื่อ Virus ที่โปรแกรม สามารถ Clean ได้ ใน VirusList.txt
-------------------------------------------------------------------------------------
ท่านใดที่ Download PeeTechFix tool ไปใช้แล้วมีปัญหาหรือลบไม่ออก โปรดแจ้งปัญหา ที่ email : MalwareHunter.info@gmail.com ด้วยครับ หรือส่งไฟล์ virus ให้ด้วย จะขอบพระคุณอย่างยิ่ง
-------------------------------------------------------------------------------------
Safemode Recovery (.reg) แก้ปัญหา Virus ลบ Key Safeboot แล้วเข้า safemode ไม่ได้
------------------------------------------------------------------------------------
วิธีแก้ Error message (แก้อาการเปิดไฟล์ .exe ใน USB Drive ไม่ได้)
"Windows cannot open this program because it has been prevented by a software restriction policy. For more information, open Event Viewer or contact your system administrator"
วิธีแก้ ดูที่ link นี้ครับ
-------------------------------------------------------------------------------------
วิธีแก้ MSN /Windows Live Messenger Disconnect (จาก virus OnlineGames)
-------------------------------------------------------------------------------------
How to start Windows in Safe Mode


Thursday

Fake Alert: Antivirus Plus

Fake Alert : Antivirus Plus

Photobucket
-------------------------------------------------------------------------------
AntivirusVersionLast UpdateResult
a-squared4.5.0.502010.04.15Trojan.SuspectCRC!IK
AhnLab-V35.0.0.22010.04.14-
AntiVir7.10.6.772010.04.14TR/Crypt.ZPACK.Gen
Antiy-AVL2.0.3.72010.04.14-
Authentium5.2.0.52010.04.15W32/Genome.B.gen!Eldorado
Avast4.8.1351.02010.04.14Win32:Trojan-gen
Avast55.0.332.02010.04.14Win32:Trojan-gen
AVG9.0.0.7872010.04.14Generic17.AYNV
BitDefender7.22010.04.15Trojan.Generic.KD.6291
CAT-QuickHeal10.002010.04.14-
ClamAV0.96.0.3-git2010.04.14-
Comodo46002010.04.15Heur.Suspicious
DrWeb5.0.2.033002010.04.15-
eSafe7.0.17.02010.04.14Win32.TRCrypt.ZPACK
eTrust-Vet35.2.74262010.04.14-
F-Prot4.5.1.852010.04.14W32/Genome.B.gen!Eldorado
F-Secure9.0.15370.02010.04.15Trojan.Generic.KD.6291
Fortinet4.0.14.02010.04.12-
GData192010.04.15Trojan.Generic.KD.6291
IkarusT3.1.1.80.02010.04.15Trojan.SuspectCRC
Jiangmin13.0.9002010.04.13-
Kaspersky7.0.0.1252010.04.15Trojan-Downloader.Win32.FraudLoad.xaht
McAfee5.400.0.11582010.04.15-
McAfee-GW-Edition6.8.52010.04.15Trojan.Crypt.ZPACK.Gen
Microsoft1.56052010.04.14Trojan:Win32/FakePlus
NOD3250292010.04.14a variant of Win32/Kryptik.COO
Norman6.04.112010.04.14-
nProtect2010-04-14.012010.04.14-
Panda10.0.2.72010.04.14Trj/CI.A
PCTools7.0.3.52010.04.15-
Prevx3.02010.04.15High Risk Cloaked Malware
Rising22.43.02.042010.04.14-
Sophos4.52.02010.04.15Mal/FakeAV-CQ
Sunbelt61772010.04.15Trojan.Win32.Generic!BT
Symantec20091.2.0.412010.04.15Trojan.FakeAV
TheHacker6.5.2.0.2612010.04.14-
TrendMicro9.120.0.10042010.04.14-
VBA323.12.12.42010.04.14-
ViRobot2010.4.14.22762010.04.14-
VirusBuster5.0.27.02010.04.14Trojan.FakePlus.IC
-------------------------------------------------------------------------------
File size: 223232 bytes
MD5 : 4ab2cb0dd839df64ec8d682f904827ef
SHA1 : 6446a7980e27582a8c3f44903a38fa5d79be910d
-------------------------------------------------------------------------------
Files Added
C:\Documents and Settings\[User name]\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll
C:\Documents and Settings\[User name]\Application Data\avp.ico
C:\Documents and Settings\[User name]\Start Menu\Programs\Startup\AntiVirus Plus.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AntiVirus Plus.lnk
C:\Documents and Settings\[User name]\Start Menu\Programs\AntiVirus Plus\AntiVirus Plus.lnk
C:\Documents and Settings\[User name]\Start Menu\Programs\AntiVirus Plus\EULA.url
C:\Documents and Settings\[User name]\Start Menu\Programs\AntiVirus Plus\Uninstall.lnk
C:\Documents and Settings\[User name]\Desktop\AntiVirus Plus.lnk
C:\Documents and Settings\[User name]\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus Plus.lnk
C:\Documents and Settings\[User name]\Desktop\~res.htm
C:\Documents and Settings\[User name]\Recent\Antivirus plus.log.lnk


Keys Added
HKLM\SOFTWARE\Classes\CLSID\{C2B5AAB8-2183-4be7-81A6-F11493C45872}
HKLM\SOFTWARE\Classes\CLSID\{C2B5AAB8-2183-4be7-81A6-F11493C45872}\InProcServer32
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2B5AAB8-2183-4be7-81A6-F11493C45872}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus

Values added
HKLM\SOFTWARE\Classes\CLSID\
{C2B5AAB8-2183-4be7-81A6-F11493C45872}\
InProcServer32\: "%userProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll"

HKLM\SOFTWARE\Classes\CLSID\
{C2B5AAB8-2183-4be7-81A6-F11493C45872}\
InProcServer32\ThreadingModel: "Apartment"

HKLM\SOFTWARE\Classes\CLSID\
{C2B5AAB8-2183-4be7-81A6-F11493C45872}\: 41 6E 74 69 76 69 72 75 73 20 50 6C 75 73 20 42 48 4F 00 00 43 4C 53 49

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2B5AAB8-2183-4be7-81A6-F11493C45872}\NoExplorer: 0x00000001

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus Plus: ""%system32%\rundll32.exe" "%userProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll", start 1"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus\DisplayName: "AntiVirus Plus"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus\UninstallString: ""%system%\rundll32.exe" "%userProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll", start 1 uninstall"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus\
NoModify: 0x00000001

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus\
NoRepair: 0x00000001

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus Plus\DisplayIcon: "%userProfile%\Application Data\avp.ico,0"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
AntiVirus Plus: ""%system%\rundll32.exe" "%userProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll", start 1"

Values modified
HKLM\SYSTEM\ControlSet001\Services\wscsvc\Start: 0x00000004
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start: 0x00000004

Hosts Modified
O1 - Hosts: 78.159.125.56 www.google.co.jp
O1 - Hosts: 78.159.125.56 www.google.co.uk
O1 - Hosts: 78.159.125.56 search.yahoo.com
O1 - Hosts: 78.159.125.56 us.search.yahoo.com
O1 - Hosts: 78.159.125.56 www.google.ch
O1 - Hosts: 78.159.125.56 www.google.gr
O1 - Hosts: 78.159.125.56 www.google.fr
O1 - Hosts: 78.159.125.56 www.google.com.br
O1 - Hosts: 78.159.125.56 www.google.co.za
O1 - Hosts: 78.159.125.56 www.google.be
O1 - Hosts: 78.159.125.56 uk.search.yahoo.com
O1 - Hosts: 78.159.125.56 www.google.at
O1 - Hosts: 78.159.125.56 www.google.com.au
O1 - Hosts: 78.159.125.56 www.google.dk
O1 - Hosts: 78.159.125.56 www.google.nl
O1 - Hosts: 78.159.125.56 www.google.pt
O1 - Hosts: 78.159.125.56 www.google.ie
O1 - Hosts: 78.159.125.56 www.google.com
O1 - Hosts: 78.159.125.56 www.google.de
O1 - Hosts: 78.159.125.56 www.google.no
O1 - Hosts: 78.159.125.56 www.google.fi
O1 - Hosts: 78.159.125.56 www.google.es
O1 - Hosts: 78.159.125.56 www.google.com.mx
O1 - Hosts: 78.159.125.56 www.google.ca
O1 - Hosts: 78.159.125.56 www.google.se
O1 - Hosts: 78.159.125.56 www.google.it

-------------------------------------------------------------------------
วิธีกำจัด / แก้ไข : Fake Alert : Antivirus Plus
-------------------------------------------------------------------------

1. Run rkill.com

2. ใช้ Hijack This fix checked บรรทัดต่อไปนี้

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\rundll32.exe
O1 - Hosts: 78.159.125.56 www.google.co.jp
O1 - Hosts: 78.159.125.56 www.google.co.uk
O1 - Hosts: 78.159.125.56 search.yahoo.com
O1 - Hosts: 78.159.125.56 us.search.yahoo.com
O1 - Hosts: 78.159.125.56 www.google.ch
O1 - Hosts: 78.159.125.56 www.google.gr
O1 - Hosts: 78.159.125.56 www.google.fr
O1 - Hosts: 78.159.125.56 www.google.com.br
O1 - Hosts: 78.159.125.56 www.google.co.za
O1 - Hosts: 78.159.125.56 www.google.be
O1 - Hosts: 78.159.125.56 uk.search.yahoo.com
O1 - Hosts: 78.159.125.56 www.google.at
O1 - Hosts: 78.159.125.56 www.google.com.au
O1 - Hosts: 78.159.125.56 www.google.dk
O1 - Hosts: 78.159.125.56 www.google.nl
O1 - Hosts: 78.159.125.56 www.google.pt
O1 - Hosts: 78.159.125.56 www.google.ie
O1 - Hosts: 78.159.125.56 www.google.com
O1 - Hosts: 78.159.125.56 www.google.de
O1 - Hosts: 78.159.125.56 www.google.no
O1 - Hosts: 78.159.125.56 www.google.fi
O1 - Hosts: 78.159.125.56 www.google.es
O1 - Hosts: 78.159.125.56 www.google.com.mx
O1 - Hosts: 78.159.125.56 www.google.ca
O1 - Hosts: 78.159.125.56 www.google.se
O1 - Hosts: 78.159.125.56 www.google.it

O2 - BHO: Antivirus Plus BHO - {C2B5AAB8-2183-4be7-81A6-F11493C45872} - %UserProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll

O4 - HKLM\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "%UserProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll", start 1

O4 - HKCU\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "%UserProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll", start 1

O4 - Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe

3. Scan ด้วย Malwarebytes' Anti-Malware อีกครั้งหนึ่ง
...

No comments:

Post a Comment

Exploit-DB updates

Exploits Database by Offensive Security

Metasploit

Metasploit Framework: Activity

iDefense Labs Software Releases