Files size 126,656 bytes
MD5: 0x59410CCC9572CE2851827C23336A174C
SHA-1: 0x3E23464479F3BB7F48980214D6976540F54B273A
===================================================
Files Created
C:\WINDOWS\system32\aqoeerw.exe
C:\WINDOWS\system32\bnmkue0.dll (0-9)
X:\n89f1d1w.exe
X:\autorun.inf
Registry Modifications
Key Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
Value Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\
urlinfo : awscjm.r
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
coolsos : %System%\aqoeerw.exe
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ Folder\Hidden\SHOWALL\CheckedValue: 0x00000000 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
ShowSuperHidden: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ NoDriveTypeAutoRun: 0x00000091
URL to be downloaded
http://www.765hdc.com/1tw/at1.rar > %Temp%\at1.rar
-----------------------------------------------------------------------วิธีกำจัด n89f1d1w.exe ,aqoeerw.exe
-----------------------------------------------------------------------
Download Fix Tool: PeeTechFix-PSW.OnlineGame 2.05 AVDB-009
http://hotzone-it.blogspot.com/2009/08/virus-remove-tool.html
No comments:
Post a Comment