Files size 108,286 bytes
MD5: 86F86117C10A9239839B4BDAC9267BE0
SHA-1: 82E2F5D3E89D444B8974951AEC9250CD0363883B
SHA-1: 82E2F5D3E89D444B8974951AEC9250CD0363883B
=======================================================
Files Created
C:\WINDOWS\system32\uret463.exe
C:\WINDOWS\system32\lhgjyit0.dll (0-9)
X:\d22xl.bat
X:\autorun.inf
Registry Modifications
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
dorfgwe = "%System%\uret463.exe
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue: 0x00000000 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden: 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun: 0x00000091
=========================================================
วิธีกำจัด/ แก้ virus :
d22xl.bat
================================================================
Download : PeeTechFix-Win32/PSW.OnlineGame 2.0.5
1. Run
PeeTechFix-Win32/PSW.OnlineGame 2.0.5
2. เข้าไป delete ไฟล์
d22xl.bat
แบบ manual ทุก root drive ( C:\ - Z:\)
หมายเหตุ : จะ Update ให้ใน AVDB-013 นะครับ (กลับจากพักร้อนก่อนนะ )
No comments:
Post a Comment