imghyva6.exe , herss.exe
Files size 106496 bytes
MD5: 9383CF94210BBDF523CD2343CAC04437
SHA-1: 4819E7FA2F66B5C960AE219178FD9824714B4C6D
================================================
a-squared 2009.12.27 -
AhnLab-V3 2009.12.26 -
AntiVir 2009.12.26 -
Antiy-AVL 2009.12.25 -
Authentium 2009.12.26 -
Avast 2009.12.27 -
AVG 2009.12.27 -
BitDefender 2009.12.27 -
CAT-QuickHeal 2009.12.26 -
ClamAV 2009.12.27 PUA.Packed.ASPack212
Comodo 2009.12.27 Heur.Packed.Unknown
DrWeb 2009.12.27 -
eSafe 2009.12.24 -
eTrust-Vet 2009.12.25 -
F-Prot 2009.12.26 -
F-Secure 2009.12.27 Suspicious:W32/Malware!Gemini
Fortinet 2009.12.27 -
GData 2009.12.26 -
Ikarus 2009.12.27 -
Jiangmin 2009.12.27 -
K7AntiVirus 2009.12.26 -
Kaspersky 2009.12.27 -
McAfee 2009.12.26 -
McAfee+Artemis 2009.12.26 -
McAfee-GW-Edition 2009.12.27 Heuristic.LooksLike.Win32.Suspicious.H
Microsoft 2009.12.26 -
NOD32 2009.12.27 -
Norman 2009.12.27 -
nProtect 2009.12.27 -
Panda 2009.12.15 -
PCTools 2009.12.27 -
Rising 2009.12.27 -
Sophos 2009.12.27 -
Sunbelt 2009.12.26 Worm.Win32.AutoRun
Symantec 2009.12.27 -
TheHacker 2009.12.26 -
TrendMicro 2009.12.27 PAK_Generic.001
VBA32 2009.12.26 -
ViRobot 2009.12.26 -
VirusBuster 2009.12.26 -
================================================
Files Created
%Temp%\cvasds0.dll (0-9)
%Temp%\herss.exe
X:\imghyva6.exe
X:\autorun.inf
%Temp% = C:\Documents and Settings\[UserName]\Local Settings\Temp\
X:\ = C:\- Z:\
Registry Modifications
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
cdoosoft = "%Temp%\herss.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091
==================================================
วิธีกำจัด/แก้ virus : imghyva6.exe , herss.exe
==================================================
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames
No comments:
Post a Comment