j8dfa.exe , ahnsbsb.exe
MD5: CE295C940F5D7681733EB2E0C21E68B5
SHA-1: 7B38540A639A7E2C9BEF214F7656A15145F016E7
=================================================
Files Created
%System%\ahnsbsb.exe
%System%\ahnfgss0.dll (0-9)
%System%\ahnxsds0.dll (0-9)
X:\j8dfa.exe
X:\autorun.inf
%System% = C:\Windows\System32\
X:\ = C:\- Z:\
File deleted
%System%\drivers\cdaudio.sys
Registry Modifications
Keys Added
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\ProgID
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\Programmable
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{AF4DA69B-E1D6-469A-855B-6445294857D4}
HKLM\SYSTEM\ControlSet001\Services\AVPsys
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum
Values Added
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\VersionIndependentProgID\
(Default) = "IEHlprObj.IEHlprObj"
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\ProgID\
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\InprocServer32\
(Default) = "%System%\ahnxsds0.dll"
ThreadingModel = "Apartment"
HKLM\SOFTWARE\Classes\CLSID\
{AF4DA69B-E1D6-469A-855B-6445294857D4}\
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\TypeLib\
(Default) = "{AF4DA692-E1D6-469A-855B-6445294857D4}"
Version = "1.0"
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\ProxyStubClsid32\
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\ProxyStubClsid\
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\
{AF4DA69C-E1D6-469A-855B-6445294857D4}\
(Default) = "IIEHlprObj"
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\0\win32\
(Default) = "%System%\ahnxsds0.dll"
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\HELPDIR\
(Default) = "%System%\"
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\FLAGS\
(Default) = "0"
HKLM\SOFTWARE\Classes\TypeLib\
{AF4DA692-E1D6-469A-855B-6445294857D4}\1.0\
(Default) = "IEHelper 1.0 Type Library"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer\
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID\
(Default) = "{AF4DA69B-E1D6-469A-855B-6445294857D4}"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\
(Default) = "IEHlprObj Class"
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Enum\
Count = 0x00000000
NextInstance = 0x00000000
INITSTARTFAILED = 0x00000001
HKLM\SYSTEM\ControlSet001\Services\AVPsys\Security\
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM\SYSTEM\ControlSet001\Services\AVPsys\
Type = 0x00000001
Start = 0x00000003
ErrorControl = 0x00000001
ImagePath = "%System%\drivers\cdaudio.sys"
DisplayName = "AVPsys"
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Enum\
Count = 0x00000000
NextInstance = 0x00000000
INITSTARTFAILED = 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\Security\
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
HKLM\SYSTEM\CurrentControlSet\Services\AVPsys\
Type = 0x00000001
Start = 0x00000003
ErrorControl = 0x00000001
ImagePath = "%System%\drivers\cdaudio.sys"
DisplayName = "AVPsys"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
ahnsoft = "%System%\ahnsbsb.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091
=======================================================
วิธีกำจัด/แก้ virus : j8dfa.exe , ahnsbsb.exe
=======================================================
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames
No comments:
Post a Comment