avmb.exe , aqoeerw.exe
Files size 121,618 bytes
MD5: 000B9828ED4BC8F55BBF60A858A41ECC
SHA-1: 8BE35CF0671B84D6A3A61D2DF17A7E579A9D9BC2
==================================================
Files Created
%System%\aqoeerw.exe
%System%\bnmkue0.dll (0-9)
X:\avmb.exe
X:\autorun.inf
%System% = C:\Windows\System32
X:\ C:\ - Z:\
Registry Modifications
Key Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN
Values Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo = "awszad.r"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
coolsos = "%System%\aqoeerw.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091
Remote Host
202.111.175.157 port 80
URLs to be download/data identified
http://www.sina90f.com/1tw/at1.rar
http://www.googles0f.com/1tw/at.rar
=======================================================
วิธีกำจัด/แก้ virus : avmb.exe , aqoeerw.exe
=======================================================
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames
หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เช่น
Panda USB Vaccine
http://www.pandasecurity.com/homeusers/downloads/usbvaccine/
or
KB971029, KB967715 (Disable AutoRun)
http://hotzone-it.blogspot.com/2009/08/kb971029-fix-autorun-microsoft.html
No comments:
Post a Comment