ph.com , ckvo.exe
Files size 704,520 bytes
MD5: A9BCE8F0B9888BB8F5FBB7FD16D115E8
SHA-1: F0A75084F357FCCF7C7A98E22AB217DE3D2C7437
==================================================
Files Created
%System%\ckvo.exe
%System%\ckvo0.dll (0-9)
X:\ph.com
X:\autorun.inf
%System% = C:\Windows\System32
X:\ C:\ - Z:\
Registry Modifications
Value Added
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
kamsoft = "%System%\ckvo.exe"
Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091
=======================================================
วิธีกำจัด/แก้ virus : ph.com , ckvo.exe
=======================================================
Download Fix Tool : PeeTechFix-Win32/PSW.OnlineGames
หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เช่น
Panda USB Vaccine
http://www.pandasecurity.com/homeusers/downloads/usbvaccine/
or
KB971029, KB967715 (Disable AutoRun)
http://hotzone-it.blogspot.com/2009/08/kb971029-fix-autorun-microsoft.html
No comments:
Post a Comment