File size 19,968 bytes
MD5: 0CC9CF665B24C217F26F459059C0DB74
SHA-1: 5D0F040A0AA4F3E31EE73809BDB8E0AB5976F72F
==================================================
w4mgXcd4.dll
File size 49,152 bytes
MD5: 426CAACB0CD46DECF56FFEF59E0383C7
SHA-1: 8C6C33126E240011A439B0C0142B241752E5D23F
==================================================
Antivirus | Version | Last Update | Result |
---|---|---|---|
a-squared | 4.5.0.50 | 2010.03.03 | Trojan.Hiloti!IK |
AhnLab-V3 | 5.0.0.2 | 2010.03.02 | - |
AntiVir | 8.2.1.180 | 2010.03.02 | - |
Antiy-AVL | 2.0.3.7 | 2010.03.02 | - |
Authentium | 5.2.0.5 | 2010.03.03 | - |
Avast | 4.8.1351.0 | 2010.03.02 | - |
Avast5 | 5.0.332.0 | 2010.03.02 | - |
AVG | 9.0.0.730 | 2010.03.02 | - |
BitDefender | 7.2 | 2010.03.03 | - |
CAT-QuickHeal | 10.00 | 2010.03.02 | - |
ClamAV | 0.96.0.0-git | 2010.03.03 | - |
Comodo | 4091 | 2010.02.28 | - |
DrWeb | 5.0.1.12222 | 2010.03.03 | Trojan.Packed.453 |
eSafe | 7.0.17.0 | 2010.03.02 | - |
eTrust-Vet | 35.2.7337 | 2010.03.03 | - |
F-Prot | 4.5.1.85 | 2010.03.02 | - |
F-Secure | 9.0.15370.0 | 2010.03.02 | Packed:W32/Mufanom.A |
Fortinet | 4.0.14.0 | 2010.02.28 | - |
GData | 19 | 2010.03.03 | - |
Ikarus | T3.1.1.80.0 | 2010.03.02 | Trojan.Hiloti |
Jiangmin | 13.0.900 | 2010.03.03 | - |
K7AntiVirus | 7.10.987 | 2010.03.02 | - |
Kaspersky | 7.0.0.125 | 2010.03.03 | - |
McAfee | 5908 | 2010.03.02 | - |
McAfee+Artemis | 5908 | 2010.03.02 | - |
McAfee-GW-Edition | 6.8.5 | 2010.03.03 | - |
Microsoft | 1.5502 | 2010.03.03 | Trojan:Win32/Hiloti.gen!D |
NOD32 | 4910 | 2010.03.02 | - |
Norman | 6.04.08 | 2010.03.02 | - |
nProtect | 2009.1.8.0 | 2010.03.02 | - |
Panda | 10.0.2.2 | 2010.03.02 | - |
PCTools | 7.0.3.5 | 2010.03.02 | - |
Prevx | 3.0 | 2010.03.03 | - |
Rising | 22.37.01.04 | 2010.03.02 | - |
Sophos | 4.50.0 | 2010.03.02 | Mal/Hiloti-C |
Sunbelt | 5733 | 2010.03.03 | - |
Symantec | 20091.2.0.41 | 2010.03.03 | Suspicious.Insight |
TheHacker | 6.5.1.7.218 | 2010.03.03 | - |
TrendMicro | 9.120.0.1004 | 2010.03.02 | - |
VBA32 | 3.12.12.2 | 2010.03.02 | Bscope.Malware-Cryptor.Tip |
ViRobot | 2010.3.2.2208 | 2010.03.02 | - |
VirusBuster | 5.0.27.0 | 2010.03.02 | - |
-------------------------------------------------------------------------------
Files Added
C:\WINDOWS\system32\nynw.wmo
%Temp%Temp\E51.tmp
C:\WINDOWS\w4mgXcd4.dll
%System% = C:\WINDOWS\system32
%WinDir% = C:\WINDOWS
%Temp% = C:\Documents and Settings\[UserName]\Local Settings\Temp
Keys added
HKLM\SOFTWARE\Classes\idid
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Yxitageqe
HKCU\Software\Microsoft\Office\11.0\Word\Security
Values Added
HKLM\SOFTWARE\Classes\idid\op: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Yxitageqe\
Cvebahubimu: 43 01 38 03 58 05 51 07 41 09 44 0B 48 0D 41 0F 47 11 41 13 48 15 61 17 2C 19 77 1B 7B 1D 46 1F 43 21 46 23 10 25 08 27 4C 29 46 2B 40 2D 2E 2F
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Yxitageqe\Xfezepixohaye: "99"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Yxitageqe\
Nxoliqop: 38 01 35 03 31 05 06 07
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Yxitageqe\
Egamujoxuc: 44 01 32 03 36 05 34 07 39 09 39 0B 34 0D 3A 0F 22 11 53 13 57 15 26 17 2C 19 23 1B 24 1D 5A 1F 18 21 14 23 13 25 16 27 11 29 6F 2B 6A 2D 6F 2F 02 31 77 33 71 35 01 37 0A 39 0A 3B 0E 3D 0F 3F 40 41
HKCU\Software\Microsoft\Office\11.0\Word\Security\Level: 0x00000004
HKCU\Software\Microsoft\Office\11.0\Word\Security\AccessVBOM: 0x00000000
Values modified
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Shell: "Explorer.exe rundll32.exe nynw.wmo mynleeq"
HKLM\SYSTEM\ControlSet001\Control\Lsa\Notification Packages: 'scecli w4mgXcd4.dll'
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages: 'scecli w4mgXcd4.dll'
HKCU\Software\Microsoft\Office\11.0\Word\MTTF: 0x00042BEB
HKCU\Software\Microsoft\Office\11.0\Word\MTTA: 0x00042BEB
HKCU\Software\Microsoft\OfficeLive\wordCmdBarTop: 0x00000000
HKCU\Software\Microsoft\OfficeLive\wordCmdBarRowIndex: 0xFFFFFFFF
------------------------------------------------------------------------
วิธีกำจัด / แก้ไข : w4mgXcd4.dll ,nynw.wmo
------------------------------------------------------------------------
Download Fix Tool : PeeTechFix-Win32.Oficla 1.0
1. Install RemoveOnReboot.exe
2. เข้าไปที่ C:\WINDOWS\system32
3. Click ขวาที่ nynw.wmo > Send to > RemoveOnReboot.exe
4. Run PeeTechFix-Win32.Oficla
5. Restart
...
No comments:
Post a Comment