Win32/AutoRun.Agent.UP ( Detect by NOD32)
File size: 56320 bytes
MD5 : febff135ee99795e0dbf52c5ce4adecb
SHA1 : 66300ed2fd9a423a6f50135cced87901378ebc77
=======================================================
Antivirus | Version | Last Update | Result |
---|---|---|---|
a-squared | 4.5.0.50 | 2010.03.11 | - |
AhnLab-V3 | 5.0.0.2 | 2010.03.11 | - |
AntiVir | 8.2.1.180 | 2010.03.11 | TR/Crypt.XDR.Gen |
Antiy-AVL | 2.0.3.7 | 2010.03.11 | - |
Authentium | 5.2.0.5 | 2010.03.11 | - |
Avast | 4.8.1351.0 | 2010.03.10 | - |
Avast5 | 5.0.332.0 | 2010.03.10 | - |
AVG | 9.0.0.787 | 2010.03.10 | Injector.EZ |
BitDefender | 7.2 | 2010.03.11 | - |
CAT-QuickHeal | 10.00 | 2010.03.11 | - |
ClamAV | 0.96.0.0-git | 2010.03.11 | - |
Comodo | 4223 | 2010.03.11 | - |
DrWeb | 5.0.1.12222 | 2010.03.11 | - |
eSafe | 7.0.17.0 | 2010.03.10 | - |
eTrust-Vet | 35.2.7353 | 2010.03.11 | - |
F-Prot | 4.5.1.85 | 2010.03.10 | - |
F-Secure | 9.0.15370.0 | 2010.03.11 | - |
Fortinet | 4.0.14.0 | 2010.03.09 | - |
GData | 19 | 2010.03.11 | - |
Ikarus | T3.1.1.80.0 | 2010.03.11 | - |
Jiangmin | 13.0.900 | 2010.03.11 | - |
K7AntiVirus | 7.10.994 | 2010.03.10 | - |
Kaspersky | 7.0.0.125 | 2010.03.11 | - |
McAfee | 5916 | 2010.03.10 | - |
McAfee+Artemis | 5916 | 2010.03.10 | Artemis!FEBFF135EE99 |
McAfee-GW-Edition | 6.8.5 | 2010.03.11 | Trojan.Crypt.XDR.Gen |
Microsoft | 1.5502 | 2010.03.11 | - |
NOD32 | 4934 | 2010.03.11 | a variant of Win32/AutoRun.Agent.UP |
Norman | 6.04.08 | 2010.03.10 | W32/Obfuscated.H!genr |
nProtect | 2009.1.8.0 | 2010.03.11 | - |
Panda | 10.0.2.2 | 2010.03.10 | - |
PCTools | 7.0.3.5 | 2010.03.11 | - |
Rising | 22.38.03.04 | 2010.03.11 | - |
Sophos | 4.51.0 | 2010.03.11 | Mal/Behav-043 |
Sunbelt | 5822 | 2010.03.11 | Trojan.Win32.Generic!BT |
Symantec | 20091.2.0.41 | 2010.03.11 | Suspicious.Insight |
TheHacker | 6.5.2.0.230 | 2010.03.11 | - |
TrendMicro | 9.120.0.1004 | 2010.03.11 | - |
VBA32 | 3.12.12.2 | 2010.03.11 | - |
ViRobot | 2010.3.11.2221 | 2010.03.11 | - |
VirusBuster | 5.0.27.0 | 2010.03.10 | - |
-------------------------------------------------------------------------------
Files Added
%Temp%\ader.exe
%Temp%\mxs.exe
%Temp%\[FolderName].exe
%Temp%\_1897.tmp
%Windir%\mssrvc\svchost.exe
%Windir%\Temp\rdl1896.tmp
%Windir%\Temp\rdl1896.tmp.exe
%System%\crt4.dll
%System%\kbupdate.dll
%System%\kbdatat4.dll
%System%\kboem32.dat
%System%\crt.dat
%System%\rdl1898.tmp
%System%\rdl1898.tmp.exe
%System%\drivers\avfwimq.sys
็สร้าง Folder ปลอมใน USB ใน Drive > [Folder].exe
และได้ซ่อน Folder จริงใน USB Drive ไว้
มี Popup ฟ้องเกี่ยวกับไฟล์ mxs.exe
Registrys Modified
Keys added
HKLM\SOFTWARE\Microsoft\Active Setup\Data
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kbupdate
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\Control
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum
HKLM\SYSTEM\ControlSet001\Services\avfwimq
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\Control
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum
Values added
HKLM\SOFTWARE\Microsoft\Active Setup\Data\data5: 48 52 37 36 25 1F 45 8C F3 70 F5 5F 87 E1 44 8B F7 4E CE 05 84 4E B9 B4 AC 90 F2 70 F5 7B CD 30 39 2C 32 3D 10 2C 3B D2 B5 3D EA 50 8F E9 5B 8B CC 49 94 23 A6 08 B6 B1 AD 8E F2 70 C1 5F
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
svchost: "C:\WINDOWS\mssrvc\svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\DllName: 6B 62 75 70 64 61 74 65 2E 64 6C 6C 00 00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Startup: "WinlogonStartupEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Logoff: "WinlogonLogoffEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Shutdown: "WinlogonLogoffEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Asynchronous: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Impersonate: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\*NewlyCreated*: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\ActiveService: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Service: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Legacy: 0x00000001
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
ConfigFlags: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Class: "LegacyDriver"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
DeviceDesc: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\
NextInstance: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
Count: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
Count: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\
0: "Root\LEGACY_AVFWIMQ\0000"
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\Count: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\NextInstance: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Start: 0x00000002
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Type: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\ErrorControl: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\DisplayName: "avfwimq"
HKLM\SYSTEM\ControlSet001\Services\avfwimq\ImagePath: "\??\C:\WINDOWS\System32\DRIVERS\avfwimq.sys"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\*NewlyCreated*: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\ActiveService: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Service: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Legacy: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
ConfigFlags: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Class: "LegacyDriver"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
DeviceDesc: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\
NextInstance: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
Count: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
Count: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\
0: "Root\LEGACY_AVFWIMQ\0000"
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\
Count: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\
NextInstance: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\
Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\
Type: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq
\ErrorControl: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\
DisplayName: "avfwimq"
Values added
HKLM\SOFTWARE\Microsoft\Active Setup\Data\data5: 48 52 37 36 25 1F 45 8C F3 70 F5 5F 87 E1 44 8B F7 4E CE 05 84 4E B9 B4 AC 90 F2 70 F5 7B CD 30 39 2C 32 3D 10 2C 3B D2 B5 3D EA 50 8F E9 5B 8B CC 49 94 23 A6 08 B6 B1 AD 8E F2 70 C1 5F
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
svchost: "C:\WINDOWS\mssrvc\svchost.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\DllName: 6B 62 75 70 64 61 74 65 2E 64 6C 6C 00 00
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Startup: "WinlogonStartupEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Logoff: "WinlogonLogoffEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Shutdown: "WinlogonLogoffEvent"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Asynchronous: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Notify\kbupdate\Impersonate: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\*NewlyCreated*: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\ActiveService: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Service: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Legacy: 0x00000001
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
ConfigFlags: 0x00000000
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
Class: "LegacyDriver"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\0000\
DeviceDesc: "avfwimq"
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ\
NextInstance: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
Count: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\avfwim\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
Count: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\
0: "Root\LEGACY_AVFWIMQ\0000"
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\
Count: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Enum\
NextInstance: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Start: 0x00000002
HKLM\SYSTEM\ControlSet001\Services\avfwimq\Type: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\ErrorControl: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\avfwimq\DisplayName: "avfwimq"
HKLM\SYSTEM\ControlSet001\Services\avfwimq\ImagePath: "\??\C:\WINDOWS\System32\DRIVERS\avfwimq.sys"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\*NewlyCreated*: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Control\ActiveService: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Service: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Legacy: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
ConfigFlags: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
Class: "LegacyDriver"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\0000\
DeviceDesc: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ\
NextInstance: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
Count: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\avfwim\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
Count: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
NextInstance: 0x00000000
HKLM\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum\
INITSTARTFAILED: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\0: "Root\LEGACY_AVFWIMQ\0000"
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\
Count: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Enum\
NextInstance: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Start: 0x00000002
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\Type: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\ErrorControl: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\DisplayName: "avfwimq"
HKLM\SYSTEM\CurrentControlSet\Services\avfwimq\
ImagePath: "\??\C:\WINDOWS\System32\DRIVERS\avfwimq.sys"
Values modified
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Userinit: "%Temp%\[Folder Name].exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
Hidden: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
HideFileExt: 0x00000002
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
AppData: "%System%\config\systemprofile\Application Data"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
Cookies: "%System%\config\systemprofile\Cookies"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
Startup: "%System%\config\systemprofile\Start Menu\Programs\Startup
"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
Cache: "%System%\config\systemprofile\Local Settings\Temporary Internet Files"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
History: "\%System%\config\systemprofile\Local Settings\History"
-------------------------------------------------------------------------
วิธีกำจัด / แก้ไข : Win32/AutoRun.Agent.UP ( NOD32)
-------------------------------------------------------------------------
Download Fix Tool :
(สำหร้บ โปรแกรม DKDC_Hash ต้องติดตั้ง dotnet 2.0 ถึงจะเปิดได้นะครับ)
Manual Delete
ก่อนอื่นให้เสียบ Flash Drive ที่ติดไวรัสนี้ไว้กับ computer ไว้เลยครับ
1. เิปิดโปรแกรม Kill Process แล้ว เลือก End Process ไฟล์ ที่เป็นรูป [FolderName].exe
2. เข้าไปที่ folder mssrvc ที่ตำแหน่ง C:\Windows\mssrvc
Click ขวาที่ไฟล์ svchost.exe เลือก Unlocker
เมื่อขึ้นหน้าต่าง Click ที่ไฟล์ svchost.exe แล้วกดปุ่ม Unlock
(เลือก Option ด้านล่าง เป็น Delete)
3. Click ที่ Start > Setting > Control Panel แล้ว Double click ที่ Folder Options
เมื่อขึ้นหน้าต่าง Folder Option แล้้ว click ที่ view เลือกที่ Show hidden files and folders
และเอาเครื่องหมายถูกออกตรงช่อง Hide extensions for know file types
4. Click Start > Run พิมพ์ %temp% แล้ว Enter จากนั้น Delete ไฟล์ ใน Temp
5. เ้ข้าไป Delete ไฟล์ตามตำแหน่งนี้
%Windir%\Temp\rdl1896.tmp
%Windir%\Temp\rdl1896.tmp.exe
%Windir% = C:\Windows
%System%\crt4.dll
%System%\kbupdate.dll
%System%\kbdatat4.dll
%System%\kboem32.dat
%System%\crt.dat
%System%\rdl1898.tmp
%System%\rdl1898.tmp.exe
%System%\drivers\avfwimq.sys
%System% = C:\Wondows\System32
(ใครใช้โปรแกรม Everything ช่วยในการ Delete ก็ได้ครับ เพียงแต่พิมพ์ชื่อไฟล์ลงไปเท่าีนั้น)
6. ใช้โปรแกรม Hijack This Fix Checked ที่บรรทัดนี้
F2 - REG:system.ini: UserInit=%Temp%\[FolderName].exe
O4 - HKLM\..\Run: [svchost] C:\WINDOWS\mssrvc\svchost.exe
O20 - Winlogon Notify: kbupdate - C:\WINDOWS\SYSTEM32\kbupdate.dll
7. เปิดโปรแกรม RegAssissin จากนั้น Copy Key ที่ virus ได้สร้างไว้ paste ลงในช่อง
แล้ว กดปุ่ม Delete โดยทำทีละ key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kbupdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVFWIMQ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avfwim\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VProEventMonitor\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avfwimq
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVFWIMQ
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avfwim\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VProEventMonitor\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avfwimq
8. เปิดโปรแกรม DKDC_Hash แล้ว Click ที่ ไฟล์ต้นฉบับ เลือกไฟล์ [FolderName].exe
ที่อยู่ใน flash drive เมื่อได้ไฟล์ต้นฉบับแล้ว Click ที่ ค้นหา+ทำลาย
..
No comments:
Post a Comment