"Malware Fix รวมวิธีแก้ปัญหา virus computer โครงการทำดีเพื่อสังคม" "เนื่องจากภาระหน้าที่ทางการงาน ต้องขออภัยผู้เยี่ยมชมทุกท่านนะครับ ที่เ้ข้ามาแล้ว ไม่มีการ update virus ตัวใหม่ นะครับ"

Information

http://malwarefighting.blogspot.com


Photobucket
แจ้งเตือนภัย ! Crypt0L0cker (Ransomware)
เข้ารหัสข้อมูลใน คอมพิวเตอร์ กำลังระบาดในไทย
และกำลังระบาดหนักในเกาหลี
ThaiCERT , Crytpo Prevention Tool

*ห้ามจ่ายเงินโดยเด็ดขาด เพราะจะเสียทั่้งเงินและกู้ข้อมูลไม่ได้
รบกวนคนที่เข้ามาอ่านช่วยแชร์ด้วยนะครับ
http://hotzone-it.blogspot.com/2015/07/how-to-remove-crypt0l0cker-not.html
==============================================
PeeTechFix >> JupiterFix
==============================================
Photobucket

วิธีใช้งาน : JupiterFix-Win32.PSW.OnlineGames
ท่านสามารถตรวจสอบรายชื่อ Virus ที่โปรแกรม สามารถ Clean ได้ ใน VirusList.txt
-------------------------------------------------------------------------------------
ท่านใดที่ Download PeeTechFix tool ไปใช้แล้วมีปัญหาหรือลบไม่ออก โปรดแจ้งปัญหา ที่ email : MalwareHunter.info@gmail.com ด้วยครับ หรือส่งไฟล์ virus ให้ด้วย จะขอบพระคุณอย่างยิ่ง
-------------------------------------------------------------------------------------
Safemode Recovery (.reg) แก้ปัญหา Virus ลบ Key Safeboot แล้วเข้า safemode ไม่ได้
------------------------------------------------------------------------------------
วิธีแก้ Error message (แก้อาการเปิดไฟล์ .exe ใน USB Drive ไม่ได้)
"Windows cannot open this program because it has been prevented by a software restriction policy. For more information, open Event Viewer or contact your system administrator"
วิธีแก้ ดูที่ link นี้ครับ
-------------------------------------------------------------------------------------
วิธีแก้ MSN /Windows Live Messenger Disconnect (จาก virus OnlineGames)
-------------------------------------------------------------------------------------
How to start Windows in Safe Mode


Monday

Fake alert : PC Defender Antivitus

Fake alert : PC Defender Antivitus

Photobucket


File size: 1056768 bytes
MD5 : 2396047703db29f8789df8d1bb91d236
SHA1 : e079605c0b426a24be68485130f58db11f221e34
...
AntivirusVersionLast UpdateResult
AhnLab-V32010.08.08.002010.08.07-
AntiVir8.2.4.342010.08.08-
Antiy-AVL2.0.3.72010.08.06-
Authentium5.2.0.52010.08.07-
Avast4.8.1351.02010.08.08Win32:Adware-gen
Avast55.0.332.02010.08.08Win32:Adware-gen
AVG9.0.0.8512010.08.08-
BitDefender7.22010.08.08-
CAT-QuickHeal11.002010.08.07-
ClamAV0.96.0.3-git2010.08.08-
Comodo56862010.08.08-
DrWeb5.0.2.033002010.08.08Trojan.Fakealert.18633
Emsisoft5.0.0.362010.08.08-
eSafe7.0.17.02010.08.08-
eTrust-Vet36.1.77732010.08.07-
F-Prot4.6.1.1072010.08.07-
F-Secure9.0.15370.02010.08.07-
Fortinet4.1.143.02010.08.08-
GData212010.08.08Win32:Adware-gen
IkarusT3.1.1.84.02010.08.08-
Jiangmin13.0.9002010.08.07-
Kaspersky7.0.0.1252010.08.08-
McAfee5.400.0.11582010.08.08-
McAfee-GW-Edition2010.12010.08.08-
Microsoft1.60042010.08.08-
NOD3253492010.08.07Win32/Adware.PCDefender
Norman6.05.112010.08.08-
nProtect2010-08-08.012010.08.08-
Panda10.0.2.72010.08.08-
PCTools7.0.3.52010.08.08-
Prevx3.02010.08.08-
Rising22.59.05.042010.08.07-
Sophos4.56.02010.08.08-
Sunbelt67032010.08.08Trojan.Win32.Generic.pak!cobra
SUPERAntiSpyware4.40.0.10062010.08.08-
Symantec20101.1.1.72010.08.08-
TheHacker6.5.2.1.3382010.08.08-
TrendMicro9.120.0.10042010.08.08-
TrendMicro-HouseCall9.120.0.10042010.08.08-
VBA323.12.12.82010.08.04-
ViRobot2010.7.29.39612010.08.08-
VirusBuster5.0.27.02010.08.08-
...

Files Added
C:\Program Files\Def Group\PC Defender\uninstall.bat
C:\Program Files\Def Group\PC Defender\proccheck.exe
C:\Program Files\Def Group\PC Defender\rundelay.exe
C:\Program Files\Def Group\PC Defender\prockill64.exe
C:\Program Files\Def Group\PC Defender\prockill32.exe
C:\Program Files\Def Group\PC Defender\pcdef.exe
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\PC Defender.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\Uninstall.lnk


Registry modification
Values Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
PC Defender: "C:\Program Files\Def Group\PC Defender\pcdef.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\AuthorizedCDFPrefix: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Comments: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Contact: "Def Group"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\DisplayVersion: "2.0.0"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\HelpLink: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\HelpTelephone: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\InstallDate: "20100809"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\InstallLocation: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\InstallSource: "C:\Documents and Settings\Administrator\Desktop\"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\ModifyPath: "MsiExec.exe /X{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\NoModify: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Publisher: "Def Group"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Readme: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Size: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\EstimatedSize: 0x0000053C
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\UninstallString: "MsiExec.exe /X{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\URLInfoAbout: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\URLUpdateInfo: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\VersionMajor: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\VersionMinor: 0x00000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\WindowsInstaller: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Version: 0x02000000
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\Language: 0x00000409
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{456A3B12-8FE6-41AE-9E5C-5E55F0712C09}\DisplayName: "PC Defender"

Value Modified
HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify: 0x00000001

------------------------------------------------------------------------
วิธีกำจัด /แก้ไข : Fake alert : PC Defender Antivitus
------------------------------------------------------------------------
วิธีที่ 1 : Manual Delete

1. โปรแกรม Process Explorer แล้ว Click ขวาที่ไฟล์ pcdef.exe แล้วเลือก Kill process Tree

Photobucket

2. เข้าไปที่ C:\Program Files แล้ว delete folder ชื่อ Def Group ทิ้งไป
3. ใช้ โปรแกรม Hijack This Fix checked ที่บรรทัดนี้

O4 - HKLM\..\Run: [PC Defender] C:\Program Files\Def Group\PC Defender\pcdef.exe

........................
or

วิธีที่ 2 : ใช้โปรแกรม Malwarebytes' AntiMalware กำจัดออก

Photobucket


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4410

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

09/08/2553 20:35:14
mbam-log-2010-08-09 (20-35-14).txt

Scan type: Quick scan
Objects scanned: 129610
Time elapsed: 5 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af4da69b-e1d6-469a-855b-6445294857d4} (Spyware.OnlineGames) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pc defender (Rogue.PCDefender) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\Program Files\Def Group\PC Defender (Rogue.PCDefender) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender (Rogue.PCDefender) -> No action taken.

Files Infected:
C:\Program Files\Def Group\PC Defender\pcdef.exe (Rogue.PCDefender) -> No action taken.
C:\Program Files\Def Group\PC Defender\proccheck.exe (Rogue.PCDefender) -> No action taken.
C:\Program Files\Def Group\PC Defender\prockill32.exe (Rogue.PCDefender) -> No action taken.
C:\Program Files\Def Group\PC Defender\prockill64.exe (Rogue.PCDefender) -> No action taken.
C:\Program Files\Def Group\PC Defender\rundelay.exe (Rogue.PCDefender) -> No action taken.
C:\Program Files\Def Group\PC Defender\uninstall.bat (Rogue.PCDefender) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\PC Defender.lnk (Rogue.PCDefender) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\Uninstall.lnk (Rogue.PCDefender) -> No action taken.

No comments:

Post a Comment

Exploit-DB updates

Exploits Database by Offensive Security

Metasploit

Metasploit Framework: Activity

iDefense Labs Software Releases