E6zxc.exe
...
| Antivirus | Version | Last update | Result |
|---|---|---|---|
| AhnLab-V3 | 2011.09.04.01 | 2011.09.05 | Dropper/Win32.OnlineGameHack |
| AntiVir | 7.11.14.93 | 2011.09.05 | TR/Crypt.ASPM.Gen2 |
| Antiy-AVL | 2.0.3.7 | 2011.09.05 | - |
| Avast | 4.8.1351.0 | 2011.09.05 | - |
| Avast5 | 5.0.677.0 | 2011.09.05 | - |
| AVG | 10.0.0.1190 | 2011.09.05 | - |
| BitDefender | 7.2 | 2011.09.05 | - |
| ByteHero | 1.0.0.1 | 2011.09.01 | Trojan.Win32.Heur.Gen |
| CAT-QuickHeal | 11.00 | 2011.09.05 | - |
| ClamAV | 0.97.0.0 | 2011.09.05 | PUA.Packed.ASPack |
| Commtouch | 5.3.2.6 | 2011.09.04 | - |
| Comodo | 9997 | 2011.09.05 | TrojWare.Win32.Trojan.Agent.Gen |
| DrWeb | 5.0.2.03300 | 2011.09.05 | - |
| Emsisoft | 5.1.0.11 | 2011.09.05 | Gen.Variant.Taterf!IK |
| eSafe | 7.0.17.0 | 2011.09.04 | - |
| eTrust-Vet | 36.1.8540 | 2011.09.05 | - |
| F-Prot | 4.6.2.117 | 2011.09.04 | - |
| F-Secure | 9.0.16440.0 | 2011.09.05 | - |
| Fortinet | 4.3.370.0 | 2011.09.05 | - |
| GData | 22 | 2011.09.05 | - |
| Ikarus | T3.1.1.107.0 | 2011.09.05 | Gen.Variant.Taterf |
| Jiangmin | 13.0.900 | 2011.09.04 | - |
| K7AntiVirus | 9.111.5090 | 2011.09.05 | - |
| Kaspersky | 9.0.0.837 | 2011.09.05 | - |
| McAfee | 5.400.0.1158 | 2011.09.05 | - |
| McAfee-GW-Edition | 2010.1D | 2011.09.05 | - |
| Microsoft | 1.7604 | 2011.09.05 | - |
| NOD32 | 6437 | 2011.09.05 | a variant of Win32/Kryptik.SKB |
| nProtect | 2011-09-05.01 | 2011.09.05 | - |
| Panda | 10.0.3.5 | 2011.09.04 | Suspicious file |
| PCTools | 8.0.0.5 | 2011.09.05 | - |
| Prevx | 3.0 | 2011.09.05 | - |
| Rising | 23.73.01.03 | 2011.08.30 | - |
| Sophos | 4.69.0 | 2011.09.05 | - |
| SUPERAntiSpyware | 4.40.0.1006 | 2011.09.04 | - |
| Symantec | 20111.2.0.82 | 2011.09.05 | - |
| TheHacker | 6.7.0.1.290 | 2011.09.03 | - |
| TrendMicro | 9.500.0.1008 | 2011.09.03 | - |
| TrendMicro-HouseCall | 9.500.0.1008 | 2011.09.05 | - |
| VBA32 | 3.12.16.4 | 2011.09.05 | - |
| VIPRE | 10376 | 2011.09.05 | - |
| ViRobot | 2011.9.5.4657 | 2011.09.05 | - |
| VirusBuster | 14.0.200.0 | 2011.09.03 | - |
| MD5: 9de2e0deb0edca0edfac2d19c6f27891 |
| SHA1: 0848703ba9a611dc74ae56e144a32373991bced9 |
| SHA256: 396bedd604a199c1fd2c4359c8a24ed40751dc15800ebe71dba5f83c317f4410 |
| File size: 285696 bytes |
| Scan date: 2011-09-05 09:41:15 (UTC) |
...
Files Added
%System%\E6zxc.exe
%System%\E6szxc10.dll
%System%\E6szxc11.dll
%System%\E6szxc20.dll
%UserProfile%\Microsoft\strFree.dll
Keys Added
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\ProgID
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\Programmable
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\VersionIndependentProgID
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
Values Added
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\VersionIndependentProgID
(Default) = "IEHlprObj.IEHlprObj"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\ProgID
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}\InprocServer32
(Default) = "%System%\E6szxc20.dll"
ThreadingModel = "Apartment"
HKLM\SOFTWARE\Classes\CLSID\{D3DBA9D2-4657-44BC-B9FF-485C026FA281}
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\TypeLib
(Default) = "{D3DBA9D8-4657-44BC-B9FF-485C026FA281}"
Version = "1.0"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid32
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}\ProxyStubClsid
(Default) = "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{D3DBA9D1-4657-44BC-B9FF-485C026FA281}
(Default) = "IIEHlprObj"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\0\win32
(Default) = "%System%\E6szxc20.dll"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\HELPDIR
(Default) = "%System%\"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0\FLAGS
(Default) = "0"
HKLM\SOFTWARE\Classes\TypeLib\{D3DBA9D8-4657-44BC-B9FF-485C026FA281}\1.0
(Default) = "IEHelper 1.0 Type Library"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer
(Default) = "IEHlprObj.IEHlprObj.1"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj
(Default) = "IEHlprObj Class"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID
(Default) = "{D3DBA9D2-4657-44BC-B9FF-485C026FA281}"
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1
(Default) = "IEHlprObj Class"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E6sos = "%System%\E6zxc.exe"
strFree = "rundll32.exe "%UserProfile%\Microsoft\strFree.dll", CreLcfAchF"
...
Effect : MSN /Windows live messenger error and disconnect
=======================================================
วิธีกำจัด/แก้ virus : E6zxc.exe
=======================================================
Download Fix Tool :
ใชัโปรแกรม Hijack This Fix check บรรทัดนี้
O4 - HKCU\..\Run: [E6sos] %System%\E6zxc.exe
O4 - HKCU\..\Run: [rundll32.exe] %UserProfile%\Microsoft\strFree.dll", CreLcfAchF"
หมายเหตุ : ท่านใดที่ได้รับผลกระทบจากไวรัสตัวนี้ โืดย MSN จะ Error และ Disconnect
ก็ลองเอาไปแก้ดูนะครับ
------------------------------------------------------------------------------
หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เพื่อป้องกันการเรียกใช้ autorun
เช่น
Program Advice (Stop AutoRun function/autorun.inf)
Microsoft path : Fix autorun function
or
NoAutoRun (.REG)
No comments:
Post a Comment