How to remove gvljsysguard.exe

gvljsysguard.exe (Trojan.Win32.FraudPack.zcq :Detect by Kaspersky Lab)
Files size261,120 bytes
MD5: 6C3FBB123876E29DA7F47DDA34239B41
SHA-1: 5DA1537714A019B34BF5BE6924C35A227F6223E5
=================================================
File created
%ProgramFiles%\sytnko\gvljsysguard.exe


Registry Modifications
Keys Added:
HKLM\SOFTWARE\AvScan
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
HKLM\Software\Microsoft\Windows Script
HKLM\Software\Microsoft\Windows Script\Settings


Values Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
system tool = "%ProgramFiles%\sytnko\gvljsysguard.exe"


HKLM\SOFTWARE\AvScan\knkd = 0x00000001
HKCU\Software\Microsoft\Internet Explorer\Download\
RunInvalidSignatures = 0x00000001


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\
LowRiskFileTypes = ".exe"


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\
SaveZoneInformation = 0x00000001


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
system tool = "%ProgramFiles%\sytnko\gvljsysguard.exe"


HKCU\Software\Microsoft\Windows Script\Settings
JITDebug = 0x00000001


Value deleted
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
AppInit_DLLs = ""


Value modified
HKCU\Software\Microsoft\Internet Explorer\Download\
CheckExeSignatures =


Remote Host
91.212.127.226 port 80


Data identified
http://91.212.127.226/check
http://winguard-2009.com/loads2.php?r=59.5


Hosts modified
127.0.0.1 localhost
::1 localhost
91.212.127.226 winguard2009.microsoft.com
91.212.127.226 winguard-2009.com
91.212.127.226 www.winguard-2009.com


=======================================================
วิธีกำจัด/แก้ virus : gvljsysguard.exe
=======================================================


Download Fix Tool : PeeTechFix-Win32.FraudPack.zcq 1.0
็Hijack This


1. Run PeeTechFix-Win32.FraudPack.zcq 1.0
2. ใช้ Hijack This Fix checked ตามนี้


O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.226 winguard2009.microsoft.com
O1 - Hosts: 91.212.127.226 winguard-2009.com
O1 - Hosts: 91.212.127.226 www.winguard-2009.com

No comments:

Post a Comment