gvljsysguard.exe (Trojan.Win32.FraudPack.zcq :Detect by Kaspersky Lab)
Files size261,120 bytes
MD5: 6C3FBB123876E29DA7F47DDA34239B41
SHA-1: 5DA1537714A019B34BF5BE6924C35A227F6223E5
=================================================
File created
%ProgramFiles%\sytnko\gvljsysguard.exe
Registry Modifications
Keys Added:
HKLM\SOFTWARE\AvScan
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
HKLM\Software\Microsoft\Windows Script
HKLM\Software\Microsoft\Windows Script\Settings
Values Added
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
system tool = "%ProgramFiles%\sytnko\gvljsysguard.exe"
HKLM\SOFTWARE\AvScan\knkd = 0x00000001
HKCU\Software\Microsoft\Internet Explorer\Download\
RunInvalidSignatures = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\
LowRiskFileTypes = ".exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\
SaveZoneInformation = 0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
system tool = "%ProgramFiles%\sytnko\gvljsysguard.exe"
HKCU\Software\Microsoft\Windows Script\Settings
JITDebug = 0x00000001
Value deleted
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
AppInit_DLLs = ""
Value modified
HKCU\Software\Microsoft\Internet Explorer\Download\
CheckExeSignatures =
Remote Host
91.212.127.226 port 80
Data identified
http://91.212.127.226/check
http://winguard-2009.com/loads2.php?r=59.5
Hosts modified
127.0.0.1 localhost
::1 localhost
91.212.127.226 winguard2009.microsoft.com
91.212.127.226 winguard-2009.com
91.212.127.226 www.winguard-2009.com
=======================================================
วิธีกำจัด/แก้ virus : gvljsysguard.exe
=======================================================
Download Fix Tool : PeeTechFix-Win32.FraudPack.zcq 1.0
็Hijack This
1. Run PeeTechFix-Win32.FraudPack.zcq 1.0
2. ใช้ Hijack This Fix checked ตามนี้
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.226 winguard2009.microsoft.com
O1 - Hosts: 91.212.127.226 winguard-2009.com
O1 - Hosts: 91.212.127.226 www.winguard-2009.com
No comments:
Post a Comment