How to remove v0s.cmd

v0s.cmd , amvo.exe
Files size 104,363 bytes
MD5: 5888B6D0FCA71A2959292EA3781334C8
SHA-1: 5CD5BAE910CCF3BC17021143A3B9820364A685D4
===============================================
Files created
%System%\amvo.exe
%System%\amvo0.dll (0-9)
X:\v0s.cmd
X:\autorun.inf

%System% =C:\WINDOWS\system32\
X:\ = C:\ - Z:\

Registry Modifications
Value added

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
amva = "%System%\amvo.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = "0"

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = "2"

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = "0"

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = "91"

=======================================================
วิธีกำจัด/แก้ virus : v0s.cmd , amvo.exe
=======================================================


No comments:

Post a Comment