How to remove avmb.exe

avmb.exe , aqoeerw.exe
Files size 121,618 bytes
MD5: 000B9828ED4BC8F55BBF60A858A41ECC
SHA-1: 8BE35CF0671B84D6A3A61D2DF17A7E579A9D9BC2
==================================================
Files Created
%System%\aqoeerw.exe
%System%\bnmkue0.dll (0-9)
X:\avmb.exe
X:\autorun.inf

%System% = C:\Windows\System32
X:\ C:\ - Z:\

Registry Modifications
Key Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN

Values Added
HKLM\SOFTWARE\Classes\CLSID\MADOWN\urlinfo = "awszad.r"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
coolsos = "%System%\aqoeerw.exe"

Values modified
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ Folder\Hidden\SHOWALL\CheckedValue = 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Hidden = 0x00000002

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\ShowSuperHidden = 0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
NoDriveTypeAutoRun = 0x00000091

Remote Host
202.111.175.157 port 80

URLs to be download/data identified
http://www.sina90f.com/1tw/at1.rar
http://www.googles0f.com/1tw/at.rar

=======================================================
วิธีกำจัด/แก้ virus : avmb.exe , aqoeerw.exe
=======================================================



หลังจากกำจัด virus ได้แล้ว แนะนำให้ติดตั้งโปรแกรมเพิ่มเติม เช่น

Panda USB Vaccine
http://www.pandasecurity.com/homeusers/downloads/usbvaccine/

or
KB971029, KB967715 (Disable AutoRun)
http://hotzone-it.blogspot.com/2009/08/kb971029-fix-autorun-microsoft.html

No comments:

Post a Comment