everdrinker007

Language Bar ကုိပိတ္ေသာvirus အသစ္ေပၚေန

ေဟး... hacker တို႔ေရ...
အခု language bar ကိုပိတ္တဲ႔ virus တစ္ေကာင္ထြက္ေနတယ္ဗ်ိဳ႕ အဲဒီအေကာင္ကို manual သတ္လို႔ေတာ႔ရျပီ anti-virus နဲ႔ေတာ႔မစမ္းရေသးဖူး... အဲဒီအေကာင္ အလုပ္လုပ္ပံုက ဒီလိုဗ်....
source file က MS-DOS.com ပါ... သူနဲ႔အတူပါတာက autorun.inf ဆိုတဲ႔ file ပါ... အဲဒီအေကာင္ run သြားျပီဆိုရင္ task manager မွာ Global.exe ရယ္ system.exe ရယ္ svchost.exe ဆိုျပီးေတာ႔ run ပါတယ္.... ေနာက္ျပီး registry ကိုျပင္လည္း သြားျပင္ပါတယ္... အဲဒီအေကာင္ျပင္သြားတာေတြက ဘာေတြလဲဆိုတာေတာ႔ ကြ်န္ေတာ္လဲ မေျပာတတ္ပါဘူး... backup လုပ္ထားတဲ႔ ဖိုင္လားပါလားေတာ႔မသိဖူး C:\WINDOWS\pchealth\Global.exe
C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com
C:\WINDOWS\system32\dllcache\Default.exe
C:\WINDOWS\system\KEYBOARD.exe
C:\WINDOWS\Fonts\Fonts.exe
C:\WINDOWS\Cursors\Boom.vbs
C:\WINDOWS\Help\microsoft.hlp
C:\windows\fonts\tskmgr.exe
C:\windows\media\rndll32.pif
အဲဒီဖိုင္ေတြေတာ႔ေတြ႔တယ္....

မွတ္ခ်က္။ ။ကြ်န္ေတာ္ pan drive မွာေတာ႔ ကြ်န္ေတာ္႔ရဲ႕ folder ေတြကို hidden လုပ္ျပီ အဲဒီ file name ေတြနဲ႔ folder ပံုစံ application ေတြကို ျပထားပါတယ္... သတိထားၾကပါ pan drive သံုးသူေတြကိုေျပာပါတယ္... folder ေတြထဲမ၀င္ခင္မွာ ၀င္မယ္႔ folder ကို selectေပးျပီး ALT+ENTER ပဲျဖစ္ျဖစ္၊ right click > properties ပဲျဖစ္ျဖစ္ properties ထဲက general က type မွာ folder လို႔ေပၚေနတယ္ဆိုရင္ အဲဒါ folder အစစ္ပါ... ဒါမွမဟုတ္ဘဲ application လို႔ျဖစ္ေနတယ္ဆိုရင္ေတာ႔ အဲဒီ folder ဟာ folder အစစ္မဟုတ္ပါဘူး... ဒီလိုနဲ႔ properties ထဲကိုအရင္၀င္ၾကည့္ျပီး စိတ္ခ်ရမွ folder ထဲကို၀င္ၾကပါလို႔ သတိေပးလိုက္ပါတယ္... ဒါမွမဟုတ္ရင္ OS ျပန္တင္ရလိမ္႔မယ္...
အဲဒီအေကာင္ကိုလိုခ်င္ရင္ ေျပာပါ။ mail ကေနပို႔ေပးလိုက္ပါ႔မယ္....

Tags: Caution

Views: 291

Reply to This

Replies to This Discussion

Hi Bro!
I also want this Virus.Thank U Very Much.
My mail is minnaing163@gmail.com.
ကၽြန္ေတာ္က ျမန္မာအိုင္တီပရိုက ယူစာတစ္ေယာက္ပါ ျပည့္စံုပါ။

ဗိုင္းရပ္လိုခ်င္ၾကတယ္ဆိုလို. ကၽြန္ေတာ္လိုမ်ိဳး ေမြးတဲ့လူေတြမ်ားပါလာမလားဆိုၿပီ ဗိုင္းရပ္မ်ားကို ပို.ေပးလိုက္ပါတယ္။ ဗိုင္းရပ္ေတြ ၀ါသနာမပါဘူးဆိုရင္လည္း ေနာက္မပို.ေတာ့ပါဘူး။
attach ဖိုင္မွာ က New Folder.exe ဆိုတဲ့ ဗိုင္းရပ္။

ေဟာဒီမွာ က ကၽြႏ္ေတာ္ေတြထာတဲ့ဗိုင္းရပ္ေပါက္စေလး။ ၀င္းဒိုးကိုေတာ့ မဖ်က္စီးပါဘူး။ ဟိုပိတ္ဒီပိတ္ပဲ။ ၀ါသနာပါရင္ေတာ့ စမ္းၾကည့္လို.ရတယ္ဗ်ိဳ.။



ဒီဗိုင္းရပ္ ေလးရယ္ ေဟာဒီက New Folder
Attachments:
Hi

I read here some kind of virus which closed Language bar.
( I think this is new version but they look same)
I had been attacked by this virus long time ago.It is attack on April 1.
Here is that virus detail.
----------------------
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\svchost.exe
Path thật : C:\WINDOWS\system32\dllcache\svchost.exe
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe
Path thật : C:\WINDOWS\system32\dllcache\system.exe
C:\WINDOWS\system32\dllcache\Recycler.{645FF040-5081-101B-9F08-00AA002F954E}\Global.exe
Path thật : C:\WINDOWS\system32\dllcache\Global.exe
---------------------------------------------------------------------
[autorun]
Open=MS-DOS.com
Shellexecute=MS-DOS.com
Shell\Open\command=MS-DOS.com
Shell\Explore\command=MS-DOS.com
-----------------------------------------------------------------
C:\WINDOWS\system32\dllcache\svchost.exe
C:\WINDOWS\system32\dllcache\Global.exe
C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com
C:\WINDOWS\system32\dllcache\system.exe
C:\WINDOWS\Fonts\Fonts.exe
C:\WINDOWS\system32\drivers\drivers.cab.exe
C:\WINDOWS\system32\dllcache\Global.exe
C:\WINDOWS\system32\dllcache\svchost.exe
C:\WINDOWS\system\KEYBOARD.exe
C:\WINDOWS\system32\dllcache\Default.exe
C:\WINDOWS\system32\regedit.exe
C:\WINDOWS\Fonts\tskmgr.exe
C:\WINDOWS\Media\rndll32.pif
C:\WINDOWS\Cursors\Boom.vbs
--------------------------------------------------------------------
Ngelay
Hi ko Pyae sone

I download your little virus for test.
Thank.

i ko la` pay par

frozenheart.kay@gmail.com  par

ကၽြန္ေတာ္ကုိ ပို.ေပးပါ။ကၽြန္ေတာ္ရဲ. Gmail က guelay1010@gmail.com

thank you

I wants this virus, pls mail me

nyeinready@gmail.com

Thanks you

က်ေနာ္႔ ကုိလည္းပို႕ေပးပါဦးဗ်ာ။ ေက်းဇူးျပဳၿပီး။ myinyinesky@gmail.com

al di virus ka last 4 year lout ka paw kal tar par. desktop paw hmar lal star pone kyi paw par tal .screen saver lo myo par.key bord ka nay command pay lo. ma ya aung pait tar par.taskmanager tot kaw lo. ya par tal. end process lote lo. ma ya par bu. a khu a chain hmar tot bal antivirus nal ma so kill naing nay par pe. sait pu sa yar ma lo tot par bu.

i also couldn't use language keyboard for new phonetic layout fonts,  later also hide in keyboard select list and cannot choose again. please show me how to fix without re-installation.

Do u have any tools or files to replace KEYBOARD.exe or edit reg?

Thanks

ပုိ႔လုိက္ေလးအဆင္ေၿပတာေပါ႔ဟဲဟဲ koaung.532@gmail.com

Reply to Discussion

RSS

Latest Activity

Profile Icon

Job Vacancy -ASP.Net C# Programmers

Blog post by Phyu Sin Kyaw 27 minutes ago
Profile Icon
ThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnailThumbnail
Minn htwe, itgirl, moekyaw and 11 more joined MyanmarITpro.com 41 minutes ago
Profile Icon

Bandwidth Splitter ' Shaping Rule & Quota Rule

Discussion posted by Mung Rat 1 hour ago
Profile Icon
Profile Icon
Profile Icon
Profile Icon
Profile Icon

Looking for Channel Partners to represent Sage software in Myanmar

Discussion posted by Gee 4 hours ago
Profile Icon
Gee updated their profile 4 hours ago
Profile Icon
golpi replied to golpi's discussion 'Pls help' 17 hours ago
Profile Icon
Profile IconProfile Icon
pyay thein and sumon are now friends 19 hours ago
Profile Icon
Richard Htin updated their profile 21 hours ago
Profile Icon

iphone 4g မွာ custom ringtone ကုိဘယ္လိုထည့္ရမလဲခင္ဗ် (sync မလုပ္ပဲနဲ. manual ထည့္ခ်င္လို.)

Discussion posted by GaaRa yesterday
Profile Icon
Sithu Kyaw updated their profile yesterday
Profile Icon
Profile Icon
www.fixnetcomputer.webs.com မွာၾကိဳေနမယ္ မိတ္ေဆြတို႔ ... :)
Status posted by fixcomputerservices yesterday
Profile Icon
Profile Icon
*Return Of FixNet* See U again All Member Nice to meet u :)
Status posted by fixcomputerservices yesterday
Profile Icon

© 2012   Created by Ko Chit.

Badges  |  Report an Issue  |  Terms of Service