Kill the "Fujacks"

SYMPTOMS :

every exe files extensions, icon'll be changed to Panda Bear.
spreads to other network computers using file sharing
and also removable storages are attached the infected computer.


SOLUTIONS :

turn off System Restore My Computer -> Properties -> System Restore -> Turn off system restore

For W32/Fujacks.AF
1. Go to Start Button -> Click Run -> type "Regedit"
2. Edit your Registry by following these...

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\policies\Explorer\Run
Delete "logo1_.exe"="C:\WINDOWS\logo_1.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run
Delete "logo1_.exe"="C:\WINDOWS\logo_1.exe"

3. Restart


For W32/Fujacks.AD
1. Go to Start Button -> Click Run -> type "Regedit"
2. Edit your Registry by following these...

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Delete
FuckJacks = "c:\windows\system32\FuckJacks.exe"
svohost = "C:\WINDOWS\system32\FuckJacks.exe"
svcshare = "spoclsv.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Delete
FuckJacks = "c:\windows\system32\FuckJacks.exe"
svohost = "C:\WINDOWS\system32\FuckJacks.exe"
svcshare = "spoclsv.exe"

3. Restart


For W32/Fujacks.L
1. Go to Start Button -> Click Run -> type "Regedit"
2. Edit your Registry by following these...

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Delete "svcshare"="spoclsv.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
"svcshare"="spoclsv.exe"

3. Restart


For W32/Fujacks.E
1. Go to Start Button -> Click Run -> type "Regedit"
2. Edit your Registry by following these...

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Delete "svcshare"="%System%\Drivers\spoclsv.exe"

3. Restart


By the way, there is easy way and save your time...Click here

FM 106 ครอบครัวข่าว