Documente Academic
Documente Profesional
Documente Cultură
AESL
Lakukan pembersihan pada mode safe mode
Disable System Restore untuk sementara selama proses pembersihan dilakukan
Matikan proses virus dengan nama [6DSS92c31Apgjk.exe]. Untuk mematikan proses in
i sebaiknya gunakan tools selain Task Manager, seperti ProceeXP (http://technet.
microsoft.com/en-us/sysinternals/bb896653)
Repair registry Windows yang sudah dibuat oleh virus. Untuk mempercepat proses p
enghapusan salit script dibawah ini pada program notepad kemudian simpan dengan
nama REPAIR.INF. Install dengan cara: Klik kanan REPAIR.INF | Klik INSTALL
[Version]
Signature="$Chicago$"
Provider=Vaksincom Oyee 2012
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,ShowSuperHidde
n,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,SuperHidden,0x
00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHi
dden, UncheckedValue,0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFil
eExt, UncheckedValue,0x00010001,0
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, BFwoCYFrNlwR.exe
HKU, S-1-5-21-842925246-1383384898-1343024091-1003\software\microsoft\windows\cu
rrentversion\run, BFwoCYFrNlwR.exe
HKLM, SOFTWARE\Microsoft\ESENT\Process\BFwoCYFrNlwR
HKLM, SOFTWARE\Microsoft\ESENT\Process\6DSS92c31Apgjk
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop, NoChangi
ngWallPaper
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Associations, LowRiskFi
leTypes
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Attachments, SaveZoneIn
formation
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDesktop
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptio
ns
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistry
Tools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoFolderOptio
ns
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system, DisableRegistry
Tools
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system, DisableTaskMgr