How to remove Win32/Oficla.CI (Detect by NOD32 > 4740)
File size: 37888 bytesMD5 : 451EFA53C71E15822BA2D842E303EB3F
SHA1 : C4B7B54195E481179522F7E8C8E879CC774505ED
==================================================
Antivirus | Version | Last Update | Result |
---|---|---|---|
a-squared | 4.5.0.46 | 2010.01.04 | - |
AhnLab-V3 | 5.0.0.2 | 2010.01.02 | - |
AntiVir | 7.9.1.122 | 2009.12.31 | - |
Antiy-AVL | 2.0.3.7 | 2009.12.31 | - |
Authentium | 5.2.0.5 | 2010.01.04 | - |
Avast | 4.8.1351.0 | 2010.01.03 | - |
AVG | 8.5.0.430 | 2010.01.03 | - |
BitDefender | 7.2 | 2010.01.04 | Trojan.Generic.IS.107588 |
CAT-QuickHeal | 10.00 | 2010.01.04 | - |
ClamAV | 0.94.1 | 2010.01.04 | - |
Comodo | 3462 | 2010.01.04 | - |
DrWeb | 5.0.1.12222 | 2010.01.04 | - |
eSafe | 7.0.17.0 | 2010.01.03 | - |
eTrust-Vet | 35.1.7214 | 2010.01.04 | - |
F-Prot | 4.5.1.85 | 2010.01.03 | - |
F-Secure | 9.0.15370.0 | 2010.01.04 | Trojan.Generic.IS.107588 |
Fortinet | 4.0.14.0 | 2010.01.02 | - |
GData | 19 | 2010.01.04 | Trojan.Generic.IS.107588 |
Ikarus | T3.1.1.79.0 | 2009.12.31 | - |
Jiangmin | 13.0.900 | 2010.01.04 | - |
K7AntiVirus | 7.10.936 | 2010.01.02 | - |
Kaspersky | 7.0.0.125 | 2010.01.04 | - |
McAfee | 5850 | 2010.01.03 | - |
McAfee+Artemis | 5850 | 2010.01.03 | - |
McAfee-GW-Edition | 6.8.5 | 2010.01.04 | - |
Microsoft | 1.5302 | 2010.01.04 | - |
NOD32 | 4741 | 2010.01.04 | - Trojan Win32/Oficla.CI |
Norman | 6.04.03 | 2009.12.31 | - |
nProtect | 2009.1.8.0 | 2010.01.04 | - |
Panda | 10.0.2.2 | 2010.01.03 | - |
PCTools | 7.0.3.5 | 2010.01.04 | - |
Prevx | 3.0 | 2010.01.04 | - |
Rising | 22.29.00.04 | 2010.01.04 | - |
Sophos | 4.49.0 | 2010.01.04 | - |
Sunbelt | 3.2.1858.2 | 2010.01.03 | - |
TheHacker | 6.5.0.3.131 | 2010.01.04 | - |
TrendMicro | 9.120.0.1004 | 2010.01.04 | - |
VBA32 | 3.12.12.1 | 2010.01.04 | - |
ViRobot | 2010.1.4.2119 | 2010.01.04 | - |
VirusBuster | 5.0.21.0 | 2010.01.03 | - |
Files Created
%system%\dchn.sco
%temp%\242c.tmp
Keys added
HKLM\SOFTWARE\Classes\idid
HKCU\Software\Microsoft\Office\11.0\Word\Security
Values added
HKLM\SOFTWARE\Classes\idid\op = 0x00000001
HKLM\SOFTWARE\Classes\idid\url1= 68 74 74 70 3A 2F 2F 6C 75 62 6F 79 64 6F 6D 65 6E 2E 63 6E 2F 6D 79 6C 2F 62 62 2E 70 68 70 00 00 00 00 00 00 00 00 00 00 00 00 2C 03 00 00 B4 E6 07 00 F1 5A 91 7C 03 00 00 01 00 00 00 00 A0 10 08 00 78 E6 07 00 14 E6 07 00 C0 C2 97 7C 4F 5B 91 7C 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
HKLM\SOFTWARE\Classes\idid\url2 = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A0 10 08 00 00 00 00 00 00 00 00 00 F5 53 91 7C 80 E6 07 00 48 C2 97 7C A4 E6 07 00 E0 E6 07 00 00 00 00 00 12 00 0A 02 00 FC FD 7F 93 A2 00 00 00 00 00 00 07 57 91 7C 00 00 02 00 AC E6 07 00 AC E6 07 00 AC E6 07 00 02 00 00 00 02 00 00 00 2C 03 00 00 6C E7 07 00 00 00 00 00 93 A2 00 00 1C E8 07 00 54 E7 07 00 1C E8 07 00 00 5A 91
HKCU\Software\Microsoft\Office\11.0\Word\Security\Level = 0x00000004
HKCU\Software\Microsoft\Office\11.0\Word\Security\AccessVBOM = 0x00000000
Values modified
HKCU\Software\Microsoft\OfficeLive\wordCmdBarTop: 0x00000000
HKCU\Software\Microsoft\OfficeLive\wordCmdBarRowIndex: 0xFFFFFFFF
HKCU\Software\Microsoft\Office\11.0\Word\MTTF: 0x00043816
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Shell: "Explorer.exe rundll32.exe dchn.sco pntvj"
------------------------------------------------------------------------
ฺวิธีกำจัด
------------------------------------------------------------------------Win32/Oficla.CI
(Detect by NOD32 > 4740)
Download fix Tool : ATF Cleaner , Hijack This
Manual delete
1. Delete ไฟล์ dchn.sco ใน C:Windows\System32\dchn.sco
2. ใช้โปรแกรม ATF Cleaner เคลียร์ Temp ไฟล์
3. ใช้โปรแกรม Hijack This Fix Checked ที่บรรทัดนี้
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe dchn.sco pntvj
4. ไปที่ Start > Run พิมพ์ regedit.exe แล้วไป delete 2 key ตามตำแหน่งนี้
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid
HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Security
5. แก้ไขค่า Value wordCmdBarTop และ wordCmdBarRowIndex ตามนี้
HKEY_CURRENT_USER\Software\Microsoft\OfficeLive\wordCmdBarTop = 4c
HKEY_CURRENT_USER\Software\Microsoft\OfficeLive\wordCmdBarRowIndex = 4
--------------------------------------------------------------------------
หรือ Update antivirus ของ NOD32 แล้ว Scan ครับ
ไม่มีความคิดเห็น:
แสดงความคิดเห็น