Langkah pembantaian sebagai berikut:
1. Matikan wscript.exe yang aktif dimemori (silahkan download dialamat http://download.sysinternals.com/Files/ProcessExplorer.zip)
2. gunakan tools pengganti registry editor (regAnalizer, silahkan download di alamat http://www.safer-networking.org/files/regalyz.exe) kemudian masuk ke lokasi HKCR\inffile\shell\Install\command, kemudian ganti string “default” yang ada disebeah kanan layar menjadi C:\Windows\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1
3. Hapus registry yang dibuat virus, untuk mempercepat proses pembersihan copy script dibawah ini pada program notepad, simpan dengan nama repair.inf kemudian jalankan dengan cara
- klik kanna repair.inf
- klik Install
[Version]
Signature=”$Chicago$”
Provider=Vaksincom
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SOFTWARE\Classes\exefile\DefaultIcon,,,”%1″
HKLM, SOFTWARE\Classes\VBSFile,,,”VBScript Script file”
HKLM, SOFTWARE\Classes\VBSFile\DefaultIcon,,,”C:\WIndows\System32\WScript.exe,2″
HKLM, SOFTWARE\Classes\VBSFile\Shell\Edit\Command,,,”C:\WIndows\system32\notepad.exe %1″
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Adobe
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDesktop
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFileAssociate
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderoptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoRun
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableCMD
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system, DisableTaskmgr
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TaskMgr.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe, Debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe, Debugger
HKLM, SOFTWARE\Classes\VBSFile, NeverShowExt
4. Hapus file virus dengan ekstensi VBS (berukuran 9 KB) dan DOC.VBS. Untuk mempermudah proses pencarian gunakan tools search windows, hapus jiga autorun.inf di setiap folder
5. Tampilkan file doc yg disembunyikan (attrib -s -h *.doc /s) pada dos prompt dengan memastikan kursor berada di drive yang akan di cek
6. Untuk pembersihan optimal dan mencegak infeksi ulang silahkan scan dengan antivirus yang sudah dapat menengenali vrus ini dengan baik.
Anda dapat mendownload antivirus Norman free trial 1 bulan di alamat berikut:
http://www.norman.com/Download/Trial_versions/