Clean bait.doc.exe winword.doc.exe winword2.doc.exe virus Removal
Clean bait.doc.exe winword.doc.exe winword2.doc.exe virus Removal:
Here is a step by step set of instructions designed to help you clean up the virus:
1. Temporarily Disable System Restore, Reboot computer in SafeMode;
2.Find and delete the following files in the folder:
%USERPROFILE%\local settings\temp\89c244e57fb899f8d5ff0a578e4d5ca3bda46ab1.exe
%USERPROFILE%\desktop\bait.doc.exe
%USERPROFILE%\my documents\bait.doc.exe
%USERPROFILE%\templates\winword.doc.exe
%USERPROFILE%\templates\winword2.doc.exe
%WINDIR%\mydoc.rtf
%WINDIR%\shellnew\winword8.doc.exe
%WINDIR%\system32\bafjzmhu.exe
%WINDIR%\system32\config\systemprofile\templates\winword.doc.exe
%WINDIR%\system32\config\systemprofile\templates\winword2.doc.exe
%WINDIR%\system32\dvohhhqsmigze.exe
%WINDIR%\system32\ooqcvhabsgybywh.exe
%WINDIR%\system32\pckhar.exe
%WINDIR%\system32\vxdlfzfgez.exe
c:\documents and settings\default user\templates\winword.doc.exe
c:\documents and settings\default user\templates\winword2.doc.exe
c:\documents and settings\stupid\templates\winword.doc.exe
c:\documents and settings\stupid\templates\winword2.doc.exe
3. Open the Start Menu.In the white line (Start Search) area, type regedit and press Enter.Delete or modify the following registry keys and values:
- disableregistrytools = 1
- disablecmd = 2
- com1 = 32452d0b9c2d83536a4377a170202cd97df465aa
- com2 = 6abafabbfe17f1e3840f3b32869a3993b38c02884261033be2be45e708a2
- com3 = 2fb2b12b479339e852c4baa6329dd4b8
- com4 = 7ef5fcf8482f85199130d72f7e94bceee144593767406234d791
- startcom1 = e78068b0fe1a22d9d108d0a88b799017
- startcom2 = 184fc7781590dac3b8bc7f95ede234ca
- antivirusdisablenotify = 1
- antivirusoverride = 1
- firewalldisablenotify = 1
- firewalloverride = 1
- firstrundisabled = 1
- updatesdisablenotify = 1
- programcount = 2
- hidefileext = 1
- showsuperhidden = 0
- nodrivetypeautorun = 145
- (default) = txtfile
- (default) = txtfile
- (default) = txtfile
- (default) = txtfile
- (default) = txtfile
- (default) = txtfile
- disablesr = 1
- sfcdisable = 1113997
- sfcscan = 0
- checkedvalue = 0
- wordfiles = 261379
- (default) = dvohhhqsmigze.exe
- jugqqfpv = vxdlfzfgez.exe
- oyicaxec = ooqcvhabsgybywh.exe
- computername = virusbenci
- hostname = virusbenci
- nv hostname = virusbenci
4. Scan your computer completely using antivirus software(AVG,Malwarebytes,CCleaner,etc.).