Removal tool for Oficla.H!dll, Win32.Fregee.av (reader_s.exe, file1.exe) Trojan

March 10, 2010 by admin  
Filed under Removal Tips,Tools and Videos


449 views   2 Comments

 

Sample Submitted By Sven Berger

 

 

 

 

Severity Level : 6/10

 

Alias:

  • Mal/Generic-A, Mal / Oficla-A [Sophos]
  • SpyAgent-br.dll [McAfee]
  • Trojan.Win32.Fregee.av [Kaspersky Lab]
  • Trojan:Win32/Oficla.H!dll [Microsoft]

 

reader_s.exe VirusTotal Report : (Click Here)

file1.exe VirusTotal Report : (Click Here)

 

File System Modifications

The following files were created in the system:

 

  • %system%\onyc.ffo
  • %system%\ reader_s.exe
  • %UserProfile%\reader_s.exe
  • %UserProfile%\Local Settings\Temp\?.tmp
  • %UserProfile%\Local Settings\Temp\file1.exe

 

Note:

  • %system% is a variable that refers to the System folder. By default, this is “C:\Windows\System” (Windows 95/98/Me), “C:\Winnt\System32″ (Windows NT/2000), or “C:\Windows\System32″ (Windows XP).
  • ? = Random file name.

 

Memory Modifications

There were new processes created in the system:

 

Process Name

Process Filename

reader_s.exe %system%\ reader_s.exe
onyc.ffo %system%\onyc.ffo

 

 

Registry Modifications

The newly created or modified Registry Value is:

 

  • [HKCR\idid]
  • [HKLM\SOFTWARE\AGprotect]
  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>“reader_s” = %system%\reader_s.exe
  • [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>“reader_s” = %system%\reader_s.exe
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]>“Shell” = explorer.exe rundll32.exe onyc.ffo hgikqnb

 

For auto removal :


Download Fregee.av, Trojan.Win32.Fregee.av Trojan removal tool that provided by VirusExperts.org you can download it from Here.

 

 

For manual removal First download these tools:


1- RRT : Registry, Task Manager and Folder Options Repair Tool (Click Here).

2- KillBox : Kill the Process if your Access Denied (Click Here).

3- Task Manager Enabler : (Click Here).

4- Registry Enabler : (Click Here).

 

Now Follow these instructions :


Recommend Removal from Safe Mode

To Start in Safe mode Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.

The Infected Files Can be Seen in these folders and names also Running in Tasks
End the Following Active Process Before Removal

 

 

Kill these Process, by using Killbox

  •  reader_s.exe

 

Delete These Files

  • %system%\reader_s.exe
  • %system%\ onyc.ffo
  • %UserProfile%\Local Settings\Temp\?.tmp
  • %UserProfile%\Local Settings\Temp\file1.exe   


    [ No Exact Information about Files, search above related files in Program files Folder ] If you have any of these files in running process from task manger, end the process before removal.
    Note: if task manager is disabled, Download Task Manager Enabler and Open it with Regedit.exe [%system32\regedit.exe], then it Confirms Add to registry Yes or No, Confirm Yes, then click Ok.

     

     

Remove Registry Entries

Click Start, Run,Type regedit,Click OK.


 

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor.

  • Download this UnHookExec.inf, [ Right Click - Save Target As/Linked Content As ]
    and then continue with the removal. Save it to your Windows desktop. Do not run it at this time, download it only.
  • After booting into the Safe Mode or VGA Mode.
  • Right-click the UnHookExec.inf file and click Install. [This is a small file. It does not display any notice or boxes when you run it].
  • Or Download Regfile to enable Registry editor and Open it withma Registry editor.

 

Delete These Entries
  • HKEY_CLASSES_ROOT\idid
  • HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect
Go to These Entries

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Delete file Keys from the right side
The Key “reader_s ” with value %system%\reader_s.exe

  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Delete file Keys from the right side
The Key “reader_s ” with value %system%\reader_s.exe

 

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Edit (Don’t Delete) file Keys from the right side
The Key “Shell ” to value Explorer.exe

Exit the Registry Editor,
Restart your Computer.

 

 

For any help contact us.
VirusExperts.org TEAM

%Temp%\cvasds0.dll
%Temp%\cvasds1.dll
%Temp%\cvasds2.dll


Related posts:

  1. Removal tool for Win32.Genome.aocx (outlook.exe, brazilian.exe, sysinternals.exe) Trojan-Downloader
  2. Removal tool for Troj/DwnLdr-ICI, Win32.Genome.aodo (windowsupdate.exe, updt.exe) Trojan
  3. Removal tool for Magania.bzmw (Taterf.B,Win32.Inhoo) Trojan
  4. Removal tool for Dybalom.gd Trojan and Key logger not detected yet
  5. Removal tool for Sus/Delf-J, Trojan.Heur.GZ.kGX@bKStsDeG (Foto_253.com, javahr.exe, javahr2.exe, javahu.exe) Trojan

Comments

2 Responses to “Removal tool for Oficla.H!dll, Win32.Fregee.av (reader_s.exe, file1.exe) Trojan”

Trackbacks

Check out what others are saying about this post...
  1. [...] Removal tool for Oficla.H!dll, Win32.Fregee.av (reader_s.exe … [...]

  2. [...] Removal tool for Oficla.H!dll, Win32.Fregee.av (reader_s.exe … [...]



Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!