Computer virus always using sociable technique to infecting their victims. When there is gossip virus creator always using this gossip to spreading their virus ex:paris hilton xxx movies, what FBI hidding from us, etc. This time they’re using facebook popularity to infect all facebook fans. This virus also has been reported bundled with FAKE antispyware security tools.

When you see this on your monitor that mean you’re already infected.

Just ignore this fake antispyware warning, if you follow it you will get more virus infected your computer or your operating system gonna be corrupt.

How to Remove Facebook Virus W32/Obfuscated.D2!genr :

1. It’s recommended to running windows in “safe mode” when in cleaning process, backup all your important data first!.

2. Disable “System Restore” when in cleaning process.

3. Disconnected your computers from local network.

4. Download “unlocker” and install it.

5. Download “security task manager“  then kill virus process active in computer background.

6. Download repair.inf then right click, choose “install”. Make sure repair.inf content same with this:

[Version]

Signature=”$Chicago$”
Provider=nobody

[DefaultInstall]
AddReg=inject
DelReg=rem

[inject]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKCU, Software\Microsoft\Internet Explorer\Main, tart Page,0, “about:blank”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,userinit,0, “userinit.exe”

[rem]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,47543326
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,PromoReg
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,EnableProfileQuota
HKLM, SOFTWARE\AGProtect
HKLM, SOFTWARE\47543326
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network, UID
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion, Rlist
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{8FFA689D-2C2B-2B2E-D865-74C04CA4EF06}

7. Delete this file list has been created by virus,  before you doing this set your computers to show all hidden files.

%systemroot%\Documents and Settings\All Users\Application Data\47543326
%systemroot%\Documents and Settings\%user%\Start Menu\Programs\Security Tools.lnk
%systemroot%\Documents and Settings\%user%\Desktop\Security Tools.lnk
%systemroot%\Documents and Settings\%user%\Application Data\wiaservg.log
%systemroot%\Documents and Settings\%user%\Local Settings\Temp\*.tmp
%systemroot%\WINDOWS\Temp\wpv311256600826.exe
%systemroot%\WINDOWS\Temp\wpv411256806849.exe
%systemroot%\Documents and Settings\%user%\reader_s.exe
%systemroot%\Documents and Settings\%user%\Start Menu\Programs\Startup\isqsys32.exe
%systemroot%\WINDOWS\system32\reader_s.exe
%systemroot%\Windows\system32\wbem\proquota.exe
%systemroot%\windows\system32\sdra64.exe

%systemroot%\Windows\system32\lowsec
local.ds
user.ds
user.ds.lll

* NOTE: when you have problem deleted folder %systemroot%\Windows\system32\lowsec and file %systemroot%\windows\system32\sdra64.exe please use unlocker. Right click on folder/files then choose unlocker, choose deleted then click OK. If there any warning just ignore it.

7. Deleted all temporary files using ATF-Cleaner.

8. Update your best antivirus then scan full all your system, make sure there is no virus/worm/trojan left.

9. Subscribe to my blog… hehehe :D

Good luck, have a great day :)

[Version]
Signature=”$Chicago$”
Provider=nobody

[DefaultInstall]
AddReg=inject
DelReg=rem

[inject]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKCU, Software\Microsoft\Internet Explorer\Main, tart Page,0, “about:blank”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,userinit,0, “userinit.exe”

[rem]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,47543326
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,PromoReg
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,EnableProfileQuota
HKLM, SOFTWARE\AGProtect
HKLM, SOFTWARE\47543326
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network, UID
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion, Rlist
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{8FFA689D-2C2B-2B2E-D865-74C04CA4EF06}

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

SIMILAR POST :

Incoming search terms:

  • mylovefacebook liuyifei removal
  • facebook virus
  • how to remove mylovefacebook virus
  • virus facebook
  • mylovefacebook liu yifei
  • my love facebook virus removal tool
  • bsod background
  • MyLoveFacebook virus
  • فس بوك
  • winlogon
  • w32/obfuscated ma
  • facebook vairus
  • remove mylovefacebook liu
  • וירוס my love facebook
  • my love facebook removal
  • how to delete facebook
  • wirus facebook
  • how to remove virus from your facebook account
  • trick virus ads
  • how to remove mylovefacebook
  • mylovefacebook removal tool
  • mylovefacebook kaspersky
  • Manage virus on network
  • mylovefacebook how to find in regedit
  • virus my love facebook
  • VIRUS EN FACEBOOK
  • virus de facebook
  • my love facebook liuyifei
  • my love facebook virus removal
  • w32/obfuscated a!genr
  • mylovefacebook removal
  • manually remove mylovefacebook
  • how to remove myLoveFaceBok
  • how to remove mylove facebook virus
  • how to remove my love facebook virus
  • فايرس ماي لوف
  • facebook virus make
  • facebook virus pictures
  • facebook virus remove
  • all virus on facebook
  • طريقة إزالة فيروس ماى لوف فيس بوك من الجهاز
  • facebook with virus
  • remove my love face book
  • removable mylovefacebook
  • obfuscated_m jl
  • Remove_Virus_MyLove
  • how to remove facebook virus
  • كيفية ازالة فايروس my love face book
  • كيف ازيل الفيروس من الفيس بوك؟
  • كيف اتخلص من ماي لوف فيس بوك
  • كيف امسح فايروس my love facebook
  • كيف أزيل بلوك الفيس بوك
  • كيف نتخلص من الفايروس للفيس
  • mylove facebook virus
  • كيف ازيل my love facebook
  • مسح الاوتوران
  • مسح فايروس autorun
  • كيف ازيل فيروس من الفيس بوك
  • كيف ازيل الفيروسات من الفيس البوك
  • كيفية حذف الفيروس من الفيس البوك
  • كيفية مسح فايروس mylovefacebook
  • كيف ازيل الفيروسات من الفيس بوك
  • كيف ازيل فايروس مى لاف فيسبوك
  • virus facebook remove
  • virus image facebook
  • برنامج ازالة فيروس facebook my love
  • برنامج حذف اوتورن
  • تنيل البرنامج اللذي يزيل فايروس ماي لوف فيس بوك
  • تحميل بر نا مج الفير وس
  • تحميل برنامج لمسح الاوتورن
  • تحميل برنامج لأزالة فايروس مى لاف فيس بوك
  • حذف فايروس mylove facebook liuyifei
  • حذف ملف zzzzzzz
  • حذف ايروس mylovefacebook
  • طريقه مسح فايروس ماي لوف فيس بوك
  • طريقه مسح الاوتورن
  • طريقة مسح فايروس اوتورن
  • طريقة أزالة فيروس فيس بوك ماى لوف
  • برنامج يشيل فيرس الاتوران
  • ازالة فايروس my love facebook
  • ازالة فيرس اوتورن
  • انتى فايروس رموف ماى لوف فس بوك
  • virus my love facebook liu
  • virus mylove exe
  • virus no facebook
  • virus sur facebook
  • Virut Facebook
  • w32/obfuscated a!genr removal tool
  • w32/obfuscated_m jl
  • zzzzzzz virus
  • ازالة my love facebook
  • facebook wirus
  • ازالة فيروس my love facebook liuyifei
  • ازالة فيروس mylove
  • ازالة mylovefacebook
  • chtara 110
  • how remove mylovefacebook
  • how to delete virus on facebook
  • how to love lyricst rid of a virus on my facebook page
  • how to manually remove mylovefacebook
  • how to remove my love facebook
  • how to remove mylovefacebook liu
  • how to remove mylovefacebook virus manually
  • how to remove mylovefacebook virus vbs
  • how to remove virus
  • how to remove virus my love facebook
  • how to remove virus mylovefacebook
  • liuyifei virus registry entries
  • how do you delete facebook
  • how can remove i [lovemyfacebook] virus
  • how can delete mylovefacebook
  • chtara 110mb virus?
  • d2 exe virus
  • delete facebook
  • delete mylovefaceboo liuyifei
  • delete mylovefacebook
  • downloadMyLoveFaceBook remover
  • facebook con virus
  • facebook lover malware removal
  • facebook Task system
  • facebook virus file list
  • facebook viruses
  • fei my love facebook
  • MY DS IS VIRUSED
  • my love facebook virus
  • my love facebook viruse
  • obfucated m
  • remov my love facebook
  • remove facebook exe malware
  • remove my love facebook virus
  • remove mylove facebook virus
  • Remove virus my love face
  • Remove Virus MyLoveFaceBook
  • Remove Virus MyLoveFaceBook TOOL
  • REMOVING MYLOVEBOOK LIUYIFEI
  • REMOVING mylovefacebook liu yifei
  • repair mylovefacebook
  • rmove mylove facebook
  • Norman W32/Obfuscated H!genr
  • mylovefacebook virus removal
  • mylovefacebook remove
  • my love facebook ازالة فيرس
  • my lovefacebook virus
  • mylove facebook liuyifei
  • mylove facebook liuyifei removal tool
  • mylovefacebook
  • mylovefacebook fix
  • mylovefacebook liu remover software
  • myLovefacebook Liu Yi removal
  • mylovefacebook liu yifei removal torrent
  • mylovefacebook liuyifei
  • mylovefacebook liuyifei tool
  • mylovefacebook liuyifei virus
  • site-officiel 110mb

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!