Computer virus always using sociable technique to infecting their victims. When there is gossip virus creator always using this gossip to spreading their virus ex:paris hilton xxx movies, what FBI hidding from us, etc. This time they’re using facebook popularity to infect all facebook fans. This virus also has been reported bundled with FAKE antispyware security tools.

When you see this on your monitor that mean you’re already infected.

Just ignore this fake antispyware warning, if you follow it you will get more virus infected your computer or your operating system gonna be corrupt.

How to Remove Facebook Virus W32/Obfuscated.D2!genr :

1. It’s recommended to running windows in “safe mode” when in cleaning process, backup all your important data first!.

2. Disable “System Restore” when in cleaning process.

3. Disconnected your computers from local network.

4. Download “unlocker” and install it.

5. Download “security task manager” then kill virus process active in computer background.

[to_plus]

6. Download repair.inf then right click, choose “install”. Make sure repair.inf content same with this:

[Version]

Signature=”$Chicago$”
Provider=nobody

[DefaultInstall]
AddReg=inject
DelReg=rem

[inject]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe €œ%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, €œExplorer.exe”
HKCU, Software\Microsoft\Internet Explorer\Main, tart Page,0, €œabout:blank”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,userinit,0, €œuserinit.exe”

[rem]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,47543326
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,PromoReg
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,EnableProfileQuota
HKLM, SOFTWARE\AGProtect
HKLM, SOFTWARE\47543326
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network, UID
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion, Rlist
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{8FFA689D-2C2B-2B2E-D865-74C04CA4EF06}

7. Delete this file list has been created by virus, before you doing this set your computers to show all hidden files.

%systemroot%\Documents and Settings\All Users\Application Data\47543326
%systemroot%\Documents and Settings\%user%\Start Menu\Programs\Security Tools.lnk
%systemroot%\Documents and Settings\%user%\Desktop\Security Tools.lnk
%systemroot%\Documents and Settings\%user%\Application Data\wiaservg.log
%systemroot%\Documents and Settings\%user%\Local Settings\Temp\*.tmp
%systemroot%\WINDOWS\Temp\wpv311256600826.exe
%systemroot%\WINDOWS\Temp\wpv411256806849.exe
%systemroot%\Documents and Settings\%user%\reader_s.exe
%systemroot%\Documents and Settings\%user%\Start Menu\Programs\Startup\isqsys32.exe
%systemroot%\WINDOWS\system32\reader_s.exe
%systemroot%\Windows\system32\wbem\proquota.exe
%systemroot%\windows\system32\sdra64.exe

%systemroot%\Windows\system32\lowsec
local.ds
user.ds
user.ds.lll

* NOTE: when you have problem deleted folder %systemroot%\Windows\system32\lowsec and file %systemroot%\windows\system32\sdra64.exe please use unlocker. Right click on folder/files then choose unlocker, choose deleted then click OK. If there any warning just ignore it.

7. Deleted all temporary files using ATF-Cleaner.

8. Update your best antivirus then scan full all your system, make sure there is no virus/worm/trojan left.

9. Subscribe to my blog… hehehe 😀

Good luck, have a great day 🙂

[Version]
Signature=”$Chicago$”
Provider=nobody[DefaultInstall]
AddReg=inject
DelReg=rem[inject]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe €œ%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, €œExplorer.exe”
HKCU, Software\Microsoft\Internet Explorer\Main, tart Page,0, €œabout:blank”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,userinit,0, €œuserinit.exe”

[rem]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,47543326
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,PromoReg
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,EnableProfileQuota
HKLM, SOFTWARE\AGProtect
HKLM, SOFTWARE\47543326
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network, UID
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion, Rlist
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{8FFA689D-2C2B-2B2E-D865-74C04CA4EF06}

Similar Posts:

Related Search Terms:

  • mylovefacebook liuyifei removal
  • mylovefacebook liuyifei removal
  • facebook virus
  • facebook virus
  • how to remove mylovefacebook virus
  • how to remove mylovefacebook virus
  • virus facebook
  • virus facebook
  • bsod background
  • bsod background
  • mylovefacebook liu yifei
  • mylovefacebook removal tool
  • mylovefacebook removal tool
  • mylovefacebook liu yifei
  • my love facebook virus removal tool
  • my love facebook virus removal tool
  • w32/obfuscated ma
  • w32/obfuscated ma
  • remove mylovefacebook liu
  • facebook vairus
  • וי××•× my love facebook
  • remove mylovefacebook liu
  • facebook vairus
  • וי××•× my love facebook
  • virus my love facebook
  • my love facebook removal
  • remove my love face book
  • virus my love facebook
  • my love facebook removal
  • remove my love face book
  • ØØÙŠÙ‚Ø ØØØÙ„Ø ÙÙŠØÙˆØ Ù…ØÙ‰ لو٠ÙÙŠØ Øوك من ØÙ„ØÙ‡ØØ
  • delete facebook
  • facebook virus pictures
  • removable mylovefacebook
  • w32/obfuscated a!genr
  • mylovefacebook how to find in regedit
  • facebook virus pictures
  • mylovefacebook removal
  • delete facebook
  • ØØÙŠÙ‚Ø ØØØÙ„Ø ÙÙŠØÙˆØ Ù…ØÙ‰ لو٠ÙÙŠØ Øوك من ØÙ„ØÙ‡ØØ
  • mylovefacebook how to find in regedit
  • w32/obfuscated a!genr
  • mylovefacebook removal
  • removable mylovefacebook
  • mylovefacebook liuyifei tool
  • mylovefacebook liuyifei tool
  • كي٠ØØيل Øلوك ØÙ„ÙÙŠØ Øوك
  • Virut Facebook
  • how to remove virus my love facebook
  • ØØÙ ÙØÙŠØÙˆØ mylove facebook liuyifei
  • facebook Task system
  • mylove facebook liuyifei removal tool
  • mylovefacebook remove
  • how can delete mylovefacebook
  • how can remove i [lovemyfacebook] virus
  • w32/obfuscated a!genr removal tool
  • virus my love facebook liu
  • obfucated m
  • Virut Facebook
  • how to love lyricst rid of a virus on my facebook page
  • obfucated m
  • how remove mylovefacebook
  • how can remove i [lovemyfacebook] virus
  • ØØØÙ„Ø ÙÙŠØÙˆØ my love facebook liuyifei
  • كي٠ØØيل Øلوك ØÙ„ÙÙŠØ Øوك
  • mylovefacebook remove
  • how remove mylovefacebook
  • virus my love facebook liu
  • w32/obfuscated a!genr removal tool
  • how to remove virus my love facebook
  • ØØØÙ„Ø ÙÙŠØÙˆØ my love facebook liuyifei
  • how can delete mylovefacebook
  • facebook Task system
  • ØØÙ ÙØÙŠØÙˆØ mylove facebook liuyifei
  • mylove facebook liuyifei removal tool
  • how to love lyricst rid of a virus on my facebook page
    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!