This virus categorized as low class because actually this virus not really hard to removed and not really annoyed. Carefully when you received this messages/pop up:

1  nikmatnya_gadis_desa
2  saat pertama berkenalan dengannya aku merasa senang
3  dia hanya seorang gadis desa
4  dengan cahaya pada bola matanya
5  yang mampu membawaku terbang
6  dengan keluguannya
7  yang selalu membuatku membimbingnya
8  dia adalam matahariku
9  yang mencairkan kebekuan hatiku
10 dari :rieysha

To know if your computer infected by this virus is you will see many multimedia files with size around 148KB This virus will generate lot of this files type so it will take enough your disk-space.

Norman antivirus can detect this virus as W32/Wayrip.A

wayrip_norman.JPG

Virus Master

After success to active this virus will creating his master file and also copied it into another drive like d: e: etc.

3gp.exe
dari_rieysha_anak_jogja.exe
dokumenPenting.exe
film.exe
gambar.exe
musik.exe
puisi.txt

Virus will change registry value in HKLM to make it active each time computer reboot:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nikmatnya_gadis_desa = C:\nikmatnya_gadis_desa.exe

To protect himself from people( like me :P ) this Virus will try to blocking some windows function like:

- Folder Option
- Run
- Find
- Menu Shutdown
- Drive C:\
- Registry Editor
- Task Manager
- CMD

Virus will change your browser start page redirected to http://h1.ripway.com/anharku (Account already deleted by ripway company) This is the virus creator homepage he try to get lot of people come to his website maybe just for click him adsense ads *LOL*

Virus will change your time AM PM value into riesyha

wayrip-2.JPG

Virus will change your windows information

wayrip-3.JPG

Virus will hiding your drive C:

wayrip-4.JPG

The best part of this virus he will try to kill all security/antivirus programs with caption:

Virus
Trend
procexp.exe
Remove
Panda
mmc.exe
Kill
Kaspersky
cmd.exe
Rontok
Aladdin
Windows
Rontox
Sysinter
Setup
Machine
brontokwasher.exe
ansav
Norton
hijackthis.exe
anti
Symantec
killbox.exe
kill
Norman
Movzx
scan
Bitdef
Ertanto
remov
Avast
Washer
security
Mcaf
Killbox
config
Grisoft
Registry
patrol
Cillin
Utility
hijack
Process
Master
pcmav

I said this is the best part of this virus because it might make some people confused :D this virus also still active on windows mode “safe mode with command prompt” and the last lame autorun.inf file for spreading himself using flash disk media.

wayrip-5.JPG

Enough now time to remove this virus!

1. Turn off “system restore” service when in cleaning process.

2. Kill virus process using 3rd party tools killVB, Download it on here or download from my server here

wayrip-6.JPG

3. Delete registry changed by Virus using FixRegistry download from here or download from my server here

wayrip-7.JPG

4. Delete all master virus with specification:

  • Size 148KB
  • Icon Multimedia
  • File extension .exe
  • File type Application

Before you do this set folder option to show hidden files.

5.  Delete also this file list on root drive (c:\, d:\, etc)

  • pesene_seng_gawe.htm (size 22 KB)
  • xx pesene_seng_gawe.htm (size 1 KB), xx = Random
  • Autorun.inf
  • C:\Puisi.txt
  • C:\Windows\Taskman.com

6. Last scan with your best antivirus program to make sure your system clean.

Done, Have a nice day :D

Similar Posts:

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

newforex3gp, newforex3gp blogspot, gadis desa, forex3gp, dewi3gp blogspot, youtubebokeptv, www blogspot co id, japanxx 3gp, My faporite 3gp, dewi3gpblogsport, puisi desa, Indo xx 3gp, newforex3gp blogspot video, Gadis bugil, forex3gp blogspot, newforex3gp blog, new forex 3gp, gambar gadis, new forex3gp, gadisdesa, newforex 3gp, newforex 3gp blogspot, Newforex blogspot, gadis tube, gadis desa bugil, gambar gadis desa, forek3gp, 3gpgadis desa, 3gpblogsport, 3gp japanXX, 3gp GADIS, bugil gadis desa, tubexx 3gp, blog indo xx 3gp, gadis desa 3gp, tube3gp blogsport, youtube gadis desa, new forex3gp blogspot, new forex3gp blok, www xvidios3gp indo com, indoxxbugil, xx gadis kampung, newforex3gp blog spot, new forex 3gp blogspot, youtube www indoxvideo com, newforek3gp blogspot, mahu berkenalan dengan gadis indonesia, kantor pusat bpd jawa timur, kampung bugil, japanxx blogspot, indoxx3gp, Xx file gadis bugil xx, rontox exe virus, puisi gadis desa, POTO CEWE DESA, Vidio gadis indonesia xx, NIKMATNYA GADIS DESA, newforex3gp com, virus redirected to ripway, ww newforex blogspot com, www Gadis Desa Bugil, www tubexx blogspot com, tube blogsport3gp, newforex3gp block, Wxw gambar cewek cnm, xvideos 3gp download, xvideos newforek 3gp blogspot, xvidios 3gp, search category xx 3gp, indoxx bugil, 3gp blogsport, Bugilbloksport, cewekindone, desa awek blogspot, dewi3gpblogspotyoutube, DIDU DESA 3GP VIDEOS, Download gadis indonesia bugil, download video bokeptv, file tipe 3gp awek, foreg3gp, FORES NEW KOOLWAP IN MP4, bokeptv indonesia, blogsport3gp, 3gp gadis desa, 3gp gadisdesa, 3gpgadis, 3gpgadis desa asli blogspot com, anew forex 3gp blogspot, awek bugil blok sport, bianchi, BloG gadis gadis video, 22 xx 3gp, blogger gadis bugil, forex blogspot 3gp, forex3gp tube, forex3p blog, gadisxx bugil, gadisxx vidio 3gp, gadis desa blogspot, gambr gadis desa, Indo 3gp tube, indo gadis 3gp, indo xvideos 3gp, indo xx, indoxvideos 3gp, Indoxx, Gadisxx, gadisdesa bugil, gadi8s, gadis 12th xx, gadis bugil desa, gadis desa 3gp blogspot, gadis desa adult, gadis gadis bornoe youtube, gadis virus, gadis xx, Gadisbugilsek blog spot, gadisbugilxx, indoxx 3gp

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!