Sandra Dewi Bugil….? This is not p**n! this is an computer virus! :P but surely this is a noob virus creator *again*

sandra_dewi

Virus characteristic:

  • Virus size 132kb
  • Virus file type “application”
  • Virus extension .exe
  • Using images icon

Sandra Dewi Bugil Virus has been created using visual basic, If virus success on infected your system he will created some files:

  • \Sandra Dewi Bugil.exe (In all root drive)
  • \Documents and Settings\%user%\Start Menu\Programs\Startup\Sandra Dewi Bugil.exe
  • \WINDOWS\Sandra Dewi Bugil.exe
  • \WINDOWS\system32\ Sandra Dewi Bugil.exe
  • Creating duplicate virus on all folder in removable drive/usb.

This virus will show message when your computer active, the easiest way to know is you’re system infected by this virus.

sandradewibugil-virus-1

This virus will blocking some windows function to make him hard to removed.

  • Disable Folder Options
  • Disable Registry Editor
  • Disable Search/Find
  • Disable Command Prompt
  • Disable Task Manager
  • Disable Control Panel
  • Disable Msconfig/System Configuration Utility
  • Disable Right Click on Desktop
  • Disable “All Programs” on Start Menu
  • Disable Log Off/Turn Off


Virus will change your name and organization on your System Properties.

sandradewibugil-virus-2

Virus will change your Internet Explorer Header.

sandradewibugil-virus-3

When your computer starts it will showing message (look at the the top article) then splash with picture:

sandradewibugil-virus-4

What do you think about this? virus maker team? I think so.. They try to act become popular *LOL* I can created this virus within 10 minutes surely they all noob :P *LOL* When you click “keluar” (out) button virus will shown confirmation box asking to sending email to virus creator

sandradewibugil-virus-5

This option actually has nothing to do, each button will bring you into the auto shutdown box.

sandradewibugil-virus-6

Spreading Method:

This virus spreading from removable media/USB flash disk,virus will created a copy into any removable media/USB flash disk plugin into infected system.

How to Remove Sandra Dewi Bugil Virus W32/Sadra.A:

1. Disconnected your computer from network.

2. Disable System Restore when in cleaning process.

3. Kill active virus process in your computer background, use this 3rd party tools process explorer kill all sandra dewi bugil process.

sandradewibugil-virus-7

4. Repair your registry using code below or download repair.inf

[Version]
Signature=”$Chicago$”
Provider=Nobody

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKCR, batfile\shell\open\command,,,”””%1″” %*”
HKCR, comfile\shell\open\command,,,”””%1″” %*”
HKCR, exefile\shell\open\command,,,”””%1″” %*”
HKCR, piffile\shell\open\command,,,”””%1″” %*”
HKCR, lnkfile\shell\open\command,,,”””%1″” %*”
HKCR, scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOrganization,0, “Organization”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOwner,0, “Owner”
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0×00010001,1
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue, 0×00010001,2

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableMsConfig
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
HKCU, Software\Policies\Microsoft\Windows\system, DisableCMD
HKCU, Software\Microsoft\Internet Explorer\Main, Window Title
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoClose
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoControlPanel
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoRun
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoStartMenuMorePrograms
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoViewContextMenu
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoViewOnDrive
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, StartMenuLogoff

5. Search and Destroy all virus in your system, before doing this as usually show all hiden files back and carefull when you deleted files, make sure it virus… find files with this specification:

  • Icon Images (JPEG)
  • File Extension .exe
  • File Size 132kb

sandradewibugil-virus-8

6. Last, scan with your best antivirus. Norman user download in here for free.

Have a nice day :D

Similar Posts:

Related Search Terms:

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!