They never been stop spreading their knowledge…. and we also never let them alive forever. This is the article how to remove amburadul virus for all varian no need for antivirus program you can simply clean it using manual technique.

The simple way to know if your computer infected by this virus is you will see JPEG files with aplication extension. Now let’s start to remove it!

1. Unplug your infected computer from your network to stop this virus spreading.
2. DisableSystem Restore” when in cleaning process.
3. Kill the virus process using power tools “currprocess” kill all process with icon JPG.
4. Repair your registry that already changed by the virus using this code:

[Version]
Signature=”$Chicago$”
Provider=Nobody

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0×00010001,0
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt,CheckedValue,0×00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt,DefaultValue,0×00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0×00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, CheckedValue,0×00010001,0
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, DefaultValue,0×00010001,0
HKCU, Software\Microsoft\Internet Explorer\Main, Start Page,0, “about:blank”
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, type,0, “checkbox”
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, type,0, “checkbox”
HKCU, Control Panel\International, s1159,0, “AM”
HKCU, Control Panel\International, s2359,0, “PM”
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden,0×00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden,0×00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, HideFileExt,0×00010001,0

[del]
HKCU, Software\Microsoft\Internet Explorer\Main, Window Title,
HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore, DisableConfig
HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore, DisableSR
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspoold.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspool.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HokageFile.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rin.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Obito.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SMP.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KakashiHatake.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Britney Spears-CLN.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Britney Spears-RTP.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boot.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HOKAGE4.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Britney Spears
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Britney Spears
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansav.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe,debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Instal.exe, debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe,debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansavgd.exe
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind
HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, DisableMSI
HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, LimitSystemRestoreCheckpointing
HKCR, exefile, NeverShowExt
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, PaRaY_VM
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ConfigVir
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NviDiaGT
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NarmonVirusAnti
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AVManager
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, EnableLUA

5. Delete the master virus in %systemroot%\system32\~A~m~B~u~R~a~D~u~L~ before you do this you have to make hiden files become visible.
Then deleted this file list:

csrcc.exe
smss.exe
lsass.exe
services.exe
winlogon.exe
Paraysutki_VM_Community.sys
msvbvm60.dll
Drive:\Autorun.inf
Drive:\FoToKu xx-x-*.exe, where x show the date when virus active
Drive:\Friendster Community.exe
Drive:\J3MbataN K4HaYan.exe
Drive:\MyImages.exe
Drive:\PaLMa.exe
Drive:\Images

To make sure your computer clean you can check scan your computer using your favorite antivirus programs.
Done, have a nice day :D

Similar Posts:

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

photo-t432e jpeg exe, the system cannot find the file specified ayodance, cara membersihkan trojan dari windows 7 starter, menghapus direktory internet download manager, photo-t432e jpeg, application not found pada disk E, problem with shorcut artinya, ouc exe no disk, Mengembalikan registry karena virus, menghapus winlogos, membasmi virus sality, ayodance the system cannot find the file specified, cara mengatasi virus shortcut, penyebab the path is too deep, photo-t432e, rgedit terkena virus, update cara memperbaiki flash rusak, software pencari varian virus, cara membuka memory card yg tidak tampil, Cara memperbaiki net exe error win7, cara mengatasi data yang terkena virus, cara membasmi virus shortcut, apakah ada deep freeze memory card, found debugger on your memory maksudnya gmn?, flashdisk terkunci, membuka fd terproteck, kenapa selalu keluar there is no disk in the drive, membuka billing yang terkena virus, salty101 exe, sallity, virus amburadul, virus, cara mengtasi software yang tidak valid dengan syistem 32, cara menghapus virus lewat cmd, cara menghapus idm di laptop, cmd hilang, mengatasi mmc write protect, mengaktifkan anti virus yang di protect oleh virus, menghilangkan write protection, mengatasi masalah mmc will not run with a version of internet explorer erlier than, mmc rusak kena virus, menghilangkan virus sality 101, cara hapus sality virus, Cara hapus virus di mmc, almanahe remover, antivirus diblok virus, cara hapus virus short cut, cara atasi virus shortcut, cara matikan microsoft has stopped working, apa penyebab flashdisk error cannot specified find, cara memperbaiki file mmc yang corup, cara mengatasi mmc terprotect virus, cara memperbaiki hardisk, cara mengatasi pesan aha dialer exe is not valid a win32 aplikation, cara memperbaiki flasdik yang terkena virus w32, cara meng hilangkan virus ms dos, cara membuat virus dan cara menghilanginya, cara mengatasi file regedit exe yang invalid, Cara mengatasi memory could not be read di komputer, cara memperbaiki sofware yg rusak, Cara memperbaiki MMC eror, cara menformat usb di internet, Cara mencari file yang error, cara memperbaiki laptop windows rusak, cara memperbaiki win32 yang di protec virus, cara membuka data di laptop yg terblokir, cara membuka cmd yang terkena virus, cara membunuh virus trojan, cara memperbaiki flashdisk yang terkena write protect, cara memperbaiki flashdisk yang minta di format, cara membuka flashdisk yang terprotect virus, cara memperbaiki explore exe terkena trojan, cara memperbaiki download manager yang terprotec, cara membersihkan virus amburadul, cara mengatasi antivirus di blokir virus, Cara membersihkan registry yang terinfeksi virus, cara memperbaiki fd rusak, cara membersihkan virus di bb, cara membersihkan virus di laptop windows xp, cara membersihkan virus flash disk, cara memperbaiki File Format Is Not Valid, cara membersihkan virus memory card, Cara memperbaiki mmc yg rusak, cara mengatasi antivirus program has been stopped, cara mengatasi photo-t432e jpeg exe, cara membersihkan virus sality 101 di flashdisk, delete ansav that write protected, cara mengatasi virus jpg, cara menghapus rundill, cara menghilangkan lsass, Cara menghapus file yang failed di IDM, Clean menghapus file, cara menghapus virus lewat bios, clean service exe virus muncul, cara menghapus virus winlogon, cara menghapus virus t432e, cara menghapus virus aadrive32 exe, cara mengembalikan billing expoler error, cara menghapus virus di mmc, cara menghapus polder yang susah, cara menghilangkan virus jpeg exe, cara mengatasi shortcut pada mmc, cara menghilangkan system shutdown DI:/system32/service exe, Cara menghilangkan virus flashdisk tanpa software, cara menghilangkan setup exe valid windows 32, explorer exe hilang windows 7 program di maximize tak tampak, cara scan virus lewat cmd, cara scan virus jpag, cara menghilangkan pesan stopped working saat buka exe, memperbaiki win32 window 7 xp, hardis kena virus shortcut, memperbaiki registy shell32 yang kena virus, Hkey_local_machine\sofware\ terinfeksi virus, memperbaiki billing server, memperbaiki fike kena virus html, memperbaiki fd dengan regedit, hapus sality tanpa menghapus program, membuka task manager yang kena blok, memperbaiki drive d error, invalid win32 aplication saat membuka file mp3, memperbaiki memory card yang terkena virus, Kenapa cmd gak bisa di buka di laptop, kena winlogon gimana atasin, membasmi virus sality dan ink, memory card kena virus, memperbaiki flash disk, meatasi rundll, kenapa windows stop working, melihat file jpg dg cmd pada memori card, hapus virus lnk lewat cmd, google di blok virus, memperbaiki rundll32 yang not responding, memperbaiki rundll32 pada saat shutdown, fix shortcut setelah kena virus lnk, sality 101 registry, virus pif remover, virus sality 101 selalu membuat shortcut dos dengan ekstension pif, virus shortcut hilang, Solusi regedit yang di block administrator, reparing short cut rusak, repair shortcut * lnk, tidak bisa aktifkan anti virus, virus amburadul express cleaner, solusi run dll error, setiap membuka explore selalu muncul confirmed folder delete, Tips menghapus virus flashdisc dari dos, solusi hardisk external disable, software pembasmi aadrive32 exe, task manager ada pesan "the system cannot find the file specified", Software penghapus empty registry, virus yg merusak pencarian google, w32/vbworm beau, photo-t432e jpg, privacy protection muncul blok komputer, photo-t432e jpg exe, buka folder not responding windows xp, bagaimana cara memulihkan data yang terkena virus autorun, cara mematikan rtp, cara delet polder yg kg bs di delet, cara hapus virus sistem shutdown, Cara hapus rundll 32, cara format flashdisk lewat cmd, cara hapus virus autorun d memory tanpa scan, Cara hapus virus shortcut laptop, apa kerosakan pada laptop windows selalu corrupt, apa itu virus sality 101, apa artinya the disc is write protect ?, billing ecafepro terkena virus, buka mmc keblokir kena virus, bagaimana cara memgatasi problem windows, basmi sality 101, cara membasmi virus sality, arti winlogos, atasi rundll 32 file corup, cara hilangin virus yang tidak bisa di hapus di flasdisk, cara membasmi virus trojan, cara format mmc di cmd, cara atasi fd yang minta format, cara enable task manager akibat conficker, cara membasmi virus ink, cara membasmi virus HKEY-CLASSES_ROOT, cara atasi windows disabl exe, cara membasmi virus amburadul, cara membasmi virus almahe b, cara jitu menghilangkan write protec, mengatasi virus winlogon, mengatasi blackberry selalu bufering, menghilangkan virus aadrive32 exe, patcher ayodance the system cannot find the file specified, mengembalikan photo yang rusak terkena virus, menghilangkan virus penyebab write protected, mengatasi komputer selalu minta restart, mengatasi is not valid win32 application, penghancur sality, mengatasi mmc yang protect, mengatasi explorer hilang, menghilangkan virus image, menghilangkan virus cmd super hiden, mengatasi problem with shorcut, mencari data yang hilang pada memory card

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!