Bulubebek virus has been made using visual basic with size 53kb. Bulubebek Virus very easy to removed using some manual technique. Once virus active it will created master files:

  • \Windows\Script.exe
  • \Windows\LSASS.exe
  • \Documents and Settings\%user%\autorun.inf
  • \Documents and Settings\%user%\bulubebek.ini
  • \bulubebek.ini
  • \autorun.inf

When virus active it will blocking some windows functions such as task manager, folder option, command prompt and more… This virus spreading (usually because it was designed) using flashdisk media by creating autorun.inf files.

bulubebek_autorun.JPG

Hidden folder and duplicate folder

Bulubebek has been designed and working almost same with older brontox varian, it will hidden your  real folder and make duplicate .exe files with folder icon to tricky some newbie out there.

Step to cleaning bulubebek virus

1. I recommended to unplug your computers from your network, not really necessary but I think it’s gonna be safe.
2. Disable “System Restore” when in cleaning process.
3. Kill active virus process using 3rd party tools such as process explorer, kill virus process with icon folder.

process-explorer.JPG

4.  Repair registry has been changed by virus, save this code as any name with .inf extension and install it.

[Version]
Signature=”$Chicago$”
Provider=Nobody

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0×00010001,1
HKLM, SOFTWARE\Microsoft\Command Processor, AutoRun,0,
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0×00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue, 0×00010001,2
HKCU, Software\Microsoft\Command Processor, AutoRun,0,

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NOFind
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NORun
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PAYXX.exe
HKCU, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools

In case if this copy-paste code not working correctly in your text editor you can download repair files in Here

5. Find and deleted duplicate folder has been made by virus using search function. find any folders or files with rules:

  • Using folder icon.
  • Size 53 KB.
  • .exe extension
  • File type Application.

6. Shown your hidden files back, You can us your 3rd favorite tool or you can do it manually using attrib command by typing:

ATTRIB –s –h –r /s /d

NOTE: Should typing in drive root.

7. To make sure it was totally clean you can scan your computers with your best antivirus program.

Done :D

Similar Posts:

    Digg Del.icio.us StumbleUpon Reddit Twitter RSS

savira virus, bulu bebek source code, w32/vbworm beua, setprinter sys vbs, virus yang menghilangkan sound, virus savira, virus bulubebek, Savira exe, cara menghapus virus angel2 exe, cara hapus virus autorun, how to kill w32/vbworm beua virus, remove savira virus, cara membersihkan bulu bebek, remove nadia saphira, how to clean virus blue bebek, virus mematikan sound, virus matiin soundcard, cara mengatasi virus exe, Hilangkan Windows Script Host, virus hiden printer audio, membersihkan virus autorun, sound device hilang, mematikan virus yang mendisable card lan device, ANTIVIRUS BEBEK, svira virus, w32 vwworm qxe, cara mengatasi active desktop recovery, how to delete savira exe worm, settingan untuk HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Safeboot, w32/vbworm folder shortcut, remove bulu bebek, virus mematikan card lan, savira virus forum, remove setprinter sys virus, savira, mencegah virus disable sound, removal tools for W32/VBWorm bEAU, mengatasi lan eror, Mengatasi lsass exe endpoint, manually remove angel2 worm, mengatasi virus angel2 exe, nak buang virus scr, mengatasi virus network audio, menghapus virus registry editor disable win7, menghapus virus yang mematikan sharing printer, menghilangkan virus bulubebek, menghilangkan virus visualbasic, merepair win32 yang hilang, Nadira sapira bugil, mengatasi virus worm, nak hapus virus yang hidden file, membasmi virus angel2, savira worm, virus svira, virus vbworm beua code, virus yang mematikan soun card, virus yang mematikan sound card, virus yang mendisable audio dan network, virus yang mendisable sound card, virus yang menonaktifkan sound, virus yg mematikan sound, w32/vbworm beau remover, w32/vbworm beua ?, w32/vbworm beua how to remove from systeam, w32/vbworm beua removal tool, what anti virus can delete a savira exe, what is savira exe, virus sound hilang, virus mendisable paste, virus men disable paste, script virus to disable sound, setprinter sys vbs showing how can recover, sound disable virus recovery, svira und autorun inf entfernen, w32/vbworm beau removal tool, tools membersihkan virus shortcut, tools removal virus bulu bebek, virus apa yang menghilangkan sound, virus driver audio hilang, virus hilang sound laptop, virus mematikan audio, virus mematikan sound card, virus mematikan sound dives, virus mematikan soundcard, win32 autorun pif, active desktop bagaimana memperbaiki, cara bersihkan bulu, cara hapus virus angel2, cara hapus virus blue bebek, cara hendak buang hidden folder, cara membasmi angel2, cara membersihkan virus saily, cara membersihkan virus win32, cara membersihkan virus worm win32 amnl, cara memperbaiki active desktop recovery, cara memperbaiki internet extensions for win32 has stopped working windows 7, cara memperbaiki lan setting, cara memperbaiki registry console tool has stopped working, cara memperbaiki registry copy/paste windows 7, cara memperbaiki registry lisensi this copy of windows is not genuine, cara memperbaiki registry windows 7, cara memperbaiki restore my active desktop, cara bersihkan angel2 exe, bulubebek source remover, bulubebek remover tool, antivirus untuk menghapus virus angel2, antivirus untuk virus bulu bebek, apa itu HKLM/SYSTEM/CurrentControlsSet/SafeBoot/AlternateShell Value, apa itu vorus w32, atasi sys, atasi virus yang hidden file, autorun hilangkan, bagaimana cara buang virus hidden folder, bagaimana cara hilangin genuine windows, bagaimana cara memperbaiki systim windows 7 yang erorr, bagaimana mengatasi cannot copy file : cannot read from the source file or disk, bagaimana mengatasi internet extensions for win32 has stopped working windows 7, bgaimana cara membersihkan virus exe, bulu bebek, bulubebek removal, bulubebek remove, cara memperbaiki restore my active desktop dari regedit, cara memperbaiki sound win 7 yang hilang, cara remove active desktop recovery, clean svira, delete svira virus of flash memory, download contoh virus, file exe hilang, file win32 exe hilang, fix bulubebek, folder hilang scr membuang, hacked by bulu bebek, how to fix disabled network and sound by virus, how to remove setprinter sys vbs, how to remove svira, how to remove svira virus, how to remove w32/vbworm beua manually, internet extension for win32 has stopped working adalah, internet extensions for win32 has stopped working windows 7, cara perbaiki update task exe has stopped working, cara perbaikan memory card yang kena virus, cara menghulangkan virus angel2, cara memperbaiki sounds and device audio yang hilang, cara memperbaiki windows 7, cara mendelete nadira shapira, cara mengapus autorun inf, cara mengapus paksa file, cara mengatasi google chrome has stopped working, cara mengatasi LAN yang hilang, cara mengatasi remove audio error, cara mengatasi restore my active desktop, cara menghapus system duplicate network, cara menghapus virus angel2, cara menghilangkan active dekstop recovery, cara menghilangkan download master, cara menghilangkan ramnit lewat cmd, cara menghilangkan virus type worm, cara menghilangkan windows script error, internet extensions for win32 has stopped working windows 7 cara

If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!