This virus categorized as low class because actually this virus not really hard to removed and not really annoyed. Carefully when you received this messages/pop up:
1Â nikmatnya_gadis_desa
2Â saat pertama berkenalan dengannya aku merasa senang
3Â dia hanya seorang gadis desa
4Â dengan cahaya pada bola matanya
5Â yang mampu membawaku terbang
6Â dengan keluguannya
7Â yang selalu membuatku membimbingnya
8Â dia adalam matahariku
9Â yang mencairkan kebekuan hatiku
10 dari :rieysha
To know if your computer infected by this virus is you will see many multimedia files with size around 148KB This virus will generate lot of this files type so it will take enough your disk-space.
Norman antivirus can detect this virus as W32/Wayrip.A
Virus Master
After success to active this virus will creating his master file and also copied it into another drive like d: e: etc.
3gp.exe
dari_rieysha_anak_jogja.exe
dokumenPenting.exe
film.exe
gambar.exe
musik.exe
puisi.txt
Virus will change registry value in HKLM to make it active each time computer reboot:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nikmatnya_gadis_desa = C:\nikmatnya_gadis_desa.exe
To protect himself from people( like me 😛 ) this Virus will try to blocking some windows function like:
– Folder Option
– Run
– Find
– Menu Shutdown
– Drive C:\
– Registry Editor
– Task Manager
– CMD
Virus will change your browser start page redirected to https://h1.ripway.com/anharku (Account already deleted by ripway company) This is the virus creator homepage he try to get lot of people come to his website maybe just for click him adsense ads *LOL*
Virus will change your time AM PM value into riesyha
Virus will change your windows information
Virus will hiding your drive C:
The best part of this virus he will try to kill all security/antivirus programs with caption:
Virus
Trend
procexp.exe
Remove
Panda
mmc.exe
Kill
Kaspersky
cmd.exe
Rontok
Aladdin
Windows
Rontox
Sysinter
Setup
Machine
brontokwasher.exe
ansav
Norton
hijackthis.exe
anti
Symantec
killbox.exe
kill
Norman
Movzx
scan
Bitdef
Ertanto
remov
Avast
Washer
security
Mcaf
Killbox
config
Grisoft
Registry
patrol
Cillin
Utility
hijack
Process
Master
pcmav
I said this is the best part of this virus because it might make some people confused 😀 this virus also still active on windows mode “safe mode with command prompt” and the last lame autorun.inf file for spreading himself using flash disk media.
Enough now time to remove this virus!
1. Turn off “system restore” service when in cleaning process.
2. Kill virus process using 3rd party tools killVB, Download it on here or download from my server here
3. Delete registry changed by Virus using FixRegistry download from here or download from my server here
4. Delete all master virus with specification:
- Size 148KB
- Icon Multimedia
- File extension .exe
- File type Application
Before you do this set folder option to show hidden files.
5. Delete also this file list on root drive (c:\, d:\, etc)
- pesene_seng_gawe.htm (size 22 KB)
- xx pesene_seng_gawe.htm (size 1 KB), xx = Random
- Autorun.inf
- C:\Puisi.txt
- C:\Windows\Taskman.com
6. Last scan with your best antivirus program to make sure your system clean.
Done, Have a nice day 😀
Similar Posts:
- Microsoft.lnk Shortcut Virus? Worm:PIF/Starter.A
- Remove Sandra Dewi Bugil Virus W32/Sadra.A
- Remove MaHaDeWa VBS.Autorun.AM
- Simple Step To Remove Recycler.lnk Mso.SYS
RELATED SEARCH TERMS:
- newforex3gp
- newforex3gp
- newforex3gp blogspot
- newforex3gp blogspot
- gadis desa
- forex3gp
- gadis desa
- forex3gp
- dewi3gp blogspot
- dewi3gp blogspot
- dewi3gpblogsport
- dewi3gpblogsport
- newforex 3gp
- forek3gp
- tubexx 3gp
- new forex3gp
- newforex 3gp
- forek3gp
- tubexx 3gp
- new forex3gp
- anew forex 3gp blogspot
- forex blogspot 3gp
- dewi3gpblogspotyoutube
- gadis desa adult
- FORES NEW KOOLWAP IN MP4
- new forex 3gp blogspot
- gadis desa 3gp blogspot
- Wxw gambar cewek cnm
- gadis desa adult
- anew forex 3gp blogspot
- forex blogspot 3gp
- dewi3gpblogspotyoutube
- FORES NEW KOOLWAP IN MP4
- new forex 3gp blogspot
- gadis desa 3gp blogspot
- Wxw gambar cewek cnm
Good job. I can’t think it took me so long to find the blog. I really love the formatting.