How to remove Madforelmo malware

“Madforelmo!”, you can view this at windows taskbar when you are infected with samok.vbs malware. This is a variant of sowar.vbs where your task manager and folder options where disabled plus no more run command and registry editing is disabled.

You will be annoyed when this malware changed your “Open” command in the right click menu to “b-b2g” and “Explore” command to “Owned” when you right click a drive or folder.

Registry Entries:

  • The newly created Registry Values are:
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\explore]
    • (Default) = “Owned!”
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\open]
    • (Default) = “b-b2g”
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    • autoMe = “wscript.exe “%Windir%\samok.vbs”"

  • You can find the technical specifications of the virus here

How to Remove the malware manually:

1.  Google and download the tools to enable the taskmanager (Download Here) and  regedit (Download here) and Download combofix 2.  Restart the computer in Safe Mode (press F8 before the Windows Startup Screen and Select Safe Mode)

3.  Select the Administrator Account

4. Copy the tools that enable taskmanager and regedit to Desktop and double click to run

5. Copy combofix to desktop and double-click it to  run  program  (follow the combofix instruction)

6. After the combofix had remove malware in your PC, kindly click to Tools>Folder Options

*If Folder Options is not found, run regedit in the RUN command or at the command prompt, changed the values of this keys from 1 to 0

  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    • NoFolderOptions = 0
    • NoRun = 0

7. Click View Tab>Click Show Hidden Files and Folders

8. Browse to C:\Windows\

9. Find the file samok.vbs and Delete the file

10. Run Regedit to Cleanup the Registry (to run Regedit click RUN Type Regedit or in the command prompt type Regedit

Change these Keys to return to defaul AM and PM

  • [HKEY_CURRENT_USER\Control Panel\International]
    • s1159 = “b-b2g” changed to “am”
    • s2359 = “madforelmo” changed to “pm”

Please search this registry entries:

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\explore]
    • (Default) = “Owned!” -> Removed the value
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\open]
    • (Default) = “b-b2g” -> Removed the value
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    • autoMe = “wscript.exe “%Windir%\samok.vbs”" -> Removed the entry

Restart Your Computer.

Popularity: 100% [?]

Share and Enjoy:
  • Digg
  • Sphinn
  • Facebook
  • Mixx
  • Google Bookmarks
  • MisterWong
  • MySpace
  • NewsVine
  • Reddit
  • RSS
  • Technorati
  • Tipd
  • Twitter