Win32.zafi.b Malware Virus Removal

Symptoms : Fake alert saying about win32.Zafi.B, and the computer will freezes on boot up.

Type of Infection : Malware ||    Risk Level : Medium

Removal:
Reboot the computer in safemode with networking and download  the tool Malwarebyte. You can find Malwarebyte on Download.com and here the direct link . Rename the downloaded file to setup.exe.
Open the file by double clicking it  and while installing the program its seem like frozing the system, but it hasnt and  will take about 20 minutes to 1 hour to complete the entire process.
After the installation go to the Malware folder in the  Program Files, then rename the executable to mab.exe and run the program.
Restart the computer.

Remove Antivirus 2008 – Fake Malware Virus

Antivirus 2008 is a virus that affects the computer and shows non-existant infections and prompts the user to buy the premium version to remove these viruses. This is a fake anti-virus that affects the PC user and the infections that it shows are not really there.

These are the files that AntiVirus2008 installs on your computer. If you have these files in your computer, then you are likely to be having this computer virus.

c:\Program Files\Antivirus 2008
c:\Program Files\Antivirus 2008\Antvrs.exe
c:\Documents and Settings\forensics\Start Menu\Antivirus
c:\Documents and Settings\forensics\Desktop\antvrs.exe
c:\Documents and Settings\forensics\Application Data\Antivirus
c:\Documents and Settings\forensics\Start Menu\Antivirus\Antivirus 2008.lnk
c:\Documents and Settings\forensics\Start Menu\Antivirus\Uninstall Antivirus.lnk
c:\Documents and Settings\forensics\Local Settings\Temporary Internet Files\Content.IE5\0L6FS9QR\instlog[1].htm
c:\Documents and Settings\forensics\Local Settings\Temporary Internet Files\Content.IE5\IQJ9X5GB\antvrs[1].exe

Registry Entries of Anti-Virus 2008

HKEY_CURRENT_USER\Software\Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus2008y”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce “3P_UDEC”