My Virtual Voice

July 8, 2008

Virus “81u3f4nt45y”

Filed under: IT, My Voice

Siapa bilang ngelawan virus harus pakai anti virus?
Ikuti langkah2 ini untuk ngelawan virus 81u3f4nt45y…

1. Kalau bisa, matiin System Restore dulu.
Caranya:
- pencet Start + Pause | Break
- Pilih tab "System Restore", beri centang pada "Turn off system.. bla3…"

2. Matikan proses "Adobe Online.com" dan "Adobe Update.com" di memori
Caranya:
- pencet Ctrl + Shift + Esc
- pada tab "Processes" cari kedua file di atas
- matikan dengan cara klik namanya, lalu klik End Process
- kalau nggak bisa ulang lagi, tapi klik yang End Process Tree

3. Betulkan entry registry yang dirusak virus
Caranya:
- Buka Notepad (Start + R , ketik notepad lalu enter)
- Copy paste tulisan yang dicetak miring di bawah ini
- Simpan dengan nama terserah.inf (Ctrl + S, pastikan save as typenya jadi "All Files" lho ya)
- Lalu klik kanan di file baru tadi, pilih Install

[Version]

Signature="$Chicago$"

[DefaultInstall]

AddReg=UnhookRegKey

DelReg=del

[UnhookRegKey]

HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""

HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"

HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"

HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"

HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0

HKLM, SOFTWARE\Classes\scrfile,,,"Screen Saver"

[del]

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeCaptio

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, LegalNoticeText

HKLM, SOFTWARE\Classes\scrfile, InfoTip

HKLM, SOFTWARE\Classes\scrfile, NeverShowExt

HKLM, SOFTWARE\Classes\scrfile, TileInfo

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

4. Hapus file2 virus
Caranya:
- Buka Windows Explorer (Ctrl + E)
- Masuk C:\Document and Settings\%namausernya%\Start Ment\Programs\Startup\
-Hapus file yang namanya Adobe Online.com dan Adobe Update.com
- Masuk C:\ Hapus file yang bergambar folder dengan ukuran +- 40Kb dan file autorun.inf dan file Thumbs.com dan file Thumbs .db (untuk Thums.db ukurannya sekitan 1,300 Kb)
- Ulangi langkah hapus untuk setiap drive yang ada

5. Terakhir… tampilkan file yang dihidden virus
Caranya:
- Buka Command Prompt (Start + R)
- ketik cmd
- ketik cd\
- ketik attrib -s -h /s /d
- ulangi untuk setiap drive (untuk ganti drive ketik D:\ atau E:\ dst…)

Selamat mencoba, klo gak berhasil silahkan pake Antivirus yang jitu dan handal. 

3 Comments »

The URI to TrackBack this entry is: http://iisrasjeed.blogsome.com/2008/07/08/81u3f4nt45y/trackback/

  1. mas ajari dunk saya bahasa madura

    Comment by antown — July 19, 2008 @ 12:52 am

  2. Boleh2 aja…kamu minta diajari yang dari dasar apa gimana..kykna kamu salah masuk thread deh..silakan kamu masuk dalam kategori pos yang madura dan budaya.

    Best regard,

    -IIS-

    Comment by iisrasjeed — July 20, 2008 @ 4:55 pm

  3. mas boleh tau forum/web/milisnya alumni SLTPN 1 pangpajung modung ga?

    Comment by ryu_cadas — January 7, 2009 @ 12:32 pm

RSS feed for comments on this post.

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>



Anti-spam measure: please retype the above text into the box provided.






















Get free blog up and running in minutes with Blogsome
Theme designed by B A Khan