� Back

� WWW.SPYROZONE.TK �

 

[017]. Membasmi Virus My Heart 2

 

------------------------------------------------------

Author  : SPYRO KiD

Contact : spyro_zone@Yahoo.com ==> www.spyrozone.tk

CopyLEFT (c) 2004 www.spyrozone.tk All Rights Reserved

� 01/12/2004  12:25:20 WIB

------------------------------------------------------

 

Wew, Virus My Heart 2 mulai merajalela. Kali ini saya berikan cara ringkas untuk membantainya. Carilah file-file dengan nama berikut ini di komputer anda.
 

ACCOUN~1.EXE 

ACDWAL~1.EXE 

ADVENT~1.EXE 

ADULTO~1.EXE 

AVRILL~1.EXE 

BLUEPO~1.EXE 

BACKUP~1.EXE

BRITNE~1.EXE

BANKDA~1.EXE 

COMAND.EXE

BIBLIO.EXE 

DATAOW~1.EXE

BLACKB~1.EXE 

DBASTO~1.EXE

BLUELA~1.EXE 

DESTIN~1.EXE

CALLC.EXE 

DISCOPER.EXE

CHKDKS.EXE

DON'TO~1.EXE

COFFEE~1.EXE

DRWATS~1.EXE

GONEFI~1.EXE

EMINEM~1.EXE

GREENS~1.EXE

EXE~1

HACKER~1.EXE

EXPLODER.EXE

HACKER~2.EXE

FBIWAN~1.EXE

HLOOKUP.EXE

FEATHE~1.EXE

JAVA-B~1.EXE

FIREHO~1.EXE

JAVA-T~1.EXE

ST5UNSTS.EXE

KRNL38~1

TELLNET.EXE

LASTAR~1.EXE

TONKHA~1.EXE

LIMPBI~1.EXE

TRYTHI~1.EXE

LIMPBI~2.EXE

VAGINA~1.EXE

LIMPBI~3.EXE

VLOOKUP.EXE

MOBSYNCS.EXE

WHATUP~1.EXE

MSSIEXEC.EXE

WHOIST~1.EXE

MYHEAR~1.EXE

WINGWORD.EXE

NCLIEN~1.EXE

WINNTS.EXE

NETVIEWS.EXE

ZAPOTECS.EXE

NIRVAN~1.EXE

SANTAF~1.EXE

NITEVI~1.EXE

SEPULT~1.EXE

NORTHW~1.EXE

SETUPI~1.EXE

NOTAPAD.EXE

SEXPEN~1.EXE

NTSRVO~1.VXD

SEXYHO~1.EXE

OHYEKI~1.EXE

SOAPBU~1.EXE

OPENOF~1.EXE

SQLREP~1.EXE

REGEDITS.EXE

PLAYAN~1.EXE

RHODOD~1.EXE

PORNAR~1.EXE

RIVERS~1.EXE

PORNBA~1.EXE

RUNONCES.EXE

PRAIRI~1.EXE

SALLAR~1.EXE

PWDUMPS.EXE


 

Bersihkan Startup Windows:

--------------------------
drwatsoon.exe ;234 kb ==> drwats~1.exe
mobsyncs.exe ;234 kb ==> mobsyncs.exe
NClienti386.exe ; 57 kb ==> nclien~1.exe
krnl386Mem ; 234 kb ==> krnl38~1
ntsrvosi386.vxd ; 234 kb ==> ntsrvo~1.vxd
.exe ; n/d ==> exe~1

**** folder default :
-------------------------------------------
\windows\system\ atau \windows\system32\
\winnt\system\ atau \winnt\system32\

-------------------------------------------
 
folder Start Up pada Start Menu :
----------------------------------------------------------------------------------
\WINDOWS\Start Menu\Programs\Start Up\ ==> \windows\startm~1\programs\startup\
\Documents and Settings\*User\Start Menu\Programs\Startup\ ========> \docume~1\*user\startm~1\programs\startup
----------------------------------------------------------------------------------

Menormalkan System
------------------
Pada windows 98 ketikan win.ini pada run kemudian hapus line yang memuat kata:
'mobsyncs.exe'
Pada windows nt/2000/xp coba find registry yang mengandung kata: 
mobsyncs.exe, drwatsoon.exe dan NClienti386.exe 

Misalnya pada Windows 2000 :

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sync Server"="C:\\WINNT\\System32\\drwatsoon.exe /n logon"
"Srv RPCmod"="C:\\WINNT\\System32\\NClienti386.exe"
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load"="C:\\WINNT\\System32\\mobsyncs.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe drwatsoon.exe"
 
Terakhir, Restart lah windows Anda.

   

/* ------------------------------|EOF|------------------------------ */

 

   � Back

� WWW.SPYROZONE.TK �