|
[017]. Membasmi Virus My
Heart 2
------------------------------------------------------
Author : SPYRO KiD
Contact : spyro_zone@Yahoo.com
==> www.spyrozone.tk
CopyLEFT (c) 2004
www.spyrozone.tk All Rights Reserved
� 01/12/2004 12:25:20 WIB
------------------------------------------------------
Wew, Virus My Heart 2
mulai merajalela. Kali ini saya berikan cara ringkas untuk membantainya. Carilah
file-file dengan nama berikut ini di komputer anda.
|
ACCOUN~1.EXE
|
ACDWAL~1.EXE |
|
ADVENT~1.EXE
|
ADULTO~1.EXE |
|
AVRILL~1.EXE
|
BLUEPO~1.EXE |
|
BACKUP~1.EXE
|
BRITNE~1.EXE |
|
BANKDA~1.EXE
|
COMAND.EXE |
|
BIBLIO.EXE
|
DATAOW~1.EXE
|
|
BLACKB~1.EXE
|
DBASTO~1.EXE
|
|
BLUELA~1.EXE
|
DESTIN~1.EXE
|
|
CALLC.EXE
|
DISCOPER.EXE
|
|
CHKDKS.EXE
|
DON'TO~1.EXE
|
|
COFFEE~1.EXE
|
DRWATS~1.EXE
|
|
GONEFI~1.EXE
|
EMINEM~1.EXE
|
|
GREENS~1.EXE
|
EXE~1
|
|
HACKER~1.EXE
|
EXPLODER.EXE
|
|
HACKER~2.EXE
|
FBIWAN~1.EXE
|
|
HLOOKUP.EXE
|
FEATHE~1.EXE
|
|
JAVA-B~1.EXE
|
FIREHO~1.EXE
|
|
JAVA-T~1.EXE
|
ST5UNSTS.EXE
|
|
KRNL38~1
|
TELLNET.EXE
|
|
LASTAR~1.EXE
|
TONKHA~1.EXE
|
|
LIMPBI~1.EXE
|
TRYTHI~1.EXE
|
|
LIMPBI~2.EXE
|
VAGINA~1.EXE
|
|
LIMPBI~3.EXE
|
VLOOKUP.EXE
|
|
MOBSYNCS.EXE
|
WHATUP~1.EXE
|
|
MSSIEXEC.EXE
|
WHOIST~1.EXE
|
|
MYHEAR~1.EXE
|
WINGWORD.EXE
|
|
NCLIEN~1.EXE
|
WINNTS.EXE
|
|
NETVIEWS.EXE
|
ZAPOTECS.EXE
|
|
NIRVAN~1.EXE
|
SANTAF~1.EXE
|
|
NITEVI~1.EXE
|
SEPULT~1.EXE
|
|
NORTHW~1.EXE
|
SETUPI~1.EXE
|
|
NOTAPAD.EXE
|
SEXPEN~1.EXE
|
|
NTSRVO~1.VXD
|
SEXYHO~1.EXE
|
|
OHYEKI~1.EXE
|
SOAPBU~1.EXE
|
|
OPENOF~1.EXE
|
SQLREP~1.EXE
|
|
REGEDITS.EXE
|
PLAYAN~1.EXE
|
|
RHODOD~1.EXE
|
PORNAR~1.EXE
|
|
RIVERS~1.EXE
|
PORNBA~1.EXE
|
|
RUNONCES.EXE
|
PRAIRI~1.EXE
|
|
SALLAR~1.EXE
|
PWDUMPS.EXE
|
Bersihkan Startup Windows:
--------------------------
drwatsoon.exe ;234 kb ==> drwats~1.exe
mobsyncs.exe ;234 kb ==> mobsyncs.exe
NClienti386.exe ; 57 kb ==> nclien~1.exe
krnl386Mem ; 234 kb ==> krnl38~1
ntsrvosi386.vxd ; 234 kb ==> ntsrvo~1.vxd
.exe ; n/d ==> exe~1
****
folder default :
-------------------------------------------
\windows\system\ atau \windows\system32\
\winnt\system\ atau \winnt\system32\
-------------------------------------------
folder Start Up pada Start Menu :
----------------------------------------------------------------------------------
\WINDOWS\Start Menu\Programs\Start Up\ ==> \windows\startm~1\programs\startup\
\Documents and Settings\*User\Start Menu\Programs\Startup\ ========> \docume~1\*user\startm~1\programs\startup
----------------------------------------------------------------------------------
Menormalkan System
------------------
Pada windows 98 ketikan win.ini pada run kemudian hapus line yang memuat kata:
'mobsyncs.exe'
Pada windows nt/2000/xp coba find registry yang mengandung kata:
mobsyncs.exe, drwatsoon.exe dan NClienti386.exe
Misalnya pada Windows 2000 :
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sync Server"="C:\\WINNT\\System32\\drwatsoon.exe /n logon"
"Srv RPCmod"="C:\\WINNT\\System32\\NClienti386.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load"="C:\\WINNT\\System32\\mobsyncs.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe drwatsoon.exe"
Terakhir,
Restart lah windows Anda.
/* ------------------------------|EOF|------------------------------ */
|