11 February 2007

Virus Babon Dan Cara Ngilanginnya

Komputermu kena virus babon ya gampang kok manual aja dech ngilanginnya....
ciri-ciri kena babon
1. desktopnya jadi babon komputer jamnya juga jadi babon kalo ngeklik desktop keluar babonnya wakakakaka
Cara ngilanginya gini dech
buat file yang ekstensinya .BAT yang isinya kayak gini

delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion,Bron-Spizeatus,value)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft
\Windows\CurrentVersion\Policies\System,NoClose,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft
\Windows\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft
\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions,1,0,dword)
doubleext(%system%\shellnew\sempalong.exe,exe,kill)
doubleext(%windows%\shellnew\sempalong.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\Ok-SendMail-Sens-asi,dir,killdir)
doubleext(%userdir%\Local Settings\Application Data
\Loc.Mail.Bron.Tok,dir,killdir)
doubleext(%windows%\eksplorasi.exe,exe,kill)
|doubleext(%windows%\shellnew\sempalong.exe,exe,kill)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoFolderOptions,1,0,dword)
doubleext(%system%\%username%'s setting.scr,scr,kill)
|doubleext(%userdir%\Local Settings\Application Data
\csrss.exe,tok,kill)
doubleext(%userdir%\Local Settings\Application Data
\inetinfo.exe,tok,kill)
doubleext(%userdir%\Local Settings\Application Data
\lsass.exe,tok,kill)
doubleext(%userdir%\Local Settings\Application Data
\winlogon.exe,tok,kill)
doubleext(%userstartup%\empty.pif",pif,kill)
|doubleext(%usertemplates%\Brengkolang.com,com,kill)
doubleext(%system%\svchos.exe,exe,kill)
checkandkill(%windows%\tasks\at0.job)
checkandkill(%windows%\tasks\at1.job)
checkandkill(%windows%\tasks\at2.job)
delregkey(HKEY_CLASSES_ROOT\TGMfile,0,key)
delregkey(HKEY_CLASSES_ROOT\LLGfile,0,key)
delregkey(HKEY_CLASSES_ROOT\PLGfile,0,key)
delregkey(HKEY_CLASSES_ROOT\.TGM,0,key)
delregkey(HKEY_CLASSES_ROOT\.plg,0,key)
delregkey(HKEY_CLASSES_ROOT\.LLG,0,key)
changeregvalue(HKEY_CLASSES_ROOT\exefile,NeverShowExt,1,0,string)
changeregvalue(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT
\CurrentVersion
\Winlogon,shell,Explorer.exe itelnet.exe,Explorer.exe,0,string)
changeregvalue(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion
\policies\Explorer,NoFolderOptions,1,0,dword)
changeregvalue(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion
\policies\system,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\SOFTWARE\Microsoft
\Windows\CurrentVersion
\policies\system,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
\Windows\CurrentVersion
\policies\system,DisableTaskMgr,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft

\Windows\CurrentVersion
\Policies\System,DisableTaskMgr,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Policies\Microsoft
\windows
\system,DisableCMD,1,0,dword)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion,MU,value)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion,Winsys,value)
doubleext(C:\Documents and Settings\All Users\Application Data
\BackupMe\mura.LLG,exe,kill)
doubleext(C:\Documents and Settings\All Users\Application Data
\BackupMe\mura.PLG,exe,kill)
doubleext(C:\Documents and Settings\All Users\Desktop
\Internet Explorer.exe,exe,kill)
doubleext(C:\Documents and Settings\All Users\Start Menu
\Programs\Internet Explorer.exe,exe,kill)
doubleext(C:\mura.TGM,exe,kill)
doubleext(C:\www.free-porno.com.html.exe,exe,kill)
doubleext(C:\www.free-porno.com_files
\www.free-porno.com.html.exe,exe,kill)
doubleext(C:\www.free-porno.com_files
\www.free-porno.com_files.html.exe,exe,kill)
doubleext(%virpath%\data_%username%,dir,killdir)
doubleext(filename,ico,attribute)
doubleext(filename,jpg,attribute)
doubleext(filename,bmp,attribute)
doubleext(filename,gif,attribute)
doubleext(filename,htm,attribute)
doubleext(filename,html,attribute)
doubleext(%userdir%\Local Settings\Application Data
\csrss.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\inetinfo.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\lsass.exe.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\services.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\smss.exe,exe,kill)
doubleext(%userdir%\Local Settings\Application Data
\winlogon.exe,exe,kill)
doubleext(%userdir%\Start Menu\Programs\Startup\Empty.pif,pif,kill)
doubleext(%userdir%\Templates\WowTumpeh.com,com,kill)
doubleext(%windows%\eksplorasi.exe,exe,kill)
doubleext(%windows%\ShellNew\bronstab.exe,exe,kill)
doubleext(%system%\%username%'s Setting.scr,scr,kill)
doubleext(%userdir%\Local Settings\Application Data
\Loc.Mail.Bron.Tok,dir,killdir)
doubleext(%userdir%\Local Settings\Application Data
\Ok-SendMail-Bron-tok,dir,killdir)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,NoClose,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoFolderOptions,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoFolderOptions,1,0,dword)
checkandkill(%windows%\tasks\at0.job)
checkandkill(%windows%\tasks\at1.job)
checkandkill(%windows%\tasks\at2.job)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,NoClose,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoFolderOptions,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoRun,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,NoFind,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableTaskMgr,1,0,dword)
shell(attrib.exe "%virpath%\*.*" -s -h -r /S /D)
doubleext(%system%\google.htm,htm,kill)
doubleext(%system%\nvcpl32.exe,exe,kill)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run,Application,value)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run,Log,value)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableRegistryTools,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\Explorer,DisableTaskMgr,1,0,dword)
changeregvalue(HKEY_CURRENT_USER\Software\Microsoft\Windows
\CurrentVersion\Policies\System,DisableTaskMgr,1,0,dword)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run,lexplorer,value)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run,dkernel,value)
doubleext(filename,doc,attribute)
doubleext(%windows%\lexplorer.exe,exe,kill)
doubleext(%system%\i75-d2\inz.d,d,kill)
doubleext(%system%\i75-d2\d2.mix,mix,kill)
doubleext(%system%\i75-d2\dkernel.exe,exe,kill)
doubleext(%system%\i75-d2,dir,killdir)
doubleext(%system%\ssevtmgr.exe,exe,kill)
doubleext(%userdocuments%\letter.exe,exe,kill)
doubleext(C:\Program Files\Accessories\Clean.Exe,exe,kill)
delregkey(HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run,LoadService,value)

0 comments:

 

Home | Blogging Tips | Blogspot HTML | Make Money | Payment | PTC Review

AQ Cybernet © Template Design by Herro | Publisher : Templatemu