caranya ga bakalan bisa dari safe-mode sampe saat ini , cara ini yg ane pake cukup efektip... 1. booting dengan xp-live (terserah mo pake minipe, bartpe, ato apa deh) 2. scan dengan NOD32 (di ane update sampe tgl 12 desember 06 sudah mampu babat nih virus) 3. booting normal lagi ke windows xp nya 4. baikin registrinya, copy paste dari source bawah ini, buat nama "terserah.inf" asal .inf yah...terus klik kanan di file ini kalo dah kelar, pilih install
[Version] Signature="$Chicago$" Provider=xaviero [DefaultInstall] AddReg=UnhookRegKey DelReg=del [UnhookRegKey] HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*" HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*" HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*" HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*" HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1"" HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*" HKCU, Control Panel\Desktop, SCRNSAVE.EXE,0, HKLM, SOFTWARE\Classes\exefile,,,"Application" HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe" HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe" HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe" HKLM, SYSTEM\ControlSet003\Control\SafeBoot, AlternateShell,0, "cmd.exe" HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe" HKCU, Software\Microsoft\Internet Explorer\Main, Start Page,0, "About:Blank" HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1 [del] HKCU, Software\Microsoft\Windows\CurrentVersion\Run,tboh.exe HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,iusbi HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore, DisableConfig HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore, DisableSR HKLM, SOFTWARE\Classes\exefile, NeverShowExt HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\calc.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CClaw.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\freecell.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshearts.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nip.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nipsvc.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshearts.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Niu.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Njeeves.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvccf.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcoas.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcod.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcsched.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sol.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spider.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\URemovalCRC32.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winamp.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmine.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV32.exe ok, selamat membersihkan virus rachmat_oom wrote: >--- In [email protected], "Vikodratillah HB" ><[EMAIL PROTECTED]> wrote: > > >>All Friend Milis... >> >>Ass... >> >>Ane mo minta tlong nih. >>Baru2 ini komputer ane dikantur kena pirus "Pangeran Blank". >>Pirus ini masup'y dari UFD yang sangat "mobile' sekali. >>Ane udah coba antivirus mulai dari >>Avast (Update'an terbaru krna ane pake avast n' rajin update min 1 >> >> >minggu > > >>sekali), >>Symantec, Norton 2006, AVG bahkan Norman (emang sih bukan yang ori >> >> >tp > > >>c**ran). >>Itu virus kaga' juge bisa kedetect. >> >>Akhir'y Bos ane panggil mpuh'y yang jago kmptr. Kate mpuhnya itu >> >> >pirus lokal > > >>yang masih >>varian dari Brontok. Emang masih baru n' blm kedetect ama smua >> >> >antivirus. > > >>Si Mpuh ngejinaki itu pirus make "ERD Commander 2002". >> >>Ciri2 tuh pirus sama kaya' induknya, cuma dia bukan menyembunyikan >> >> >file tp > > >>folder. >>Semua folder yang ke infeksi jadi Aplication. Ukurannya 34KB. >> >> >Selain itu > > >>juga didrive >>system ada notepad berjudl "Pangeran Blank" dengan "wejangan" yang >> >> >intinya > > >>beliau mo menjaga kmpter ane dari segala tindakan2 yang >> >> >membahayakan bagi > > >>kmptr ane. Trus ql ngejalani suatu program dalam beberapa saat >> >> >setelah run > > >>akan >>menutup sendiri. >> >>Nah, pertanyaannya, kira2 antivirus apa yang bisa ngedetect itu >> >> >pirus. > > >>Ato se nggak2'y gimana cara ngebunuh tuh pirus ql udah merasuki >> >> >kompter ane. > > >>Soal'y ane rada2 alergi ama pirus (ql pilus kaga' alergi). >> >> >Trus, "ERD > > >>Commander" itu >>Software apa-an? Ada dijual gak software itu di outlet2 B**Kan?!? >> >>Thanks atas semua perhatiannya dari teman2. >> >>Wass... >> >> >>[Non-text portions of this message have been removed] >> >> >> > >Ass war wab >Laptop temenku juga kena virus serupa. >Susah juga cari obatnya karena dalam kondisi safe mode pun masih >aktif, hapus registry juga masih ada, padahal system restorenya udah >di off tapi masih hidup lagi-hidup lagi. >Gimana nih >Wass war wab > > > > Send instant messages to your online friends http://au.messenger.yahoo.com
