Virus Shortcut

Inget temen gw kemaren jadi pengen buat posting tentang artikel ini, yah nggk jauh2 sih kasusnya tentang virus shortcut, awalnya sih si doi minta tolong suruh bener'n kompynya, wokey lah besuk senin dia bilang, yah sud dc, tapi sekarang gi hari sabtu, hmm,..bingung dc mw ngapain malem minggu gini, pacar juga lum punya, haduew,, betapa malang nasipku ne, hehe,..  akhirnya gw iseng2 buat artiket ini dc, ya sud lah dari pada kepanjangan, :D
 
 Virus PIF/Starter atau yang lebih dikenal dengan virus shortcut membuat kesal korbannya dengan banyak sekali shortcut yang dibuat oleh virus tersebut. Repotnya, kalau cara penanganan virus ini tak tepat maka ia malah akan kembali lagi, lagi dan lagi.

Berikut ini beberapa cara dari analis virus Vaksincom MG Lat untuk menghentikan banjir shortcut yang diakibatkan virus ini:

1. Sebelumnya matikan dulu proses system restore.

2. Matikan proses dari file Wscript yang terletak di C:\Windows\System32, dengan cara menggunakan tools seperti CProcess, HijackThis atau dapat juga menggunakan Task Manager dari Windows.

3. Setelah dimatikan proses dari Wscript tersebut, kita harus men-delete atau me-rename dari file tersebut agar tidak digunakan untuk sementara oleh virus tersebut.

Sebagai catatan, kalau kita me-rename dari file Wscript.exe tersebut dengan otomatis, maka akan dikopikan lagi di folder tersebut. Oleh sebab itu, kita harus mencari di mana file Wscript.exe yang lainnya, biasanya ada di C:\Windows\$NtServicePackUninstall$, C:\Windows\ServicePackFiles\i386.

Tidak seperti virus-virus VBS lainnya, kita bisa mengganti Open With dari file VBS menjadi Notepad, virus ini berextensi MDB yang berarti adalah file Microsoft Access. Jadi Wscript akan menjalankan file DATABASE.MDB seolah-olah dia adalah file VBS.

4. Delete file induknya yang ada di C:\Documents and Settings\\My Documents\database.mdb, agar setiap kali komputer dijalankan tidak akan me-load file tersebut. Dan jangan lupa kita buka juga MSCONFIG, disable perintah yang menjalankannya.

5. Sekarang kita akan men-delete file-file Autorun.INF. Microsoft.INF dan Thumb.db. Caranya, klik tombol START, ketik CMD, pindah ke drive yang akan dibersihkan, misalnya drive C:\, maka yang harus kita lakukan adalah:

Ketik C:\del Microsoft.inf /s, perintah ini akan men-delete semua file microsoft.inf di seluruh folder di drive C:. Sementara kalau mau pindah drive tinggal diganti nama drivenya saja contoh: D:\del Microsoft.inf /s.

Untuk file autorun.inf, ketik C:\del autorun.inf /s /ah /f, perintah akan men-delete file autorun.inf (syntax /ah /f) digunakan karena file tersebut memakai attrib RSHA, begitu juga untuk file Thumb.db lakukan juga hal yang sama.

6. Untuk men-delete file-file selain 4 file terdahulu, kita harus mencarinya dengan cara search file dengan ekstensi .lnk ukurannya 1 kb. Pada 'More advanced options' pastikan option 'Search system folders' dan 'Search hidden files and folders' keduanya telah dicentang.

Harap berhati-hati, tidak semua file shortcut / file LNK yang berukuran 1 kb adalah virus, kita dapat membedakannya dari ikon, size dan tipenya. Untuk shortcut yang diciptakan virus ikonnya selalu menggunakan icon 'folder', berukuran 1 kb dan bertipe 'shortcut'. Sedangkan folder yang benar harusnya tidak memiliki 'size' dan tipenya adalah 'File Folder'.

7. Fix registry yang sudah diubah oleh virus. Untuk mempercepat proses perbaikan registry salin script dibawah ini pada program 'notepad' kemudian simpan dengan nama 'Repair.inf'. Jalankan file tersebut dengan cara:

- Klik kanan repair.inf
- Klik Install

[Version]
Signature="$Chicago$"
Provider=Vaksincom Oyee

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"

[del]
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer

Disable Cookie 3 methods for safer surfing

The role of cookie a lot of people know - cookie which maintains our record of websites visited, so that people with ulterior motives to see if this information, the information they achieved the purpose of spying, and now for the cookie's attack a few, these black hands by downloading the network database method to download local computer cookie, including our view of information, background information on our server, our administrators and even our bank account passwords and so on.

There are a number of thefts use of social engineering, such as through the spy to steal your cookie number, etc. of your qq, so although you can appeal to come back, but inevitably you qq friends are being deleted, also have our own game account and password, this is a lot of people are very concerned, cookie landed on a record of such information, if we allow the evil manipulator abuses, who knows what the future would happen, although what the network is virtual, but looking at their hard earned equipment went to the pockets of others, you have any plans?

Many of them "safe", they insist spent a day cleaning up the computer in a timely manner ie the cache file, delete the cookie work. Have to admire the perseverance to do so every day, but it is a fact that is undeniable - a day to do so, too much trouble. So how simple but effective in preventing others using the cookie spying on us?

Disable the cookie can directly reach the above objectives. There are three ways for you choose:

1, IE Options Act

1, start IE;

2, in the "Tools" menu, click "Internet Options", open the "Internet Options" dialog box;

3, click the "Privacy" tab, move the slider on a higher level of privacy. If you move to the top is select "block all Cookie", then the system will block all sites Cookie, and the site can not read the computer has the Cookie;

4, click "OK" button.

Second, property law

 Of course, the above "IE Options Act," the author is in IE6 in the operation is complete, if you're using IE5, then at the "Internet Options" dialog box "Security" tab to set it in IE4 in different. The following "property law" to save the Cookie folder is set to "read only" attribute, which website will not be able to write to the Cookie information. The law applies to all versions of IE.

1 to start the "Windows Explorer";

2, find the Save Cookie folder. Use the Windows versions, save the Cookie folder is different. For example, in Windows XP, the folder is "C: Documents and Settings Username Cookies" folder; in Windows 98, is "C: WindowsCookies" folder;

3, right-click the folder, then click "Properties", open the folder Properties dialog box, select the "Read Only" check box, specify the file in this folder is read-only attribute, read-only means that the file can not be changed or accidentally deleted;

4, click "OK" button. Third, the registry law

"Property law" actually have some flaws that can be read by a computer site still has the Cookie. But there are some special Cookie not in the form of text files, but stored in memory. Type of Cookie is usually the user access to certain special Web site, the system automatically generates in memory, once the visitors leave the site then automatically deleted from memory Cookie. Cookie of the two methods would do nothing to help those through QQ love (http://www.qqai.net) introduced the "Registry" system can make up for these deficiencies.

 1, click the "Start" menu, then click "Run", then "Open" box, type "regedit", click "OK" button, open the "Registry Editor" window;

2, expand "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsCacheSpecial PathsCookies" branch, right-click "Cookies", then click on the shortcut menu, "delete" command, when prompted to confirm the deletion, click "Yes" button;

3, close the "Registry Editor" window.

In order to prevent some site will Cookie files on your computer, in addition to manually set up as described above, there is a simple method is to install software to protect your Cookie files. More of such software, you can go to the major software download site to download. For example, Complete Cleanup Software Trail is a Cookie is specifically designed to remove all kinds of software, it is very powerful, not only allows the saved in the computer Cookie nowhere to hide, users can also browse web pages stored in the hard disk cache of spam removal.



 

=======================================================================================