<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Welcome To REAGEN blog's</title>
	<atom:link href="http://reagen.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://reagen.wordpress.com</link>
	<description>Trada yang tra mungkin to!!!!!</description>
	<lastBuildDate>Tue, 05 Feb 2008 07:27:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='reagen.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Welcome To REAGEN blog's</title>
		<link>http://reagen.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://reagen.wordpress.com/osd.xml" title="Welcome To REAGEN blog&#039;s" />
	<atom:link rel='hub' href='http://reagen.wordpress.com/?pushpress=hub'/>
		<item>
		<title>How To Handling Malware [3]</title>
		<link>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-3/</link>
		<comments>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-3/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 07:27:28 +0000</pubDate>
		<dc:creator>reagen</dc:creator>
				<category><![CDATA[Tips dan Trik]]></category>

		<guid isPermaLink="false">http://reagen.wordpress.com/?p=6</guid>
		<description><![CDATA[Hawdi????!!!! heheheh moga-moga aja ga bosen-bosen neeh dengar celotehan na gw di topic yang gw buat sendiri!!!!!!&#8230;. gini cerita kali ini&#8230;&#8230;&#8230; pasti rekan-rekan sekalian pernah nemuin kasus dimana ada file-file yang ber-ekstensi kan .EXE dan ber-Icon FOLDER&#8230;.. yang mana ANTIVIRUS membaca na sebagai : W32/wbworm.mxs w32/lightmoon.gen5 w32/vbworm.mxd w32/vbworm.mxr w32/malware.bhkq nah virus ini mempunyai gejala dimana [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=6&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span class="postbody">Hawdi????!!!!</p>
<p>heheheh moga-moga aja ga bosen-bosen neeh dengar celotehan na gw di topic yang gw buat sendiri!!!!!!&#8230;.<br />
gini cerita kali ini&#8230;&#8230;&#8230;<br />
pasti rekan-rekan sekalian pernah nemuin kasus dimana ada file-file yang ber-ekstensi kan .EXE dan ber-Icon FOLDER&#8230;.. yang mana ANTIVIRUS membaca na sebagai : </span></p>
<p><font color="#ff0000">W32/wbworm.mxs<br />
w32/lightmoon.gen5<br />
w32/vbworm.mxd<br />
w32/vbworm.mxr<br />
w32/malware.bhkq </font></p>
<p><span class="postbody"> nah virus ini mempunyai gejala dimana setiap PC dalam keadaan aktif akan selalu menjalan pertahanan pada:  </span></p>
<p><font color="#ff0000">C:\windows\jpv2w5k\oro86s6l.com</font></p>
<p><span class="postbody"> ato juga file tersebut akan menjalan file-file yang berada pada:  </span></p>
<p><font color="#ff0000">C:\windows\jpv2w5k</font></p>
<p><span class="postbody"> ato lain na seperti:<br />
</span></p>
<p><font color="#ff0000">services.exe<br />
smss.exe<br />
system.exe<br />
winlogon.exe<br />
lsass.exe</font></p>
<p><span class="postbody"> puji TUHAN untuk semua AV updatean terbaru sudah dapat mendeteksi varian tersebut&#8230;&#8230;<br />
nah namun akan  menjadi MISSPOSTING jika gw ga beri manualisasi na didalam topic ini&#8230;..<br />
lo pade bisa bikin lagi sebuah file BALIKIN.inf dengan source na kira-kira seperti ini:  </span></p>
<p><font color="#0000ff">[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=yooogy<br />
[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del<br />
[UnhookRegKey]<br />
HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;<br />
HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;<br />
HKCU, Software\Microsoft\Internet Explorer\Main, Start Page,0, &#8220;about:blank&#8221;<br />
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SOFTWARE\Classes\exefile,,,application<br />
[del]<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr<br />
HKLM,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoRecentDocsMenu<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoSetFolders<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoRun<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFind<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoTrayContextMenu<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoViewContextMenu<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,ShowSuperHidden<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegistryEditor.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe<br />
HKLM, SOFTWARE\Classes\exefile, NeverShowExt<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoPrinters<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoThemesTab<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system,NoDispAppearancePage<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system,NoDispScrSavPage<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system,NoDispSettingsPage<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,ClassicShell<br />
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoThemesTab<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoInstrumentation<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoPrinters<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoSetTaskbar<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoSMHelp<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoStartMenuMorePrograms<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoThemesTabNoThemesTab<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoTrayContextMenu<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoUserNameInStartMenu<br />
HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoClose<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoClose<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,HideClock<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,HideClock<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,NoDispAppearancePage<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,NoDispScrSavPage<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,NoDispSettingsPage<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,ClassicShell<br />
HKLM,SOFTWARE\Policies\Microsoft\Windows\Installer, DisableMSI<br />
HKLM,SOFTWARE\Policies\Microsoft\Windows\Installer,LimitSystemRestoreCheckpointing<br />
HKCU, Software\Microsoft\Internet Explorer\Main, Window Title<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, NoDiskCpl<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDesktop<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp, Disabled<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop<br />
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoSaveSettings<br />
HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer,NoControlPanel </font></p>
<p><span class="postbody"> setelah jadi lo hanya perlu klik kanan pada file BALIKIN.inf lalu klik INSTALL  </span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/reagen.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/reagen.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reagen.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reagen.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reagen.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=6&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/128b4c3fc875be6d9496c961bdf7fa52?s=96&#38;d=identicon" medium="image">
			<media:title type="html">reagen</media:title>
		</media:content>
	</item>
		<item>
		<title></title>
		<link>http://reagen.wordpress.com/2008/02/05/5/</link>
		<comments>http://reagen.wordpress.com/2008/02/05/5/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 07:22:21 +0000</pubDate>
		<dc:creator>reagen</dc:creator>
				<category><![CDATA[Tips dan Trik]]></category>

		<guid isPermaLink="false">http://reagen.wordpress.com/2008/02/05/5/</guid>
		<description><![CDATA[antivirus MC.AFFE gw pernah ngedetec sebuah VIRUS namun tidak dapat di delete ato di clean&#8230;..sedangkan Proccess XP dah gw pake namun alhasil na = NULL&#8230;data sebagai berikut: Filename : C:\windows\system32\cnpmmn.dll Malware : Win32:Agent-OUX [Trj] Malwaretype : Trojan Horse atas bantuan beberapa teman gw akhir na gw nemu cara na gw pake aja KILLBOX lalu gw [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=5&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span class="postbody">antivirus MC.AFFE gw pernah ngedetec sebuah VIRUS namun tidak dapat di delete ato di clean&#8230;..sedangkan Proccess XP dah gw pake namun alhasil na = NULL&#8230;data sebagai berikut: </span></p>
<p><font color="#ff0000">Filename : C:\windows\system32\cnpmmn.dll<br />
Malware : Win32:Agent-OUX [Trj]<br />
Malwaretype : Trojan Horse </font></p>
<p><span class="postbody"> atas bantuan beberapa teman gw akhir na gw nemu cara na</p>
<p>gw pake aja <a href="http://killbox.net/downloads/KillBox.exe." target="_blank" class="postlink">KILLBOX</a> lalu gw masukin file yang akan dihapus  </span></p>
<p><font color="#ff0000">C:\windows\system32\cnpmmn.dll. </font></p>
<p><span class="postbody"> trus saya pilih di delete setelah restart&#8230;.<br />
alhasil na file tersebut sudah terdelete sebelum masuk ke dalam system windows&#8230;&#8230;&#8230;&#8230;.</p>
<p>Mudah-mudahan aja membantu buat teman-teman semua yang tidak sengaja menemukan kasus yang serupa ma kasus GW  </span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/reagen.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/reagen.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reagen.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reagen.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reagen.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=5&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reagen.wordpress.com/2008/02/05/5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/128b4c3fc875be6d9496c961bdf7fa52?s=96&#38;d=identicon" medium="image">
			<media:title type="html">reagen</media:title>
		</media:content>
	</item>
		<item>
		<title>How To Handling Malware [2]</title>
		<link>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-2/</link>
		<comments>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-2/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 07:16:17 +0000</pubDate>
		<dc:creator>reagen</dc:creator>
				<category><![CDATA[Tips dan Trik]]></category>

		<guid isPermaLink="false">http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-2/</guid>
		<description><![CDATA[ups gw balik lagi&#8230;.. crita na skarang gw ketemu virus yang super gila&#8230;..cerita nah dia dah matikan semua extensi file yang berhubungan dengan mengganggunnya proses hidup VIRUS tersebut [.BAT, .INF,etc]&#8230;&#8230;.. cara kerja nya simple aja mereka matiin dos,notepad,regedit,msconfig,MS.Word,etc&#8230;&#8230;..cara matiin na virus tersebut hanya meng-FORWARD program-program diatas ke program laen seperti SOLITAIRE,WINAMP,etc [tergantung kemauan si maker [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=4&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span class="postbody">ups gw balik lagi&#8230;..<br />
crita na skarang gw ketemu virus yang super gila&#8230;..cerita nah dia dah matikan semua extensi file yang berhubungan dengan mengganggunnya proses hidup VIRUS tersebut [.BAT, .INF,etc]&#8230;&#8230;..<br />
cara kerja nya simple aja mereka matiin dos,notepad,regedit,msconfig,MS.Word,etc&#8230;&#8230;..cara matiin na virus tersebut hanya meng-FORWARD program-program diatas ke program laen seperti SOLITAIRE,WINAMP,etc [tergantung kemauan si maker VIRI na]<br />
otomatis file BALIKIN.INF yang gw bikin ga bisa di buka donk!!!!nah disini gw mulai berkreasi lagi&#8230;.. selaen PROCCESSXP gw pake juga tools pengganti REGEDIT nama na <a href="http://www.safer-networking.org/files/regalyz.exe" target="_blank" class="postlink">RegAlizer</a><br />
tapi proses penginstalan tools ini gw lakukan di SAFE MODE&#8230;.gimana masuk na?[dah ada di awal topic ini brur!!!!] <img src="http://www.yogyafree.net/forum2/images/smiles/icon_razz.gif" alt="Razz" border="0" /><br />
nah setelah terinstall gw masuk ke dalam KEY ini: </span></p>
<p><font color="#0000ff">HKEY_CLASSES_ROOT\inffile\shell\Install\command<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\shell\Install\command</font></p>
<p><span class="postbody"> trus settingan default di dalam key tersebut gw ganti dengan:  </span></p>
<p><font color="#ff0000">C:\Windows\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1</font></p>
<p><span class="postbody"> klo SO ente menggunakan WINDOWS NT/2000/2003 ente ganti dengan:  </span></p>
<p><font color="#ff0000">C:\Winnt\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1</font></p>
<p><span class="postbody"> nah sampe disini berarti file BALIKIN.inf gw dah berfungsi&#8230;..so gw udah lakukan sedikit modifikasi source BALIKIN.inf, kira-kira gini bentuk source na:  </span></p>
<p><font color="#0000ff">[Version]<br />
Signature=&#8221;$Chicago$&#8221;<br />
Provider=yooogy<br />
[DefaultInstall]<br />
AddReg=UnhookRegKey<br />
DelReg=del<br />
[UnhookRegKey]<br />
HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;<br />
HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;<br />
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;<br />
HKLM, SOFTWARE\Classes\exefile\DefaultIcon,,,&#8221;%1&#8243;<br />
HKLM, SOFTWARE\Classes\VBSFile,,,&#8221;VBScript Script file&#8221;<br />
HKLM, SOFTWARE\Classes\VBSFile\DefaultIcon,,,&#8221;C:\WIndows\System32\WScript.exe,2&#8243;<br />
HKLM, SOFTWARE\Classes\VBSFile\Shell\Edit\Command,,,&#8221;C:\WIndows\system32\notepad.exe %1&#8243;<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,UncheckedValue,0&#215;00010001,1<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,CheckedValue,0&#215;00010001,0<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,DefaultValue,0&#215;00010001,0<br />
HKLM, SOFTWARE\Classes\VBSFile, FriendlyTypeName,0,&#8221;@C:\Windows\System32\wshext.dll,-4802&#8243;<br />
[del]<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Adobe<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDesktop<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFileAssociate<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderoptions<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoRun<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableCMD<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr<br />
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system, DisableTaskmgr<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TaskMgr.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe, Debugger<br />
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe, Debugger<br />
HKLM, SOFTWARE\Classes\VBSFile, NeverShowExt</font></p>
<p><span class="postbody"> trus gw klik kanan di BALIKIN.INF n klik INSTALL<br />
lalu gw restart tuh PC&#8230;..nah sampe disini gw blom puas soal ne so pasti ada file yang dah ke Infeksi disembunyiin&#8230;<br />
gw masuk ke DOS [RUN-CMD] trus gw ketik:  </span></p>
<p><font color="#ff0000">attrib -s -h /s /d</font></p>
<p><span class="postbody"> n gw cek setiap drive yang ada file autorun.exe na gw delete</p>
<p>oh iya gw lupa&#8230;..sebelum melakukan proses install <a href="http://www.safer-networking.org/files/regalyz.exe" target="_blank" class="postlink">RegAlizer</a> gw pake PROCCESSXP buat nge-KILL file wscript.exe yang aktif di memory!!!</p>
<p>soo&#8230;&#8230;untuk sementara gw rasa PC gw agak sedikit aman!!!!!!  </span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/reagen.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/reagen.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reagen.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reagen.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reagen.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=4&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/128b4c3fc875be6d9496c961bdf7fa52?s=96&#38;d=identicon" medium="image">
			<media:title type="html">reagen</media:title>
		</media:content>

		<media:content url="http://www.yogyafree.net/forum2/images/smiles/icon_razz.gif" medium="image">
			<media:title type="html">Razz</media:title>
		</media:content>
	</item>
		<item>
		<title>How To Handling Malware [1]</title>
		<link>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-1/</link>
		<comments>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-1/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 07:01:51 +0000</pubDate>
		<dc:creator>reagen</dc:creator>
				<category><![CDATA[Tips dan Trik]]></category>

		<guid isPermaLink="false">http://reagen.wordpress.com/?p=3</guid>
		<description><![CDATA[gw puna cara yang agak sedikit membosankan, berawal saat gw kena sebuah virus yang mematikan sistem restore dan save mode 1. gw download ProcessXP untuk mematikan semua proses virus seperti: - smss.exe - services.exe - winlogon.exe biar ga salah ngapus proses gw cari yang bericon FOLDER trus gw kill 2. gw restart komputer, trus gw [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=3&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span class="postbody">gw puna cara yang agak sedikit membosankan, berawal saat gw kena sebuah virus yang mematikan sistem restore dan save mode</span></p>
<p>1. gw download <a href="http://www.sysinternals.com/Utilities/ProcessExplorer.html" target="_blank" class="postlink">ProcessXP</a> untuk mematikan semua proses virus seperti:<br />
- smss.exe<br />
- services.exe<br />
- winlogon.exe<br />
biar ga salah ngapus proses gw cari yang bericon FOLDER trus gw kill<br />
2. gw restart komputer, trus gw masuk ke &#8220;safe mode with command prompt”, dengan cara menekan tombol [F8] ketika komputer restart, hal ini dimaksudkan agar virus tidak aktif pada posisi ”safe mode” dan komputer tidak melakukan restart selama proses pembersihan.</p>
<p>3. Setelah masuk mode ”Command Prompt” gw tekan tombol [CTRL] + [ALT] + [Del] secara bersamaan, kemudian gw pilih [Task Manager], setelah layar Task Manager muncul, gw klik menu [File] pilih [New Task (Run..), kemudian gw ketik [explorer] pada jendela [create new task file] setelah itu gw klik enter.<br />
Kemudian akan muncul layar desktop (layaknya masuk ke mode &#8220;safe mode&#8221;)<br />
nah sampe proses ini aja gw dah bahagia banget soalna gw udah berhasil masuk mode SAFE MODE&#8230;..<br />
but bukan disini perjuangan gw&#8230;.tentu na semua file/folder masih ter hidden&#8230;..ya udah gw u restart PC n ulangi proses awal tadi trus gw tampilkan semua file/folder yang terhidden di folder option biar gw gampang melakukan manualisasi gw bikin file sendiri pake NOTEPAD dengan nama Balikin.inf yang kira-kira source seperti ini:</p>
<p><font color="#0000ff">[Version] Signature=&#8221;$Chicago$&#8221; Provider=yooogy [DefaultInstall] AddReg=UnhookRegKey DelReg=del [UnhookRegKey] HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221; HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221; [del] HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions</font></p>
<pre></pre>
<p><span class="postbody"> nah setelah itu pada file Balikin.inf gw klik kanan n then gw klik INSTALL</span></p>
<p>Bimsalabim gw dah bisa masuk ke REGEDIT, MSCONFIG, GPEDIT, CMD,etc&#8230;&#8230;</p>
<p>disini lah pekerjaan membosankan coz gw kudu masuk satu persatu ke dalam setiap key yang kira-kira emang di serang sama si VIRUS na!!!!</p>
<p>pertama-tama banget gw masuk kedalam key</p>
<p><font color="#0000ff">HKCU, Software\Microsoft\Windows\CurrentVersion\Run HKLM,</font><font color="#0000ff">SOFTWARE\Microsoft\Windows\CurrentVersion\Run</font><br />
<span class="postbody"> soal na disini neeh biasa nah Virus dapat bertahan hidup&#8230;.gw liat key/value yang aneh-aneh trus gw delete&#8230;..</span></p>
<p>sampe disini aja gw masih ragu so gw masuk kedalam</p>
<p><font color="#0000ff">C:\Windows  C:\windows\system32</font></p>
<p><font color="#0000ff">  C:\windows\ShellNew  </font></p>
<p><font color="#0000ff">C:\Documents and Settings\%user%\Local Settings\Application Data</font></p>
<p><span class="postbody"> trus gw liat ada ga seeh yang ter hidden disitu dengan nama yang rada aneh!!!!! if visible.true then delete&#8230;&#8230;.ixixiixixixix kira-kira geto bahasa dalam VB [hasil ngintip share di topic sebelah hehehhehehehhe]</span></p>
<p>sampe disini gw rasa udah beres namun untuk lebih mantab gw edit file AUTOEXEC.bat di [path]C:<br />
gw hapus tuh command pause</p>
<p>trus satu hal lagi yang gw mesti lakukan adalah proses TAsk Schedule, coz tiap virus memiliki jadwal yang beda-beda!!!so gw masuk ke scheduled tasks lewat START-SETTING-CONTROL PANNEL<br />
lalu gw delete semua scheduled yang di buat oleh virus tersebut!!!!!</p>
<p>taraaaaaaaaatttt&#8230;&#8230;untuk sementar gw SAVE dari marah bahaya virus itu!!!!hehehheheheheh</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/reagen.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/reagen.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reagen.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reagen.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reagen.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=3&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reagen.wordpress.com/2008/02/05/how-to-handling-malware-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/128b4c3fc875be6d9496c961bdf7fa52?s=96&#38;d=identicon" medium="image">
			<media:title type="html">reagen</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome</title>
		<link>http://reagen.wordpress.com/2008/02/05/hello-world/</link>
		<comments>http://reagen.wordpress.com/2008/02/05/hello-world/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 04:57:52 +0000</pubDate>
		<dc:creator>reagen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Selamat datang di blog nya saya&#8230; Oleh karena saya merupakan salah satu orang dari sekian banyak orang yang menyukai dunia teknik informasi, maka dalam blog ini kebanyakan berisi tentang seluk beluk dunia teknik informasi&#8230;. Tetapi sebagai seorang manusia juga, bukan berarti saya hanya monoton pada satu bidang saja&#8230;.di sini saya juga menulis tentang sisi-sisi kehidupan [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=1&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Selamat datang di blog nya saya&#8230;</p>
<p>Oleh karena saya merupakan salah satu orang dari sekian banyak orang yang menyukai dunia teknik informasi, maka dalam blog ini kebanyakan berisi tentang seluk beluk dunia teknik informasi&#8230;.</p>
<p>Tetapi sebagai seorang manusia juga, bukan berarti saya hanya monoton pada satu bidang saja&#8230;.di sini saya juga menulis tentang sisi-sisi kehidupan manusia&#8230;&#8230;</p>
<p>Mudah-mudahan saja blog ini dapat berguna bagi sahabat blogger/netter sekalean!!!!</p>
<p>BRAVO</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/reagen.wordpress.com/1/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/reagen.wordpress.com/1/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reagen.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reagen.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reagen.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reagen.wordpress.com&amp;blog=2750286&amp;post=1&amp;subd=reagen&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reagen.wordpress.com/2008/02/05/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/128b4c3fc875be6d9496c961bdf7fa52?s=96&#38;d=identicon" medium="image">
			<media:title type="html">reagen</media:title>
		</media:content>
	</item>
	</channel>
</rss>
