Cara Remove W32.IMAUT.J (Virus YM yang ngirim thecoolpics.net)
by blueq@kaskus#14
1. download ini dulu (IE “save target as” atau Firefox “save link as”):
Cara Remove W32.IMAUT.J (Virus YM yang ngirim thecoolpics.net)
by blueq@kaskus#14
1. download ini dulu (IE “save target as” atau Firefox “save link as”):
http://securityresponse.symantec.com/av … okExec.inf
2. klik kanan di file yang barusan di donlot, pilih install (untuk kita bisa jalanin Regedit)
3. kemudian jalankan regedit32 dari folder system32 di windows, biasanya ada di C:\WINDOWS\SYSTEM32\ untuk XP
4. buka
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
atau
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
atau
HKey_Current_User\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
hapus yang (antara ini) DisableLocalMachineRun atau DisableLocalMachineRunOnce atau DisableCurrentUserRun atau DisableCurrentUserRunOnce atau noRun. dia bisa pake apa aja untuk disable RUN, kalo gak ada key nya dan run masih di disable, search for “noRun”
5. hapus juga
“DisableTaskMgr”
“DisableRegistryTools”
6. buka
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Hapus
“Task Manager” = “%Windir\system\svchost32.exe”
“SVCHOST” = “%Windir\system\svhost.exe”
7. buka
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
hapus
“Start Page” =”[http://]thecoolpics.com/[REMOVED]”
8. buka
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
hapus
“Homepage” = “1″
9. buka
HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_buzz dan HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_Launchcast
hapus
“content url” = “[http://]thecoolpics.com/[REMOVED]”
10. Restart, masuk ke safe mode
11. hapus file berikut
C:\WINDOWS\system32\svchost32.exe
C:\WINDOWS\system32\svhost.exe
(ini bukan file system, file system adalah svchost.exe dia niru)
12. Reputasi nya ya…..jgn lupa karna komputer uda bersih… he he he he he …
2. klik kanan di file yang barusan di donlot, pilih install (untuk kita bisa jalanin Regedit)
3. kemudian jalankan regedit32 dari folder system32 di windows, biasanya ada di C:\WINDOWS\SYSTEM32\ untuk XP
4. buka
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
atau
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
atau
HKey_Current_User\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
hapus yang (antara ini) DisableLocalMachineRun atau DisableLocalMachineRunOnce atau DisableCurrentUserRun atau DisableCurrentUserRunOnce atau noRun. dia bisa pake apa aja untuk disable RUN, kalo gak ada key nya dan run masih di disable, search for “noRun”
5. hapus juga
“DisableTaskMgr”
“DisableRegistryTools”
6. buka
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Hapus
“Task Manager” = “%Windir\system\svchost32.exe”
“SVCHOST” = “%Windir\system\svhost.exe”
7. buka
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
hapus
“Start Page” =”[http://]thecoolpics.com/[REMOVED]”
8. buka
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
hapus
“Homepage” = “1″
9. buka
HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_buzz dan HKEY_CURRENT_USER\Software\Yahoo\pager\View\YMSGR_Launchcast
hapus
“content url” = “[http://]thecoolpics.com/[REMOVED]”
10. Restart, masuk ke safe mode
11. hapus file berikut
C:\WINDOWS\system32\svchost32.exe
C:\WINDOWS\system32\svhost.exe
(ini bukan file system, file system adalah svchost.exe dia niru)
Post a Comment
Bannerad
Artikel Terpopuler
-
Despite that at the end of this post you will find a filtered and somehow manually edited list of Pligg-based social bookmarking sites, this...
-
2016-08-09 18:38:19.0 Guangzhou Int'l Parcel Center received 2016-08-09 18:38:25.0 Guangzhou Int'l Parcel Center customs scan 20...
-
It seems the method for us to use is far simpler than my initial impressions - we need only add two small sections of code to our templates ...
-
Disaat-saat tertentu untuk menghilangkan kejenuhan kadang kala entertain (kesenangan) harus kita upayakan, demikian pula ketika kita berkuta...
-
Last month we showed you some of the more popular and useful Adobe AIR applications (see " 6 Adobe AIR Apps to Check Out ...
-
PicPick is an all-in-one software for software developers, graphic designers and home user. It has an intuitive interface and simple, elega...
-
About the author henkhei is man in the mirror where you can find everywhere henkhei . he specializes in topics of interest to techno gee...
-
Twitter pages have their own google page rank too in Google, so it is important to do that 5 mins drill better utilize your Twitter page.Thi...
-
A tablet PC is a wireless, portable personal computer with a touch screen interface. The tablet form factor is typically smaller than ...
-
Bio-Linux is an ideal system for scientists handling and analysing biological data. Bio-Linux 6.0 is a fully featured, powerful, config...
Tags
Blogumulus by Roy Tanck and Amanda Fazani