Results 1 to 3 of 3
http://idgs.in/124466
  1. #1
    lee_hawk's Avatar
    Join Date
    Jan 2007
    Location
    Indonesia
    Posts
    1,341
    Points
    1,521.20
    Thanks: 2 / 10 / 6

    Default help virus undetected

    gini jdna
    virusna
    bikin gw ga bisa buka administrative tools / command prompt / windows task manager
    jd wkt gw buka cmd
    tulisanya has been disabled by administrator
    trus klo buka administrative tools
    semuanya langsung ke close dlm 1 dtik
    smua gr2 flash disk
    help plz
    ga ngerti gw

  2. Hot Ad
  3. #2
    AiOn's Avatar
    Join Date
    Mar 2007
    Location
    Pandemonium.
    Posts
    4,845
    Points
    5,161.98
    Thanks: 3 / 30 / 25

    Default

    Sudah coba didetect pake apa aja?

    Isa akses regedit? Coba ke HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System, kl di situ ada key "DisableTaskMgr" ubah valuenya jadi 0.

    Aslinya sich key ini gda. .
    Destiny by sinner sought, Tragedy by power wrought.
    AiOn's OP Thread

  4. #3
    the_omicron's Avatar
    Join Date
    Oct 2006
    Location
    di Cinere say........... Ongoing Novel: S|L|M
    Posts
    3,908
    Points
    13,246.30
    Thanks: 6 / 116 / 69

    Default

    coba kopas code berikut ini ke notepad, setelah itu save as sebagai all type lalu tulis repair.inf sebagai nama file, klik kanan lalu install, dan voila, selesai d masalah disable2an, tp virusnya harus tetep diapus loh.. jgn lupa..


    Code:
    [Version]
    Signature="$Chicago$"
    Provider=Vaksincom
    
    [DefaultInstall]
    AddReg=UnhookRegKey
    DelReg=del
    
    [UnhookRegKey]
    HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
    HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
    HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
    HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
    HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
    HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
    HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
    HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"
    HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"
    HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1
    
    
    
    [del]
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
    HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
    HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NOFind
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NORun
    HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe, debugger
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegistryEditor.exe
    HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe, debugger

    credits to vaksin.com


    Click To Read Sweet~.

    Mari Menulis Disini

    Quote Originally Posted by dono View Post
    Dilihat dari system server kami, dikarenakan sudah lebih dari 2000 pages kami mengambil keputusan untuk menutup thread in, karena menyebabkan ada nya keberatan dari server forum sendiri. Mohon maap dan terimakasih.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •