SIOLOON FUN CLUB
Please log in or register before viewing the unlimited contents of this forum.
Thank you for visiting our website.

by aLFFiaN.
awas!! virus bro act!! Facebo10
SIOLOON FC on Facebook
LIKE or UNLIKE
SIOLOON FUN CLUB
Please log in or register before viewing the unlimited contents of this forum.
Thank you for visiting our website.

by aLFFiaN.
awas!! virus bro act!! Facebo10
SIOLOON FC on Facebook
LIKE or UNLIKE
SIOLOON FUN CLUB
Would you like to react to this message? Create an account in a few clicks or log in to continue.

SIOLOON FUN CLUB

border=0
 
HomePortalGalleryLatest imagesSearchRegisterLog in

Share | 
 

 awas!! virus bro act!!

View previous topic View next topic Go down 
AuthorMessage
aLFFiaN
ADMINISTRATOR
ADMINISTRATOR
aLFFiaN

Male
Countries/State : Malaysia
Age : 41
location : Borneo Island
Website : www.sioloon.com
Tag ID: : SFC00001
Points : 15096
Reputation : 101
Number of posts : 7895

awas!! virus bro act!! Empty
PostSubject: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime18/6/2007, 8:08 pm

sesiapa yang kena virus ni , kalu nak cari penawar dia.. boleh pm kat aku.. InsyAllah aku akan bantu apa yang mampu

kesan daripada serangan virus ini pada pc anda
1. CMD tak boleh buka
2. folder option akan hilang
3. Regedit tak boleh nak buka
4. task manager tidak berfungsi
Back to top Go down
http://www.sioloon.com
Luis Garcia
SENIOR
SENIOR
Luis Garcia

Male
Age : 38
location : labuan/sandakan
Tag ID: : 128
Points : 12768
Reputation : 0
Number of posts : 536

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime21/6/2007, 7:32 am

geng mcm mn nk don lod anti bro nie.......
Back to top Go down
aLFFiaN
ADMINISTRATOR
ADMINISTRATOR
aLFFiaN

Male
Countries/State : Malaysia
Age : 41
location : Borneo Island
Website : www.sioloon.com
Tag ID: : SFC00001
Points : 15096
Reputation : 101
Number of posts : 7895

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime21/6/2007, 9:15 am

tiada takde nak download apa²pun... tapi ada cara untuk buat.. sebab dia ni serang bahagian registry ja.. banyak items dia bagi disable.. contohnya.. task manager dan folder option.. nama lain virus ni RVhost... dan dikategorikan sebagai warm!! kalu ko dah kena warm ni, pm aku nanti.. aku bagi tools dia ngan ko ,luis Garcia. ok?
Back to top Go down
http://www.sioloon.com
Luis Garcia
SENIOR
SENIOR
Luis Garcia

Male
Age : 38
location : labuan/sandakan
Tag ID: : 128
Points : 12768
Reputation : 0
Number of posts : 536

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime24/6/2007, 3:22 am

ok.... bro... i tell u ... thkz ar....
Back to top Go down
Taufik
JUNIOR
JUNIOR
Taufik

Male
Age : 36
location : Kunak, Sabah
Points : 12687
Reputation : 3
Number of posts : 179

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime5/9/2007, 10:42 am

banyak kali dah aku kena virus ni... janji korg paki latest Antivirus. update sellu... tpi bgi yg dah kena... byk dah cara remove virus ni. search jer kat google... melambak dorg bagi tips...


Last edited by on 24/9/2007, 3:43 pm; edited 1 time in total
Back to top Go down
Taufik
JUNIOR
JUNIOR
Taufik

Male
Age : 36
location : Kunak, Sabah
Points : 12687
Reputation : 3
Number of posts : 179

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime24/9/2007, 3:41 pm

sedikit info ttg virus ni..

Name: Yahoo Messengger
Filename: RVHOST.exe
Fix RVHOST.exe errors: Try a Registry Scan
Command: C:\Windows\System32\RVHOST.exe
Description: Added by the W32/SillyFDC-G floppy disk and network worm.
File Location: %System%
Startup Type: This startup entry is started automatically from a Run, RunOnce, RunServices, or RunServicesOnce entry in the registry.

- scan pc ko gan mana2 antivirus spt kaspersky/AVG
- pas2 bleh jga try download portable AV made malaysia d data0.net atau guna hijackthis

- buka notepad & copy text d bawah & paste d notepad.

[b][color=orange]On Error Resume Next
Set shl = CreateObject("WScript.Shell")
Set fso = CreateObject("scripting.FileSystemObject")
shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools"
shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr"
shl.RegDelete
[/color][/b]
- [color=yellow]save file dgn nama "Enable.VBS" & change type to "all".[/color]

- run>regedit>
ikut arahan selanjutnya...

In the left panel, double-click the following:
[color=orange]HKEY_CURRENT_USER>Software>Microsoft>
Windows>CurrentVersion>Run
[/color]In the right panel, locate and delete the entry:
[color=orange]Yahoo Messengger = "%System%\RVHOST.exe"
[/color](Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, and C:\Windows\System32 on Windows XP and Server 2003.)-->
Removing Other Entry from the Registry

Still in Registry Editor, in the left panel, double-click the following:
[color=orange]HKEY_CURRENT_USER>Software>Microsoft>Windows>
CurrentVersion>Policies>Explorer
In the right panel, locate and delete the entry:
NofolderOptions = "1"
Restoring Modified Entries from the Registry
[/color]
Still in Registry Editor, in the left panel, double-click the following:
[color=orange]HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>
CurrentVersion>Winlogon
In the right panel, locate the entry:
Shell = "Explorer.exe RVHOST.exe"
Right-click on the value name and choose Modify. Change the value data of this entry to:
Explorer.exe
[/color]In the right panel, double-click the following:
[color=orange]HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
Services>Schedule
In the right panel, locate the entry:
NextAtJobId = "2"
Right-click on the value name and choose Modify. Change the value data of this entry to:
1
[/color]Close Registry Editor.
Deleting the Malware File(s)

Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
In the Named input box, type:
[color=orange]AT1.JOB
[/color]In the Look In drop-down list, select My Computer, then press Enter.
Once located, select the file then press [color=orange]SHIFT+DELETE[/color].
Note: AT1.JOB is a Sheduled Task so you can find this in C:\WINDOWS


hrp dpt mmbantu...
Back to top Go down
aLFFiaN
ADMINISTRATOR
ADMINISTRATOR
aLFFiaN

Male
Countries/State : Malaysia
Age : 41
location : Borneo Island
Website : www.sioloon.com
Tag ID: : SFC00001
Points : 15096
Reputation : 101
Number of posts : 7895

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime24/9/2007, 4:12 pm

memang info yg aku_pendiam bagi ni sangat berguna.. sebab aku pun guna teknik yg sama bila nak bersihkan virus ni...



p/s:cantik signature ko
Back to top Go down
http://www.sioloon.com
alangmada
FRESHIE
FRESHIE


Male
Countries/State : Terengganu
Age : 41
location : terengganu
Points : 12404
Reputation : 0
Number of posts : 3

awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime23/11/2007, 6:07 pm

guna jer lah penawar brontok, yg di buat oleh org johor nie, bagus lah juga, cuba klik pada link nie www.kaer-media.org
try lah
Back to top Go down
Sponsored content




awas!! virus bro act!! Empty
PostSubject: Re: awas!! virus bro act!!   awas!! virus bro act!! Icon_minitime

Back to top Go down
 

awas!! virus bro act!!

View previous topic View next topic Back to top 

 Similar topics

+
Page 1 of 1

Permissions in this forum:You cannot reply to topics in this forum
SIOLOON FUN CLUB :: ENTERTAINMENT :: COMPUTER ZONE-
Jump to: