It is currently Sun Dec 27, 2009 8:16 am

All times are UTC + 7 hours



Welcome
Welcome to LABORATS for TEKNIK ELEKTRO





 Page 1 of 1 [ 1 post ] 
Author Message
 Post subject: [Manual] Mengmbalikan efek virus Robbie.exe
PostPosted: Fri May 02, 2008 11:17 pm 
Tikus
User avatar

Joined: Tue Jan 01, 2008 11:19 am
Posts: 317
Location: Manado, Sulawesi Utara
Sebelumnya,salam kenal buat "RAINHEART REBEL REVOLUTION"
Ternyata ada yg bikin "virus-like" sperti Gutbai.exe
Mumpung nganggur, ane dunlut to virus dan mencoba menjalankannya.

BTW: Ane gak pake System Restore/Anti Virus apapun buat ngebalikin efek dari Robbie.exe
Cuman SAFE MODE aja... Sory klo kebanyakan gambar..

Alat dan Bahan :
1. VMWare Workstation 5.5
2. ISo Wind**ws XP SP2 VLK
3. Sedikit logika + Segelaz Wedang Jahe

Tahap 1
Extract file virus dari RAR

Jalanin tu virus
Image
Image
Image
Efeknya terlihat seperti gambar
Image

wah..sepertinya Command Prompt+registry didisabled (seperti biasanya virus lokal)
Langsung saja, ane reboot, pengen nge-etest SAFE MODE Command Prompt
Image

Login sebagai Administrator, jgn user paz kita jalanin tu virus, soalnya
user tsb udh di disable command prompt + registry-nya

Langsung perintah "explorer" untuk manggil explorer..ternyata bisa..
Image

Coba "dir" ke C: ..lha nemu Windows.exe + folder Windows jadi Hidden :)
Image
Image
Langsung rename Windows.exe jadi Windows.exe.txt :D

Coba cari autorun.inf ato folder autorun
Image
Lha nemu, langsung rename menjadi Setup.exe.txt juga autorun.inf jadi autorun.inf.txt
Image
Sekalian Rename folder autorun menjadi autorun-txt
Image

Cari kembaran Windows.exe maupun setup.exe di direktory windows..nah..ada Rebel.exe
Image
Cari lagi di System32 ach.. lho.. koq ada XP@SP4.exe yah..
Image

Jadi kembarannya (windows.exe,setup.exe,XP@SP4.exe ama rebel.exe)

Apa lagi ya.. Coba extensi *.com /*.pif /*.scr <-- biasanya virus
Metode cari sederhana, cari yg kembar di folder windows berikut subfoldernya...
Image
Setelah nemu, cukup di rename jadi dell.com.txt
Image

Jadi kembarannya (dell.com di Windows dan Windows/System32)

Test jalankan regedit
Image
Browse ke [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies]
Wadoh..banyak yg dirubah..
Image
Image
Image

Cek juga [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
Hapus aja key itu!
Image
Periksa [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
Hapus aja key itu!
Image
Periksa juga [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion]
Rubah dengan Registered Owner dan Organization defaultnya PC kamu..
Image
Cek [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer]
Hapus semua key-nya
Image

Nah, setelah ini buat user baru (untuk mendefaultkan settingan yg disabled)
pake perintah
"net user %userbaru% /add"
"net localgroup Administrator %userbaru% /add
Hapus username yg dipake buat jalanin tuh virus (misalkan name usernya BEJO)
"net user BEJO /delete"

Lalu restart, pake perintah "shutdown -r -f -t 00"
Setelah restart, masuk normal ke windows XP ente..

beberapa bagian masih belom normal..
buka registry..browse ke policies di hkcu
Image

Log off kemudian login lagi..
Udah deh balik normal lagi...
Image

Proses diatas memang agax ribet, tapi bisa jadi PROOF of CONCEPT bahwa ngembalikin
efek Robbie.exe gak harus pake SystemRestore (yg siapapun aja juga bisa)
Image

Maap klo ada kata2 yg salah.. :D Harap maklum masik blajar instal wind**s...
Pizzz...

©blackmarlincode 23:00 02/05/2008



_________________
..Indonesia Timur.. Here I come..
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 1 post ] 

All times are UTC + 7 hours


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

cron