It is currently Sun Dec 27, 2009 8:16 am

All times are UTC + 7 hours



Welcome
Welcome to LABORATS for TEKNIK ELEKTRO





 Page 1 of 1 [ 2 posts ] 
Author Message
 Post subject: Virus W32.Netsky.A
PostPosted: Tue Feb 12, 2008 9:07 am 
Tikus
User avatar

Joined: Tue Jan 01, 2008 11:19 am
Posts: 317
Location: Manado, Sulawesi Utara
Critanya, ane dpt Adobe Audition 3 [2007]...CD bajakan tentunya :lol: :lol:
nah, keygen yg include di CDnya tu terdetect sebagai trojan [symantec endpoint protection]..
Alhasil, ane nyari2 keygen laen via web browser...
Nemu...ane dunlut..eh, ada trojane juga :? :? wah..parah...

Gak putus asa..nyari di P2P [.torrent]..
Nemu buanyak..malah program2 baru udah ada juga [ex:corel draw X4]..
huwaaa..pengen juga

Ane dunlut tu keygen buat Adobe Audition 3..
Lambat bgt.. cm dpt 4-6 kbps..asem.. padahal Peer-nya ada 29

Paz selesai, ane buka tu *.zip...
asem...self extract ke %temp%...

Ane cari + bunuh semua exe di %temp% pake perintah
del %temp%\*.exe /f /s /q


Ane scan system... tuh zip udh terquarantine... qrain dah beyes :lol: :lol:
Liat proses ama service yg jalan pake Process Explorer ..kagak ada yg mencurigakan..
Alhasil..ane restart tu kompi..

Pas load...
kaget... di desktop jadi ada 3 aplikasi baru...
system tray muncul ikon silang (bahaya) warna merah ama putih..
active aplication juga blink2..3x bergantian... 8)
ada peringatan [frame box] ....
Quote:
Your computer infected by trojan or viruses...
click here to download latest update spyware and adware remover
Virus detected : W32.Netsky.A
[OK] [Cancel]


Wah..asem, ane cari processnya...
nemu 4 process baru, yaitu 2 buah BHO [browser helper object] unknown.. (beda nama)
ama 2 buah DLL di %systemroot%\system32..

Gak bisa di kill.. :shock: :shock: :shock:
di scan pake PCMAV RC24 + Clamav.db tetep gak kedetect..
di scan pake Symantec End Point Protection juga gak detect.. [updatean 4 February 2008]

Lg malez perang ma virus + ngantux.. juruz utama di keluarin... :twisted: :twisted:
Restore pake Norton Ghost boot CD... nunggu 10 mnitan...
beyes dah..

Sekedar sharing barangkali ada yg mengalami masalah serupa..



_________________
..Indonesia Timur.. Here I come..
Offline
 Profile  
 
 Post subject:
PostPosted: Sat Mar 08, 2008 11:20 am 

Joined: Tue Jan 08, 2008 7:34 am
Posts: 2
klo aq kena w32.virut mas




ngeselno





mosok exe keserang kabeh...


Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 2 posts ] 

All times are UTC + 7 hours


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

cron