//inmobi ads MUDAH ITU BERKAH DAN INDAH : bulubebek virus tai kuku

Rabu, 10 Juni 2009

bulubebek virus tai kuku

1minggu yg lalu saya disibukan dengan virus bulu bebek tidak mengganggu sih ni virus tapi penasaran juga setelah tanya2 sama mas google bisa juga dihilangin tp jadi masalah adalah faile program g bisa dijalanin
untung dah pengalaman pas ngilangi virus autorun repair.cmd

buat ngerepairnya gampang
tulis scripts dibawah dg notepad dan simpan dg nama ant.vbs


Dim oWSH: Set oWSH = CreateObject("WScript.Shell")
on error resume Next
oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell \open\command\","""%1"" %*"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell \open\command\","""%1"" %*"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell \open\command\","""%1"" %*"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell \open\command\","""%1"" %*"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\S afeBoot\AlternateShell","cmd.exe"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\S afeBoot\AlternateShell","cmd.exe"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contr ol\SafeBoot\AlternateShell","cmd.exe"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell","Explorer.exe"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Shell \Edit\Command\","C:\Windows\System32\notepad.exe %1"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Defau ltIcon\","C:\Windows\System32\WScript.exe,2"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\shell \Install\command\","C:\windows\System32\rundll32.e xe setupapi,InstallHinfSection DefaultInstall 132 %1"
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Explorer\NoFind ")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Explorer\NoFold erOptions")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Explorer\NoRun" )
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Explorer\NoFile Associate")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Explorer\NoDriv es")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\DisableR egistriTools")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\DisableT askMgr")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\DisableC MD")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\DisableR egedit")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\RunLogon ScriptSync")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\HideLega cyLogonScripts")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\HideLogo ffScripts")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\HideStar tupScripts")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\System\RunStart upScriptSync")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\run\JeNGKoL")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Classe s\VBSFile\NeverShowExt")
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\","VB Script Script File"
oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Frien dlyTypeName","VBScript Script File"
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\System\Disable RegistriTools")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\System\Disable TaskMgr")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\System\Disable Regedit")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\System\RunLogo nScriptSync")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\System\EnableL UA")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\Explorer\NoFol derOptions")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\Explorer\NOFin d")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\Explorer\NORun ")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\Explorer\NoDri ves")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Micros oft\Windows\CurrentVersion\Policies\Explorer\NoDri veAutoRun")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows\CurrentVersion\policies\WinOldApp\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\command.com\")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\install.exe\debugger")
oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\Micros oft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\debugger")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\ActiveDesktop\" )
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\Associations\")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\explorer\Disall owRun\")
oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microso ft\Windows\CurrentVersion\Policies\explorer\Run\")

kemudian buat dg notepad juga script dg nama filenya oto.cmd



@echo off
echo.
reg del HKLM\Software\Classes\exefile\shell\open\command /ve /d %%fe340ead%% /f
echo.
shutdown.exe -s -c "sedang diperbaiki mas" -f -t 10
echo.
exit

Tidak ada komentar:

Posting Komentar

silahkan komentar