<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-87537835582802971</id><updated>2011-04-22T05:49:48.592+08:00</updated><title type='text'>Just A Litle Part</title><subtitle type='html'>Welcome in my blog.. it just some part of this wide world...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>42</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-8517075626412783385</id><published>2009-05-05T19:27:00.001+08:00</published><updated>2009-05-05T19:27:50.718+08:00</updated><title type='text'>Mega Test 5 Tools Conficker Network Detection</title><content type='html'>&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt; &lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style=""&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 8pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;Seiring dengan maraknya Swine Flu (Flu Babi) yang menyerang manusia dan menurut WHO sudah pada taraf kegentingan 4, bandara di seluruh dunia langsung bersiaga memantau para penumpang dari Meksiko dan Amerika Serikat. Kalau di dunia komputer yang menjadi sumber penyebaran virus adalah file yang terinfeksi virus, maka di dunia nyata, yang terinfeksi virus dan menjadi sarana penyebaran virus adalah manusia. Karena itu bandara menerapkan scanning atas penumpang yang dicurigai mengidap flu dengan menggunakan scanner suhu tubuh karena pengidap flu (apapun jenisnya) pasti mengalami peningkatan suhu tubuh karena badannya bereaksi atas adanya virus asing yang masuk. Sebenarnya prinsip di dunia komputer juga sama, kalau bandara menggunakan scanner suhu tubuh maka “bandara” di internet adalah router-router dan aplikasi yang digunakan bukan scanner tubuh manusia melainkan Firewall. Tetapi ada satu keunggulan yang dimiliki oleh dunia IT dibandingkan dunia manusia (jika dibandingkan) saat ini, dimana pada dunia manusia tidak mungkin (sangat sulit dan mahal) untuk dapat memantau seluruh manusia di satu kota dan menentukan siapa saja yang terinfeksi flu. Kalau di dunia IT kita bisa menggunakan scanner khusus untuk mendeteksi komputer mana saja yang terinfeksi virus sehingga dapat dilakukan antisipasi yang cepat dan efektif untuk menghadapi masalah virus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Setelah melakukan test terhadap beberapa tools untuk membasmi Conficker, &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;langkah berikutnya yang paling krusial jika anda administrator jaringan adalah mengidentifikasi komputer mana saja yang terinfeksi virus dan berusaha menyebarkan virus. Karena itu, Vaksincom &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;melakukan pengetesan terhadap tools &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;untuk mendeteksi &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;komputer &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;di jaringan &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;yang terinfeksi Conficker dan berusaha melakukan penyebaran terhadap komputer dalam jaringan. Jika kita hanya melakukan pembersihan terhadap satu komputer saja tentu tidak masalah, tetapi bagaimana jika dalam jaringan anda terinfeksi komputer tetapi anda tidak tahu komputer mana yang terinfeksi&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;, karena terkadang komputer yang menginfeksi jaringan kita tidak terduga-duga, misalnya komputer notebook yang sering dibawa pulang oleh pimpinan atau bagian yang sering dinas luar. Selain itu, jika kita memvonis komputer tertentu terinfeksi virus, tentunya kita harus memiliki bukti.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Conficker dan gejala (dalam jaringan....)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Jika pada mega test sebelumnya dijelaskan gejala conficker pada komputer tsb, &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;maka kali ini kita harus mengatahui apa dampak conficker pada jaringan, sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Berusaha mendownload dan mencoba akses pada 250 domain (conficker B) atau 50&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;000 domain (conficker C) yang random. Berikut beberapa domain yang random tsb :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;aaidhe.net&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;barhkuuu.cn&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;cfhlglxofyz.biz&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;dtosuhc.org&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;elivvks.info&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;fsrljjeemkr.cc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;gbmkghqcqy.ch&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;hudphigb.net&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;iqrzamxo.ws&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin-left: 36.85pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;jjhajbfcdmk.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 36.75pt; text-align: justify;"&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;dst.................&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 36.75pt; text-align: justify; text-indent: -17.25pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Berusaha akses ke beberapa domain yang umum untuk mengecek waktu saat ini. Beberapa domain tsb yaitu :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 36.75pt; text-align: justify; text-indent: -17.25pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;baidu.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;google.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;yahoo.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;msn.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;ask.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;w3.org&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;aol.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;cnn.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;ebay.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;msn.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;myspace.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;facebook.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoBodyText" style="margin: 2.85pt 0in 0.0001pt 0.5in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;rapidshare.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Pada dasarnya virus ini berusaha melakukan penyebaran melalu&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;i&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt; default share windows menggunakan port 445, tetapi selain itu Conficker juga menggunakan port 1024 s/d 10000 untuk melakukan penyebaran pada jaringan komputer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;The Tools, Conficker Network Detection...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Dari beberapa tools yang ada, &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Vaksincom &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;me&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;lakukan pengetesan&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt; beberapa tools yang familiar dan sering digunakan. Tools tsb dikeluarkan oleh beberapa vendor security untuk membantu mempermudah deteksi dari serangan Conficker pada jaringan anda.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Berikut beberapa tools yang tersedia sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style=""&gt;1)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Wireshark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Wireshark/Ethereal merupakan salah satu dari sekian banyak &lt;em&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;tools &lt;/span&gt;&lt;/em&gt;Network Analyzer yang banyak digunakan oleh Network administrator untuk menganalisa kinerja jaringannya&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; dan juga merupakan tools andalan Vaksinis (teknisi Vaksincom)&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;. Wireshark banyak disukai karena interfacenya yang menggunakan Graphical User Interface (GUI) atau tampilan grafis. Wireshark mampu menangkap paket-paket data/informasi yang berseliweran dalam jaringan yang kita “intip”. Semua jenis paket informasi dalam berbagai format protokol pun akan dengan mudah ditangkap dan dianalisa. Tools ini tersedia di berbagai versi OS, seperti Windows, Linux, Macintos&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;h&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;, dll.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Pada awal kemunculan dan perkembangan Conficker, tools ini merupakan “pelopor” tools yang digunakan oleh beberapa vendor security untuk menganalisa paket-paket data/informasi dalam jaringan dari serangan Conficker. Anda dapat mendownload wireshark pada alamat &lt;a href="http://www.wireshark.org/download.html"&gt;http://www.wireshark.org/download.html&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Pada saat instalasi, perhatikan untuk mengaktifkan dan menginstall plugin &lt;b&gt;MATE&lt;/b&gt; (&lt;i&gt;Meta Analysis Tracing Engine&lt;/i&gt;), karena secara default belum &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;diaktifkan&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;. Plugin ini dapat berfungsi untuk memfilter seluruh paket-paket data dari berbagai protocol yang lewat dalam jaringan. Selain itu dalam proses instalasi juga disertakan WinPcap. Lakukan instalasi WinPcap, WinPcap merupakan driver yang digunakan untuk membaca dan mem-filter lalu lintas paket data/informasi yang lewat.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (lihat gambar 1)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:453pt;" preferrelative="f" allowoverlap="f" filled="t"&gt;  &lt;v:fill color2="black"&gt;  &lt;v:imagedata src="conficker%20scanner%20review_files/image001.jpg" title=""&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Scanner/conficker%20scanner%20review_files/image002.jpg" shapes="_x0000_i1025" width="604" border="0" height="415" hspace="12" /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 1, Wireshark in action&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Untuk penggunaannya cukup mudah, pada saat anda menjalankan Wireshark, pilih saja tab &lt;i&gt;Capture &lt;/i&gt;kemudian pilih list &lt;i&gt;Interfaces&lt;/i&gt;. Pada pilihan capture interfaces, pilih yang sesuai dengan jaringan LAN/Ethernet card anda kemudian klik tombol start. &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Wireshark juga memiliki kemampuan untuk melakukan scan komputer antar segmen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Untuk deteksi Conficker, lakukan filter dengan protocol &lt;b&gt;NBNS&lt;/b&gt; (&lt;i&gt;NetBIOS Name Service&lt;/i&gt;) kemudian perhatikan info yang diberikan, umumnya NBNS akan membaca hostname komputer tetapi jika NBNS membaca selain hostname komputer dalam hal ini adalah domain-domain yang dituju oleh Conficker, maka source IP tsb merupakan komputer yang terinfeksi dan berusaha untuk menyebarkan dan mengupdate dirinya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style=""&gt;2)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Nmap&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Nmap (&lt;i&gt;Network Mapper&lt;/i&gt;) merupakan salah satu tools eksplorasi jaringan, dan secara eksklusif menjadi salah satu andalan yang sering digunakan oleh administrator jaringan. Dengan Nmap kita dapat melakukan penelusuran ke seluruh jaringan dan mencari tahu service apa yang aktif pada port yang lebih spesifik&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;. &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Nmap merupakan salah satu tools yang paling banyak digunakan untuk melakukan scanning jaringan dan terkenal sebagai tool yang multi platform, cepat dan ringan&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;.&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; Nmap berjalan pada semua jenis OS, baik mode console maupun grafis. Hebatnya lagi, tidak seperti Wireshark, Nmap juga melakukan scanning pada celah keamanan MS08-067 yang di eksploitasi oleh Conficker sehingga dapat membantu administrator menentukan komputer mana saja yang masih memiliki celah keamanan yang dapat dieksploitasi oleh Conficker. Selain itu, Nmap juga memiliki satu keunggulan yang mungkin membuat administrator jaringan besar jatuh cinta, ia dapat melakukan scanning komputer antar segmen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Terhadap kemunculan dan perkembangan Conficker, Nmap dengan bantuan source code dari &lt;b&gt;Tillman Werner&lt;/b&gt; dan &lt;b&gt;Felix Leder&lt;/b&gt; dari The Honeynet Project, telah merilis versi baru dengan tambahan fitur deteksi terhadap komputer yang terinfeksi Conficker. Anda dapat mendownload versi terbaru pada alamat &lt;a href="http://nmap.org/download.html"&gt;http://nmap.org/download.html&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Proses instalasi Nmap cukup mudah, sama halnya seperti wireshark, Nmap juga melakukan instalasi terhadap WinPcap (jika belum terinstall). Jika sudah terinstall WinPcap, biasanya akan terjadi error dan proses instalasi WinPcap sebaiknya di lewatkan saja. (lihat gambar 2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="'width:453pt;height:312pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="conficker%20scanner%20review_files/image003.jpg" title="nmap-deteck"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;img alt="Nmap" src="http://www.vaksin.com/2009/0409/Conficker%20Scanner/imgF-s.jpg" width="608" height="420" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 2, NMAP yang juga mampu memantau jaringan tidak kalah dari Wireshark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Untuk penggunaannya, baik mode console maupun GUI, kita tetap menggunakan perintah command. Penggunaan command untuk mendeteksi Conficker ada 2 cara :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Scan jaringan dengan membaca port 139 &amp;amp; 445 (lebih cepat) :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;nmap -p 139,445 -T4 --script p2p-conficker,smb-os-discovery,smb-check-vulns --script-args checkconficker=1,safe=1 192.168.1.1/24 &lt;i&gt;(contoh dengan jaringan IP 192.168.1…..)&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Scan jaringan dengan membaca seluruh port yang digunakan Conficker (agak lambat) : &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;nmap -p - -T4 --script p2p-conficker,smb-os-discovery,smb-check-vulns --script-args checkall=1,safe=1 192.168.1.1/24 &lt;i&gt;(contoh dengan jaringan IP 192.168.1….)&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style=""&gt;3)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Retina Network Security Scanner (Conficker Worm)&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Walaupun agak terlambat dan diluncurkan menjelang 1 April 2009, sebagai salah satu vendor keamanan komputer, &lt;b&gt;eEye Digital Security&lt;/b&gt; juga ikut meluncurkan tools khusus dan gratis untuk mendeteksi keberadaan Conficker dalam jaringan&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;. &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Tools ini didesain untuk mendeteksi keberadaan Conficker dan sekaligus mendeteksi vulnerability windows tsb dari celah keamanan Windows Server Service (patch MS08-067). Anda dapat mendownload tools ini pada alamat &lt;a href="http://www.eeye.com/html/downloads/other/ConfickerScanner.html"&gt;http://www.eeye.com/html/downloads/other/ConfickerScanner.html&lt;/a&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Proses instalasi sangat mudah dan cepat, anda cukup menjalankan file instalasi yang dilanjutkan perintah-perintah selanjutnya hingga selesai. (lihat gambar 3)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" style="'width:425.25pt;height:283.5pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="conficker%20scanner%20review_files/image005.jpg" title="eeye-deteck"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Scanner/conficker%20scanner%20review_files/image006.jpg" shapes="_x0000_i1027" width="567" border="0" height="378" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 3, Eeye yang merupakan pakar vulnerability Windows meluncurkan Retina Scanner untuk Conficker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Bagi pengguna umum, tools Retina dari Eeye relatif lebih mudah dibandingkan Wireshark dan Nmap, saat anda menjalankan tools ini anda dapat langsung memilih target yang diinginkan baik single IP maupun dengan range IP. Jika sudah, anda dapat langsung klik tombol scan. Jika sudah selesai akan muncul box pesan tanda selesai. Hasil dari scan tsb terdapat 4 kategori yaitu :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Not Tested&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (biasanya dikarenakan port 445 tertutup/disable, sehingga tidak bisa scan)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Infected&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (komputer terdeteksi terinfeksi Conficker)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Patched&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (komputer bersih dan sudah di patch MS08-067)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Vulnerable&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (komputer bersih tetapi belum di patch, rawan terinfeksi Conficker)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Sayangnya tools ini hanya membaca port 139 dan 445, sehingga sangat sulit jika komputer yang terinfeksi tidak mengaktifkan port tsb (&lt;i&gt;File and Printer Sharing&lt;/i&gt;). Selain itu, Retina tidak dapat melakukan scanning antar segmen dan juga tidak memantau port 1024 – 10.000 yang di eksploitasi oleh Conficker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style=""&gt;4)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;SCS (Simple Conficker Scanner)&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Tools &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;simple dan canggih buatan &lt;b&gt;Tillman Werner&lt;/b&gt; dan &lt;b&gt;Felix Leder&lt;/b&gt; dari &lt;i&gt;The Honeynet Project&lt;/i&gt;, yang pada saat awal diluncurkan banyak digunakan oleh Vaksincom untuk mendeteksi IP – IP ISP Indonesia yang terinfeksi Conficker ini menjadi rujukan beberapa vendor untuk membuat tools sejenis. Mereka membuat tools conficker network scanner dari bahasa Python yang kemudian beserta source code-nya dipublish secara bebas. Tercatat beberapa vendor seperti Nmap, eEye dan Foundstone menggunakan source code yang kemudian di compile dan dijadikan plugin tools masing-masing vendor untuk digunakan mendeteksi conficker. Tools ini dapat didownload pada alamat &lt;a href="http://www.4shared.com/get/95921961/d7727fab/scs.html"&gt;http://www.4shared.com/get/95921961/d7727fab/scs.html&lt;/a&gt; .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;SCS tidak perlu diinstall, anda hanya perlu akstrak pada folder/drive yang anda tentukan saja. Tetapi untuk menjalankan SCS anda perlu meng-install &lt;i&gt;Nmap&lt;/i&gt;. Hal ini dikarenakan SCS membutuhkan driver paket monitoring data. (lihat gambar 4)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" style="'width:425.25pt;height:170.25pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="conficker%20scanner%20review_files/image007.jpg" title="scs-deteck"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Scanner/conficker%20scanner%20review_files/image008.jpg" shapes="_x0000_i1028" width="567" border="0" height="227" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 4, Simple Conficker Scanner yang simple tetapi canggih&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Untuk penggunaannya, SCS menggunakan mode console atau command prompt. Pada mode command prompt, pindah pada folder scs kemudian ketik perintah berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;“scs [IP_Awal] [IP Akhir]” , contoh : &lt;b&gt;C:\scs&gt;&lt;i&gt;scs 192.168.1.1 192.168.1.255&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Sama seperti &lt;i&gt;Retina&lt;/i&gt;, SCS hanya membaca port 139 dan 445 saja.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style=""&gt;5)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Conficker Detection Tool (MCDT)&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Melalui salah satu divisi-nya yaitu &lt;i&gt;Foundstone&lt;/i&gt;, McAfee ikut merilis salah satu tools network untuk mendeteksi keberadaan conficker. &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Tools &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;yang juga menggunakan source dari &lt;b&gt;Tillman Werner&lt;/b&gt; dan &lt;b&gt;Felix Leder&lt;/b&gt; dari &lt;i&gt;The Honeynet Project&lt;/i&gt;, merupakan pengembangan dari team &lt;i&gt;Foundstone&lt;/i&gt; yang didesain untuk mendeteksi keberadaan komputer yang terinfeksi conficker, dan telah dipublish secara gratis. Anda dapat mendownload pada alamat &lt;a href="http://www.mcafee.com/us/enterprise/confickertest.html"&gt;http://www.mcafee.com/us/enterprise/confickertest.html&lt;/a&gt; .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Tools ini tidak perlu diinstall, anda hanya perlu ekstrak pada direktori / drive yang anda tentukan saja. (lihat gambar 5)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1029" type="#_x0000_t75" style="'width:269.25pt;height:240.75pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="conficker%20scanner%20review_files/image009.jpg" title="mcafee-deteck"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Scanner/conficker%20scanner%20review_files/image010.jpg" shapes="_x0000_i1029" width="359" border="0" height="321" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 5, Conficker Detection Tool in action&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Untuk penggunaannya pun cukup mudah, saat anda menjalankan tools ini anda dapat langsung memilih range target yang diinginkan. Bahkan anda dapat melakukan scanning jika terdapat beberapa segmen pada jaringan komputer anda, hal ini yang tidak terdapat pada Retina. Tetapi sayangnya tools ini tidak melakukan pemeriksaan pada celah keamanan MS08-067 yang di eksploitasi Conficker seperti Nmap dan Retina. Berbeda dengan Retina, tools ini memiliki 3 kategori hasil scan yaitu :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -14.7pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;INFECTED&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (komputer terinfeksi conficker)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -14.7pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Not infected&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (komputer bersih atau tidak terinfeksi)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -14.7pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Not tested&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; (biasanya dikarenakan port 445 tertutup/disable, sehingga tidak bisa scan)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Sama seperti halnya Retina dan SCS, tool ini hanya membaca port 139 dan 445 (&lt;i&gt;File Printer Sharing&lt;/i&gt;) dan tidak melakukan pemantauan atas port 1024 – 10.000 yang di eksploitasi oleh Conficker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Hasil Perbandingan.....&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Dari beberapa tools tsb, kami me-review dan membuat tabel perbandingan-nya&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;table class="MsoNormalTable" style="width: 478.9pt; margin-left: 4.65pt; border-collapse: collapse;" width="639" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style="height: 15pt;"&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; background: rgb(238, 236, 225) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Keterangan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 61.65pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Wireshark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 60.5pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Nmap&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 53.2pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Retina&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 62.9pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;SCS&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 62.7pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;MCDT &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Modus Program/Aplikasi&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Installer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Installer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Installer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Modus Penggunaan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;GUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Command&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;GUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Command&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;GUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Deteksi Port 139&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Deteksi Port 445&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Deteksi Port 1024 s/d 10000&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Status Deteksi Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Broadcast&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Kecepatan Scan (1-3)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Scan antar segmen/segmen lain&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(0, 176, 240) none repeat scroll 0% 0%; width: 177.95pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 15pt;" valign="bottom" width="237" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Scan vulnerability (patch   MS08-067)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 61.65pt; height: 15pt;" valign="bottom" width="82" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 60.5pt; height: 15pt;" valign="bottom" width="81" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 53.2pt; height: 15pt;" valign="bottom" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.9pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 62.7pt; height: 15pt;" valign="bottom" width="84" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;Dari hasil pe&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;ngujian yang dilakukan oleh lab Vaksincom&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;, terlihat bahwa &lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;tidak ada tools yang sempurna. Masing-masing tools memiliki kelebihan dan kekurangannya masing-masing. &lt;i&gt;Nmap &lt;/i&gt;walaupun memiliki fitur yang paling lengkap tetapi memiliki kelemahan pada sisi penggunaan yang masih menggunakan command dan kecepatan scan yang lambat dibanding tools yang lain. Sementara &lt;i&gt;MCDT&lt;/i&gt; merupakan tools yang sangat simple tanpa instalasi serta proses scan cukup cepat memilki kelemahan tidak dapat berfungsi dengan baik jika port 445 ditutup/disable (&lt;i&gt;File and Printer Sharing&lt;/i&gt; di non aktifkan) dan tidak melakukan pemeriksaan pada celah keamanan MS08-067 yang dieksploitasi oleh Conficker.&lt;br /&gt;&lt;br /&gt;thx to vaksin[dot]com&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-8517075626412783385?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/8517075626412783385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=8517075626412783385&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8517075626412783385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8517075626412783385'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/05/mega-test-5-tools-conficker-network.html' title='Mega Test 5 Tools Conficker Network Detection'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-4444982006552397980</id><published>2009-05-05T19:25:00.000+08:00</published><updated>2009-05-05T19:26:32.768+08:00</updated><title type='text'>Conficker.C, Bom waktu atau April Mop ?</title><content type='html'>&lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="center"&gt;   &lt;span class="style8"&gt;         &lt;/span&gt;&lt;span class="style9"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Tanpa bantuan Lembaga Survei manapun, tentunya para pengguna komputer sepakat bahwa Conficker merupakan virus jawara yang paling banyak menyebar di dunia, terumasuk Indonesia. Virus yang mengeksploitasi celah keamanan RPC Dcom MS 08-067 secara de facto telah membuat pusing semua pengguna komputer, khususnya administrator jaringan karena kemampuannya menyebar di jaringan dengan sangat efektif dan untuk membasmi virus ini sangat sulit. Untuk mengeyahkan Conficker dari komputer yang terinfeksi sangat sulit karena ia menempel pada proses Windows svchost yang jika di stop akan menyebabkan komputer restart. Jadi sekali menginfeksi komputer ibarat orang kalau digigit tokek, kata nenek tidak akan lepas sampai ada geledek menyambar :P./P&gt;   &lt;/p&gt;&lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Celakanya, rupanya pembuat Conficker tidak mudah puas dengan “prestasinya” dimana varian A dan B berhasil menginfeksi belasan juta komputer di seluruh dunia. Terakhir muncul Conficker.C yang memberikan ancaman baru bagi pengguna komputer, dimana pada tanggal 1 April 2009 seluruh komputer yang terinfeksi Conficker.C ini akan secara serentak menghubungi 50.000 situs di internet untuk mengupdate dirinya. Jika anda bertanya, mengapa 50.000 situs, dan bukan 500 situs. Bukankah bisa gempor membuat 50.000 situs ? Jawabannya adalah justru pembuat Conficker ini ingin membuat gempor para vendor antivirus karena dia belajar dari pengalaman dimana varian awalnya mengupdate ke ratusan situs, tetapi karena situs-situs tersebut di blok atas permintaan vendor antivirus maka Conficker A dan B dapat dikatakan “layu sebelum berkembang” karena misinya mengupdate dirinya gagal. Kalau virus Conficker A dan B yang “layu sebelum berkembang” saja sudah mampu membuat para korbannya babak belur dan menginfeksi belasan juta komputer di seluruh dunia, lalu apa yang akan dilakukan virus Conficker.C kalau berhasil “mekar” pada tanggal 1 April 2009 nanti ? Berdoa saja semoga ini hanya menjadi April Mop dan pembuat Conficker.C ini tidak melakukan update atau updatenya gagal. Tetapi yang jelas, secara teknis semua komputer yang terinfeksi Conficker.C dan terkoneksi ke internet sudah dapat dipastikan akan menghubungi 50.000 situs untuk mengupdate dirinya.&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;&lt;b&gt;Pengguna Gaptek dan Provider Cuek&lt;/b&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Jika anda bertanya, bagaimana sebenarnya Conficker menyebar. Caranya mudah saja, Conficker belajar dari Amway atau CNI untuk menyebarkan dirinya. Karena sifatnya worm, ia hanya perlu menginfeksi satu komputer saja di jaringan dan kemudian komputer tersebut akan melakukan scanning terhadap seluruh komputer dijaringannya dan menginfeksi semua komputer yang bisa di infeksinya. Lalu, jika komputer yang di infeksinya terkoneksi ke jaringan lain, ia akan kembali melakukan scanning dan menginfeksi komputer di jaringan lain. Hal ini berjalan terus menerus tanpa henti.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Celakanya, salah satu sumber penyebaran Conficker adalah komputer-komputer yang terkoneksi ke ISP internet baik secara dial up atau broadband. Dimana jika satu pelanggan terinfeksi oleh Conficker, maka ia akan berusaha terus menerus menginfeksi komputer lain yang terkoneksi melalui jaringan dan ISP yang sama. Perlu anda ketahui, yang dimaksud ini tidak terbatas pada dial up dan broadband konvensional tetapi juga broadband 3G. Vaksincom melakukan scanning pada salah satu jaringan 3G Broadband milik provider terbesar Indonesia pada tanggal 31 Maret 2009 dan menemukan banyak komputer-komputer yang terinfeksi Conficker. (lihat gambar 1)&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;&lt;img src="http://www.vaksin.com/2009/0309/confickermop/Bom%20waktu%20atau%20April%20Mop_html_1d954839.jpg" name="graphics1" width="492" align="bottom" border="0" height="678" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;&lt;i&gt;Gambar 1, Conficker mampu menyebar melalui jaringan broadband ISP 3G&lt;/i&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;&lt;b&gt;Apa yang mungkin terjadi ?&lt;/b&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Jika kita belajar dari kasus-kasus infeksi virus yang secara serempak digunakan untuk menyerang satu situs tertentu, kita bisa melihat contoh virus MyDoom yang pada tanggal 1 Februari 2004 berhasil memberikan “kiamat” (down) bagi situs Santa Cruz Operation karena di Ddos oleh jutaan komputer yang terinfeksi virus MyDoom. Sebabnya SCO di Ddos kemungkinan adalah karena dua hal, pertama karena SCO berseteru dengan para pengguna Linux dan yang kedua adalah karena mereka pada tanggal 27 Januari 2004 menawarkan US $ 250.000 bagi siapapun yang bisa memberikan informasi untuk menangkap pembuat virus MyDoom. Sebenarnya situs Microsoft juga sempat di Ddos oleh MyDoom pada tanggal 3 Februari 2004, tetapi “untung” tidak sampai mengakibatkan “kiamat” bagi situs Microsoft. Apakah Ddos ini disebabkan karena Microsoft juga mengeluarkan sayembara hadian US $ 250.000 bagi yang bisa membantu menangkap pembuat virus MyDoom …. Hanya pembuat MyDoom yang tahu. Yang jelas, Microsoft juga mengeluarkan sayembara US $ 250.000 bagi yang bisa membantu menangkap pembuat Conficker.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Cerita lain dari MyDoom adalah pada tanggal 26 Juli 2004 MyDoom juga menyerang 3 search engine terpopuler saat itu, Google, AltaVista dan Lycos dan serangan ini berhasil mengganggu beberapa fungsi search Google dan mengakibatkan kelambatan yang signifikan pada situs AltaVista dan Lycos.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Selain Ddos pada situs, kira-kira hal apa yang mungkin dilakukan oleh virus Conficker.C pada 1 April  2009 nanti ? Kalau virus Conficker.C tidak memiliki kebiasaan buruk dan hanya melakukan Ddos dan menggunakan komputer korbannya untuk mengirimkan SPAM, kerugian yang mungkin kita alami adalah lalu lintas internet akan sangat padat dan kemungkinan para pengguna internet pada 1 April 2009 akan mengalami kelambatan koneksi. Baik karena Ddos, penyebaran ulang varian baru Conficker ataupun karena SPAM yang disebarkan oleh komputer-komputer yang terinfeksi Conficker.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Tetapi jika pembuatnya memiliki niat jahat seperti mencuri data komputer korbannya dan menjual kepada pihak yang berminat, maka kasus serupa dengan “Goshnet” bukan tidak mungkin akan terjadi. Maka jika anda pengguna komputer yang terkoneksi ke internet dan memiliki data penting yang kalau hilang bisa membuat anda nangis bombay, Vaksincom menyarankan anda untuk melakukan backup atas data anda. Jika anda memiliki data yang conficential dan di incar orang seperti rahasia negara atau sejenisnya, khususnya untuk pekerja di kedutaan besar. Sebisa mungkin hindari menggunakan jaringan internet tanpa perlindungan yang memadai dalam berkomunikasi dan jangan sekali-kali mencampurkan komputer yang memproses data classified dengan data pribadi anda. Ingat jaringan internet adalah jalan umum yang bisa dilalui siapa saja dan jika anda mengobrol di jalan umum, kemungkinan untuk didengar orang lain sangat besar. Usahakan menggunakan jalan khusus seperti VPN, atau kalau mampu seperti Presiden Obama menggunakan jaringan GSM khusus yang terpisah dari umum untuk komunikasi Barrackberrynya (Sectera Edge).&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;&lt;b&gt;Preventif&lt;/b&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Vaksincom menyarankan para pengguna komputer Indonesia melakukan tindakan-tindakan berikut dalam mengantisipasi kemungkinan terburuk serangan Conficker.C :&lt;/p&gt; &lt;ol&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Lakukan  PATCH semua OS di komputer-komputer jaringan anda dengan lengkap.  Khusus untuk antisipasi virus Conficker perhatikan bahwa patch MS  08-067 terinstal dengan baik dan benar.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;BACKUP  data penting anda, baik di komputer masing-masing maupun di database  server. Ingat, file yang di backup ditempatkan terpisah dari  komputer yang di backup dan jangan sekali-kali di simpan di harddisk  yang sama dengan komputer yang di backup. Kalau bisa miliki satu  harddisk backup USB atau kalau mau murah backup ke CD / DVD.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Hindari  menyalakan komputer yang tidak terpakai pada saat pulang kantor,  apalagi komputer tersebut terhubung ke internet secara broadband  karena sangat rentan digunakan untuk Ddos, menyebarkan virus atau  spam.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Jika  anda memiliki database server, webserver atau mailserver yang harus  dinyalakan 24 jam. PASTIKAN semua patch sudah terinstal dengan baik  dan lindungi dengan aplikasi sekuriti yang memadai.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; font-family: Arial,Helvetica,sans-serif; font-size: small; margin-top: 0pt;" align="justify"&gt;Jika  anda ingin pendekatan “paranoid”, matikan semua komputer  dan internet pada malam ini 31 Maret 2009 dan jangan hidupkan  internet sampai besok pagi kira-kira jam 10.00 atau sampai anda  dengan persis apa yang akan dilakukan oleh Conficker.C besok.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p class="style2" align="justify"&gt;&lt;span class="style4"&gt;Jika anda  pelanggan Vaksincom, hubungi &lt;/span&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="mailto:teknisi@vaksin.com"&gt;  &lt;span class="style4"&gt;teknisi@vaksin.com&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span class="style4"&gt;  atau &lt;/span&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="mailto:cs@vaksin.com"&gt;  &lt;span class="style4"&gt;cs@vaksin.com&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span class="style4"&gt;  untuk mendapatkan tools khusus scan jaringan dari infeksi Conficker.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-4444982006552397980?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/4444982006552397980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=4444982006552397980&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4444982006552397980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4444982006552397980'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/05/confickerc-bom-waktu-atau-april-mop.html' title='Conficker.C, Bom waktu atau April Mop ?'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-4700465980284797880</id><published>2009-05-05T19:24:00.000+08:00</published><updated>2009-05-05T19:25:35.430+08:00</updated><title type='text'>MEGA Tes 8 Tools Conficker Killer</title><content type='html'>&lt;p class="MsoNormal" style="text-align: center;" align="center"&gt; &lt;b style=""&gt; &lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" class="style8"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="" class="style1"&gt;Virus Conficker yang juga dikenal dengan nama &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;Kido&lt;/span&gt;&lt;span style="" class="style1"&gt; atau &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;Downadup&lt;/span&gt;&lt;span style="" class="style1"&gt; rasanya sudah pasti akrab di telinga administrator komputer di tahun 2009 ini. &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;Salah satu jenis virus berkategori worm yang melakukan penyebaran yang sangat dahsyat dan memiliki dampak yang &lt;/span&gt; &lt;span style="" class="style1"&gt;sangat &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;serius &lt;/span&gt; &lt;span style="" class="style1"&gt;bagi komputer di jaringan&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;.&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="" class="style1"&gt;Karena itu, vendor sekuriti berlomba-lomba mengeluarkan tools dan “mengklaim” diri sebagai yang paling baik dan paling ampuh untuk membasmi Conficker. Yang menjadi pertanyaan bagi pengguna komputer yang menjadi korban Conficker tentunya simple, apakah semua tools tersebut sesuai janjinya ? Apakah seperti Carrie Underwood yang sudah cantik dan suaranya merdu, seperti William Hung yang agak culun, suara pas-pasan dan juga tidak bisa nari (tetapi tetap ngetop &lt;/span&gt; &lt;span style="" class="style1"&gt;&lt;span style=""&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="" class="style1"&gt;) atau seperti Susan Boyle yang sudah berumur dan tampangnya pas-pasan …. tetapi mampu membuat Simon Cowell ternganga &lt;/span&gt; &lt;span style="" class="style1"&gt;&lt;span style=""&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="" class="style1"&gt;. Kali ini Vaksincom akan mengadakan test atas beberapa tools yang tersedia di internet dan semuanya bisa didapatkan secara Gratis.&lt;/span&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;Dan apa kesimpulan akhir dari hasil pengetesan ini, apakah benar semua tools bisa membasmi Conficker sampai ke akar-akarnya atau masih memerlukan beberapa tambahan pekerjaan manual, silahkan lihat pada tabel perbandingan yang Vaksincom berikan dan kesimpulan pada akhir artikel ini.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="" class="style1"&gt;Conficker dan gejalanya&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Sebelumnya, mari kita lihat kembali beberapa gejala &lt;/span&gt;&lt;span style="" class="style1"&gt;komputer terinfeksi &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;Conficker&lt;/span&gt;&lt;span style="" class="style1"&gt; :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Tidak bisa akses domain name web security &amp;amp; tidak bisa update antivirus&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 36.75pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Ini salah satu &lt;/span&gt;&lt;span style="" class="style1"&gt;ciri khas &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;dari conficker. Coba cek dengan akses pada beberapa web security semisal www.microsoft.com, www.kaspersky.com dan www.norman.com. Bandingkan dengan akses melalui ip dari web tsb, http://65.55.12.249 (microsoft), http://195.27.181.34 (kaspersky) dan http://87.238.48.130 (norman). &lt;/span&gt; &lt;span style="" class="style1"&gt;Jika browser anda tidak bisa mengkases situs tersebut di atas dengan mengetikkan alamat situsnya TETAPI bisa diakses jika mengetikkan alamat Ipnya, maka anda perlu “hakul” yakin bahwa komptuernya terinfeksi Conficker (99 %). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 36.75pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hal ini dilakukan &lt;/span&gt;&lt;span style="" class="style1"&gt;oleh Conficker &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;dengan &lt;/span&gt; &lt;span style="" class="style1"&gt;cara &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;melakukan patch pada DNS Query, sehingga jika mengakses DNS tertentu akan diblok oleh conficker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Mematikan dan men-disabled beberapa Service Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Untuk memudahkan infeksi secara efektif, Conficker mematikan beberapa services seperti Automatic Updates (wuauserv), Background Intelligent Transfer Service (BITS), Error Reporting Service (ERSvc), Help and Support (helpsvc), Security Center (wscsvc).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-align: justify; text-indent: -0.75in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Membuat service baru dan berjalan dengan mendompleng svchost&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hal ini bertujuan agar mudah aktif dan menginfeksi komputer lain serta mendownload file virus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Membuat rule firewall baru&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hal ini digunakan agar conficker dapat keluar (menginfeksi komputer lain) dan masuk (update virus baru) dengan mudah. Conficker menggunakan port antara 1024 s/d 10000. jika port yang digunakan virus sama dengan program aplikasi kita, maka &lt;/span&gt; &lt;span style="" class="style1"&gt;aplikasi tersebut akan terganggu.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 18.75pt; text-align: justify; text-indent: 0in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Membuat scheduled task&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hal ini digunakan agar tetap running pada komputer yang terinfeksi. Agar optimal, Conficker membuat beberapa scheduled task agar running setiap saat.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -16.5pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Disable Show Hidden File &amp;amp; System Restore&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hal ini digunakan agar &lt;/span&gt;&lt;span style="" class="style1"&gt;korban &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;tidak mudah melakukan pembersihan pada virus yang sudah masuk dan &lt;/span&gt; &lt;span style="" class="style1"&gt;berhasil &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;menginfeksi komputer maupun drive flash&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;external. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-align: justify; text-indent: -0.75in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt; font-family: Wingdings;" lang="IN"&gt;&lt;span style=""&gt;ü&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span class="style1" lang="IN"&gt;Disable System Restore&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Berfungsi agar &lt;/span&gt; &lt;span style="" class="style1"&gt;komputer korbannya &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;tidak dapat mengembalikan &lt;/span&gt; &lt;span style="" class="style1"&gt;komputer ke setting awal sebelum di infeksi Conficker. Seperti kita ketahui, System Restore merupakan fitur pada Windows XP / vista yang berfungsi seperti mesin waktu yang dapat menolong kita jika terjadi salah instal / terinfeksi virus dimana hanya dengan beberapa klik kita dapat mengembalikan setting komputer pada hari / waktu sebelum komputer terinfeksi virus / salah instal.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span class="style1" lang="IN"&gt;Here are The Tools, Conficker Killer...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Dari beberapa tools yang ada, &lt;/span&gt; &lt;span style="" class="style1"&gt;Vaksincom &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;mereview beberapa tools yang familiar dan sering digunakan. Tools tsb terdapat 2 kategori, yaitu tools secara umum yang dikeluarkan oleh vendor &lt;/span&gt; &lt;span style="" class="style1"&gt;seperti Kaspersky AVP Removal Tools, Microsoft Malicious Software Removal Tools, Stinger besutan Mc Afee dan Norman Malware Cleaner. Catatan khusus untuk Norman Malware Cleaner, selain berfungsi untuk membersihkan Conficker juga sekaligus berfungsi untuk membersihkan dan membasmi virus lain dan Norman Malware Cleaner tidak hanya membasmi file virus saja tetapi juga melakukan pembenahan komputer lebih jauh seperti repair host dan repair registry.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="" class="style1"&gt;Selain itu, Vaksincom membandingkan &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;tool khusus untuk penanganan virus conficker saja&lt;/span&gt;&lt;span style="" class="style1"&gt; yang tidak dapat digunakan untuk membersihkan virus lain&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;.&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Berikut beberapa tools yang &lt;/span&gt; &lt;span style="" class="style1"&gt;tesedia &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;1)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Kaspersky AVP Removal Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Merupakan tools andalan dari Kaspersky Lab yang dibuat sebagai tools pengganti antivirus. Anda dapat mendownload secara gratis. Tetapi sayangnya, tools ini harus diinstall terlebih dahulu sebelum menggunakannya, sehingga jika komputer sudah terinfeksi virus akan sangat sulit &lt;/span&gt; &lt;span style="" class="style1"&gt;jika &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;virus memblok&lt;/span&gt;&lt;span style="" class="style1"&gt; instalasi tools atau aplikasi sekuriti&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;. Untuk conficker&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;kido, AVP sudah menyertakan database-nya. Desain interface sangat mirip dengan interface antivirus-nya. Sayang tidak bisa untuk repair registry, repair service dan repair host yang diubah oleh virus.&lt;/span&gt;&lt;span style="" class="style1"&gt; (lihat gambar 1)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:198.75pt;" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image001.jpg" title="AVP1"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image002.jpg" shapes="_x0000_i1025" width="265" height="208" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 1, Kaspersky AVP Removal Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;2)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Norman Malware Cleaner&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span style="" class="style1"&gt;Dibandingkan versi sebelumnya, t&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;ools &lt;/span&gt; &lt;span style="" class="style1"&gt;GRATIS &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;buatan &lt;/span&gt; &lt;span style="" class="style1"&gt;Norman &lt;a href="http://www.norman.com/"&gt;www.norman.com&lt;/a&gt; &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;ini mengalami kemajuan yang pesat. Tools ini dapat dijadikan alternatif jika komputer terinfeksi virus, karena mampu mengembalikan registry, service dan host yang dibuat oleh virus/spyware. Untuk conficker, tools ini dapat dijadikan alternatif pembersihan. Sayangnya jika tools ini memiliki masa expire (± 14 hari), jadi anda diharuskan untuk mendownload versi yang terbaru&lt;/span&gt;&lt;span style="" class="style1"&gt; dari website norman &lt;a href="http://norman.com/Virus/Virus_removal_tools/24789/"&gt;http://norman.com/Virus/Virus_removal_tools/24789/&lt;/a&gt;. Adapun aksi yang dapat dilakukan Norman Malware Cleaner adalah :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Menghentikan proses virus yang sedang berjalan.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Memberishkan file virus dari media (Flash Disk, Harddisk etc), termasuk komponen ActiveX &lt;span style=""&gt; &lt;/span&gt;dan BHO (Browser Helper Object) yang banyak di eksploitasi oleh Spyware.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Menemukan dan membasmi rootkit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Mengembalikan nilai registri yang dirubah oleh virus (tidak tersedia pada removal tools lain)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Membersihkan perubahan pada hosts file (tidak tersedia pada removal tools lain).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt; &lt;span style="" class="style1"&gt;Membenarkan rule Windows Firewall yang dibuat oleh virus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span style="" class="style1"&gt;Lihat gambar 2 dibawah untuk melihat Norman Malware Cleaner menjalankan aksinya.&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="'width:339.75pt;height:198.75pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image003.jpg" title="nmc"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image004.jpg" shapes="_x0000_i1026" width="328" border="0" height="213" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 2, Norman Malware Cleaner in action&lt;/span&gt;&lt;/i&gt;&lt;i style=""&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;3)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;McAfee AVERT Stinger&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Bagi anda pengguna McAfee, tentunya familiar dengan nama ini. Stinger buatan AVERT &lt;/span&gt; &lt;span style="" class="style1"&gt;yang sempat menjadi salah satu pelopor tools pembersih virus andalan para pengguna komputer dimasa awal kemunculannya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Sayangnya, perkembangan tools ini &lt;/span&gt;&lt;span style="" class="style1"&gt;agak &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;lambat sehingga &lt;/span&gt; &lt;span style="" class="style1"&gt;mendapatkan saingan banyak tools-tools baru&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;. Untuk conficker, stinger sudah menyertakan databasenya. Masih memiliki desain yang simple seperti dulu &lt;/span&gt;&lt;span style="" class="style1"&gt;tetapi jika digunakan untuk membasmi Conficker, ter&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;kadang agak sulit jika virus sudah menginjeksi file system windows&lt;/span&gt;&lt;span style="" class="style1"&gt; dan gagal dibersihkan&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;.&lt;/span&gt;&lt;span style="" class="style1"&gt; (lihat gambar 3)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" style="'width:184.5pt;height:156pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image005.jpg" title="mcafee"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image006.jpg" shapes="_x0000_i1027" width="246" border="0" height="208" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 3, Stinger in action&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;4)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Microsoft Malicious Software Removal Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Tools milik Microsoft yang dapat dijadikan sebagai alternatif scan virus saja. Tools ini dapat didownload secara otomatis setiap bulan dengan fitur automatic updates windows yang ada. Lokasi file ini berada pada C:\WINDOWS\system32, dengan nama MRT.exe. Tools ini memiliki fitur scan yang dapat disesuaikan dengan yang anda inginkan. Jika menemukan virus yang aktif di memory, MRT akan meminta user untuk restart. Walaupun dapat mendeteksi conficker, tetapi tools ini digunakan hanya untuk scanning virus saja, tanpa merepair registry yang sudah dibuat oleh virus. &lt;/span&gt; &lt;span style="" class="style1"&gt;(lihat gambar 4)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" style="'width:198.75pt;height:184.5pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image007.jpg" title="microft removal2"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image008.jpg" shapes="_x0000_i1028" width="265" border="0" height="246" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="" class="style1"&gt;Gambar 4, MWMSRT - Microsoft Windows Malicious Software Removal Tools&lt;/span&gt;&lt;/i&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Sedangkan beberapa tools yang khusus &lt;/span&gt; &lt;span style="" class="style1"&gt;dibuat &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;untuk &lt;/span&gt;&lt;span style="" class="style1"&gt;membasmi &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;conficker adalah sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;1)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;KidoKiller (Kaspersky)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Tools khusus buatan &lt;i style=""&gt;Kaspersky Lab&lt;/i&gt; untuk &lt;/span&gt; &lt;span style="" class="style1"&gt;virus Conficker&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;. Tools ini sudah masuk revisi 3 yaitu mendeteksi virus conficker versi C/III. Fiturnya pun ditambah &lt;/span&gt; &lt;span style="" class="style1"&gt;terus &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;agar mampu mendeteksi dan mendelete scheduled task, serta mampu mngembalikan system restore. Kelebihan tools ini yaitu mampu mengembalikan fungsi DNS Query tanpa harus restart komputer. Tools ini berjalan pada modus command prompt. Berbeda dengan symantec, tools ini hanya scanning pada path tertentu saja yang dicurigai terinfeksi conficker, sehingga waktu scanning menjadi lebih cepat. &lt;/span&gt; &lt;span style="" class="style1"&gt;(lihat gambar 5)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1029" type="#_x0000_t75" style="'width:248.25pt;height:191.25pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image009.jpg" title="kaspersky kido"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image010.jpg" shapes="_x0000_i1029" width="331" border="0" height="255" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 5, KidoKiller by Kaspersky&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;2)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Fix Downad (Trend Micro)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Tools &lt;/span&gt; &lt;span style="" class="style1"&gt;keluaran &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;Trend Micro untuk mengatasi conficker&lt;/span&gt;&lt;span style="" class="style1"&gt; ini s&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;ayangnya tidak menyertakan database&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;patternnya saat di download, sehingga kita harus mendownload terlebih dahulu pattern&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;database-nya. Kelebihannya database&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;pattern tsb dapat scanning dari virus/worm lain, sehingga dapat membersihkan virus lain. Jika tools lain hanya terdiri dari satu file, tools ini memilki beberapa file baik exe maupun file lain yang ternyata terdiri dari pengecekan database&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;/&lt;/span&gt;&lt;span style="" class="style1" lang="IN"&gt; &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;pattern, pengecekan schedule task, pengecekan patch windows, pengecekan virus, pengecekan registry dan pengecekan services. Walau terdiri dari banyak file, kita cukup menjalankan saja 1 file bat (batch file), yang kemudian akan mengeksekusi file lain.&lt;/span&gt;&lt;span style="" class="style1"&gt; (lihat gambar 6)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1030" type="#_x0000_t75" style="'width:326.25pt;height:184.5pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image011.jpg" title="trend micro"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image012.jpg" shapes="_x0000_i1030" width="435" border="0" height="246" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 6, FixTOOL Worm_Downad oleh TrendMicro&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;3)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;W32.Downadup Removal (Symantec)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Sesuai dengan namanya, tools ini dibuat oleh perusahaan antivirus Symantec untuk mengatasi virus conficker/downadup/kido. &lt;/span&gt; &lt;span style="" class="style1"&gt;(lihat gambar 7)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1031" type="#_x0000_t75" style="'width:255pt;height:84.75pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image013.jpg" title="scan symantec"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image014.jpg" shapes="_x0000_i1031" width="340" border="0" height="113" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 7, Downad Removal Tool by Symantec&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 21.3pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Sekilas tools ini sangat simple, hanya ada menu start, cancel dan about. Tools ini tidak memiliki op&lt;/span&gt;&lt;span style="" class="style1"&gt;si &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;scanning drive yang diinginkan. Untuk scanning, tools ini mampu mematikan proses virus, mendelete file virus dan memperbaiki registry yang sudah diubah oleh virus. Sayangnya tools ini tidak menghapus schedule task yang dibuat oleh virus, tidak menghapus rule firewall yang dibuat oleh virus dan tidak mengembalikan system restore kembali normal. &lt;/span&gt; &lt;span style="" class="style1"&gt;Tetapi seperti guru SD saya, &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;tools ini memberikan &lt;/span&gt; &lt;span style="" class="style1"&gt;“nasehat” kepada &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;user agar segera melakukan patching windows dengan MS08-067.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1032" type="#_x0000_t75" style="'width:354.75pt;height:57pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image015.jpg" title="symantec3"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image016.jpg" shapes="_x0000_i1032" width="473" border="0" height="76" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 8, “Nasehat” yang diberikan oleh Downad Removal Symantec&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;b style=""&gt;&lt;span style=""&gt; &lt;span style="" class="style1" lang="IN"&gt;4)&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;!--[endif]--&gt;&lt;b style=""&gt; &lt;span style="" class="style1"&gt;E&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;ConfickerRemover (ESET/NOD32)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Tidak mau ketinggalan, ESET juga mengeluarkan tools khusus conficker bagi penggunanya. Tools ini sangat sederhana, &lt;/span&gt; &lt;span style="" class="style1"&gt;sebenarnya kalau sederhana dan ampuh itu yang dicari. Tetapi yang terjadi adalah sangking sederhanya sehingga a&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;nda harus menjalankan melalui command prompt. &lt;/span&gt; &lt;span style="" class="style1"&gt;T&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;ools ini selain dapat mematikan proses virus dan mendeletenya, &lt;/span&gt; &lt;span style="" class="style1"&gt;tetapi &lt;/span&gt;&lt;span class="style1" lang="IN"&gt;tidak ada hal khusus lain yang dilakukan.&lt;/span&gt;&lt;span style="" class="style1"&gt; (lihat gambar 9)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1033" type="#_x0000_t75" style="'width:340.5pt;height:170.25pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image017.jpg" title="eset"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image018.jpg" shapes="_x0000_i1033" width="454" border="0" height="227" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 9, EconfickerRemover by Eset&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="" class="style1"&gt;MEGA Test Conficker Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;Adapun hasil perbandingan 8 tools tersebut adalah sebagai berikut : (lihat tabel 1 dan 2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="" class="style1"&gt;Kategori Tools Umum :&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;table class="MsoNormalTable" style="width: 486.75pt; margin-left: 4.65pt; border-collapse: collapse;" width="649" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: solid solid none; border-color: windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 53.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="71" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Kategori&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Keterangan&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 77.7pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="104"&gt;   &lt;p class="style5" style="" align="center"&gt;Kaspersky&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 81pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Norman&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 78.3pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;McAfee&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 83.7pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Microsoft&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 53.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="71" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="151" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 77.7pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="104"&gt;   &lt;p class="style5" style="" align="center"&gt;AVP Removal Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 81pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Malware Cleaner&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 78.3pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;AVERT Stinger&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 83.7pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Malicious Removal   Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td rowspan="5" style="border-style: none solid solid; border-color: -moz-use-text-color windowtext black; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(51, 102, 255) none repeat scroll 0% 0%; width: 53.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="71" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Virus Umum&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Penggunaan&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Instalasi&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Virus/Spyware &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Host&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Registry&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Update Definisi&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td rowspan="9" style="border-style: none solid solid; border-color: -moz-use-text-color windowtext black; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(51, 102, 255) none repeat scroll 0% 0%; width: 53.05pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="71" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Matikan Proses Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Schedule Task&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Service Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Service Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Rule Firewall&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Fix DNS Query&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Enable System Restore&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 113pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="151" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Show Hidden&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 77.7pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 81pt; height: 12.75pt;" valign="bottom" width="108" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 78.3pt; height: 12.75pt;" valign="bottom" width="104" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 83.7pt; height: 12.75pt;" valign="bottom" width="112" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="" class="style1"&gt;Tabel 1, Perbandingan Conficker Tools kategori tools umum&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;/p&gt; &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="" class="style1"&gt;Kategori Tools Khusus :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;table class="MsoNormalTable" style="width: 462.95pt; margin-left: 4.65pt; border-collapse: collapse;" width="617" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: solid solid none; border-color: windowtext windowtext -moz-use-text-color; border-width: 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 48pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="64" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Kategori&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Keterangan&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 48.2pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Kaspersky&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 54.3pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;TrendMicro&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 114.9pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Symantec&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid none none; border-color: windowtext windowtext -moz-use-text-color -moz-use-text-color; border-width: 1pt 1pt medium medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 87.1pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Eset (NOD32)&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 48pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="147" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 48.2pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;KidoKiller&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 54.3pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Fix Downad&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 114.9pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;W32.Downadup   Removal&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: silver none repeat scroll 0% 0%; width: 87.1pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Conficker Remover&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td rowspan="5" style="border-style: none solid solid; border-color: -moz-use-text-color windowtext black; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(51, 102, 255) none repeat scroll 0% 0%; width: 48pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="64" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Umum&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Penggunaan&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Portable&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Virus/Spyware &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Host&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Registry&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Update Definisi&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td rowspan="9" style="border-style: none solid solid; border-color: -moz-use-text-color windowtext black; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: rgb(51, 102, 255) none repeat scroll 0% 0%; width: 48pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" width="64" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Matikan Proses Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Schedule Task&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Service Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Service Virus&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Delete Rule Firewall&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Fix DNS Query&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="style5" style="" align="center"&gt;Restart&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Enable System Restore&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 12.75pt;"&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: yellow none repeat scroll 0% 0%; width: 110.45pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; height: 12.75pt;" valign="bottom" width="147" nowrap="nowrap"&gt;   &lt;p class="style1" style=""&gt;Repair Show Hidden&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 48.2pt; height: 12.75pt;" valign="bottom" width="64" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 54.3pt; height: 12.75pt;" valign="bottom" width="72" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 114.9pt; height: 12.75pt;" valign="bottom" width="153" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;√&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 87.1pt; height: 12.75pt;" valign="bottom" width="116" nowrap="nowrap"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;-&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="" class="style1"&gt;Tabel 2, Perbandingan Conficker Tools kategori khusus&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="" class="style1"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Dari hasil &lt;/span&gt; &lt;span style="" class="style1"&gt;pengetesan yang dilakukan oleh lab Vaksincom, baik tools khusus maupun tools umum dapat dilihat bahwa Norman Malware Cleaner membersihkan lebih lengkap dibandingkan tools umum lain karena melakukan “Repair Host”, “Repair Registry”, “Repair Service Windows” dan “Delete Service Virus” yang tidak dilakukan oleh Tools umum lainnya. Tetapi Norman Malware Cleaner tidak melakukan “Delete Schedule Task” yang dibuat oleh virus dan hal ini dilakukan oleh Kaspersky KidoKiller dan TrendMicro Fix Downad. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;TrendMicro Fix downad dan Kaspersky Kido Killer tidak melakukan Repair Host dan Repair Registry.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;Ada satu keunggulan Kaspersky Kido Killer dimana ia bisa melakukan Fix DNS Query tanpa mengharuskan Windows Restart dimana tools lain setelah fix DNS Query mengharuskan Windows restart.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style2" style=""&gt;Jadi dapat disimpulkan bahwa&lt;span style=""&gt;  &lt;/span&gt;Norman Malware Cleaner menjadi pemenang untuk tools umum dan Kaspersky Kido Killer menjadi pemenang di kategori tools khusus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="" class="style1"&gt;Adapun beberapa perubahan yang dilakukan oleh Conficker yang perlu menjadi perhatian sekalipun anda sudah menggunakan tools pembersihan adalah sebagai &lt;/span&gt; &lt;span class="style1" lang="IN"&gt;berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Schedule Task&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Hapus schedule task yang sudah dibuat oleh virus. &lt;/span&gt; &lt;span style="" class="style1"&gt;(lihat gambar 10)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1034" type="#_x0000_t75" style="'width:396.75pt;height:226.5pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image019.emz" title=""&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image020.gif" shapes="_x0000_i1034" width="529" border="0" height="302" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 10, Schedule Task yang dibuat oleh Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Rule Firewall&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Delete rule firewall yang dibuat oleh virus.&lt;/span&gt;&lt;span style="" class="style1"&gt; (lihat gambar 11)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1035" type="#_x0000_t75" style="'width:191.25pt;height:219.75pt'" preferrelative="f" allowoverlap="f"&gt;  &lt;v:imagedata src="mega%20test%20conficker%20tools_files/image021.jpg" title="fire-3"&gt;  &lt;o:lock ext="edit" aspectratio="f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://www.vaksin.com/2009/0409/Conficker%20Tools/mega%20test%20conficker%20tools_files/image022.jpg" shapes="_x0000_i1035" width="255" border="0" height="293" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt;&lt;i style=""&gt; &lt;span style="" class="style1"&gt;Gambar 11, Hapus Rule Firewall yang dibuat oleh Conficker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt; &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt;&lt;span class="style1" lang="IN"&gt;Repair Registry&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Repair registry yang dirubah oleh virus (service windows yang mati dan show hidden file). Buat script pada notepad, kemudian save as menjadi repair.inf.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;[Version]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Signature="$&lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;Chicago&lt;/st1:place&gt;&lt;/st1:city&gt;$"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Provider=Vaksincom&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;span style=""&gt;            &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;[DefaultInstall]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;AddReg=UnhookRegKey&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;DelReg=&lt;st1:state st="on"&gt;&lt;st1:place st="on"&gt;del&lt;/st1:place&gt;&lt;/st1:state&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;[UnhookRegKey]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden, 0x00000001,1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden, 0x00000001,1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0x00000001,1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SYSTEM\CurrentControlSet\Services\BITS, Start, 0x00000002,2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SYSTEM\CurrentControlSet\Services\ERSvc, Start, 0x00000002,2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SYSTEM\CurrentControlSet\Services\wscsvc, Start, 0x00000002,2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SYSTEM\CurrentControlSet\Services\wuauserv, Start, 0x00000002,2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" class="style6" lang="IN"&gt;[&lt;/span&gt;&lt;span class="style1" lang="IN"&gt;&lt;st1:place st="on"&gt;&lt;st1:state st="on"&gt;del&lt;/st1:state&gt;&lt;/st1:place&gt;&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" lang="IN"&gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, dl&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Applets, ds&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, dl&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Applets, ds&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin: 0in 0in 6pt 0.5in; text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;HKLM, SYSTEM\CurrentControlSet\Services\Tcpip\Parameters, TcpNumConnections&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span class="style1" lang="IN"&gt;Clean temporary file&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Bersihkan temporary file, gunakan disk cleanup atau dapat menggunakan tools cleaner seperti ATF Cleaner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span class="style1" lang="IN"&gt;Tips Pencegahan...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="style1" lang="IN"&gt;Dari hasil tes, walaupun sudah dibersihkan tetapi virus/worm ini masih mudah masuk dikarenakan beberapa faktor sebagai berikut :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt; &lt;span class="style1" lang="IN"&gt;Autoplay/Autorun Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Lakukan pencegahan dengan men-disable fungsi autoplay. Fungsi ini memudahkan conficker masuk dan menginfeksi komputer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt; &lt;span class="style1" lang="IN"&gt;Default Share Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Fungsi ini memudahkan virus/worm berusaha masuk melalui jaringan dengan mudah. Matikan fungsi ini jika tidak diperlukan. Sebagai alternatif jika masih diperlukan gunakan password komputer (baik lokal maupun jaringan) yang unik dan tidak standar/biasa serta kombinasi angkadan huruf.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt; &lt;span class="style1" lang="IN"&gt;Patch Windows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Selalu rajin patch windows. Hal ini akan mencegah dari serangan virus saat koneksi internet. Akan lebih baik jika meng-aktifkan Automatic Updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-align: justify; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 11pt;" lang="IN"&gt;&lt;span style=""&gt;-&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;" class="style1"&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt; &lt;span class="style1" lang="IN"&gt;Install Antivirus dan Update&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style1" lang="IN"&gt;Terakhir, lakukan instalasi antivirus dan selalu pastikan terupdate dengan baik.&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="style3" style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  Jika anda mengalami infeksi Conficker yang membandel dan sudah mecoba berbagai macam cara tetapi masih belum tuntas. Mungkin karena sudah gemas sampai anda memformat komputer-komputer di jaringan tetapi setelah dihubungkan ke jaringan kembali terinfeksi. Ada baiknya anda pertimbangkan untuk meminta bantuan support dari vendor antivirus anda. Bagi pengguna Norman Virus Control for Corporate dapat menghubungi teknisi Vaksincom untuk mendapatkan support onsite Free.&lt;br /&gt;&lt;br /&gt;thx to vaksin[dot]com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-4700465980284797880?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/4700465980284797880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=4700465980284797880&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4700465980284797880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4700465980284797880'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/05/mega-tes-8-tools-conficker-killer.html' title='MEGA Tes 8 Tools Conficker Killer'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-4064778956964654618</id><published>2009-03-23T16:41:00.000+08:00</published><updated>2009-03-23T16:43:54.427+08:00</updated><title type='text'>Hati-hati Phishing YM mengincar account Yahoo anda</title><content type='html'>&lt;p class="western" style="margin-bottom: 0pt; margin-top: 0pt;" align="center"&gt;   &lt;span class="style1"&gt;       &lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0pt; margin-top: 0pt;" align="justify"&gt;Mau tahu “ular berbisa” versi Messenger yang sedang marak beredar di internet ? Salah satu teknik yang paling mudah untuk menjerat korban phishing adalah menggunakan rekayasa sosial yang tepat, dan kalau hal ini dilakukan oleh orang yang mengerti hukum, maka hal ini akan mengakibatkan banjir phishing di internet. Kali ini yang menjadi korban adalah para pengguna Messenger, baik Yahoo Messenger maupun MSN Messenger.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Jika anda pernah menerima pesan di Yahoo Messenger seperti dibawah ini :&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_m75f8f49c.jpg" name="graphics1" width="383" align="bottom" border="0" height="99" /&gt;&lt;br /&gt;&lt;i&gt;Gambar  1, Pesan yang dikirimkan oleh Phishing YM&lt;/i&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Hey  chck my yahoo flicker account… uploaded some pics &lt;span style="font-family:Wingdings;"&gt;&lt;/span&gt;  &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.summer-picz.com/"&gt;http://www.summer-picz.com&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Hi  there…. Come check my pictures… different kind of pics  of me WILD and CRAZY &lt;span style="font-family:Wingdings;"&gt;&lt;/span&gt;  &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.summer-picz.com/"&gt;http://www.summer-picz.com&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Dan jika anda klik link tersebut maka anda akan diarahkan pada website phishing yang telah disiapkan (lihat gambar 2)&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_76f3fc01.jpg" name="graphics2" width="473" align="bottom" border="0" height="675" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;i&gt;Gambar 2, Situs Phishing yang akan ditampilkan oleh website pencuri Account Yahoo Messenger&lt;/i&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;JANGAN sekali-kali anda masukkan Yahoo Email dan Password anda karena rekening YM anda akan langsung diketahui. Sekali Account Yahoo anda diketahui, secara teknis banyak sekali hal-hal berbahaya yang dapat dilakukan tanpa sepengetahuan anda. Seperti mengirimkan Phishing, SPAM, email fitnah sampai mengubah data pemilik Account. Terlebih jika anda memiliki akses berharga pada Account YM anda seperti administrator mailinglist dengan jumlah anggota yang besar, account produk-produk Yahoo dan lainnya.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;b&gt;Mengapa orang bisa tertipu ?&lt;/b&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Jika anda “merasa” belum pernah tertipu dan bertanya-tanya, kok keterlaluan banget yah, orang bisa tertipu begitu mudah ? Jawabannya selain karena “kurang teliti” karena mengira situs yang dikunjungi adalah situs milik Yahoo tetapi sebab lain yang utama adalah karena yang mengirimkan pesan tersebut adalah kontak anda yang ada di Yahoo Messenger. Tentunya anda percaya bahwa teman anda tidak mungkin mencelakakan anda dengan menjebak anda ke situs phishing (kalau benar ada rasanya keterlaluan banget deh &lt;span style="font-family:Wingdings;"&gt;&lt;/span&gt;). Jadi, kalau anda menerima pesan seperti di atas, jangan mengamuk dulu sama teman anda. Masalahnya, pesan YM tersebut rupanya tidak dikirimkan oleh teman anda, melainkan karena Account Yahoonya telah diketahui dan digunakan untuk mengirimkan pesan yang menggiring semua kontak untuk mengklik link yang membuka halaman web yang meminta Yahoo Mail dan password. SEGERA minta teman anda untuk mengganti Password YM dan memeriksa dengan teliti apakah data pendukung rekening Yahoonya masih sesuai dengan dirinya. Kalau masih sesuai, “mungkin” rekening Yahoo tersebut masih bisa digunakan. Tetapi kalau anda was-was dan ingin menerapkan paranoid mode, ganti rekening Yahoo anda dengan yang baru dan jangan lupa lengkapi login Yahoo anda dengan “Sign in Seal” dan selalu perhatikan alamat situs Yahoo setiap kali memasukkan username dan password.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;b&gt;Siapa yang baca Term and Conditions ?&lt;/b&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Jika ditanya, apakah anda membaca dengan seksama Terms and Conditions setiap kali anda menginstal software atau menggunakan satu layanan di internet ? Dapat dikatakan 99 % akan menjawab TIDAK. Nah, kelemahan inilah yang dimanfaatkan oleh T P Ltd, perusahaan yang menjadi dalang dari semua ini.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;T P Ltd adalah satu perusahaan yang menggunakan domisili hukum Panama. Dan perusahaan ini sudah melindungi dirinya dengan perangkat hukum yang baik karena dia sudah mencantumkan bahwa anda setuju account Yahoo Anda digunakan untuk tujuan promosi dalam Term and Conditions yang tercantum linknya di halaman depan situs forgery tersebut. (yang kami yakin anda yang pernah masuk situs tersebutpun belum tentu ingat ada kalimat “- By logging in you accept Terms and Conditions-”, apalagi megklik dan membaca linknya. Berikut ini kutipan salah satu point dalam “Terms and Conditions” :&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;span style="font-size:85%;"&gt;&lt;i&gt;By using our service/website you hereby fully authorize T P Ltd to send messages of a commercial nature via Instant Messages and E-Mails on behalf of third parties via the information you provide us.&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Firefox – Internet Explorer – Safari&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Satu hal yang menarik dan Vaksincom alami dalam mengakses situs forgery ini menggunakan beberapa browser yang berbeda seperti Firefox, Internet Explorer dan Safari adalah :&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Secara default (tanpa setting khusus) browser Firefox versi 3.0.6 relatif lebih aman dari browser Internet Explorer versi 7.0.6001.18000 dan Safari versi 3.2.1.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Mengapa ?&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Situs Firefox memberikan peringatan berulang-ulang setiap kali mengakses situs forgery yang rasanya agak “keterlaluan” kalau sampai pengguna firefox sampai bisa tertipu oleh situs ini. Jadi, saat pertama kali Vaksincom masuk ke situs &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.holiday-picz.com/"&gt;www.holiday-picz.com&lt;/a&gt;&lt;/u&gt;&lt;/span&gt; langsung mendapatkan peringatan berwarna Merah dengan gambar icon polisi memegang rambu lalulintas “dilarang masuk” (coba kurang jelas bagaimana pesan yang diberikan :P) bahwa situs ini dilaporkan BERBAHAYA dan dipalsukan dan hanya dua tombol yang mudah di klik : (lihat gambar 2)&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_m7295dc47.jpg" name="graphics3" width="599" align="bottom" border="0" height="420" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;i&gt;Gambar 2, Peringatan yang diberikan oleh Firefox jika kita ingin mengakses situs forgery &lt;/i&gt;&lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.holiday-picz.com/"&gt;&lt;i&gt;www.holiday-picz.com&lt;/i&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;i&gt; &lt;/i&gt; &lt;/p&gt; &lt;ol&gt;&lt;li&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Get  me out of here ! Yang kalau di klik akan membawa anda keluar dari  situs berbahaya tersebut.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Why  was this site blocked ? Yang kalau di klik akan memberikan informasi  lebih jauh mengenai web forgery dan phishing&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Hanya saja kalau anda tetap keukeuh dan ingin mengakses situs tersebut, anda dapat mengklik kalimat kecil di pojok kanan “Ignore this warning” anda baru bisa mengakses situs tersebut (lihat gambar 3). Itupun masih tetap dengan adanya pita berwarna merah berisi peringatan dari Firefox “Reported Web Forgery !”. Kemungkinan pengguna Firefox dan tetap bisa terjebak memasukkan Alamat email dan password adalah karena “gatal” ingin mengklik dan memasukkan segala sesuatu tanpa membaca atau karena pengguna tersebut kurang mengerti Bahasa Inggris. (tapi harusnya kan mengerti yah, kalau merah itu berarti bahaya, mana ada gambar polisi galak bawa rambu verboden … kok masih diterabas …. Kaya naik motor ajah :P).&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_76f3fc01.jpg" name="graphics4" width="473" align="bottom" border="0" height="675" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;i&gt;Gambar 3, Situs Holiday-picz.com yang ditampilkan oleh Firefox tetap memberi peringatan Web Forgery&lt;/i&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Bandingkan dengan tampilan situs ini di Internet Explorer dan Safari (gambar 4 dan 5)&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_m6aa0d921.jpg" name="graphics5" width="513" align="bottom" border="0" height="641" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;i&gt;Gambar 4, Internet Explorer 7 langsung menampilkan situs Forgery ini tanpa peringatan apapun&lt;/i&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;img src="http://vaksin.com/2009/0309/ym%20phishing/ym%20phishing_html_2e38533f.png" name="graphics6" width="481" align="bottom" border="0" height="620" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;i&gt;Gambar 5, Safari juga menampilkan situs forgery ini tanpa peringatan apapun.&lt;/i&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Menurut perkiraan Vaksincom, secara tidak langsung karena Yahoo Messenger secara default akan membuka setiap link menggunakan Internet Explorer sehingga menyebabkan tingginya korban dari web foegery ini.&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;Celakanya, Vaksincom mendapatkan laporan bahwa TP Ltd ini sangat kreatif dan selalu memperbaharui situs forgerynya dengan pesan yang makin hari makin canggih. Selain itu, bukan hanya Yahoo Messenger saja yang menjadi korbannya, tetapi juga MSN Messenger. Dalam artikel berikut, Vaksincom akan memberikan hasil pengetesan Lab menggunakan Account Yahoo messenger dan bagaimana mendeteksi Account Yahoo anda sedang dipakai dan terakhir yang tidak kalah menarik, ada perusahaan game online internet yang populer di Indonesia dengan anggota ratusan ribu pengguna ternyata menggunakan jasa TP Ltd dalam menyebarkan iklan gamenya.&lt;/p&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin-bottom: 0.14in;" align="justify"&gt;thx to vaksin[dot]com&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-4064778956964654618?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/4064778956964654618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=4064778956964654618&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4064778956964654618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/4064778956964654618'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/03/hati-hati-phishing-ym-mengincar-account.html' title='Hati-hati Phishing YM mengincar account Yahoo anda'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-3721813370021028315</id><published>2009-03-23T16:40:00.000+08:00</published><updated>2009-03-23T16:41:17.022+08:00</updated><title type='text'>Virus yang membuat komputer anda banjir Shortcut</title><content type='html'>&lt;p class="style4"&gt;Di tengah gencarnya virus-virus Confiker melanda dunia persilatan jaringan, maka ada sebuah virus lokal yang tidak mau kalah untuk unjuk gigi. Virus ini penulis dapatkan secara tidak sengaja, ketika sedang beranjang &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;sana&lt;/st1:city&gt;&lt;/st1:place&gt; di sebuah tempat kerja sahabat dekat, dia mengeluh kok banyak banget sih shortcut di komputernya. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style4"&gt;Setelah diamati memang benar banyak sekali file-file shortcut yang bertebaran di setiap folder yang ada di dalam komputernya, seperti Microsoft.lnk, dan juga file shortcut dengan nama seperti nama folder yang dimiliki. Akhirnya dengan naluri &lt;i style=""&gt;vaksinis&lt;/i&gt; yang tidak bisa &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;menden&lt;/st1:place&gt;&lt;/st1:city&gt;gar ada virus baru yang tidak terdeteksi oleh antivirus, maka dengan segera keluhan tersebut langsung dianalisa lebih lanjut dan dibuatkan cara mengatasinya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style4"&gt;   &lt;o:p&gt;Norman Virus Control mendeteksi virus ini sebagai    Worm:PIF/Starter.A (lihat gambar 1) :&lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style4"&gt;   &lt;o:p&gt;   &lt;img alt="NSS detect shortcut" src="http://vaksin.com/File/2009/shotcut.JPG" width="649" height="438" /&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style4"&gt;   &lt;o:p&gt;&lt;em&gt;Gambar 1, Norman Security Suite mendeteksi virus Shortcut    sebagai Worm:PIF/Starter.A&lt;/em&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style4"&gt;Ciri-ciri dari virus tersebut adalah :&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Di      folder My Documents terdapat sebuah file yang bernama &lt;b style=""&gt;database.mdb&lt;/b&gt;, dan ternyata ini adalah file induknya.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="style15" style="margin-right: 0in; margin-bottom: 0.0001pt; text-align: justify;"&gt;  &lt;span class="style12"&gt;File &lt;b style=""&gt;Autorun.inf, Thumb.db&lt;/b&gt;,   &lt;b style=""&gt;Microsoft.lnk&lt;/b&gt; di setiap driver, folder dan flash disk sampai pada SUB Folder yang ke-2&lt;o:p&gt;.&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="style15" style="margin-right: 0in; margin-bottom: 0.0001pt; text-align: justify;"&gt;  &lt;span class="style12"&gt;Membuat &lt;b style=""&gt;File Duplikat&lt;/b&gt; setiap folder dengan   &lt;b style=""&gt;extensi .lnk, &lt;/b&gt;maksimal 5 nama folder pertama, misalnya kalau di C:\Windows ada banyak maka hanya akan diambil 5 nama pertama saja. Dan berlaku sampai sub folder yang ke-2&lt;o:p&gt; (lihat gambar 2)&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt; &lt;/p&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;   &lt;span class="style13"&gt;&lt;span style="'mso-spacerun:yes'" class="style2"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="style12"&gt;SHAPE&lt;span style="'mso-spacerun:yes'"&gt;  &lt;/span&gt;\* MERGEFORMAT &lt;/span&gt;&lt;![endif]--&gt;&lt;!--[if gte vml 1]&gt;&lt;v:group id="_x0000_s1040" style="'width:515.7pt;height:278.5pt;" coordorigin="690,3960" coordsize="10314,5570"&gt;  &lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;   &lt;v:stroke joinstyle="miter"&gt;   &lt;v:formulas&gt;    &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;    &lt;v:f eqn="sum @0 1 0"&gt;    &lt;v:f eqn="sum 0 0 @1"&gt;    &lt;v:f eqn="prod @2 1 2"&gt;    &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;    &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;    &lt;v:f eqn="sum @0 0 1"&gt;    &lt;v:f eqn="prod @6 1 2"&gt;    &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;    &lt;v:f eqn="sum @8 21600 0"&gt;    &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;    &lt;v:f eqn="sum @10 21600 0"&gt;   &lt;/v:formulas&gt;   &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;   &lt;o:lock ext="edit" aspectratio="t"&gt;  &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_s1041" type="#_x0000_t75" style="'position:absolute;" wrapcoords="-38 0 -38 21550 21600 21550 21600 0 -38 0"&gt;   &lt;v:imagedata src="virus%20shortcut_files/image001.png" title="" croptop="8728f" cropbottom="48040f" cropleft="32597f" cropright="1140f"&gt;  &lt;/v:shape&gt;&lt;v:group id="_x0000_s1042" style="'position:absolute;left:720;top:3960;" coordorigin="720,3960" coordsize="10284,2263"&gt;   &lt;v:shape id="_x0000_s1043" type="#_x0000_t75" style="'position:absolute;" wrapcoords="-57 0 -57 21518 21600 21518 21600 0 -57 0"&gt;    &lt;v:imagedata src="virus%20shortcut_files/image002.png" title="" cropbottom="20521f"&gt;   &lt;/v:shape&gt;&lt;v:shape id="_x0000_s1044" type="#_x0000_t75" style="'position:absolute;" wrapcoords="-54 0 -54 21526 21600 21526 21600 0 -54 0"&gt;    &lt;v:imagedata src="virus%20shortcut_files/image003.png" title="" croptop="12775f" cropbottom="30230f"&gt;   &lt;/v:shape&gt;&lt;/v:group&gt;&lt;v:shapetype id="_x0000_t202" coordsize="21600,21600" spt="202" path="m,l,21600r21600,l21600,xe"&gt;   &lt;v:stroke joinstyle="miter"&gt;   &lt;v:path gradientshapeok="t" connecttype="rect"&gt;  &lt;/v:shapetype&gt;&lt;span style="'font-size:11.0pt;font-family:"&gt;&lt;v:shape id="_x0000_s1045" type="#_x0000_t202" style="'position:absolute;"&gt;   &lt;v:textbox&gt;    &lt;![if !mso]&gt;    &lt;table cellpadding="0" cellspacing="0" width="100%"&gt;     &lt;tr&gt;      &lt;td&gt;&lt;![endif]&gt;      &lt;div&gt;      &lt;p class="style4"&gt;Bisa dilihat gambar di sebelah kanan      atas, virus ini akan mengambil maksimal 5 nama pertama dari folder yang      ada, kemudian akan mendupkikasikan dirinya menjadi file *.LNK, pada Sub      Folder yang kedua, akan dibuat demikian juga seperti pada sub folder      pertama, dan di dalamnya ada juga file-file AUTORUN.INF, THUMB.DB dan      MICROSOFT.LNK dengan attrib RSHA&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;      &lt;/div&gt;      &lt;![if !mso]&gt;&lt;/td&gt;     &lt;/tr&gt;    &lt;/table&gt;    &lt;![endif]&gt;&lt;/v:textbox&gt;  &lt;/v:shape&gt;&lt;/span&gt;&lt;w:wrap type="none"&gt;  &lt;w:anchorlock/&gt; &lt;/v:group&gt;&lt;![endif]--&gt;&lt;span class="style12"&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0209/shortcut/virus%20shortcut_files/image004.gif" shapes="_x0000_s1040 _x0000_s1041 _x0000_s1042 _x0000_s1043 _x0000_s1044 _x0000_s1045" width="691" height="374" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;&lt;span style="'font-family:" class="style13"&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:515.7pt;height:278.5pt'"&gt;  &lt;/span&gt;  &lt;v:imagedata croptop="-65520f" cropbottom="65520f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;   &lt;/p&gt;   &lt;p class="style12" style="text-align: justify;"&gt;   &lt;o:p&gt;&lt;em&gt;Gambar 2, Aksi virus Shortcut memalsukan folder&lt;/em&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="4" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Mematikan      fungsi dari file Registry&lt;o:p&gt; (lihat gambar 3)&lt;/o:p&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="style16"&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;"DisableRegistrytools"=dword:00000001&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-align: justify;"&gt; &lt;span class="style12"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" style="'width:270pt;height:96.75pt'" wrapcoords="-60 0 -60 21433 21600 21433 21600 0 -60 0" allowoverlap="f"&gt;  &lt;v:imagedata src="virus%20shortcut_files/image005.png" title="" croptop="28590f" cropbottom="26214f" cropleft="21750f" cropright="21258f"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0209/shortcut/virus%20shortcut_files/image006.jpg" shapes="_x0000_i1027" width="360" height="129" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style5" style="margin-left: 0.25in; text-align: justify;"&gt;   &lt;o:p&gt;&lt;em&gt;Gambar 3, Pesan yang ditampilkan jika mengakses Registry Edit&lt;/em&gt;&lt;/o:p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style5" style="margin-left: 0.25in; text-align: justify;"&gt;   &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="5" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Menambahkan      value di registry &lt;o:p&gt;:&lt;/o:p&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="style16"&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style17"&gt;"Explorer"="Wscript.exe //e:VBScript \"C:\Documents and Settings\Administrator\My Documents\database.mdb\""&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;"WinUpdate"="Wscript.exe /e:VBScript \"C:\WINDOWS\:Microsoft Office &lt;span style=""&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;Update for Windows XP.sys\""&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;Untuk script yang terakhir mungkin sekali ini hanya script untuk mengecoh saja, tetapi &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;dalam prakteknya kita harus mendeletenya. Jika pada saat kita LogOn komputer, maka &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style16"&gt;akan didapat message error seperti di bawah ini&lt;o:p&gt; (lihat gambar 4)&lt;/o:p&gt;&lt;/p&gt;   &lt;p class="style16"&gt;   &lt;o:p&gt;&lt;/o:p&gt;   &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify; text-indent: 0.5in;"&gt; &lt;span class="style12"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" style="'width:388.5pt;height:78.75pt'" wrapcoords="-42 0 -42 21394 21600 21394 21600 0 -42 0" allowoverlap="f"&gt;  &lt;v:imagedata src="virus%20shortcut_files/image007.png" title="" croptop="28590f" cropbottom="26132f" cropleft="12595f" cropright=".1875"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0209/shortcut/virus%20shortcut_files/image008.jpg" shapes="_x0000_i1028" width="518" height="105" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="style12" style="text-align: justify; text-indent: 0.5in;"&gt;   &lt;o:p&gt;&lt;em&gt;Gambar 4, Pesan error yang ditampilkan saat logon karena gagal    loading script.&lt;/em&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style4"&gt;Yang membuat kita menjadi &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;gera&lt;/st1:place&gt;&lt;/st1:city&gt;m adalah banyak sekali shortcut yang dibuat oleh virus tersebut. Dan hebatnya virus tersebut kalau cara penanganannya tidak tepat maka akan kembali lagi dan lagi. Oleh sebab itu ada beberapa cara yang harus dilakukan untuk memberantas virus yang menyebalkan ini :&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Matikan      proses dari file WSCRIPT yang terletak di C:\Windows\System32, dengan cara      menggunakan tools seperti CProcess, HijackThis atau dapat juga menggunakan      Task Manager dari windows. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;ol style="margin-top: 0in;" start="2" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Sebelumnya      matikan dulu proses SYSTEM RESTORE.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;ol style="margin-top: 0in;" start="3" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Setelah      dimatikan proses dari Wscript tersebut, kita harus mendetele atau merename      dari pada file tersebut agar tidak digunakan (untuk sementara) lagi oleh      virus tersebut. Sebagai catatan, kalau kita merename dari file Wscript.exe      tersebut dengan automatis akan dikopikan lagi di folder tersebut, oleh      sebab itu kita harus mencari di mana file Wscript.exe yang lainnya      biasanya ada di C:\Windows\$NtServicePackUninstall$,      C:\Windows\ServicePackFiles\i386. Tidak seperti virus-virus VBS lainnya, kita      bisa mengganti Open With dari file VBS menjadi Notepad, virus ini      berextensi MDB yang berarti adalah file Microsoft Access. Jadi Wscript      akan menjalankan file DATABASE.MDB seolah-olah dia adalah file VBS. (Virus      pintar &lt;st1:place st="on"&gt;&lt;st1:state st="on"&gt;kan&lt;/st1:state&gt;&lt;/st1:place&gt;)      &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="style8"&gt;Wscript.exe //e:VBScript \"C:\Documents and Settings\Administrator\My Documents\database.mdb\""&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="4" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style1"&gt;&lt;st1:state st="on"&gt;&lt;span class="style12"&gt;Del&lt;/span&gt;&lt;/st1:state&gt;&lt;span class="style12"&gt;ete file &lt;st1:state st="on"&gt;&lt;st1:place st="on"&gt;ind&lt;/st1:place&gt;&lt;/st1:state&gt;uknya yang ada      di C:\Documents and Settings\&lt;user&gt;\My Documents\database.mdb, agar      setiap kali komputer dijalankan tidak akan meload file tersebut. Dan      jangan lupa kita buka juga MSCONFIG, disable perintah yang menjalankannya.      &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;ol style="margin-top: 0in;" start="5" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Sekarang      kita akan mendelete file-file Autorun.INF. Microsoft.INF dan Thumb.db.      dengan cara, klik tombol START, ketik CMD, pindah ke drive yang akan      dibersihkan, misalnya drive C:\, maka yang harus kita lakukan adalah &lt;o:p&gt;&lt;/o:p&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="style11"&gt;Ketik C:\del Microsoft.inf /s&lt;span style=""&gt;   &lt;/span&gt;= perintah ini akan mendelete semua file microsoft.inf di seluruh folder di drive C: , kalau mau pindah drive tinggal diganti nama drivenya saja contoh : D:\del Microsoft.inf /s&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="style11"&gt;Untuk file autorun.inf, ketik C:\del autorun.inf /s /ah /f&lt;span style=""&gt;  &lt;/span&gt;= perintah akan mendelete file autorun.inf&lt;span style=""&gt;  &lt;/span&gt;(syntax /ah /f digunakan karena file tersebut memakai attrib RSHA, begitu juga untuk file Thumb.db lakukan juga hal yang sama.&lt;span class="style12"&gt;&lt;!--[if !vml]--&gt; (lihat gambar 5)&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="style11"&gt;&lt;span class="style12"&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0209/shortcut/virus%20shortcut_files/image010.jpg" shapes="_x0000_i1029" width="528" height="266" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="style11"&gt;&lt;!--[if !vml]--&gt;&lt;em&gt;Gambar 5, Perintah mendelete file lnk    yang diciptakan virus.&lt;/em&gt;&lt;!--[endif]--&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="6" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style1"&gt;&lt;span class="style12"&gt;Untuk      mendelete file-file selain 4 file terdahulu, kita harus mencarinya dengan      cara Search file dengan ekstensi .lnk ukurannya 1 KB, Pada “More advanced      options”, pastikan option “Search system folders” dan “Search hidden files      and folders” keduanya telah dicentang.&lt;/span&gt;&lt;span class="fullpost"&gt;&lt;span style="" class="style12"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="style10"&gt;Harap berhati-hati, tidak semua file shortcut / file LNK yang berukuran 1 KB adalah virus, kita dapat membedakannya dari iconnya, size dan Type. Untuk shortcut yang diciptakan virus iconnya selalu  menggunakan icon "folder", ukuran 1 KB dengan Type "Shortcut". Sedangkan folder  yang benar harusnya tidak memiliki "size" dan Typenya adalah "File Folder".  Contoh di bawah, gambar bagian kiri folder dengan nama "Music", "Video",  "Programs", "Documents" dan "Compressed" sebenarnya adalah shortcut yang  memalsukan diri sebagai icon folder yang diciptakan oleh virus dan harus dihapus  karena memiliki size 1 KB dan Type "Shortcut". Sedangkan Folder dengan nama  "Compressed", "Documents", "Music", "Programs", "Video" dan "Virus" yang tidak  memiliki Size dan Type "File Folder" adalah folder asli yang namanya dicatut  oleh virus. Sedangkan gambar kanan, shortcut yang asli dari program memiliki  icon khusus sesuai icon programnya. (lihat gambar 6)&lt;/p&gt;   &lt;p class="style10"&gt;&lt;span class="style12"&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0209/shortcut/virus%20shortcut_files/image013.gif" shapes="_x0000_s1053 _x0000_s1048 _x0000_s1052" width="555" height="239" /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="style10"&gt;&lt;em&gt;Gambar 6, &lt;/em&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;   &lt;span class="style13"&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="'width:416.25pt;height:179.25pt'"&gt;    &lt;em&gt; &lt;/em&gt;&lt;/span&gt;&lt;v:imagedata croptop="-65520f" cropbottom="65520f"&gt;&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;o:p&gt;&lt;em&gt;Shortcut    yang dibuat virus akan menyerupai icon folder, tetapi memiliki Size 1 KB    dan Type "Shortcut"&lt;/em&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="7" type="1"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;  &lt;p class="style5"&gt;Fix      registry yang sudah di ubah oleh virus. Untuk mempercepat proses perbaikan      registry salin script dibawah ini pada program “notepad” kemudian simpan      dengan nama "Repair.inf". Jalankan file tersebut dengan cara:&lt;/p&gt;  &lt;/li&gt;&lt;/ol&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 30pt; font-size: x-small; font-family: Arial;"&gt;  &lt;/p&gt;   &lt;p class="western" style="margin: 0in 0in 0.0001pt 30pt; font-size: x-small; font-family: Arial;"&gt;- Klik kanan repair.inf&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 30pt; font-size: x-small; font-family: Arial;"&gt;- Klik Install&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt; font-family: Arial; font-size: x-small;"&gt;  &lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;[Version]&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;Signature="$&lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Chicago&lt;/st1:city&gt;&lt;/st1:place&gt;$"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;Provider=Vaksincom Oyee&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-family: Arial; font-size: x-small;"&gt;  &lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;[DefaultInstall]&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;AddReg=UnhookRegKey&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;DelReg=&lt;st1:place st="on"&gt;&lt;st1:state st="on"&gt;del&lt;/st1:state&gt;&lt;/st1:place&gt;&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-family: Arial; font-size: x-small;"&gt;  &lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;[UnhookRegKey]&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-family: Arial; font-size: x-small;"&gt;  &lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in;"&gt; &lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;" class="style13"&gt;[&lt;/span&gt;&lt;span class="style12"&gt;&lt;st1:place st="on"&gt;&lt;st1:state st="on"&gt;del&lt;/st1:state&gt;&lt;/st1:place&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKLM,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Winupdate&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;HKCU,SOFTWARE\Microsoft\Windows\CurrentVersion\Run, explorer&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;span style="font-size:85%;"&gt;Thx to vaksin[dot]com&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;/p&gt;&lt;p class="western" style="margin: 0in 0in 0.0001pt 0.5in; font-size: x-small; font-family: Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-3721813370021028315?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/3721813370021028315/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=3721813370021028315&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3721813370021028315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3721813370021028315'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/03/virus-yang-membuat-komputer-anda-banjir.html' title='Virus yang membuat komputer anda banjir Shortcut'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-6509029114641834263</id><published>2009-03-23T16:38:00.000+08:00</published><updated>2009-03-23T16:39:36.097+08:00</updated><title type='text'>Antivir palsu</title><content type='html'>&lt;p class="style5"&gt; &lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt; &lt;o:p&gt;Artikel Chip November 2008 &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt; &lt;o:p&gt;&lt;/o:p&gt; &lt;/p&gt; &lt;p class="MsoNormal"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Serigala berbulu domba. Ungkapan ini patut di ingat-ingat oleh para pengguna komputer yang mendadak mendapatkan peringatan bahwa di komputernya di temukan virus / spyware dan langsung ditawarkan removalnya saat itu juga. Peringatan yang muncul banyak variasinya, dari perubahan wallpaper, muncul pesan di “system icons” di pojok kanan bawah layar komputer (sebelah jam) atau pesan pop up. (lihat gambar 1 dan 2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:502.5pt;"&gt;  &lt;v:imagedata src="antivirus%20gadungan_files/image001.jpg" title="fake-wallpaper"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0309/scareware/antivirus%20gadungan_files/image002.jpg" shapes="_x0000_i1025" width="670" height="499" /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 1, Scareware Antivirus-2008 yang merubah Wallpaper komputer korbannya menjadi peringatan palsu adanya spyware dan menawarkan removal yang sebenarnya palsu.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="'width:223.5pt;height:306pt'"&gt;  &lt;v:imagedata src="antivirus%20gadungan_files/image003.jpg" title="xpantivirus2008-spyware alert2"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0309/scareware/antivirus%20gadungan_files/image003.jpg" shapes="_x0000_i1026" width="298" height="408" /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 2, Peringatan palsu adanyaSpyware yang ditampilkan oleh Antivirus 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Istilah yang diberikan pada program antivirus gadungan ini adalah Rogue Scanner, Advance Antivirus atau Scareware. Dikatakan sebagai scareware karena cara kerjanya yang menakut-nakuti korbannya bahwa komputernya terinfeksi virus dan spyware dengan tingkat bahaya yang sangat tinggi dan disarankan untuk mendownload antivirus gadungan (yang sebenarnya juga spyware) ke situs yang telah dipersiapkan terlebih dahulu. Jika korban berhasil ditakuti dan masuk ke situs yang telah dipersiapkan, ia akan ditawari untuk membeli antivirus gadungan dan membayar dengan kartu kreditnya. Kemungkinan besar korbannya ini akan terperdaya karena memang aplikasi scareware dan situs-situs pendukung ini sudah dipersiapkan dengan baik dan tampilan aplikasi dan websitenya terlihat cukup profesional. Dimana tampilan scareware tersebut tidak kalah dengan tampilan program antivirus terkini dan hebatnya situs yang dikunjungipun memiliki sistem penerimaan pembayaran dengan kartu kredit yang online. Masalahnya adalah, sebenarnya peringatan tentang belasan virus yang berhasil di deteksi oleh scareware tersebut adalah peringatan palsu, dimana sebenarnya tidak ada virus yang dimaksudkan di komputer korban. Namanya juga scareware (ingat scarecrow, patung-patungan palsu untuk manakuti burung (gagak) supaya tidak memakani padi) tujuan utamanya adalah menakuti korbannya untuk tujuan komersial dan celakanya cara yang dipakai kurang terpuji dengan memberikan peringatan virus palsu. Selain itu, jika korbannya setuju untuk mendownload program scareware yang ditawarkan. Maka ibarat kata pepatah, “Sudah Jatuh Tertimpa Tangga” …. (di gigit anjing lagi :P) maka selain membayar untuk sesuatu yang tidak perlu, kemungkinan besar kartu kredit yang digunakan untuk membeli scareware tersebut akan dijadikan sebagai sasaran fraud. Banyak laporan yang menyebutkan bahwa biaya yang ditagihkan ke kartu kredit tidak sesuai dengan yang tertera pada saat transaksi dan bisa beberapa kali lipat. Karena itu sebaiknya anda segera memblokir kartu kredit tersebut dan mengganti dengan yang baru untuk menjaga kemungkinan digunakan untuk fraud.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Metode infeksi&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Scareware akan datang dalam banyak alternatif :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Mengeksploitasi celah keamanan (Java Script) browser waktu      mengunjungi website tertentu sehingga akan terinstal secara otomatis dan      menampilkan peringatan palsu.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Menawarkan scan malware gratis atau tune up sistem komputer gratis.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Email, dalam hal eksploitasi email pembuat virus ini cukup      kreatif. Adapun bentuk-bentuk email yang terdeteksi adalah sebagai berikut      :&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-top: 0in;" type="circle"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style=""&gt; &lt;/span&gt;Kartu ucapan / greeting       card. Email yang datang juga memiliki banyak varian, baik yang datang       dalam lampiran bervirus (biasanya di kompres / zip) maupun hanya link       download yang memanfaatkan fitur “drive by download”.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Breaking News dari CNN atau situs berita yang lain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Menawarkan film porno artis ternama seperti Angelina Jolie yang       dikombinasikan dengan baik sekali dengan rekayasa sosial pada situs You       Tube. Dimana file yang mengandung virus seakan-akan harus di download       sebagai codec (file yang diperlukan untuk menonton file film di You       Tube). Lihat artikel &lt;a href="http://vaksin.com/2008/0808/anjelina-jolie2/anjelina-jolie2.html"&gt;http://vaksin.com/2008/0808/anjelina-jolie2/anjelina-jolie2.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Datang dalam lampiran terkompres seperti yang terakhir ditemui       Vaksincom datang sebagai email konfirmasi pengiriman barang dari UPS yang       meminta kita mencetak invoice .doc yang sebenarnya adalah file virus       karena memiliki ekstensi ganda (ups_letter.doc.exe). Supaya lampiran ini       tidak diblok di mailserver ia di kompres terlebih dahulu dengan nama       “ups_letter.zip”. &lt;span style=""&gt; &lt;/span&gt;(lihat gambar 3)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 70.9pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" style="'width:401.25pt;height:3in'"&gt;  &lt;v:imagedata src="antivirus%20gadungan_files/image004.jpg" title="upspic"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0309/scareware/antivirus%20gadungan_files/image005.jpg" shapes="_x0000_i1027" width="535" border="0" height="288" /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 70.9pt; text-align: justify;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:group id="_x0000_s1032" style="'position:absolute;left:0;text-align:left;" coordorigin="106746675,108289725" coordsize="6804000,3648139"&gt;  &lt;v:rect id="_x0000_s1033" style="'position:absolute;left:106746675;top:108289725;" preferrelative="t" filled="f" insetpen="t" cliptowrap="t"&gt;   &lt;v:imagedata src="antivirus%20gadungan_files/image006.jpg" title="ups mail"&gt;   &lt;v:shadow color="#ccc"&gt;   &lt;v:path extrusionok="f"&gt;   &lt;o:lock ext="edit" aspectratio="t"&gt;  &lt;/v:rect&gt;&lt;v:rect id="_x0000_s1034" style="'position:absolute;left:107518200;" fillcolor="black" insetpen="t" cliptowrap="t"&gt;   &lt;v:shadow color="#ccc"&gt;   &lt;v:textbox inset="2.88pt,2.88pt,2.88pt,2.88pt"&gt;  &lt;/v:rect&gt;&lt;/v:group&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;!--[if gte vml 1]&gt;&lt;v:group id="_x0000_s1029" style="'position:absolute;left:0;text-align:left;" coordorigin="106746675,108289725" coordsize="6804000,3648139"&gt;   &lt;v:rect id="_x0000_s1030" style="'position:absolute;left:106746675;top:108289725;" preferrelative="t" filled="f" insetpen="t" cliptowrap="t"&gt;&lt;v:imagedata src="antivirus%20gadungan_files/image006.jpg" title="ups mail"&gt;&lt;v:shadow color="#ccc"&gt;&lt;v:path extrusionok="f"&gt;&lt;o:lock ext="edit" aspectratio="t"&gt;&lt;/v:rect&gt;&lt;v:rect id="_x0000_s1031" style="'position:absolute;left:107518200;" fillcolor="black" insetpen="t" cliptowrap="t"&gt;&lt;v:shadow color="#ccc"&gt;&lt;v:textbox inset="2.88pt,2.88pt,2.88pt,2.88pt"&gt;&lt;/v:rect&gt;&lt;/v:group&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 3, Cara terbaru scareware menyebarkan dirinya dengan mengirimkan dirinya sebagai lampiran melalui email.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Ada puluhan varian scareware&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Sebenarnya seberapa gawat sih masalah scareware ini dan seberapa banyak varian scareware ini ? Pada awalnya Vaksincom mengira scareware ini seperti kata pepatah “hangat-hangat tahi ayam”, paling dalam waktu beberapa bulan akan menghilang dan digantikan oleh spyware / malware lainnya. Dan varian scareware ini meskipun cukup banyak tetapi menurut perkiraan Vaksincom tidak akan melebihi belasan varian. Tetapi kenyataannya sangat mengejutkan, karena ternyata sampai saat ini sudah tedeteksi 85 scareware yang beredar di internet yang lengkap dengan infrastruktur pendukungnya seperti website dan sistem pembayaran online. Beberapa nama yang digunakan juga cukup menjebak seperti Antivirus XP 2008, Antivirus XP 2009, Vista Antivirus 2008, WinFixer, Spyware Stormer, Smart Antivirus 2008, Smart Antivirus 2009, PC-Antispyware, MS Antispyware, MS Antivirus, IE Antivirus, ID Defender, Antivirus 2008, Antivirus 2009 dan masih banyak lagi. Melihat hal ini dapat disimpulkan bahwa pembuat scareware ini cukup terorganisir,&lt;span style=""&gt;  &lt;/span&gt;profesional, ditunjang oleh back up finansial yang kuat dengan motif ekonomi dan bukan hanya melakukan hit and run seperti pembuat virus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Beberapa ciri scareware yang sedang aktif&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Beberapa ciri scareware yang saat ini sedang marak menyebar di internet adalah sebagai berikut : &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Jika komputer korbannya mendapatkan peringatan adanya malware      tetapi tidak melakukan tindakan seperti mendownload scareware yang      disarankan, maka komputer tersebut akan terus menerus mendapatkan      peringatan pop up windows yang meninformasikan adanya malware di      komputernya. Dalam beberapa kasus, bahkan komputer korban “dikerjai”      seperti drive C: dihilangkan dari Windows Explorer dan menghilangkan      folder-folder baik di harddrive lokal maupun folder sharing di jaringan      sehingga makin menambah kepanikan pengguna komputer korbannya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Scareware ini sulit di deteksi antivirus karena ia akan selalu      mengupdate dirinya dan melakukan release ulang guna mencegah deteksi      program antivirus.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Menurut pantauan Vaksincom, saat ini banyak scareware sudah mampu      menginfeksi Widnwos Vista, jadi korbannya tidak hanya terbatas pada      Windows XP / 2000 saja.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Walaupun anda sudah klik [Cancel] atau [X] untuk menutup box      dialog ketika ditanyakan apakah mau mendownload scareware, aksi yang      dilakukan TETAP akan mendownload scareware. Bahkan beberapa scareware      secara otomatis mendownloadkan dan menginstalkan dirinya ke komputer      korbannya.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Anda tidak dapat menghentikan proses download yang berlangsung,      sekalipun anda menutup browser anda karena proses download akan      berlangsung di background (tidak terlihat). Salah satu cara yang cukup      efektif untuk menghentikan download adalah menggunakan key [Alt][F4].&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Administrator jaringan di korporat dapat mempertimbangkan memblok      akses ke situs-situs download scareware seperti winfixer.com,      winantivirus.com, systemdoctor.com tetapi seperti kita ketahui jumlah      scareware yang mencapai lebih dari 80 pada saat ini dan dalam waktu      singkat akan mencapai lebih dari 100 scareware membuat proses blokir      website scareware ini sangat melelahkan. Salah satu cara yang efektif      mengatasi infeksi scareware adalah menggunakan filter jaringan yang      dipasang di router backbone internet anda seperti Norman Network Protector      yang akan melakukan scanning seluruh traffic yang masuk ke jaringan      intranet baik itu traffic http, smtp, pop maupun ftp. Dengan adanya      Network Protector ini pengguna jaringan akan terlindung dari download dan      upload scareware maupun malware tanpa perlu melakukan perubahan pada      setting komputer karena scanner ini berfungsi sebagai bridge (transparent      proxy). (lihat gambar 4)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" style="'width:458.25pt;height:136.5pt'"&gt;  &lt;v:imagedata src="antivirus%20gadungan_files/image008.jpg" title="top 20 origin"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;img src="http://vaksin.com/2009/0309/scareware/antivirus%20gadungan_files/image009.jpg" shapes="_x0000_i1028" width="611" border="0" height="182" /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 35.45pt; text-align: justify;"&gt;&lt;i style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Gambar 4, NNP yang mampu mendeteksi dan menghentikan scareware yang secara otomatis mendownload dirinya pada protokol http, smtp, pop dan ftp&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;b style=""&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Bagaimana cara menghindari dan mengatasi scareware&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Jika anda menanyakan bagaimana cara menghindari dan mengatasi scareware, jawabannya mungkin klasik. Pastikan komputer anda dilindungi program antivirus / spyware yang terupdate dan jangan sembarangan memilih antivirus yang belum anda kenal. Kalau anda paranoid hindari email html (set sebagai plain text saja) untuk mencegah kesalahan karena klik pada email html yang memicu download scareware. Jangan sembarangan menggunakan software atau scanner online yang tidak anda ketahui kompetensinya. Lakukan patch (penambalan celah keamanan) secara teratur, usahakan untuk melakukan automatic patch pada OS anda jika komputer anda memiliki hubungan ke internet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span style="font-size: 10pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Jika komputer anda sudah terinfeksi scareware, satu hal yang paling penting anda lakukan adalah “putuskan hubungan ke internet”, hal ini penting untuk mencegah scareware mengupdate dirinya. Gunakan Norman Security Suite dengan update terakhir yang bisa anda dapatkan pada DVD / CD Chip terbaru untuk membasmi scareware ini.&lt;br /&gt;&lt;br /&gt;thx to vaksin[dot]com &amp;amp; Chip&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-6509029114641834263?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/6509029114641834263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=6509029114641834263&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/6509029114641834263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/6509029114641834263'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/03/antivir-palsu.html' title='Antivir palsu'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-8899746752618458747</id><published>2009-03-23T16:35:00.000+08:00</published><updated>2009-03-23T16:36:47.978+08:00</updated><title type='text'>Virus nomor 1 di Indonesia, injeksi file exe/com/scr</title><content type='html'>&lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="center" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="center" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Kalau Conficker dapat dikatakan sebagai worm nomor satu di Indonesia, maka predikat virus yang paling merepotkan dan paling banyak ditemui Vaksincom di Indonesia pantas di sandang oleh Sality. Virus yang disinyalir  berasal dari Taiwan / Cina ini secara meyakinkan menempati ranking pertama dalam  infeksi virus yang diterima oleh Vaksincom bersama-sama dengan Conficker.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Memang menyebalkan jika semua program kita ikut dimakan oleh virus [di infeksi], disamping sulit dalam memberantas virusnya terkadang juga file yang sudah di injeksi tersebut tidak dapat digunakan alias rusak setelah di scan dan dibersihkan oleh antivirus, alhasil harus reinstall semua program yang error atau download ulang file yang sudah di injenksi tersebut.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Salah satu virus yang akan menginjeksi file exe/com/scr ini adalah W32/Sality.AE (lihat gambar 1)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;img src="http://vaksin.com/2009/0309/Sality/sality_html_3aa5c5b.png" name="graphics1" width="552" align="bottom" border="0" height="379" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 1, Norman Security Suite dapat  mendeteksi Sality.AE dengan baik&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Ukuran file yang sudah terinfeksi W32/Sality.AE akan bertambah besar beberapa KB dan file yang sudah terinfeksi W32/Sality.AE ini masih dapat di jalankan seperti biasa. Biasanya virus ini akan mencoba untuk blok program antivirus atau removal tools saat dijalankan serta mencoba untuk blok task manager atau “registry editor” Windows. Untuk mempermudah dalam proses penyebarannya selain memanfaatkan “File Sharing” dan “Default Share” virus ini juga akan memanfaatkan media Flash Disk dengan cara membuat file acak yang mempunyai ekstensi exe/com/scr/pif serta menambahkan file autorun.inf yang memungkinkan virus dapat aktif secara otomatis setiap kali user mengakses Flash Disk.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Untuk blok task manager atau Registry tools, W32/Sality.AE ini akan membuat string pada registry berikut:&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;DisableRegistryTools&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;DisableTaskMgr&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Pada saat file yang terinfeksi W32/Sality.AE, ia akan mendekrip dirinya dan mencoba untuk kopi beberapa file *.dll (acak) file DLL kemudian akan menginjeksi file lain yang aktif di memori serta file lain yang terdapat di komputer dan jaringan (file sharing) serta  menginfeksi file *.exe yang terdapat dalam list registry berikut sehingga memungkinkan virus dapat aktif secara otomatis setiap kali komputer dinyalakan.&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span style="font-style: normal;"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span style="font-style: normal;"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Berikut beberapa contoh file *.dll yang akan di drop oleh W32/Sality.AE.&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0in;" lang="en-US"&gt;  &lt;em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;C:\Windows\system32\syslib32.dll&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;i&gt;  &lt;/i&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" lang="en-US"&gt;&lt;em&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;C:\Windows\system32\oledsp32.dll&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;i&gt;  &lt;/i&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" lang="en-US"&gt;&lt;em&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;C:\Windows\system32\olemdb32.dll&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;i&gt;  &lt;/i&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" lang="en-US"&gt;&lt;em&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;C:\Windows\system32\wcimgr32.dll&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;i&gt;  &lt;/i&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0pt; margin-top: 0pt;" lang="en-US"&gt;&lt;em&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;C:\Windows\system32\wmimgr32.dll&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain membuat file DLL, sality juga akan membuat file *.sys [acak] di direktori “C:\Windows\system32\drivers” [contoh: kmionn.sys]&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" lang="en-US"&gt;    &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Blok Antivirus dan software security&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Seperti yang sudah dijelaskan di atas bahwa untuk mempermudah proses penyebaran ia juga akan mencoba untuk mematikan proses yang berhubungan dengan program security khususnya antivirus dengan cara mematikan proses yang mempunyai nama dibawah ini: &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;table width="100%" border="1" border cellpadding="4" cellspacing="0" style="color:#000000;"&gt;  &lt;col&gt;  &lt;col width="128"&gt;  &lt;tbody&gt;&lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ALG    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;InoRPC    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;aswUpdSv    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;InoRT    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;avast!    Antivirus &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;InoTask    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;avast!    Mail Scanner &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ISSVC    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;avast!    Web Scanner &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;KPF4    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;AVP&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;LavasoftFirewall    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;BackWeb    Plug-in - 4476822 &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;LIVESRV    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;bdss    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;McAfeeFramework    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;BGLiveSvc    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;McShield    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;BlackICE    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;McTaskManager    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;CAISafe    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;navapsvc    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ccEvtMgr    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NOD32krn    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ccProxy    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NPFMntor    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ccSetMgr    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NSCService    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;F-Prot    Antivirus Update Monitor &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Outpost    Firewall main module &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;fsbwsys    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;OutpostFirewall    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FSDFWD    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PAVFIRES    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;F-Secure    Gatekeeper Handler Starter &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PAVFNSVR    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;fshttps    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PavProt    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FSMA    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PavPrSrv    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PAVSRV    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Symantec    Core LC &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PcCtlCom    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Tmntsrv    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PersonalFirewal    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;TmPfw    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PREVSRV    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;tmproxy    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ProtoPort    Firewall service &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UmxAgent    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;PSIMSVC    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UmxCfg    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;RapApp    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UmxLU    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;SmcService    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UmxPol    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;SNDSrvc    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;vsmon    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;SPBBCSvc    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;VSSERV    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;WebrootDesktopFirewallDataService&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;WebrootFirewall    &lt;/span&gt;    &lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr valign="top"&gt;   &lt;td style="width: 46%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;     &lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 41%;"&gt;    &lt;p class="western" style="margin-top: 0pt; margin-bottom: 0pt;" align="justify" lang="en-US"&gt;    &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;XCOMM&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain mematikan proses antivirus di atas, ia juga akan berupaya untuk blok agar user tidak dapat mengakses web dari beberapa antivirus berikut:&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Cureit &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Drweb &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Onlinescan &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Spywareinfo &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Ewido &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virusscan &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Windowsecurity &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Spywareguide &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Bitdefender &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Panda software &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Agnmitum &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virustotal &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Sophos &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Trend Micro &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Etrust.com &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Symantec &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;McAfee &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;F-Secure &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Eset.com &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Kaspersky&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;W32/Sality.AE juga akan mencoba untuk merubah regisrty berikut:&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet  Setting\"GlobalUserOffline" = "0" &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA"  = "0"&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xxx  [xxx adalah acak, contoh : abp470n5]&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\[USER  NAME]914 &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80  &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain itu ia juga akan mencoba untuk merubah beberapa string registry Windows Firewall  berikut dengan menambahkan value dari 0 menjadi 1:&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;AntiVirusDisableNotify &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;AntiVirusOverride &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FirewallDisableNotify&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FirewallOverride &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UacDisableNotify &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UpdatesDisableNotify &lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;dan membuat key “SVC” serta string berikut dengan value 1&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;AntiVirusDisableNotify &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;AntiVirusOverride &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FirewallDisableNotify&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;FirewallOverride &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UacDisableNotify&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;UpdatesDisableNotify  &lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Tak cuma itu W32/s\Sality.AE juga akan menghapus key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ALG”.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span style="font-weight: normal;"&gt;ALG atau Application Layer Gateway Service adalah services yang m&lt;/span&gt;emberikan support untuk plug-in protokol aplikasi dan meng-enable konektivitas jaringan / protokol. Service ini boleh saja dimatikan. Dampaknya adalah program seperti MSN Messenger dan Windows Messenger tidak akan berfungsi. Service ini bisa dijalankan, tetapi hanya jika menggunakan firewall, baik firewall bawaan Windows atau firewall lain. Jika tidak komputer yang terinfeksi virus ini akan mengalami celah keamanan yang serius. &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; font-weight: normal; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Blok akses “safe mode”&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Dalam rangka “mempertahankan” dirinya, W32/Sality.AE juga akan mencoba untuk blok akses ke mode “safe mode” sehingga user tidak dapat booting pada mode “safe mode” dengan menghapus key yang berada di lokasi di bawah ini :&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot  &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Injeksi file exe/com/scr&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Tujuan utama dari virus ini adalah mencoba untuk menginjeksi program instalasi dan file yang mempunyai ekstensi exe/com/scr yang ada di drive C - Y terutama file hasil instalasi (file yang berada di direktori C:\Program Files&lt;span style="color:#000000;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="text-decoration: none;"&gt;) dan file-file portable (file yang langsung dapat dijalankan tanpa perlu instal)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, ia juga akan menginfeksi file yang mempunyai ekstensi “.exe” yang terdapat dalam list registry berikut sehingga memungkinkan virus dapat aktif secara otomatis setiap kali komputer dinyalakan.&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span style="font-style: normal;"&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;em&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span style="font-style: normal;"&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;File yang berhasil di injeksi biasanya ukurannya akan bertambah sekitar 68 - 80 KB dari ukuran semula. Program yang telah terinfeksi ini akan tetap dapat di jalankan seperti biasa sehingga user tidak curiga bahwa file tersebut sebenarnya telah di infeksi oleh W32/Sality.AE. Salah satu kecanggihan Sality adalah kemampuannya menginjeksi file tumpangannya sehingga ukuran file bervirus tidak seragam, jelas lebih sulit diidentifikasi dibandingkan virus lain yang menggantikan file yang ada sehingga ukuran filenya akan sama besar.&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Harap berhati-hati, tidak semua program antivirus dapat membersihkan file yang sudah terinfeksi W32/Sality.AE, bisa-bisa file tersebut akan rusak setelah di scan dan di bersihkan oleh antivirus tersebut.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Tidak mau kalah dengan virus mancanegara lain, untuk memperlancar aksinya ia akan mencoba untuk melakukan koneksi ke sejumlah alamat web yang sudah ditentukan dengan tujuan untuk memanggil/mendownload trojan/virus lainnya yang di sinyalir merupakan varian dari versi sebelumnya yang memungkinkan virus ini dapat mengupdate dirinya.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]pedmeo222nb.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]pzrk.ru &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]technican.w.interia.pl &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]www.kjwre9fqwieluoi.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bpowqbvcfds677.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bmakemegood24.com &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bperfectchoice1.com &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bcash-ddt.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bddr-cash.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]btrn-cash.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bmoney-frn.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bclr-cash.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]bxxxl-cash.net &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]balsfhkewo7i487fksd.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]buynvf96.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]89.119.67.154/tes[xxx] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]oceaninfo.co.kr/picas[xxx] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]kukutrustnet777.info/home[xxx] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]kukutrustnet888.info/home[xxx]  &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]kukutrustnet987.info/home[xxx]  &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]kukutrustnet777.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]www.kjwre9fqwieluoi.info &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;[http://]kjwre77638dfqwieuoi.info&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://mattfoll.eu.interia.pl/[sensor] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://st1.dist.su.lt/l[sensor]&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://lpbmx.ru/[sensor] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://bjerm.mass.hc.ru/[sensor] &lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://SOSiTE_AVERI_SOSiTEEE.[sensor]&lt;/span&gt;&lt;br /&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Mengeksploitasi Default Share dan Full Sharing&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;W32/Sality.AE akan menyebar dengan cepat melalui jaringan dengan memanfaatkkan default share windows atau share folder yang mempunyai akses full dengan cara menginfeksi file yang mempunyai ekstensi exe/com/scr. Karena itu, Vaksincom menyarankan pengguna komputer untuk menonaktifkan Default Share (C$, D$ .. dst) dan hindari Full Sharing folder anda di jaringan.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain menyebar dengan menggunakan jaringan, ia juga akan memanfaatkan flash disk yakni dengan cara kopi dirinya dengan nama file acak dengan ekstensi  exe/cmd/pif serta membuat file autorun.inf agar dirinya dapat aktif secara otomatis tanpa harus menjalankan file yang sudah terinfeksi virus, selain itu ia juga akan menginfeksi file yang mempunyai ekstensi exe/com/scr yang terdapat dalam flash disk tersebut.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain itu Sality.AE juga akan menambahkan string [MCIDRV_VER]  dan DEVICEMB=xxx, dimana xxx menunjukan karakter acak ke dalam file C:\Windows\system.ini. (lihat gambar 2 dan 3)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;img src="http://vaksin.com/2009/0309/Sality/sality_html_50b6180.png" name="graphics2" width="372" align="bottom" border="0" height="232" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 2, File system.ini sebelum di ubah oleh W32/Sality.AE&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;img src="http://vaksin.com/2009/0309/Sality/sality_html_m498b6758.png" name="graphics3" width="373" align="bottom" border="0" height="281" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 3, File system.ini setelah di ubah oleh W32/Sality.AE&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Cara membersihkan W32/Sality.AE&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Putuskan hubungan  komputer yang akan dibersihkan dari jaringan dan internet&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Matikan System Restore  selama proses pembersihan berlangsung.&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Matikan Autorun dan  Default Share. Silahkan download file berikut kemudian jalankan  dengan cara:&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Klik kanan repair.inf&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Klik install&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.4shared.com/file/82762498/f5dc1edd/repair.html?dirPwdVerified=feea1d94"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://www.4shared.com/file/82762498/f5dc1edd/repair.html?dirPwdVerified=feea1d94&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="4"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Matikan program aplikasi  yang aktif di memori agar proses pembersihan lebih cepat terutama  program yang ada dalam daftar startup.&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Sebaiknya scan dengan  menggunakan removal tools dengan terlebih dahulu merubah ekstensi  dari removal tools tersebut dengan ekstensi lain [contoh: CMD] agar  tidak di infeksi ulang oleh W32/Sality.AE. Dalam contoh di bawah,  nama file “Norman_Malware_Cleaner.exe” di rename menjadi  “Norman_Malware_Cleaner.cmd” supaya tidak di infeksi  Sality. (lihat gambar 4)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt;   &lt;p class="western" style="margin-left: 0.5in; text-indent: -0.25in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;      &lt;img alt="Rename Norman Malware Cleaner" src="http://vaksin.com/File/2009/img4.jpg" width="541" height="96" /&gt;&lt;br /&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 4, File “Norman_Malware_Cleaner.exe” yang telah di rename ekstensinya menjadi “Norman_Malware_Cleaner.cmd”, kotak biru&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.25in; text-indent: 0.25in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selalu gunakan Norman Malware Cleaner terbaru untuk membersihkan dan membasmi virus baru. Download Norman Malware Cleaner terbaru dari “&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.49in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; &lt;a href="http://download.norman.no/public/Norman_Malware_Cleaner.exe"&gt;http://download.norman.no/public/Norman_Malware_Cleaner.exe&lt;/a&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.25in; text-indent: 0.25in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;img src="http://vaksin.com/2009/0309/Sality/sality_html_m64431036.jpg" name="graphics4" width="506" border="0" height="376" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Gambar 5, Gunakan Norman Malware Cleaner untuk mendeteksi dan membasmi Sality.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Catatan:&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Agar removal tersebut  tidak terinfeksi oleh W32/Sality.AE, Sebaiknya ubah ekstensi dari  removal tools tersebut menjadi ekstensi lain [contohnya: CMD] (lihat gambar   4 di atas)&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Sality.AE ini akan  mencoba untuk menginfeksi file yang mempunyai ekstensi EXE dan SCR  serta COM, file yang sudah berulang kali di infeksi oleh virus ini  terkadang akan mengalami kerusakan jika dibersihkan oleh program  antivirus, oleh karena itu jika terdapat program yang error setelah  di scan oleh antivirus sebaiknya install ulang program tersebut.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;PENTING !!!&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Harap Backup data penting anda sebelum melakukan pembersihan virus. PT. Vaksincom tidak bertanggung jawab atas kerugian yang diakibatkan oleh proses pembersihan virus ini baik langsung maupun tidak langsung !!!&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="6"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Agar komputer yang sudah  terinfeksi W32/Sality.AE dapat booting “safe mode”,  silahkan restore registry yang sudah di ubah oleh virus.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Silahkan download file berikut kemudian jalankan sesuai OS yang terinfeksi W32/Sality.AE tersebut.&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;a href="http://www.4shared.com/file/82761423/934fb170/_2__Sality.htmldirPwdVerified=feea1d94"&gt;http://www.4shared.com/file/82761423/934fb170/_2__Sality.htmldirPwdVerified=feea1d94&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="7"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Fix registry lain yang  di ubah oleh virus, silahkan download tools berikut kemudian  jalankan file tersebut dengan cara:&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;ol&gt;&lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Klik kanan repair.inf&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Klik install&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.75in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.4shared.com/file/82762498/f5dc1edd/repair.html?dirPwdVerified=feea1d94"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;http://www.4shared.com/file/82874724/f485f1dd/repair.html?dirPwdVerified=3b1f2fa9&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="8"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Restart komputer dan  scan ulang dengan menggunakan removal tools untuk memastikan  komputer telah bersih dari virus.&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="en-US"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Untuk pembersihan  optimal dan mencegah infeksi ulang sebaiknya install dan scan dengan  antivirus yang dapat mendeteksi Sality dengan baik.&lt;/span&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;thx vaksin[dot]com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-8899746752618458747?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/8899746752618458747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=8899746752618458747&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8899746752618458747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8899746752618458747'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2009/03/virus-nomor-1-di-indonesia-injeksi-file.html' title='Virus nomor 1 di Indonesia, injeksi file exe/com/scr'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-8416431454641774293</id><published>2008-12-29T13:01:00.002+08:00</published><updated>2008-12-29T13:08:02.039+08:00</updated><title type='text'>virus "bad brother"</title><content type='html'>paste code berikut ke notepad.. kemudian save dengan nama remover.bat.. simpan ke drive C&lt;br /&gt;&lt;br /&gt;code :&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 354px; text-align: left;"&gt;del C:\windows\bad1.exe /f&lt;br /&gt;del C:\windows\bad2.exe /f&lt;br /&gt;del C:\windows\bad3.exe /f&lt;br /&gt;del C:\windows\system.exe /f&lt;br /&gt;del C:\windows\bad1.exe /a /f&lt;br /&gt;del C:\windows\bad2.exe /a /f&lt;br /&gt;del C:\windows\bad3.exe /a /f&lt;br /&gt;del C:\windows\system.exe /a /f&lt;br /&gt;&lt;br /&gt;echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;echo "NoRun"=dword:00000000&lt;br /&gt;echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;echo "NoFolderOptions"=dword:00000000&lt;br /&gt;echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]&lt;br /&gt;echo "NoFolderOptions"=dword:00000000&lt;br /&gt;echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;echo "DisableRegistryTools"=dword:00000000&lt;br /&gt;echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;echo "DisableTaskMgr"=dword:00000000&lt;br /&gt;echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;echo "DisableTaskMgr"=dword:00000000&lt;/pre&gt;&lt;br /&gt;untuk repair nya paste script di bawah ini ke notepad and save dengan repair.vbs... kemudian klik 2x&lt;br /&gt;&lt;br /&gt;code :&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 498px; text-align: left;"&gt;dim rg,std,a,b,c,t&lt;br /&gt;a = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\"&lt;br /&gt;b = "HKEY_LOCAL_MACHINE\Software\Microsoft\WIndows NT\Image File Execution Options\"&lt;br /&gt;std = chr(34) &amp;amp; "%1" &amp;amp; chr(34) &amp;amp; " %*"&lt;br /&gt;set rg=createobject("wscript.shell")&lt;br /&gt;&lt;br /&gt;t=msgbox("repair g nih????)",36,"code:darkzeus")&lt;br /&gt;if t = 6 then&lt;br /&gt;do&lt;br /&gt;sehat&lt;br /&gt;loop until i = 1&lt;br /&gt;else&lt;br /&gt;sehat&lt;br /&gt;end if&lt;br /&gt;&lt;br /&gt;sub sehat()&lt;br /&gt;&lt;br /&gt;rg.regwrite a &amp;amp; "System\DisableRegistryTools",0,"REG_DWORD"&lt;br /&gt;rg.regwrite a &amp;amp; "System\DisableTaskMgr",0,"REG_DWORD"&lt;br /&gt;rg.regwrite a &amp;amp; "System\DisableCMD",0,"REG_DWORD"&lt;br /&gt;rg.regwrite a &amp;amp; "Explorer\NoFolderOptions",0,"REG_DWORD"&lt;br /&gt;rg.regwrite b &amp;amp; "msconfig.exe\Debugger",""&lt;br /&gt;rg.regwrite b &amp;amp; "regedit.exe\Debugger",""&lt;br /&gt;rg.regwrite b &amp;amp; "cmd.exe\Debugger",""&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\.exe\","exefile"&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\.com\","comfile"&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\.bat\","batfile"&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\.lnk\","lnkfile"&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\.pif\","piffile"&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\exefile\shell\open\command\",std&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\batfile\shell\open\command\",std&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\comfile\shell\open\command\",std&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\lnkfile\shell\open\command\",std&lt;br /&gt;rg.regwrite "HKEY_CLASSES_ROOT\piffile\shell\open\command\",std&lt;br /&gt;end sub&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;semoga membantu.. thx to darkzeus @kaskus&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-8416431454641774293?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/8416431454641774293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=8416431454641774293&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8416431454641774293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8416431454641774293'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/12/virus-bad-brother.html' title='virus &quot;bad brother&quot;'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-67776591397014495</id><published>2008-12-29T12:58:00.001+08:00</published><updated>2008-12-29T13:01:38.892+08:00</updated><title type='text'>I'm four2one.virus</title><content type='html'>cara basminya&lt;br /&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;matikan koneksi inet&lt;br /&gt;&lt;/li&gt;&lt;li&gt;matikan system restore caranya ada di page 1&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Restart PC masuk Save Mode, (tekan f6 atau f8 untuk masuk ke SAVE MODE saat windows boot), Masuk Control Panel Windows, kemudian klick Mouse, Seting Mouse pada pointer speed menjadi midle untuk Basmi Virus i’m four2one&lt;br /&gt;&lt;/li&gt;&lt;li&gt;gunakan PC MAV&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pcmav.biz/" target="_blank"&gt;http://pcmav.biz/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ato ansav&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ansav.com/" target="_blank"&gt;www.ansav.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ato smadav&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.smadav.net/" target="_blank"&gt;www.smadav.net&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;setelah Clean, Restart PC Dan Biarkan Masuk Ke windows Normal&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Klik RUN, Masukkan Regedit.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Klik EDIT &gt;FIND , pastikan anda memasukkan Keyword “Please Look at me” , setelah ditemukan lakukan delete registry tersebut.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Klik EDIT+FIND ,masukkan keyword “four2one”, kemudian delete lagi.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;klo udah restart pc anda n lakukan langkah2 masalah yg terjadi setelah terkena virus (klo ansav msh eror linknya silahkan pakai smadav..cukup discan lalu pada tab infected registry value pilih select all n fix all)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;lakukan basic computer maintenance&lt;/li&gt;&lt;/ol&gt;semoga membantu,..&lt;br /&gt;thx to kocak_gober @kaskus&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-67776591397014495?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/67776591397014495/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=67776591397014495&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/67776591397014495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/67776591397014495'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/12/im-four2onevirus.html' title='I&apos;m four2one.virus'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-7715544608567061147</id><published>2008-11-03T17:21:00.004+08:00</published><updated>2008-11-10T15:12:49.583+08:00</updated><title type='text'>Tugas Metode Numerik. mission ascomplished..</title><content type='html'>download link : tugas &lt;a href="http://www.kitaupload.com/download.php?file=805test.rar"&gt;hamsir&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;masih belum selesai..&lt;br /&gt;untuk jalaninnya harus di isi dulu kolom panjang and lebar luas nya..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;link baru yg sudah jadi... &lt;a href="http://www.kitaupload.com/download.php?file=757numerik%20done.rar"&gt;download&lt;br /&gt;&lt;/a&gt;silahkan di baca² dlu...&lt;br /&gt;c'ma sempet kek gini aja nih..&lt;br /&gt;litlebit busy..&lt;br /&gt;thx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-7715544608567061147?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/7715544608567061147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=7715544608567061147&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/7715544608567061147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/7715544608567061147'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/11/tugas-metode-numerik.html' title='Tugas Metode Numerik. mission ascomplished..'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-3848402921629637383</id><published>2008-10-28T15:09:00.001+08:00</published><updated>2008-10-30T11:00:57.706+08:00</updated><title type='text'>Tips Mencegah Komputer Terinfeksi Virus dari Removable Drive</title><content type='html'>&lt;b&gt;1. Matikan Autoplay drive&lt;/b&gt;&lt;br /&gt;Windows XP Pro.&lt;br /&gt;klik start-Run and ketik “gpedit.msc” enter.&lt;br /&gt;klik group policy-user configuration-administrative templates system klik 2 kali turn off autoplay. klik enable.&lt;br /&gt;Windows Xp Home.&lt;br /&gt;karena windows Xp home tidak ada gpeditnya. jd pke software tweakUI.&lt;br /&gt;masuk ke my computer-autoplay-types. uncheck (hilangin) dua2anya.&lt;br /&gt;&lt;a href="http://download.microsoft.com/download/f/c/a/fca6767b-9ed9-45a6-b352-839afb2a2679/TweakUiPowertoySetup.exe"&gt;link download&lt;/a&gt; nya&lt;br /&gt;&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;b&gt;2. Disable Script.&lt;/b&gt;&lt;br /&gt;Berguna untuk mencegah script virus menginfeksi komputer anda. biasanya file2 tersebut berekstensi .Vbs&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img154.imageshack.us/img154/9947/noscriptdp2.jpg" alt="" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/avcenter/noscript.exe"&gt;Download Link&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;b&gt;3.Nonaktifkan Hide exstensions for known file type dari folder option.&lt;/b&gt;&lt;br /&gt;Dan set view folder anda menjadi details. agar ketahuan mana file-file yang benar -benar dokumen dan mana file-file yang hanya menyamar sebagai icon dokumen.&lt;br /&gt;Cara lain adalah mengganti icon dokumen anda menjadi icon yang unik.&lt;br /&gt;klik tools-folder option-file type-pilih DOC-advance-change icon-pilih icon yang unik yang lain daripada icon doc default. jadi anda akan tau mana file doc yang asli dengan icon baru dan mana file virus yang menyamar dengan icon microsoft word.&lt;br /&gt;lakukan hal yang sama pada file excel dan file yang sering dijadikan penyamaran oleh virus.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. Gunakan FD Guard untuk mencegah file2 virus menginfeksi komputer anda ketika memasukan flashdisk ke dalam komputer. &lt;span style="color:Red;"&gt;Amat Disarankan!!!&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;Software ini mencegah komputer tertular virus dari flashdisk dengan cara merename file" .Exe .Scr .Bat .Com .Vbs menjadi .Ex_ .Sc_ .Ba_ .Co_ .Vb_ jadi sebelum sepet nular file virusnya udah mati suri duluan.&lt;br /&gt;&lt;br /&gt;kekurangan. cuma check root drive gak sampe folder.&lt;br /&gt;dia juga ngerubah program .Exe yang di root drive walau bukan virus. tapi bisa dikembalikan dengan mengembalikan .Ex_ jadi .Exe&lt;br /&gt;jadi saran saya pindahkan software yang di root drive ke dalam folder biar gak kena juga.&lt;br /&gt;Baca Comment.txt untuk panduan penggunaan.&lt;br /&gt; &lt;a href="http://www.ansav.com/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=38&amp;amp;&amp;amp;Itemid=55"&gt;Download Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-3848402921629637383?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/3848402921629637383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=3848402921629637383&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3848402921629637383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3848402921629637383'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/tips-mencegah-komputer-terinfeksi-virus.html' title='Tips Mencegah Komputer Terinfeksi Virus dari Removable Drive'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-3840817070409195554</id><published>2008-10-28T14:59:00.002+08:00</published><updated>2008-10-28T15:00:13.045+08:00</updated><title type='text'>Mengatasi Virus MSN / WLM</title><content type='html'>Virus MSN merupakan virus yang cukup mengganggu. bila terinfeksi virus ini windows messenger anda akan mengirmkan message berupa link sebuah situs.&lt;br /&gt;&lt;div align="center"&gt;&lt;img src="http://uploadgambar.com/files/zn4jywnq9mvlogdhr5mv.jpg" alt="" border="0" /&gt;&lt;/div&gt; untuk membersihkanya ikuti langkah manual berikut:&lt;br /&gt;&lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;masuk ke control panel - Add/Remove Programs.&lt;br /&gt;Cari Toolbar888 dan klik Change/Remove  untuk membuangnya&lt;/li&gt;&lt;li&gt;Pencet CTRL+ALT+DELETE untuk membuka task manger. cari kemudian mastikan process ini dengan cara klik kanan end process.&lt;/li&gt;&lt;/ol&gt;&lt;blockquote&gt;Update.exe&lt;br /&gt;goll.exe&lt;br /&gt;loadadv455.exe&lt;br /&gt;drsmartload.exe&lt;br /&gt;goll.exe&lt;br /&gt;two.exe&lt;br /&gt;vcncr.exe&lt;br /&gt;rorjxk.exe&lt;br /&gt;eyewblbby.exe&lt;br /&gt;cgqrvrva.exe&lt;br /&gt;&lt;/blockquote&gt;&lt;b&gt;Cari dah Hapus kedua Folder ini:&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;C:Program FilesCommon Files{28676FB5-0AE9-3081-1205-03030930003d}&lt;/li&gt;&lt;li&gt;C:Program FilesCommon Files{38676FB5-0AE9-3081-1205-03030930003d}&lt;/li&gt;&lt;/ul&gt; &lt;b&gt;Cari dan Hapus File-File ini di dalam Folder C:Windows\system32\&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;goll.exe&lt;/li&gt;&lt;li&gt;drv.exe&lt;/li&gt;&lt;li&gt;loadadv455.exe&lt;/li&gt;&lt;li&gt;one.exe&lt;/li&gt;&lt;li&gt;two.exe&lt;/li&gt;&lt;/ul&gt; &lt;b&gt;Di dalam Folder: C: Documents and Settings[current user]&lt;/b&gt;&lt;br /&gt;(Current User merupakan nama account anda)&lt;br /&gt;&lt;b&gt;Cari dan Hapus File-File ini:&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;goll.exe&lt;/li&gt;&lt;li&gt;drv.exe&lt;/li&gt;&lt;li&gt;loadadv455.exe&lt;/li&gt;&lt;li&gt;one.exe&lt;/li&gt;&lt;li&gt;two.exe&lt;/li&gt;&lt;/ul&gt; &lt;b&gt;Di dalam Drive: C: Cari dan Hapus File-File ini:&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;goll.exe&lt;/li&gt;&lt;li&gt;drv.exe&lt;/li&gt;&lt;li&gt;loadadv455.exe&lt;/li&gt;&lt;li&gt;one.exe&lt;/li&gt;&lt;li&gt;two.exe&lt;/li&gt;&lt;li&gt;drsmartload.exe&lt;/li&gt;&lt;/ul&gt; Update Antivirus anda dengan update definition terbaru dan lakukan full scan. sebelum melakukan full scanning matikan dahulu sytem restore. Jika anda belum memiliki anti virus NOD32 merupakan pilihan terbaik.&lt;br /&gt;Anda mungkin perlu menginstall ulang MSN setelah membersihkan virusnya.&lt;br /&gt;Cara diatas merupakan cara manual menghilangkan virusnya. Berikut adalah removal virus MSN. silahkan download MSN Virus Removal Tool atau MSN Fix. kemudian jalankan.&lt;br /&gt;Download link 1 : &lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://dli.sharekingdom.com/download/570/MSNVRl.exe/Antivirus&lt;/pre&gt; &lt;/div&gt; Download Link 2 : &lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://www.mediafire.com/?m1xvtyjmjgt&lt;/pre&gt; &lt;/div&gt;  &lt;div align="center"&gt;&lt;img src="http://uploadgambar.com/files/rv9x3hwglo9mmndu8o3u.jpg" alt="" border="0" /&gt;&lt;/div&gt; MSN Fix.&lt;br /&gt;Download link 1 : &lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://dli.sharekingdom.com/download/570/MSNFix.zip/Antivirus&lt;/pre&gt; &lt;/div&gt; Download Link 2 : &lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://www.mediafire.com/?oklluhvxnxt&lt;/pre&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-3840817070409195554?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/3840817070409195554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=3840817070409195554&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3840817070409195554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3840817070409195554'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/kocakgober-is-just-really.html' title='Mengatasi Virus MSN / WLM'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-3300709417284036832</id><published>2008-10-28T14:58:00.001+08:00</published><updated>2008-10-28T14:58:23.530+08:00</updated><title type='text'>Mengatasi virus kavo, kvxo-menyebabkan ym error, exit sendiri dan tidak bisa login</title><content type='html'>&lt;div class="alt2" style="border: 1px inset ; margin: 0px; padding: 6px;"&gt; &lt;div style=""&gt;&lt;br /&gt;&lt;span style="color:black;"&gt;Pernahkah ym anda exit sendiri ketika anda mecoba sign in id yahoo. atau keluar pesan error. bisa dipastikan anda tekena virus kavo.&lt;/span&gt;&lt;br /&gt; Cara menghilangkannya: &lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt;Putuskan koneksi internet anda.&lt;/li&gt;&lt;li&gt;Matikan system restore, klik kanan my computer-properties-system restore-turn off system restore on all hard drive&lt;/li&gt;&lt;li&gt;Download removalnya.&lt;/li&gt;&lt;li&gt;Klik 2 kali file kavo_killer.exe&lt;/li&gt;&lt;li&gt;Klik gambar monsternya.&lt;/li&gt;&lt;li&gt;Klik OK.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Atau menggunakan kxvo fix. klik dua kali file Kxvo -fix.exe klik delete.&lt;br /&gt;  &lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://www.indowebster.com/Kavo_Removal.html&lt;/pre&gt; &lt;/div&gt; &lt;/div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-3300709417284036832?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/3300709417284036832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=3300709417284036832&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3300709417284036832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/3300709417284036832'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/mengatasi-virus-kavo-kvxo-menyebabkan.html' title='Mengatasi virus kavo, kvxo-menyebabkan ym error, exit sendiri dan tidak bisa login'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-7511069031407641993</id><published>2008-10-28T14:56:00.000+08:00</published><updated>2008-10-28T14:57:34.147+08:00</updated><title type='text'>virus ym</title><content type='html'>Trojan / virus ini amat menyebalkan karen secara terus menerus dalam interval waktu tertentu mengirimkan message dalam bahasa vietnam ke contact list kita.&lt;br /&gt; &lt;div align="center"&gt;&lt;img src="http://www.imagetitan.info/files/zyzmwwtaz0yunzmxnxme.jpg" alt="" border="0" /&gt;&lt;/div&gt; &lt;ol style="list-style-type: decimal;"&gt;&lt;li&gt; Tutup Browser anda. Log out     messenger / Putuskan koneksi internet.&lt;/li&gt;&lt;li&gt;Untuk mengaktifkan Fungsi regedit yang telah didisable virusKlik Start, Run and ketik perintahdibawah ini: (Tinggal copy – paste)REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies System /v DisableRegistryTools /t REG_DWORD /d 0 /f&lt;/li&gt;&lt;li&gt;Untuk Mengaktifkan Task Manager yang didisable virus: (Untuk menghilangkan procces kita memerlukan task manager, bisa juga menggunakan software lain)Klik Start, Run and ketik perintahdibawah ini: (Tinggal copy – paste)&lt;br /&gt;REG add     HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies  System /v     DisableTaskMgr /t REG_DWORD /d 0 /f&lt;/li&gt;&lt;li&gt;Sekarang kita rubah default page Internet Expplorer melalui     regedit.&lt;br /&gt;Start&gt;Run&gt; ketik Regedit&lt;br /&gt;Dari lokasi dibawah ini ganti default home pagenya dengan google.com atau kosongkan HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerMain&lt;br /&gt; HKEY_ LOCAL_MACHINESOFTWAREMicrosoftInternet     ExplorerMain&lt;br /&gt; HKEY_USERSDefaultSoftwareMicrosoftInternet     ExplorerMain&lt;/li&gt;&lt;li&gt;Hentikan Process virusnya dengan menekan Ctrl + Alt + Del&lt;br /&gt;End task process svhost32.exe . ( kemungkinan lebih dari     satu-periksa dengan teliti)&lt;/li&gt;&lt;li&gt;Delete file svhost32.exe , svhost.exe dari folderWindows/ &amp;amp; temp/ directories. Atau gunakan fasilitas search windows explorer.&lt;/li&gt;&lt;li&gt;Masuk regedit cari dah delete key svhost yang ditemukan&lt;/li&gt;&lt;li&gt;Restart komputer anda dan komputer anda sudah bersih dari trojan / virus ini.&lt;/li&gt;&lt;/ol&gt; berikut adalah removal untuk menghilangkan trojan/virus&lt;br /&gt; Download link : &lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://dli.sharekingdom.com/download/570/RVY.vbs/Antivirus&lt;/pre&gt; &lt;/div&gt;bia tidak berhasil gunakan Norman mallware remover.&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://download.norman.no/public/Norman_Malware_Cleaner.exe&lt;/pre&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-7511069031407641993?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/7511069031407641993/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=7511069031407641993&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/7511069031407641993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/7511069031407641993'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/virus-ym.html' title='virus ym'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-8321047983819805676</id><published>2008-10-28T11:08:00.003+08:00</published><updated>2008-10-28T11:08:56.121+08:00</updated><title type='text'>Mengatasi Search option yang hilang</title><content type='html'>Pernah mengalami search option tidak muncul, yang ada cuma animated screen character saja. kemungkinan besar adalah adanya perubahan pada registry anda yang disebabkan oleh virus. &lt;img src="http://img100.imageshack.us/img100/8440/clipboard01pe2.jpg" alt="" border="0" /&gt;&lt;br /&gt;Untuk mengtasinya. lakukan hal berikut.&lt;br /&gt;Klik Start - Run&lt;br /&gt;ketik regsvr32 wshom.ocx enter&lt;br /&gt;ketik regsvr32 jscript.dll enter&lt;br /&gt;ketik regsvr32 urlmon.dll enter&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-8321047983819805676?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/8321047983819805676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=8321047983819805676&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8321047983819805676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/8321047983819805676'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/mengatasi-search-option-yang-hilang.html' title='Mengatasi Search option yang hilang'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-5964099613162639505</id><published>2008-10-28T11:08:00.001+08:00</published><updated>2008-10-28T11:08:37.289+08:00</updated><title type='text'>Harddisk / Flashdisk Tidak bisa di klik 2x (muncul open with, error message)</title><content type='html'>wah ga bsa di dobel klik nih FD nya...&lt;br /&gt;"can't find *bla-bla-bla* .dll"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pilih salah satu langkah berikut. tidak perlu semuanya dijalankan.&lt;br /&gt;&lt;br /&gt;1. Klik kanan hardisk-properties-tools-check now- klik automatically fix file system errors-klik start.&lt;br /&gt;&lt;br /&gt;2. Klik tools-folder option-view. klik show hidden files and folder. Hilangkan hide protected operating system file (recomended)&lt;br /&gt;cari file autorun.inf di semua drive dan hapus.&lt;br /&gt;&lt;br /&gt;3. Gunakan Flash Disinfector&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe&lt;/pre&gt; &lt;/div&gt;Untuk menghindari terinfeksi virus dari removable drive sebaiknya Matikan autoplay drive. Lihat #5 &lt;b&gt;&lt;span style="color:Red;"&gt;Tips Mencegah Komputer Terinfeksi Virus dari Removable Drive&lt;/span&gt;&lt;/b&gt; untuk lebih jelasnya.&lt;br /&gt;&lt;br /&gt;Tambahan, bila anda mengklik 2x drive anda kemudian terbuka di new windows, maka gunakan cara ini agar ketika drive diklik 2 x akan terbuka di windows yang sama.&lt;br /&gt;masuk regedit (klik start-run ketik regedit) masuk ke&lt;br /&gt;&lt;b&gt;HKEY_CLASSES_ROOT/Drive/Shell.&lt;br /&gt;&lt;/b&gt;di sebelah kanan klik 2 &lt;b&gt;(default)&lt;/b&gt; isinya harus &lt;b&gt;none&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-5964099613162639505?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/5964099613162639505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=5964099613162639505&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/5964099613162639505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/5964099613162639505'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/harddisk-flashdisk-tidak-bisa-di-klik.html' title='Harddisk / Flashdisk Tidak bisa di klik 2x (muncul open with, error message)'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-2632724329043106724</id><published>2008-10-28T11:07:00.000+08:00</published><updated>2008-10-28T11:08:09.612+08:00</updated><title type='text'>YM ga nongol tulisannya.. ?</title><content type='html'>jund: kmu dimana ?&lt;br /&gt;someone : apa ?&lt;br /&gt;jund: z.z.z. dimana kamu&lt;br /&gt;someone: ga muncul tulisanmu jund... &lt;a href="http://www.xtremenitro.org/" title="Friendster Smiley - MySpace Emoticons - Multiply Smiley"&gt;&lt;img src="http://cinta.kaskusradio.com/onion/smiley/blsh3.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;jund: wew...&lt;br /&gt;&lt;br /&gt;jadi inget temen yang sempet reinstal o/s gara² kek gini.. &lt;a href="http://www.xtremenitro.org/" title="Friendster Smiley - MySpace Emoticons - Multiply Smiley"&gt;&lt;img src="http://cinta.kaskusradio.com/onion/smiley/nyahaha.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;berikut langkah-langkah untuk mengatasi hal tersebut.&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt; &lt;div align="left"&gt;&lt;br /&gt;Klik Start - Run&lt;br /&gt;ketik &lt;b&gt;regsvr32 wshom.ocx &lt;/b&gt;enter&lt;br /&gt;ketik &lt;b&gt;regsvr32 jscript.dll&lt;/b&gt; enter&lt;br /&gt;ketik &lt;b&gt;regsvr32 urlmon.dll&lt;/b&gt; enter&lt;br /&gt;ketik &lt;b&gt;regsvr32 c:\Windows\System32\vbscript.dll&lt;/b&gt; enter&lt;br /&gt;&lt;/div&gt; &lt;div align="left"&gt;&lt;br /&gt;Bila tidak berhasil download script berikut ini. kemudian install di komputer anda. terus restart.&lt;/div&gt; &lt;div align="left"&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://dli.sharekingdom.com/download/570/Scripten%20WinXP.exe/Antivirus&lt;/pre&gt; &lt;/div&gt;&lt;/div&gt; &lt;div align="left"&gt;Kemudian Klik Start - Run&lt;/div&gt; &lt;div align="left"&gt;ketik regsvr32 c:\Windows\System32\vbscript.dll Enter.&lt;br /&gt;atau download ini.&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;  &lt;div class="smallfont" style="margin-bottom: 2px;"&gt;Code:&lt;/div&gt;  &lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://imac-252a.stanford.edu/programs/VBscript/scripten.exe&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-2632724329043106724?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/2632724329043106724/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=2632724329043106724&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2632724329043106724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2632724329043106724'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/10/ym-ga-nongol-tulisannya.html' title='YM ga nongol tulisannya.. ?'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-1277765826995945387</id><published>2008-09-24T15:37:00.001+08:00</published><updated>2008-09-24T15:39:43.218+08:00</updated><title type='text'>watch out...</title><content type='html'>&lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="center"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;-= GoldenGhost Was Here =-&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="center" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_m49a896f3.jpg" name="graphics12" width="533" align="bottom" border="0" height="157" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; text-align: center; font-size: x-small; font-family: Arial; margin-top: 0pt;" lang="id-ID"&gt; &lt;span lang="en-us"&gt;&lt;em&gt;Hasil copy / paste teks komputer terinfeksi akan  digantikan dengan desahan&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; text-align: center; margin-top: 0pt;" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Kalau Hellboy dalam pertarungannya menyelamatkan bumi harus menghadapi Pasukan Emas (Golden Army), maka pengguna internet Indonesia tanpa bantuan Hellboy harus menghadapi Hantu Emas (Golden Ghost). Bagi anda yang terinfeksi virus ini, harap berhati-hati karena ia akan merubah default page browser Internet Explorer ke &lt;a href="http://www.playboy.com/"&gt;www.playboy.com&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Saat ini virus lokal bukan saja sekedar membuat file duplikat, menyembunyikan file atau injeksi file data (Ms. Office) tetapi sudah sampai menginjeksi file executable (exe file) walaupun file yang diserang masih sebatas single file (bukan hasil file instalasi) media penyebarannya pun sudah semakin canggih bukan saja melalui media Flash Disk atau jaringan tetapi sudah menggunakan aplikasi email atau media chating seperti IRC walaupun virus lokal seperti ini masih jarang tetapi ini merupakan kemajuan yang sangat pesat.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Setelah kemunculan virus Maxtrox yang sempat membuat panik end user karena menyebabkan semua program  tidak dapat dijalankan, kini muncul jenis virus baru yang sedang mengintai para mengguna komputer.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virus ini mempunyai target akan menginjeksi file executable (exe) dan Norman Security Suite   sudah dapat memperbaiki file yang sudah di injeksi tersebut.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;Ciri-Ciri Virus&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Ciri-ciri  yang mudah dikenali dari virus ini adalah munculnya pesan error  “16 bit MS-DOS Subsystem” pada saat komputer dinyalakan.  (lihat gambar 1)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_m5d33d257.png" name="graphics1" width="402" align="bottom" border="0" height="124" /&gt;&lt;/p&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 1, Pesan error saat komputer dinyalakan&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="2"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Merubah nama pemilik dan  nama Organisasi komputer manjadi (lihat gambar 2)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - RegisteredOrganization = GoldenGhost.Inc&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - RegisteredOwner = GoldenGhost&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_786f0c25.png" name="graphics2" width="274" align="bottom" border="0" height="313" /&gt;&lt;/p&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;&lt;span lang="id-ID"&gt;Gambar 2, Nama pemilik Windows yang sudah diubah virus&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="3"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Menambahkan  string -= GoldenGhost Was Here =- pada file C:\Boot.ini sehinga pada  saat booting Windows akan muncul menu tambahan dengan nama  &lt;i&gt;GoldenGhost  Was Here =- (lihat gambar  3)&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_mb77b5d9.png" name="graphics3" width="504" align="bottom" border="0" height="281" /&gt;&lt;/p&gt; &lt;p class="western" style="text-indent: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 3, Menu tambahan saat komputer booting&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Virus ini dibuat menggunakan program bahasa Visual Basic dan dikompres menggunakan UPX, ukuran Virus ini cukup besar sekitar 1,312 KB. Untuk mengelabui user ia akan menggunakan icon “Windows media player”. (lihat gambar 4)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_m7d2e6c28.png" name="graphics4" width="416" align="bottom" border="0" height="35" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 4, File induk W32/Agent.GYMR&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Dengan update terbaru Norman Security Suite mendeteksi virus ini dengan nama W32/Agent.GYMR (lihat gambar 5)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;&lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_273cfbac.jpg" name="graphics6" width="554" align="bottom" border="0" height="404" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;&lt;span lang="id-ID"&gt;Gambar 5, Norman Security Suite mendeteksi GoldenGhost sebagai W32/Agent.GYMR&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;File induk W32/Agent.GYMR&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Pada saat file virus di jalankan ia akan membuat beberapa file induk yang akan dijalankan setiap kali komputer  dihidupkan/restart di lokasi berikut:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;C:\Windows\%folder%\%file%.exe  (acak)&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;C:\Windows\system32\%folder%\%file%.exe  (acak)&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_4948348b.gif" name="Frame1" alt="Frame1" width="510" height="130" hspace="12" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Berikut beberapa nama file yang akan di buat (acak)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;devil.ocx&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;pluto.ocx&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;capiw.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;dusiw.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;gexuw.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;GoldenGhost.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;mamuv.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ridec.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;msvbvm60.dll&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;heluh.exe &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;muxim.exe &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;quniw.exe &lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;gutum.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;helef.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;kabuh.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;mideg.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;tixec.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;vuvey.exe&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Autostart Registry&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Agar file tersebut dapat dijalankan secara otomatis, ia akan membuat string pada registry berikut:&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;GoldenGhost   =C:\%SystemRoot%\%Folder%\%File%.exe atau    C:\%Windir%\folder%\%Files%.exe&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;  &lt;/li&gt;&lt;li value="1"&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows  NT\CurrentVersion\Winlogon&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Shell   = Explorer.exe C:\%SystemRoot%\%Folder%\%File%.exe atau    C:\%Windir%\folder%\%Files%.exe&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Blok Fungsi Windows&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Untuk mempertahankan dirinya ia akan blok beberapa fungsi windows seperti:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable fungsi “paste”&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable run&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable Searh&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable FolderOptions&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable menu Recent  Documents&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disble Klik kanan&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Disable  CMD&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable RegistryTools&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Disable TaskMgr&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Tidak dapat menampilkan  file yang disembunyikan&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Untuk melakukan hal tersebut ia akan membuat string pada registry berikut:&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Hidden = 2&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HideFileExt = 1&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ShowSuperHidden= 0&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li value="1"&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Explorer = NoClose&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoFInd&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoFOlderOption&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoRecentDocsMenu&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoRUn&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoSaveSettings&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoSetFolders&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoTrayContextMenu&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;NoViewContextMenu&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;li value="1"&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;DisableCMD&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;DisableRegistryTools&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;DisableTaskMgr&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;type = -&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;type = -&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;type = -&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virus ini juga akan membuat sting pada registri berikut :&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\GoldenGhost.A&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - AppAll = tupin.exe (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - AppMirc = heluh.exe (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - AppOther = quniw.exe (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - AppSetan = gutum.exe (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - AppUtama = muxim.exe (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - Lokasi = C:\WINDOWS\System32\config (random)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain blok fungsi Windows di atas, ia juga akan mencoba untuk blok tools security seperti proceexp, curr preoces, pocket killbox, security task manager serta tools lainnya.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Hapus file program antivirus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Selain itu ia juga akan mencoba untuk menghapus file dari program antivirus Norman Virus Control, Kaspersky dan McAfee yang mempunyai ekstensi *.exe, *.zip, *.dll. &lt;/span&gt;&lt;/span&gt; &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;Merubah informasi Windows&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Untuk menunjukan eksistensinya ia akan merubah nama pemilik Windows menjadi&lt;/span&gt; &lt;span lang="id-ID"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;- RegisteredOrganization = GoldenGhost.Inc&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - RegisteredOwner = GoldenGhost&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Dengan merubah string pada registry berikut:&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - RegisteredOrganization = GoldenGhost.Inc&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - RegisteredOwner = GoldenGhost&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - DefCompany = GoldenGhost.Inc&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - DefName = GoldenGhost&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_USERS\S-1-5-21-2025429265-527237240-725345543-1003\Software\Microsoft\MS Setup (ACME)\User Info"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - DefCompany = GoldenGhost.Inc&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 40px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - DefName =  GoldenGhost&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;(lihat gambar 2 di atas)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Mengakses Playboy dan mengeluarkan &lt;span lang="en-us"&gt;teks nakal&lt;/span&gt; saat copy and paste&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Selain merubah nama pemilik Windows, ia juga akan merubah alamat utama Internet Explorer menjadi  &lt;/span&gt;&lt;/span&gt;&lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.playboy.com/"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;http://www.playboy.com/&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt; dengan terlebih dahulu membuat string pada registry berikut:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - Start Page = http://www.playboy.com/&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Host file windows juga tak luput dari serangan virus ini yakni dengan manghapus isi dari file “C:\Windows\System32\Drivers\etc\host”. Selain menghapus isi file Host tersebut ia juga akan menambahkan string &lt;b&gt;@echo off&lt;/b&gt; pada file “C:\autoexec.bat” dan menambahkan string &lt;b&gt;-= GoldenGhost Was Here =-&lt;/b&gt; pada file “C:\boot.ini” sehingga setiap kali komputer booting akan muncul satu menu tambahan dengan nama &lt;b&gt;GoldenGhost Was Here =-, &lt;/b&gt;jika menu ini dipilih maka komputer akan restart. (lihat gambar 3 di atas)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Merubah hasil Copy and Paste teks menjadi desahan&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virus ini juga akan menampilkan text &lt;i&gt;Oohhh... Aughhhh... yess... babbby...!!&lt;/i&gt; setiap kali user copy paste isi text file. (lihat gambar 6 dan 7)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_5127a40d.jpg" name="graphics5" width="554" align="bottom" border="0" height="194" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 6, Teks yang di [copy] adalah “The type of the file system is FAT”&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_m49a896f3.jpg" name="graphics13" width="555" align="bottom" border="0" height="168" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;&lt;span lang="id-ID"&gt;Gambar 7, Hasil [paste] yang seharusnya “The type of the file system is FAT” dirubah menjadi desahan “Oohhh ... Aughhhh... yess... babbby”&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;Membuat file duplikat dan menginjeksi EXE file&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Virus ini juga akan membuat file duplikat disetiap folder yang di akses sesuai dengan nama folder tersebut atau sesuai dengan caption text dari suatu file / aplikasi yang dijalankan. (lihat gambar 8)&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_34ff677.png" name="graphics8" width="431" align="bottom" border="0" height="194" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 8, File duplikat yang dibuat oleh virus&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Selain membuat file duplikat, virus ini juga akan mencoba untuk menginjeksi file yang mempunyai ekstensi EXE, ukuran file yang berhasil di injeksi ini akan bertambah sekitar 1.312 KB dari ukuran semula, sehingga jika user menjalankan file tersebut maka secara otomatis akan menjalankan dirinya, dengan update terbaru Norman Security Suite sudah dapat memperbaiki setiap file yang di injeksi.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;“&lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;Error 16 bit MS-DOS Subsystem”&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Setiap kali komputer dinyalakan virus ini akan memunculkan pesan “&lt;b&gt;error 16 bit MS-DOS Subsystem&lt;/b&gt;”, pesan error ini juga akan mucul setiap berapa menit sesuai dengan waktu yang sudah ditentukan serta membuat file duplikat (random) di direktori “C:\Windows”&lt;b&gt; &lt;/b&gt;yang kemudian&lt;b&gt; &lt;/b&gt;file yang sudah&lt;b&gt; &lt;/b&gt;dibuat tersebut   akan dihapus kembali.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Media penyebaran&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Virus ini akan berusaha untuk join kesejumlah channel IRC seperti Surabaya, Jakarta, Medan, Bandung, Jogja, Malang, Solo, Sembarang dengan menggunakan aplikasi chat IRC dengan terlebih dahulu melakukan koneksi ke salah satu server IRC berikut punch.va.us.dal.net, rumble.fl.us.dal.net, mozilla.se.eu.dal.net, swiftco.wa.us.dal.net, haarlem.nl.eu.undernet.org dan plasa.id.allnetwork.org dalam rangka menyebarkan dirinya.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Berikut beberapa pesan yang akan dikirimkan :&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;nick, free picture  indonesia sex double klik url&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;nick Ada info baru ne  Marshanda, Agnes Monica, Dian Sastro, Bunga.C Dah Berani Bugil,  Untuk liat Fotonya double klik url&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;artis indonesia nude,  double klik url&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;nick , indo artis  majalah playboy double klik url&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;nick mo liat artis  majalah playboy indo&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;nick indonesia free  porn, double klik url&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;ce bangsa indo, double  klik&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Karena itu, para pengguna IRC harap berhati-hati dan jangan mudah percaya janji-janji gombal yang menyebar di IRC. Mengharapkan gambar, anda malah akan mendapatkan virus.&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Selain menyebar dengan menggunakan media chating (IRC), ia juga akan menggunakan flash disk sebagai media penyebaran dirinya dengan membuat file duplikat dengan ciri-ciri:&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Icon Windows Media   Player&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Ukuran 1.312 KB&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Ekstensi EXE&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Type File “Application”&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;b&gt;Menghapus file pada flash disk&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Aksi terakhir yang dilakukan adalah mencoba untuk menghapus file yang mempunyai ekstensi &lt;b&gt;*.mov,*.wmv, *.3gp, *.avi, *.mpg, *.mpeg&lt;/b&gt; pada drive &lt;b&gt;E:\&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;&lt;span lang="id-ID"&gt;Cara membersihkan W32/Agent.GYMR&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Matikan  proses virus. Untuk mempercepat proses penghapusan gunakan tools  “Ice Sword”. Blok proses yang mempunyai icon Windows  Media Player kemudian klik kanan pada proses tersebut dan klik  “Terminate Process”. Silahkan download tools tersebut di  alamat berikut : (lihat gambar 9)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;a href="http://www.4shared.com/file/62289467/cf8da562/Ice_Sword_v122.html?dirPwdVerified=feea1d94"&gt;http://www.4shared.com/file/62289467/cf8da562/Ice_Sword_v122.html?dirPwdVerified=feea1d94&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_3897532e.jpg" name="graphics9" width="554" align="bottom" border="0" height="460" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Gambar 9, Gunakan program Ice Sword untuk menghentikan proses virus &lt;/span&gt; &lt;/p&gt; &lt;ol start="2"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Repair  registry yang sudah di ubah / dibuat oleh virus. Untuk mepercepat  perbaikan registri salin script dibawah ini pada program "notepad"  kemudian simpan dengan nama "repair.vbs" kemudian jalankan  file tersebut dengan klik 2x file repair.vbs.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Dim oWSH: Set oWSH = CreateObject("WScript.Shell")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;on error resume Next&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command\","""%1"" %*"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command\","""%1"" %*"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command\","""%1"" %*"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command\","""%1"" %*"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\Software\CLASSES\scrfile\shell\open\command\","""%1"" /S"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell","cmd.exe"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell","cmd.exe"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\AlternateShell","cmd.exe"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell","cmd.exe"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell","Explorer.exe"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\system",""&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization","Your Organization"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner","YourOwner"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page","about:Blank"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\type","Group"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt\type","checkbox"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.Regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\type","checkbox"&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\GoldenGhost")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsMenu")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Nofind")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools")&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;oWSH.RegDelete("HKEY_LOCAL_MACHINE\SOFTWARE\GoldenGhost.A\")&lt;/span&gt;&lt;/p&gt; &lt;ol start="3"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Hapus  file induk dan file duplikat virus. Untuk mempercepat proses  penghapusan gunakan search windows dengan terlebih dahulu  menampilkan file yang tersembunyi. Jika folder option dan search  belum muncul restart / logoff komputer terlebih dahulu. (lihat  gambar 10)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_326d952f.png" name="graphics10" width="386" align="bottom" border="0" height="468" /&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;i&gt;Gambar 10, Menampilkan file yang tersembunyi&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Setelah file ditemukan, hapus file yang mempunyai ukuran 1,312 KB. selain itu hapus juga file :&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; text-indent: 0.05in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 80px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - devil.ocx = 1 KB&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 80px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - pluto.ocx = 1 KB&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 80px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; - GoldenGhost.exe =1 KB&lt;/span&gt;&lt;/p&gt; &lt;ol start="4"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Hapus  string &lt;b&gt;@echo off&lt;/b&gt;  pada file [C:\Autoexec.bat]&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Hapus  string  &lt;b&gt;-= GoldenGhost Was Here =-&lt;/b&gt;   pada file [C:\boot.ini]&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Restore  Host File Windows dengan menggunakan tools  Hoster. &lt;/span&gt;&lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-left: 0.25in; text-indent: 0.25in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Silahkan download tools tersebut di alamat berikut:&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.4shared.com/file/62290120/73265114/HostsXpert.html?dirPwdVerified=feea1d94"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;http://www.4shared.com/file/62290120/73265114/HostsXpert.html?dirPwdVerified=feea1d94&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Untuk merestore host file windows, klik tombol "Restore MS Host File " pada tools HosterExpert tersebut. (lihat gambar 9)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 80px; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;&lt;img src="http://vaksin.com/2008/0908/goldenghost/goldenghost_html_7dcd42a.png" name="graphics11" width="492" align="bottom" border="0" height="411" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-left: 80px; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt; &lt;i&gt;Gambar 11, Mengembalikan Host File Windows dengan Hoster&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;ol start="7"&gt;&lt;li&gt;  &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt;  &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Jika  menggunakan antivirus Norman / Mcafee / Kaspersky sebaiknya install  ulang antivirus tersebut kemudian scan komputer untuk  memastikan  komputer benar-benar bersih dari virus. Bagi pengguna Norman yang  membutuhkan support untuk masalah antivirus anda, silahkan hubungi  &lt;a href="mailto:support@vaksin.com"&gt;support@vaksin.com&lt;/a&gt; untuk  mendapatkan bantuan dari teknisi Vaksincom (gratis) dengan  menunjukkan Kartu Lisensi.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;b&gt;Norman Virus Contol disinfected W32/Agent.GYMR&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;Update terbaru Norman Security Suite sudah dapat memperbaiki setiap file yang diinjeksi oleh W32/Agent.GYMR. Silahkan download antivirus Noman atau removal tools berikut.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Download antivirus   Norman&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.norman.com/Download/Trial_versions/"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;http://www.norman.com/Download/Trial_versions/&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;ul&gt;&lt;li value="1"&gt;   &lt;p class="western" style="margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;   &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;Download removal tools&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify"&gt; &lt;span style="color:#0000ff;"&gt;&lt;u&gt;&lt;a href="http://www.4shared.com/file/63315440/4932579b/AgentGYMR_Cleaner.html?dirPwdVerified=feea1d94"&gt; &lt;span style="font-family:Arial, sans-serif;font-size:85%;"&gt;&lt;span lang="id-ID"&gt;http://www.4shared.com/file/63315440/4932579b/AgentGYMR_Cleaner.html?dirPwdVerified=feea1d94&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt; &lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;sumber vaksin.com&lt;/p&gt;&lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="western" style="margin-left: 0.5in; margin-bottom: 0in; margin-top: 0pt;" align="justify" lang="id-ID"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-1277765826995945387?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/1277765826995945387/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=1277765826995945387&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/1277765826995945387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/1277765826995945387'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/09/watch-out.html' title='watch out...'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-2877292337369961681</id><published>2008-07-25T10:44:00.000+08:00</published><updated>2008-07-25T10:46:26.762+08:00</updated><title type='text'>Oprek o/s XP</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;b&gt;1. Memperbaiki Instalasi (Repair Install)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jika Windows XP Anda rusak (corrupted) dimana Anda tidak mempunyai sistem operasi lain untuk booting,&lt;br /&gt;Anda dapat melakukan perbaikan instalasi (Repair Install) yang bekerja sebagaimana setting (pengaturan)&lt;br /&gt;yang awal.&lt;br /&gt;&lt;br /&gt;- Pastikan Anda mempunyai kunci (key) Windows XP yang valid.&lt;br /&gt;- Keseluruhan proses akan memakan waktu kurang lebih 1/2 atau 1 jam, tergantung spek komputer Anda.&lt;br /&gt;- Jika Anda dimintai password administrator, sebaiknya Anda memilih opsi perbaikan (repair) yang kedua,&lt;br /&gt;  bukan yang pertama.&lt;br /&gt;- Masukkan CD Windows XP Anda dan lakukan booting dari CD tersebut.&lt;br /&gt;- Ketika sudah muncul opsi perbaikan kedua R=Repair, tekan tombol R&lt;br /&gt;  Ini akan memulai perbaikan.&lt;br /&gt;- Tekan tombol F8 untuk menyetujui proses selanjutnya "I Agree at the Licensing Agreement"&lt;br /&gt;- Tekan tombol R saat direktori tempat Windows XP Anda terinstal. Biasanya C:\WINDOWS&lt;br /&gt;  Selanjutnya akan dilakukan pengecekan drive C: dan mulai menyalin file-file.&lt;br /&gt;  Dan secara otomatis restart jika diperlukan. Biarkan CD Anda dalam drivenya.&lt;br /&gt;- Berikutnya Anda akan melihat sebuah gambar "progress bar" yang merupakan bagian dari perbaikan,&lt;br /&gt;  dia nampak seperti instalasi XP normal biasanya, meliputi "Collecting Information, Dynamic Update,&lt;br /&gt;  Preparing Installation, Installing Windows, Finalizing Installation".&lt;br /&gt;- Ketika ditanya, klik tombol Next&lt;br /&gt;- Ketika ditanya untuk memasukkan kunci, masukkan kunci (key) Windows XP Anda yang valid.&lt;br /&gt;- Normalnya Anda menginginkan tetap berada dalam nama Domain atau Workgroup yang sama.&lt;br /&gt;- Komputer akan restart.&lt;br /&gt;- Kemudian Anda akan mempunyai layar yang sama sebagaimana pengaktifan sistem ketika instalasi normal.&lt;br /&gt;- Register jika Anda menginginkannya (biasanya tidak diperlukan).&lt;br /&gt;- Selesai&lt;br /&gt;&lt;br /&gt;Sekarang Anda bisa log in dengan account Anda yang sudah ada.&lt;br /&gt;&lt;br /&gt;________________________________________ _______________________ ________________________________________ _______________________&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. NTOSKRNL Rusak atau Hilang (Missing or Corrupt)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jika Anda mendapati pesan error bahwa "NTOSKRNL not found" / NTOSKRNL tak ditemukan, lakukan:&lt;br /&gt;- Masukkan CD Windows XP dan booting dari CD tersebut.&lt;br /&gt;- Pada saat muncul opsi R=Repair yang pertama, tekan tombol R.&lt;br /&gt;- Tekan angka sesuai dengan lokasi instalasi Windows yang ingin diperbaiki yang sesuai.&lt;br /&gt;- Biasanya #1&lt;br /&gt;- Pindahlah ke drive CD Drive Anda berada.&lt;br /&gt;- Tulis: CD i386&lt;br /&gt;- Tulis: expand ntkrnlmp.ex_ C:\Windows\System32\ntoskrnl.exe&lt;br /&gt;- Jika Windows XP Anda terinstal di tempat lain, maka ubahlah sesuai dengan lokasinya.&lt;br /&gt;- Keluarkan CD Anda dan ketikkan EXIT&lt;br /&gt;&lt;br /&gt;________________________________________ _______________________ ________________________________________ _______________________&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. HAL.DLL Rusak atau Hilang (Missing or Corrupt)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jika Anda mendapatkan error berkenaan dengan rusak atau hilangnya file hal.dll, ada kemungkinan&lt;br /&gt;file BOOT.INI mengalami salah konfigurasi (misconfigured).&lt;br /&gt;&lt;br /&gt;- Masukkan CD Windows XP dan booting dari CD tersebut.&lt;br /&gt;- Pada saat muncul opsi R=Repair yang pertama, tekan tombol R.&lt;br /&gt;- Tekan angka sesuai dengan lokasi instalasi Windows yang ingin diperbaiki yang sesuai.&lt;br /&gt;- Biasanya #1&lt;br /&gt;- Tulis: bootcfg /list&lt;br /&gt;  Menampilkan isi/masukan pada file BOOT.INI saat ini&lt;br /&gt;- Tulis: bootcfg /rebuild&lt;br /&gt;  Memperbaiki konfigurasi dari file BOOT.INI&lt;br /&gt;- Keluarkan CD Anda dan ketikkan EXIT&lt;br /&gt;&lt;br /&gt;________________________________________ _______________________ ________________________________________ _______________________&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. NTLDR atau NTDETECT.COM tak ditemukan (NTLDR or NTDETECT.COM Not Found)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jika Anda mendapati error bahwa NTLDR tak ditemukan saat booting:&lt;br /&gt;&lt;br /&gt;a. Untuk partisi tipe FAT&lt;br /&gt;   - Silakan Anda melakukan booting dari disket Win98 Anda dan salinlah file NTLDR atau NTDETECT.COM&lt;br /&gt;     dari direktori i386 ke drive induk/akar (root) C:\&lt;br /&gt;    &lt;br /&gt;b. Untuk partisi tipe NTFS&lt;br /&gt;   - Masukkan CD Windows XP dan booting dari CD tersebut.&lt;br /&gt;   - Pada saat muncul opsi R=Repair yang pertama, tekan tombol R.&lt;br /&gt;   - Tekan angka sesuai dengan lokasi instalasi Windows yang ingin diperbaiki yang sesuai.&lt;br /&gt;   - Biasanya #1&lt;br /&gt;   - Masukkan password administrator jika diperlukan.&lt;br /&gt;   - Masukkan perintah berikut, dimana X: adalah alamat drive dari CD ROM Anda (Sesuaikan!).&lt;br /&gt;   - Tulis: COPY X:\i386\NTLDR C\:&lt;br /&gt;   - Tulis: COPY X:\i386\NTDETECT.COM C:\&lt;br /&gt;   - Keluarkan CD Anda dan ketikkan EXIT&lt;/p&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;Semoga bermanfaat..&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-2877292337369961681?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/2877292337369961681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=2877292337369961681&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2877292337369961681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2877292337369961681'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/07/oprek-os-xp.html' title='Oprek o/s XP'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-2316899197920750454</id><published>2008-07-23T13:51:00.003+08:00</published><updated>2008-07-23T14:08:23.028+08:00</updated><title type='text'>Repair windows tanpa format</title><content type='html'>&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;pagi waktu menuju ke TKP... tiba² hp geter²... "jun komputer nya mba' sri error... blue screen"&lt;br /&gt;wah error lg nih... segera sesampainya di TKP langsung melihat barang bukti.. hehe.. kek BUSER aj nih..&lt;br /&gt;pas gw nyalain kompnya.... jreeeng.. muncuL kata² sakti "&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;Windows could not start because the following files is missing or corrupt&lt;br /&gt;\WINDOWS\SYSTEM32\CONFIG\SYSTEM "&lt;br /&gt;wah .. apa yaah commandnya.. lupa ui... coba tlpn tmn² dlu .. kali aja ad yg inget...&lt;br /&gt;&lt;br /&gt;"tuuuut...tuuuut.. tuuuuut..&lt;br /&gt;Mr.X : ya halo..&lt;br /&gt;☼ : mas... ganggu nih... lg repot ga...&lt;br /&gt;Mr.X : ga'.. knp jun..&lt;br /&gt;☼ : anu.. mau tanya command nya untuk repair windos ap ya.. lupa nih...&lt;br /&gt;Mr.X : o0o... gini jun... kemungkinan windosmu... bla..bla..bla.... trus ntr bla.. bla...bla..&lt;br /&gt;☼ : *buset ga nyambung nih... * o0o iya mas makasih...&lt;br /&gt;&lt;br /&gt;tlpn ke yg lainnya lagi dagH...&lt;br /&gt;*nsp ST12.. aku masih sayang...*&lt;br /&gt;Mr.Z : halo... pagi...&lt;br /&gt;☼ : pagi mas... lg sibuk ga ?&lt;br /&gt;Mr.Z : ga juga sih... knp jun...&lt;br /&gt;☼ : tau command repair windos ga... .&lt;br /&gt;Mr.Z : umm... yang mana yaaa itu...&lt;br /&gt;☼ : *GUBRAAKK !!! * &lt;/span&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;itu ... yg pijit R pas instal windos nya.&lt;br /&gt;Mr.Z : o0o... klo ga salah mesti di rename apa nya gtu jun.. lupa aku...&lt;br /&gt;☼ : o0o rename yaa... system ya.. ic²... makasih mas...&lt;br /&gt;Mr.Z : iya sama²...&lt;br /&gt;*yg ini masih mending lpa tapi inget juga nyambung dikit :) *&lt;br /&gt;&lt;br /&gt;akhirnya gw rename system nya.. .trus di copy system yg baru dari cd windos nya...&lt;br /&gt;berikut langkah² ya :&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;Direktori \WINDOWS\SYSTEM32\CONFIG rusak atau hilang&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;br /&gt;&lt;br /&gt;MuncuL Tulisan :&lt;br /&gt;&lt;br /&gt;"Windows could not start because the following files is missing or corrupt&lt;br /&gt;\WINDOWS\SYSTEM32\CONFIG\SYSTEM or \WINDOWS\SYSTEM32\CONFIG\SOFTWARE"&lt;br /&gt;&lt;br /&gt;- Masukkan CD Windows XP dan booting dari CD tersebut.&lt;br /&gt;- Pada saat muncul opsi R=Repair yang pertama, tekan tombol R.&lt;br /&gt;- Tekan angka sesuai dengan lokasi instalasi Windows yang ingin diperbaiki yang sesuai.&lt;br /&gt;- Biasanya #1&lt;br /&gt;- Masukkan password administrator jika diperlukan.&lt;br /&gt;- Tulis: cd \windows\system32\config&lt;br /&gt;- Berikutnya tergantung di bagian mana letak terjadinya kerusakan:&lt;br /&gt;- Tulis: ren software software.rusak ATAU ren system system.rusak ( klo ga bsa di rename coba di check disk dlu drive C: nya )&lt;br /&gt;- Berikutnya lagi juga tergantung di bagian mana letak terjadinya kerusakan:&lt;br /&gt;- Tulis: copy \windows\repair\system&lt;br /&gt;- Tulis: copy \windows\repair\software&lt;br /&gt;- Ketikkan EXIT&lt;br /&gt;&lt;br /&gt;kemudian boot biasa ke hard disk.. jgn ke cd lg...&lt;br /&gt;jreeeeeng.... windows nya ud bisa jalan lagi... horeeee...&lt;br /&gt;ups... driver² nya kok tanda tanya ????&lt;br /&gt;iya .. coz system nya kan di ganti yg baru... jd ya mesti di instal driver nya lagi.. untuk sound,vga, pci, dll&lt;br /&gt;&lt;br /&gt;tapi file² and data kita ga ilang.. 100% masih ad ....&lt;br /&gt;program instalan juga tetep jalan....&lt;br /&gt;&lt;br /&gt;selamat mencoba&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/87537835582802971-2316899197920750454?l=jund-r.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jund-r.blogspot.com/feeds/2316899197920750454/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=87537835582802971&amp;postID=2316899197920750454&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2316899197920750454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/87537835582802971/posts/default/2316899197920750454'/><link rel='alternate' type='text/html' href='http://jund-r.blogspot.com/2008/07/repair-windows-tanpa-format.html' title='Repair windows tanpa format'/><author><name>Jund</name><uri>http://www.blogger.com/profile/06402104760052174961</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_ImTmVzDNb5I/SVQ1QdADAeI/AAAAAAAAAE4/E9fvXSN2XFE/S220/dsc00145yp7.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-87537835582802971.post-2184039986000093109</id><published>2008-07-22T10:00:00.001+08:00</published><updated>2008-07-22T10:02:01.901+08:00</updated><title type='text'>yg mudah yang terlupakan</title><content type='html'>&lt;h4&gt;Tips And Trik o/s Xp&lt;br /&gt;&lt;/h4&gt;&lt;h4&gt;&lt;br /&gt;&lt;/h4&gt;&lt;h4&gt;&lt;span class="content"&gt;Menghilangkan Windows Messenger&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Klik menu Start, Run, ketik gpedit.msc---&gt;Computer configuration---&gt;Windows components ---&gt; Windows messenger. Dari sini anda bisa meng-enable-kan pilihan "Do not allow Windows Messenger to be run" dan "Do not automatically start Windows messenger initially".Dengan langkah tersebut maka Windows messenger tidak ditampilkan lagi.&lt;a name="Hilangkan Sharing Dokumen"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Hilangkan Sharing Dokumen&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Bukalah Regedit (Start-Run Regedit)dab tujulah pada HKEY_LOCAL_MACHINE SOFTWARE, Microsoft, Windows, CurrentVersion, Explorer, My Computer, NameSpace, DelegateFolders. Kemudian perhatikan sub-key yg bernama {59031a47-3f72-44a7-89c5-5595fe6b30ee}. Dengan menghapusnya, anda bisa meremove beberapa file yang tersimpan pada group. &lt;a name="Mengurangi File Space Temporary Internet"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Mengurangi File Space Temporary Internet&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Jalankan internet explorer---&gt;pilih Tools dari menu bar---&gt;Pilih internet options dari menu drop down---&gt;pertama kali internet options diload, klik general tab---&gt;Di bawah bagian temporary internet files, klik tombol settings---&gt;Maka jendela setting akan di load, anda bisa menggeser slider dengan ukuran yang kecil---&gt;Klik OK---&gt;Klik OK lagi. &lt;a name="Matikan System Recovery"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Matikan System Recovery&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Klik kanan pada My computer---&gt;Pilih properties---&gt;Klik system Restore tab---&gt;Check box Turn off System Restore. Hal ini akan meningkatkan performa windows dan save disk space. &lt;a name="Enable dan Disable Firewall"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Enable dan Disable Firewall&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Buka Control panel---&gt;klik dua kali pada Network Connctions(maka box baru akan ditampilkan)---&gt;klik kanan pada connection---&gt;dan klik Advanced tab---&gt;Check atau uncheck pada box untuk mengenablekan dan men-disable firewall. &lt;a name="Shutdown Win XP tidak Normal"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Shutdown Win XP tidak Normal&lt;/span&gt;&lt;/h4&gt;&lt;p align="left"&gt; &lt;span class="content"&gt;- Buka Control Panel, plilih Power Options.&lt;br /&gt;- Klik pada APM Tab, Check "Enable   Advanced Power Management support".&lt;br /&gt;- Shut down PC anda, dan sekarang proses Shut down akan berjalan normal.&lt;a name="Mengatur variasi Visual Effect"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Mengatur variasi Visual Effect&lt;/span&gt;&lt;/h4&gt;&lt;p align="justify"&gt;&lt;span class="content"&gt;Bukalah Control Panel---&gt;Di bawah System klik Advanced tab---&gt;Klik Settings di bawah pilihan Performance---&gt;Sekarang anda bisa mengubah variasi effect (baik animasi dan bayangan). &lt;a name="Men-Disable error reporting"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Men-Disable error reporting&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt;Buka Control Panel---&gt;Klik Performance and Maintenance---&gt;Klik System---&gt;Klik Advanced tab---&gt;Klik pada tombol error reporting yang terdapat di bawah windows---&gt;Pilih Disable error reporting---&gt;Klik OK---&gt;Klik OK. &lt;a name="Hilangkan Panah Shortcut pada Icon Dekstop"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;h4&gt;&lt;span class="content"&gt;Hilangkan Panah Shortcut pada Icon Dekstop&lt;/span&gt;&lt;/h4&gt; &lt;p align="justify"&gt;&lt;span class="content"&gt; Jalankan Regedit---&gt;Bukalah HKEY_CLASSES_ROOT Inkfile---&gt;Hapus nilai IsShortcut---&gt;Restart Windows XP.  &lt
