Cleaning manual virus (â€Pendekar Blankâ€)
February 24th, 2008 by | Filed under Uncategorized.
Cleaning manual virus (”Pendekar Blank”)
By Heddy a.k.a cambah @ deskofdesign.co.cc
Tutorial for cleaning Pendekar Blank Virus
1. You must have ProceXP and run it, You can download @ http://www.sysinternals.com/
2. Click @ Right and choice suspend @ blank.doc ,empty.jpg ,hole.zip,unoccupied.reg ,zero.txt
3. Next go to controlpanel ==> folder options, choice Tab View and @ advanced settings:
choice Show Hidden files and folder
Unmark Hide extensions for known file types
Unmark Hide protected operating system files (Recommended)
4. Search and delete file contain of the virus :
c:\aut0exec.bat
c:\windows\system32\dllcache\Regedit32.com
c:\windows\system32\dllcache\Shell32.com
c:\windows\system32\dllcache\rund1132.exe
c:\windows\system32\dllchache.exe
c:\windows\system32\M5VBVM60.exe
c:\(Read Me)Pendekar Blank.txt
c:\windows\system32\dllchache\blank.doc
c:\windows\system32\dllchache\empty.jpg
c:\windows\system32\dllchache\hole.zip
c:\windows\system32\dllchache\msvbvm60.dll
c:\windows\system32\dllchache\unoccupied.reg
c:\windows\system32\dllchache\zero.txt
c:\windows\system32.exe
5. Clean and Repair registry
Delete HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Secure32
Delete HKEY_CURRENT_USER, Software\Microsoft\Windows\CurrentVersion\Run, Secure64
Delete HKEY_LOCALMACHINE, Software\Microsoft\Windows\CurrentVersion\Run, Blank Antiviri
CHANGE & MODIFY @ HKCR, comfile\shell\open\command,,,”””%1″” %*”
CHANGE & MODIFY @ HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, “cmd.exe”
CHANGE & MODIFY @ HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, “cmd.exe”
CHANGE & MODIFY @ HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit,0, “C:\Windows\system32\userinit.exe,”
CHANGE & MODIFY @ HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden,0×00010001,1
CHANGE & MODIFY @ HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit.,0, “userinit.exe”
6. Restart yout computer
7. Enjoy
- Playing Visual Basic Payload In Registry Windows
This sample program is for securing windows based OS, Where many virus programer use this to secure…
- TimeCount
0-day i make this software to help me toes work. because too bored count manual time calculation …
[Read the rest on (it)gossips network: heddy]
Subscribe to Our FREE Newsletter Now:
Subscribe Feed (RSS)






































Add New Comment
Viewing 2 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Add New Comment
Trackbacks
(Trackback URL)
June 18, 2008 at 1:47 am
[...] Norton 2005 yang menyediakan daily updatenya belum bisa menyempurnakan untuk melumpuhkan virus ini. Tapi jangan khawatir Apabila komputer atau ...