+ Reply to Thread
Results 1 to 9 of 9
- 05-04-2007 11:13 PM #1Loyal Member Array
- Join Date
- Jan 2007
- Location
- null
- Posts
- 577
- Thanks
- 0
- Thanked 1 Time in 1 Post
Anda pernah kena serangan Malware RVHOST.exe
Baru2 ini saya ada kena malware RVHOST.exe Apabila saya scan guna AVG antivirus dan AVG anti spyware, tiada sebarang tanda yang menunjukkan ada virus.
Tetapi bagaimana saya tahu ia adalah malware atau perosak pc?
1. Apabila tekan butang Ctrl+Alt+Del, Task manager disekat oleh RVHOST.exe.
2. Apabila saya buka registry editor(regedit), ia disekat juga oleh RVHOST.exe.
3. Folder option dihilangkan oleh perosak ini.
File bernama RVHOST ini meletakkan dirinya didalam c:/windows dan c:/windows/system32. FIle ini berupa bentuk gambar folder, jadi anda kan kurang pasti samada ia folder atau malware tersebut.
Jika anda telah terkena jangkitan ini, ia akan menduplikasikan didalam folder2 pc anda dengan nama folder. Contohnya di desktop ada satu folder bernama gambar. Jika anda buka folder tersebut anda akan nampak lagi satu folder yang namanya gambar. Jika diperhatikan ia bukan folder tetapi file exe.
Saya mendapat perosak ini melalui Yahoo messenger. Tak tahu sapa kasi. tetiba jer masuk semasa saya sedang online. Jadi berhati2lah ya. Ia cepat merebak jika anda didalam kawasan ber"network".
- 05-04-2007 11:13 PM # ADS
- 05-05-2007 12:27 AM #2Junior Member Array
- Join Date
- Jun 2006
- Location
- Terengganu/Selangor
- Posts
- 94
- Thanks
- 0
- Thanked 0 Times in 0 Posts
samalah kita
Saya pun kena macam tu gak...ingatkan benda biasa-biasa je sebab kesan dia tak signifikan sangat...tapi memang nak cleankan lah sebab menyakitkan mata. Satu lagi, bila masukkan thumbdrive, nanti thumbdrive tu jadi pelik...instead of direct click bila nak buka, kita kena right-click dan guna "open with"...thumbdrive tu nanti bila bukak kat komputer lain pun jadi benda yang sama..
Kini ada cara yang mudah untuk membuat satay...
www.sataydiy.com
Visit my NEW blog:
http://blog.sataydiy.com
Rahsia kami terbongkar!
http://rahsia.sataydiy.com
- 05-05-2007 12:52 AM #3
aku kena 2 minggu lepas.
Task manager has been disable by admin.
ape kejadah laa..
Run menu pun hilang. Tekan Windows + R pun takleh.
nak bukak registery pun tak leh.. Hangin gak memula..
scan guna spybot search n desroy pun tetiba scan abort by user.
banyak lagi yang jadi..
setelah menggodek sana sini.. akhirnya berjaya gak selesaikan masalah tuh..
tapi aku pun sampai tak ingat step by step yang aku buat..
- 05-05-2007 12:55 AM #4WC Premium Array
- Join Date
- Feb 2007
- Location
- Kuala Terengganu
- Posts
- 1,622
- Thanks
- 2
- Thanked 3 Times in 2 Posts
ooh, kawan saya pernah kene jangkitan ini. parah dan nazak jugak komputer diye. Dirokemenkan "dibunuh" dengan segera. Download this antivirus.
1) download file here ( 19+ kb )
2) just click dekat icon antivirus diye
3) diye automatic akan scan - no installation - and automatic delete
4) setakat ni berhasil dalam remove pende ni ( folder dlm folder )
- 05-05-2007 12:55 AM #5Loyal Member Array
- Join Date
- Jan 2007
- Location
- null
- Posts
- 577
- Thanks
- 0
- Thanked 1 Time in 1 Post
Saya clearkan guna beberapa code yang saya buat sendiri benggunakan *.bat program. Ada juga code *.vbs yang saya download. Apabila task RVHOST.exe saya dah kill baru saya baiki semula fail regedir supaya folder option dapat dilihat. jika ada sesiapa yang hendak file tersebut sila PM saya.
Simple jer.
- 05-05-2007 01:09 PM #6Junior Member Array
- Join Date
- Apr 2006
- Location
- Waseda kamo shirenai
- Posts
- 157
- Thanks
- 0
- Thanked 0 Times in 0 Posts
kalau vbs/ bat,
share jela codenya
:-)
- 05-05-2007 01:26 PM #7Pioneer Member Array
- Join Date
- May 2006
- Posts
- 943
- Thanks
- 0
- Thanked 0 Times in 0 Posts
Memang ada virus jenis ni. Biasanya dinamakan virus rvhost.
Tapi skrg ni ada lagi satu virus yg dikatakan lebih dahsyat dari virus rvhost ni. Aku baru terbaca dlm paper. Virus file .ani. Virus ni boleh merosakkan sistem windows, ada sesapa dah terkena virus ni belum? selalunya tanda2 bila terkena virus ni, masa kita tgh surf internet tetiba kursor mouse kita bertukar jadi ikon botol pengira masa. Masa tu pc kita terus jem sbb dia tgh download sesuatu dari internet. Operasi jadi lembab. Kalau ada sesapa yg tau program nak buang virus ni,kongsi le kat sini.
- 05-05-2007 01:40 PM #8
Nak kill process - guna tune up utilities, hijack this
Takleh masuk registry - guna tune up utilities
Dah boleh kill process n masuk registry, macam-macam boleh buat.
Nak enablekan task manager:
-Masuk registry
-Navigate ke sini :
-Cari key DisableTaskMgrCode:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
-tukar value kepada '0'.
Dah tau buat ni, macam-macam korang boleh ejas nanti. Hehe
- 05-05-2007 02:24 PM #9Loyal Member Array
- Join Date
- Jan 2007
- Location
- null
- Posts
- 577
- Thanks
- 0
- Thanked 1 Time in 1 Post
OK, kita kongsi code.
1. buka notepad, taip : Taskkill /T /IM "RVHOST.EXE dan save as .bat file. ataupun Start Menu>>Run>> paste code Taskkill /T /IM "RVHOST.EXE
2. taip dlm notepad:
On Error Resume Next
Set shl = CreateObject("WScript.Shell")
Set fso = CreateObject("scripting.FileSystemObject")
shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\Curr entVersion\Policies\System\DisableRegistryTools"
shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\Curr entVersion\Policies\System\DisableTaskMgr"
shl.RegDelete
save as .vbs file
3. buka notepad, paste code:
'togglefolderopts.vbs - Enables/Disables Folder Options settings
'in Win95/98
'© Doug Knox - rev 12/02/99
'Thanks to Max Spyridakis for his suggestions
Option Explicit
On Error Resume Next
Dim WSHShell, itemtype, n, MyBox, p, p1, p2, t, mustboot, errnum, vers
Dim urladdr
Set WSHShell = WScript.CreateObject("WScript.Shell")
p = "HKCU\Software\Microsoft\Windows\CurrentVersion\Po licies\Explorer\"
p1 = "NoFolderOptions"
p2 = p & p1
itemtype = "REG_DWORD"
t = "Toggle Folder Options"
mustboot = "Log off and back on, or restart your pc to"
mustboot = mustboot & vbCR & "effect the changes"
'This section tries to read the registry key value. If not present an
'error is generated. Normal error return should be 0 if value is
'present
t = "Enable/Disable Folder Options"
Err.Clear
n = WSHShell.RegRead (p2)
errnum = Err.Number
if errnum <> 0 then
'Create the registry key value for NoFolderOptions with value 0
WSHShell.RegWrite p2, 0, itemtype
End If
'If the key is present, or was created, it is toggled
'Confirmations can be disabled by commenting out
'the two MyBox lines below
If n = 0 Then
n = 1
WSHShell.RegWrite p2, n, itemtype
Mybox = MsgBox("Folder Options are now DISABLED" & vbCR & mustboot, 4096, t)
ElseIf n = 1 then
n = 0
Mybox = MsgBox("Folder Options are now ENABLED" & vbCR & mustboot, 4096, t)
WSHShell.RegWrite p2, n, itemtype
End If
save as .vbs
4. buka notepad, paste code :
del c:\windows\RVHOST.exe
del c:\windows\system32\RVHOST.exe
save as .bat file
5. buka notepad, paste code:
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run]
"Yahoo Messengger"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\Curre ntVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
"**del.DisableTaskMgr"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\system\]
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"DisableCAD"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoFolderOptions"=dword:00000000
save file as .reg
6. kumpulkan file tersebut dan klik mengikut urutan.
Lain kali leh guna kalau kena serangan RVHOST.exe
Just my 2cent.
Similar Threads
-
Pernah tgk benda ni tak...
By bitol in forum Perniagaan InternetReplies: 11Last Post: 03-24-2007, 03:02 AM -
Pernah guna Pospay?
By percuma in forum Tips & PanduanReplies: 2Last Post: 03-08-2007, 01:02 PM -
adsense aku kena serangan
By metana21 in forum Sembang UmumReplies: 31Last Post: 12-07-2006, 09:45 PM -
kena serang
By misaikejang in forum Program Jana Wang OnlineReplies: 7Last Post: 12-05-2006, 04:27 PM



LinkBack URL
About LinkBacks
Reply With Quote



Bookmarks