Aduh... capek deh...kalo udah kena virus Sality, Baru di install ulang udah kena lagi...datanya di pindahin..ikut pindah juga nih virus Capek broo,udah coba pake berbagai anti virus,emang virusnya ke detek tapi biasanya file kita udah rusak mo gak mo harus install ulang Windowsnya baru bisa normal lagi.Nih ane nemu thread mungkin berguna buat kita semua gan...
Virus Sality ini yamg diperkirakan dari Taiwan / Cina banyak kita temui di sini dengan perkembangan varian yang terus berganti.
Nama lain virus : W32/Sality.AE, W32.Sality.AE, TROJ_AGENT.XOO [Trend], W32/Sality.ae [McAfee], Sality.AG [Panda Software], Win32/Sality.Z [Computer Associates], Win32/Sality.AA [Computer Associates]
Virus ini akan meng infeksi dan merusak file exe / com / scr. Ukuran file yang sudah terinfeksi Sality akan bertambah besar beberapa KB dan masih dapat di jalankan seperti biasa. Biasanya virus ini akan mem blok antivirus atau removal tools selain itu juga akan memblok task manager atau registry editor Windows. Untuk mempermudah dalam proses penyebarannya selain memanfaatkan File Sharing dan Default Share virus ini juga akan memanfaatkan media Flash Disk dengan cara membuat file acak dengan ekstensi exe/com/scr/pif serta menambahkan file autorun.inf
Untuk blok task manager atau Registry tools, Sality akan membuat :
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system
DisableRegistryTools
DisableTaskMgr
File yang terinfeksi akan men dekrip dirinya dan mencoba copy *.dll (acak) dan menginjeksi file lain yang aktif di memori serta file lain yang terdapat di computer dan network (file sharing) serta menginfeksi file *.exe yang terdapat dalam list registry hingga virus dapat aktif secara otomatis setiap kali komputer dinyalakan.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
Beberapa file *.dll yang akan di drop oleh Sality.
C:\Windows\system32\syslib32.dll
C:\Windows\system32\oledsp32.dll
C:\Windows\system32\olemdb32.dll
C:\Windows\system32\wcimgr32.dll
C:\Windows\system32\wmimgr32.dll
Selain membuat file DLL, sality juga akan membuat file *.sys [acak] di direktori C:Windowssystem32drivers [misal : kmionn.sys]
Blok Antivirus dan software security
program security dan antivirus yang dimatikan prosesnya : ALG, aswUpdSv, avast! Antivirus, avast! Mail Scanner, avast! Web Scanner, AVP, BackWeb Plug-in – 4476822, bdss, BGLiveSvc, BlackICE, CAISafe, ccEvtMgr, ccProxy, ccSetMgr, F-Prot Antivirus Update Monitor, fsbwsys, FSDFWD, F-Secure Gatekeeper Handler Starter, fshttps FSMA,InoRPC, InoRT, InoTask, ISSVC, KPF4, LavasoftFirewall, LIVESRV, McAfeeFramework, McShield, McTaskManager, navapsvc, NOD32krn, NPFMntor, NSCService, Outpost Firewall main module, OutpostFirewall, PAVFIRES, PAVFNSVR, PavProt, PavPrSrv, PAVSRV, PcCtlCom, PersonalFirewal, PREVSRV, ProtoPort Firewall service, PSIMSVC, RapApp, SmcService, SNDSrvc, SPBBCSvc, Symantec Core LC, Tmntsrv, TmPfw, tmproxy, UmxAgent, UmxCfg, UmxLU, UmxPol, vsmon, VSSERV, WebrootDesktopFirewallDataService, WebrootFirewall, XCOMM
Beberapa website juga di blok seperti : Cureit, Drweb, Onlinescan, Spywareinfo, Ewido, Virusscan, Windowsecurity, Spywareguide, Bitdefender, Panda software, Agnmitum, Virustotal, Sophos, Trend Micro, Etrust.com, Symantec, McAfee, F-Secure, Eset.com, Kaspersky
Sality juga merubah registry :
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xxx [xxx adalah acak, contoh : abp470n5]
HKEY_CURRENT_USER\Software\[USER NAME]914
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
Selain itu akan merubah beberapa string registry Windows Firewall berikut dengan menambahkan value dari 0 menjadi 1:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify
AntiVirusOverride
FirewallDisableNotify
FirewallOverride
UacDisableNotify
UpdatesDisableNotify
dan membuat key “SVC” serta string berikut dengan value 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
AntiVirusDisableNotify
AntiVirusOverride
FirewallDisableNotify
FirewallOverride
UacDisableNotify
UpdatesDisableNotify
Sality menghapus key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesALG.
ALG ( Application Layer Gateway Service ) adalah services yang memberikan support untuk plug-in protokol aplikasi dan meng-enable konektivitas jaringan / protokol. Jika service ini dimatikan, program seperti MSN Messenger dan Windows Messenger tidak akan berfungsi. Service ini bisa dijalankan, hanya jika menggunakan firewall, baik firewall bawaan Windows atau firewall lain. Jika tidak komputer yang terinfeksi virus ini akan mengalami celah keamanan yang serius.
..
Blok safe mode
User tidak dapat booting pada mode “safe mode” hal imi di sebabkan adannya penghapusan key :
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
Injeksi file exe / com / scr
File yang ber ekstensi “.exe” yang terdapat dalam list registry menyebabkan virus dapat aktif secara otomatis setiap kali komputer dinyalakan.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
File yang di injeksi ukurannya bertambah sekitar 68 – 80 KB dari ukuran semula. Salah satu kecanggihan Sality adalah kemampuannya menginjeksi file induk sehingga ukuran file bervirus tidak seragam, jelas lebih sulit diidentifikasi dibandingkan virus lain yang menggantikan file yang ada sehingga ukuran filenya akan sama besar.
Tidak semua program antivirus dapat membersihkan file yang sudah terinfeksi Sality, file tersebut bisa rusak setelah di scan dan di bersihkan oleh antivirus tersebut.
Untuk memperlancar aksinya, virus ini akan akan melakukan koneksi ke sejumlah alamat web yang sudah ditentukan, dan men download trojan / virus lainnya yang di sinyalir merupakan varian dari versi sebelumnya ( update ).
Eksploitasi Default Share dan Full Sharing
Sality akan menyebar dengan cepat melalui jaringan dengan memanfaatkkan default share windows atau share folder yang mempunyai akses full dengan cara menginfeksi file yang mempunyai ekstensi exe/com/scr. Maka sebaiknya nonaktifkan Default Share (C$, D$ .. dst) dan hindari Full Sharing folder di jaringan.
Sality juga akan menambahkan string [MCIDRV_VER] dan DEVICEMB=xxx, dimana xxx menunjukan karakter acak ke dalam file C:Windowssystem.ini.
Clean, Remove & Repair Virus Sality
CARA PEMBERSIHAN SALITY
Putuskan hubungan komputer dari jaringan dan internet
Matikan System Restore selama proses pembersihan berlangsung.
Matikan Autorun dan Default Share, buat *.inf (misal repair.inf dari notepad atau download di sini filenya), klik kanan – install
[Version]
Signature="$Chicago$"
Provider=Vaksincom
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\CurrentControlSet\Services\lanmanserver\parameters, AutoShareWks,0x00010001,0
HKLM, SYSTEM\CurrentControlSet\Services\lanmanserver\parameters, AutoShareServer,0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr
HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr
Matikan program aplikasi yang aktif di memori terutama dalam daftar startup.
Scan dengan removal tools dengan terlebih dahulu merubah ekstensi dari removal tools tersebut dengan ekstensi lain ( misal, *.exe menjadi *.cmd ) atau pakai media write protect, file removal tersebut tidak di infeksi ulang oleh Sality.
Sality Repair lainnya :
- Sality Repair
- Fix Register
Clean, Remove & Repair Virus Sality
Delete the value from the registry (symantec)
- Click Start > Run.
- Type regedit
- Click OK.Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
- Navigate to and delete the following registry entry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"[INFECTED FILE]" = "[INFECTED FILE]:*:Enabled:ipsec"
- Navigate to and delete the following registry subkeys:
HKEY_CURRENT_USER\Software\[USER NAME]914
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
- Restore the following registry entries to their previous values, if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"
- Restore registry entries under the following registry subkeys to their previous values, if required:
HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
- Exit the Registry Editor.
From : Symantec and vaksin.com
Oh and one more thing …
6pck will allow Transfers only untill April 19th, 2011 after that date Transfers stop. Every Member that refer new 6pck Member with a Transfer will get for each such Member 5% commission of this Member’s Transfer. These websites below
paybox – virtapay.com
365DayClub(365dayclub.com)
AutoPayouts(autopayouts.com)
Paying PTR(payingptr.com)
Rolex-Mails(rolex-mails.com)
Sweet PTR(sweetptr.net)
and others have thousands of Members that can’t cash out. Members have thousands of dollars there. They don’t lose anything, it doesn’t cost them anything, all they need to do is open 6pck account, transfer the money and they still keep the amount at original website untill they don’t cash out at 6pck.
All Members get to work help your friends out and earn. April 19th, 2011 is close and until than you can really earn thousands of dollars.
I have $1260 at rolex-mails.com please i want it added to my 6pck balance. my 6pck id is 12510.
I am a transfer agent I willbe happy to help you cashout to 6pck.com
I have 515 $ Svio, 730 $ Hotvivid, 1500Virtapay, would like to cash out through 6pck help on how tocontact the transfer agent of Russia, my ID30028
I have 515 $ Svio, 730 $ Hotvivid, 1500Virtapay, would like to cash out through 6pck help , my ID30028 swetlanaborz@gmail.com
hello mr. David my name is Seth. I want you to help me transfer my money from my virtapay account to my 6pck account. My email address is seth_osei11@yahoo.com. Please contact me for my details. thank you
Hi, Please, transfer from my virtapay account $ 253
user name: rwc
6pck ID: 15746
Thanks , szilva2
I sent this message to Mr.David Johnson
Hello David
I’m so glad, you can help me to transfer my earns from some site to my 6pck account. By the way I have two questions:
I have more than one account on many sites. Is it possible to transfer earnings from more than one site?
Is it important to reach the pay out level on any site, or doesn’t matter?
Thanks, Pal
Hello! My 6pck ID 20202 Virtapay have 1000$.
Please help me
Gabor
Hi! I have virtapay account. I wish to convey 6pck. My 6pck ID 2875. Virtapay Username: Kameya8. I want to withdraw all my money at my expense AlertPay, provided at registration.
I have about $4000 in virtapay.com and about 1800 bonus and 15 NP points. Tell me how I can get the money cash out wither from virtapay or 6pck. Regards,
amiragalstyan@gmail.com
do you have your Transfer agent? I you want me for your Transfer agent, please send me an e-mail with your 6pck ID and amount you want to cash out
virnaknez8@gmail.com
Hi,
6pck my bonus: $ 4,200 USD, my ID: 9267
Please tell me the details of a payment of the amount on my AlertPay_Konto: hneubert@email.de or Liberty Reserve: U5664779 with.
Greatings Heinz Neubert
Hallo Herr Neubert, bin leider nicht so gut in englisch. Haben Sie Informationen bekommen wie 6pck Salden ausgezahlt werden können?
LG. und schönes Wochenend.
Petra
Hiiiii
i have earn $ 1200 in virta pay .
so ply Tell me how I can get the money cash out wither from virtapay Regards,
mob no 09219055569
I am a transsfer agent I would be happy to help you cash out to 6pck.com I need your 6pck.com id
Hello i have $3,681.85 on my virtapay acount. kotlos61 I would like to transfer to 6pck.My 6pck id is 18926
and i want to withdrawn all my money………. to my liberty reserve account, my liberty reserve account id U0268549 ,alertpay:kotlos61@citromail.hu
I am from Nigeria, and i will like to cash my money here in nigeria. I have bonus on 6pck and paybox(vitapay), how do you think you can help me.
Nekem is van a virtapay.com számlámon 7425 dollárom amit szeretnék a 6 pck-ra utalni ID számom: 2538 amin van Net 45 Classified . 600, News Net 45 508, Bonusz 5092, mivel szeretném 2 hét múlva készpénzbe kivenni
Hello i have 2234$ on my virtapay acount.I would like to transfer to 6pck.My 6pck id is 9844.Soplease let me know how to do it .I will let know my refferals
I can help you cash out to 6pck.com
én nem igazán értem mit is kell tennem, sem a 6pck sem a paybox fiókban összeszedett összeggel, valaki tud értelmesen segíteni, hogyan lehet hozzájutni a keresett értékhez, vagy csak nagy átverés volt az egész.
?
Üdvözlettel
Witam.Mam 1500$na koncie Virtpay i chciałbm je przeniesc do 6pck.Daj mi znac jak to zrobic.
hello, i have $2,344.35 in my virtapay account and i want to withdrawn all my money………. to my liberty reserve account, my liberty reserve account id:U2251344
thanks
regard from titi
The money would be withdrawn to your 6pck.com account and then you would be able to withdraw from the 6pck.com account if you do not have a 6pck.com account signe up here http://6pck.com/signup.php?ref=3673
I have 515 $ Svio, 730 $ Hotvivid, 1500Virtapay, would like to cash out through 6pck help on how , my ID30028
hi! i have question, i want to transfer 365dayclub.com cash to my libertyreserve
account, that is 2000 usd , does any transfer agents help me or not?
zhenyuan,
Your money can be transfered to 6pck.com and cashed out from there
Good news. But me it is not clear how to contact Transfer Agent. I would like to contact Alexander Sozykin and to discuss with it details of transfer of money on clear to both of us language. I have funds in VirtaPay and 6pck which I very much would wish to cash. With me it is possible to communicate in Skype: wittal59
Hi David! My name is Vitaly Butin. Mine 6pck ID: 5286, a login: wittal. My balance Bonus: $7525. Still I have funds in VirtaPay: Account Balance $4,169.41, and I wish to cash all it. My login in VirtaPay: wittal
Help me to make it! Mine Skype: wittal59
Hello i have $3,681.85 on my virtapay acount. kotlos61 I would like to transfer to 6pck.My 6pck id is 18926
and i want to withdrawn all my money………. to my liberty reserve account, my liberty reserve account id U0268549 ,alertpay:kotlos61@citromail.hu
Hello i have $2,314.04 on my virtapay acount. olga5855 I would like to transfer to 6pck.My 6pck id is 5696
and i want to withdrawn all my money. to my account alertpay:olara8@gmail.com
I have 515 $ Svio, 730 $ Hotvivid, 1500Virtapay, would like to cash out through 6pck help on how to contact the transfer agent of Russia, my ID30028
Hi! i have question, i want to transfer Sweet PTR ($ 5,230.0000),cash to my libertyreserve U2901648
account, that is , does any transfer agents help me or not?I Would like to transfer to 6pck.My 6pck ID 29050
i have money in sweet ptr and virtapay..how could i get it sent to my 6-pck account? ty terry monroe
Здравствуйте!Помогите пожалуйста обналичить деньги с сайта 6cpk мой ID 19422 на мой счёт Alertpay Suzannakisa@gmail.com
i would like a transfer agent to help me transfer money from my virtapay account into my 6pck account. Please send me an email if you can help me to seth_osei11@yahoo.com
Как правильно перевести средства с VirtaPay-1063$ -paolapriz на ID 18933 6pck? И как их вывести хотя-бы на AlertPay?Кто-то же из русскоговорящих соображает и правильно работает в проекте-подскажите,пожалуйста! Очень надеюсь на помощь!
Hi! I have $ 2,245.43 on my virtapay account. I would like to transfer to 6pck. My 6pck ID 6678. virtapay username: medvzol78
I want to withdrawn all my money. to my account
AlertPay: medvzol78@indamail.hu
Who-be really deduced money?? Whether write there are already positive transfers???
I have in this website at least $1008.00 in my account I want to cash out can you help me out of it
Miss Amira Galstyan
hello….i want to win…pls help me..
could a transfer agent that speaks enlgish please contact me at my email addy to transfer funds from two accounts thank you ..terry
Hi! I have virtapay account. I wish to convey 6pck. My 6pck ID 7358. Virtapay Username: Corall28. I want to withdraw all my money at my expense AlertPay, provided at registration
Hello i have $2992.31on my virtapay acount. scott2010 I would like to transfer to 6pck.My 6pck id is scott2011
and i want to withdrawn all my money………. to my liberty reserve account, my liberty reserve account id U2488090
,alertpay:tibhauser@aol.com.
hello david johnson…..I want you to be my agent and help me to cash out my money from virtapay to 6pck.com…my 6pck id is 15429
hello david johnson…..I want you to be my agent and help me to cash out my money.$5000 from virtapay to 6pck.com…my 6pck id is 15429
i have question, when my funds transfer to my 6pck account, how do i cash out these money from 6pck to my libertyreserve or alertpay account???
waiting reply!
thanks!
hello david johnson…..I want you to be my agent and help me to cash out my money.$5000 from virtapay and $1930 from rolex-mails.com to 6pck.com…my 6pck id is 15429…thank you….waiting for your reply…..
Hi! I’m out of my an аccount virtapay want to transfer $ 500, I would like to transfer to 6pck.My 6pck id is: 28197
and i want to withdrawn all my money … … …. to my liberty reserve account, my liberty reserve account id: U1065961
Hi David Johnson! Please, transfer from my virtapay account $ 500
My virtapay login: “Bibars”
6pck ID: 28197
Thanks!
pls help me to transfer my money from sureptr.com and virtapay my
ID:hafeezta i will be glad if u help me
thank u
i have 3,457 in virtapay pls help me to withdraw 3, 000 from there my ID is hafeezta
and in sureptr i have 53,450.0000 pls help me with to transfer it
my ID there also is hafeezta
how can we transfer money from other to 6pck.com
У меня tanyagold1 на аккаунте $2,706.46,а у моего реферала german0303 $1,264.75.Подскажите,пожалуйста,как вывести деньги с аккаунта на 6рск нам обоим,так как у него 6рск нету!
Hello David Johnson!
Virtapay is my account of $ 4,800, the entry name is “bekenyi”.
6pck ID 30727 has transferred please.
Paypal e-mail: bekenyi52@gmail.com
Thanks, Laszlo Bekényi
Could you transfer from Virta pay to Liberty reseve or Alertpay?
must cash out to 6pck account
Dear David Johnson!
Virtapay account the $ 4100 entry “Bajcsi”
6pck ID 30821 trans-shipped, please.
Thank you very much Mary Bajcsi
added to transfer list
hello david johnson…..I want to transfer my money $10,850 from aglocomails.com to 6pck.com… my 6pck id is 15429…..Thank you…waiting for ur reply
will check and see if we can get site added to list
Hello on David Johns!
Virtapay my account it 1289 $, the name of the entry “meccs5608″.
6pck ID: 30956 conveyed it please.
Paypal e-mail: farkas.geza3@freemail.hu
added to transfer list!
Hello David Johnson!
Virtapay is my account of $ 1289 the entry name is “meccs5608”.
6pck ID 30956 has transferred please.
Thank you very much Geza Farkasi
All that want money transfered from websites that don’t pay you can do it now that it’s free of charge and contact Transfer Agent lordeirik@yahoo.com
Transfers are done ONLY TO 6pck.com and from there on you can cash out April 19, 2011.
So stop asking about Liberty Reserve, Alertpay, Paypal etc. from 6pck you’ll cash it out on April 19, 2011.
THANK YOU ADMIN FOR CLARIFYING THAT POINT !!