<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>[dot]EXE - All About IT &#38; Electro Engineering &#187; ansav</title>
	<atom:link href="http://dotexe.unnes.ac.id/tag/ansav/feed/" rel="self" type="application/rss+xml" />
	<link>http://dotexe.unnes.ac.id</link>
	<description>Komunitas Studi Teknologi Informasi &#38; Elektro, Mahasiswa Teknik Elektro UNNES</description>
	<lastBuildDate>Thu, 04 Mar 2010 16:34:13 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>id</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='dotexe.unnes.ac.id' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/0e63d56f2d5b1a6518e809fe95e47989?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>[dot]EXE - All About IT &#38; Electro Engineering &#187; ansav</title>
		<link>http://dotexe.unnes.ac.id</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://dotexe.unnes.ac.id/osd.xml" title="[dot]EXE &#8211; All About IT &amp; Electro Engineering" />
	<atom:link rel='hub' href='http://dotexe.unnes.ac.id/?pushpress=hub'/>
		<item>
		<title>Download Smadav 2009 revisi 7.4 (Baru)</title>
		<link>http://dotexe.unnes.ac.id/2009/12/01/download-smadav-2009-revisi-7-4-baru/</link>
		<comments>http://dotexe.unnes.ac.id/2009/12/01/download-smadav-2009-revisi-7-4-baru/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 22:51:41 +0000</pubDate>
		<dc:creator>dotexe</dc:creator>
				<category><![CDATA[Smadav]]></category>
		<category><![CDATA[ansav]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[berita]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[info]]></category>
		<category><![CDATA[islam]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[komputer]]></category>
		<category><![CDATA[norton]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[Pendidikan]]></category>
		<category><![CDATA[sekolah]]></category>
		<category><![CDATA[smadav]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[teknologi]]></category>
		<category><![CDATA[Umum]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://dotexe.unnes.ac.id/?p=1837</guid>
		<description><![CDATA[Silakan didownload via Ziddu di:
http://www.ziddu.com/downloadlink/7572280/smadav74.zip

Dukung terus pengembangan SmadAV dengan menjadi Donatur dan Pengguna SmadAV PRO. Silakan kunjungi smadav.net untuk lebih lanjutnya.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1837&subd=dotexe&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Silakan didownload via Ziddu di:</p>
<p><em><a href="http://www.ziddu.com/downloadlink/7572280/smadav74.zip" target="_blank">http://www.ziddu.com/downloadlink/7572280/smadav74.zip</a></em></p>
<hr />
Dukung terus pengembangan SmadAV dengan menjadi Donatur dan Pengguna SmadAV PRO. Silakan kunjungi smadav.net untuk lebih lanjutnya.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dotexe.wordpress.com/1837/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dotexe.wordpress.com/1837/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dotexe.wordpress.com/1837/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dotexe.wordpress.com/1837/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dotexe.wordpress.com/1837/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dotexe.wordpress.com/1837/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dotexe.wordpress.com/1837/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dotexe.wordpress.com/1837/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dotexe.wordpress.com/1837/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dotexe.wordpress.com/1837/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1837&subd=dotexe&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://dotexe.unnes.ac.id/2009/12/01/download-smadav-2009-revisi-7-4-baru/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a94a147311b2193c4290ed39767fdf9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dotexe</media:title>
		</media:content>
	</item>
		<item>
		<title>10 Invite Akun Google Wave, Ikuti Kuis ini</title>
		<link>http://dotexe.unnes.ac.id/2009/11/30/10-invite-akun-google-wave-ikuti-kuis-ini/</link>
		<comments>http://dotexe.unnes.ac.id/2009/11/30/10-invite-akun-google-wave-ikuti-kuis-ini/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 04:03:47 +0000</pubDate>
		<dc:creator>dotexe</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ansav]]></category>
		<category><![CDATA[berita]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Blogroll]]></category>
		<category><![CDATA[dotexe]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google wave]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[im]]></category>
		<category><![CDATA[indonesia]]></category>
		<category><![CDATA[info]]></category>
		<category><![CDATA[informasi]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[islam]]></category>
		<category><![CDATA[komputer]]></category>
		<category><![CDATA[kuis]]></category>
		<category><![CDATA[messenger]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[politik]]></category>
		<category><![CDATA[smadav]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[teknologi]]></category>
		<category><![CDATA[Umum]]></category>
		<category><![CDATA[wave]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://dotexe.unnes.ac.id/?p=1835</guid>
		<description><![CDATA[dotexe &#8211; Sesuai rencana semula, jika akun wave kami sudah aktif, kami membuka kuis berhadiah 10 invite Google Wave untuk 10 pemenang. Syaratnya mudah:
1. terbukti jadi subscriber dotexe, via Feedburner (bukti via Screenshoot)
2. 10 komentar di 10 artikel dotexe (dotexe.unnes.ac.id) yang berbeda (bukti via screenshoot)
3. gabung di Group [dot]EXE di Facebook (URL: http://www.facebook.com/group.php?gid=70353547790
4. sebuah akun <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1835&subd=dotexe&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>dotexe</strong> &#8211; Sesuai rencana semula, jika akun wave kami sudah aktif, kami membuka kuis berhadiah 10 invite Google Wave untuk 10 pemenang. Syaratnya mudah:<br />
1. terbukti jadi subscriber dotexe, via Feedburner (bukti via Screenshoot)<br />
2. 10 komentar di 10 artikel dotexe (dotexe.unnes.ac.id) yang berbeda (bukti via screenshoot)<br />
3. gabung di Group [dot]EXE di Facebook (URL: <a href="http://www.facebook.com/group.php?gid=70353547790">http://www.facebook.com/group.php?gid=70353547790</a><br />
4. sebuah akun gmail aktif,</p>
<p>semua syarat dikirim via email ke <strong>dotexenator[at]gmail.com</strong>, pemenang ditentukan oleh redaksi tak dapat diganggu gugat (walah). Jika memungkinkan terdapat sisa invite, akan dinominasikan lagi.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dotexe.wordpress.com/1835/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dotexe.wordpress.com/1835/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dotexe.wordpress.com/1835/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dotexe.wordpress.com/1835/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dotexe.wordpress.com/1835/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dotexe.wordpress.com/1835/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dotexe.wordpress.com/1835/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dotexe.wordpress.com/1835/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dotexe.wordpress.com/1835/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dotexe.wordpress.com/1835/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1835&subd=dotexe&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://dotexe.unnes.ac.id/2009/11/30/10-invite-akun-google-wave-ikuti-kuis-ini/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a94a147311b2193c4290ed39767fdf9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dotexe</media:title>
		</media:content>
	</item>
		<item>
		<title>Download SmadAV 2009 Revisi 7.3 (November 2009)</title>
		<link>http://dotexe.unnes.ac.id/2009/11/14/download-smadav-2009-revisi-7-3-november-2009/</link>
		<comments>http://dotexe.unnes.ac.id/2009/11/14/download-smadav-2009-revisi-7-3-november-2009/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 15:03:09 +0000</pubDate>
		<dc:creator>dotexe</dc:creator>
				<category><![CDATA[Smadav]]></category>
		<category><![CDATA[ansav]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[berita]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[info]]></category>
		<category><![CDATA[informasi]]></category>
		<category><![CDATA[iptek]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[komputer]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[smadav]]></category>
		<category><![CDATA[smadav 2009]]></category>
		<category><![CDATA[smadav.net]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[teknologi]]></category>
		<category><![CDATA[TIK]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Umum]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://dotexe.wordpress.com/?p=1781</guid>
		<description><![CDATA[Silakan bagi para pengguna SmadAV download dan upgrade SmadAV kalian dengan SmadAV 2009 Revisi 7.3. Download via Uploaded berikut:
http://ul.to/wztkld
Baca pula hal baru di Smadav di official sitenya: http://www.viruslokal.com/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1781&subd=dotexe&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Silakan bagi para pengguna SmadAV download dan upgrade SmadAV kalian dengan SmadAV 2009 Revisi 7.3. Download via Uploaded berikut:</p>
<p><a href="http://ul.to/wztkld">http://ul.to/wztkld</a></p>
<p>Baca pula hal baru di Smadav di official sitenya: http://www.viruslokal.com/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dotexe.wordpress.com/1781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dotexe.wordpress.com/1781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dotexe.wordpress.com/1781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dotexe.wordpress.com/1781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dotexe.wordpress.com/1781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dotexe.wordpress.com/1781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dotexe.wordpress.com/1781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dotexe.wordpress.com/1781/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dotexe.wordpress.com/1781/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dotexe.wordpress.com/1781/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1781&subd=dotexe&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://dotexe.unnes.ac.id/2009/11/14/download-smadav-2009-revisi-7-3-november-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a94a147311b2193c4290ed39767fdf9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">dotexe</media:title>
		</media:content>
	</item>
		<item>
		<title>Virus Sality Terbaru (Sality.AE)</title>
		<link>http://dotexe.unnes.ac.id/2009/10/31/virus-sality-terbaru-sality-ae/</link>
		<comments>http://dotexe.unnes.ac.id/2009/10/31/virus-sality-terbaru-sality-ae/#comments</comments>
		<pubDate>Sat, 31 Oct 2009 15:20:29 +0000</pubDate>
		<dc:creator>luthfi.emka</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ansav]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[informasi]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[komputer]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[sality]]></category>
		<category><![CDATA[smadav]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[teknologi]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virologi]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://dotexe.wordpress.com/?p=1648</guid>
		<description><![CDATA[Keterangan Sample Virus:
Diterima: 31 Oktober 2009, 09:49:20
Hash:
File MD5: 0xE42D69F9C18175414B5EE9BE3A5BFFD2
File SHA-1: 0&#215;4A3A1B9044309C66A6AB389A8D2B24915241673C
Filesize: 360.960 byte
Alias:
Virus.Win32.Sality.ae [Kaspersky Lab]
W32/Sality.gen.c [McAfee]
Mal/Behav-328, Mal/Behav-103, Mal/Behav-043, Mal/Sality-C [Sophos]
Win32/Kashu.C [AhnLab]
Modifikasi file dilakukan oleh sality pada:
%Windir%\system.ini
%System%\cmd.exe
%System%\mmc.exe
%System%\taskmgr.exe
Modifikasi memori, khususnya pada driver Windows dilakukan pada:
ipfltdrv.sys	%System%\drivers\ipfltdrv.sys
flgko.sys	%System%\drivers\flgko.sys
Sality.AE juga melakukan perubahan registry Windows seperti:
Membuat item baru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Enum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system
HKEY_CURRENT_USER\Software\Apcrmkeh
HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023
Menghapus item registry yang sudah ada di:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PCI Configuration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PlugPlay
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PNP Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Primary <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1648&subd=dotexe&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Keterangan Sample Virus:<br />
Diterima: 31 Oktober 2009, 09:49:20<br />
Hash:<br />
File MD5: 0xE42D69F9C18175414B5EE9BE3A5BFFD2<br />
File SHA-1: 0&#215;4A3A1B9044309C66A6AB389A8D2B24915241673C<br />
Filesize: 360.960 byte<br />
Alias:<br />
Virus.Win32.Sality.ae [Kaspersky Lab]<br />
W32/Sality.gen.c [McAfee]<br />
Mal/Behav-328, Mal/Behav-103, Mal/Behav-043, Mal/Sality-C [Sophos]<br />
Win32/Kashu.C [AhnLab]</p>
<p>Modifikasi file dilakukan oleh sality pada:<br />
%Windir%\system.ini<br />
%System%\cmd.exe<br />
%System%\mmc.exe<br />
%System%\taskmgr.exe<span id="more-1648"></span></p>
<p>Modifikasi memori, khususnya pada driver Windows dilakukan pada:<br />
ipfltdrv.sys	%System%\drivers\ipfltdrv.sys<br />
flgko.sys	%System%\drivers\flgko.sys</p>
<p>Sality.AE juga melakukan perubahan registry Windows seperti:<br />
Membuat item baru:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000\Control<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000\Control<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Security<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Enum<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000\Control<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000\Control<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Security<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Enum<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system<br />
HKEY_CURRENT_USER\Software\Apcrmkeh<br />
HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023</p>
<p>Menghapus item registry yang sudah ada di:<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmt<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Base<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot Bus Extender<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot file system<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\CryptSvc<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\DcomLaunch<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmadmin<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmboot.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmio.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmload.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmserver<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\EventLog<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\File system<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Filter<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\HelpSvc<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Netlogon<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PCI Configuration<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PlugPlay<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PNP Filter<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Primary disk<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\RpcSs<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SCSI Class<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sermouse.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sr.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SRService<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\System Bus Extender<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vga.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vgasave.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinMgmt<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AFD<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AppMgmt<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Base<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot Bus Extender<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot file system<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Browser<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\CryptSvc<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\DcomLaunch<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Dhcp<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmadmin<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmboot.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmio.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmload.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmserver<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\DnsCache<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\EventLog<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\File system<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Filter<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\HelpSvc<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ip6fw.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ipnat.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanServer<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanWorkstation<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\LmHosts<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Messenger<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS Wrapper<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Ndisuio<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOS<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOSGroup<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBT<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetDDEGroup<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Netlogon<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetMan<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Network<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetworkProvider<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NtLmSsp<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PCI Configuration<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PlugPlay<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP Filter<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP_TDI<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Primary disk<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpcdd.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpdd.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpwd.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdsessmgr<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\RpcSs<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SCSI Class<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sermouse.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SharedAccess<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sr.sys<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SRService<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Streams Drivers<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\System Bus Extender</p>
<p>Modifikasi item di:<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]<br />
UacDisableNotify = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]<br />
AntiVirusOverride = 0&#215;00000001<br />
AntiVirusDisableNotify = 0&#215;00000001<br />
FirewallDisableNotify = 0&#215;00000001<br />
FirewallOverride = 0&#215;00000001<br />
UpdatesDisableNotify = 0&#215;00000001<br />
UacDisableNotify = 0&#215;00000001</p>
<p>to disable notification of firewall, antivirus and/or update status through the Windows Security Center<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]<br />
EnableLUA = 0&#215;00000000<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000\Control]<br />
*NewlyCreated* = 0&#215;00000000<br />
ActiveService = &#8220;abp470n5&#8243;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5000]<br />
Service = &#8220;abp470n5&#8243;<br />
Legacy = 0&#215;00000001<br />
ConfigFlags = 0&#215;00000000<br />
Class = &#8220;LegacyDriver&#8221;<br />
ClassGUID = &#8220;{8ECC055D-047F-11D1-A537-0000F8753ED1}&#8221;<br />
DeviceDesc = &#8220;abp470n5&#8243;<br />
Capabilities = 0&#215;00000000<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ABP470N5]<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000\Control]<br />
*NewlyCreated* = 0&#215;00000000<br />
ActiveService = &#8220;IpFilterDriver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER000]<br />
Service = &#8220;IpFilterDriver&#8221;<br />
Legacy = 0&#215;00000001<br />
ConfigFlags = 0&#215;00000000<br />
Class = &#8220;LegacyDriver&#8221;<br />
ClassGUID = &#8220;{8ECC055D-047F-11D1-A537-0000F8753ED1}&#8221;<br />
DeviceDesc = &#8220;IP Traffic Filter Driver&#8221;<br />
Capabilities = 0&#215;00000000<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER]<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Enum]<br />
0 = &#8220;Root\LEGACY_ABP470N5000&#8243;<br />
Count = 0&#215;00000001<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5\Security]<br />
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\abp470n5]<br />
Type = 0&#215;00000001<br />
Start = 0&#215;00000003<br />
ErrorControl = 0&#215;00000001<br />
ImagePath = &#8220;%System%\drivers\flgko.sys&#8221;<br />
DisplayName = &#8220;abp470n5&#8243;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000\Control]<br />
*NewlyCreated* = 0&#215;00000000<br />
ActiveService = &#8220;abp470n5&#8243;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5000]<br />
Service = &#8220;abp470n5&#8243;<br />
Legacy = 0&#215;00000001<br />
ConfigFlags = 0&#215;00000000<br />
Class = &#8220;LegacyDriver&#8221;<br />
ClassGUID = &#8220;{8ECC055D-047F-11D1-A537-0000F8753ED1}&#8221;<br />
DeviceDesc = &#8220;abp470n5&#8243;<br />
Capabilities = 0&#215;00000000<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ABP470N5]<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000\Control]<br />
*NewlyCreated* = 0&#215;00000000<br />
ActiveService = &#8220;IpFilterDriver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER000]<br />
Service = &#8220;IpFilterDriver&#8221;<br />
Legacy = 0&#215;00000001<br />
ConfigFlags = 0&#215;00000000<br />
Class = &#8220;LegacyDriver&#8221;<br />
ClassGUID = &#8220;{8ECC055D-047F-11D1-A537-0000F8753ED1}&#8221;<br />
DeviceDesc = &#8220;IP Traffic Filter Driver&#8221;<br />
Capabilities = 0&#215;00000000<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER]<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Enum]<br />
0 = &#8220;Root\LEGACY_ABP470N5000&#8243;<br />
Count = 0&#215;00000001<br />
NextInstance = 0&#215;00000001<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5\Security]<br />
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0<br />
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5]<br />
Type = 0&#215;00000001<br />
Start = 0&#215;00000003<br />
ErrorControl = 0&#215;00000001<br />
ImagePath = &#8220;%System%\drivers\flgko.sys&#8221;<br />
DisplayName = &#8220;abp470n5&#8243;<br />
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system]<br />
DisableTaskMgr = 0&#215;00000001<br />
DisableRegistryTools = 0&#215;00000001</p>
<p>to prevent users from starting Task Manager (Taskmgr.exe)<br />
to disable the Windows registry editors (Regedt32.exe and Regedit.exe)<br />
[HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023]<br />
1919251285 = 0&#215;0000000D<br />
-456464726 = 0&#215;00000000<br />
1462786559 = 0&#215;00000000<br />
-912929452 = 0&#215;00000023<br />
1006321833 = 0&#215;000000D0<br />
-1369394178 = &#8220;0500687474703A2F2F6D696B656576656E74732E676F2E726F2F696D616765732F6C6F676F735F732E67696600687474703A2F2F6161726F6E646173747275702E636F6D2F696D616765732F6C6F676F735F732E67696600687474703A2F2F61616E6E6137342E65752E696E74657269612E706C2F6C6F676F735F732<br />
549857107 = &#8220;98D0D660D1605BD69A2A29715E39E1C3C36FBF4C3CB9D28605D66E0F6FC803B5EFF2E22D32F4E4838C75469C942158BE8C71ACD0052ABF4D63C4ECEAA31542B9AD17C8C20B6A905CB87FAA7370AE90F7A7286D29635A3A91C2F7091D4423729A586AD4EEE79E0FB5AFDB49B34E4F198DC3C47FC738A0AF4B515A9E365<br />
[HKEY_CURRENT_USER\Software\Apcrmkeh]<br />
U1_0 = 0xCC96283A<br />
U2_0 = 0&#215;0000158D<br />
U3_0 = 0&#215;01036A29<br />
U4_0 = 0&#215;00000000<br />
U1_1 = 0&#215;3C434D3C<br />
U2_1 = 0&#215;726566D8<br />
U3_1 = 0&#215;7366197C<br />
U4_1 = 0&#215;72657355<br />
U1_2 = 0xA07CA28F<br />
U2_2 = 0xE4CAF327<br />
U3_2 = 0xE5C98C83<br />
U4_2 = 0xE4CAE6AA<br />
U1_3 = 0&#215;407959CF<br />
U2_3 = 0&#215;57304C72<br />
U3_3 = 0&#215;563333D6<br />
U4_3 = 0&#215;573059FF<br />
U1_4 = 0&#215;2DE49FAD<br />
U2_4 = 0xC995D8D9<br />
U3_4 = 0xC896A77D<br />
U4_4 = 0xC995CD54<br />
U1_5 = 0&#215;05C27C61<br />
U2_5 = 0&#215;3BFB5524<br />
U3_5 = 0&#215;3AF82A80<br />
U4_5 = 0&#215;3BFB40A9<br />
U1_6 = 0xFAD02AA8<br />
U2_6 = 0xAE60A673<br />
U3_6 = 0xAF63D9D7<br />
U4_6 = 0xAE60B3FE<br />
U1_7 = 0&#215;5CD57500<br />
U2_7 = 0&#215;20C632DE<br />
U3_7 = 0&#215;21C54D7A<br />
U4_7 = 0&#215;20C62753<br />
U1_8 = 0&#215;6A4E9B0D<br />
U2_8 = 0&#215;932B8F25<br />
U3_8 = 0&#215;9228F081<br />
U4_8 = 0&#215;932B9AA8<br />
U1_9 = 0xAE7D98A4<br />
U2_9 = 0&#215;05911870<br />
U3_9 = 0&#215;049267D4<br />
U4_9 = 0&#215;05910DFD<br />
U1_10 = 0xC7CCC5EF<br />
U2_10 = 0&#215;77F69E3A<br />
U3_10 = 0&#215;76F5EB7B<br />
U4_10 = 0&#215;77F68152<br />
U1_11 = 0&#215;9A054AF6<br />
U2_11 = 0xEA5BEEE3<br />
U3_11 = 0xEB589E8E<br />
U4_11 = 0xEA5BF4A7<br />
U1_12 = 0xF1941DB1<br />
U2_12 = 0&#215;5CC174A0<br />
U3_12 = 0&#215;5DC20DD5<br />
U4_12 = 0&#215;5CC167FC<br />
U1_13 = 0&#215;6442F698<br />
U2_13 = 0xCF26C1F5<br />
U3_13 = 0xCE25B178<br />
U4_13 = 0xCF26DB51<br />
U1_14 = 0xCCF2087F<br />
U2_14 = 0&#215;418C5B58<br />
U3_14 = 0&#215;408F248F<br />
U4_14 = 0&#215;418C4EA6<br />
U1_15 = 0xF9F6F3A5</p>
<p>modifikasi lain di:<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]<br />
AlternateShell = &#8220;cmd.exe&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]<br />
(Default) = &#8220;Human Interface Devices&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]<br />
(Default) = &#8220;Volume&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Floppy disk drive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;System&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;SCSIAdapter&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;PCMCIA Adapters&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Mouse&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Keyboard&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Hdc&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Standard floppy disk controller&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;DiskDrive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;CD-ROM Drive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]<br />
(Default) = &#8220;Universal Serial Bus controllers&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinMgmt]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vgasave.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vga.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\System Bus Extender]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SRService]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sr.sys]<br />
(Default) = &#8220;FSFilter System Recovery&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sermouse.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SCSI Class]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\RpcSs]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Primary disk]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PNP Filter]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PlugPlay]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PCI Configuration]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Netlogon]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\HelpSvc]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Filter]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\File system]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\EventLog]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmserver]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmload.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmio.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmboot.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmadmin]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\DcomLaunch]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\CryptSvc]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot file system]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot Bus Extender]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Base]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmt]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]<br />
(Default) = &#8220;Human Interface Devices&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]<br />
(Default) = &#8220;Volume&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Floppy disk drive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;System&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;SCSIAdapter&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;PCMCIA Adapters&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;NetTrans&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;NetService&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;NetClient&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Net&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Mouse&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Keyboard&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Hdc&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;Standard floppy disk controller&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;DiskDrive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]<br />
(Default) = &#8220;CD-ROM Drive&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]<br />
(Default) = &#8220;Universal Serial Bus controllers&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\WZCSVC]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\WinMgmt]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\vgasave.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\vga.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\termservice]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdtcp.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdpipe.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\TDI]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Tcpip]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\System Bus Extender]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Streams Drivers]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SRService]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sr.sys]<br />
(Default) = &#8220;FSFilter System Recovery&#8221;<br />
[[pathname with a string SHARE]\SharedAccess]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\sermouse.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SCSI Class]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\RpcSs]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdsessmgr]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpwd.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpdd.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpcdd.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Primary disk]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP_TDI]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP Filter]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PlugPlay]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\PCI Configuration]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NtLmSsp]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm.sys]<br />
(Default) = &#8220;Driver&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\nm]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetworkProvider]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Network]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetMan]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Netlogon]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetDDEGroup]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBT]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOSGroup]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOS]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Ndisuio]<br />
(Default) = &#8220;Service&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS Wrapper]<br />
(Default) = &#8220;Driver Group&#8221;<br />
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS]<br />
(Default) = &#8220;Driver Group&#8221;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dotexe.wordpress.com/1648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dotexe.wordpress.com/1648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dotexe.wordpress.com/1648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dotexe.wordpress.com/1648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dotexe.wordpress.com/1648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dotexe.wordpress.com/1648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dotexe.wordpress.com/1648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dotexe.wordpress.com/1648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dotexe.wordpress.com/1648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dotexe.wordpress.com/1648/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1648&subd=dotexe&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://dotexe.unnes.ac.id/2009/10/31/virus-sality-terbaru-sality-ae/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f106671e9b8154cda46f270f0caff466?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">luthfi.emka</media:title>
		</media:content>
	</item>
		<item>
		<title>Download PCMAV 2.2 + Update Build 1</title>
		<link>http://dotexe.unnes.ac.id/2009/10/25/download-pcmav-2-2-update-build-1/</link>
		<comments>http://dotexe.unnes.ac.id/2009/10/25/download-pcmav-2-2-update-build-1/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 16:44:00 +0000</pubDate>
		<dc:creator>kulinet</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[komputer]]></category>
		<category><![CDATA[Pemrograman]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[update pcmav]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[ansav]]></category>
		<category><![CDATA[berita]]></category>
		<category><![CDATA[smadav]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[ansav update]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[update ansav]]></category>
		<category><![CDATA[handphone]]></category>
		<category><![CDATA[Analisis Virus]]></category>
		<category><![CDATA[update kaspersky]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Update AV]]></category>
		<category><![CDATA[Bluetooth]]></category>
		<category><![CDATA[dialogue]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[functionality]]></category>
		<category><![CDATA[Install]]></category>
		<category><![CDATA[kind]]></category>
		<category><![CDATA[manager]]></category>
		<category><![CDATA[Suggestion]]></category>
		<category><![CDATA[warning]]></category>
		<category><![CDATA[PCMAV Updatem PCMedia]]></category>
		<category><![CDATA[Avast]]></category>
		<category><![CDATA[Ad-Aware]]></category>
		<category><![CDATA[Update Smadav]]></category>
		<category><![CDATA[ntivirus]]></category>

		<guid isPermaLink="false">http://dotexe.wordpress.com/?p=1584</guid>
		<description><![CDATA[Download PCMAV 2.2 + Update Build 1 disini:

 Via Uploaded di http://ul.to/kpsgj6,
 Via Ziddu di http://www.ziddu.com/download/7070011/PCMAV-2.2-Update-1.intipadi.com.zip.html
 Via KewlShare di http://kewlshare.com/dl/9676ac0bb242/PCMAV-2.2-Update-1.intipadi.com.zip.html
 Via 4Shared di http://www.4shared.com/file/143536536/80bf2096/PCMAV-22-Update-1intipadicom.html

Apa yang baru di PCMAV 2.2 Ini? Inilah :
a. UPDATED! Ditambahkan database pengenal dan pembersih 71 virus lokal/
asing/varian baru yang dilaporkan menyebar di Indonesia. Total 3025
virus beserta variannya, termasuk varian virus Conficker <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1584&subd=dotexe&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Download PCMAV 2.2 + Update Build 1 disini:</p>
<ul>
<li> Via <strong>Uploaded</strong> di <a href="http://ul.to/kpsgj6">http://ul.to/kpsgj6</a>,</li>
<li> Via <strong>Ziddu</strong> di <a href="http://www.ziddu.com/download/7070011/PCMAV-2.2-Update-1.intipadi.com.zip.html">http://www.ziddu.com/download/7070011/PCMAV-2.2-Update-1.intipadi.com.zip.html</a></li>
<li> Via <strong>KewlShare</strong> di <a href="http://kewlshare.com/dl/9676ac0bb242/PCMAV-2.2-Update-1.intipadi.com.zip.html">http://kewlshare.com/dl/9676ac0bb242/PCMAV-2.2-Update-1.intipadi.com.zip.html</a></li>
<li> Via <strong>4Shared</strong> di <a href="http://www.4shared.com/file/143536536/80bf2096/PCMAV-22-Update-1intipadicom.html">http://www.4shared.com/file/143536536/80bf2096/PCMAV-22-Update-1intipadicom.html</a></li>
</ul>
<p>Apa yang baru di PCMAV 2.2 Ini? Inilah :<span id="more-1584"></span></p>
<p>a. UPDATED! Ditambahkan database pengenal dan pembersih 71 virus lokal/<br />
asing/varian baru yang dilaporkan menyebar di Indonesia. Total 3025<br />
virus beserta variannya, termasuk varian virus Conficker yang<br />
canggih, yang banyak beredar di Indonesia telah dikenal di versi<br />
2.2 ini.</p>
<p>b. IMPROVED! Ditambahkan pengenal khusus yang dapat mengenali virus<br />
Induc yang sedang banyak dilaporkan di seluruh dunia.</p>
<p>c. BUG FIXED! Kesalahan deteksi (false alarm) heuristik pada beberapa<br />
program dan script.</p>
<p>d. IMPROVED! Perubahan beberapa nama virus mengikuti varian baru yang<br />
ditemukan.</p>
<p>e. IMPROVED! Perbaikan beberapa minor bug dan improvisasi kode internal<br />
untuk memastikan bahwa PCMAV tetap dapat menjadi antivirus<br />
kebanggaan Indonesia.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dotexe.wordpress.com/1584/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dotexe.wordpress.com/1584/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dotexe.wordpress.com/1584/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dotexe.wordpress.com/1584/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dotexe.wordpress.com/1584/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dotexe.wordpress.com/1584/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dotexe.wordpress.com/1584/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dotexe.wordpress.com/1584/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dotexe.wordpress.com/1584/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dotexe.wordpress.com/1584/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dotexe.unnes.ac.id&blog=2170446&post=1584&subd=dotexe&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://dotexe.unnes.ac.id/2009/10/25/download-pcmav-2-2-update-build-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2628ffbd98b7bd8e7e915573bcb0bc74?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kulinet</media:title>
		</media:content>
	</item>
	</channel>
</rss>