<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DkACSX4-fSp7ImA9WhRaFEk.&quot;"><id>tag:blogger.com,1999:blog-8121439277147166860</id><updated>2012-02-16T18:12:48.055-08:00</updated><category term="data dan dokumen hilang" /><category term="promofromoffer" /><category term="Port 1900 dan IP 239.255.255.250" /><category term="Tipuan Trojan dan Malware" /><category term="menampilkan hidden folder" /><title>Lagi-lagi kejedot</title><subtitle type="html">Masalah yang terjadi pada komputer ku</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://aduh-kejedot.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://aduh-kejedot.blogspot.com/" /><author><name>Aduh Kejedot</name><uri>http://www.blogger.com/profile/18107528193867710572</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://4.bp.blogspot.com/_2b60Xo1gzcs/Se4U-ZW-dzI/AAAAAAAAABw/1CV3VAYRqwg/S220/orang-utan.jpeg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Lagi-lagiKejedot" /><feedburner:info uri="lagi-lagikejedot" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;DEcER3szfSp7ImA9WxJSEE4.&quot;"><id>tag:blogger.com,1999:blog-8121439277147166860.post-8721314508118912361</id><published>2009-04-29T11:31:00.000-07:00</published><updated>2009-04-29T13:13:26.585-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-29T13:13:26.585-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="menampilkan hidden folder" /><category scheme="http://www.blogger.com/atom/ns#" term="data dan dokumen hilang" /><title>Flashdisk kena virus, data hilang</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3hDmb5rRpNk_76FTnznL3MWfirE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3hDmb5rRpNk_76FTnznL3MWfirE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3hDmb5rRpNk_76FTnznL3MWfirE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3hDmb5rRpNk_76FTnznL3MWfirE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Kesal sekali, file hilang semua, padahal aku yakin telah menyimpan semua dokumen word ke flasdisk. Dalam file document tersebut ada yang berisi data penting mengenai &lt;u&gt;surat perjanjian jual beli tanah&lt;/u&gt;. Data Company Profile CV. Kaliandra juga menghilang, termasuk daftar alamat pengrajin sepatu di Cibaduyut, Bandung.&lt;br /&gt;&lt;br /&gt;Bukan itu saja, hasil download lagu terbaru &lt;u&gt;Rihanna, umbrella, Good Girl Gone Bad&lt;/u&gt; dan mp3 file dari 4shared pun lenyap. Film 3GP yang diam-diam ku salin dari komputer si mamo juga tidak ada, padahal itu filem anu (aduh kejedot .. aku baru tahu dataku hilang ketika ingin menontonnya).&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Menurut tabloid info komputer yang kubaca, file-file tersebut sebenarnya tidak hilang atau terhapus. Ini adalah perbuatan virus yang menyembunyikan semua isi flashdisk, lalu aku ikuti petunjuknya tentang bagaimana cara menampilkan kembali file atau folder yang di hidden.&lt;br /&gt;&lt;br /&gt;Petunjuknya begini:&lt;br /&gt;Klik &lt;span style="font-weight: bold;"&gt;start&lt;/span&gt; -&gt; &lt;span style="font-weight: bold;"&gt;run&lt;/span&gt; lalu ketik &lt;span style="font-weight: bold; color: rgb(255, 102, 0);font-family:courier new;" &gt;cmd&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Setelah jendela Command Promt tampil, ketiklah drive atau Removable Disk tujuan yang ingin dirubah attribut nya.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;C:\Document and Settings\user&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;i&lt;/span&gt;:  (lalu tekan enter)&lt;br /&gt;(&lt;span style="font-style: italic;"&gt; flashdrive ku ada di drive i, kamu dapat mengetahuinya dengan membuka Windows Explorer.&lt;/span&gt;)&lt;br /&gt;Jika sudah pindah drive, ketik&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I:\&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 102, 0); font-weight: bold;"&gt;attrib&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;-r&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;-h&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;-s&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;*.*&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;/s&lt;/span&gt;[spasi]&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;/d&lt;/span&gt; (kemudian tekan ENTER)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_2b60Xo1gzcs/SfiiNE-oStI/AAAAAAAAACY/z_WBXqy_SZE/s1600-h/change-file-attribute.png" title="change-file-attribute"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 393px; height: 170px;" src="http://3.bp.blogspot.com/_2b60Xo1gzcs/SfiiNE-oStI/AAAAAAAAACY/z_WBXqy_SZE/s400/change-file-attribute.png" alt="change-file-attribute" id="BLOGGER_PHOTO_ID_5330188504551410386" border="0" /&gt;&lt;/a&gt;&lt;blockquote&gt;Apa berhasil? ya dan tidak. Ketika mempraktekannya di komputer temanku hidden folder dan semua file ada kembali, tetapi begitu flashdisk tersebut ditancap ke PC ku huilang lagi.&lt;/blockquote&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8121439277147166860-8721314508118912361?l=aduh-kejedot.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Lagi-lagiKejedot/~4/Yl1FjH9xM4U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://aduh-kejedot.blogspot.com/feeds/8721314508118912361/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://aduh-kejedot.blogspot.com/2009/04/flashdisk-kena-virus-data-hilang.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/8721314508118912361?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/8721314508118912361?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Lagi-lagiKejedot/~3/Yl1FjH9xM4U/flashdisk-kena-virus-data-hilang.html" title="Flashdisk kena virus, data hilang" /><author><name>Aduh Kejedot</name><uri>http://www.blogger.com/profile/18107528193867710572</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://4.bp.blogspot.com/_2b60Xo1gzcs/Se4U-ZW-dzI/AAAAAAAAABw/1CV3VAYRqwg/S220/orang-utan.jpeg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_2b60Xo1gzcs/SfiiNE-oStI/AAAAAAAAACY/z_WBXqy_SZE/s72-c/change-file-attribute.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://aduh-kejedot.blogspot.com/2009/04/flashdisk-kena-virus-data-hilang.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUBSHsycSp7ImA9WxJSEE4.&quot;"><id>tag:blogger.com,1999:blog-8121439277147166860.post-8948235778928571986</id><published>2009-04-17T05:00:00.000-07:00</published><updated>2009-04-29T12:44:19.599-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-29T12:44:19.599-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Port 1900 dan IP 239.255.255.250" /><title>Port 1900 apa bahaya?</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nvI0dTnPfnA2FrSvrN_BcS0JWY0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nvI0dTnPfnA2FrSvrN_BcS0JWY0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nvI0dTnPfnA2FrSvrN_BcS0JWY0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nvI0dTnPfnA2FrSvrN_BcS0JWY0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;Begitu modem ku konek ke Internet, langsung muncul pemberitahuan dari Software Firewall yang ku install. . . ini gambarnya.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_2b60Xo1gzcs/Sed4lD6UdxI/AAAAAAAAABM/o9J08RqQAWo/s1600-h/port-1900.jpg" title="Generic Host Process for Win32 Services (svchost.exe) is trying to broadcast to [239.255.255.250]. Using remote port 1900 (SSDP - Simple Service Discovery Protocol). Do you want to allow this program to access the network?"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 105px;" src="http://2.bp.blogspot.com/_2b60Xo1gzcs/Sed4lD6UdxI/AAAAAAAAABM/o9J08RqQAWo/s320/port-1900.jpg" alt="warning port 1900" id="BLOGGER_PHOTO_ID_5325357662489310994" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Karena penasaran aku klik YES saja, dan coba cari tahu.&lt;br /&gt;Port 1900 adalah port UDP (User Datagram Protocol), port ini memang terbuka dan digunakan oleh windows untuk menjalankan Universal Plug and Play (UPnP) service.&lt;br /&gt;&lt;br /&gt;Untuk menjalankan UPnP service tersebut windows menggunakan:&lt;ul&gt;&lt;li&gt;Simple Service Discovery Protocol (SSDP). Servis ini untuk menemukan perangkat UPnP di dalam jaringan/network.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Universal Plug and Play Device Host. Servis ini menyediakan suport ke host dari perangkat Universal Plug and Play(mungkin ini artinya server, komputer, atau mesin lain ya?)&lt;/li&gt;&lt;/ul&gt;Setiap perangkat UPnP saling mengirimkan dan menerima paket data atau pesan dari perangkat UPnP lainnya. Dibawah ini Gambar dari Packet Log firewall.&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_2b60Xo1gzcs/Sed7CWSP6II/AAAAAAAAABU/P8YzaE_jitE/s1600-h/Packet-Log.png" title="Packet Log Firewall"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 215px;" src="http://2.bp.blogspot.com/_2b60Xo1gzcs/Sed7CWSP6II/AAAAAAAAABU/P8YzaE_jitE/s320/Packet-Log.png" alt="Firewall Packet Log" id="BLOGGER_PHOTO_ID_5325360364660975746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Tapi kenapa kok broadcast nya ke IP 239.255.255.250 ?&lt;br /&gt;Setelah di trace dan di lihat dengan whois lookup, hasilnya ini:&lt;br /&gt;&lt;blockquote&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgName:    Internet Assigned Numbers Authority&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgID:      IANA&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Address:    4676 Admiralty Way, Suite 330&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;City:       Marina del Rey&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;StateProv:  CA&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;PostalCode: 90292-6695&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Country:    US&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NetRange:   224.0.0.0 - 239.255.255.255&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;CIDR:       224.0.0.0/4&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NetName:    MCAST-NET&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NetHandle:  NET-224-0-0-0-1&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Parent:    &lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NetType:    IANA Special Use&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NameServer: FLAG.EP.NET&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NameServer: STRUL.STUPI.SE&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NameServer: NS.ISI.EDU&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;NameServer: NIC.NEAR.NET&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Comment:    This block is reserved for special purposes.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Comment:    Please see RFC 3171 for additional information.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Comment:   &lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;RegDate:    1991-05-22&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;Updated:    2002-09-16&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgAbuseHandle: IANA-IP-ARIN&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgAbuseName:   Internet Corporation for Assigned Names and Number&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgAbusePhone:  +1-310-301-5820&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgAbuseEmail:  abuse@iana.org&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgTechHandle: IANA-IP-ARIN&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgTechName:   Internet Corporation for Assigned Names and Number&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgTechPhone:  +1-310-301-5820&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;OrgTechEmail:  abuse@iana.org&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;# ARIN WHOIS database, last updated 2009-04-15 19:10&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;# Enter ? for additional hints on searching ARIN's WHOIS database.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;Nomer IP tersebut digunakan untuk alamat IP multicast.  Dan daripada aku pusing  mengartikan n ngetiknya, tak kasih link  nya aja deh..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/IP_multicast" target="_blank"&gt;IP Multicast&lt;/a&gt; &lt;a href="http://www.iana.org/protocols/" target="_blank"&gt;Protocol&lt;/a&gt; &lt;a href="http://www.iana.org/assignments/multicast-addresses/multicast-addresses.xhtml" target="_blank"&gt;Multicast-address&lt;/a&gt; &lt;a href="http://tools.ietf.org/html/rfc3171" target="_blank"&gt;RFC 3171&lt;/a&gt;&lt;br /&gt;http://en.wikipedia.org/wiki/IP_multicast&lt;br /&gt;http://www.iana.org/protocols/&lt;br /&gt;http://www.iana.org/assignments/multicast-addresses/multicast-addresses.xhtml&lt;br /&gt;http://tools.ietf.org/html/rfc3171&lt;br /&gt;&lt;br /&gt;Waduh ini ada yang muncul lagi..&lt;br /&gt;&lt;blockquote&gt;"&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;Generic Host Process for Win32 Services (svchost.exe) is trying to broadcast to [224.0.0.22]. Do you want to allow this program to access the network?&lt;/span&gt;&lt;/span&gt;"&lt;/blockquote&gt;&lt;blockquote&gt;"&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;NT Kernel System (NTOSKRNL.EXE) is trying to broadcast to [224.0.0.22]. Do you want to allow this program to access the network?&lt;/span&gt;&lt;/span&gt;"&lt;/blockquote&gt;Ini pasti akibat di klik YES.&lt;br /&gt;Terus harusnya bagaimana apa port 1900 itu ditutup saja, ada yang bilang sih bahaya kalau otomatis terbuka.&lt;br /&gt;&lt;br /&gt;Biar tau bahaya apa nggak, download 2 file PDF  di ziddu&lt;br /&gt;http://www.ziddu.com/download/4325636/Port1900.rar.html dan  http://www.ziddu.com/download/4325635/Port_Plug_n_Pray.rar.html&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8121439277147166860-8948235778928571986?l=aduh-kejedot.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Lagi-lagiKejedot/~4/jVhORpr_ck0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://aduh-kejedot.blogspot.com/feeds/8948235778928571986/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://aduh-kejedot.blogspot.com/2009/04/port-1900-apa-bahaya.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/8948235778928571986?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/8948235778928571986?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Lagi-lagiKejedot/~3/jVhORpr_ck0/port-1900-apa-bahaya.html" title="Port 1900 apa bahaya?" /><author><name>Aduh Kejedot</name><uri>http://www.blogger.com/profile/18107528193867710572</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://4.bp.blogspot.com/_2b60Xo1gzcs/Se4U-ZW-dzI/AAAAAAAAABw/1CV3VAYRqwg/S220/orang-utan.jpeg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_2b60Xo1gzcs/Sed4lD6UdxI/AAAAAAAAABM/o9J08RqQAWo/s72-c/port-1900.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://aduh-kejedot.blogspot.com/2009/04/port-1900-apa-bahaya.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYCQno5eSp7ImA9WxJSEE4.&quot;"><id>tag:blogger.com,1999:blog-8121439277147166860.post-6796381709686439133</id><published>2009-04-13T01:34:00.001-07:00</published><updated>2009-04-29T12:26:03.421-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-29T12:26:03.421-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tipuan Trojan dan Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="promofromoffer" /><title>tipuan trojan atau malware</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aENzvOQW7IaREnYgj7eDYxEOh-g/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aENzvOQW7IaREnYgj7eDYxEOh-g/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/aENzvOQW7IaREnYgj7eDYxEOh-g/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aENzvOQW7IaREnYgj7eDYxEOh-g/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;Whether you know it or not your computer is always at risk of becoming infected with viruses, worms, trojans, rootkits, dialers, spyware, and malware that are constantly evolving and becoming harder to detect and remove. Only the most sophisticated anti-malware techniques can detect and remove these malicious programs from your computer. &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Setiap  komputerku konek ke internet pasti muncul pop up halaman promofromoffer, dilanjutkan dengan munculnya popup yang memberitahukan bahwa komputer ku tidak aman, "segera download antivirus-xp 2009".&lt;br /&gt;&lt;br /&gt;Untung aku nggak ketipu untuk mengklik popup tersebut, pokoknya jangan klik yes atau cancel, termasuk meng-klik tanda silang, karena itu juga tipuan. Matikan Internet Explorernya dengan menggunakan Task Manager, emang sih cara ini gak efektif karena semua halaman yang kita buka pake IE bakalan ketutup.&lt;br /&gt;&lt;br /&gt;Selain kejadian tersebut PC ku juga berusaha terhubung ke situs griehe.com, 299979593048282496.joeplz.com, dan situs-situs gak bener lainnya.  Antivirus, anti trojan, anti malware yang ku punya pada buta semua alias gak ngedeteksi.&lt;br /&gt;&lt;br /&gt;Setelah googling akhirnya ketemu juga software untuk membasmi trojan dan malware yang ampuh, yaitu Malwarebytes' Anti-Malware yang bisa didownload di &lt;span class="fullpost"&gt;malwarebytes.org&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_2b60Xo1gzcs/SeREFypdcRI/AAAAAAAAAA8/6pHFVZxZgS4/s1600-h/malware-perform-full-scan.jpg" title="malware-perform-full-scan"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 242px;" src="http://3.bp.blogspot.com/_2b60Xo1gzcs/SeREFypdcRI/AAAAAAAAAA8/6pHFVZxZgS4/s320/malware-perform-full-scan.jpg" alt="malware perform full-scan" id="BLOGGER_PHOTO_ID_5324455525744472338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_2b60Xo1gzcs/SeREl37_rmI/AAAAAAAAABE/VrvsvFJ57wA/s1600-h/hasil-scan-malwarebytes.jpg" title="hasil scan malwarebytes"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 242px;" src="http://1.bp.blogspot.com/_2b60Xo1gzcs/SeREl37_rmI/AAAAAAAAABE/VrvsvFJ57wA/s320/hasil-scan-malwarebytes.jpg" alt="hasil-scan-malwarebytes" id="BLOGGER_PHOTO_ID_5324456076920204898" border="0" /&gt;&lt;/a&gt;Dibawah ini adalah laporannya:&lt;br /&gt;&lt;blockquote&gt;Malwarebytes' Anti-Malware 1.36&lt;br /&gt;Database version: 1945&lt;br /&gt;Windows 5.1.2600 Service Pack 2&lt;br /&gt;&lt;br /&gt;4/13/2009 11:48:52 AM&lt;br /&gt;mbam-log-2009-04-13 (11-48-52).txt&lt;br /&gt;&lt;br /&gt;Scan type: Full Scan (C:\|)&lt;br /&gt;Objects scanned: 165780&lt;br /&gt;Time elapsed: 1 hour(s), 39 minute(s), 11 second(s)&lt;br /&gt;&lt;br /&gt;Memory Processes Infected: 0&lt;br /&gt;Memory Modules Infected: 2&lt;br /&gt;Registry Keys Infected: 14&lt;br /&gt;Registry Values Infected: 2&lt;br /&gt;Registry Data Items Infected: 2&lt;br /&gt;Folders Infected: 0&lt;br /&gt;Files Infected: 5&lt;br /&gt;&lt;br /&gt;Memory Processes Infected:&lt;br /&gt;(No malicious items detected)&lt;br /&gt;&lt;br /&gt;Memory Modules Infected:&lt;br /&gt;C:\WINDOWS\system32\qoMdDvVl.dll (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;C:\WINDOWS\system32\emehqb.dll (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;&lt;br /&gt;Registry Keys Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53fa93af-2925-4fd0-bba9-c7382527c235} (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;HKEY_CLASSES_ROOT\CLSID\{53fa93af-2925-4fd0-bba9-c7382527c235} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9737d1ab-9ee1-499a-936e-640b1782d7ad} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CLASSES_ROOT\CLSID\{9737d1ab-9ee1-499a-936e-640b1782d7ad} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CLASSES_ROOT\CLSID\{7ec6076b-b489-405f-8262-b0d733617b73} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9737d1ab-9ee1-499a-936e-640b1782d7ad} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{53fa93af-2925-4fd0-bba9-c7382527c235} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -&gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;br /&gt;Registry Values Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7ec6076b-b489-405f-8262-b0d733617b73} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{7ec6076b-b489-405f-8262-b0d733617b73} (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;br /&gt;Registry Data Items Infected:&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -&gt; Data: c:\windows\system32\qomddvvl -&gt; Quarantined and deleted successfully.&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -&gt; Data: c:\windows\system32\qomddvvl  -&gt; Delete on reboot.&lt;br /&gt;&lt;br /&gt;Folders Infected:&lt;br /&gt;(No malicious items detected)&lt;br /&gt;&lt;br /&gt;Files Infected:&lt;br /&gt;C:\WINDOWS\system32\qoMdDvVl.dll (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;C:\WINDOWS\system32\lVvDdMoq.ini (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;C:\WINDOWS\system32\lVvDdMoq.ini2 (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;C:\WINDOWS\system32\emehqb.dll (Trojan.Vundo.H) -&gt; Delete on reboot.&lt;br /&gt;C:\WINDOWS\system32\gtlfvnha.dll (Trojan.Vundo.H) -&gt; Quarantined and deleted successfully.&lt;br /&gt;&lt;/blockquote&gt;:)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8121439277147166860-6796381709686439133?l=aduh-kejedot.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Lagi-lagiKejedot/~4/vfIJta5b73s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://aduh-kejedot.blogspot.com/feeds/6796381709686439133/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://aduh-kejedot.blogspot.com/2009/04/tipuan-tojan-atau-malware.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/6796381709686439133?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8121439277147166860/posts/default/6796381709686439133?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Lagi-lagiKejedot/~3/vfIJta5b73s/tipuan-tojan-atau-malware.html" title="tipuan trojan atau malware" /><author><name>Aduh Kejedot</name><uri>http://www.blogger.com/profile/18107528193867710572</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://4.bp.blogspot.com/_2b60Xo1gzcs/Se4U-ZW-dzI/AAAAAAAAABw/1CV3VAYRqwg/S220/orang-utan.jpeg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_2b60Xo1gzcs/SeREFypdcRI/AAAAAAAAAA8/6pHFVZxZgS4/s72-c/malware-perform-full-scan.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://aduh-kejedot.blogspot.com/2009/04/tipuan-tojan-atau-malware.html</feedburner:origLink></entry></feed>

