Cara Mengatasi Virus KSpoold
Virus KSpoold adalah salah satu jenis virus yang mungkin termasuk kelas menengah karene memiliki sifat sebagai berikut:
a. Tidak melakukan blocking (Task Manager, Registry editor, system configuration Utility, dan Command prompt)
b. Hanya menyerang dokumen Word dan Exel
Nah bagai mana mengatasinya jika file dokumen kita terserang virus ini???
ikuti langkah-langkah berikut:
1. Buka notepad
2. Tulis script dibawah ini kedalam Notepad
echo off
cls
REM - ubah warna
color a
REM - ubah judul
title KSPOOLD KILLER * by nama anda
REM - masuk ke direktori sistem
%SYSTEMDRIVE%
cd %SYSTEMDRIVE%\system32
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo KSPOOLD KILLER
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo after you press any keys on ypu keyboard, I do
echo - removing related registry
echo - stopping kspoold process
echo - deleting kspoold file in the system directory
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo.
pause
echo.
REM - hapus registry yang dibuat sebagai service virus
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\controlset001\services\kspooldaemon" /f
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\controlset002\services\kspooldaemon" /f
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\Currentcontrolset\services\kspooldaemon" /f
REM - hentikan proses virus
taskkill /IM kspoold.exe /F /T
REM - set atribut file virus menjadi normal
attrib -s -h -r kspoold.exe
REM - hapus file virus
del kspoold.exe
Cls
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo KSPOOLD KILLER
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo after you press any keys on ypu keyboard, I do
echo - removing related registry
echo - stopping kspoold process
echo - deleting kspoold file in the system directory
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo.
echo press any key to continue . . .
echo.
echo will done - The "kspoold" was completely removed
echo.
pause
Simpan dengan nama KSpoold killer.BAT
Save As type diganti ALL FILE
Cara menjalankan cukup klik dua kali
Semoga bermanfaat........
a. Tidak melakukan blocking (Task Manager, Registry editor, system configuration Utility, dan Command prompt)
b. Hanya menyerang dokumen Word dan Exel
Nah bagai mana mengatasinya jika file dokumen kita terserang virus ini???
ikuti langkah-langkah berikut:
1. Buka notepad
2. Tulis script dibawah ini kedalam Notepad
echo off
cls
REM - ubah warna
color a
REM - ubah judul
title KSPOOLD KILLER * by nama anda
REM - masuk ke direktori sistem
%SYSTEMDRIVE%
cd %SYSTEMDRIVE%\system32
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo KSPOOLD KILLER
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo after you press any keys on ypu keyboard, I do
echo - removing related registry
echo - stopping kspoold process
echo - deleting kspoold file in the system directory
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo.
pause
echo.
REM - hapus registry yang dibuat sebagai service virus
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\controlset001\services\kspooldaemon" /f
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\controlset002\services\kspooldaemon" /f
reg delete "HKEY_LOKAL_MACHINE\SYSTEM\Currentcontrolset\services\kspooldaemon" /f
REM - hentikan proses virus
taskkill /IM kspoold.exe /F /T
REM - set atribut file virus menjadi normal
attrib -s -h -r kspoold.exe
REM - hapus file virus
del kspoold.exe
Cls
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo KSPOOLD KILLER
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo after you press any keys on ypu keyboard, I do
echo - removing related registry
echo - stopping kspoold process
echo - deleting kspoold file in the system directory
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
echo.
echo press any key to continue . . .
echo.
echo will done - The "kspoold" was completely removed
echo.
pause
Simpan dengan nama KSpoold killer.BAT
Save As type diganti ALL FILE
Cara menjalankan cukup klik dua kali
Semoga bermanfaat........