HXHACKER-Hacker University

HxHacker berisi tentang Tutorial dan Artikel terkait dalam bilang Komputer (Hacking, Virus, dll).

Hacking

Tutorial Hacking dalam HxHacker berkaitan dengan celah keamanan pada sistem komputer.

Membuat Virus

Tutorial Pembuatan Virus dalam HxHacker adalah membuat virus dengan skirpt - skript yang terdapat pada sebuah virus sehingga menjadi virus baru.

Tampilkan postingan dengan label Eksekusi Virus Tanpa ANTIVIRUS. Tampilkan semua postingan
Tampilkan postingan dengan label Eksekusi Virus Tanpa ANTIVIRUS. Tampilkan semua postingan

Sabtu, 14 Mei 2011

Eksekusi Virus Shortcut

Selama ini Virus sudah berkembang dengan berbagai jenis atau ekstensi. Virus juga mempunyai cara untuk merusak yang berbeda - beda. Kali ini HxHacker akan membahas Virus Shortcut, virus ini biasanya terdapat pada Flashdisk atau Memori Eksternal. Keunggulan Virus ini adalah saat alat penyimpanan data (contoh:Flashdisk) terhubung dengan komputer, alat penyimpanan langsung terinfeksi, biasanya terdapat file Copy of Shortcut to.ink sebanyak 4 file. File tersebut tidak bisa dihapus, karena jika dihapus akan kembali lagi. Berikut adalah cara Eksekusi Virus tersebut:



1. Nonaktifkan ‘System Restore’ untuk sementara selama proses Eksekusi.

2. Putuskan Jaringan/Koneksi Internet Komputer .

3. Matikan proses virus yang aktif di memori dengan menggunakan tools ‘Ice Sword’. Setelah tools tersebut terinstal, pilih file yang mempunyai icon ‘Microsoft Visual Basic Project’ kemudian klik ‘Terminate Process’. Silahkan download tools tersebut di http://icesword.en.softonic.com/ .

4. Hapus registri yang sudah dibuat oleh virus dengan cara:
-. Klik menu>Start.
-. Klik Run.
-. Ketik REGEDIT.exe, kemudian klik Ok.
-. Pada aplikasi Registry Editor, carii key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Kemudian hapus key yang mempunyai data C:\Document and Settings\%user% .


5. Copy dan Paste skript Berikut di Notepad:
------------------------------Skript------------------------------
[Version]
Signature=”$Chicago$”
Provider=Vaksincom
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\comfile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\exefile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\piffile\shell\open\command,,,”"”%1″” %*”
HKLM, Software\CLASSES\regfile\shell\open\command,,,”regedit.exe “%1″”
HKLM, Software\CLASSES\scrfile\shell\open\command,,,”"”%1″” %*”
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255

---------------------------akhir skript---------------------------

Pada Notepad pilih "File" lalu klik "Save as", lalu ubah save as type menjadi "all files", simpan dengan format ".inf", misal Hx.inf, lalu klik kanan pada file tersebut, pilih "install".


6. Hapus File induk dan file duplikat yang dibuat oleh virus termasuk di flash disk. Untuk mempercepat proses pencarian, Anda dapat menggunakan fungsi ‘Search’. Sebelum melakukan pencarian sebaiknya tampilkan semua file yang tersembunyi dengan mengubah pada setting Folder Options.
Jangan sampai terjadi kesalahan pada saat menghapus file induk maupun file duplikat yang telah dibuat oleh virus. Lalu hapus file induk virus yang mempunyai ciri-ciri:
-. Icon ‘Microsoft Visual Basic Project’.
-. Ukuran File 128 KB (untuk varian lain akan mempunyai ukuran yang bervariasi).
-. Ekstesi file ‘.EXE’ atau ‘.SCR’.
-. Type file ‘Application’ atau ‘Screen Saver’.
Kemudian hapus File duplikat shortcut yang mempunyai ciri-ciri:
>. Icon Folder atau icon
>. Ekstensi .LNK
>. Type File ‘Shortcut’
>. Ukuran file 1 KB
Hapus juga file yang .DLL (contoh: ert.dll) dan file Autorun.inf di flash disk atau folder yang di-share. Sementara untuk menghindari virus tersebut aktif kembali, hapus file induk yang mempunyai ekstensi EXE atau SCR terlebih dahulu baru kemudian hapus file Shortcut (.LNK).

7. Tampilkan kembali folder yang telah disembunyikan oleh virus. Untuk mempercepat proses tersebut, silahkan download tools UnHide File and Folder di http://www.flashshare.com/bfu/download.html.
Setelah diinstall, pilih direktori [C:\Documents and settings] dan folder yang ada di flash disk dengan cara menggeser ke kolom yang sudah tersedia. Pada menu [Attributes] kosongkan semua pilihan yang ada, kemudian klik tombol [Change Attributes].

Restart Komputer untuk melihat hasil dari proses eksekusi.

__________________________________________________________________




Zeke hack {Trickster}



Senin, 11 April 2011

Eksekusi Virus Facebook

Banyak cara - cara yang digunakan oleh para Cracker untuk mencuri Password Social Networking (Facebook), salah satunya adalah dengan membuat virus bernama Facebook yang isinya akan menjebak anda dengan mengirimkan e-mail yang seolah - olah facebook menginginkan anda merubah password anda dengan berperan sebagai Spyware yang mencoba melindungi. Berikut adalah cara Eksekusi Virus tersebut:

1. Siapkan Software Unlocker.

2. Putuskan koneksi komputer anda dengan Internet.

3. Matikan System Restore, lalu Restart dan masuklah ke menu safe mode.

4. Matikan proses virus yang masih aktif di memori melaui Task Manager. Matikan sdra64.exe.

5. Untuk Memperbaiki Registry Copy dan Paste Skript Berikut di Notepad:

------------------------------Skript------------------------------
[Version]
Signature="$Chicago$"


[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKCU, Software\Microsoft\Internet Explorer\Main, tart Page,0, "about:blank"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,userinit,0, "userinit.exe"

[del]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,47543326
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,PromoReg
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,reader_s
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,EnableProfileQuota
HKLM, SOFTWARE\AGProtect
HKLM, SOFTWARE\47543326
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network, UID
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion, Rlist
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
HKU, .DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{8FFA689D-2C2B-2B2E-D865-74C04CA4EF06}


---------------------------akhir skript---------------------------

6. Matikan Proses Virus yang masih berjalan dengan Unlocker.Hapus file yang dibuat oleh virus,sebelumnya agar file virus terlihat, buka Windows Explorer>Tools>Folder Options>Pilih tab View>Pada hidden files and folders pilih Show hidden files and folders. Kemudian hapus file berikut:

C:\Documents and Settings\All Users\Application Data\47543326
C:\Documents and Settings\Elvina\Start Menu\Programs\Security Tools.lnk
C:\Documents and Settings\Elvina\Desktop\ Security Tools.lnk
C:\Documents and Settings\Elvina\Application Data\ wiaservg.log
C:\Documents and Settings\Elvina\Local Settings\Temp\*.tmp
C:\WINDOWS\Temp\ wpv311256600826.exe
C:\WINDOWS\Temp\ wpv411256806849.exe
C:\Documents and Settings\%user%\reader_s.exe
C:\Documents and Settings\%user%\Start Menu\Programs\Startup\isqsys32.exe
C:\WINDOWS\system32\reader_s.exe
C:\Windows\system32\wbem\proquota.exe
C:\windows\system32\sdra64.exe
C:\Windows\system32\lowsec
local.ds
user.ds
user.ds.lll

Setelah itu Restart Komputer
__________________________________________________________________
----Gunakanlah Tutorial Dengan Bijak----



Zeke hack {Trickster}


Sabtu, 02 April 2011

Eksekusi Virus Rontokbro.GOL

Virus Rontokbro adalah virus lokal yang tergolong berbahaya karena sampai menjangkau Save Mode. Virus ini mempunyai kemampuan merusak yang lumayan dan sulit dihentikan bila tidak ada ANTIVIRUS. Namun ada cara untuk menghentikan kinerja Virus tersebut tanpa menggunakan ANTIVIRUS. Berikut adalah cara Eksekusi Virus tersebut:

1. Matikan System Restore pada komputer.

2. Matikan Proser yang berjalan di memori seperti lsass.exe, services.exe, dan winlogon.exe, kemudian matikan juga file lain yang berada di "C:\Documents and sttings\%user%\Local Settings\Aplication\Data" dari daftar autorun di Registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run dan HKEY_LOCAL _MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.

3. Untuk Memperbaiki Registry Copy dan Paste Skript Berikut di Notepad:

------------------------------Skript------------------------------
[Version]
Signature="$Chicago$"

[Version]
Signature="$Chicago$"
Provider=Microsoft

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, X84-YitnoDiah
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Diah-YitnosX84
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableCMD
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools

---------------------------akhir skript---------------------------

4. Pada Notepad pilih "File" lalu klik "Save as", lalu ubah save as type menjadi "all files", simpan dengan format ".inf", misal Hx.inf, lalu klik kanan, pilih "install".

5.Hapus file induk dan file duplikat yang dibuat oleh virus dengan menggunakan fungsi Search Windows di semua Drive termasuk Removable Disk [Flash Disk]. Kemudian hapus file didalam folder berikut: C:\Documents and settings\%user%\Local Settings\Application Data
* Winlogon.exe
* services.exe
* lsass.exe
* smss.exe
* inetinfo.exe
* Diah84.Yitn.oss.txt
* csrss.exe
* C:\Windows\Inf\Yitnoss.exe
* C:\Documents and settings\%user%\Start Menu\Programs\Startup\YITNO.pif
* C:\Documents and Settings\%user%\Templates\B.Yitnoss.com


Hapus juga file/folder berikut:
C:\Documents and settings\%user%\Local Settings\Application Data
* 84-DiahLove-Yitn-oss
* Yitn.oss-3-27
* Yitn.oss-3-31
* Diah84.Yitn.oss.txt
____________________________________________________________________
----Gunakanlah Tutorial Dengan Bijak----



Zeke hack {Trickster}

Sabtu, 26 Februari 2011

Eksekusi Virus Cantix

Dalam Tutorial kali ini HxHacker akan membahas tentang Eksekusi Virus Cantix. Seperti yang diketahui sebelumnya, Virus ini tidak bisa dihapus secara langsung dan akan membuat Shortcut dengan sendirinya. Virus ini juga akan membawa anda ke situs bendot.co.nr. Berikut adalah cara Eksekusi Virus tersebut:

1. Putuskan Koneksi Jaringan di komputer (baik Koneksi LAN dan juga Internet).

2. Nonaktifkan/Matikan System Restore selama proses Eksekusi/Pembersihan.

3. Matikan Proses WSCRIPT.exe di Task Manager.

4. Untuk Menghapus File yang virus buat di Registry, Copy dan Paste skript Berikut di Notepad:
------------------------------Skript------------------------------
[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKLM, Software\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0x000000ff,255
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,ShowSuperHidden,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,SuperHidden,0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Df5serv
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Svchost
HKCU, Software\Microsoft\Windows\CurrentVersion\Run, Explorer
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistrytools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, WarningIfNotDefault
HKLM, Software\Microsoft\Windows\CurrentVersion\Run, WinUpdate
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder
HKCU, Software\Microsoft\Internet Explorer\Main,Start Page

---------------------------akhir skript---------------------------

Pada Notepad pilih "File" lalu klik "Save as", lalu ubah save as type menjadi "all files", simpan dengan format ".inf", misal Hx.inf, lalu klik kanan pada file tersebut, pilih "install".


5. Buka Explorer.exe, lalu klik menu "Tools>Folder>Options>View" lalu aktifkan opsi "Show hidden and folders" dan nonaktifkan opsi "Hide ProtectedOperating System files (Recommended)".

6. Gunakan "Software Restriction Policies"untuk memblokir file induk virus. Caranya adalah, Jalankan "secpol.msc" pada menu "Run" yang terletak di Tombol "Start". Pada Jendela "Local Security Settings", klik kanan "Software Restriction Policies", klik "Create new policies", lalu klik kanan pada "Additional Rules", dan Klik "New Hash Rule...". Pada kolom "File hash", klik tombol "browse" kemudian cari file "desktop.ini", lalu klik file tersebut yang mempunyai ukuran 16 KB. Pada kolom "Security Level" pilih "Disallowed".

7. Hapus file berikut:

# C:\Windows\Microsoft Office Update for Windows XP.sys
# C:\Documents and Settings\%user%\My Documents\df5srvc.bfe

# C:\Documents and Settings\%user%\Local Settings\Application Data\Microsoft\CD Burning\desktop.ini

# C:\WINDOWS\system32\serviks.sys
# C:\WINDOWS\svchost.exe

# C:\WINDOWS\task\autorun.inf

# C:\WINDOWS\task\desktop.ini

# C:\WINDOWS\task\Folder.ink

# C:\WINDOWS\system32\auto.exe

# C:\WINDOWS\system32\rad%xx%.tmp


Untuk Tanda Persen (%%) (contoh : rad72C8D.tmp)

8. Hapus file bernama "autorun.inf" dengan ukuran 1 KB dan "desktop.ini" dengan ukuran 16 KB.

9. Salin file MSVBVM60.dll dari komputer lain dengan Oprating System (OS) yang sama dan belum terinfeksi virus tersebut, kemudian simpan ke direktori "C:\WINDOWS\system 32".

____________________________________________________________________



Zeke hack {Trickster}

Sabtu, 05 Februari 2011

Eksekusi Virus Luna Maya ( ala Hacker )

Seringkali komputer yang terinfeksi virus hanya mengandalkan ANTIVIRUS, padahal banyak virus yang lolos dari pantauan ANTIVIRUS terutama virus lokal. Tutorial kali ini akan membahas Eksekusi Virus Luna Maya tanpa menggunakan ANTIVIRUS. Dalam Virus ini terdapat perintah yang berbahaya yaitu: memformat Flash Disk/ removable disk lainnya, mengubah fungsi klik kanan menjadi klik kiri, memindahkan tombol start ke kiri ketika di klik, CD/DVD-Room yang tidak bisa ditutup, dll. Ciri dari virus ini adalah memakai ikon MS Word dan berukuran 37 kb. Virus tersebut akan membuat file virus, antara lain:
  • C:\nt.bat
  • C:\WINDOWS\system32\Amoumain.exe
  • Love.exe (pada semua root drive)


Untuk mengeksekusi virus tersebut, Berikut Caranya:


1. Download Software CurrProcess disini. Lalu ekstrak Program tersebut (CurrProcess bukanlah Program ANTIVIRUS, tapi memiliki fungsi hampir mirip dengan Task Manager).

[Penjelasan]
---Karena Task Manager di blokir oleh virus ini maka dibutuhkan Program CurrProcess untuk menggantikan Task Manager.---


2. Masuklah ke menu Safe Mode dengan cara, restart windows lalu tekan F8 pada saat masuk menu Boot selanjutnya pilih Windows Advanced Options lalu pilih Safe Mode.

3. Setelah masuk menu Safe Mode, Jalankan Program CurrProcess kemudian cari virus bernama "Amoumain.exe". Lalu klik kiri pilih Kill Selected Processes. Jika Virus sudah terhapus, Tutup Program CurrProcess.

4. Untuk Menghapus File yang virus buat di Registry Copy dan Paste skript Berikut di Notepad:
------------------------------Skript------------------------------
[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, HideFileExt,0x00010001,0
HKLM, SOFTWARE\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\system, DisableTaskMgr
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\explorer, NoRun

---------------------------akhir skript---------------------------

5. Pada Notepad pilih "File" lalu klik "Save as", lalu ubah save as type menjadi "all files", simpan dengan format ".inf", misal Hx.inf, lalu klik kanan, pilih "install".

6. Hapus juga jika anda menemukan virus seperti Amoumain.exe, Luna Maya.exe, Love.exe, dan nt.bat.
____________________________________________________________________



Zeke hack {Trickster}