Jumat, 13 Mei 2011

Malware/Spyware: Xp Home Security & Xp Internet Security 2011

Hari ini dapat kasus, computer customers tidak bisa browsing internet lewat internet explorer atau melalui mozilla. Salah satu computer selalu muncul peringatan dengan nama "Xp Home Security" dan computer kedua dengan nama "Xp Internet Security 11"

Sebenarnya computer sedang terserang malware yang selalu akan memberikan peringatan palsu seperti dibawah:

Attention: DANGER!
ALERT! System scan for spyware, adware, trojans and viruses is complete.
XP Home Security 2011 detected 29 critical system objects.

Security breach!
Beware! Spyware infection was found. Your system security is
at risk. Private information may get stolen, and your PC
activity may get monitored. Click for an anti-spyware scan.

System danger!
Your system is in danger. Privacy threats detected.
Spyware, keyloggers or Trojans may be working in the
background right now. Perform an in-depth scan and removal
now, click here.

Kadang-kadang, XP Home Security 2011 akan "hijack" mozilla browser, akan muncul peringatan palsu seperti:

XP Home Security 2011 ALERT
Internet Explorer alert. Visiting this site may pose a security threat to your system


Setelah sekian lama nanya sama google, ketemu salah satu web site: http://www.myantispyware.com/2011/04/07/how-to-remove-xp-home-security-2011-virus/

Jadi solusinya:
# Untuk computer yang kena Malware: Xp home security

Copy semua text dibawah ke dalam Notepad.

[Version]
Signature="$Chicago$"
Provider=www.myantispyware.com

[DefaultInstall]
DelReg=regsec
AddReg=regsec1

[regsec]
HKCU, Software\Classes\.exe
HKCU, Software\Classes\pezfile
HKCR, .exe\shell\open\command

[regsec1]
HKCR, exefile\shell\open\command,,,"""%1"" %*"
HKCR, .exe,,,"exefile"
HKCR, .exe,"Content Type",,"application/x-msdownload"

Simpan dengan nama fix.inf di Desktop kemudian klik kanan pilih install dan reboot computer.

# Untuk computer yang kena Malware: Xp Internet security 2011
Download Super anti spyware free edition (install and scan computer)