Original Sender : "Newbie Forever" <[EMAIL PROTECTED]>
---------------------------------


> Original Sender : "Syaefullah Siddik[Dike]" <[EMAIL PROTECTED]>
> ---------------------------------

> Coba ikutin artikel di bawah nih... dari MCAfee...
> Windows 9x Internet Backdoor trojan. When running it gives virually
> unlimited access to the system over the Internet to anyone running the
> appropriate client software.
> This trojan installs 3 files on the system. in WINDOWS and WINDOWS\SYSTEM.
> NODLL.EXE - This exe is installed in WINDOWS folder. It is used to load
the
> main trojan server. It is called from an entry in the 'run=' line of
> WIN.INI. This file is identified as BackDoor-G.ldr SERVER.EXE or
KERNEL16.DL
> or WINDOW.EXE - This exe is installed in the WINDOWS folder. This file is
> the main trojan receives and carries out commands from the client software
> via the Internet. This file is identified as BackDoor-G.srv. This program
is
> usually the first file that the user receives and contains copies of the
> other 2 files.
> WATCHING.DLL or LMDRK_33.DLL - This dll is copied to the WINDOWS\SYSTEM
> folder. This file is used by the trojan server program to monitor the
> Internet for connections from the client software. This file is identified
> as BackDoor-G.dll
> Other files associated with this trojan are the client program which is
> identified as BackDoor-G.cli and a configuration program which is
identified
> as BackDoor-G.cfg.
> NOTE: The filenames given above are only a guide, as the configuration
> program can be used to change the names of the files used.
>
> Kalo File-file di atas udah bersih, tapi masih juga...wah... nggak tau
dech :(

AAAAAAkh  akhirnya berhasil juga menghilangkan trojan ini.
Cuma buat sekedar berbagi pengalaman saja nih.

Pertama saya sudah mencari commmand "aneh" di "registry + local ini files"
tapi tidak menemukan kejanggalan.
Semua yang di load adalah program yang biasa saja. (termasuk pada baris
"run=" dalam Win.ini)
Kemudian karena masih penasaran dan malas untuk install ulang....:)
saya cari program yang "aneh" yang di load dengan menggunakan daftar
"program yang di load pada Norton System Information/memory"
Saya cek semua file exe satu per satu yang terdapat pada daftar tersebut
dengan cara melihat "properties" pada setiap file exe tsb.
Melalui "file properties", dapat diperoleh keterangan program apa yang yang
menggunakan file exe tsb.
Kejanggalan terlihat pada satu file yang bernama "wincache.exe". "file
properties" tidak memberitahukan program apa yang menggunakan file tsb.
Saya coba untuk menghapus file "wincache.exe" dan "watching.dll" melalui DOS
mode.
Dan ternyata BERHASIL.

Tetapi yang mengherankan saya, tidak ada perintah untuk loading
"wincache.exe" dalam "registry + local ini files".
Lalu apa/siapa yang memerintahkan  untuk loading file tsb ?
Apakah ada yang bisa menerangkan ??????

       Regards,
       Newbie Forever
       [EMAIL PROTECTED]



----------------------------------------------------------------
Compu-Mania MailingList is provided by PT Centrin Utama
Maintained by   : [EMAIL PROTECTED]
To Post a msg   : Send mail to [EMAIL PROTECTED]
To Unsubscribe  : Mail to [EMAIL PROTECTED]
BODY : unsubscribe Compu-Mania
For more information, send mail to [EMAIL PROTECTED]
with "HELP" in the BODY of your mail (without quote).
----------------------------------------------------------------

Kirim email ke