<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Guardianlaptop's Weblog</title>
	<atom:link href="http://guardianlaptop.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://guardianlaptop.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 08 Feb 2008 02:35:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='guardianlaptop.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Guardianlaptop's Weblog</title>
		<link>http://guardianlaptop.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://guardianlaptop.wordpress.com/osd.xml" title="Guardianlaptop&#039;s Weblog" />
	<atom:link rel='hub' href='http://guardianlaptop.wordpress.com/?pushpress=hub'/>
		<item>
		<title>KeBingUngAN</title>
		<link>http://guardianlaptop.wordpress.com/2008/02/08/kebingungan/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/02/08/kebingungan/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 02:30:19 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[logz]]></category>
		<category><![CDATA[kebingungan menjelang pernikahan]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=20</guid>
		<description><![CDATA[wadoh, lagi bener-bener bingung neh. Uang nya udah hampir terkuras habis buat biaya pernikahan. Namanya juga menikah kali yah, jadi butuh banyak uang, buat biaya ini itu, biaya semua tetek bengek. &#8220;Kadang suka bingung, nanti habis menikah bagaimana yah ? Takut gak bisa kasih makan , Takut gak bisa menjadi pemimpin yang baik, Bagaimana bisnis [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=20&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>wadoh, lagi bener-bener bingung neh. Uang nya udah hampir terkuras habis buat biaya pernikahan. Namanya juga menikah kali yah, jadi butuh banyak uang, buat biaya ini itu, biaya semua tetek bengek.</p>
<p>&#8220;Kadang suka bingung, nanti habis menikah bagaimana yah ?<br />
Takut gak bisa kasih makan ,<br />
Takut gak bisa menjadi pemimpin yang baik,<br />
Bagaimana bisnis aku sehabis menikah,<br />
Padahal uang simpanan dan tabungan aku udah hampir abis, dan aku perkirakan bakalan habis ketika menikah ,<br />
jadi bagaimana dong?<br />
Ditengah kebutuhan yang begitu banyak, aku memberanikan diri mengikuti acara yang terbilang cukup mahal untuk di hadiri selama 2 hari. di jakarta pula.<br />
Tapi aku pikir acara ini insyallah bermanfaat ..<br />
Mudah-mudahan Allah SWT memberikan dan mengkaruniakan ilmu kepada aku lewat acara ini..<br />
dan dapat digunakan untuk melanjutkan kehidupan di dunia ini.<br />
Mudah-mudahan bisa terbayar berlipat-lipat ongkos acara ini, bela-belain bayar sebegini mahal buat acara itu, padahal kebutuhan pernikahan masih banyak ..<br />
Mudah-mudahan Allah SWT meridhoi langkah aku..<br />
Mudah-mudahan dikaruniakan Rezeki yang melimpah dan berkah serta halal an toyyibah..<br />
Mudah-mudahan bisa menjadi keluarga yang sakinah mawadah warahmah ..<br />
Mudah-mudahan bisnis aku jadi lancar, bisnis online nya jg lancar, bisnis properti nya jg bisa maju..Amin ya Allah Amin..</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=20&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/02/08/kebingungan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>40 MISTAKES MEN MAKE WHILE HAVING SEX WITH WOMEN</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/40-mistakes-men-make-while-having-sex-with-women/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/40-mistakes-men-make-while-having-sex-with-women/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 04:24:25 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Family Life]]></category>
		<category><![CDATA[40 MISTAKES MEN MAKE WHILE HAVING SEX WITH WOMEN]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/2008/01/31/40-mistakes-men-make-while-having-sex-with-women/</guid>
		<description><![CDATA[1) NOT KISSING FIRST. Avoiding her lips and diving straight for the erogenous zones makes her feel like you&#8217;re paying by the hour and trying to get your money&#8217;s worth by cutting out nonessentials. A proper passionate kiss is the ultimate form of foreplay. &#160; 2) BLOWING TOO HARD IN HER EAR. Admit it, some [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=19&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>1) NOT KISSING FIRST.<br />
Avoiding her lips and diving straight for the erogenous zones    makes her<br />
feel like you&#8217;re paying by the hour and trying to get your money&#8217;s worth by<br />
cutting out nonessentials. A proper passionate kiss is the ultimate form of<br />
foreplay.</p>
<p align="left">&nbsp;</p>
<p align="left">2) BLOWING TOO HARD IN HER EAR.<br />
Admit it, some kid at school told you girls love this. Well,    there&#8217;s a<br />
difference between being erotic and blowing as if you&#8217;re trying to<br />
extinguish<br />
the candles on your 50th birthday cake. That hurts.</p>
<p align="left">&nbsp;</p>
<p align="left">3) NOT SHAVING.<br />
You often forget you have a porcupine strapped to your chin    which you<br />
rake<br />
repeatedly across your partner&#8217;s face and thighs. When she turns her head<br />
from side to side, it&#8217;s not passion, it&#8217;s avoidance.</p>
<p align="left">&nbsp;</p>
<p align="left">4) SQUEEZING HER BREAST.<br />
Most men act like a housewife testing a melon for ripeness    when they<br />
get<br />
their hand on a pair. Stroke, caress, and smooth them.</p>
<p align="left">&nbsp;</p>
<p align="left">5) BITING HER NIPPLES.<br />
Why do men fasten onto a woman&#8217;s nipples, then clamp down    like they&#8217;re<br />
trying to deflate her body via her breasts? Nipples are highly sensitive.<br />
They can&#8217;t stand up to chewing. Lick and suck them gently. Flicking your<br />
tongue across them is good. Pretending they&#8217;re a doggie toy isn&#8217;t.</p>
<p align="left">&nbsp;</p>
<p align="left">6) TWIDDLING HER NIPPLES.<br />
Stop doing that thing where you twiddle the nipples between    finger and<br />
thumb like you&#8217;re trying to find a radio station in a hilly area. Focus on<br />
the whole breasts, not just the exclamation points.</p>
<p align="left">&nbsp;</p>
<p align="left">7) IGNORING THE OTHER PARTS OF HER BODY.<br />
A woman is not a highway with just three turnoffs: Breastville    East and<br />
West, and the Midtown Tunnel. There are vast areas of her body which you&#8217;ve<br />
ignored far too often as you go bombing straight into downtown Vagina.     So<br />
start paying them some attention.</p>
<p align="left">&nbsp;</p>
<p align="left"> <img src='http://s0.wp.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> GETTING THE HAND TRAPPED.<br />
Poor manual dexterity in the underskirt region can result    in tangled<br />
fingers and underpants.  If you&#8217;re going to be that aggressive, just ask<br />
her<br />
to take the damn things off.</p>
<p align="left">&nbsp;</p>
<p align="left">9) LEAVING HER A LITTLE PRESENT.<br />
Condom  disposal is the man&#8217;s responsibility. You wore it, you store it.</p>
<p align="left">&nbsp;</p>
<p align="left">10) ATTACKING THE CLITORIS.<br />
Direct pressure is very unpleasant, so gently rotate your    fingers along</p>
<p>side of the clitoris.</p>
<p align="left">&nbsp;</p>
<p align="left">11) STOPPING FOR A BREAK.<br />
Women, unlike men, don&#8217;t pick up where they left off. If    you stop, they</p>
<p>plummet back to square one very fast. If you can tell she&#8217;s not there, keep</p>
<p>going at all costs, numb jaw or not.</p>
<p align="left">&nbsp;</p>
<p align="left">12) UNDRESSING HER AWKWARDLY.<br />
Women hate looking stupid, but stupid she will look when    naked at the<br />
waist with a sweater stuck over her head. Unwrap her like an elegant<br />
present,<br />
not a kid&#8217;s toy.</p>
<p align="left">&nbsp;</p>
<p align="left">13) GIVING HER A WEDGIE DURING FOREPLAY.<br />
Stroking her gently through her panties can be very sexy.    Pulling the<br />
material up between her thighs and yanking it back and forth is not.</p>
<p align="left">&nbsp;</p>
<p align="left">14) BEING OBSESSED WITH THE VAGINA.<br />
Although most men can find the clitoris without maps, they    still<br />
believe<br />
that the vagina is where it&#8217;s all at. No sooner is your hand down there<br />
than<br />
you&#8217;re trying to stuff stolen banknotes up a chimney.  This is okay in<br />
principle, but if you&#8217;re not careful, it can hurt &#8211; so don&#8217;t get carried<br />
away. It&#8217;s best to pay more attention to her clitoris and the exterior of<br />
her<br />
vagina at first, then gently slip a finger inside her<br />
and see if she likes it.</p>
<p align="left">&nbsp;</p>
<p align="left">15) MASSAGING TOO ROUGHLY.<br />
You&#8217;re attempting to give her a sensual, relaxing massage    to get her in<br />
the mood. Hands and  fingertips are okay; elbows and knees are not.</p>
<p align="left">&nbsp;</p>
<p align="left">16) UNDRESSING PREMATURELY.<br />
Don&#8217;t force the issue by stripping before she&#8217;s at least    made some move<br />
toward getting your stuff off, even if it&#8217;s just undoing a couple of<br />
buttons.</p>
<p align="left">&nbsp;</p>
<p align="left">17) TAKING YOUR PANTS OFF FIRST.<br />
A man in socks and underpants is at his worst.  Lose    the socks first.</p>
<p align="left">&nbsp;</p>
<p align="left">18) GOING TOO FAST.<br />
When you get to the  penis-in-vagina situation, the worst thing you can<br />
do<br />
is pump away like an  industrial power tool &#8211; she&#8217;ll soon feel like an<br />
assembly line worker made  obsolete by your technology.  Build up slowly,<br />
with<br />
clean, straight,  regular thrusts.</p>
<p align="left">&nbsp;</p>
<p align="left">19) GOING TOO HARD.<br />
If you bash your great triangular hip bones into her thigh    or stomach,<br />
the pain is equal to two weeks of horseback riding concentrated into a few<br />
seconds.</p>
<p align="left">&nbsp;</p>
<p align="left">20) COMING TOO SOON.<br />
Every man&#8217;s fear. With reason. If you shoot before you see    the whites<br />
of<br />
her eyes, make sure you have a backup plan to ensure her pleasure too.</p>
<p align="left">&nbsp;</p>
<p align="left">21) NOT COMING SOON ENOUGH.<br />
It may appear to you that humping for an hour without climaxing    is the<br />
mark of a sex god, but to her it&#8217;s more likely the mark of a numb vagina.<br />
At<br />
least buy some intriguing wall hangings, so she has something to hold her<br />
interest while you&#8217;re playing Marathon Man.</p>
<p align="left">&nbsp;</p>
<p align="left">22) ASKING IF SHE HAS COME.<br />
You really ought to be able to tell. Most women make noise.    But if you<br />
really don&#8217;t know, don&#8217;t ask</p>
<p align="left">&nbsp;</p>
<p align="left">23) PERFORMING ORAL SEX TOO GENTLY.<br />
Don&#8217;t act like a giant cat at a saucer of milk. Get your    whole mouth<br />
down<br />
there, and concentrate on gently rotating or flicking your tongue on her<br />
clitoris.</p>
<p align="left">&nbsp;</p>
<p align="left">24) NUDGING HER HEAD DOWN.<br />
Men persist in  doing this until she&#8217;s eyeball-to-penis, hoping that it<br />
will lead very  swiftly to mouth-to-penis. All women hate this. It&#8217;s about<br />
three steps from  being dragged to a cave by their hair. If you want her to<br />
use her mouth, use  yours; try talking seductively to her.</p>
<p align="left">&nbsp;</p>
<p align="left">25) NOT WARNING HER BEFORE YOU CLIMAX.<br />
Sperm tastes like sea water mixed with egg white.  Not    everybody likes<br />
it.<br />
When she&#8217;s performing oral sex, warn her before you come so she can do<br />
what&#8217;s<br />
necessary.</p>
<p align="left">&nbsp;</p>
<p align="left">26) MOVING AROUND DURING FELLATIO.<br />
Don&#8217;t thrust. She&#8217;ll do all the moving during fellatio. You    just lie<br />
there. And don&#8217;t grab her head.</p>
<p align="left">&nbsp;</p>
<p align="left">27) TAKING ETIQUETTE ADVICE FROM PORN MOVIES.<br />
In X-rated movies, women seem to love it when    men ejaculate over<br />
them.<br />
In real life, it just means more laundry to do.</p>
<p align="left">&nbsp;</p>
<p align="left">28) MAKING HER RIDE ON TOP FOR AGES.<br />
Asking her to be on top is fine. Lying there grunting while    she does<br />
all<br />
the hard work is not. Caress her gently, so that she doesn&#8217;t feel quite so<br />
much like the captain of a schooner. And let her have a rest.</p>
<p align="left">&nbsp;</p>
<p align="left">29) ATTEMPTING ANAL SEX AND PRETENDING IT WAS AN ACCIDENT.<br />
This is how men earn a reputation for not being able to follow<br />
directions.<br />
If you want to put it there, ask her first. And don&#8217;t think that being<br />
drunk<br />
is an excuse.</p>
<p align="left">&nbsp;</p>
<p align="left">30) TAKING PICTURES.<br />
When a man says, &#8220;Can I take a photo of you?&#8221; she&#8217;ll hear    the<br />
words&#8221;__to<br />
show my buddies.&#8221; At least let her have custody of them.</p>
<p align="left">&nbsp;</p>
<p align="left">31) NOT BEING IMAGINATIVE ENOUGH.<br />
Imagination is anything from drawing patterns on her back    to pouring<br />
honey<br />
on her and licking it off. Fruit, vegetables, ice and feathers are all<br />
handy<br />
props; hot candle wax and permanent dye are a no no.</p>
<p align="left">&nbsp;</p>
<p align="left">32) SLAPPING YOUR STOMACH AGAINST HERS.<br />
There is no less erotic noise. It&#8217;s as sexy as a belching    contest.</p>
<p align="left">&nbsp;</p>
<p align="left">33) ARRANGING HER IN STUPID POSES.<br />
If she wants to do advanced yoga in bed, fine, but unless    she&#8217;s a<br />
Romanian<br />
gymnast, don&#8217;t get too ambitious. Ask yourself if you want a sexual partner<br />
with snapped hamstrings.</p>
<p align="left">&nbsp;</p>
<p align="left">34) LOOKING FOR HER PROSTATE.<br />
Read this carefully: Anal stimulation feels good for men    because they<br />
have<br />
a prostate. Women don&#8217;t.</p>
<p align="left">&nbsp;</p>
<p align="left">35) GIVING LOVE BITES.<br />
It is highly erotic to exert some gentle suction on the sides    of the<br />
neck,<br />
if you do it carefully. No woman wants to have to wear turtlenecks and<br />
jaunty<br />
scarves for weeks on end.</p>
<p align="left">&nbsp;</p>
<p align="left">36) BARKING INSTRUCTIONS.<br />
Don&#8217;t shout encouragement like a coach with a megaphone.    It&#8217;s not a big<br />
turn-on.</p>
<p align="left">&nbsp;</p>
<p align="left">37) TALKING DIRTY.<br />
It makes you sound like a lonely magazine editor calling    a 1-900line.<br />
If<br />
she likes nasty talk, she&#8217;ll let you know</p>
<p align="left">&nbsp;</p>
<p align="left">38) NOT CARING WHETHER SHE COMES.<br />
You have to finish the job. Keep on trying until you get    it right, and<br />
she<br />
might even do the same for you.</p>
<p align="left">&nbsp;</p>
<p align="left">39) SQUASHING HER.<br />
Men generally weigh more than women, so if you lie on her    a bit too<br />
heavily, she will turn blue.</p>
<p align="left">&nbsp;</p>
<p>40) THANKING HER.<br />
Never thank a woman for having sex with you. Your bedroom is not a<br />
soup  kitchen.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/19/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/19/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=19&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/40-mistakes-men-make-while-having-sex-with-women/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Blokir Fungsi-fungsi Windows</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/blokir-fungsi-fungsi-windows/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/blokir-fungsi-fungsi-windows/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:53 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Malcodes]]></category>
		<category><![CDATA[Viri]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=6</guid>
		<description><![CDATA[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\Explorer § NoFolderOptions = 1 - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansav.exe § Debugger = “” - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansavgd.exe § Debugger = “” - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avguard.exe § Debugger = “” - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe § Debugger = “” - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avscan.exe § Debugger = [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=6&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span><span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;"></span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"><br />
</span><span style="font-size:10pt;font-family:'Arial','sans-serif';">Policies\Explorer</span></p>
<p class="MsoNormal" style="margin-left:1.25in;text-align:justify;text-indent:0;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFolderOptions = 1</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansav.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansavgd.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avguard.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avscan.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ClamWinPortable.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\command.com</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-SE.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\\debugger</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ViRemoval.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winamp.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winrar.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winzip.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antv-md5-pattern.exe</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger<span>         </span>= “” </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">CheckedValue = 2 </span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DefaultValue = 2 </span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">CheckedValue = 1 </span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DefaultValue = 1</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoClose</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFInd</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFolderOptions</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoRun</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoTrayContextMenu</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoViewContextMenu </span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoWinLeys </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableRegistryTools</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Syste</span><span style="font-size:10pt;font-family:'Arial','sans-serif';">m</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"></span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableCMD </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableMSI </span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoClose</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFolderOptions </span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoViewContextMenu</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoWinKeys</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regfile\shell\open\command</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = cmd.exe /c del &#8220;%1&#8243;</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"> <span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span> </span>NeverShowExt [menyembunyikan ext. exe]</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CLASSES_ROOT\exefile</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NeverShowExt [menyembunyikan ext. exe]</span></p>
<p class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Untuk menyamarkan tipe file ia membuat string registry :</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCR\exefile</span></p>
<p class="MsoNormal" style="margin-left:0.5in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">(default) ===&gt; icon</span></p>
<p class="MsoNormal" style="margin-left:0.5in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Nevershowext ===&gt; </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\SOFTWARE\Classes\exefile</span></p>
<p class="MsoNormal" style="margin-left:0.5in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">(default) ===&gt; icon</span></p>
<p>  <span style="font-size:10pt;font-family:'Arial','sans-serif';">Nevershowext ===&gt;</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Seperti kita ketahui virus ini tidak memblok fungsi windows seperti folder options, tetapi akan mencoba melakukan perubahan terhadap setting folder options. Untuk itu ia akan membuat string registry </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">(lihat gambar 4) </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">:</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\</span></p>
<p class="MsoNormal" style="margin-left:0.25in;text-align:justify;text-indent:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">ShowSuperHidden ===&gt; 0</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden</span></p>
<p class="MsoNormal" style="margin-left:0.25in;text-align:justify;text-indent:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">CheckedValue ===&gt; 1</span></p>
<p class="MsoNormal" style="margin-left:0.25in;text-align:justify;text-indent:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">DefaultValue ===&gt; 1</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"></span></p>
<p class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Sebagai penunjang, ia akan membuat string registry pada :</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\SOFTWARE\Microsoft\Windows|CurrentVersion\Run</span></p>
<p class="MsoNormal" style="margin-left:0.5in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">def ===&gt; C:\WINDOWS\Temp\Vel.exe</span></p>
<p class="MsoNormal" style="margin-left:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>      </span>SysRestore ===&gt; c:\windows\system32\restoration.msd</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCU\Control Panel\Desktop</span></p>
<p>  <span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>      </span>SCRNSAVE.exe<span>            </span>===&gt; C:\WINDOWS\Temp\%fileduplikat%.exe</span></p>
<p class="MsoNormal"><b><u><span style="font-size:10pt;font-family:'Arial','sans-serif';">Aktif pada </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">Safe Mode &amp; Safe Mode with Command Prompt</span></u></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Selain aktif pada mode “normal”, virus ini pun aktif pada mode “safe mode” dan “safe mode with command prompt”. Untuk itu ia membuat string registry pada :</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\SYSTEM\ControlSet001\Control\SafeBoot</span></p>
<p class="MsoNormal" style="margin-left:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>      </span>AlternateShell<span>    </span>===&gt; c:\windows\system32\CommandPrompt.Sysm</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\SYSTEM\ControlSet002\Control\SafeBoot</span></p>
<p class="MsoNormal" style="margin-left:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>      </span>AlternateShell<span>    </span>===&gt; c:\windows\system32\CommandPrompt.Sysm</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot</span></p>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>      </span>AlternateShell<span>    </span>===&gt; c:\windows\system32\CommandPrompt.Sysm</span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-size:10pt;font-family:'Arial','sans-serif';">Mengganti Task Manager, Regedit dan Solitaire dengan game FreeCel</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Untuk menjaga eksistensinya, VBWorm.NUJ akan mencoba untuk blok beberapa fungsi Windows seperti Folder Option/regedit/maupun </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">T</span><span style="font-size:10pt;font-family:'Arial','sans-serif';">ask </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">M</span><span style="font-size:10pt;font-family:'Arial','sans-serif';">anager dengan </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">menggantinya dengan program game </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">seperti yang pernah dilakukan oleh varian FaceCool, untuk melakukan hal tersebut VBWorm.NUJ akan mencoba untuk membuat string pada registry berikut</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows      NT\CurrentVersion\Image File Execution Options\regedit.exe</span></li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">debugger = C:\WINDOWS\system32\freecell.exe</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows      NT\CurrentVersion\Image File Execution Options\rstrui.exe</span></li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">debugger = C:\WINDOWS\system32\sol.exe</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"></span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows      NT\CurrentVersion\Image File Execution Options\taskmgr.exe</span></li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">debuger = C:\WINDOWS\system32\spider.exe</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableMSI =1</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">LimitSystemRestoreCheckpointing = 1</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows      NT\SystemRestore</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableConfig</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableSR</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows      NT\CurrentVersion\SystemRestore</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableCOnfig = 1</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableSR = 1</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFolderOptions</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NORun</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableRegistryTools</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableTaskMgr</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoFolderOption</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NoRun</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisableRegistryTools</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisabletaskMgr</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Hidden = 0</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HideFileExt = 1</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ShowSuperHidden = 0</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">text = @shell32.dll,-30501</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">text = @shell32.dll,-30500</span> <b><span style="font-size:10pt;font-family:'Arial','sans-serif';">esan dari pembuat virus <span> </span></span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Salah satu aksi yang aka dilakukan oleh VBWorm.NUJ adalah akan menampilkan sebuah kendela Internet Explorer setiap kali komputer dinyalakan dengan menjalankan file C:\Message From Indonesia.htm yang diiringingi dengan lagu kebangsaan Indonesia Raya.</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Berikut petikan pesan yang akan ditampilkan dari Internet Explorer</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Untuk melakukan hal ini, VBWorm.NUJ akan mencoba untuk membuat string pada registry berikut:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Start Page = C:\Message From Indonesia.htm</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">VBWorm.NUJ juga akan mencoba untuk merubah nama perusahaan dan nama pemilik Windows dengan membuat string pada registry berikut: </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ProcessorNameString = Core 2 Duo Extreme</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">RegisteredOrganization = Paraysutki #VM Community</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">RegisteredOwner = W32.Moontox.Bro [B-2]</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ProductId = Hacker@Cracker@Indonesia</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;">&nbsp;</p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"> <b><span style="font-size:10pt;font-family:'Arial','sans-serif';">File Exe berubah menjadi File Folder</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Untuk melakukan hal tersebut, VBWorm.NUJ akan membuat string pada registry berikut:</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>            </span>- Default = file folder</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>            </span>- InfoTip = file folder</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>            </span>- NeverShowExt</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>            </span>- TileInfo = file folder</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DefaultIcon</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = %SystemRoot%\System32\shell32.dll,4</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">AlwaysShowExt = FIle Folder</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">InfoTip = File Folder</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">NeverShowExt = File Folder</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">VBWorm.NUJ juga akan membut string pada registry berikut:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Description = !!! Sory ya Ngk boleh buka Aplication Microsoft (.msi) Kecuali buka Executable (.exe) !!!</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">imagePath = Go To Vagina</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ObjectPath = Dasar Buaya Darat</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisplayName = WIndows Installer</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">type = 4</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">description = !!! Maaf yee Fitur Security Center gue Non aktifkan dulu&#8230;biar aman !!!</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">imagepath= Go To Mak Erot</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">objectpath = LocalMoontox</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisplayName =Security Center</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">type = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.5in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">description = !!! Hi..hi..hi biar ngak ketauan gue non aktif aja fitur ini (:-p) wee !!!</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">imagepath = Mulutmu Harimaumu</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">objectpath = Mulutmu Harimaumu</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DisplayName = Alerter</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">DependOnService = LanmanWorkstation</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">type = 4</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Type = 4</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ansavgd</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Description = !!! ANSAV kga Mempan sama Moontox Bro (&gt;_&lt;)</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Imagepath = Go To Mak Erot</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ObjectName = !!! Kasian Dech lo, Cape dech !!!</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">type = 4</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice</span></li>
</ul>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Description = !!! Tak akan kubiarkan kau mengembalikan keadaan !!!</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Display name = System Restore Service</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">imagepath = %SystemRoot%\System32\svchost.exe -k netsvcs (ok)</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">start = 4</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">stop = 4</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\Parameters</span></li>
</ul>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.5in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">ServiceDll = C:\WINDOWS\service.exe</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole</span></li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">EnableRemoteConnect = N</span></p>
<p class="MsoNormal" style="text-align:justify;"><b><span style="font-size:10pt;font-family:'Arial','sans-serif';">Logoff jika akses Regedit / VBS file</span></b></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Dalam rangka melindungi dirinya dari pembasmian, v</span><span style="font-size:10pt;font-family:'Arial','sans-serif';">irus ini </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">menambahkan</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"> blok akses file INF/VBS dan Registry file sehingga jika user menjalankan file yang mempunyai ekstensi tersebut maka komputer akan langsung logoff. Untuk melakukan hal tersebut ia akan membuat string pada registry berikut:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Shell\Edit\Command</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\Shell\Install\Command</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regfile\Shell\open\Command</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCR\inffile\shell\Install\command</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCR\regfile\shell\open\command</span></p>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCR\VBSFile\Shell\Edit\Command</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Default = logoff.exe</span></p>
<p><span style="font-size:10pt;font-family:Wingdings;"><span>Ø<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\winlogon</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">Userinit<span>       </span> = C:\windows\system32\userinit.exe, c:\documents and settings\localservice\local settings\spoolsv.exe</span></i></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">Shell<span>           </span> =<span>  </span>explorer.exe C:\documents and settings\localservice\local settings\svchost.exe</span></i></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">System<span>       </span> = C:\Documents and Settings\LocalService\Local Settings\mencerdaskan_Bangsa.exe</span></i></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.75in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>Ø<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">Load = c:\documents and settings\%user%\local settings\application data\csrss.exe</span></i></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>Ø<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AEDebug</span></p>
<p class="MsoNormal" style="margin-left:0.75in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">Debugger = C:\Documents and Settings\LocalService\Local Settings\Application Data\lsass.exe</span></i></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>Ø<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Command Processor</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:Symbol;"><span>·<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">         </span></span></span><!--[endif]--><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">Autorun</span></i></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;">&nbsp;</p>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';"></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=6&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/blokir-fungsi-fungsi-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Bersihkan Registry Virus Windows</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/bersihkan-registry-virus-windows/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/bersihkan-registry-virus-windows/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:30 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Malcodes]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Viri]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=7</guid>
		<description><![CDATA[Buat File inf [Version] Signature=&#8221;$Chicago$&#8221; Provider=Vaksincom Oye [DefaultInstall] AddReg=UnhookRegKey DelReg=del [UnhookRegKey] HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221; HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM&#60; SOFTWARE\Classes\lnkfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221; HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221; HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221; HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221; HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221; HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,UncheckedValue,0&#215;00010001,1 HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN, CheckedValue,0&#215;00010001,2 HKLM, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=7&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Buat File inf</p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[Version]</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Signature=&#8221;$Chicago$&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Provider=Vaksincom</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"> Oye</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span> </span></span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[DefaultInstall]</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">AddReg=UnhookRegKey</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">DelReg=del</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[UnhookRegKey]</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\batfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\comfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\exefile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\piffile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\regfile\shell\open\command,,,&#8221;regedit.exe &#8220;%1&#8243;&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\CLASSES\scrfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM&lt; SOFTWARE\Classes\lnkfile\shell\open\command,,,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, &#8220;Explorer.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, &#8220;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden,UncheckedValue,0&#215;00010001,1</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN, CheckedValue,0&#215;00010001,2</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN, DefaultValue,0&#215;00010001,2</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue,0&#215;00010001,1</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue,0&#215;00010001,1</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[del]</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistriTools</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistriTools</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegistriEditor.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, winsystem</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Microfost</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysedit</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansav.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ansavgd.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avguard.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Avscan.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ClamWinPortable.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\command.com</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-SE.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe, debugger</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ViRemoval.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winamp.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winrar.exe</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winzip.exe</span></p>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antv-md5-pattern.exe</span></p>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';">im oWSH: Set oWSH = CreateObject(&#8220;WScript.Shell&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">on error resume Next</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command\&#8221;,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command\&#8221;,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command\&#8221;,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command\&#8221;,&#8221;"&#8221;%1&#8243;&#8221; %*&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\scrfile\shell\open\command\&#8221;,&#8221;"&#8221;%1&#8243;&#8221; /S&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\Software\CLASSES\regfile\shell\open\command\&#8221;,&#8221;regedit.exe %1&#8243;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell&#8221;,&#8221;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell&#8221;,&#8221;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite &#8220;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\AlternateShell&#8221;,&#8221;cmd.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.Regwrite</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"> 		<span style="font-size:10pt;font-family:'Arial','sans-serif';">&#8220;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell&#8221;,&#8221;cmd.exe&#8221;oWSH.Regwrite</span><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span><span style="font-size:10pt;font-family:'Arial','sans-serif';">&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell&#8221;,&#8221;Explorer.exe&#8221;</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Word&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Printer Cpl&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\DisableMSI&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\LimitSystemRestoreCheckpointing&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWinLeys&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCLose&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Nofind&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisableMSI&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWinLeys&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NOLogoff&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWinKeys&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWinKeys&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogoff&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispApprearancePage&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCpl&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispSettingsPage&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"> 		<span style="font-size:10pt;font-family:'Arial','sans-serif';">System\NoScrSavPage&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CLASSES_ROOT\exefile\NeverShowExt&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions&#8221;)</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">oWSH.RegDelete(&#8220;HKEY_CURRENT_USER\Software\policies\Microsoft\system\DisableCMD&#8221;)</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=7&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/bersihkan-registry-virus-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Mencegah Virus Autoinfect via Flash Disk</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/mencegah-virus-autoinfect-via-flash-disk/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/mencegah-virus-autoinfect-via-flash-disk/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:27 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Malcodes]]></category>
		<category><![CDATA[Viri]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=10</guid>
		<description><![CDATA[Seperti cara yang anda baca di artikel “Mencegah Virus Autoinfect via Flash Disk” kita mendisable Autorun/Autoplay melalui Group Policy [GPEDIT.MCS] : Klik menu [START], Klik [Run] Ketik GPEDIT.MSC pada kolom “RUN” Pilih Administrative Templates pada menu Computer Configuration. Klik pada View kemudian pilih Filtering Klik un-select pada check-box untuk mematikan pilihan &#8220;Only show policy settings [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=10&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Seperti cara yang anda baca di artikel “<b>M</b></span><b><span style="font-size:10pt;font-family:'Arial','sans-serif';">encegah Virus Autoinfect via Flash Disk”</span></b><span style="font-size:10pt;font-family:'Arial','sans-serif';"> kita men<i>d</i></span><i><span style="font-size:10pt;font-family:'Arial','sans-serif';">isable</span></i><span style="font-size:10pt;font-family:'Arial','sans-serif';"> Autorun/Autoplay melalui <b>Group Policy</b> [GPEDIT.MCS] : </span></p>
<ol>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik      menu [START], </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik      [Run]</span><span style="font-size:10pt;"></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Ketik      <i>GPEDIT.MSC</i> pada kolom “RUN”</span><span style="font-size:10pt;"></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Pilih      <i>Administrative Templates</i> pada      menu <i>Computer Configuration. </i><span> </span></span><span style="font-size:10pt;"></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik      pada <i>View</i> kemudian pilih <i>Filtering</i></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik un-select pada check-box      untuk mematikan pilihan <i>&#8220;Only      show policy settings that can be fully managed&#8221;</i> dan kemudian klik      OK </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik kanan pada menu <i>Administrative Template</i>, pilih <i>Add/Remove Template</i></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Pastikan bahwa file <i>write_protect_removable_drives.adm</i>      ada di direktori C:\Window\INF. Kalau belum ada bisa di download di <a href="http://www.petri.co.il/software/usb_write_protect_adm.zip">http://www.petri.co.il/software/usb_write_protect_adm.zip</a></span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Setelah selesai di download, <i>un-pack</i> file tersebut kemudian      jalankan file <i>batch</i>-nya. Sehingga      file write_protect_removable_drives.adm tercopy di direktori      C:\Windows\INF</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Kemudian Anda klik tombol ADD,      pilih file <i>write_protect_removable_drives.adm</i>.      Klik tombol OPEN </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Kalau berhasil pada Add/Remove      Templates akan nampak file <i>write_protect_removable_drives.adm      </i>tersebut. Klik tombol CLOSE untuk mengakhiri sesi tersebut.</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Setelah ditutup, maka akan      terlihat sebuah menu baru dengan nama “<b><i>Custom Policy Settings”</i></b>      dengan sub menu <b><i>“Write Protection”</i> </b><span> </span>dengan status “d<i>isable</i>” </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Klik 2 (dua) kali pada <b><i>Write      Protect USB Removable Drives</i></b>. Akan nampak <b><i>Write Protect USB Removable      Drives Properties</i></b>. Pada tab Setting pilih <b>ENABLED</b> dan statusnya Anda rubah menjadi <b>ON.</b> Klik Apply, dan untuk mengakhiri klik OK </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Kalau berhasil, maka Statenya berubah menjadi <b>Enable </b>(lihat gambar 9).Untuk mengakhiri klik File, kemudian Exit.</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Untuk merubah menjadi DISABLE,      Anda ikuti langkah no. 12 dan 13 pada tab Setting pilih <b>DISABLE </b>dan statusnya Anda rubah      menjadi <b>OFF</b>.</span></li>
</ol>
<p class="MsoNormal" style="margin-left:0.25in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">Ada cara lain untuk memproteksi penulisan pada Flash disk dengan menggunakan REGEDIT sebagai berikut :</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoListParagraph" style="text-align:justify;text-indent:-0.5in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span><span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">      </span>i.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Jalankan Regedit.exe, kemudian masuk ke : </span></p>
<p class="MsoNormal" style="margin-left:0.25in;text-align:justify;text-indent:0.25in;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Control\StorageDevicePolicies </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';">buat sebuah value (DWORD) </span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;"><span style="font-size:10pt;font-family:'Arial','sans-serif';"> </span></p>
<p>  <i><span style="font-size:10pt;font-family:'Arial','sans-serif';">WriteProtect</span></i><span style="font-size:10pt;font-family:'Arial','sans-serif';"> dan beri nilai 1</span></p>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span><span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span>ii.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">        </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Kemudian tutup Registry Editor, Anda tidak perlu merestart computer untuk menjalankan fungsi tersebut. Untuk men-disable-kan fungsi di atas, ganti Value data-nya menjadi 0. File-file registri untuk masalah tersebut bisa Anda download di <a href="http://www.petri.co.il/software/usb_write_protect.zip">http://www.petri.co.il/software/usb_write_protect.zip</a>. Pilih salah satu file REG-nya Disable atau Enable.</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=10&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/mencegah-virus-autoinfect-via-flash-disk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Registry Buat Virus</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/registry-buat-virus/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/registry-buat-virus/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:21 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=5</guid>
		<description><![CDATA[Start Up HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run - microfost = C:\windows\system32\hanny.exe - sysedit = C:\windows\iexplorer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - winsystem = c:\windows\system32\aniee.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - Printer Cpl = C:\WINDOWS\SPOOL32.EXE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run - Microsoft Word = C:\WINDOWS\system32\WINWORD.EXE o HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\4LLI o HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\ CurrentControlSet\Services\4LLI o HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\ CurrentControlSet\Services\4LLI o HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\ CurrentControlSet\Services\4LLI o HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run § windowsapp = C:\WINDOWS\windowsapp.exe<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=5&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Start Up</p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</span></li>
</ul>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">microfost = C:\windows\system32\hanny.exe</span></p>
<p class="MsoNormal" style="margin-left:1in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">sysedit = C:\windows\iexplorer.exe</span></p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</span></li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">winsystem = c:\windows\system32\aniee.exe</span></p>
<ul>
<li>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</span></li>
</ul>
</li>
</ul>
<p class="MsoNormal" style="margin-left:1.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span> </span>Printer Cpl = C:\WINDOWS\SPOOL32.EXE</span></p>
<ul>
<li>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</span></li>
</ul>
</li>
</ul>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Arial','sans-serif';"><span>-<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">       </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">Microsoft Word = C:\WINDOWS\system32\WINWORD.EXE</span></p>
<p><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\4LLI</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\ CurrentControlSet\Services\4LLI</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\ CurrentControlSet\Services\4LLI</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\ CurrentControlSet\Services\4LLI</span></p>
<p class="MsoNormal" style="margin-left:0.5in;text-align:justify;text-indent:-0.25in;"><!--[if !supportLists]--><span style="font-size:10pt;font-family:'Courier New';"><span>o<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">    </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</span></p>
<p><!--[if !supportLists]--><span style="font-size:10pt;font-family:Wingdings;"><span>§<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;">  </span></span></span><!--[endif]--><span style="font-size:10pt;font-family:'Arial','sans-serif';">windowsapp = C:\WINDOWS\windowsapp.exe</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=5&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/registry-buat-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Tools-Tools Buat Babat Virus</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/tools-tools-buat-babat-virus/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/tools-tools-buat-babat-virus/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:18 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=8</guid>
		<description><![CDATA[Berikut ini tools-tools buat babat virus Security Task Manager CurrProcess http://www.nirsoft.net/utils/cprocess.html<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=8&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Berikut ini tools-tools buat babat virus</p>
<p>Security Task Manager<br />
CurrProcess   http://www.nirsoft.net/utils/cprocess.html</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/8/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/8/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=8&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/tools-tools-buat-babat-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>Tempat Nyimpen File Induk Virus</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/tempat-nyimpen-file-induk-virus/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/tempat-nyimpen-file-induk-virus/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 01:31:09 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Malcodes]]></category>
		<category><![CDATA[Viri]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/?p=4</guid>
		<description><![CDATA[Tempat-tempat yang biasa digunakan buat nyimpen file induk virus C:\Windows\system32\hanny.exe C:\windows\system23\aniee.exe C:\autoexec.bat S:\tunggul.vbs C:\aniee.txt C:\windows\iexplorer.exe (Gultung.A) C:\Documents and Settings\%user login% [System Process]BabII.doc .exe [System Process]Fileku.doc .exe [System Process]Jangan di buka .doc.exe [System Process]Tolong.doc .exe [System Process]Data.doc .exe [System Process]Desposisi.doc .exe [System Process]Empat Mata.doc .exe [System Process]Benci.doc .exe C:\Documents and Settings\%user%\Local Settings\Temp\Ngsys<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=4&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Tempat-tempat yang biasa digunakan buat nyimpen file induk virus</p>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\Windows\system32\hanny.exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\windows\system23\aniee.exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\autoexec.bat </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">S:\tunggul.vbs</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\aniee.txt</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\windows\iexplorer.exe      (Gultung.A)</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\Documents and Settings\%user      login%</span>
<ul>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]BabII.doc .exe       </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Fileku.doc       .exe </span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Jangan di buka       .doc.exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Tolong.doc       .exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Data.doc .exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Desposisi.doc       .exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Empat Mata.doc       .exe</span></li>
<li class="MsoNormal"><span style="font-size:10pt;font-family:'Arial','sans-serif';">[System Process]Benci.doc .exe</span></li>
</ul>
</li>
</ul>
<p><span style="font-size:10pt;font-family:'Arial','sans-serif';">C:\Documents and Settings\%user%\Local      Settings\Temp\Ngsys</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=4&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/tempat-nyimpen-file-induk-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>How To Reinstall Windows Without Losing Anything</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/how-to-reinstall-windows-without-losing-anything/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/how-to-reinstall-windows-without-losing-anything/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 00:58:34 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[How To Reinstall Windows Without Losing Anything]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/2008/01/31/how-to-reinstall-windows-without-losing-anything/</guid>
		<description><![CDATA[Over time, Windows loses stability. If you keep a computer for more than two years, at some point you&#8217;re going to have to bite the bullet and reinstall Windows from scratch. But contrary to popular belief, you won&#8217;t have to reformat your hard drive (with one exception, discussed below). The bad stuff you need to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=18&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Over time, Windows loses stability. If you keep a computer for more than two years, at some point you&#8217;re going to have to bite the bullet and reinstall Windows from scratch. But contrary to popular belief, you won&#8217;t have to reformat your hard drive (with one exception, discussed below). The bad stuff you need to get rid of is all in your Windows folder.</p>
<p>Before you begin, gather your Windows and application CD-ROMs. Back up your data files (just to be safe), and then clear two days off your calendar. If everything goes smoothly, you can reinstall Windows in a few hours. But you have to assume something will go wrong: You may not be able to find a necessary CD, or data won&#8217;t be where you thought it was, or something will simply refuse to work.</p>
<p>There&#8217;s a difference between a repair reinstall and a complete reinstall. Though a repair (also called a refresh) will let you keep your current settings, a complete reinstall will give you a truly fresh version of Windows. Repairs are fast and easy, but they don&#8217;t fix anywhere near as many problems. The instructions below are for total reinstalls, except where noted.<br />
Your Vendor&#8217;s Restore CD</p>
<p>Most computers ship with a vendor-specific restore CD rather than with a Microsoft Windows CD-ROM. (If your PC came with a Microsoft Windows CD, or if you bought a retail copy of Windows, skip to the section for your version.)</p>
<p>Some restore CDs give you all the options of a full Microsoft Windows CD, but with better instructions and the convenience of having all the right hardware drivers. Others can do nothing except reformat your hard drive and restore it to the condition it was in when you bought the PC. (This case is the exception I mentioned above that requires a reformat.)</p>
<p>If your restore CD is reformat-only, back up your data files to a network or a removable medium before reinstalling Windows. If you use Windows 98 or Me, back up C:\My Documents, plus the folders inside C:\Windows discussed in the 98*steroidsRgangstaa section below. If you have Windows 2000 or XP, back up C:\Documents and Settings. Also back up any other folders in which you store your data files.<br />
Windows 98 and ME CDs</p>
<p>These Windows versions keep some important data inside your soon-to-be-erased Windows folder, so you need to copy several of its subfolders to another location. Right-click My Computer and select Explore. Double-click the C: drive icon (in Me, you may then have to click View the entire contents of this drive). Right-click in the right pane and select New, Folder. Name the new folder oldstuff.</p>
<p>Go to the Windows folder (you might have to click View the entire contents of this folder), hold down Ctrl, and select the following subfolders: All Users, Application Data, Desktop, Favorites, Local Settings, Profiles, SendTo, and Start Menu. If you don&#8217;t see them all, select View, Folder Options (Tools, Folder Options in Me), click the View tab, select Show all files, and click OK. (If you still don&#8217;t see them all, don&#8217;t worry about it.) Press Ctrl and drag the folders to C:\oldstuff (see FIGURE 1).</p>
<p>Restart Windows with a start-up disk in your floppy drive. (To make a start-up floppy, insert a disk, select Start, Settings, Control Panel, double-click Add/Remove Programs, click Startup Disk, Create Disk, and follow the prompts.) At the Startup Menu, select Start computer with CD-ROM support. While the drivers load, insert your Windows CD-ROM.</p>
<p>Unless you&#8217;re doing a repair reinstall, type the command c:\windows\command\deltree /y c:\windows and press Enter. Deleting your old files could take time, but the /y switch suppresses confirmation prompts, so take a break.</p>
<p>When you&#8217;re back at the A: prompt, type x:setup, where x is your CD drive letter (it&#8217;s likely one letter past what it usually is in Windows, so if it&#8217;s D: in Windows, it&#8217;s probably E: here). Press Enter and follow the prompts.</p>
<p>Once you&#8217;re back in Windows, reinstall your graphics card driver. If you have Windows set up for more than one user, you&#8217;ll also have to re-create each account. Select Start, Settings, Control Panel, Users to do so. It&#8217;s important that the user names match those in the old installation. If you&#8217;re not sure, open Windows Explorer and navigate to C:\oldstuff\profiles. There you&#8217;ll find a folder for each registered user name (see FIGURE 2). Don&#8217;t worry about passwords. Log off and log back on as each user. When you&#8217;re done, log off and back on one more time, but instead of choosing a user name and a password, press Esc to enter Windows without being a specific user.</p>
<p>Select Start, Programs, MS-DOS Prompt (in Windows 98) or Start, Programs, Accessories, MS-DOS Prompt (in Windows Me). Type xcopy c:\oldstuff\*.* c:\windows /s /h /r /c and press Enter (if you want to know what the xcopy switches do, enter the command xcopy /?). When xcopy asks if it should overwrite a file, press a for All.</p>
<p>When xcopy is through, reboot and log on (as a particular user, if necessary). Open My Documents to make sure all your personal files are where they belong, including your Internet Explorer favorites and your custom Start menu shortcuts.</p>
<p>Now skip ahead to &#8220;Finishing the Job.&#8221;<br />
Windows 2000 and XP CDs</p>
<p>Boot your computer with your Windows CD-ROM inserted. When you get the &#8216;Press any key to boot from CD&#8217; message, do so. (If you don&#8217;t see that message before Windows starts, restart Windows, press the key you&#8217;re prompted to enter for your PC Setup program, and change the boot order so your CD drive is first.)</p>
<p>At the &#8216;Welcome to Setup&#8217; screen, press Enter. The R (repair) option takes you to the Recovery Module, which is useful if Windows won&#8217;t boot, but it&#8217;s no help with a reinstallation. Soon you&#8217;ll be told that there&#8217;s already a Windows installation on the computer. Press r for a repair reinstall or Esc to begin a complete, destructive one. For a complete restore, select your C: partition and press Enter. When you get the warning that says an operating system is on that partition, press c. When you are asked your partition preference, select Leave the current file system intact (no changes). When you&#8217;re told that a Windows folder (or Winnt folder for Windows 2000) already exists, press l (&#8216;ell&#8217;) to delete it and create a new one. Follow the series of prompts. When the installation program asks for your name, enter temp.</p>
<p>Once the installation is complete, your system will reboot into Windows, and you&#8217;ll be logged on as user Temp. If the screen is difficult to read, reinstall your graphics card driver.</p>
<p>If you are reinstalling Windows XP, skip to &#8220;For Both Windows XP and 2000.&#8221;</p>
<p>If you&#8217;re reinstalling Windows 2000, log off as Temp and back on as Administrator. Now log off and on again, this time as Temp. Open Windows Explorer and navigate to C:\Documents and Settings. One of the subfolders will be named Administrator. Another will be named something like Administrator.computername.</p>
<p>Select Start, Programs, Accessories, Command Prompt. Type cd &#8220;\documents and settings&#8221; and press Enter. Then type xcopy administrator\*.* administrator.computername /s /h /r /c, replacing computername with the last part of that folder&#8217;s name (after &#8220;Administrator.&#8221;) in Documents and Settings. Now press Enter, and when you&#8217;re asked about overwriting files or folders, press a for All.</p>
<p>If you have any users on the old installation besides Administrator, continue with the &#8220;For Both Windows XP and 2000&#8243; section. Otherwise, open Windows Explorer and make sure your data files are where they belong. Then go to Control Panel&#8217;s Users and Passwords applet and delete the user Temp before skipping to &#8220;Finishing the Job.&#8221;<br />
For Both Windows XP and 2000</p>
<p>Reopen Windows Explorer. Select your C: drive (you may have to click Show the contents of this folder). Right-click in the right pane and select New, Folder. Name the new folder oldstuff. In the left pane, choose the Documents and Settings folder. It should have subfolders for each user from the previous install, plus one for Temp and a few others. Move the folders for your previous user names to oldstuff.</p>
<p>Select Start, Control Panel, User Accounts (Start, Settings, Control Panel, Users and Passwords in Windows 2000). Create an account for each user who was registered before the reinstall. Be sure to use the exact names. They are the same names as the folders you just moved to oldstuff (as shown in FIGURE 2). In Windows XP, at least one user must have administrator privileges.</p>
<p>Log off and back on as each user, before logging back on as Temp. Make sure that you select Log Off and not Switch User at Windows XP&#8217;s Log Off dialog box (this isn&#8217;t an issue in Win 2000).</p>
<p>Log on as Temp, select Start, Programs, Accessories, Command Prompt (in XP, Start, All Programs, Accessories, Command Prompt), type xcopy c:\oldstuff\*.* &#8220;c:\documents and settings&#8221; /s /h /r /c, and press Enter. Press a when asked if you want to overwrite a file. Log off Temp and log on to each restored account to make sure everyone&#8217;s documents and data are where they belong. Log on as an administrator and run Control Panel&#8217;s User Accounts applet again to remove the user Temp.<br />
Finishing the Job</p>
<p>Now you&#8217;ve got Windows going, but not much else. You may have to reinstall your printer, sound card, and so on. Luckily, if a driver for the gadget came on your Windows or vendor restore CD, it was probably reinstalled automatically.</p>
<p>You&#8217;ll have to reinstall your applications to reintroduce them to Windows. Some of their settings will not be changed by the reinstallation, but those that were stored in the Registry were wiped out.</p>
<p>Once your Internet connection is running again, browse to Windows Update and download all critical updates for your version (see FIGURE 3). Then visit the sites of your hardware vendors to update your drivers.</p>
<p>After the reinstall, some of your data may not show up where it should. Search for it in both your Application Data and oldstuff folders, and see if you can move it to the folder in which Windows or your apps are looking for it. If you find a folder called Identities with two subfolders whose names are long and indecipherable, try moving the contents of one to the other and see if your data reappears.</p>
<p>You&#8217;ve probably guessed that the final step is deleting the c:\oldstuff folder&#8211;and the Administrator folder in Windows 2000. Make this the very last step, however. Wait a couple of days, weeks, or even months until you&#8217;re confident that all of your needed files are accessible.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/18/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/18/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=18&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/how-to-reinstall-windows-without-losing-anything/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
		<item>
		<title>A Web Standards Checklist, How to make a proper website</title>
		<link>http://guardianlaptop.wordpress.com/2008/01/31/a-web-standards-checklist-how-to-make-a-proper-website/</link>
		<comments>http://guardianlaptop.wordpress.com/2008/01/31/a-web-standards-checklist-how-to-make-a-proper-website/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 00:57:14 +0000</pubDate>
		<dc:creator>guardianlaptop</dc:creator>
				<category><![CDATA[WebDev]]></category>
		<category><![CDATA[A Web Standards Checklist]]></category>
		<category><![CDATA[How to make a proper website]]></category>

		<guid isPermaLink="false">http://guardianlaptop.wordpress.com/2008/01/31/a-web-standards-checklist-how-to-make-a-proper-website/</guid>
		<description><![CDATA[The term web standards can mean different things to different people. For some, it is &#8216;table-free sites&#8217;, for others it is &#8216;using valid code&#8217;. However, web standards are much broader than that. A site built to web standards should adhere to standards (HTML, XHTML, XML, CSS, XSLT, DOM, MathML, SVG etc) and pursue best practices [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=17&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The term web standards can mean different things to different people. For some, it is &#8216;table-free sites&#8217;, for others it is &#8216;using valid code&#8217;. However, web standards are much broader than that. A site built to web standards should adhere to standards (HTML, XHTML, XML, CSS, XSLT, DOM, MathML, SVG etc) and pursue best practices (valid code, accessible code, semantically correct code, user-friendly URLs etc).</p>
<p>In other words, a site built to web standards should ideally be lean, clean, CSS-based, accessible, usable and search engine friendly.</p>
<p>About the checklist</p>
<p>This is not an uber-checklist. There are probably many items that could be added. More importantly, it should not be seen as a list of items that must be addressed on every site that you develop. It is simply a guide that can be used:</p>
<p>* to show the breadth of web standards<br />
* as a handy tool for developers during the production phase of websites<br />
* as an aid for developers who are interested in moving towards web standards</p>
<p>The checklist</p>
<p>1.Quality of code<br />
1. Does the site use a correct Doctype?<br />
2. Does the site use a Character set?<br />
3. Does the site use Valid (X)HTML?<br />
4. Does the site use Valid CSS?<br />
5. Does the site use any CSS hacks?<br />
6. Does the site use unnecessary classes or ids?<br />
7. Is the code well structured?<br />
8. Does the site have any broken links?<br />
9. How does the site perform in terms of speed/page size?<br />
10. Does the site have JavaScript errors?</p>
<p>2. Degree of separation between content and presentation<br />
1. Does the site use CSS for all presentation aspects (fonts, colour, padding, borders etc)?<br />
2. Are all decorative images in the CSS, or do they appear in the (X)HTML?</p>
<p>3. Accessibility for users<br />
1. Are &#8220;alt&#8221; attributes used for all descriptive images?<br />
2. Does the site use relative units rather than absolute units for text size?<br />
3. Do any aspects of the layout break if font size is increased?<br />
4. Does the site use visible skip menus?<br />
5. Does the site use accessible forms?<br />
6. Does the site use accessible tables?<br />
7. Is there sufficient colour brightness/contrasts?<br />
8. Is colour alone used for critical information?<br />
9. Is there delayed responsiveness for dropdown menus (for users with reduced motor skills)?<br />
10. Are all links descriptive (for blind users)?</p>
<p>4. Accessibility for devices<br />
1. Does the site work acceptably across modern and older browsers?<br />
2. Is the content accessible with CSS switched off or not supported?<br />
3. Is the content accessible with images switched off or not supported?<br />
4. Does the site work in text browsers such as Lynx?<br />
5. Does the site work well when printed?<br />
6. Does the site work well in Hand Held devices?<br />
7. Does the site include detailed metadata?<br />
8. Does the site work well in a range of browser window sizes?</p>
<p>5. Basic Usability<br />
1. Is there a clear visual hierarchy?<br />
2. Are heading levels easy to distinguish?<br />
3. Does the site have easy to understand navigation?<br />
4. Does the site use consistent navigation?<br />
5. Are links underlined?<br />
6. Does the site use consistent and appropriate language?<br />
7. Do you have a sitemap page and contact page? Are they easy to find?<br />
8. For large sites, is there a search tool?<br />
9. Is there a link to the home page on every page in the site?<br />
10. Are visited links clearly defined with a unique colour?</p>
<p>6. Site management<br />
1. Does the site have a meaningful and helpful 404 error page that works from any depth in the site?<br />
2. Does the site use friendly URLs?<br />
3. Do your URLs work without &#8220;www&#8221;?<br />
4. Does the site have a favicon?</p>
<p>1. Quality of code</p>
<p>1.1 Does the site use a correct Doctype?<br />
A doctype (short for &#8216;document type declaration&#8217;) informs the validator which version of (X)HTML you&#8217;re using, and must appear at the very top of every web page. Doctypes are a key component of compliant web pages: your markup and CSS won&#8217;t validate without them.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/guardianlaptop.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/guardianlaptop.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/guardianlaptop.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/guardianlaptop.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/guardianlaptop.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=guardianlaptop.wordpress.com&amp;blog=2670448&amp;post=17&amp;subd=guardianlaptop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://guardianlaptop.wordpress.com/2008/01/31/a-web-standards-checklist-how-to-make-a-proper-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8efba04ebddaba5354fa4fed39ceede3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">guardianlaptop</media:title>
		</media:content>
	</item>
	</channel>
</rss>
