<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7720018365100417042</id><updated>2012-02-16T05:28:21.134-08:00</updated><title type='text'>Info Ghoben</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ghoben.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720018365100417042/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ghoben.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>info berita</name><uri>http://www.blogger.com/profile/11713266779297757966</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp3.blogger.com/__R6yDw2etAM/R7x09QxUqPI/AAAAAAAAACM/89X_xErEyDE/S220/1_827066444l.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7720018365100417042.post-668912093518043575</id><published>2009-03-07T19:11:00.001-08:00</published><updated>2009-03-07T19:11:38.789-08:00</updated><title type='text'>Download MP3</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720018365100417042-668912093518043575?l=ghoben.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ghoben.blogspot.com/feeds/668912093518043575/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7720018365100417042&amp;postID=668912093518043575&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720018365100417042/posts/default/668912093518043575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720018365100417042/posts/default/668912093518043575'/><link rel='alternate' type='text/html' href='http://ghoben.blogspot.com/2009/03/download-mp3.html' title='Download MP3'/><author><name>info berita</name><uri>http://www.blogger.com/profile/11713266779297757966</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp3.blogger.com/__R6yDw2etAM/R7x09QxUqPI/AAAAAAAAACM/89X_xErEyDE/S220/1_827066444l.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7720018365100417042.post-6490311269774137636</id><published>2008-02-25T10:38:00.002-08:00</published><updated>2008-02-25T23:14:40.520-08:00</updated><title type='text'>Salah Satu Penyebab Bill Gates Gulung Tikar…</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 102);font-size:78%;" &gt;Written by nexago &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 102);font-size:78%;" &gt;Wednesday, 30 January 2008 21:54&lt;/span&gt;&lt;span style="color: rgb(255, 102, 102);"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;  &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;Beberapa waktu yang lalu anggota crew yogyafree berhasil membuat sebuah mahakarya yang di klaim merupakan celah di windows yang dapat menyebabkan Bill Gates gulung tikar…dan berikut analisa “mahakarya” tersebut :&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;span style=""&gt;1. &lt;/span&gt;Compiled dari VB 6.0, dengan no packer dan native code.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;2. &lt;/span&gt;&lt;!--[endif]--&gt;Mengubah/menambah beberapa key registry :&lt;br /&gt;&lt;span style=""&gt;   &lt;/span&gt;* DisableRegistryTools&lt;br /&gt;&lt;span style=""&gt;   &lt;/span&gt;* DisableTaskMgr&lt;br /&gt;&lt;span style=""&gt;   &lt;/span&gt;* HKLM\Software\Microsoft\Windows&lt;span style=""&gt;  &lt;/span&gt;NT\CurrentVersion\Winlogon\Shell\Explorer.exe menjadi gutbai.exe&lt;span style=""&gt;  &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span style=""&gt;  &lt;/span&gt;* HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system\Shell\&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;3. &lt;/span&gt;&lt;!--[endif]--&gt;Gutbai.exe&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;4. &lt;/span&gt;Mencopy dirinya sendiri ke C:\Windows&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 9pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;5. &lt;/span&gt;&lt;!--[endif]--&gt;“Membunuh” proses Explorer.exe&lt;br /&gt;&lt;br /&gt;Bila dijalankan, aplikasi ini akan memunculkan window dengan 2 Button yang pertama berisi tantangan untuk meng-kliknya dan&lt;br /&gt;kedua akan menutup aplikasinya. &lt;span style="" lang="SV"&gt;Bila button pertama diklik maka akan muncul MessageBox yang berisi bahwa anda sudah menjalankan&lt;br /&gt;tantangannya dan aplikasi akan me-Log Off anda. Begitu anda Log On kembali maka anda hanya dihadapkan tampilan wallpaper saja.&lt;br /&gt;Mengapa demikian?? karena pada dasarnya Windows melakukan boot secara garis besar sbb:&lt;br /&gt;&lt;br /&gt;Boot Sector -&gt; NTLDR -|&lt;br /&gt;|-&gt; Ntdetect.com -&gt; HKLM\HARDWARE\DESCRIPTION&lt;br /&gt;|-&gt; HKLM\SYSTEM\CurrentControlSet\Services&lt;br /&gt;|-&gt; Ntoskrnl.exe |-&gt; bootvid.dll&lt;br /&gt;|-&gt; Windows Session Manager (smss.exe) -&gt; HKLM\SYSTEM\CurrentControlSet\Session Manager\Bootexecute&lt;br /&gt;-&gt; HKLM\SYSTEM\CurrentControlSet\Session Manager\Memory Management\PagingFiles&lt;br /&gt;-&gt; HKLM\SYSTEM\CurrentControlSet\Session Manager\Environment&lt;br /&gt;-&gt; Winlogon -&gt; MSGina.dll&lt;br /&gt;-&gt; Shell (Explorer.exe) ;Nah disini lah permasalahan terjadi&lt;br /&gt;&lt;br /&gt;Sang gutbai.exe menggantikan dirinya sebagai shell yang asli, yaitu Explorer.exe. Maka dari itu anda tidak mempunyai shell tapi mempunyai logon yang valid,&lt;br /&gt;karena MSGina sudah dieksekusi terlebih dahulu. TaskManager tidak bisa dibuka, sama halnya dengan Registry Editor (Regedit) karena telah di blok.&lt;br /&gt;&lt;br /&gt;Banyak cara untuk mengembalikan shell asli anda, seperti menggunakan media boot CD, disket, USB, dll. Yang pada dasarnya mengganti value registry yang telah&lt;br /&gt;diganti oleh aplikasi tsb. Berhubung kita menggunakan media boot, maka tidak dapat mengubah Registry secara langsung. DIperlukan aplikasi yang dapat membaca&lt;br /&gt;dan mengubah value registry. Untuk penyimpanan Registry Windows terdapat pada %SystemRoot%\Config\Software (karena HKLM\Software yang kita tuju).&lt;br /&gt;Dianjurkan menggunakan aplikasi yang sifatnya GUI (Graphical User Interface) dalam mengubah registry supaya memudahkan recovery. &lt;/span&gt;Penulis menggunakan&lt;br /&gt;CD Recovery XP 1.00 Build On PEBuilder yang didalamnya sudah terintegrasi Regedit bawaan. UNtuk mendapatkan atau mengetahui cara membuat CD tsb bisa menghubungi&lt;br /&gt;penulis.&lt;br /&gt;&lt;br /&gt;Cara Recovery:&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;1. &lt;/span&gt;&lt;!--[endif]--&gt;Buka Regedit dari Run.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;2. &lt;/span&gt;Browse HKEY_LOCAL_Machine Pilih File pada menu dan pilih Load Hive (File Type : Hive File)&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;3. &lt;/span&gt;&lt;!--[endif]--&gt;Browse ke Drive windows anda (biasanya C:).&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;4. &lt;/span&gt;Browse ke C:\Windows\System32\Config, lalu pilih file Software.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;5. &lt;/span&gt;&lt;!--[endif]--&gt;Akan muncul kotak input box, Buat nama key baru misal HKEY_BARU.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;6. &lt;/span&gt;&lt;!--[endif]--&gt;Browse ke HKEY_BARU\Microsoft\Windows\CurrentVersion\policies\system lalu &lt;span style=""&gt;  &lt;/span&gt;hapus value Shell.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;7. &lt;/span&gt;&lt;!--[endif]--&gt;Browse ke HKEY_BARU\Microsoft\Windows NT\CurrentVersion\Winlogon lalu ganti&lt;span style=""&gt;      &lt;/span&gt;value Shell menjadi Explorer.exe.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;8. &lt;/span&gt;Pilih File pada menu dan pilih Export.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;9. &lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="" lang="SV"&gt;Save 1 folder dengan file software tadi, misal dengan nama software2. &lt;/span&gt;Jangan lupa &lt;span style=""&gt; &lt;/span&gt;untuk memilih selected branch : HKEY_LOCAL_MACHINE\HKEY_BARU.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;10. &lt;/span&gt;&lt;!--[endif]--&gt;Pilih File pada menu dan pilih UnLoad Hive.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;11. &lt;/span&gt;&lt;!--[endif]--&gt;Browse ke C:\Windows lalu hapus file gutbai.exe.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;12. &lt;/span&gt;&lt;!--[endif]--&gt;Browse ke folder C:\Windows\System32\Config, lalu hapus file Software dan rename file software2 menjadi software.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="" lang="SV"&gt;&lt;span style=""&gt;13. &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="" lang="SV"&gt;Reboot Komputer anda.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt; text-indent: 0cm;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="" lang="SV"&gt;&lt;span style=""&gt;14. &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="" lang="SV"&gt;Gunakan file ini.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 9pt;"&gt;&lt;span style="" lang="SV"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;senkouryu&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;_NewBie^Foreva-&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7720018365100417042-6490311269774137636?l=ghoben.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ghoben.blogspot.com/feeds/6490311269774137636/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7720018365100417042&amp;postID=6490311269774137636&amp;isPopup=true' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7720018365100417042/posts/default/6490311269774137636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7720018365100417042/posts/default/6490311269774137636'/><link rel='alternate' type='text/html' href='http://ghoben.blogspot.com/2008/02/salah-satu-penyebab-bill-gates-gulung_25.html' title='Salah Satu Penyebab Bill Gates Gulung Tikar…'/><author><name>info berita</name><uri>http://www.blogger.com/profile/11713266779297757966</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp3.blogger.com/__R6yDw2etAM/R7x09QxUqPI/AAAAAAAAACM/89X_xErEyDE/S220/1_827066444l.jpg'/></author><thr:total>0</thr:total></entry></feed>
