Jengkol.. What a stupid virus name, Jengkol is traditional food in Indonesia, I don’t know how to categorized this one as food or fruit… usually some people like to eat this thing but I’m not those crazy one. THE SMELL *LOL*

Alright I think no need to explain more about what is jengkol ha..ha..ha..
This virus jengkol affect is it will logging off your computers once you executed .INF files or when you editing .VBS file. This virus will works by hiding all files he found with .DOC extension. You work in big company? when this happen your bos will fire you *LOL*
Alright let’s remove this virus out from your computers with 6 simple steps.
1. Unplug your computer from your local area network to stop it spreading.
2. Deactivated “System Restore” when in cleaning progress.
3. Kill virus process using 3rd party tools, Process Explorer.
4. Repair your registry changed by virus using code below, save it as anything with .VBS extension. In case this code coverting wrong download the source in HERE.
Dim oWSH: Set oWSH = CreateObject(“WScript.Shell”)
on error resume Next
oWSH.Regwrite “HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command\”,”"”%1″” %*”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command\”,”"”%1″” %*”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command\”,”"”%1″” %*”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command\”,”"”%1″” %*”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell”,”cmd.exe”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell”,”cmd.exe”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell”,”cmd.exe”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell”,”Explorer.exe”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\Shell\Edit\Command\”,”C:\Windows\System32\notepad.exe %1″
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\DefaultIcon\”,”C:\Windows\System32\WScript.exe,2″
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inffile\shell\Install\command\”,”C:\windows\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1″
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileAssociate”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistriTools”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegedit”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\RunLogonScriptSync”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\HideLegacyLogonScripts”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\HideLogoffScripts”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\HideStartupScripts”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\RunStartupScriptSync”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\run\JeNGKoL”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\NeverShowExt”)
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\”,”VBScript Script File”
oWSH.Regwrite “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\FriendlyTypeName”,”VBScript Script File”
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistriTools”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegedit”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\RunLogonScriptSync”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NOFind”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NORun”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveAutoRun”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Msconfig.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\attrib.exe\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\command.com\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe\debugger”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\debugger”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\DisallowRun\”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\Run\”)
oWSH.RegDelete(“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\”)
oWSH.RegDelete(“HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\”)
5. Delete virus duplicated files using windows search function, search files with:
- Using JPEG or VBS icon
- Size 14 KB
- File Type JPEG image or VBS Script file.
6. Scan with your best antivirus, antimallware, or antispyware to make sure your system clean.
Well done
SIMILAR POST :
- Stop Virus Stargate
- Remove GoldenGhost Virus W32/Agent.GYMR
- Remove virus AMBURADUL (all varian)
- Remove W32/SmallTroj.VPCG
Incoming search terms:
- jengkol
- cara memperbaiki virus shortcut
- C:\Wscript exe /e:vbs Thambs db
- how to kill watermark exe
- cara menghapus virus html drop agent ab
- software untuk mengatasi end program rundll32
- cara menghilangkan notepad exe
- hapus autorun inf
- cara mengatasi rundll32 exe end program
- menghilangkan rundll32
- menghilangkan vbs
- Sysfake wscript virus
- cara menghapus fakesys wscript
- watermark virus remover
- Teknik hilangkan water mark pada windors xp
- cara hilangkan virus exlorer exe pada start up
- mengatasi Rundll32 exe end program
- menghilangkan vbscript encoded script file dengan notepad
- menghilangkan end program rundll32 exe
- makanan jengkol
- memperbaiki virus vbscript
- menghapus virus watermark
- menghapus virus vbscript encoded
- Menghapus permanent rundll32 exe
- thambs db virus
- mengatasi end program rundll32
- menghilangkan virus vbscript
- owsh regwrite
- thambs db vbs virus processes
- thambs db clean
- What kind of viruse are SysFake Logoff and SysFake Wscript
- system32 db
- sysfake wscript
- store jengkol in us
- shellexecute=wscript exe stop-virus vbs
- shellexecute=wscript exe /e:vbs thumbss db كيف امسح
- repair watermark virus registry
- repair watermark virus
- remove watermark virus
- remove shellexecute=WScript exe //e:VBS thamb db
- removal for system32 db virus
- virus vbs sysfake
- kill virus watermark
- image buah jengkol
- cara menghilangkan rundll32 exe
- cara menghilangkan end program startup
- Cara menghapus wscipt exe
- cara menghapus virus sysfake
- cara menghapus virus ramnit dan html/drop agent dengan cmd
- cara menghapus virus html/drop agent ab dan WR/ramnit
- cara menghapus merepair virus sysfake logoff pada system
- cara mengatasiend program rundll32 exe
- cara mengatasi End Program-rundll32 exe
- cara mengapus rundll32 exe
- Cara menangani virus html drop agent
- cara memperbaiki vbscript encoded script
- cara hilangkan end program
- cara hapus autorun inf melalui notepad remove bat
- cara menghilangkan VBScript Encoded Scripf File
- cara menghilangkan virus desktop vbscript script file
- html drop agent ab removal
- how to kill watermark virus
- how to kill watermark exe removebale download
- how to fix stop-virus vbs
- hilangkan virus watermark
- hilangkan html/drop agent AB
- gambar cara menghapus virus VBscript Encoded Script file
- fakesys removal tool download
- FakeSys Logoff virus
- efek virus watermark exe
- cleaning virus watermark
- cara nak uji anti virus
- cara menghilangkan virus vbs sysfake
- cara menghilangkan virus system32
- buah jengkol
If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!






Did you know?
Tag cloud
Blogs Statistic
Subscribe my feed

November 30th, 2008 at 3:14 AM
That picture pete .. not jengkol .. hehehe
thank you for her source remover jengkol hehe … good
November 30th, 2008 at 4:12 AM
ha .. ha .. ha .. This image instead jengkol? I understand that the green jengkol same way that smells really brown: P
December 1st, 2008 at 8:06 PM
wah … Local virus plus the longer strange.
Tutorial may be very useful for rental-rentals near campus. most of his life pelangganya in typing. Doc
Currently, I’m probably not affected by this virus, but later if met, I knew where to find a solution.
talk about Lamtoro gung, Petai, Jengkol, Gayam. it’s somewhat similar. petai and jengkol when I was a bit hard to distinguish (more lazy gogling). but if such mas Is said, jengkol brown color, it is usually called from the western part of Java. if the eastern part of Java used to call it chocolate jengkol Gayam dg fruit. CMIIW. Instead, discuss the culinary … but on this blog it was not a sign of culinary ya? all need time yes …. heehehe : D TFS
December 5th, 2008 at 10:28 AM
I always like to leave comments when I see a good looking website. Keep up the great work.
January 19th, 2009 at 6:12 PM
pete’s picture, if jengkol chocolate, really long code
January 19th, 2009 at 6:16 PM
hehe according to this understanding of my family pictures jengkol
November 7th, 2009 at 12:21 AM
“If you are looking to monetize your website or content you should check out CPALead http://www.joincpalead.com/“
January 3rd, 2010 at 8:05 PM
Hi I reach this site by mistake when i was searching yahoo for this registry cleaner issue, I must
December 19th, 2010 at 11:29 AM
it’s not enough to kill this virus, because it generates too files in System32 folder by names “Thambs.db” and “system32.db”
you have to delete them also and restore the registry by using
ComboFix tool “www.combofix.org/download.php”