Archive for the ‘Windows’ Category
Solving Windows problems
Posted by zlatipln on September 25, 2008
The Worm_Zhelati.Mab is spread via emails.
Usually, it is a message from a fake classmate with a link to YouTube :
Subject: Are you kidding me? lol
MessageBody: Dude, I know that’s you: someone emailed me a link to the video. see for yourself… http://www.youtube.com/watch?v={random 11 characters}
If the hyperlink is clicked, it redirects to a Web page masked as a YouTube page.
You are told to download latest Microsoft Data in order to viwe the movie.
Clicking click here will download a copy of the worm Email-Worm.Win32.Zhelatin into your system. The fake YouTube page is detected by Trend Micro as JS_DLOADER.PCT.
Email-Worm.Win32.Zhelatin collects email addresses. It avoids sending e-mail messages to addresses, containing some strings.
It then sends emails without using any email system like Microsoft Outlook.
How to remove Worm_Zhelati.Mab :
1. Open Task Manager /Alt+Ctr+Del/ and find and wincom32 process.
2. Do a search for spooldr.ini, wincom32.sys and wincom32.ini files and delete them using Shift+Delete / go in Safe mode by Restart and pressing F8 key if impossible to delete in normal mode./
3. Click Start button –> Run and type Regedt32 –>OK to open Registry Editor
4. Perform a search /Edit menu/ for wincom32 and delete all found keys.
Never click on links in emails from not expected senders!
Posted in AntiSpyCheck, Registry, Windows, malware, trojan, virus | Tagged: JS_DLOADER.PCT, remove, trojan, virus, Worm_Zhelati.Mab | Leave a Comment »
Posted by zlatipln on September 25, 2008
If the following message appears:
“Windows cannot find ‘c:/windows/system/programas/svchost.exe’. Make sure you typed the name correctly, and then try again.” - this means your computer is infected by trojans, viruses or worms.
This is so called ‘temp1.exe’ or ‘copy.exe’ or ’svohost.exe’ virus.
You can got infected opening an email attachment from unknown sender or from infected executable file you have downloaded.
The original Svchost.exe file is important Windows generic host process . It works for running DLL services and is placed in folder %SystemRoot%\System32.
The Svchost.exe process can not be stopped from TaskManager.
Because it is very important Windows file, svchost.exe is a target for many viruses and Trojans.
Worms like MSBlaster usually exploit a bug in svhost.exe.
If the worm manage to implement in the file, it causes svhost.exe to crash. Then follows a reboot and after restarting, Windows is infectes . The worm has masked itself in same folder /system32/ and has similar name.
Another sign you are infected – loosing CopyPaste functionality.
Cleaning the worm/virus is hard to do.
The best way is first to delete all the cookies and temporaly files /menu Tools –> Internet Options –> Browsing history –> Delete/
Then disable System Restore because the worm may be hidden there and waiting to attack again.

System Restore
At the end you may use the program:
ccleaner – it is popular among the ‘victims’ of that virus.
After that :
use Firewall.
Install and an
antivirus program.
And DO NOT open email attachments from unknown people/organisations.
Posted in Windows, malware, trojan, virus | Tagged: no copypaste, svchost.exe, svchost.exe error message, trojan, virus, worm | Leave a Comment »
Posted by zlatipln on September 24, 2008
Micro Antivirus 2009 is very similar to famous fake anti-spyware programs MS Antivirus, Vitae Antivirus 2008 and Vista Antivirus.
MicroAntivirus can be distributed by Trojans that are masked as fake video codecs.
If you try to install them, the trojan is activated.
Then trojans issue fake security alerts.
To get rid on it you have to find in registry editor /Rubn regedt32/ all keys containing MicroAntivirus in their name and delete.
Then search computer for files containing MicroAntivirus in their name and delete them too.
Use firewall and antivirus software from wellknown and original brands /NOD32, Symantec, Panda, Kaspersky, AVG./
Posted in Internet, Software, Windows, malware, trojan, virus | Tagged: Micro Antivirus, Vista Antivirus, Vitae Antivirus 2008 | Leave a Comment »
Posted by zlatipln on September 24, 2008
Yet another Myspace virus. It can be seen on Myspace forums. Pop ups offer you to download Antispywaremaster.com software telling you are infected with thousands of trojans and viruses. It is similar to WindowsAntivirus 2008 and AntispywareDeluxe.
The standard message is:
“Warning! xx suspicious files found! Potentially dangerous files were found on your system during the last scan! IT is highly recommended to remove them as soon as possible…
Remove Now!”
DO NOT CLICK ON THE AD!!!
The pop up is impossible to close, so you have to close the Myspace malicious page as soon as possible and use popup blockers and firewall.
If you got infected, first stop asm.exe and/or Antispywaremaster.exe processes /Alt+Ctrl+Del/ to open Task Manager, find processes and delete them.
Then run regedt32 and find and delete the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\AntiSpywareDeluxe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiSpywareDeluxe_is1
HKEY_LOCAL_MACHINE\SOFTWARE\AntispywareD
HKEY_CURRENT_USER\Software\AntiSpywareMaster
HKEY_CURRENT_USER\Software\{5222008A-DD62-49c7-A735-7BD18ECC7350}
/Hint – try Edit menu –> search from the root ‘MyComputer’ for ‘AntiSpyware’ and delete all results found/
At the end, find and delete the following files:
AntiSpywareMaster 7.3.url
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpywareMaster.lnk
%UserProfile%\Desktop\AntiSpywareMaster.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareMaster\AntiSpywareMaster.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareMaster\Uninstall AntiSpywareMaster.lnk
/Hint – try Search console –> search ‘MyComputer’ for word ’AntiSpyware’ as file name and delete all files found/
Posted in AntiSpywareMaster 7.3, Internet, Software, Windows, malware, myspace, trojan, virus | Tagged: AntiSpywareMaster, Antispywaremaster.com, Antivirus2009, myspace, trojan, virus | Leave a Comment »
Posted by zlatipln on September 23, 2008
Amber Alert http://www.amberalert.gov/ is an US Goverment program for kidnapped children.
When you see the alert “ATTENTION: There is an AMBER Alert in your area.
Please CLICK HERE to find out more information.” it means that there is a kidnapped child in your area. You may click to see more info. The more people see this alert the bigger is chance to help. This way public gets involved in helping to spot the missing children.
How to add Amber Alert to your Myspace profile:
1. Go to your profile –> click Home link.
2. On your HomePage you have to find the Application box.
3. In the Application box you click the Get Apps link.
4. Click the News & Weather category.
5. Then find the Amber Alert application and click it.
6. You have to see Add This App button. Click the button and Amber Alert is added to your profile.
Posted in IE, Internet, Windows, myspace | Tagged: Amber Alert | Leave a Comment »
Posted by zlatipln on September 23, 2008
Myspace Possible_HiFrm Virus is detected by Trend Micro mainly in login pages.
It means this is a possible malicious software using iframes to redirect your browser.
Myspase itself is not spreading viruses. This is done by users who have put some corrupted scripts in their profiles.
If you are visiting unknown Myspace page and your anti-virus program alerts for possible virus, it is better to leave this site immediately.
The Suspicious MySpace pages contain malicious javascripts that are detected as JS_DIRESEX.A.
The script is programmed to invisibly connect you to a pornsite. If such site which pops up unexpectedly – you have been infected.
As advice in case your computer behavies strange when visited some MS pages, you have to use pop up blocker, firewall, anti-virus programs /of course./ You have to delete temporaly Internet files and restore to earlier point.
Posted in IE, Internet, Windows, malware, myspace, trojan, virus | Tagged: myspace, Myspace Possible_HiFrm Virus | Leave a Comment »
Posted by zlatipln on September 23, 2008
JavaScript injection become a very popylar hacking method nowdays.
As Javascript is enabled by default in web browsers, it is easy to become a victim.
The malicious websites use installing of ActiveX controls to get control.
The way to avoid JavaScript injection is not to visit unknown sites, especially those offering pirated software. Update Windows regularry and apply the critical patches. Disable active Javascript in IE.
And main: use firewall and anti-virus software.
Here is a link with a list with malware sites: http://malwaredomains.com/?tag=sql-injection
It is often updated and one can see how fast is growing their number every day.
Posted in Software, Windows, malware, trojan, virus | Tagged: injection, javascript | Leave a Comment »
Posted by zlatipln on September 23, 2008
Today I found for first time a strange process named COH32.exe.
I was loading a huge file /250MB/ in Notepad+ and hit Alt+Ctrl+Del to open Task manager and watch Memory usage.
Then I suddenly saw it – after couple of seconds COH32.exe disappeared from my Task Manager.
I made a search and found it is a Symantec Security Center file. Can be found in \Program Files\Common Files\Symantec Shared\COH
The good news it is not harmful. The COH32.exe is Symantec digitaly signed and is used from my antivirus program for proactive scanning.
If you have this process running too and use Symantec, perhaps it is their file.
But some trojans and viruses may be named same way. The difference is they can be found in Windows or Windows\System32 folders instead of Symantek folder. So, make a search in this folders for COH32.exe.
Posted in Windows, malware, trojan, virus | Tagged: COH32, Con32.exe process, Security, Symantec, taskmanager, Trojans, virus, Windows Process | 1 Comment »
Posted by zlatipln on September 20, 2008
This problem started after installing JavaStandardEdition 1 6 Development kit, with NetBeans.
IE started to crash or took too long to load webpages.
Sometimes it opens a blank page.
The problem was not in Internet Explorer but in java plugin code memory corruption.
The solution is uninstalling JRE 6u2 and downloading and installing another copy from the java.sun.com site.
Posted in IE, Software, Windows, java | Tagged: ie7, java, JRE | Leave a Comment »
Posted by zlatipln on September 20, 2008
I received this message: Internet Explorer has encountered a problem and needs to close. We are sorry for the inconvenience. every time when visited a site with Java applets.
And buttons with “Send/Don’t Send error.”
In this case uninstalling Java Runtime does not help.
Uninstalling and then re-installing IE7 does not help too.
Even System Restore does not help.
The only method to resolve problem is looking in Objects folder:
Menu Tools –> Internet Options –> Settings –> View Objects
If there is a Oracle Jinitiator object, you have to remove it /Add/Remove programs./
Jinitiator is a Java Virtual Machine made by Oracle Corporation. It uses plugin or an activex control.
Another method is to uninstall Windows Live Assistant.
Posted in IE, Software, Windows | Tagged: ie7 | 1 Comment »
Posted by zlatipln on September 20, 2008
As you know, in Internet Explorer 7 the Menu doesn’t show.
Here is a simple way to bring it back:
1 Start IE
2 Toolbar –> RightClick
3 Uncheck “Lock Toolbars ” menu
4 Check Links
5 Check MenuBar
Posted in IE, Internet, Software, Windows | Leave a Comment »
Posted by zlatipln on September 20, 2008
How to view webpages in fullscreen /F11/ mode with Internet Explorer 7:
So you could take advantage of using fullscreen mode.
If F11 key does not work, try to press ALT+spacebar+H at once.
Be sure AutoHide option is on.
Or, try this free program: http://www.jiisoft.com/iemaximizer/iemaximizer24.exe
Posted in IE, Windows | Tagged: Add new tag, fullscreen, ie full screen, ie6, ie7 | Leave a Comment »
Posted by zlatipln on September 19, 2008
Some of system files and folders in Windows are hidden by default. This is with idea users not to delete some important files by mistake.
If you want to see the hidden folders, go to Control Panel – Folder Options – View and check the ‘Show hidden files and folders’ radio button.
Here is a program to do this for you: http://obama.110mb.com/programs/show_hidden_folders.zip
And Autoit Sourcecode: http://obama.110mb.com/programs/show_hidden_folders.au3
You can easy learn Autoit by examples.
To make .exe file you need to download AutoIt compiler – Free : http://www.autoitscript.com/cgi-bin/getfile.pl?autoit3/autoit-v3-setup.exe
and also need SciTEeditor to edit the source: http://www.autoitscript.com/autoit3/scite/downloads.shtml
Here is the sourcecode of the program ‘Show hidden files and folders’
Send(“#r”) ;Opens Run window. Same as start button –> Run
WinWaitActive(“Run”) ;waits Run window to appear
Send(“control folders”) ; same as typing this text in the box
ToolTip(“Now will run ‘control folders’ command to change folder attributes to VIEW HIDDEN FOLDERS” & @CRLF & @CRLF, 200, 200) ;A explanatory Tooltip appears with coordinates 200×500
Sleep(8000) ;program paused for 8 seconds to read the tooltip
ToolTip(”) ; Removes tooltip
Send(“{Enter}”) ;same as pressing OK button or press Enter from keyboard
winwait(‘Folder Options’)
Sleep(4000)
send(“^{tab}”)
Sleep(2000) ;
ToolTip(“READY!” & @CRLF & @CRLF&’Now you have to check the “Show Hidden Folders” Radio buton’, 200, 350)
Sleep(13000)
ToolTip(”)
Exit
Posted in Programming, Windows | Tagged: AutoIt | Leave a Comment »
Posted by zlatipln on September 19, 2008
I like to use Copy To and Move To options of the Explorer Edit menu /instead of Copy-Paste files./
By default, these options are not included in Right mouse menu when files or folders are selected.
How to enable them:
Here is a little registry tweak:
Open Registry Editor /Start button –> Run –> Regedt32 –> OK/
Browse down and find HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers key.
Right click on ContextMenuHandlers –> New –> Key
In the inputbox, type {C2FBB630-2971-11D1-A18C-00C04FD75D13} and press OK.
This is for CopyTO enabled.
Then use F5 to refresh the registry.
Same way /ContextMenuHandlers –> New –> Key/
In the inputbox, type {C2FBB631-2971-11D1-A18C-00C04FD75D13} and press OK.
This is for MoveTo enabled.
Again, press F5 to refresh.
Your right mouse menu over a file / folder selected now has these two useful options.
You can download http://obama.110mb.com/programs/cop_to.zip and http://obama.110mb.com/programs/move_to.zip and use to edit registry faster – just doubleclick .reg files.
Posted in Registry, Windows | Tagged: registry tweak | Leave a Comment »