Friday, July 6, 2007

tip of windows vista

1.If you’re annoyed by Internet Explorer’s incessant barking that you’ve lowered your security settings (like, if you’re a non-paranoid expert), launch “gpedit.msc” from either the Run command or Start Search field, navigate through Local Computer Policy / Computer Configuration / Administrative Templates / Windows Components / Internet Explorer. In the rightmost pane, double-click “Turn off the Security Settings Check feature” and set it to Enabled.
2.If Internet Explorer’s Information Bar also annoys you, you can turn it off (again) in the Group Policy Object Editor (gpedit.msc) through Local Computer Policy / Computer Configuration / Administrative Templates / Windows Components / Internet Explorer / Security Features. In the rightmost pane, double-click “Internet Explorer Processes” and set it to Disabled. Hallelujah!
3.I’ve just mentioned two tweaks that are buried inside the Group Policy Editor. Jim Allchin pointed out that there’s a Group Policy Settings Reference spreadsheet available. Makes for great weekend reading.
4.Read the Background on Backgrounds if you’re a performance junkie. Don’t set your wallpaper through Internet Explorer ever again! Now that Windows supports JPG wallpapers, there’s absolutely no need (or excuse) for using BMPs anymore.
5.If you insist on keeping UAC (User Account Control) turned on for yourself, you might care to make the elevation prompts a bit less visually jarring. Brandon told me about this one, even though I have UAC turned off. Launch the Local Security Policy manager (secpol.msc), and navigate through Security Settings / Local Policies / Security Options. In the rightmost pane, scroll to the bottom and double-click “User Account Control: Switch to the secure desktop when prompting for elevation.” Disable it, and you can keep UAC turned on without getting turned off by the embarrassingly craptacular Aero Basic theme.
6.Vista can send you emails! The Computer Management tool can still be accessed by right-clicking “Computer” and selecting “Manage” from the menu. However, now you can attach a task to any event. Try navigating through System Tools / Event Viewer / Windows Logs / Application. Now, go ahead and select an event - then look to the rightmost pane and click “Attach Task to This Event.” Name it whatever, describe it however, click through the next step, then in the Action step, you’ll see the “Send an e-mail” option.
7.The Windows Task Manager gives you a lot more troubleshooting information in Vista. Flip to the Processes tab, and in the View menu, click “Select Columns” and add Description, Command Line, and Image Path Name. Moreover, when you right-click a process, you can select either “Go to Service(s)” or “Open File Location.” These are all long overdue options.
8.This one’s interesting. Open up the Date and Time Control Panel applet. Flip to the “Additional Clocks” tab. There, you can configure two more clocks from different time zones. They’ll appear in the tooltip when you hover over the Taskbar clock. No additional software (or silly sidebar widgets) necessary.
9.Applicable in other versions of Windows, I’m going to throw it in here for good measure. Create a shortcut to RegSvr32.exe in your SendTo folder. To get there quickly, enter “shell:sendto” in the Run command dialog or Start Search field. Now, when you wanna register a DLL or OCX file with the system, you can select it/them and “Send To” the RegSvr32 shortcut.
I figured I’d round out my first set of Windows Vista tips and tricks with a tiny bit of eye candy. 10.It doesn’t beat Picasa, but the Windows Photo Gallery is better than nothing. Once it’s indexed all your photos, click the icon next to the Search field and turn on the “Table of Contents.” That’s kinda nifty.

Monday, July 2, 2007

virus VBS.Stages.A

Description of the VBS.Stages.A worm

This worm appears as an attachment named Life_stages.txt.shs. When you run the attachment it will open a text file in Notepad. The text file describes the male and female stages of life. While you are reading the text file, a script is running in the background. This worm spreads itself using Outlook, ICQ, mIRC, and PIRCH.

You can download the fix program of this worm from:

Fix Life.exe from Symantec Corporation (You must copy this program to c:\windows\desktop)
KillStages.zip from McAfee.com
This fix program will remove the virus entry from your Windows's Registry and you must delete the file manually
Technical description of the VBS.Stages.A worm

The worm sends an e-mail to addresses listed in your Microsoft Outlook address book. The e-mail contains the LIFE_STAGES.TXT.SHS attachment. The subject of the e-mail is randomly generated and can be one of twelve strings. In some, but not all cases, the subject begins with "Fw:" It will, in any case, contain one of the following:

Life stages
Funny
Jokes
In some cases, this is followed by the word "text." The following are examples of possible subject headings:

Fw: Life stages
Jokes text
Fw: Funny text
As soon as they are sent, the worm deletes copies of the messages so that there is no record of its presence.

This worm will modify your system as follows:

The following files are crated in the Windows\System folder:
Scanreg.vbs
Vbaset.olb
msinfo16.tlb
The Scanreg.vbs value is added to the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Runservices\ScanReg = ScanReg.vbs
This will run the next time the computer is started.
The Life_Stages.txt.shs file is created in the \Windows folder
A randomly named file is added to the following locations:
The root directory of all mapped drivers (C:\, D:\, E:\, ... Z:\)
The \My Documents folder
The \Windows\Start Menu\Program folder
This randomly name file is created using the format of Random 1 + Random 2 + Random 3.txt.shs where:
Random 1 = Important, Info, Report, Secret, or Unknown.
Random 2 = '-' or '_' (Hyphen or Underscore)
Random 3 = a random number between 1 and 1000
For example, Report_439.txt.shs or Important-707.txt.shs.
The Regedit.exe file is moved into the Recycle Bin as a hidden system file named Recycled.vxd
The following files are added to the Recycle Bin as hidden, system files:
Msrcycld.dat
Rcycldbn.dat
Dbindex.vbs
Msrycld.dat is a copy of the original .shs file.
Rcycldbn.dat is a copy of the Scanreg.vbs file.
Dbindex.vbs is set to be run when ICQ is run. The script for mIRC is modified to call the Sound32b.dll file, which causes the worm to spread through mIRC and PIRCH
How to repair damaged done by the VBS.Stages.A worm

You can download the fix program of this worm from:

Fix Life.exe from Symantec Corporation (You must copy this program to c:\windows\desktop)
KillStages.zip from McAfee.com
This fix program will remove the virus entry from your Windows's Registry and you must delete the file manually
After running above tools (either one), it will remove the worm from your Windows registry and stop the infecting and propagating by this worm.

You can follow the instructions below to remove this worm manually

NOTE: This worm has done many modification to your system, the instruction below are complex which you need to have familiar with basic windows and DOS command. If you are not, we suggest you to contact the services of a computer technician.

Find and Delete files

Please follow these steps to locate and remove some of the files that were added by the worm:

Click Start -> Find and Click on Files or Folders.
Make sure that Look In is pointing to C:, or all drivers you have.
In the Named Box, type *.shs and click Find Now.
In the result pane, select any .txt.shs files and then press Delete. Click Yes to confirm.
Click New Search.
In the Named box, type scanreg.vbs vbaset.olb msinfo16.tlb and then click find now.
In the Results pane, select all the files that are found which should be found under \Windows\System folder and press Delete. Click Yes to confirm.
Restore the Registry Editor (REGEDIT.EXE).

Click Start, and click Run. The Run dialog box appears.
Type regedit and then click OK. The Registry Editor opens.
Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\RunServices
In the right pane, locate and select the Scanreg value. Press Delete, and then click Yes to confirm.
Navigate to the following key:
HKEY_USERS\.Default\Software\Mirabilis\ICQ\Agent\Apps\ICQ
In the right pane, locate and delete the following values:
Enable
Parameters
Path
StartUp
Navigate to and select the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\OSName
NOTE: This may not exist on all computers.

If it exists, press Delete, and then click Yes to confirm.
Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Classes\regfile\shell\
open\command
In the right pane, double-click Default.
11. In the Value data box, delete the current text and then type: regedit.exe

Click OK.

Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Classes\regfile\DefaultIcon
In the right pane, double-click Default.

In the Value data box, delete the current text and then type: regedit.exe

Click OK.

Navigate to the following key:
HKEY_CLASSES_ROOT\regfile\DefaultIcon
In the right pane, double-click Default.

In the Value data box, delete the current text and then type: REGEDIT.EXE
NOTE: If you have Windows installed to a location other than C:\Windows. please make the appropriate substitution when typing the path.
Click OK.
Navigate to the following key:
HKEY_CLASSES_ROOT\regfile\shell\open\command
In the right pane, double-click Default.

In the Value data box, delete the current text, and then type: regedit.exe.
NOTE: If you have Windows installed to a location other than C:\Windows then please make the appropriate substitution when typing the path.
Click OK.
Exit the registry Editor

DriverMagic 1.5

DriverMagic 1.5
this progarm can find Driver and auto Update enjoin ^ ^

http://sv2.gushare.com/file.php?file=2f0c33d74e76f5e206606ef5949fd7c9

Link Exchange

NarakClub Banner Exchange
FREE banner exchange Thaitop
Banner Exchange
Globalwarming Awareness2007, Directory