-
Disable Paging Of Core Files and Speed Up Performance
Improve System Performance in Windows NT/2000 on systems with large amounts of RAM. This tweak can be used to force the Windows system core files to be kept in memory and not paged to disk. Open the registry and find this key:
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
For the Value name: "DisablePagingExecutive" , Data Type: REG_DWORD, change the value to 1 to enable the tweak and stop the core process from being paged, or set it to 0 for the default
-
Close port 135 by disabling DCOM in Dcomcnfg.exe
Click on Start> Run> and enter: C:\WinNT\System32\Dcomcnfg.exe, then click on the Applications tab. Many programs "support" Distributed Communication (DCOM) but hardly ever use it. This includes such programs as Windows Media and Wordpad, which are designed to be used across a network. As you scan this tab, look for third-party applications that might actually require network support, as opposed to those that simply support it. To determine if these programs really require DCOM, you must disable it, run those programs, and see what happens. NOTE that it is probably only necessary to look at third-party programs here; Microsoft programs designed to run on a non-networked, stand-a-lone computer (Office, etc.) are usually written to support but not require DCOM. To disable DCOM, go to the Default Properties tab and uncheck the box labeled "Enable Distributed COM on this computer".
Reboot, and try running the third-party programs NOTEd as above. Chances are good that everything will still run correctly. If not, go back and enable DCOM again. As you re-enable it, also go to the Default Protocols tab and remove all protocols except "Connection-oriented TCP/IP". This won't make your system much safer, but it will reduce the number of connection methods you have to keep an eye on.
If you do not have to re-enable DCOM again, then on the Default Protocols tab remove all protocols. You won't need them, and that should stop the OS from listening on Port 135
-
Turn off Indexing Service
Indexing Service creates indexes of the contents and properties of documents on local and network drives. It's quite similar to "Find Fast" that ships with Microsoft Office. Indexing Service runs continuously. Turning this off may increase performance. Go to: My Computer> right click on a Drive icon> select Properties. Remove the check mark from "Allow Indexing Service to index this disk for fast file searching". Click Apply. Be sure to select "Apply changes to <driveletter>:\, subfolders and files" before clicking OK in the new window.
-
Lock Desktop Shortcuts in place and Taskbar size/position
This Registry entry will prevent you from permanently repositioning desktop shortcuts and from adjusting the size and/or position of the Taskbar.
HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer
Add or change the Value name: "NoSaveSettings", Data Type: REG_DWORD, to 1.
-
Delete An "undeletable" File
Open a Command Prompt window and leave it open.
Close all open programs.
Click Start, Run and enter TASKMGR.EXE
Go to the Processes tab and End Process on Explorer.exe.
Leave Task Manager open.
Go back to the Command Prompt window and change to the directory the AVI (or other undeletable file) is located in.
At the command prompt type DEL <filename> where <filename> is the file you wish to delete.
Go back to Task Manager, click File, New Task and enter EXPLORER.EXE to restart the GUI shell.
Close Task Manager.
Or you can try this
Open Notepad.exe
Click File>Save As..>
locate the folder where ur undeletable file is
Choose 'All files' from the file type box
click once on the file u wanna delete so its name appears in the 'filename' box
put a " at the start and end of the filename
(the filename should have the extension of the undeletable file so it will overwrite it)
click save,
It should ask u to overwrite the existing file, choose yes and u can delete it as normal
Here's a manual way of doing it.
1. Start
2. Run
3. Type: command
4. To move into a directory type: cd c:\*** (The stars stand for your folder)
5. If you cannot access the folder because it has spaces for example Program Files or Kazaa Lite folder you have to do the following. instead of typing in the full folder name only take the first 6 letters then put a ~ and then 1 without spaces. Example: cd c:\progra~1\kazaal~1
6. Once your in the folder the non-deletable file it in type in dir - a list will come up with everything inside.
7. Now to delete the file type in del ***.bmp, txt, jpg, avi, etc... And if the file name has spaces you would use the special 1st 6 letters followed by a ~ and a 1 rule. Example: if your file name was bad file.bmp you would type once in the specific folder thorugh command, del badfil~1.bmp and your file should be gone. Make sure to type in the correct extension.
or Download this Freeware
http://www.diskcleaners.com/files/deletedr.exe
-
This is especially important in case of certain types of malware and worms such as W32/Lovgate.AC.worm:
see what happens when your system is infected with this worm:
Once launched, It also saves its components in the following files:
%System%\NetMeeting.exe
%system%\spoolsv.exe
%SysDir%\msjdbc11.dll
%SysDir%\MSSIGN30.DLL
%SysDir%\ODBC16.dll
%SysDir%\Lmmib20.dll
It also creates a file named AUTORUN.INF in the root directory of all accessible disks.
Home / Viruses / Virus Encyclopedia / Malware Descriptions / Network Worms / Email Worms
Email-Worm.Win32.LovGate.w
Other versions: .a, .ad, .ah, .b, .c
Aliases
Email-Worm.Win32.LovGate.w (Kaspersky Lab) is also known as: I-Worm.LovGate.w (Kaspersky Lab), BackDoor-AQJ (McAfee), W32.Lovgate.R@mm (Symantec), Win32.HLLM.Lovgate.9 (Doctor Web), W32/Lovgate-V (Sophos), Win32/Lovgate.V@mm (RAV), Win32:Lovgate-AD (ALWIL), I-Worm/Lovgate.X (Grisoft), Win32.Lovgate.V@mm (SOFTWIN), W32/Lovgate.AC.worm (Panda), Win32/Lovgate.Z (Eset) Description added Apr 05 2004
Behavior Email Worm
Technical Details
This worm spreads via the Internet as an attachment to infected messages. It is written in MFC.
The worm itself is approximately 125KB in size, packed using ASPack. The unpacked file is approximately 205KB in size.
Installation
Once launched, the worm copies itself under several different names to the Windows system and root directories:
%system%\Kernel66.dll
%system%\IEXPLORE.exe
%system%\hxdef.exe
%system%\RAVMOND.exe
%windir%\SYSTRA.exe
c:\command.exe
It also saves its components in the following files:
%System%\NetMeeting.exe
%system%\spoolsv.exe
%SysDir%\msjdbc11.dll
%SysDir%\MSSIGN30.DLL
%SysDir%\ODBC16.dll
%SysDir%\Lmmib20.dll
It also creates a file named AUTORUN.INF in the root directory of all accessible disks.
The worm creates several copies of itself in ZIP or RAR format. These copies are saved under random names in the root directories of all accessible disks.
It registers several copies of itself in the system registry. This ensures that these copies will be launched every time Windows is restarted.
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"WinHelp"="%System%\WinHelp.exe"
"Hardware Profile"=""="%system%\hxdef.exe"
"Microsoft NetMeeting Associates, Inc."="NetMeeting.exe"
"Program in Windows"="%System%\IEXPLORE.EXE"
"Protected Storage"="RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
"VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"run"="RAVMOND.exe"
It also creates the following system registry value:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services]
"SystemTra"="%Windir%\Systra.exe"
It creates an additional registry value to flag its presence in the system:
HKLM\Software\Microsoft\Windows\CurrentVersion\ZMX LIB1
Propagation via local networks
It makes the Ó:\windows\Media folder accessible via the local network under the name \\Media.
It copies itself to all network disks under the following names:
autoexec.bat
Cain.pif
client.exe
Documents and Settings.txt.exe
findpass.exe
i386.exe
Internet Explorer.bat
Microsoft Office.exe
mmc.exe
MSDN.ZIP.pif
Support Tools.exe
Windows Media Player.zip.exe
WindowsUpdate.pif
winhlp32.exe
WinRAR.exe
xcopy.exe
The worm attempts to copy itself to all local network machines by using the Adminstrator account. It uses the following passwords to attempt to gain access to the account:
!@#$
!@#$%
!@#$%^
!@#$%^&
!@#$%^&*
0
000000
00000000
007
1
110
111
111111
11111111
12
121212
123
123123
1234
12345
123456
1234567
12345678
123456789
123abc
123asd
2003
2004
2600
321
54321
654321
666666
888888
88888888
a
aaa
abc
abc123
abcd
abcdef
abcdefg
admin
Admin
admin123
administrator
Administrator
alpha
asdf
asdfgh
computer
database
enable
god
godblessyou
guest
Guest
home
Internet
Login
login
love
mypass
mypass123
mypc
mypc123
oracle
owner
pass
passwd
password
Password
pc
pw
pw123
pwd
root
secret
server
sex
sql
super
sybase
temp
temp123
test
test123
win
xp
xxx
yxcv
zxcv
If the worm succeeds in establishing a connection, it copies itself to \admin$\system32\NetManager.exe and launches the file as 'Windows Management NetWork Service Extensions'.
The worm harvests information about the victim machine, saves it in a file named c:\Netlog.txt and sends this file to the worm's author via email.
It installs a backdoor on TCP port 6000 to receive commands.
It launches an FTP server without login or password on a random port.
The worm searches all accessible disks from C: to Z: for files with the extension .exe. It then renames them as *.zmx, ascribes the attribute 'hidden/ system' to these files, and copies itself to the original files under the original names (working in the same way as companion viruses do.)
For further information of this worm click the link below:
http://www.viruslist.com/en/viruses/...?virusid=48907