Page 2 of 2 FirstFirst 12
Results 11 to 16 of 16

Thread: Some Registry Tweaks, Unrevealed Windows Tips and Secrets

  1. #11
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    Disable Paging Of Core Files and Speed Up Performance


    Improve System Performance in Windows NT/2000 on systems with large amounts of RAM. This tweak can be used to force the Windows system core files to be kept in memory and not paged to disk. Open the registry and find this key:

    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management

    For the Value name: "DisablePagingExecutive" , Data Type: REG_DWORD, change the value to 1 to enable the tweak and stop the core process from being paged, or set it to 0 for the default

  2. #12
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    Close port 135 by disabling DCOM in Dcomcnfg.exe


    Click on Start> Run> and enter: C:\WinNT\System32\Dcomcnfg.exe, then click on the Applications tab. Many programs "support" Distributed Communication (DCOM) but hardly ever use it. This includes such programs as Windows Media and Wordpad, which are designed to be used across a network. As you scan this tab, look for third-party applications that might actually require network support, as opposed to those that simply support it. To determine if these programs really require DCOM, you must disable it, run those programs, and see what happens. NOTE that it is probably only necessary to look at third-party programs here; Microsoft programs designed to run on a non-networked, stand-a-lone computer (Office, etc.) are usually written to support but not require DCOM. To disable DCOM, go to the Default Properties tab and uncheck the box labeled "Enable Distributed COM on this computer".

    Reboot, and try running the third-party programs NOTEd as above. Chances are good that everything will still run correctly. If not, go back and enable DCOM again. As you re-enable it, also go to the Default Protocols tab and remove all protocols except "Connection-oriented TCP/IP". This won't make your system much safer, but it will reduce the number of connection methods you have to keep an eye on.

    If you do not have to re-enable DCOM again, then on the Default Protocols tab remove all protocols. You won't need them, and that should stop the OS from listening on Port 135

  3. #13
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    Turn off Indexing Service


    Indexing Service creates indexes of the contents and properties of documents on local and network drives. It's quite similar to "Find Fast" that ships with Microsoft Office. Indexing Service runs continuously. Turning this off may increase performance. Go to: My Computer> right click on a Drive icon> select Properties. Remove the check mark from "Allow Indexing Service to index this disk for fast file searching". Click Apply. Be sure to select "Apply changes to <driveletter>:\, subfolders and files" before clicking OK in the new window.

  4. #14
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    Lock Desktop Shortcuts in place and Taskbar size/position


    This Registry entry will prevent you from permanently repositioning desktop shortcuts and from adjusting the size and/or position of the Taskbar.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer

    Add or change the Value name: "NoSaveSettings", Data Type: REG_DWORD, to 1.

  5. #15
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    Delete An "undeletable" File

    Open a Command Prompt window and leave it open.
    Close all open programs.
    Click Start, Run and enter TASKMGR.EXE
    Go to the Processes tab and End Process on Explorer.exe.
    Leave Task Manager open.
    Go back to the Command Prompt window and change to the directory the AVI (or other undeletable file) is located in.
    At the command prompt type DEL <filename> where <filename> is the file you wish to delete.
    Go back to Task Manager, click File, New Task and enter EXPLORER.EXE to restart the GUI shell.
    Close Task Manager.


    Or you can try this

    Open Notepad.exe

    Click File>Save As..>

    locate the folder where ur undeletable file is

    Choose 'All files' from the file type box

    click once on the file u wanna delete so its name appears in the 'filename' box

    put a " at the start and end of the filename
    (the filename should have the extension of the undeletable file so it will overwrite it)

    click save,

    It should ask u to overwrite the existing file, choose yes and u can delete it as normal


    Here's a manual way of doing it.
    1. Start
    2. Run
    3. Type: command
    4. To move into a directory type: cd c:\*** (The stars stand for your folder)
    5. If you cannot access the folder because it has spaces for example Program Files or Kazaa Lite folder you have to do the following. instead of typing in the full folder name only take the first 6 letters then put a ~ and then 1 without spaces. Example: cd c:\progra~1\kazaal~1
    6. Once your in the folder the non-deletable file it in type in dir - a list will come up with everything inside.
    7. Now to delete the file type in del ***.bmp, txt, jpg, avi, etc... And if the file name has spaces you would use the special 1st 6 letters followed by a ~ and a 1 rule. Example: if your file name was bad file.bmp you would type once in the specific folder thorugh command, del badfil~1.bmp and your file should be gone. Make sure to type in the correct extension.

    or Download this Freeware

    http://www.diskcleaners.com/files/deletedr.exe

  6. #16
    Join Date
    Nov 2005
    Location
    AT DORRS NEAR HEAVEN
    Posts
    2,074

    Default

    This is especially important in case of certain types of malware and worms such as W32/Lovgate.AC.worm:
    see what happens when your system is infected with this worm:

    Once launched, It also saves its components in the following files:

    %System%\NetMeeting.exe
    %system%\spoolsv.exe
    %SysDir%\msjdbc11.dll
    %SysDir%\MSSIGN30.DLL
    %SysDir%\ODBC16.dll
    %SysDir%\Lmmib20.dll
    It also creates a file named AUTORUN.INF in the root directory of all accessible disks.

    Home / Viruses / Virus Encyclopedia / Malware Descriptions / Network Worms / Email Worms
    Email-Worm.Win32.LovGate.w
    Other versions: .a, .ad, .ah, .b, .c
    Aliases
    Email-Worm.Win32.LovGate.w (Kaspersky Lab) is also known as: I-Worm.LovGate.w (Kaspersky Lab), BackDoor-AQJ (McAfee), W32.Lovgate.R@mm (Symantec), Win32.HLLM.Lovgate.9 (Doctor Web), W32/Lovgate-V (Sophos), Win32/Lovgate.V@mm (RAV), Win32:Lovgate-AD (ALWIL), I-Worm/Lovgate.X (Grisoft), Win32.Lovgate.V@mm (SOFTWIN), W32/Lovgate.AC.worm (Panda), Win32/Lovgate.Z (Eset) Description added Apr 05 2004
    Behavior Email Worm
    Technical Details


    This worm spreads via the Internet as an attachment to infected messages. It is written in MFC.

    The worm itself is approximately 125KB in size, packed using ASPack. The unpacked file is approximately 205KB in size.

    Installation
    Once launched, the worm copies itself under several different names to the Windows system and root directories:

    %system%\Kernel66.dll
    %system%\IEXPLORE.exe
    %system%\hxdef.exe
    %system%\RAVMOND.exe
    %windir%\SYSTRA.exe
    c:\command.exe
    It also saves its components in the following files:

    %System%\NetMeeting.exe
    %system%\spoolsv.exe
    %SysDir%\msjdbc11.dll
    %SysDir%\MSSIGN30.DLL
    %SysDir%\ODBC16.dll
    %SysDir%\Lmmib20.dll
    It also creates a file named AUTORUN.INF in the root directory of all accessible disks.

    The worm creates several copies of itself in ZIP or RAR format. These copies are saved under random names in the root directories of all accessible disks.

    It registers several copies of itself in the system registry. This ensures that these copies will be launched every time Windows is restarted.

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "WinHelp"="%System%\WinHelp.exe"
    "Hardware Profile"=""="%system%\hxdef.exe"
    "Microsoft NetMeeting Associates, Inc."="NetMeeting.exe"
    "Program in Windows"="%System%\IEXPLORE.EXE"
    "Protected Storage"="RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
    "VFW Encoder/Decoder Settings"="RUNDLL32.exe MSSIGN30.DLL ondll_reg"
    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    "run"="RAVMOND.exe"
    It also creates the following system registry value:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services]
    "SystemTra"="%Windir%\Systra.exe"
    It creates an additional registry value to flag its presence in the system:

    HKLM\Software\Microsoft\Windows\CurrentVersion\ZMX LIB1
    Propagation via local networks
    It makes the Ó:\windows\Media folder accessible via the local network under the name \\Media.

    It copies itself to all network disks under the following names:

    autoexec.bat
    Cain.pif
    client.exe
    Documents and Settings.txt.exe
    findpass.exe
    i386.exe
    Internet Explorer.bat
    Microsoft Office.exe
    mmc.exe
    MSDN.ZIP.pif
    Support Tools.exe
    Windows Media Player.zip.exe
    WindowsUpdate.pif
    winhlp32.exe
    WinRAR.exe
    xcopy.exe
    The worm attempts to copy itself to all local network machines by using the Adminstrator account. It uses the following passwords to attempt to gain access to the account:


    !@#$
    !@#$%
    !@#$%^
    !@#$%^&
    !@#$%^&*
    0
    000000
    00000000
    007
    1
    110
    111
    111111
    11111111
    12
    121212
    123
    123123
    1234
    12345
    123456
    1234567
    12345678
    123456789
    123abc
    123asd
    2003
    2004
    2600
    321
    54321



    654321
    666666
    888888
    88888888
    a
    aaa
    abc
    abc123
    abcd
    abcdef
    abcdefg
    admin
    Admin
    admin123
    administrator
    Administrator
    alpha
    asdf
    asdfgh
    computer
    database
    enable
    god
    godblessyou
    guest
    Guest
    home
    Internet
    Login
    login
    love



    mypass
    mypass123
    mypc
    mypc123
    oracle
    owner
    pass
    passwd
    password
    Password
    pc
    pw
    pw123
    pwd
    root
    secret
    server
    sex
    sql
    super
    sybase
    temp
    temp123
    test
    test123
    win
    xp
    xxx
    yxcv
    zxcv




    If the worm succeeds in establishing a connection, it copies itself to \admin$\system32\NetManager.exe and launches the file as 'Windows Management NetWork Service Extensions'.

    The worm harvests information about the victim machine, saves it in a file named c:\Netlog.txt and sends this file to the worm's author via email.

    It installs a backdoor on TCP port 6000 to receive commands.

    It launches an FTP server without login or password on a random port.

    The worm searches all accessible disks from C: to Z: for files with the extension .exe. It then renames them as *.zmx, ascribes the attribute 'hidden/ system' to these files, and copies itself to the original files under the original names (working in the same way as companion viruses do.)

    For further information of this worm click the link below:

    http://www.viruslist.com/en/viruses/...?virusid=48907

Page 2 of 2 FirstFirst 12

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •