** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.08.25
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.asp#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.asp#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.asp#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.asp#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.asp#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.asp#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.asp#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.asp#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.asp#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.asp#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.asp#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.asp#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.asp#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.asp#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.asp#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.asp#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.asp#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.asp#trace
How do I report a hacker?
http://securityadmin.info/faq.asp#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.asp#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.asp#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.asp#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.asp#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.asp#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.asp#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.asp#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.asp#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.asp#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.asp#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.asp#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.asp#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.asp#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.asp#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: Internet History/Internet Temp Files Tag: 59960
Logging in windows
Hi
I need to know whether net send messages are logged by
windows and if so where can I find them and what
information they contain. Am trying to track someone who
has been sending threatening messages across our network.
Thanx in advance
Rich Tag: Internet History/Internet Temp Files Tag: 59956
Changing password
I have a large windows 2000 network. I would like to get users to change
their passwords in a staggered fashion. Is there any way in windows that I
can set up a method to get users to change their passwords then have those
passwords come up for re entering at times in the future. Tag: Internet History/Internet Temp Files Tag: 59951
I have sp1. Questions about sp2
Ok I went to the web site to read as much as I could about stuff on the new
sp2-still, some things Im not sure of.
I have xp home,ZA free firewall (version 5), AVG antivirus, adaware, & I use
yahoo and yahoo messenger.
My concern is that these programs wont work properly or perhaps they need to
be configured to do so. Anyone have these same programs and can give me some
tips??
ALso, is sp2 really all that great??Have you all seen great improvements or
pluses on having installed this program??thanks Tag: Internet History/Internet Temp Files Tag: 59943
spyware is ruining my computer
I seemed to have picked up a trojan virus. It is one of those what
says: you have to download "SPY WARE"
I always refused to download that thing. My Norton antivirus has been
quarentining the virus. So far 70 copies of it has been quarentined.
The problem is that the function of my computer has been going down.
It is now to the point that I can no longer surf the internet b/c
internet explorer locks up.
Do you think I should have downloaded spyware? What is spyware? I
figured that it was another virus that the first trojan horse is just
trying to get me to dl a bigger virus.
Also, even tho norton has been putting these viruses in quarentine,
they still continue to damage my computer.
So, I am now to the point where I have to format my harddrive and
reinstall everyhting. It is going ot be a pain in the butt.
any help? Any one know more about htis spyware thing?\
thjx in advance. Tag: Internet History/Internet Temp Files Tag: 59941
slow web pages
my web pages load very slowly or sometimes not all the
way can anyone tell me what to do? Tag: Internet History/Internet Temp Files Tag: 59937
CONSUMER REPORT ON VIEW SONIC LCD MONITOR
VIEW SONIC IS RIPPING PEOPLE OFF WITH DEFECTED LCD
MONITOR,,, THEY ARE SELLING NEW DEFECTED LCD MONITOR TO
THE CONSUMERS .
DO NOT PURCHASED ANYTHING TO DO WITH VIEW
SONIC UNTIL VIEW SONIC DOES THE RIGHT THING .
IF YOU ARE THINKING OF PURCHASING FROM VIEW SONIC AND
IGNORE THIS MESSAGE LATER YOU WILL BE SORRY ... Tag: Internet History/Internet Temp Files Tag: 59931
Cannot access attachments on outlook express 6 - help!
I recently purchased XP with all the Norton anti-virus-
spam-and-firewall stuff. When I receive Emails with
attachmentsd I cannot access them. Help and other menues
are no great help. Can anyone give me soem directions
please? Tag: Internet History/Internet Temp Files Tag: 59928
Firewalls
Why do I need a software firewall when there is all ready a SPI firewall in
my wireless router? To me it is a duplication that is not needed. Yet SP2
"yells" if I disable it. Tag: Internet History/Internet Temp Files Tag: 59927
CDs that execute code without asking
Hi,
The other day I took my 35mm film to a photography shop and asked for
a CD of my scanned photos along with negatives and prints.
When I put the CD in my PC, Windows XP immediately executed a FujiFilm
photo-viewing program on the CD without asking me.
I am no expert on security, but doesn't this break all the rules?
When you insert, say, an audio CD, Windows asks you what you want to
do with it. One of the choices is "Do Nothing". Microsoft have gone
to some lengths to educate people not to execute e-mail attachments.
So why is Windows running arbitrary code on a 3rd party CD without my
consent?
Unlike e-mail attachments, I'm reasonably confident it won't have a
virus. But still, running code can do anything. Did software get
installed? Even if the purpose is innocent (say, to make start-up
time faster next time), did it add/change registry settings?
Overwrite DLLs? This risks breaking something else on the PC. What
about spyware? "Bundled" commercial software like this is a high-risk
category for spyware, I'd think.
Anyway, the point is not whether this particular software is safe -
it's that I don't think Windows should have run it without asking me.
I want Windows to tell me the CD is trying to run software, and ask
if I agree. Then I can decide whether I trust the vendor. After all,
I asked for data, not software.
Is there any way to recongifure Windows to prevent it doing this? Is
this behaviour still the default in SP2?
Thanks,
James Tag: Internet History/Internet Temp Files Tag: 59925
white hand with a red circle around it
i get a error page on the left hand corner of screnn and
the a white hand with a red circle around it,, Tag: Internet History/Internet Temp Files Tag: 59922
windows update
My system is telling that I do not have the update
fuction. I've tried manually activating it but it won't
let me click on any thing. Tag: Internet History/Internet Temp Files Tag: 59921
Hisecweb and Scheduled tasks
Hi!
I have applied hisecweb to my XP computer but then Norton Antivirus and
other scheduled tasks stoped to work. Do anyone know how to fix that?
Regards
/Marcus Tag: Internet History/Internet Temp Files Tag: 59920
www.ads234.com
I get this whenever I sign on internet explorer 6.0 and
it happens sometimes when I open a new browser window.
It locks up for a long time before connecting. It doesnt
do it when I use msn explorer. It is slowing everything
down and I cannot seem to locate the problem on the
computer. Microsoft help has been absolutely ridiculous
to contact and is worthless as far as I am concerned. If
you dont get down on your knees and beg them to help fix
a problem with THEIR software, you get nothing. Tag: Internet History/Internet Temp Files Tag: 59918
Does anyone recognize this?
wupdater.exe
My son has a program on his 2 month old Dell (running
Windows XP) called "wupdater.exe".
In the course of a "normal" shutdown, his computer is
very slow to respond and a box pops up asking if he wants
to end the "wupdater.exe" program that is running.
What's going on? Tag: Internet History/Internet Temp Files Tag: 59905
Recent E-mail telling me to to open "patch.exe"
I received an e-mail that looks like it came
from "Microsoft". It says to open "patch.exe". I did
not do this because the explanation was miss-worded and
not in very good english.
Is this legit? Tag: Internet History/Internet Temp Files Tag: 59903
How to apply security updates to PCs not connected to the Internet?
Hi,
I need to apply all security updates to PCs in our enterprise. These PCs are
on a LAN not connected to the Internet. Is it possible to download all
security updates to a CD and then apply them? All the PCs are Win98.
Is it any Windows product for managing centralized distribution of security
updates instead the Windows Update web page that requires direct Internet
access?
Thanks in advance
--
Faustino Dina
--------------------------------------------------------
If my email address starts with two 'f'
drop the first 'f' when mailing me. Tag: Internet History/Internet Temp Files Tag: 59902
port 139/445 traffic not picked up by antivirus
Having a lot of 139/445 traffic in my network, so much
that when this virus runs on one of the servers gets a
event id 2022 -out of connections. All patches and updates
have been loaded. Been in contact with Trend they picked
up some spyware appending to secfind.exe, but haven't
fixed it as yet. We have a mixed enviroment, win2k and XP.
This only affects the Win2k. Win2k security problem?
Have spoken to Microsoft in S.Africa but they only have a
sweat and rather charming Gal to help you with virus
removal tools etc but no where to excalate to.
Been hacking at this for 2 weeks now!!!!!!!!!! Tag: Internet History/Internet Temp Files Tag: 59893
Microsoft update with attached file
I just recieved an e-mail with an attached file that
claimed to be from Microsofts Program Security Section.
It urged me to run the attached file claiming to be a
cumulative patch that eliminates all known security
vulnerabilities in Internet Explorer, Outlook and Outlook
Express. I did not open the file and deleted it. Could
this have been a valid update or more then likely a
virus. If this was a virus why did my Norton Antivirus e-
mail scanning feature not catch it. Thanks Alan Tag: Internet History/Internet Temp Files Tag: 59892
windows updates
Hallo, I used to have regular alerts for Windows service
updates but since I had a full recovery I cannot see how
to make this automatic again. Could you please direct me
to have automatic alerts for Critical updates?
Thanks
Malvina Tag: Internet History/Internet Temp Files Tag: 59884
"Cannot Find Server" Message
Hi all. We got an email from a friend a while back that
had no subject with an attachment. The message said, "I
have a new phone number, please update your records". We
opened the attachment and ever since internet explorer
launches continuosly with the message "cannot find
server". The page cannot find server page also pops up.
Then it closes and does it again. Sometimes many copies
are open at the same time. I have scanned it with Norton,
it doesn't find anything. Any suggestions? Tag: Internet History/Internet Temp Files Tag: 59882
Cookies and Tracking
I have Windows XP Pro sp1 with IE6.0 I also have
installed Adware SE. I just ran scan and found a tracking
on my cookies. I immediately deleted it. I then went
into tools/internet options/privacy/advanced for cookie
handling. Can someone tell me how this should be set?
Should the overide automatic cookie handling be checked
or unchecked and if checked what do I set for 1st party
and 3rd party... Accept, Block, or enable? Any help
would be great. I just ran a scan yesterday and found
8. How do these tracking things get on one's computer? Tag: Internet History/Internet Temp Files Tag: 59879
Hewlett Packard Certificate
Have had a pop-up that appears to be from HP. However, if you read further,
you will find out that if you click on close or no, you are authorizing the
agent to retrieve data or download data to your computer without your
consent. Looks like a HP certificate but if you look on down, the expiration
date is (I think) 9-02. I have reported it to Microsoft security. Anyone else
seen this thing? It has happened 3 times to me.
--
Sam Tag: Internet History/Internet Temp Files Tag: 59875
How to isolate laptops from domain until AV is current.
Hello, I need some help! We are having a problem with
users logging on to the domain with laptops that are
infected. Is there a way to isolate systems until their AV
definitions are brought current. We are using NAV
Corporate Edition. Tag: Internet History/Internet Temp Files Tag: 59859
Microsoft's role in Biometric windows authentication???
I was wondering if anyone knows and can tell me where Windows XP stands as
far as supporting biometric devices. I am working on a project and trying to
do a little research. I am working with Windows XP Pro on some IBM Thinkpads
(T42). These laptops are headed to some field users and need to be a little
more secure against theft AND unauthorized access in case they are able to
access our network. Biometrics seems to be my next step to look into. So,
if anyone has any information or any experiences please send them my way.
Thanks! Tag: Internet History/Internet Temp Files Tag: 59857
Microsoft's role in Biometric windows authentication???
I was wondering if anyone knows and can tell me where Windows XP stands as
far as supporting biometric devices. I am working on a project and trying to
do a little research. I am working with Windows XP Pro on some IBM Thinkpads
(T42). These laptops are headed to some field users and need to be a little
more secure against theft AND unauthorized access in case they are able to
access our network. Biometrics seems to be my next step to look into. So,
if anyone has any information or any experiences please send them my way.
Thanks! Tag: Internet History/Internet Temp Files Tag: 59856
Advertisements pouring in through IE
When I leave my computer on and only the icons are on the
screen, stuff pours in through the explorer and I can't
figure out a way to block this. The other day I had 30
advertisements to close just to get back to the main
screen. Any help would be appreciated. Tag: Internet History/Internet Temp Files Tag: 59855
Create a computer certificate for non-connected machine?
Here's my scenario: We're doing L2TP VPNs, and we have a very well
functional internal PKI set up (doing EAP-TLS for interal wireless, so
it's well tested).
In doing L2TP VPNs, we need to get certificates on the clients--a User
level certificate stored in the local computer store. That's easy, we
do it with autoenrollment and a GPO on the domain.
However, I have 2 clients that are not part of my domain that need to
get a computer certificate. I can get them the certs for my Root and
issuing certificate authorities, that's easy, but how in the world do
I get them a computer certificate?
Please note, they are completely disconnected. Our Certificate server
is not reachable from the outside world, nor are these computers going
to be toted into the office to be on my network anytime soon. I'm not
doing PPTP to get them in without certificates to make the request.
How can I make a request on their behalf and export something that I
can send via floppy or USB? We're not ready to do smartcards yet.
Gratzi
Edd Tag: Internet History/Internet Temp Files Tag: 59851
security log
Hi,
What is a "best practice" method of auditing failed logon
attemtps? I have a small AD - 50 users, and am auditing
failed logon attempts but there are always a bunch of
events that do not look that important - 675, 677, 617
with --, 627...how does one sift through all of the events
and pick out real "attempted logons"? What else should I
be looking for?
Thanks - Wayner Tag: Internet History/Internet Temp Files Tag: 59848
workstation locking
Hi,
I cannot find where to change locking workstation
properties. I have a user that says her computer gets
locked in way to little time. I am running 2000 servers -
AD, and XP pro workstations. I looked in domain group
policy but could not find anything...
Thanks - Wayner Tag: Internet History/Internet Temp Files Tag: 59845
log on to line at welcome page is missing
When I logon I use to have 3 lines show up
User Name
Password
Lon on as
I now can't seem to get the Log on as to show up. I press options beside
the shut down buttom but that doesn't display it either. The reason why I
need this is that the administrator account I used was associated with my
domain, now it would appear that the only account I can access is a guest
account. This doesn't help me to do any administrator work. How or can I
get this to display back so I can log into my admin account. I can hook this
machine back onto the network but I still can't get the machine to look for
the admin on the server, it will only look locally. Tag: Internet History/Internet Temp Files Tag: 59844
having windows errors
I have a McAfee firewall and have received some
error messages ie: "AVSYNMGR32DLL has caused and
error in MCSCAN32DLL" also another message of "RULAUNCH
caused an error in (UNknown)"
Anything I need to do at this time? Tag: Internet History/Internet Temp Files Tag: 59841
help express
what is this? why, after three years is the box for help
express popping up at start? why does my fire wall and
virus protection call this spy ware? what or where can i
find it installed on the computer?should i be concerned? Tag: Internet History/Internet Temp Files Tag: 59839
sp2
How can I receive an sp2 update on cd? I move tomorrow
and will loose my broadband service. It will be replaced
with dial up service. Tag: Internet History/Internet Temp Files Tag: 59836
KB840315
I sent Microsoft Press an email stating that a training
kit I purchased for study does not work.
I recieved the following response:
"Hello,
Thank you for contacting Training Kit Feedback.
We have discovered that the Windows Hotfix KB840315
update causes the Readiness Review program to fail. You
can verify if this Hotfix is installed on your system by
looking at the list of programs shown under Add/Remove
Programs in the Control Panel. We are currently working
to acquire a fix for this issue. Once a fix becomes
available, we will let you know, and also post details in
an article in the Microsoft Knowledge Base.
Regards,
Xin
Microsoft Learning Support
http://www.microsoft.com/learning/support
I hope this response was helpful. If you have comments
about our support, write to us at mspts@microsoft.com.
Please remember to include the subject line from your
original message. Thank you." Tag: Internet History/Internet Temp Files Tag: 59830
System shutdown initiated...
My computer self-restarted with the following message:
"This system is shutting down. Please save all work in
progress and log off. any unsaved changes will be lost.
This shutdown was initiated y NT Authority\SYSTEM.
Message : System shutdown initiated"
I did not initiate the shutdown. Scan with latest virus
definition files. no virus found. Also scan with Blaster
worm removal tool. Nothing found.
Please help Tag: Internet History/Internet Temp Files Tag: 59828
spyware jerks
I just want to post this here for all of you to see. Who
knows, it will probably help you also. I have found a file
in my windows\system that is spyware and unrecognizable
and unremovable. The file is xwxnwhcw.exe and it's owned
by a company called www.callinghome.biz . So far I haven't
found a way to get rid of it. I tried from dos even with
windows shut down. This guy is a real sneaky jerk ( not
the words I'd use to his face), who should have his nose
broke but, what're ya gonna do? At any rate, if anyone
knows a fix, please post it, thanks. Tag: Internet History/Internet Temp Files Tag: 59823
validating a file's digital signature
Is there a way to validate the digital signature of a file (the one show in
it's properties window of windows explorer) using code (preferable vb code)?
dimitris Tag: Internet History/Internet Temp Files Tag: 59822
Disable ICF after Network setup Wizard
Ok i was told that the Network setu wizard automaticaly activate the Internet
Connection Firewall, whih may be what keeps screwing up my atempts to file
and printer share, or even view the computers on each others network places.
SO how do i disable the ICF after the newtwork setup wizard. During the
setup it bridged my internet connections (LAC and 1394 on the desktop and,
LAC 1394 and Wireless on the laptop) and now i no longer have an advacned tab
on any of the properties/ change settings screen. Tag: Internet History/Internet Temp Files Tag: 59820
Being Hacked Need Help
guys I am really new here, and I think (well I know) someone is hacking into
my MSN account, I didnt really clue in that I may be in trouble, I say this
because every time I logged into my msn personally it would say you have been
logged into another computer and then I would have to log in again, but now
today this guy has been adding crude addresses to my account and has been
changing my name! and it is becoming a nuissance, because he like takes over
my account like every 10 minutes even if I do a really complex password, I
just need some help, I am not experienced in this kind of stuff so plz
someone help me! Tag: Internet History/Internet Temp Files Tag: 59818
download a new program
I am trying to download a new program? It tells me that I need to disable my
norton and also my explorer before I can download the program. When I go to
the task manager to shut them down they are not listed? That is what the
help prompt said to do? Can anybody help me figure this out? Tag: Internet History/Internet Temp Files Tag: 59815
Unable to search with IE
Yesterday was moving really slow and getting a lot of
extra popups last few days . Then last night could not
get on so went in safe mode and finally used my 2000 disk
to get on and now my IE is locked from me changing
anything give me an errow when I go to internet options
that I can access restrictions and to contact
administrator. I am trying to fix this please help. Cant
get anywhere on the internet. I try to search but comes
back page not found and I have 2 domains so know that they
are there. Pleas help Tag: Internet History/Internet Temp Files Tag: 59811
Norton error message
I use Norton antivirus software and run XP Home Edition.
I suddenlt get an error message when I start my computer
which says "Cannot access Drive C". What is this all
about? How do I resolve this? Thanks Tag: Internet History/Internet Temp Files Tag: 59807
cleaning up files to sell comp.
HI I am looking to sell my desktop Compaq Presario. I
would like to know if there is any way to absolutely get
rid of any files I may have on the computer?? Also is
there a way I can remove my name from the registration of
the computer?? any help would be greatly appreciated.
Thank you Tag: Internet History/Internet Temp Files Tag: 59806
internet connection firewall
When I try to check the box that says "protect my
computer and network by limiting or preventing access to
this computer from the internet" (in the properties of
Local Connection) it says "an error occured while
internet connection sharing was being enabled. the
service cannot accept control messages at this time" not
sure what to do. can anyone help me please.
thanks,
tom Tag: Internet History/Internet Temp Files Tag: 59797
hidden virus
I have done a scan of my machine from a web site and it found an infected
file called attachment.45 "yours.pif" The file location is C/documents and
settings\franks\local settings\application data\microsoft
outlook\outlook.pst>attachment.45 "yours.pif"
When I click on documents and settings, then franks, there is no local
settings folder. How do I find this file to delete it?
--
Frank Milnes Tag: Internet History/Internet Temp Files Tag: 59795
Is there a way to block the deletion of history, etc., so
that I know what is being accessed by others on my machine?