Pop ups gone wild
Please help!
Ok, here's the story. I let my daughter download Kazaa on
a computer with Windows ME and I think we started to get
some pop-up annoyances, though not terrible. At some
point, I was on the computer and saw a Windows dialog box
that said the computer was becoming overwhelmed with pop-
ups and did I want to install a pop-up protector. I am
not an idiot who believes everything he sees but this
appeared to be an official windows dialog box. To my
knowledge, I successfully downloaded and installed that
program, though I may not have been successful loading it.
Does anyone know if Windows sedns this kind of dialog box?
Anyway, I noticed that, sometime after that, it seemed
like the pop ups got worse. I then noticed that my
default internet site was not yahoo and so I changed it
back, thinking that would probably solve the problem But
it is not. The only program I am using, fight now, is
Norton AV and as it is scanning I am still getting pop ups.
First of all, with Windows ME, can I restore my registry
to what I had say three days ago and undo all the Kazaa
installation and possibly phony anti-pop up installation
I've done?
Secondly, I see a bunch of programs that I don't know what
they are. Can you folk, tell me which are likely to be
the problem causing the pop ups? They are as follows:
Bargain Buddy, BDE, Eboles Moe Money Maker, IMesh, Imesh
ads support, Lycos Sideserver, MySearch Bar, New net
domains 5.48, p2p networking, peer points manager, sanity
media master, Top Text Ilookup, Viewpoint media player
(remove only), Web Hancer Customer Companion, webHancer
Survey Companion.
Thanks,
Deana Tag: Restoring Only system32.exe? Tag: 40652
SAFEBOOT RECOVERY CODE
I HAVE WINDOWS 98 ON MY LAPTOP
AND IT HAS GON INTO SAFEBOOT AND
WANTS ADMINS RECOVERY CODE I DONT HAVE ANY MORE
CAN ANY ONE HELP PLEASE Tag: Restoring Only system32.exe? Tag: 40645
Can't access network files/folders
Grrr.....
After letting Microsoft do a "let us do it for you"
security update from the "Updates" page I cannot access
certain files and folders on other systems on my private
home network.
Any instructions for removing/resetting file access
permissions would be greatly appreciated.
I've cruised the Microsoft site but can't seem to locate
instructions on how to "undo" what the update did.
I do not normally access this newsgroup so Email to
corky1747@earthlink.net would be greatly appreciated.
Thanks,
Corky Tag: Restoring Only system32.exe? Tag: 40634
content advisor
i am using content advisor to block sites on my computer.
When you type in the website in the url, it blocks the
site. but if i search for it in yahoo, and find it, I can
double click on the link and it takes me to the site. How
can i block this site? Tag: Restoring Only system32.exe? Tag: 40630
Search for blank passwords
Hello,
I would like to know if there is a utility or function of
Windows 2000/XP command line that I can run to tell me if
a computer has a blank password on one or any local user
accounts.
If I type "net user test" (where "test" is my username)
from command line, I get all the user info, but it
doesn't seem to give me what I'm looking for.
The end result will be embedding this into a patch /
account checking application that e-mails me the results
of what it finds. I've already got the patch checking
part done, but need help on the account side.
How does the MBSA check for weak passwords?
Any ideas? Tag: Restoring Only system32.exe? Tag: 40625
Norton and Bundle.exe
My Norton program is alerting me that Bundle.exe is
attempting to go to the internet, and labels it a medium
risk access. The options are block, allow, and let me do
it manually.
1. Why is bundle.exe going to the internet?
2. Should I let it?
3. How can I tell it not to, and prevent the program from
trying ever ten minutes?
I am running Windows Millenium Edition on a Sony VAIO.
Thanks...RLB Tag: Restoring Only system32.exe? Tag: 40620
Attachments stripped from my Emails received
Attachments such as Word documents are being removed from
my incoming Emails by Internet Explorer or by Norton.
Which do you think is doing it? How do I change the
settings?
Jim Tag: Restoring Only system32.exe? Tag: 40617
Bounce e-mail question
I've been using a tool called ABouncer (recommended by someone on this NG)
to notify ISP's when I receive Unsolicited Bulk E-mail.
I started wondering whether this tool is actually working properly, so I
tried sending mail from my web-mail address to ordinary address, then used
ABouncer to bounce it back to my web address.
This has not worked, so does that mean ABouncer is'nt sending any messages
to ISP's, or am I misunderstanding something.
Incidentally, when I click SEND on ABouncer, after a few seconds it
flashes up Caught Sendmail ....... I've always assumed that meant that the
message had been sucessful. Tag: Restoring Only system32.exe? Tag: 40611
Account User Reset
I took my computer to a local computer "fixer" to have
some work done on it. When I got it back, he had somehow
deleted my account profile, leaving only my 'guest'
profile. I now do not have any administative privleges,
and don't have a password reset disk. How do I completely
restart my computer so I can set up a new adminstrator
account?
PS- Nothing needs to be saved on my computer, so deleteing
all existing files is not an issue.
Any help would be appreciated. Tag: Restoring Only system32.exe? Tag: 40607
Cool Web Search Spyware Hijacker "Schredder" Update [1.36.1]
http://www.spywareinfo.com/~merijn/
< quote>
A small utility for removing CoolWebSearch (aka CoolWwwSearch,
YouFindAll, White-Pages.ws and a dozen other names).
Spybot S&D tends to forget essential parts of the hijack,
so until it updates, you can just this to completely remove the hijack.
Updated to remove the new variants once they come out.
>>>>>Currently changing versions at the speed of light.
</quote>
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Unzip the tool, ensure that all your IE/OE Windows are *closed*
hit the executable and follow the prompts.
You are *strongly urged* to use these tools, they are MS-MVP
tested and safe.
If anyone has questions, feel free to ask -
Regards,
--
siljaline
MS - MVP Windows IE/OE
______________________
(Reply to group, as return address
is invalid - that we may all benefit) Tag: Restoring Only system32.exe? Tag: 40605
Securing the Registry.
G/day forum,
I've been ploughing through documents and whitepapers on how to secure your
web server, the best resource of all was probably Improving Web Application
Security - Threats and Countermeasures, an absoloute bible for all ye web
admins out there. Before you read the part i'm querying, it i just want to
doublecheck that i'm not missing anything. Your thoughts please :)
On Chapter 16: Securing Your Web Server, page 449, the following:
Step 9. Registry
The registry is the repository for many vital server configuration settings.
As such,you must ensure that only authorized administrators have access to
it. If an attacker is able to edit the registry, he or she can reconfigure
and compromise the security of your server.
During this step, you:
? Restrict remote administration of the registry.
? Secure the SAM (stand-alone servers only).
Restrict Remote Administration of the Registry
The Winreg key determines whether registry keys are available for remote
access. By default, this key is configured to prevent users from remotely
viewing most keys in the registry, and only highly privileged users can
modify it. On Windows 2000, remote registry access is restricted by default
to members of the Administrators and Backup operators group. Administrators
have full control and backup operators have readonly access.
The associated permissions at the following registry location determine who
can remotely access the registry.
HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg
To view the permissions for this registry key, run Regedt32.exe, navigate to
the key, and choose Permissions from the Security menu.
Secure the SAM (Stand-alone Servers Only)
Stand-alone servers store account names and one-way (non-reversible)
password hashes (LMHash) in the local Security Account Manager (SAM)
database. The SAM is part of the registry. Typically, only members of the
Administrators group have access to the account information.
Although the passwords are not actually stored in the SAM and password
hashes are not reversible, if an attacker obtains a copy of the SAM
database, the attacker can use brute force password techniques to obtain
valid user names and passwords.
Restrict LMHash storage in the SAM by creating the key (not value) NoLMHash
in the registry as follows:
HKLM\System\CurrentControlSet\Control\LSA\NoLMHash
For more information, see Microsoft Knowledge Base article 299656, "New
Registry
Key to Remove LM Hashes from Active Directory and Security Account Manager." Tag: Restoring Only system32.exe? Tag: 40594
Closing Ports
My friend recently hacked into my pc to see if it was
possible. He managed to get in and said to me I should
close port 139, but I have no idea what he is talking
about or how to do this. Can someone please help me? Tag: Restoring Only system32.exe? Tag: 40592
** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.11.24
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
My question is not mentioned below. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
I just heard about a new Microsoft security patch update. Where can I get
the patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I just installed a Microsoft security patch update, and now my computer is
having problems.
http://securityadmin.info/faq.htm#patchbroke
I received an email from Microsoft / Microsoft Support / Microsoft Internet
Security Center claiming to be a security patch [or comprehensive Internet
Explorer update]. Is this a virus?
http://securityadmin.info/faq.htm#microsoftemail
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
I received a virus email from a Microsoft email address. Who do I report
this to?
http://securityadmin.info/faq.htm#microsoftemail
I have the RPC Blaster worm "virus," what do I do?
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
My computer is giving RPC Remote Procedure Call messages.
There is a TFTP message or file on my computer.
My computer keeps locking up, and/or rebooting, or telling me that it will
reboot in 1 minute.
http://www.microsoft.com/security/incident/blast.asp
ALSO NOTE: www.grisoft.com is free antivirus, USE IT.
Where can I download the Blaster worm / RPC DCOM patch?
http://windowsupdate.microsoft.com OR
http://www.microsoft.com/technet/security/current.asp
I'm having a problem caused by the JDBGMGR.EXE Teddy Bear "virus" hoax, or I
want to replace this file.
http://securityadmin.info/faq.htm#jdbgmgr
I forgot my Windows logon password and can't log in. How do I reset it?
http://securityadmin.info/faq.htm#password
I have a problem or a question with a virus or with antivirus.
http://securityadmin.info/faq.htm#virus
NOTE: www.grisoft.com is free antivirus, USE IT.
Why is Outlook Express blocking my attachments as "unsafe"?
http://securityadmin.info/faq.htm#attachments
How do I stop getting pop-up messages? Or adware? Or spyware?
http://securityadmin.info/faq.htm#pop-ups
How do I block people from viewing adult or objectionable content on a
computer?
http://securityadmin.info/faq.htm#contentfilter
How do I block spam emails?
http://securityadmin.info/faq.htm#spam
There is a Content Advisor password blocking me from certain web sites.
http://securityadmin.info/faq.htm#contentadvisor
How do I delete an FTP folder that a hacker put on my computer and I cannot
delete?
http://securityadmin.info/faq.htm#ftpfolder
Have I been hacked? What do I do if I've been hacked?
http://securityadmin.info/faq.htm#hacked
How do I re-secure a computer that has been hacked?
http://securityadmin.info/faq.htm#re-secure
How do I test or improve the security on my computer to avoid being hacked?
http://securityadmin.info/faq.htm#harden
How do I investigate a suspicious IP address that may be trying to hack me?
http://securityadmin.info/faq.htm#trace
How do I report a hacker?
http://securityadmin.info/faq.htm#reporthacker
How do I use a port scanner or vulnerability scanner to test my security?
http://securityadmin.info/faq.htm#portscanner
How do I encrypt my files and/or hard drive?
http://securityadmin.info/faq.htm#encryption
How do I get a firewall? IDS?
http://securityadmin.info/faq.htm#firewall
I want to use the IPSec filtering or IP filtering feature of Windows to
block certain ports and have a problem or question.
http://securityadmin.info/faq.htm#ipsec
I have a problem or question with the XP ICF firewall.
http://securityadmin.info/faq.htm#icf
I have a problem or question with the IIS URLScan tool.
http://securityadmin.info/faq.htm#urlscan
How do I change the banner on my computer or server to hide what software
version I'm using?
http://securityadmin.info/faq.htm#banner
How do I enable Windows Auditing to tell who logged into Windows or who
accessed a file?
http://securityadmin.info/faq.htm#auditing
How do I inspect and disable programs that start up when Windows starts?
http://securityadmin.info/faq.htm#startup
How do I use RUNAS or let someone use RUNAS to run commands as administrator
without having to type the password?
http://securityadmin.info/faq.htm#runas
How do I let non-administrator users run Defrag or change their IP address?
http://securityadmin.info/faq.htm#runas
My question is not mentioned above. How do I get an answer immediately,
with no waiting?
http://securityadmin.info/faq.htm#moreinfo
See also: http://www.google.com/groups?as_ugroup=microsoft.public.*
See also: http://www.google.com/advanced_group_search
See also: http://www.google.com
I want to post a problem or question to the newsgroup. What info do I need
to post in order to get a correct answer quickly?
http://securityadmin.info/faq.htm#netiquette
Note that this is NOT a full list of all the questions answered in the FAQ.
Chances are, your question has probably already been answered. The complete
FAQ is at:
http://securityadmin.info/faq.htm#contents
I hope this is helpful. Feedback, suggestions and criticism regarding the
FAQ are welcome and may be emailed to me.
kind regards,
Karl Levinson, CISSP, MCSE, MVP
email: levinson_k@despammed.com Tag: Restoring Only system32.exe? Tag: 40546
Outlook Express Spam Blocker - When?
I only use Microsoft software products. It's just easier
that way. But, I've just about had it with the lack of
progress in Outlook Express concerning SPAM!
Does Microsoft have any plans whatsoever to update the
inadequate "Outlook Express" Spam blocking features? This
is getting ridiculous! Tag: Restoring Only system32.exe? Tag: 40529
Cool Web Search Spyware Hijack "Schredder" Update 1.36.0
Info: http://www.spywareinfo.com/~merijn/
File: http://www.spywareinfo.com/~merijn/files/cwshredder.zip
<snip>
A small utility for removing CoolWebSearch (aka CoolWwwSearch,
YouFindAll, White-Pages.ws and a dozen other names).
Spybot S&D tends to forget essential parts of the hijack, so until it updates,
you can just this to completely remove the hijack.
Updated to remove the new variants once they come out.
</snip>
Unzip the tool, hit the executable, ensure that all instances of IE/OE
are closed, follow the prompts.
Regards,
--
siljaline
MS - MVP Windows IE/OE
______________________
(Reply to group, as return address
is invalid - that we may all benefit) Tag: Restoring Only system32.exe? Tag: 40528
what kinda of security should i have?
what kinda of security should i make sure i have on my
wireless router
(I will be remotee accessing my network)
thank you,
nick Tag: Restoring Only system32.exe? Tag: 40523
aua.boot
This particular file keeps popping up wanting to access my
internet connection. McAfee states that it reccommends
that access should be denyied, that there have been
updates to this file since last access. My question is:
What the heck is an aua.boot and should I continue to deny
it access to the internet? I'm not a total idiot to
computers, I know the basics and can do some cool things
with them but I have not idea what that is! Please
help! :)
Thanks :) Tag: Restoring Only system32.exe? Tag: 40519
microsoft money
a friend has asked me to look at why there data in ms
money has suddenly changed giving incorrect balances, are
there any security issues or ms money targeted worms etc,
i have suggested they get a firewall, any suggestions
welcome Tag: Restoring Only system32.exe? Tag: 40515
adaware cant take out hotbar
I installed adaware the free version for the first time-
And then updated and then scanned as has always been
suggested here. then I did a pestscan scan and hotbar and
tucows were still there- I redid the ad-aware scan and it
found one more data tracker thing-went to pestscan and
the same 2 were still showing on there list-I know that I
have had problems removing hotbar manually before using
the help of any software (because hotbar is hiding
somewhere and cannot be taken out) Now it only shows up
on pestscan- what can I do. If it is suggested to send
the ref-file How safe is it? and what is it that I have
to send exactly?? Tag: Restoring Only system32.exe? Tag: 40513
Against copy of CD-ROM
Can you suggest ways of preventing copying of CD-ROM?
I have an enormous PP presentation that took 3 years to
built with 350 files and at least 4000 hypertext links
that I need to preserve.
I need astuces to render harder copying of the PP
presentation so that ordinary people won't be able to copy
easily the PP presentation. Tag: Restoring Only system32.exe? Tag: 40509
How to burn a 99 minutes PP presentation (850 MB CD)?
How to burn a 99 minutes PP presentation (850 MB CD)? I
have a PP presentation of 830 MB with 350 files taht took
me 3 years to produce. I would like to burn the PP
presentation on 1 CD-ROM of 850 capacity. I even bought
Easy CD Creator 6. I can't do it.
Can you tell me what to do? Tag: Restoring Only system32.exe? Tag: 40507
Patchlink updates
I am considering Patchlink from www.patchlink.com to disseminate
Microsoft updates and patches and I have large windows environment
that consist of 40,000 workstations and over 300 servers.
Did anyone try Patchlink and if so is it scaleable in a large
environment like our shop.
I appreciate your feedback.
Regards,
AOS Tag: Restoring Only system32.exe? Tag: 40500
mamabear or anyone
Hi, you recently gave this advice to a reader. But I
could not make out what this abbreviation means. 'AAW' as
in : This link will help you configure AAW for
your first scan: http://www.lavasoftsupport.com/index.php?
can you or anyone please tell me what the abbreviation
means Tag: Restoring Only system32.exe? Tag: 40491
Installed an update but it failed-Now it Won't let me Reinstall-HELP!!
I installed an update which my computer said I needed
to install. There were 2 of them. They both failed 2
months later it finally let me re-install 1 of them, but
it still won't let me re-install the other update. I have
Windows 98 and have tried troubleshooting and it has not
worked. What can I do to get this update re-installed.
It is my "Wizard" updated and I use my Wizard all the
time. I need this update in there and working. Please
help me to get this in there, I can't afford to pay
another $35.00 to Microsoft for a problem that never got
resolved the last time I contacted them. I wound up
having to troubleshoot and back-up my macine to the
previous back-up to clean up the problem because they
never fixed the problem after being on the phone with them
for 6 hours. So please if you have an answer for me
please let me know. Thank You in advance. donnamai52 Tag: Restoring Only system32.exe? Tag: 40490
critical updates and service patches
I am an A+ certified tech and teacher that has many
students, family, friends of family and neighbors that
bring me their PCs in various states of problems. Many
with multiple viruses, spyware, bots and spiders, asking
for my help. Often the only solution is to format and
reload their OS. I am dealing with alot of Win 98SE, win
XP home and an occasional Win95, Win2000 and of course
Internet Explorer and Outlook Espress. After redoading
their OS and Anti-virus software I update their anti-virus
software with the latest paterns with a CD that has the
latest paterns that I download from the softwares website
so they do not have to go online unprotected to get them.
I would dearly like to be able to do the same with
critical updates and service packs. As these OSs get older
and older obtaining the updates online leaves these people
unprotected while trying to update their systems. How can
I get the latest updated and service packs downloaded on
to a CD to install off line? They are constantly changing,
so even though I do not mind buying these CDs they are
only current for a month or two. Tag: Restoring Only system32.exe? Tag: 40487
Please Help!!! Advertising companies installing software not registered
I have seen some companies as orbit.com that install
software in the machine without your consent or at least
inadvertently for you. I have tried to delete those
programs (n-case is another one) but they keep coming
back as they were viruses (they are!!!).
How can I prevent these to happen? Is there a cure for
mine actual situation ?
thanks, Tag: Restoring Only system32.exe? Tag: 40484
sign in registrys
can anyone tell me how to wash sign in names off msn
messenger, each time i sign in or anyone else it leaves
all the sign in names showing
thanks Tag: Restoring Only system32.exe? Tag: 40480
pleeease help me.
hi there
i would like to know that is there any way to know
administrator password or to hack the administrator . Tag: Restoring Only system32.exe? Tag: 40479
Make a Disk Drive Private??
Does anyone know if there is a way that I can "hide" or
make private a whole hard drive while "sharing" my
computer with, say, family members and/or friends? In
other words, I installed a hard drive for extra space,
etc...and I would like to have it where only I can
see/have access to it. Is this possible?
Thanks,
Scottnphilly@aol.com Tag: Restoring Only system32.exe? Tag: 40472
frequency of fake Microsoft emails
I get about 10-20 of those things every day. Is that what most people
are getting? (Of course I don't open them.)
Do they come from a different domain name each time? Tag: Restoring Only system32.exe? Tag: 40454
e-mail
My e-mail keeps giving me the same 18 e-mails over and
over again no matter how many times I delete them. Tag: Restoring Only system32.exe? Tag: 40452
Security Program Allows a Single Password to Be Used On Every Website
For Immediate Release
Internet security took a major step forward recently as Unlimited Potential,
Inc., a privately held Kansas corporation, released a software package that
allows users to remember and use a single password for all web sites with
the same or higher security level as previously provided by using different
passwords for each.
For the first time, single password access is available for all websites on
the Internet without the need for a centralized authority such as
Microsoft's (NASDAQ: MSFT) .NET PASSPORT service. The software, known as
PassSafe Pro, is being distributed via CNET (NASDAQ: CNET) as well as
directly from http://PassSafe.com.
The patented process combines the name of a website or other protected
entity with a password selected by the user. This encrypted password
replaces the password typed by users by replacing all web-based password
fields with a secure dialog that encrypts the users' password, keystroke by
keystroke, resulting in a different encrypted password for every website
visited, even though the same password is typed by the user for every
website.
The company claims that identity thieves and hackers are stopped cold
because the generated password is virtually impossible to reverse engineer
to reveal the original user selected password. More than 10^28 possible
combinations can be generated. This means that if a super computer was used
to calculate one hundred billion passwords per second, it would take over
thirty million years just to sample 1% of the possible password combinations
created by this software.
Unlimited Potential, Inc. invites inspired individuals and companies to
debunk or confirm the claim that the resulting password from the application
is truly one-way and can not be used to recreate the original user selected
password. Mike Reed, inventor of the technology behind PassSafe says,
"Combining layers of RSA Security (NASDAQ: RSAS), MD5 algorithms with our
proprietary modulo based pseudo-random table cross referencing technology
assures the highest level of protection against reverse engineering. Even if
the source code and exact methods used were available to hackers, there is
little chance of compromise."
The company believes that, for the first time, totally secure password
protection is available to protect against hackers and identity thieves.
For more information contact:
Unlimited Potential, Inc.
Public Relations Department
publicrelations@passsafe.com
(913) 685-2700
keywords: Internet Security, Secure, Password, Passwords, Security,
Encryption, Internet Explorer, Microsoft, MSFT, RSA, RSAS, CNET, MD5,
hackers, Identity Thieves Tag: Restoring Only system32.exe? Tag: 40449
internet security updates
I have explorer 5.0. The security updates I am receiving
are for explorer 6. I have heard that explorer 6 is not
as good as 5.0, so I don't think I should download
anything. Am I right or wrong? The bulletin I am
referring to is MS03-048, 11-12-03. Tag: Restoring Only system32.exe? Tag: 40429
Help-Tried almost everything, chapter 2
I'm still dealing with an unwanted outgoing ICMP packet
being sent when I connect to the internet, but I've just
discovered another program tring to communicate. the
program is called RPCSS.EXE and it's property name is
Distributed COM Services. Any ideas? -Rockly Tag: Restoring Only system32.exe? Tag: 40427
Smart Card Force logoff and Remove Lock Workstation
Hello,
I have tried to get an answer at microsoft.public.windows.group_policy
but without any results. Therefore I try it here once more where a few
people
are using smart cards.
we have a problem with the setting of two group policies.
We are using smart cards and if someone removes the smart card
he should be logged off by the group policy Smart Card Removal
Behaviour: "Force Logoff".
Second, we also don't want to allow our students to lock the
workstation.
Therefore we put the Strg+Alt+Del Policy : "Remove Lock Workstation".
But both policies doesn't work together. "Remove Lock Workstation"
works fine but if this policy is set the "Force Logoff" doesn't work
any longer.
Can't this two policies be used together?
We are using Windows 2003 Servers and Windows XP Workstations.
Thank you for you help,
Hans Tag: Restoring Only system32.exe? Tag: 40421
Microsoft Security Update
I am getting ms security updates via e-mail, but I am not
sure they are for-real. I've received two of them this
week; the first one had attachments, that were in a
foreign language -- I am doubtful it was from microsoft.
I wonder if a hacker is using e-mails supposedly from
microsoft to deploy a virus. Here is more content from
the e-mail I received:
it was from: tdneqi@updates.msdn.com
it had the following attached file, which I will not
open: ATT00009.txt Tag: Restoring Only system32.exe? Tag: 40420
Signing in to MSN PLEASE HELP!!!
Can any one help. I have purchased a new PC and there is
more than one user, yet all can access my MSN account as
it automatically signs me in. How can I stop it from
doing this???? Tag: Restoring Only system32.exe? Tag: 40412
RPC_C_IMP_LEVEL_IMPERSONATE does not work beyond machine boudaries
Hi All,
I have a Windows service which runs in the Local System context. This
service impersonates a particular user and then loads some DLLs to perform
some task. The problem here is that the calls work fine when run only on the
DC but not on a member server or any machine from some other trusted domain.
I am using the
RPC_C_AUTHN_LEVEL_CONNECT
RPC_C_IMP_LEVEL_IMPERSONATE
EOAC_DYNAMIC_CLOAKING
Thanks in advance Tag: Restoring Only system32.exe? Tag: 40411
How to lock down server and create VPN using MS IPSec only
Hi,
I've encountered the following problem. I've created IPSec policy to connect
to VPN gateway (Cisco router) - and everything works fine. Then I've decided
to lock down the machine using IPSec policy and here comes the problem: I've
got 2 security rules for VPN (both ways) and another rule to block all IP
traffic. When I enable the 'block all' rule i loose all IP traffic - both
with Internet and VPN gateway. Is there a way to configure IPSec tunnel and
lock down the machine without f.x. TCP/IP Filtering?
Thanks,
Jacek Tag: Restoring Only system32.exe? Tag: 40395
How Effective Are Firewalls and Anti Virus Applications
No need for a firewall or anti-virus application if your on a Windows
Platform and you didn?t disable the services Windows leaves open, before
your computer went online to the Internet. Your computer already has
file and print sharing open and anyone in the world can view what is on
your hard drive, add whatever they desire to add, including Backdoors
and Trojan Horses. And don?t forget that Trojan Horses disable your
firewall, whether hardware or software and any anti-virus application on
your computer. Want proof of this technology, e-mail me at
snailmail222000@yahoo and with your permission this babe will send you
the "Redwood Broker Backdoor". Only the "elite" malicious hackers know
about this and you won?t find any information on the Internet pertaining
to it. Let?s expose the malicious hackers activity and share this
knowledge with the world.
Don't forget the malicious hackers use victims computers, running
Virtual Private Networks and Dial-Up Servers with Pre-paid Phone Cards.
Want to learn it all check out: www.secure2003flop.com
Tracker Tag: Restoring Only system32.exe? Tag: 40393
blackholes to go offline :-(
I just read this on nanae:
Quote:
The easynet blacklists/spamfilters (blackholes.easynet.nl,
proxies.blackholes.easynet.nl, dynablock.easynet.nl,
spamdomains.blackholes.easynet.nl, and the easynet
spamlists) will be
discontinued starting Dec 1 2003.
The zonefiles and associated files will be 'zero-sized' on
that day. The
domains
will continue to resolve for a long time, but they will
contain nothing more
than the test records (127.0.0.2 and example.com), so they
will not catch
anything.
Holy Crap!
- Yep.
FAQ?
- Sure.
Are you being DDos'ed out of existence?
- Nope. They probably tried. We didn't even notice it.
Are you being sued?
- Nope. They probably tried. We didn't even notice it.
Are you being threatened?
- Frankly, we will miss that part.
Are you tired?
- Damn right.
Are you giving up?
- That is not the right word. There are plenty of fine
blacklists, and new
ones
spring up every day. The wirehub/easynet lists served
their purpose, but
others
may serve that purpose equally well.
Isn't this all kinda sudden?
- Yes. Sometimes, you just know that it's time to say
goodbye. And the
moment
you know it, you must do it. Running blacklists on
anything less than 100%
motivation and energy is not how it should be done.
Anything else?
- Sure. These blacklists were maintained by a single
person, all of them.
Every
day. Listings, delistings, finding new DSL/cable ranges,
finding new open
proxies, writing better scripts, handling all email,
running statistics,
publishing overviews, providing rsync areas, DNS tranfers.
You name it.
TINW.
There's an I. And I want my life back, at least a little ;)
Life?
- Yes. Maybe not as we know it. Over the past 3-4 years,
the maintainer of
these
lists has worked 7 days a week, 10-12 hours a day running
these lists and
handling all tasks and email associated with them. Not a
single day has
passed
without at least processing delisting requests (the bare
minimum). And then
there was the day job (which was really nothing more than
running an ISP's
server farm - peanuts, it's FreeBSD).
Is that all?
- There's more to it, but the details do not really
concern you. Let's just
say
that the integrity of these lists might have been in
jeopardy in the long
run.
There are two cardinal sins when it comes to blacklists:
1. putting/keeping
someone on them who should not be - 2. not putting someone
on them who
really
should be. Avoiding '1' is a matter of discipline and a
thick skin. Avoiding
'2'
is a matter of being totally independent from all
pressures surrounding you.
Avoiding '2' has become increasingly difficult, and we'd
rather stop with
our
integrity fully intact and our reputation unharmed. That
is about now. Well,
next week.
We?
- Yes, dropping that habit will take some time ;)
Will you be back?
- Probably. Lurking.
Will you miss us?
- Depends on how well target practice goes.
Should we give up The Good Fight?
- Hell no, we're winning. There's plenty of enthusiasm,
and there are plenty
of
new and old blacklists doing fine work. Take your pick.
Keep fighting. Fight
for
your spam laws. Educate. Annoy. Sue if you must. It's up
to you now.
Is there anything we can do?
- Yes. Spread the word, please. Post to your
local/national abuse groups,
inform
anyone you know who uses these lists, update your
configurations. Nothing
will
break after Dec 1, but there will come a day when these
names (including the
old
Wirehub ones, which still resolve) will cease to resolve.
This will probably
be
announced.
Will the lists be back under a different name?
- Probably not. It started out as 'doing some extra work
to stop spam',
because
.. well .. FreeBSD and such, plenty of time left. And why
not donate that
work
to the Internet community as well. In the long run. it
turned out to be
'getting
some sleep and maybe something to eat between emails and
zone updates'.
Sometimes, enough is just enough.
Can't you just maintain one or two of the lists?
- What did I just say?
I have a question!
- The email address will probably work throughout
December. It may drop dead
after that. Hope I won't.
Goodbye all. It was invigorating, it was fun, it was
necessary. Don't give
up.
Ben.
--
easynet.nl abuse handling dept. --
abuse@abuse.nl.easynet.net
- blacklists/dnsbls:
http://abuse.easynet.nl/spamstats.html -
- aup: http://www.nl.easynet.net/pub/av/aup/nl (dutch) ----
--
- aup: http://www.nl.easynet.net/pub/av/aup/en (english) --
-- Tag: Restoring Only system32.exe? Tag: 40379
My system32.exe got infected with Backdoor.sdBot how can
I replace only system32.exe file?
NV 2002 wont clean it even with new av defs files.
>-----Original Message-----
>My system32.exe got infected with Backdoor.sdBot how can
>I replace only system32.exe file?
>
>NV 2002 wont clean it even with new av defs files.
>.
>