Friday, June 29, 2012

ZeroAccess rootkit malware


* Try using Hitman pro (link top of page), or use one of the rootkit removers (link top of page) 


If none of those tools works then try the following

----------------------
SophosLabs has been monitoring a new strain of the infamous ZeroAccess rootkit that has been hitting the internet over the last few weeks.
ZeroAccess is a sophisticated kernel-mode rootkit that enslaves victim PCs, adding them to a peer-to-peer botnet from which they receive commands to download other malware. The rootkit has undergone several revisions since its inception but this new version represents a major shift in strategy.
All previous versions have employed a kernel-mode component on 32-bit Windows. However, under 64-bit Windows there was no kernel-mode component - ZeroAccess operated entirely in user-mode memory.
And operating entirely in user-mode is exactly the shift in strategy that this new version employs.
ZeroAccess no longer has any kernel-mode component. Instead, a DLL is loaded into services.exe and explorer.exe and all functionality is performed inside those processes.
The previous generation of ZeroAccess would maintain reboot persistence by overwriting a Windows driver. This version uses the registry to ensure it will start again at the next boot.
ZeroAccess will create two files on an infected machine, either of which can launch the Trojan:
%WINDOWS%\installer\{GUID}\n
%profile%\local settings\application data\{GUID}\n
These two files are launched through the registry by hijacking an existing COM object and by abusing the load order of user COM objects under Windows.
The first file is launched by hijacking a COM object associated with WMI. The following registry entry is changed so that the malicious ZeroAccess DLL is loaded in place of the legitimate wbemess.dll:
HKCR\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32
Correct value:
%systemroot%\system32\wbem\wbemess.dll
Hijacked value:
\\.\globalroot\systemroot\Installer\{e051c979-bddd-5d1f-8953-4b8c940e9b4d}\n.
The second file is launched by creating the following COM object:
HKCU\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}
This object points to the file at:
%profile%\local settings\application data\{GUID}\n
This will ensure that the DLL is loaded because a legitimate COM object exists at:
HKCR\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}
This COM object belongs to MruPidlList which will load shell32.dll on Windows 7 and shdocvm.dll on Windows XP.
Because the COM object that ZeroAccess creates is a user object, Windows will load it before the legitimate object located in the registry under HKCR. The real benefit of this approach is that it will work under both 32 and 64-bit versions of Windows.
The peer-to-peer protocol used by the ZeroAccess botnet has also changed. Previously all communications were RC4 encrypted using a fixed key. That has now changed. The main encryption algorithm used is now much simpler, DWORD XOR is applied with a key that is adjusted on each round:
rol loop
The actual commands involved in the protocol have been slightly modified too.
The previous version would start by issuing a 'getL' command to each peer contained in its bootstrap file of peers. The command is issued over TCP and usually to one of ports 22292, 34354, 34355, 21810.
The remote machine would then respond with a 'retL' command that contained its own list of peers and a listing of files that the bot has downloaded. The new bot would then check the list of files and download any new files by issuing a 'getF' command. These files are signed with a 512 bit RSA key:
old filer
The new version also starts by issuing a 'getL' command. But this time the command is sent out over UDP, the port numbers being used are different and the structure of the command header has changed.
The remote peer still sends back a 'retL' command, this time over UDP and this time the file information is accompanied by a signature produced by a new 1024 bit RSA key. Now, instead of sending a 'getF' command to the remote peer to retrieve files the local peer doesn't already have, the peer simply sends the encrypted file information (filename, length and timestamp value) to the remote peer over TCP on the same port number that the UDP communication took place.
The remote peer then sends back the file encrypted with RC4 and a key derived from the file information:
new filer
This new version of ZeroAccess is being aggressively distributed through the normal mechanisms - drive by downloads, fake keygens, fake game downloads, and new samples of the old variant have all but dried up.
It's clear that the malware's authors have decided on a more unified approach to supported platforms and to change the footprint of ZeroAccess both on infected machines and on infected networks.
This is most likely due to the increased attention that this malware family has been receiving from security companies, but also as more and more people are using 64-bit machines it makes sense for malware authors to focus on that platform, so maintaining a complicated kernel-mode component that only works on 32-bit systems seems less and less cost effective.
The goal of ZeroAccess remains the same: to download further malware onto the infected machine. The types of malware we are seeing downloaded are broadly the same: click fraud and spam bots, although a BitCoin miner has now been added to the mix.
SophosLabs will continue to monitor this threat and protect our customers. For more background information on ZeroAccess, be sure to read the technical paper we published earlier this year.


Wednesday, June 27, 2012

Adobe Reader crashing when trying to print

Error "App Crash"


Common with adobe reader version 10.1.2


Solution:
  1.  Uninstall adobe reader
  2. Install new version from adobe's website found at: http://get.adobe.com/reader/


Error Message "This file does not have a program associated with it. For performing this action create an association in the folder options control panel"

This error message happens when using windows live mail or outlook and you click on a link in an email.


Solution:

1. Start > Control Panel > Programs > Default Program
2. Click on "Set your default program"




3. Choose your current browser, in which you want the weblinks to open.

4. Click on "Set this program as default" if your current browser is not a default one yet.
            Then click on the " Choose defaults for this program "







5. In this window - ensure all the extensions are selected & then click on "Select All' checkbox.
6. Click on Save & OK.





7. Close your Email  Application & reopen to check if your links work.


Tuesday, June 26, 2012

Black dot or blob after pasting an item in word, excel, power point

This is caused by a defective Bluetooth add-in for Word, Excel, and PowerPoint


  1. Click on "start menu"
  2. type winword
  3. Right click and select "run as admin"
  4. Click on the Microsoft button at the top left
  5. Click on Word Options
  6. Select Add-ins on the left column
  7. At the bottom drop box select Manage: COM Add-ins
  8. Press Go
  9. Untick/Uncheck "send to bluetooth"
  10. Press Ok


Thursday, June 21, 2012

Error Code 0x80070424 with Windows Firewall and "Base Filtering Engine Service" Not available in services database list.


Symptom:
The error message "Windows Firewall can't change some of your settings. Error code 0x80070424" will pop up when you try to change the Windows Firewall settings. In the meantime, when you restart the system, it might pop up an error saying that "Base Filtering Engine Service" could not be found in the system.
Please note that the same error code could pop up when you try doing anything in Windows Defender.


Microsoft Fix it tool for this issue http://support.microsoft.com/kb/968002

Resolution:
Download the registry files (You can also export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE from another working Win7 PC)


1055.BFE.reg
Launch and import them to registry

Restart your PC

Now,open RUN and type regedit and click ok

go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE

Right click on it-permissions

Click on ADD and type Everyone and click ok

Now Click on Everyone

Below you have permission for users

Select full control and click ok

Now,open RUN and type services.msc and click ok

start base filtering engine service and then windows firewall service 



source:http://blogs.technet.com/b/asiasupp/archive/2011/12/27/error-code-0x80070424-with-windows-firewall-and-quot-base-filtering-engine-service-quot-not-available-in-services-database-list.aspx

Wednesday, June 20, 2012

Auto Play not working - Windows 7

First
1. check Control Panel > Programs > Default Programs > Change AutoPlay Settings


2. Make sure that you have the box checked for "use AutoPlay for all media and devices" is ticked (enabled)


3. Click reset to default at the bottom of the page


4. Reboot PC


****If that doesn't fix it try this:


  1. Type service.msc in start search to run services console
    1. locate Sell Hardware Detection 
      1. ensure that the "service status" is Running
      2. "startup type" is Automatic
  2. Type regedit.exe in start search to run registry console
  3. Find: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services|cdrom
    1. Locate the AutoRun registry value
      1. Right click
      2. Select modify
      3. Change value to 1
  4. Find: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    1. Locate the NoDriveTypeAutoRun registry value
      1. right click
      2. select modify
      3. change value to 0 (zero)
  5. Close everything
  6. Reboot PC
  7. AutoPlay should be working now

source: http://www.mydigitallife.info/fix-windows-7-autoplay-dialog-box-missing-or-not-appear-display-and-pop-up/

Friday, June 15, 2012

Green bar across online videos (youtube)

1. Right Click on the Video, select Settings


image


2. Uncheck the box for "enable hardware acceleration"


image


3. close and refresh video




sourcehttp://markparris.co.uk/2012/04/07/youtube-displaying-a-green-bar-across-the-top/

Wednesday, June 13, 2012

CD / DVD Drive not showing up in the "my computer" folder

1. Close all open programs 
2. Click on Start, Run, and type REGEDIT and press Enter 
3. Click on the plus signs (+) next to the following folders: 

HKEY_LOCAL_MACHINE \SYSTEM \CurrentControlSet \Control \Class \{4D36E965-E325-11CE-BFC1-08002BE10318} 

4. This folder is the DVD/CD-ROM Drive Class Description in the registry. Look for any of the following names in the right hand column. 

5. Delete:

UpperFilters 
LowerFilters 
UpperFilters.bak 
LowerFilters.bak 


5. After deleting the keys, close the Registry Editor 
6. Reboot your computer 
7. Open My Computer and check to see if your CD or DVD drives have returned. You may also want to open Device Manager and verify that the yellow exclamation and error code on the CD or DVD drive is gone. Also, be sure to check under Computer to make sure the CD/DVD drive is visible. 



source: http://en.kioskea.net/forum/affich-51093-computer-can-not-show-the-cd-dvd-rom-drive-e

Monday, June 11, 2012

Fixes for Outlook not starting up

There are several things that you can do, follow the link to find solution to the following problems:


  • Open outlook in Safe Mode
  • Reset dat-files
  • Error message "Can't open the Outlook Window"
  • Disabling add-ins
  • Using scanpst.exe to fix outlook data file errors
  • Recreate your mail profile
  • Run a repair, office diagnostics

go to this link: http://www.howto-outlook.com/faq/outlookdoesntstart.htm


Flash-Killer or "kill-bit"


Microsoft has a method to easily disable certain ActiveX controls, using a "kill-bit".  It is documented at http://support.microsoft.com/kb/240797

The "kill-bit" for Flash Player is documented in http://kb2.adobe.com/cps/190/tn_19091.html


What does that mean?

Flash  Player may not be working on Internet Explorer, and the 'Shockwave  Flash Object' add-on may not show up at all.  Most likely because the FP  ActiveX has been "kill-bited" by some anti-malware app.


How to check and remove the "kill-bit"?

WARNING!   Fiddling with the Windows Registry may render Windows or installed  components unusable.  Always make a registry backup or a System Restore  Point before attempting to manually change anything in the registry!

  • open the registry editor: Start | Run | type regedit.exe
  • navigate to this registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}
  • if that key does not exist, then the "kill-bit" for Flash Player is not set
  • if it contains a DWORD entry with the name Compatibility Flags that has any value other than 0x00000000, then the "kill-bit" for Flash Player may be set
  • to remove the "kill-bit" do any of the following
    • change the value from 0x00000400 to 0x00000000 (right-click | Modify | change value data to 0)
    • or  delete the registry key (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet  Explorer\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000})  completely
  • close the registry editor when done


Error 1402 "Setup Can't Open Registry Key" during Microsoft Office 2010 install



This error is only shown when registry keys do not have Administrator permission. But you are logged in as Administrator, right? As it happens some setup can mess up the registry permissions and Office 2010 installer is no exception.
Entering the following line in Command Prompt will fix the problem for most people,

secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose
but it didn’t work for me. If it doesn’t work for you as well, follow the second method below.
1. Download SubInAcl, a command line tool from Microsoft that enables administrators to obtain security information about files, registry keys services, etc. <> It will install to Program Files folder, copy SUBINACL.EXE file to /Windows/System 32 folder.

2. Link for SubInAcl - click here

3. Now create a new notepad and paste the following code in it;

subinacl /subkeyreg HKEY_LOCAL_MACHINE /setowner=administrators
subinacl /subkeyreg HKEY_CURRENT_USER /setowner=administrators
subinacl /subkeyreg HKEY_CLASSES_ROOT /setowner=administrators
subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
cls
Exit

4. Rename the notepad to reset and change the extension to cmd, the complete name will become “reset.cmd” as shown in the screenshot below. Run this file as administrator.
reset cmd
5. The process will now take several minutes, do NOT close the Window. Once the process is complete, the command line window will automatically close and you can then install Office 2010 successfully.



Error "user profile service failed the logon. User profile can't be loaded"


Other methods found at: http://support.microsoft.com/kb/947215


Method 1 below:


To fix the user account profile, follow these steps: 


Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:How to back up and restore the registry in Windows
  1. Click Start, type regedit in the Search box, and then press ENTER.
  1. In Registry Editor, locate and then click the following registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
  1. In the navigation pane, locate the folder that begins with S-1-5 (SID key) followed by a long number.
  1. Click each S-1-5 folder, locate the ProfileImagePath entry in the details pane, and then double-click to make sure that this is the user account profile that has the error.

  • If you have two folders starting with S-1-5 followed by some long numbers and one of them ended with .bak, you have to rename the .bak folder. To do this, follow these steps:
  1. Right-click the folder without .bak, and then click Rename. Type .ba, and then press ENTER.

  1. Right-click the folder that is named .bak, and then click Rename. Remove .bak at the end of the folder name, and then press ENTER.

  1. Right-click the folder that is named .ba, and then click Rename. Change the .ba to.bak at the end of the folder name, and then press ENTER.

  • If you have only one folder starting with S-1-5 that is followed by long numbers and ends with .bak. Right-click the folder, and then click Rename. Remove .bak at the end of the folder name, and then press ENTER.
  • If you have two folders starting with S-1-5 followed by some long numbers and one of them ended with .bak, you have to rename the .bak folder. To do this, follow these steps:
  1. Right-click the folder without .bak, and then click Rename. Type .ba, and then press ENTER.

  1. Right-click the folder that is named .bak, and then click Rename. Remove .bak at the end of the folder name, and then press ENTER.

  1. Right-click the folder that is named .ba, and then click Rename. Change the .ba to.bak at the end of the folder name, and then press ENTER.

  • If you have only one folder starting with S-1-5 that is followed by long numbers and ends with .bak. Right-click the folder, and then click Rename. Remove .bak at the end of the folder name, and then press ENTER.
  1. Double-click the folder without .bak in the details pane, double-click RefCount, type 0, and then click OK.

  1. Click the folder without .bak, in the details pane, double-click State, type 0, and then click OK.

  1. Close Registry Editor.
  1. Restart the computer.
  1. Log on again with your account.




source: http://support.microsoft.com/kb/947215

Computer connecting automatically to a wireless network called "NativeWIFI Default Profile"


1. Go to msconfig

2. Uncheck the netgear adapter on the services and start-up tab

3. Deleted "NativeWIFI Default Profile" from "manage wireless networks" list

4. Reboot PC

source: http://forum1.netgear.com/showthread.php?t=57148

Computer not waking up after going into sleep mode



1. Control Panel > Hardware and sound > power options

2. Click on "change plan settings" for your current default plan

3. Click on "change advanced power settings"

4. Select Sleep > under Allow hybrid sleep > select off


source: http://www.tomshardware.com/forum/303052-31-wake-sleep

Wednesday, June 6, 2012

Email Server Settings

                        always check SMTP requires authentication
                         - email settings in alphabetical order

*some server requires the whole email address in the "email username" area

AOL server settings:
  • Incoming  - imap.aol.com  | port - 143 or  993 SSL
  • Outgoing  - smtp.aol.com  | port - 587 TLS
------------------------------------------------------------------
ATT, SbcGlobal and BellSouth server settings:
  • Incoming  - pop.att.yahoo.com     | port - 995 SSL
  • Outgoing  - smtp.att.yahoo.com    | port - 465 SSL

------------------------------------------------------------------
Century Link server settings:
  • Incoming  - pop.centurylink.net     | port -  995 SSL
  • Outgoing  - smtp.centurylink.net      | port -  587 (check TLS if available)

------------------------------------------------------------------
Charter server settings:
  • Incoming  - pop.charter.net     | port -  110
  • Outgoing  - smtp.charter.net    | port -  25

------------------------------------------------------------------
Comcast server settings:
  • Incoming  - mail.comcast.net    | port -  995 SSL
  • Outgoing  - smtp.comcast.net    | port -  465 SSL
------------------------------------------------------------------
Cox server settings:
  • Incoming  - pop.cox.net     | port -  995 SSL
  • Outgoing  - smtp.cox.net    | port -  465 SSL

------------------------------------------------------------------
Eatel server settings:
  • Incoming  - mail.eatel.net     | port -  110
  • Outgoing  - mail.eatel.net     | port -  587

------------------------------------------------------------------
Frontier server settings:
  • Incoming  - pop3.frontier.com     | port -  110
  • Outgoing  - smtp.frontier.com      | port -  25

------------------------------------------------------------------
Gmail server settings:
  • Incoming  - pop.gmail.com  | port -  995 SSL
  • Outgoing  - smtp.gmail.com   | port - 587 TLS
    • Logon using Secure Password Authentification
  • Incoming -  imap.gmail.com | port -  993 SSL
  • Outgoing  - smtp.gmail.com | port -  465 or 587 TLS
------------------------------------------------------------------
Hotmail and Live server settings:
  • Incoming  - pop3.live.com   | port - 995 SSL
  • Outgoing  - smtp.live.com    | port -  587 TLS
    • Logon using Secure Password Authentification
------------------------------------------------------------------
MSN server settings:
  • Incoming  - pop3.email.msn.com  | port - 110 or  995 SSL
  • Outgoing  - smtp.email.msn.com  | port - 25 or  587 TLS
    • Logon using Secure Password Authentification

------------------------------------------------------------------
Nemont server settings:
  • Incoming  - pop.nemont.net     | port -  110
  • Outgoing  - smtp.nemont.net    | port -  25

------------------------------------------------------------------
NetZero server settings:
  • Incoming  - pop.netzero.com     | port -  995 SSL
  • Outgoing  - smtp.netzero.com    | port -  465 SSL
------------------------------------------------------------------
PenTeleData (@ptd.net) server settings:
  • Incoming  - promail.ptd.net  | port - 110
  • Outgoing  - promail.ptd.net  | port - 25 or 587 TLS
------------------------------------------------------------------
OptOnline server settings:
  • Incoming  - mail.optonline.net | port - 110
  • Outgoing  - mail.optonline.net | port - 587 TLS
------------------------------------------------------------------
Road Runner server settings:

------------------------------------------------------------------
Suddenlink server settings:
  • Incoming  - pop.suddenlink.net  | port - 110
  • Outgoing  - smtp.suddenlink.net | port - 25

------------------------------------------------------------------
Verizon server settings:
  • Incoming  - incoming.verizon.net  | port -  995 SSL
  • Outgoing  - outgoing.verizon.net  | port -  465 SSL
------------------------------------------------------------------
Yahoo IMAP server settings:
     - This setting will work on computers and mobile devices without needing yahoo plus account
  • Incoming  - imap.mail.yahoo.com   | port - 993 SSL
  • Outgoing  - smtp.mail.yahoo.com   | port - 25 or 465 SSL
------------------------------------------------------------------

Source of all Email settings:


Friday, June 1, 2012

Fix Services MMC Extended View Is Blank in Windows XP


This has to do with broken JScript.dll registration. To fix this problem, login as Administrator or equivalent, and then run the following command from Start, Run dialog:
regsvr32.exe  jscript.dll
Press {ENTER}
You should see the output message "DllRegisterServer in jscript.dll succeeded."
This fixes the Extended view. Close and re-open Services MMC.