<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Tech Support Journal</title>
	<link>http://techsupport.specialty.be</link>
	<description>Information &#038; solutions to computer related problems.</description>
	<pubDate>Thu, 15 Jan 2009 17:08:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>
	<language>en</language>
			<item>
		<title>Internet Antivirus Pro Malware Removal</title>
		<link>http://techsupport.specialty.be/category/internet-antivirus-pro-malware-removal/</link>
		<comments>http://techsupport.specialty.be/category/internet-antivirus-pro-malware-removal/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 17:08:12 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/internet-antivirus-pro-malware-removal/</guid>
		<description><![CDATA[This is one of the variant of the original fake antivirus program XP Antivirus 2008 which has infected quite a large number of people.
This malware like it predecessors spreads typically via spam probably from the same bunch of folks trying sell enlargement stuffs, anything that can get you to reveal your credit card info.
To clear [...]]]></description>
			<content:encoded><![CDATA[<p>This is one of the variant of the original fake antivirus program <a href="http://techsupport.specialty.be/category/rogue-antivirus-program/">XP Antivirus 2008</a> which has infected quite a large number of people.</p>
<p>This malware like it predecessors spreads typically via spam probably from the same bunch of folks trying sell enlargement stuffs, anything that can get you to reveal your credit card info.</p>
<p>To clear this malware, start your PC in Safe Mode and delete the following registry entries or select the text below and save it as a file with .reg extension then open it;</p>
<p>REGEDIT4</p>
<p>[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]<br />
&#8220;iv&#8221;=-<br />
&#8220;Internet Antivirus Pro&#8221;=-</p>
<p>[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine]</p>
<p>[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ENUM\Root\LEGACY_ITGRDENGINE]</p>
<p>Delete files and folders;</p>
<p>c:\program files\Internet Antivirus Pro<br />
c:\documents and settings\{User Profile Name}\Application Data\Internet Antivirus Pro<br />
c:\documents and settings\{User Profile Name}\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe<br />
c:\documents and settings\{User Profile Name}\Local Settings\Application Data\Microsoft\Windows\services.exe</p>
<p>If you&#8217;re intending to trace the origin of the program, the config file shows the following mirror sites where updates are downloaded.</p>
<p>Mirror0=http://internetantiviruspro.com/updates/updateloadlist.ini<br />
Mirror1=http://internet-antivirus-pro.com/updates/updateloadlist.ini<br />
Mirror2=http://freewebtown.com/kvaigon/updateloadlist.ini<br />
Mirror3=http://xoomer.alice.it/gyeynon/updateloadlist.ini</p>
<p>Their related sites used primarily for stats and info gathering;</p>
<p>Url0=in4co.com<br />
Url1=in7co.com<br />
Url2=in6co.com<br />
Url3=cokiran.com<br />
Url4=cokien.com<br />
Url5=in5co.com</p>
<p>Url0=http://in4sk.com/reports/install-report.php<br />
Url1=http://in7sk.com/reports/install-report.php<br />
Url2=http://in6sk.com/reports/install-report.php<br />
Url3=http://websscan.com/reports/install-report.php<br />
Url4=http://in1sk.com/reports/install-report.php<br />
Url5=http://in5sk.com/reports/install-report.php</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/internet-antivirus-pro-malware-removal/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Recycler&#8217;s shellsrv.exe virus</title>
		<link>http://techsupport.specialty.be/category/recyclers-shellsrvexe-virus/</link>
		<comments>http://techsupport.specialty.be/category/recyclers-shellsrvexe-virus/#comments</comments>
		<pubDate>Tue, 23 Sep 2008 13:24:12 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/recyclers-shellsrvexe-virus/</guid>
		<description><![CDATA[Symantec Antivirus is unable to detect it completely while McAfee detected only the autorun.inf file that it creates as generic!.atr trojan.
Loads on startup by adding the file symlssdb.exe to startup which will run as a hidden process.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&#8220;Symantec System DB&#8221;=&#8221;symlssdb.exe&#8221;
It disables registry edit &#38; Task Manager (regedit.exe &#38; Ctrl-Alt-Del won&#8217;t work), prevents Run command and CMD [...]]]></description>
			<content:encoded><![CDATA[<p>Symantec Antivirus is unable to detect it completely while McAfee detected only the autorun.inf file that it creates as generic!.atr trojan.</p>
<p>Loads on startup by adding the file symlssdb.exe to startup which will run as a hidden process.</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
&#8220;Symantec System DB&#8221;=&#8221;symlssdb.exe&#8221;</p>
<p>It disables registry edit &amp; Task Manager (regedit.exe &amp; Ctrl-Alt-Del won&#8217;t work), prevents Run command and CMD command prompt from running.  It will also prevent malware removal tools like Combofix, Hijackthis, KillBox from running.  To run any of these tools, rename them to a different filenames.</p>
<p>On more seriously infected systems, it will also auto-generates porn-related url links on the desktop &amp; attempts to run it at random.</p>
<p>It will also infect removal drives by adding autorun.inf and shellsrv.exe into the Recycler folder.  It may also generate/replace hosts file found in c:\windows\system32\drivers\etc with one that consists mainly of antivirus software vendors&#8217; domains pointing them to an invalid loopback address of 127.0.0.1.</p>
<p>Downloading <a href="http://www.bleepingcomputer.com/files/killbox.php" title="Killbox" target="_blank">Killbox</a> &amp; deleting the process c:\windows\system32\symlssdb.exe on restart may be the only course of action that you need to take. Rename it to kb.exe after download before running it.</p>
<p>To restore registry editing, download <a href="http://securityresponse.symantec.com/avcenter/UnHookExec.inf" title="UnHookExec.inf">unhookexec.inf</a> from Symantec&#8217;s web site, save to desktop then right click and install it.</p>
<p>While at it, might as well open up the file with notepad &amp; add the following lines &amp; save before installing it so that Task Manager, CMD &amp; Run can be restored as well.</p>
<p>HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD,65537,0<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr,65537,0<br />
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoRun,65537,0</p>
<p>If you do not want to make changes to that file, run regedit after that,  browse to [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System], enable registry editing tool and task manager by changing the values for the corresponding entries.</p>
<p>On some badly infected system, you may need to download and run <a href="http://techsupport.specialty.be/category/backdoorpaproxy-trojanvirantixc-trojanwsnpoem/" title="Combofix">Combofix</a> which cleans it up easily.</p>
<p>Files associated with this infection;</p>
<p>C:\WINDOWS\onfwbsak.dll<br />
C:\WINDOWS\rwlfsdmk.dll<br />
C:\WINDOWS\eofn.exe<br />
C:\WINDOWS\dfmlxbpkexw.dll<br />
C:\WINDOWS\peltodgx.dll<br />
C:\WINDOWS\faceback.exe<br />
C:\WINDOWS\system32\symlssdb.exe<br />
C:\WINDOWS\system32\winupdate.exe<br />
C:\WINDOWS\system32\tdssservers.dat<br />
C:\WINDOWS\system32\tdssl.dll<br />
C:\WINDOWS\system32\tdssmain.dll<br />
C:\WINDOWS\system32\tdsslog.dll<br />
C:\WINDOWS\system32\tdssadw.dll<br />
C:\WINDOWS\system32\tdssinit.dll<br />
C:\WINDOWS\system32\tdssserf.dll<br />
C:\WINDOWS\system32\wscmp.dll<br />
C:\WINDOWS\system32\sex1.ico<br />
C:\WINDOWS\system32\sex2.ico<br />
C:\WINDOWS\system32\sex3.ico<br />
C:\Documents and Settings\User\Desktop\BDSM galleries.URL</p>
<p>If there are traces of tdss*.dll files,  a server service tdsserv.sys will also be running that requires to be removed.  This file is located in C:\Windows\system32\drivers folder and in registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSServ,  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet*\Services\TDSServ &amp; HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tdssserv. Permission for the key TDSServ needs to be taken over before it can be deleted.</p>
<p>Deletion can only be done in Safe Mode or via remote registry editing.</p>
<p>This trojan will also install a copy of mxlivemedia ad program which needs to be uninstalled via Add/Remove program. Unfortunately, I cannot remember the exact name of the program but it starts with Ron.</p>
<p>There seems to be many fake antivirus and antispyware malwares related to this virus like Antivirus2009 which comes with AntiSpywareShield, SAV and Seekmo, all installed after tdssserv.sys service is started on an infected PC.  Like all its other variants, this malware name its program files similiar to legit programs (SAV, etc) to avoid deletion and primarily serves porn on infected PCs.</p>
<p>It also adds schedule tasks to run some random file to load itself so that if it has higher chance of surviving removal attempts.</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/recyclers-shellsrvexe-virus/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Planex Mini100s Print Server with Vista</title>
		<link>http://techsupport.specialty.be/category/planex-mini100s-print-server-with-vista/</link>
		<comments>http://techsupport.specialty.be/category/planex-mini100s-print-server-with-vista/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 12:07:19 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Configuration]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/planex-mini100s-print-server-with-vista/</guid>
		<description><![CDATA[The currently utility that comes with this printer server doesn&#8217;t work. When you try to install PS Port or Network Print Port, Windows Vista doesn&#8217;t run and the port can&#8217;t be added, even after disabling User Account Control.
Using TCP/IP with printer server detected as Generic Card,  printing failed. The workaround is selecting Network Printer, using [...]]]></description>
			<content:encoded><![CDATA[<p>The currently utility that comes with this printer server doesn&#8217;t work. When you try to install PS Port or Network Print Port, Windows Vista doesn&#8217;t run and the port can&#8217;t be added, even after disabling User Account Control.</p>
<p>Using TCP/IP with printer server detected as Generic Card,  printing failed. The workaround is selecting Network Printer, using Internet Port http then type the ip address of the printer follow by queue name of lp1. e.g. http://192.168.1.250/lp1</p>
<p>This works with various printer models like Canon and HP.</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/planex-mini100s-print-server-with-vista/feed/</wfw:commentRss>
		</item>
		<item>
		<title>FlWin EKWin GmWin AVTAPIT.DLL Trojan</title>
		<link>http://techsupport.specialty.be/category/flwin-ekwin-gmwin-avtapitdll-trojan/</link>
		<comments>http://techsupport.specialty.be/category/flwin-ekwin-gmwin-avtapitdll-trojan/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 14:57:36 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/flwin-ekwin-gmwin-avtapitdll-trojan/</guid>
		<description><![CDATA[This trojan and its bunch of services trashed a user&#8217;s PC leaving it with no network connections and a long list of failed system services that can&#8217;t startup properly. Any attempt to restart any of those services returns a &#8220;The executable program that this service is configured to run in does not implement the service.&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>This trojan and its bunch of services trashed a user&#8217;s PC leaving it with no network connections and a long list of failed system services that can&#8217;t startup properly. Any attempt to restart any of those services returns a &#8220;The executable program that this service is configured to run in does not implement the service.&#8221; error.</p>
<p>Combofix only managed to clear some of the problems but the major problem of having a kernel-level rootkit in the system was undetectable by it. None of the rootkit removal tools I ran, Microsoft Malicious Software Removal Tool,  gromozon, hookanlz &amp;  haxfix, were able to detect it. File Secure Blacklight was aborted midway because the scanning process took too long.</p>
<p>To remove all traces of this trojan, you will to boot up either using Bartpe from your  CDROM Drive and run regedit from it or attached the infected system&#8217;s hard drive to another clean system as a secondary drive and then run regedit.</p>
<p>If your disk drive is SATA type, you will have to disable AHCI in the system BIOS when booting from BartPE and then re-enabling it back once you&#8217;re done. (Otherwise you will get a prompt to do a scandisk)</p>
<p>Load the infected systems&#8217; registry hive by browsing to the infected drive&#8217;s Windows\system32\config folder and load the file with the filename System into regedit&#8217;s  HKEY_USERS (or any of the root keys if you can remember where you place it) and then give it a random name.</p>
<p>Locate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00*\Services, where * represents whatever the digits you see in the infected system&#8217;s registry, and remove the following services by right clicking and selecting delete.</p>
<p>Some of the registry entries may be set to read-only and in order to delete it, it has to be set to Full-Control. This can be done by right-clicking and selecting Permission and  then put a check on the box beside Full-Control.</p>
<p>Services to delete on all variation of ControlSets in the registry;</p>
<p>43vpkuodh, 6to4, Ekwin, FlWin, GmWin, iprip, Irmon, P0LICYAGENT (Note: the zero in place of O in POLICYAGENT), ProtectedStorager4, RIP, RpcUsnsvc, u6qkchfua5</p>
<p>Delete the following files on the infected system;</p>
<p><u><strong>Windows folder</strong></u></p>
<p>soni.exe (Downloader)<br />
RavNT.exe (Trojan Horse)<br />
iasxin.dll (Trojan.Zlob)<br />
360safe.exe (Downloader)<br />
17533.exe (Downloader)<br />
iexplore.exe (Infostealer)<br />
ThunderAtone.dll (Trojan.Adclicker)<br />
39.exe<br />
icpb.dll (trojan service name: iprip, Win32 Service that loads using svchost process)<br />
usnsvc.exe (trojan service name: RpcUsnsvc, Loads as a stand-alone Win32 service on startup)</p>
<p><u><strong>Windows\system32 folder</strong></u></p>
<p>ggcg.exe (Backdoor.Graybird)<br />
telem32.dll (Downloader)<br />
usmsvc.exe<br />
usmsho.dll<br />
ThunderBHONew11.dll (not sure if this is from the same &#8216;vendor&#8217; or from other infections)<br />
ThunderBHONew12.dll (not sure if this is from the same &#8216;vendor&#8217; or from other infections)<br />
msn.exe<br />
UUSee_heima_Setup_110253.exe<br />
dlbar.exe (Backdoor.Trojan)<br />
msn.exe<br />
dcb.dll<br />
imsins.ini<br />
yoyo1048.exe<br />
wv.dat<br />
winxp1.exe<br />
winxp2.exe (Downloader)<br />
kmss.dat<br />
irmon64.dll (trojan service name: Irmon, Win32 Service that loads using svchost process)<br />
AVTAPIT.DLL (trojan service name: FlWin, GmWin, Ekwin, Win32 Service that loads using svchost process)<br />
6to4.dll (trojan service name: 6to4, Win32 Service that loads using svchost process)<br />
cb22b.exe (trojan service name: P0LICYAGENT, Loads as a service on startup)</p>
<p><u><strong>Windows\system32\Com\1.1.5</strong></u></p>
<p>WndHook.dll</p>
<p><u><strong>Windows\system32\drivers</strong></u></p>
<p>u6qkchfua5.sys (trojan service name: u6qkchfua5, kernel-mode driver that loads on booting up, detect as Trojan.Farfli)<br />
43vpkuodh.sys (trojan service name: 43vpkuodh, kernel-mode driver that loads on booting up, detect as Trojan.Farfli)</p>
<p><u><strong>Windows\system32\config</strong></u></p>
<p>sam5.log (trojan service name: ProtectedStorager4, Win32 Service that loads using svchost process)</p>
<p><u><strong>Documents And Settings\*User Profile*\Local Settings\Temp\</strong></u></p>
<p>RIP.exe (trojan service name: RIP, Loads as a service on startup)</p>
<p>Once done with deleting the files, export the Svchost key from HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost as on a clean system with similar operating system as a .reg file and then import it into the problematic PC. Reboot it and all the services should start without any problem.</p>
<p><a href="http://techsupport.specialty.be/wp-content/uploads/2008/07/svchost.jpg" title="Svchost key"><img src="http://techsupport.specialty.be/wp-content/uploads/2008/07/svchost.jpg" alt="Svchost key" /></a></p>
<p><a href="http://techsupport.specialty.be/wp-content/uploads/2008/07/exportkey.jpg" title="Export the full key"><br />
</a><br />
<a href="http://click.linksynergy.com/fs-bin/click?id=fKas*VYbQDc&amp;offerid=144797.10000085&amp;type=3&amp;subid=0" onmouseout="window.status=' ';return true;" onmouseover="window.status='http://www.mcafee.com';return true;" rel="nofollow">Eliminate viruses and spyware with McAfee VirusScan.</a><img src="http://ad.linksynergy.com/fs-bin/show?id=fKas*VYbQDc&amp;bids=144797.10000085&amp;type=3&amp;subid=0" border="0" height="1" width="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/flwin-ekwin-gmwin-avtapitdll-trojan/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Rogue Antivirus Program</title>
		<link>http://techsupport.specialty.be/category/rogue-antivirus-program/</link>
		<comments>http://techsupport.specialty.be/category/rogue-antivirus-program/#comments</comments>
		<pubDate>Sun, 27 Jul 2008 04:57:39 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/rogue-antivirus-program/</guid>
		<description><![CDATA[XP Antivirus 2008 is a malware program that imitates legit antivirus program by installing itself as a startup process and then place the following wallpaper to entice its victims to register their antivirus software to remove the prompts that it constantly generates.

They also install a copy of Mark Russinovich&#8217;s BSOD Screen Saver which will simulate [...]]]></description>
			<content:encoded><![CDATA[<p>XP Antivirus 2008 is a malware program that imitates legit antivirus program by installing itself as a startup process and then place the following wallpaper to entice its victims to register their antivirus software to remove the prompts that it constantly generates.</p>
<p><a href="http://techsupport.specialty.be/wp-content/uploads/2008/07/warning.jpg" title="XP Antivirus 2008"><img src="http://techsupport.specialty.be/wp-content/uploads/2008/07/warning.jpg" alt="XP Antivirus 2008" /></a></p>
<p>They also install a copy of Mark Russinovich&#8217;s BSOD Screen Saver which will simulate a PC crash and restart with the following random error messages.</p>
<p>BOGUS_DRIVER<br />
IRQL_NOT_LESS_OR_EQUAL<br />
BAD_POOL_HEADER<br />
SYSINTERNAL_GREAT_SITE<br />
KMODE_EXECPTION_NOT_HANDLED<br />
PAGE_FAULT_IN_NONEPAGE_AREA<br />
UNEXPECTED_KERNAL_MODE_TRAP<br />
PANIC_STACK_SWITCH<br />
NO_MORE_IRP_STACK_LOCATIONS<br />
MAXIMUM_WAIT_OBJECTS_EXCEEDED</p>
<p>Files that the program loads on an infected system;</p>
<p>in C:\Windows\system32</p>
<p>blphc7v6i0e5f7.exe,blphc7v6i0e5f7.scr,<br />
phc7v6j0e5f7.exe,lphcr7pj0e3d3.exe</p>
<p>in C:\Windows</p>
<p>winlogon.exe</p>
<p>in C:\Documents and Settings\{your user profile}\Local Settings\temp\</p>
<p>.tt3.tmp.vbs</p>
<p>The file names may varies with their new improved versions, but the containment of this malware is relatively easy.</p>
<p>By deleting the .vbs files found in  C:\Documents and Settings\* user profile * \Local Settings\temp\ in safe mode, the software will be crippled.</p>
<p>You may then run regedit to delete those entries similiar to the above in</p>
<p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</p>
<p>and</p>
<p>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</p>
<p>if there are entries of it within.</p>
<p>You will also need to enable &#8220;show hidden files and folders&#8221; in your Folder Options in order to see Local Settings in your local profile.</p>
<p><a href="http://click.linksynergy.com/fs-bin/click?id=fKas*VYbQDc&amp;offerid=144797.10000085&amp;type=3&amp;subid=0" onmouseout="window.status=' ';return true;" onmouseover="window.status='http://www.mcafee.com';return true;" rel="nofollow">Eliminate viruses and spyware with McAfee VirusScan.</a><img src="http://ad.linksynergy.com/fs-bin/show?id=fKas*VYbQDc&amp;bids=144797.10000085&amp;type=3&amp;subid=0" border="0" height="1" width="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/rogue-antivirus-program/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bugcheck 0&#215;0000001e Error</title>
		<link>http://techsupport.specialty.be/category/bugcheck-0x0000001e-error/</link>
		<comments>http://techsupport.specialty.be/category/bugcheck-0x0000001e-error/#comments</comments>
		<pubDate>Sun, 27 Jul 2008 04:06:05 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/category/bugcheck-0x0000001e-error/</guid>
		<description><![CDATA[Server that is running as Domain Controller and also as a mail server keeps restarting by itself at random. Suspected it to be a RAM related issue.
Replace the RAM but doesn&#8217;t seems to help. Try different slots, different combination of new 512MB with existing 512MB, then with existing 256MB then again without both the old [...]]]></description>
			<content:encoded><![CDATA[<p>Server that is running as Domain Controller and also as a mail server keeps restarting by itself at random. Suspected it to be a RAM related issue.</p>
<p>Replace the RAM but doesn&#8217;t seems to help. Try different slots, different combination of new 512MB with existing 512MB, then with existing 256MB then again without both the old memory modules, still not luck.</p>
<p>No difference whatever, whichever way I try. Notice errors showing unable to run .NET Framework or something, so decided to install .NET Framework again but I only realised that I have installed 2.0 instead only after I have started the installation.</p>
<p>Midway through the installation, there was a prompt that says that the previous .NET 1.1 was suspended, click OK to undo suspended installation and continued with installation of the 2.0 version.</p>
<p>At the same time also notice alot of strange looking services in the Services panel. Although they&#8217;re not running, their startup type were all set to start automatically.</p>
<p>Did a search on it and realise almost all of it are some sort of rootkit or malware, e.g. GrayPigeonServer which runs G_SERVER.EXE in Windows folder, QQ1 which runs QQMY.EXE in the same location or system32 location can remember exact, Socks5 Slave which runs in Windows folder under a subfolder COM\Services.exe which I am quite sure it is a form of socks server installation for proxying a connection to another location.</p>
<p>All of them are removed from HKLM\SYSTEM\CurrentControlSet\Service but there are also similiar entries under ENUM\ROOT which I am unable to remove. Initial I thought that it was due to it be referenced in a running service.</p>
<p>I restarted the server into Safe Mode and try to delete it from there but was also unable to. Did some research and realised that I need to add my rights to the registry keys before I could delete it. Remembered that to admend rights on registry, I will to run regedt32.exe instead of regedit.exe. Started it, add administrators with full access to the key, apply and then delete all of the references.</p>
<p>Also, stop all vulnerable processes like IIS, IISAdmin, FTP, WebAdmin for Mdaemon then disabled all of them. I also ran some addition tools like DeepMonitor and Killbox but I cannot remember the exact processes that I terminated.</p>
<p>How the server got infected, I have no idea as I am not the only administrator managing it.</p>
<p>Fortunately, it was at an early stage of infection and the server managed to boot up ok after that.</p>
<p><a href="http://click.linksynergy.com/fs-bin/click?id=fKas*VYbQDc&#038;offerid=144797.10000085&#038;type=3&#038;subid=0" onmouseout="window.status=' ';return true;" onmouseover="window.status='http://www.mcafee.com';return true;" rel="nofollow">Eliminate viruses and spyware with McAfee VirusScan.</a><img src="http://ad.linksynergy.com/fs-bin/show?id=fKas*VYbQDc&#038;bids=144797.10000085&#038;type=3&#038;subid=0" border="0" height="1" width="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/bugcheck-0x0000001e-error/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Backdoor.Paproxy, Trojan.Virantix.C, Trojan.wsnpoem</title>
		<link>http://techsupport.specialty.be/category/backdoorpaproxy-trojanvirantixc-trojanwsnpoem/</link>
		<comments>http://techsupport.specialty.be/category/backdoorpaproxy-trojanvirantixc-trojanwsnpoem/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 04:13:57 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Viruses Trojans and Malwares]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/backdoorpaproxy-trojanvirantixc-trojanwsnpoem/</guid>
		<description><![CDATA[This virus came as an email saying UPS Tracking Number 7117069933 with content that says;
Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office
Your UPS
The zipped attachment [...]]]></description>
			<content:encoded><![CDATA[<p>This virus came as an email saying UPS Tracking Number 7117069933 with content that says;</p>
<p>Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office</p>
<p>Your UPS</p>
<p>The zipped attachment is an executable file that will install a rootkit (ntos.exe) on the system. Additional files are downloaded when an Internet connection is detected and the system will force an auto restart after downloading and add some of it to startup.</p>
<p>For some strange reason, it also display a warning stating that your PC is infected with a virus. This is probably an early stage before it mutates into some sort of rogue antivirus software that requires purchase before removing of viruses.</p>
<p>It also disables any attempt to run malware removal tools like hijackthis, combofix, sdfix but it miss out smitfraudfix which doesn&#8217;t cleans it anyway. To be able to run those tools, you will need to rename them example hijackthis.exe to hjt.exe and combofix.exe to comb.exe. You will also need to terminate the virus process braviax.exe or buritos.exe depending on which is active at that time.</p>
<p>Combofix (Combo fix) can be downloaded from</p>
<p><span class="a"><a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">Usage of combofix</a></span></p>
<p><a href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe">Download Combofix</a></p>
<p>This particular tool will clean up the rootkit in your system and delete all the virus files it found. The author of the software also requires you to agree to a disclaimer (twice) before allowing you to run the tool. If you disagree, the downloaded file will be deleted and you have to re-download it again. If the file downloaded is more than 1 week old, it will also be deleted.</p>
<p>After cleaning, you will also need to disable system restore, empty your recycle bin and clear all temp files to ensure that no traces of the virus is in the system.</p>
<p>Symantec detected the virus as Backdoor.Paproxy, Trojan.Virantix.C, Trojan.wsnpoem for its various files and contrary to advice on Symantec&#8217;s site, this removal of ntos.exe won&#8217;t work even in safe mode.</p>
<p>Files associated with this virus;</p>
<p>in C:\windows\system32</p>
<p>ntos.exe, buritos.exe, braviax.exe, crypts.dll, winivstr.exe, karina.dat, delself.bat</p>
<p>It also creates a subfolder wsnpoem that contains two files audio.dll and video.dll.</p>
<p>Although tools like combofix is effective against viruses and malwares, it serves as a secondary course of action when you&#8217;re already infected, you will still need an antivirus software that will minimize such incidence from occurring.</p>
<p><a href="http://click.linksynergy.com/fs-bin/click?id=fKas*VYbQDc&amp;offerid=144797.10000085&amp;type=3&amp;subid=0" onmouseover="window.status='http://www.mcafee.com';return true;" onmouseout="window.status=' ';return true;" rel="nofollow">Eliminate viruses and spyware with McAfee VirusScan.</a><img src="http://ad.linksynergy.com/fs-bin/show?id=fKas*VYbQDc&amp;bids=144797.10000085&amp;type=3&amp;subid=0" border="0" height="1" width="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/backdoorpaproxy-trojanvirantixc-trojanwsnpoem/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ensuring Server Modules Are Running As A Service</title>
		<link>http://techsupport.specialty.be/category/ensuring-server-modules-are-running-as-a-service/</link>
		<comments>http://techsupport.specialty.be/category/ensuring-server-modules-are-running-as-a-service/#comments</comments>
		<pubDate>Sat, 22 Mar 2008 11:54:32 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Server Issues]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/ensuring-server-modules-are-running-as-a-service/</guid>
		<description><![CDATA[One of our servers is located at a data center for reliability &#38; better bandwidth. We are managing it via remote desktop. I know that this isn&#8217;t a secure method but it has been that way since years ago, there ought to be a better way to do it but our site administrators haven&#8217;t got [...]]]></description>
			<content:encoded><![CDATA[<p>One of our servers is located at a data center for reliability &amp; better bandwidth. We are managing it via remote desktop. I know that this isn&#8217;t a secure method but it has been that way since years ago, there ought to be a better way to do it but our site administrators haven&#8217;t got any idea to do it nor is too worried so far.</p>
<p>The server is also serving as the authoritative nameserver for some 30 odd domains and primary authoritative nameserver for two of it.  It is also not using the DNS server that is built-in to Windows 2000 Server but a third party software know as Simple DNS.</p>
<p>The two domains who emails are also hosted on this server seems to have problem receiving mails.  Upon checking, we realise that the zone information for these two domains are not available. When we query direct, we also get no response but when we log on to the server, the DNS server was running fine.</p>
<p>We  also realise that the zone information is available when we log on and finally realise that Simple DNS was not set to run as a service which it was previously. By enabling it, all zone information propagated properly soon after.</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/ensuring-server-modules-are-running-as-a-service/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Problem Connecting To Wireless Network</title>
		<link>http://techsupport.specialty.be/category/problem-connecting-to-wireless-network/</link>
		<comments>http://techsupport.specialty.be/category/problem-connecting-to-wireless-network/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 14:23:09 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Configuration]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/problem-connecting-to-wireless-network/</guid>
		<description><![CDATA[Much of the pains in troubleshooting connectivity are usually brought about by being too careful and installing more than what is sufficient.
A call that we have attended to was for a newly purchased Acer notebook was having problem connecting to the company&#8217;s wireless network.
Although the basic troubleshooting measures like releasing and renewing of IP, ensuring [...]]]></description>
			<content:encoded><![CDATA[<p>Much of the pains in troubleshooting connectivity are usually brought about by being too careful and installing more than what is sufficient.</p>
<p>A call that we have attended to was for a newly purchased Acer notebook was having problem connecting to the company&#8217;s wireless network.</p>
<p>Although the basic troubleshooting measures like releasing and renewing of IP, ensuring that the WEP keys and settings were correct has already been done the user is still unable to connect to his company&#8217;s network.</p>
<p>The notebook would be able to connect to the wireless network for a few seconds then it would be disconnected.</p>
<p>After going through the network settings, it seems Intel® PROSet/Wireless Network Connection Software has been disabled and Windows Wireless Zero Configuration are being used in place of it.</p>
<p>In the Network Connections settings, there were 2 other protocol installed along with TCP/IP, one is WLAN Transport and the otherAEGIS Protocol (IEEE 802.1x).</p>
<p>Removing both WLAN Transport and AEGIS wireless protocol resolved the issue immediately.</p>
<p>The reason could be due to Windows&#8217; Wireless Zero Configuration does not work well with the above two protocols which was actually meant to be used with Intel&#8217;s wireless software.</p>
<p>In other instances, I have encounter NWLink NetBIOS and NWLink IPX/SPX/NetBIOS Compatible Transport Protocol being installed in an environment that is non-Netware, causing the startup to be extremely slow and user having random network problems.</p>
<p>In most scenario where the network are solely Windows machines, there is no need to install anything more than Client for Microsoft Network, File And Printer Sharing and TCP/IP protocol.  QOS is only required in an environment where you have managed switches that are able to prioritize traffic based on the type of packets being transmitted.</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/problem-connecting-to-wireless-network/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Error Messages Caused By Hardware Failures</title>
		<link>http://techsupport.specialty.be/category/error-messages-caused-by-hardware-failures/</link>
		<comments>http://techsupport.specialty.be/category/error-messages-caused-by-hardware-failures/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 16:33:25 +0000</pubDate>
		<dc:creator>Tech Support</dc:creator>
		
		<category><![CDATA[Hardware Issues]]></category>

		<guid isPermaLink="false">http://techsupport.specialty.be/error-messages-caused-by-hardware-failures/</guid>
		<description><![CDATA[System startup with &#8216;Pci.sys is missing or corrupt&#8217;.
An attempt to boot from XP CD generates an error &#8216;File setupdd.sys could not be loaded.
The error code is 14
Setup cannot continue.&#8217;
Removing the pci modem changes the error code from 14 to 7. Removing and reinstalling the AGP graphic card and  memory modules and ensuring that they [...]]]></description>
			<content:encoded><![CDATA[<p>System startup with &#8216;Pci.sys is missing or corrupt&#8217;.</p>
<p>An attempt to boot from XP CD generates an error &#8216;File setupdd.sys could not be loaded.<br />
The error code is 14<br />
Setup cannot continue.&#8217;</p>
<p>Removing the pci modem changes the error code from 14 to 7. Removing and reinstalling the AGP graphic card and  memory modules and ensuring that they are fitted properly boots the system up fine without the need for a reinstallation of Windows.</p>
<p>There are also other things to bear in mind when you&#8217;re planning to troubleshoot or recover and XP crash, (These points are especially useful when your system crash with the error - &#8220;Windows could not start because the following file is missing or corrupt C:\windows\system32\config\system&#8221;) ;</p>
<p>1. There is always a folder in Windows installation folder that consists system files that can restore your system to the state of your first install, provided that the crash isn&#8217;t hardware failure related. (e.g. C:\windows\repair) The folder with your system files prior to the crash is located at c:\windows\system32\config. Copying files (after backing up the original files) to the above location will restore your system to first boot state.</p>
<p>2. Enabling wildcards to ease copy and deletion process, which can be useful when you&#8217;re working in recovery console mode. The command is  AllowWildCards = TRUE , to be typed at the command prompt. Another command AllowAllPaths = TRUE is also useful as it allows you to access all files and folders on the system.</p>
<p>3. Once you&#8217;re back into your first install state, you can then set explorer to display hidden and system files and folders, disable simple file sharing from the folder options in Windows explorer. This will enable you to see a folder call &#8220;System Volume       Information Folder&#8221; which consist system files backup at various time from c:\windows\system32\config . You may need to give yourself rights to the folder in order to access its contents.</p>
<p>Restoring the system files from point 3 will be a closer match to your last system state prior to the crash.</p>
]]></content:encoded>
			<wfw:commentRss>http://techsupport.specialty.be/category/error-messages-caused-by-hardware-failures/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
