Saturday, January 10, 2009

Are these your problems with Windows?

Assuming most of the desktops in your current enterprise are installed with Windows XP (SP2/SP3) or Windows 2000, here is a list of problems you (administrator) might be facing with them.


Problems:


1. The users on most of the desktops use administrative accounts to work on their PCs. This is usually done so as to enable to users to do all the common tasks on their PCs themselves, but this may pose problems like:



a. Users can install software themselves. Once installed, software can compromise the overall health and control of the PC, as well as introduce security and data compliance issues. With every new piece of unknown software installed, desktop performance, security, and supportability is gradually compromised.



b. No asset inventory control or license management. This can leave you in a position where you don’t know what has been installed and whether or not you have a license for the software.



c. Important data files are often changed or deleted. With administrator accounts, users have full access to the system and can often delete files that are required for system stability and reliability or even booting into the operating system, running applications or performing other day-to-day tasks



d. End users are able to change core system configurations. Users with admin rights can install drivers, change firewall settings, deactivate services, or deactivate anti-malware software, and add additional user accounts.



e. Users are not restricted from attaching devices to their PCs. With unauthorized storage devices connected (such as USB drives and MP3 players), users can easily lose or steal important data, load malware onto PCs, or misuse company assets with personal devices.



f. Systems cannot be centrally managed. In many cases software is not centrally distributed or tracked. If that is the case, computers will require manual setup and configuration.



2. Many applications are written to require admin privileges. This is often because software developers tend to develop as local administrators. Many applications are designed to assume that administrative privileges are present.



3. Applications can save their data (installation files, registry keys, and runtime data) to random locations. Applications written this way are difficult to support, because each application functions in a different way. If something breaks, it is difficult to troubleshoot the problem. For example- applications may store unknown file formats in “Program Files’ folder during installation.



So what is the ideal way in which the Windows systems must be managed and how can that state be achieved?



Read my next blog on what should be done to tackle these problems proactively, and the third one in the series on how can it be done.

Monday, January 5, 2009

Orkut is barned. Muhahaha!! Here is the solution!

Are you not able to use Orkut from your home computer??

"Orkut is banned you fool, The administrators didnt write this program
guess who did?? MUHAHAHA!!"

Are you not able to use Firefox on your computer??

Here is the solution!

If you find those messages when you try to brows; chances are your computer is affected with a virus called w32.USB worm...

w32.USB Worm

It is spreading through Pen,USB,Thump disk thats why the name

It shows messages like

"I DNT HATE MOZILLA BUT USE IE OR ELSE..."

"USE INTERNET EXPLORER U DOPE"

"Orkut is banned you fool, The administrators didnt write this program
guess who did?? MUHAHAHA!!" with title ORKUT IS BANNED

hi if u c any of the following msgs while u r working on your pc

you are possibly infected with a worm "w32.usb worm"

solution:
*********

1. Press CTRL+ALT+DEL and go to the processes tab

2. Look for "svchost.exe" under the image name. There will be many but
look for the ones which have your username under the username
[username : it is ur login name or default user name which you might have
provided. if you are still not sure open start button. the one that
appears on the top is your "username"]

3. Press DEL to kill these files. It will give you a warning, Press Yes

4. Repeat for more svchost.exe files with your username and repeat. Do
not kill svchost.exe with system, local service or network service!

5. Now open run command start>run> and type "command" without quotes

now you will see the command prompt.
x:\docume~1\
where x [mostly c] is your main drive and is the login name.
now in the command prompt type as follows

c:\docume~1\ cd\
[this will send u to the root directory i.e. C: in this case]

now

c:\attrib heap41a -s -h
[will remove the system and hidden attributes of the folder "heap41a"
which is the main worm planted folder for autorun]

c:\rem heap41a
this will remove the heap41a folder from ur system.
if it is not allowed try logoff n login again n go to the command
promt again n C:\rem heap41a
now it must b removed

now the final part
open run command type "regedit"
search for "heap41a" without quotes [use f3 function key for searching]
and delete them

now you are free to open orkut.

finally also check one more thg.
i.e. open my computer>tools> folder options>view tab>
check vit the hidden folders n files
check if unhide is working
if it is not working then possibly u might have been infected vit
"Ravmon.exe"

try installing some anti spyware software like "adaware" and scan your pc
for removal.

thats it.

Don't forget to update your anti virus regularly.....

Search The Fire Seal

Random Post: I'm feeling lucky!!!