Monday, April 7, 2008

Windows Update's silent patches

Microsoft updates Windows without users' consent By Scott Dunn

Microsoft has begun patching files on Windows XP and Vista without users' knowledge, even when the users have turned off auto-updates.

Many companies require testing of patches before they are widely installed, and businesses in this situation are objecting to the stealth patching.


Files changed with no notice to users

In recent days, Windows Update (WU) started altering files on users' systems without displaying any dialog box to request permission. The only files that have been reportedly altered to date are nine small executables on XP and nine on Vista that are used by WU itself. Microsoft is patching these files silently, even if auto-updates have been disabled on a particular PC.

It's surprising that these files can be changed without the user's knowledge. The Automatic Updates dialog box in the Control Panel can be set to prevent updates from being installed automatically. However, with Microsoft's latest stealth move, updates to the WU executables seem to be installed regardless of the settings — without notifying users.

When users launch Windows Update, Microsoft's online service can check the version of its executables on the PC and update them if necessary. What's unusual is that people are reporting changes in these files although WU wasn't authorized to install anything.

This isn't the first time Microsoft has pushed updates out to users who prefer to test and install their updates manually. Not long ago, another Windows component, svchost.exe, was causing problems with Windows Update, as last reported on June 21 in the Windows Secrets Newsletter. In that case, however, the Windows Update site notified users that updated software had to be installed before the patching process could proceed. This time, such a notice never appears.

For users who elect not to have updates installed automatically, the issue of consent is crucial. Microsoft has apparently decided, however, that it doesn't need permission to patch Windows Updates files, even if you've set your preferences to require it.

Microsoft provides no tech information — yet

To make matters even stranger, a search on Microsoft's Web site reveals no information at all on the stealth updates. Let's say you wished to voluntarily download and install the new WU executable files when you were, for example, reinstalling a system. You'd be hard-pressed to find the updated files in order to download them. At this writing, you either get a stealth install or nothing.

A few Web forums have already started to discuss the updated files, which bear the version number 7.0.6000.381. The only explanation found at Microsoft's site comes from a user identified as Dean-Dean on a Microsoft Communities forum. In reply to a question, he states:

"Windows Update Software 7.0.6000.381 is an update to Windows Update itself. It is an update for both Windows XP and Windows Vista. Unless the update is installed, Windows Update won't work, at least in terms of searching for further updates. Normal use of Windows Update, in other words, is blocked until this update is installed."

Windows Secrets contributing editor Susan Bradley contacted Microsoft Partner Support about the update and received this short reply:


"7.0.6000.381 is a consumer only release that addresses some specific issues found after .374 was released. It will not be available via WSUS [Windows Server Update Services]. A standalone installer and the redist will be available soon, I will keep an eye on it and notify you when it is available."

Unfortunately, this reply does not explain why the stealth patching began with so little information provided to customers. Nor does it provide any details on the "specific issues" that the update supposedly addresses.

System logs confirm stealth installs

In his forum post, Dean-Dean names several files that are changed on XP and Vista. The patching process updates several Windows\System32 executables (with the extensions .exe, .dll, and .cpl) to version 7.0.6000.381, according to the post.

In Vista, the following files are updated:

1. wuapi.dll
2. wuapp.exe
3. wuauclt.exe
4. wuaueng.dll
5. wucltux.dll
6. wudriver.dll
7. wups.dll
8. wups2.dll
9. wuwebv.dll

In XP, the following files are updated:

1. cdm.dll
2. wuapi.dll
3. wuauclt.exe
4. wuaucpl.cpl
5. wuaueng.dll
6. wucltui.dll
7. wups.dll
8. wups2.dll
9. wuweb.dll

These files are by no means viruses, and Microsoft appears to have no malicious intent in patching them. However, writing files to a user's PC without notice (when auto-updating has been turned off) is behavior that's usually associated with hacker Web sites. The question being raised in discussion forums is, "Why is Microsoft operating in this way?"

How to check which version your PC has

If a system has been patched in the past few months, the nine executables in Windows\System32 will either show an earlier version number, 7.0.6000.374, or the stealth patch: 7.0.6000.381. (The version numbers can be seen by right-clicking a file and choosing Properties. In XP, click the Version tab and then select File Version. In Vista, click the Details tab.)

In addition, PCs that received the update will have new executables in subfolders named 7.0.6000.381 under the following folders:

c:\Windows\System32\SoftwareDistribution\Setup\ServiceStartup\wups.dll
c:\Windows\System32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll

Users can also verify whether patching occurred by checking Windows' Event Log:

Step 1. In XP, click Start, Run.

Step 2. Type eventvwr.msc and press Enter.

Step 3. In the tree pane on the left, select System.

Step 4. The right pane displays events and several details about them. Event types such as "Installation" are labeled in the Category column. "Windows Update Agent" is the event typically listed in the Source column for system patches.

On systems that were checked recently by Windows Secrets readers, the Event Log shows two installation events on Aug. 24. The files were stealth-updated in the early morning hours. (The time stamp will vary, of course, on machines that received the patch on other dates.)

To investigate further, you can open the Event Log's properties for each event. Normally, when a Windows update event occurs, the properties dialog box shows an associated KB number, enabling you to find more information at Microsoft's Web site. Mysteriously, no KB number is given for the WU updates that began in August. The description merely reads, "Installation Successful: Windows successfully installed the following update: Automatic Updates."

No need to roll back the updated files

Again, it's important to note that there's nothing harmful about the updated files themselves. There are no reports of software conflicts and no reason to remove the files (which WU apparently needs in order to access the latest patches). The only concern is the mechanism Microsoft is using to perform its patching, and how this mechanism might be used by the software giant in the future.
http://WindowsSecrets.com/comp/070913

BEFORE you go VISTA, READ THIS from Microsoft!

Please read this important information before proceeding


• System requirements
View system requirements and information on Windows Vista Capable and Premium Ready PCs.

• Release notes
View the release notes for Windows Vista RC1 (available in English only).

• Upgrade limitations
You may not be able to upgrade your installation of Windows Vista RC1 to the final, commercially available edition of Windows Vista. To upgrade, you will need to acquire the final edition of Windows Vista and you may have to do a clean installation.

• Time-limited software
Windows Vista RC1 is time-limited, pre-release software that will expire on June 1, 2007.

• Beta support policy
This is pre-release (beta) software distributed for trial and testing purposes only.
Microsoft does not provide technical support for beta releases.

Although formal support is not offered for this beta, we have provided newsgroups to help answer questions you may have related to the installation and use of Windows Vista RC1.
To join or read postings in these newsgroups, please visit
http://windowshelp.microsoft.com.

• 2007 Office System Beta 2 compatibility
If you are using 2007 Office system Beta 2 be sure to download the 2007 Microsoft Office system Beta 2 Technical Refresh, the most recent update. (The Technical Refresh is required to use Office Beta 2 with Windows Vista RC1.)


• Installation limitations
There are three installation scenarios for Windows Vista RC1:

1. You can do a clean installation.

This process will overwrite any data that you have on your hard disk or on your installation partition. The overwritten data will be lost and unrecoverable.

2. You can upgrade an existing installation of Windows XP.


3. You can upgrade an existing installation of Windows Vista Beta 2.

No other installation scenarios are supported.

Upgrading to this beta from any other edition of Windows requires a clean installation, as described in option 1.

In addition, once you install Windows Vista RC1, you cannot roll back to the previous operating system installation—you will either have to acquire and install the final released edition of Windows Vista or reinstall a previous edition of Windows.

Before installing Windows Vista RC1 on any computer, please remember to back up all your files.

Upgrading from Windows Vista Beta 2
Please install any Critical Updates from Windows Update before upgrading from Beta 2 to RC1.
Go to Start, All Programs, Windows Update, and click the "Check for Updates" button.
Note: Please close any open applications before beginning an upgrade. During installation, we recommend that you have an active Internet connection and choose Go online to get the latest updates for installation.

Friday, April 4, 2008

start up problem

start up problem
"instruction at 0x00000000 reference memory at 0x00000000 memory could not be readed". click ok to terminate or cancel pop up message showing every time when the system boots.

Solution:


Is any Dump of Memory
Goto Start----> Right click on My Computer ---> Properties----->Advanced--->Performance--->Advanced--->Virtual Memory
---->change value to 756 MB or 1024MB
then Set and click OK ..RESTART THE COMPUTER....

Wednesday, April 2, 2008

Microsoft Surface launching April 17th... with AT&T

Microsoft Surface launching April 17th... with AT&T

No, Microsoft hasn't suddenly transformed its 30-inch, multi-touch Surface into a big-ass cellphone. It has, however, chosen AT&T to launch the world's first Surface into retail. Shoppers in New York, Atlanta, San Antonio, and San Francisco will be treated to what amounts to the novelty (at least initially) of learning about a device (Samsung BlackJack II, pictured) by simply placing it atop the Surface. They'll also have the ability to explore interactive coverage maps. Later, users will be able to drag ringtones, graphics and video and drop it into "the phones." Note their use of "the" and not "your" phone in the press release. Nevertheless, we're happy to see Microsoft get the technology out the door on its long march towards consumerdom.

http://www.engadget.com/2008/04/02/m...h-with-atandt/

MMC HARDWARE SOLUTION


Try This For Ur MMC Not Working..
90% Working...

Sunday, March 30, 2008

Virus: Worm:Win32/Sober.AH@mm

Virus Encyclopedia: Worm:Win32/Sober.AH@mm

Worm:Win32/Sober.AH@mm is a mass-mailing e-mail worm that sends itself in either English or German language e-mail, depending on the domain suffix of the infected user. Typically, the Win32/Sober worm family downloads additional malicious files at pre-determined times and locations. These files are commonly proxies that are used to relay spam from infected systems.


How do I know if my computer is infected?

The following symptoms may be indicative of a Worm:Win32/Sober.AH@mm infection:
Presence of the following subfolder:
%windir%\pooldata\
Presence of the following files in %windir%\pooldata\:
services.exe
smss.exe
csrss.exe
Note: the presence of the filenames themselves are not indicative of infection, unless specifically located in the aforementioned folder.
Presence of the following registry modifications:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
"_WinData" = "%windir%\pooldata\services.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
“Windata” = "%windir%\pooldata\services.exe"

Recovery Instructions

To manually recover from infection by Worm:Win32/Sober.AH@mm, follow these steps:
    Disconnect from the Internet.
    Restart your computer in safe mode.
    End the worm process.
    Delete the main worm file from your computer.
    Delete the worm registry entries.
    Restart your computer.
    Take steps to prevent re-infection.

Disconnect from the Internet

To help ensure that the computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.

Restart your computer in safe mode

To start your computer in safe mode
    Remove all floppy disks and CDs from the computer, and then restart the computer.
    When prompted, press F8. If Windows starts without displaying the Please select the operating system to start menu, restart your computer. Press F8 after the firmware POST process completes, but before Windows displays graphical output.
    From the Windows Advanced Options menu, select a safe mode option.

End the worm process

To end the worm process
    Press CTRL+ALT+DEL once and click Task Manager.
    Click Processes and click Image Name to sort the running processes by name.
    Select the process services.exe if it exists, and click End Process.

Delete the main worm file from your computer

To delete the main worm file from your computer
    Click Start, and click Run.
    In the Open field, type %windir%\pooldata\services.exe
    Click OK.
    Click Name to sort files by name.
    Delete the file services.exe if it is in the list.
    On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
    Click Yes to confirm the deletion.
If deleting the file fails, use the following steps to verify that process services.exe is not running:
    Press CTRL+ALT+DEL once and click Task Manager.
    Click Processes and click Image Name to sort the running processes by name.
    Confirm that services.exe is not in the list.
    Repeat these steps to locate and remove %windir%\pooldata\smss.exe and %windir%\pooldata\csrss.exe

Delete the worm registry entries

Worm:Win32/Sober.AH@mm creates entries in the Windows registry that cause the worm to run each time Windows starts. These entries should be deleted.
To delete the worm registry entries
    On the Start menu, click Run.
    Type regedit and click OK.
    In the left pane, navigate to the registry key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    In the right pane, right-click the following value, if it exists: Windata
    Click Delete and click Yes to delete the value.
    In the left pane, navigate to the registry key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    In the right pane, right-click the following value, if it exists: _WinData
    Click Delete and click Yes to delete the value.
    Close the Registry Editor.

Restart your computer

To restart your computer
    On the Start menu, click Shut Down.
    Select Restart from the drop-down list and click OK.

Infections in virus scan

Infections in virus scan
When I scan my laptop, i find infections in MBR , ntoskrnl.exe, shell32.dll, user32.dll, kernel32.dll by AVG. In the result, it shows no threats. please help.

This fdisk command will allow you to recreate the Master Boot Record or MBR. Although this can be dangerous, it is a quick way to fix many boot issues... if you know what you are doing.
1. Click Start
2. Click Run
3. Type CMD and hit ENTER
4. From this dos box command line:

FDISK /MBR
This rebuilds the boot sector of the first bootable hard disk based on current disk structure. The partition table information should not be altered.

This is usually used to repair a damaged, corrupted, or infected master boot record.

Tuesday, March 25, 2008

RESET your BIOS settings.

RESET your BIOS settings.
First try to RESET your BIOS settings.
If you can enter your BIOS then make it the default factory settings mode.
If you cannot enter into the BIOS then look for the two pins near the CMOS battery and remove them fora while to make them unshorted. this will reset your system BIOS. Look into the image for more how to reset the BIOS using Jumper settings.

How to remove icons from system tray

How to remove icons from system tray

Run -> msconfig.exe -> go to the option "startup" and uncheck the unwanted items and restart the system. This will work on windows 98/xp. But for windows 2000 you have to download it(you can copy msconfig.exe from a windows xp machine also) and put in c:\winnt folder.

Windows XP Unread Mail Count

Windows XP Unread Mail Count

Windows XP's logon screen lists the number of unread email messages associated with the user account. The message count is taken from all email accounts checked within the last 3 days using Outlook Express, Outlook, Messenger (Hotmail/MSN), and the MSN browser client. This includes not only your accounts, but those of anyone who used your computer to check their email.

The unread message count is stored in the registry at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UnreadMail and each account ever checked from this computer in the count is listed as subkeys under this key. Their unread count is only included in the total shown on the logon screen if they were checked within the last 3 days.

This can be deleted from the registry

I cannot open my Drive by double click

Open notepad, paste the following code and save the file as drive_open.reg and then double click it. Click on Yes

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Drive]
@="Drive"
"EditFlags"=hex:d2,01,00,00

[HKEY_CLASSES_ROOT\Drive\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00 ,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00 ,32,00,5c,00,73,00,68,00,\
65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c ,00,2c,00,38,00,00,00

[HKEY_CLASSES_ROOT\Drive\shell]
@="none"

[HKEY_CLASSES_ROOT\Drive\shell\find]
"SuppressionPolicy"=dword:00000080

[HKEY_CLASSES_ROOT\Drive\shell\find\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00 ,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00 ,72,00,2e,00,65,00,78,00,\
65,00,00,00

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec]
@="[FindFolder(\"%l\", %I)]"
"NoActivateHandler"=""

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\applica tion]
@="Folders"

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\topic]
@="AppProperties"

[HKEY_CLASSES_ROOT\Drive\shellex]

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s]

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\Offline Files]
@="{750fdf0e-2a26-11d1-a3ea-080036587f03}"

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\Sharing]
@="{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\Symantec.Norton.Antivirus.IEContextMenu]
@="{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\{59099400-57FF-11CE-BD94-0020AF85B590}]

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\{cc86590a-b60a-48e6-996b-41d25ed39a1e}]
@="Portable Media Devices Menu"

[HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandler s\{fbeb8a05-beee-4442-804e-409d6c4515e9}]
@=""

[HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions]

[HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{ fbeb8a05-beee-4442-804e-409d6c4515e9}]
@=""
"DriveMask"=dword:00000020

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers]

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers\Sharing]
@="{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers\{1F2E5C40-9550-11CE-99D2-00AA006E086C}]

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers\{7988B573-EC89-11cf-9C00-00AA00A14F56}]
@=""

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers\{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}]

[HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandl ers\{fbeb8a05-beee-4442-804e-409d6c4515e9}]
@=""

Locating a Lost Nortan Antivirus Product Key

Locating a Lost Nortan Antivirus Product Key

start-> Run-> regedit.exe

Locate:
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\CCPD-LC\KStore\00000082\0000000f\0000001b
find on the right side

A simple Batch program

A simple Batch program

Open an MS-DOS command window or get to MS-DOS

# At the MS-DOS prompt, type edit test.bat and press enter.
# If typed properly, you should now be in a blue screen. Within the screen, type:

pause
dir c:\windows
dir c:\windows\system

Microsoft Windows

# Click Start
# Click Run
# Type "notepad" and press enter.
# Once notepad is open, type the below lines in the file or copy and paste the below lines into notepad.

@echo off
echo Hello this is a test batch file
pause
dir c:\windows

Lock the screen (Windows 2000): using batch program

RUNDLL32 USER32.DLL,LockWorkStation

save as .bat

Transcend Unveils 32GB Flash Drive in India

Transcend announced the launch of its latest high-capacity USB flash drive - the 32GB JetFlash V60 in India. It’s the first brand selling 32GB pen drives with in India.

About the size of an AA battery (61mm x 18.6mm x 9.8mm), the JetFalsh V60 is small and light enough to be taken anywhere. With its 32GB memory capacity, users can easily store their personal files, music, digital photos, and even full-length HDTV movies.

The 32GB JetFalsh V60 is also equipped with some useful software tools designed for computer users. The JetFlash elite software suite can be installed to run directly from the JetFlash drive when you plug it in, and includes seven time-saving data management functions, including: Website AutoLogin, PC-Lock, Mobile Favorites, Secret-Zip encryption, Mobile E-mail, DataBackup and Online Update.

Priced at Rs. Rs. 7,300, the JetFlash V60 also supports Windows 98SE / Me / 2000 / XP / Vista, Mac and Linux and comes with a 3 year warranty.

Monday, March 24, 2008

Microsoft Announces Open Source Interoperability Initiative

Microsoft Announces Open Source Interoperability Initiative


Microsoft has announced Open Source Interoperability Initiative. From the announcement press release :


The Open Source Interoperability Initiative exists to foster more open engagement between Microsoft and open source communities. It will encompass a broad range of facilities, events, and resources supporting interoperability, including labs, plug fests, technical content and opportunities for ongoing cooperative development. Microsoft plans to publish APIs and protocols that are used by Windows Vista (including the .NET Framework), Windows Server 2008, SQL Server 2008, Office 2007, Exchange Server 2007 and Office SharePoint Server 2007 — as well as their future versions. Also Microsoft will not require developers to license or pay royalties for this information. Specifically, Microsoft is implementing four new interoperability principles and corresponding actions across its high-volume business products: (1) ensuring open connections; (2) promoting data portability; (3) enhancing support for industry standards; and (4) fostering more open engagement with customers and the industry, including open source communities.

Microsoft also agreed not to sue developers of open-source software and releasing tons of API.

RAJ SOLUTION'S

PROMISSING NOTE:-

All This Stuff is For u only..
But u all only If dont comments then its Better we should stop Blogging....