Google

Saturday, February 2, 2008

About Task manager

There many virus that make your task manager disable. In order to get rid of them you need to scan your computer with an updated anti-virus and once the virus has been removed you need to re-enable your task manager manually.

For Re-Enabling your task manager you can choose one of the following way:-

A) Through Group Policy

Go to "Start" -> "Run" -> Write "Gpedit.msc" and press on "Enter" button.

1. Navigate to "User Configuration" -> "Administrative Templates" -> "System" -> "Ctrl+Alt+Del Options"

2. In the right side of the screen verity that "Remove Task Manager"" option set to "Disable" or "Not Configured".

3. Close "Gpedit.msc" MMC.
----------------------------------------

--------------

B) Through Registry setting

Only if you are not using Windows XP Professional,Operating System then you'll need to edit the registry manually.

Click Start, then click Run, type in regedit, and click on OK.

Expand these registry keys in turn:

HKEY_CURRENT_USER
==>Software
==>Microsoft
==>Windows
==>CurrentVersion
==>Policies
==>System

After that Right Click on the DisableTaskMgr item,Click on Delete, confirm that you want to delete, and Task Manager should be available once again


**Warning**

Always backup your files before modifying registry entries

Regarding USB Drive (Pen Drive)

If user has the rights for editing the regedit

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies]

"WriteProtect"=dword:00000001

Change the write protect to

"WriteProtect"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR]

"Start"=dword:00000004

Change the protect to

"Start"=dword:00000003

Check and revert back

Restricting a Website - Simple way -

Suppose you wanna block www.orkut.com then

1] Browse C:\WINDOWS\system32\drivers\etc
2] Find the file named HOSTS and open it with notepad
3] Go to the last line - "127.0.0.1 localhost" - under that add 127.0.0.2 www.orkut.com, and then that site will no longer be accessible !!!

********************************************
C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.2 www.orkut.com
********************************************

If you wanna block more sites you can add more lines to this by addling 1 to the Loop back IP

********************************************
C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.2 www.orkut.com
127.0.0.3 www.yahoomail.com
127.0.0.4 www.gmail.com
********************************************


Group Policy

Open Group Policy (Run -> gpedit.msc)

Go to User configuration -> Windows settings -> Internet explorer maintenance->
security -> double click Security zones

Enable security zones and privacy by selecting import the current security zones and privacy settings -> Click on modify settings -> Click on privacy -> Click site -> In the address of the web site tab add the site name you wanna block -> Click block -> click OK -> OK -> OK

This will block the site.

This configured can be done on the local system or the same can be configured in GPO and can be applied to the entire domain !

Difference between Virus, Spyware,Adware.. etc..

Computer Virus:

Virus is a program or piece of code that is loaded onto your computer without your knowledge and runs against your wishes. Viruses can also replicate themselves. All computer viruses are manmade. A simple virus that can make a copy of itself over and over again is relatively easy to produce. Even such a simple virus is dangerous because it will quickly use all available memory and bring the system to a halt. An even more dangerous type of virus is one capable of transmitting itself across networks and bypassing security systems.
Since 1987, when a virus infected ARPANET, a large network used by the Defense Department and many universities, many antivirus programs have become available. These programs periodically check your computer system for the best-known types of viruses.

Some people distinguish between general viruses and worms. A worm is a special type of virus that can replicate itself and use memory, but cannot attach itself to other programs.



Spyware

Any software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes. Spyware applications are typically bundled as a hidden component of freeware or shareware programs that can be downloaded from the Internet; however, it should be noted that the majority of shareware and freeware applications do not come with spyware. Once installed, the spyware monitors user activity on the Internet and transmits that information in the background to someone else. Spyware can also gather information about e-mail addresses and even passwords and credit card numbers.
Spyware is similar to a Trojan horse in that users unwittingly install the product when they install something else. A common way to become a victim of spyware is to download certain peer-to-peer file swapping products that are available today.


Adware

Any software application in which advertising banners are displayed while the program is running. The authors of these applications include additional code that delivers the ads, which can be viewed through pop-up windows or through a bar that appears on a computer screen. The justification for adware is that it helps recover programming development cost and helps to hold down the cost for the user.
Adware has been criticized because it usually includes code that tracks a user's personal information and passes it on to third parties, without the user's authorization or knowledge. This practice has been dubbed spyware and has prompted an outcry from computer security and privacy
advocates, including the Electronic Privacy Information Center.


Trojan Horse

A destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves but they can be just as destructive. One of the most insidious types of Trojan horse is a program that claims to rid your computer of viruses but instead introduces viruses onto your computer.
The term comes from the a Greek story of the Trojan War, in which the Greeks give a giant wooden horse to their foes, the Trojans, ostensibly as a peace offering. But after the Trojans drag the horse inside their city walls, Greek soldiers sneak out of the horse's hollow belly and open the city gates, allowing their compatriots to pour in and capture Troy.


Computer Worm

A computer worm is a self-replicating computer program, similar to a computer virus. A virus attaches itself to, and becomes part of, another executable program; a worm is self-contained and does not need to be part of another program to propagate itself.
The name 'worm' was taken from The Shockwave Rider, a 1970s science fiction novel by John Brunner. Researchers writing an early paper on experiments in distributed computing noted the similarities between their software and the program described by Brunner and adopted the name.

The first worm to attract wide attention, the Morris worm, was written by Robert Tappan Morris, Jr. at the MIT Artificial intelligence Laboratory. It was released on November 2, 1988, and quickly infected a great many computers on the Internet at the time. It propagated through a number of bugs in BSD Unix and its derivatives. Morris himself was convicted under the US Computer Crime and Abuse Act and received 3 years' probation, community service and a fine in excess of ,000.

In addition to replication, a worm may be designed to do any number of things, such as delete files on a host system or send documents via email. More recent worms may be multi-headed and carry other executables as a payload. However, even in the absence of such a payload, a worm can wreak havoc just with the network traffic generated by its reproduction. Mydoom, for example, caused a noticeable worldwide Internet slowdown at the peak of its spread.

A common payload is for a worm to install a backdoor in the infected computer, as was done by Sobig and Mydoom. These backdoors are used by spam senders for sending junk email or to cloak their website's address


Backdoor

A program that allows a remote user to execute commands and tasks on your computer without your permission. These types of programs are typically used to launch attacks on other computers, distribute copyrighted software or media, or hack other computers.


Dialer

A program that typically dials a premium rate number that has per minute charges over and above the typical call charge. These calls are with the intent of gaining access to pornographic material.


Hijackers

A program that attempts to hijack certain Internet functions like redirecting your start page to the hijacker's own start page, redirecting search queries to a undesired search engine, or replace search results from popular search engines with their own information.


I think you got every information about what causing problems in net and web world.







Do anyone know where the password file is stored in pc(user account's) ?

Here is the answer for it

Yes password file was stored in windows system32 config and sam file

named as SAM

location : C:\windows\system32\config\SAM


we can change password by entering into the location given above.
limitation:
you cant access properly if you have not the administrator rights even you can do the changes if you are added in the power user list other wise you cant do anything with the limited account.

But you can do using cmd as given below

Go to Dos type net user administrator *
press enter now type your own password
So now you have hacked the
administrator

General System Registry Secrets

Tips for everything from using services on remote machines to successfully uninstalling software. You can change the way your interface looks, customize your Run command, and ensure that your logon scripts run correctly. You will find answers to common problems all Windows NT users face, including network protocols, printers, disk drives, and domain controllers.


Have you ever needed to start a service on a remote machine? You can use the tools in the resource kit, but they often aren’t handy or give curious results. Each service has a corresponding registry key and each key has a start value. Each service can have one of these start values:

0x0 Boot
0x1 System
0x2 Automatic
0x3 Manual
0x4 Disabled

To alter the way a service starts, change the appropriate start value for each service. I give two examples and list common services and their registry keys for a generic Windows NT installation. Many other services are available In the site given below.
for more info: http://www.windowsitlibrary.com/Content/69/01/1.html

Everything about Registry

This article explains how to use the Windows Registry. The Registry is the central storehouse for all settings for the Windows operating systems. This includes hardware configuration, file associations, and control panel settings. Many other programs will also store settings in the registry.

The registry is made up of "Keys". Each key is like the branch of a tree. Each key has one parent key, and zero or more child keys. Each key can contain zero or more "Values", each of which contains a single piece of data.

To make navigating the registry a bit easier, you can think of the registry's construction like your hard drives.

Hard drive <-> Registry
Folders <-> Keys
Files <-> Values

The registry contains 6 main keys:

  • HKEY_CLASSES_ROOT ---- Contains information on file types, including which programs are used to open a particular file type.
  • HKEY_CURRENT_USER ---- Contains user-specific settings that are built from information in the HKEY_USERS key during the logon process.
  • HKEY_LOCAL_MACHINE ---- Contains computer specific information including installed hardware and software. This is the one users tend to spend the most time in.
  • HKEY_USERS ---- Contains information (generic and user-specific) about all the users who log on to the computer. The generic settings are available to all users who log on to the computer. The information is made up of default settings for programs, desktop configurations, and so on. This key contains subkeys for each user that logs on to the computer.
  • HKEY_CURRENT_CONFIG ---- Contains information about the computer's hardware configuration .
  • HKEY_DYN_DATA ---- Contains real-time performance statistics on the computer's hardware.
for more information logon to: http://gammadyne.com/registry.htm