<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4042542981961052657</id><updated>2012-02-16T06:38:21.527-08:00</updated><category term='removal'/><category term='reformat'/><category term='recover'/><category term='Virus'/><title type='text'>Computer Info &amp; Latest Computer Virus</title><subtitle type='html'>Basic Computer Info, Computer Tips &amp;amp; Latest Computer Virus</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-3203511416814256568</id><published>2011-04-11T16:39:00.000-07:00</published><updated>2011-03-14T00:38:46.205-07:00</updated><title type='text'>Hot Promotion</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/TLOg9DMyruI/AAAAAAAAALo/-fkF75l7YBs/s1600/computer-doctor.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 362px; height: 330px;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/TLOg9DMyruI/AAAAAAAAALo/-fkF75l7YBs/s400/computer-doctor.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5526938138405154530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;• Data pada ThumbDrive anda bertukar Shortcut???&lt;br /&gt;Tak perlu reformat komputer. Remove Virus jer - &lt;strong&gt;RM25&lt;/strong&gt;&lt;br /&gt;• Reformat computer - &lt;strong&gt;RM 35&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Hubungi : &lt;br /&gt; Razi : 014 – 8736005  &lt;br /&gt; ladingmerah@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;“We Pickup, We Repair, We Deliver”&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/120x240.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-3203511416814256568?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/3203511416814256568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=3203511416814256568' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3203511416814256568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3203511416814256568'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/10/hot-promotion.html' title='Hot Promotion'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-RTTc4l_elM/TLOg9DMyruI/AAAAAAAAALo/-fkF75l7YBs/s72-c/computer-doctor.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-6421531288520383068</id><published>2011-04-11T16:36:00.000-07:00</published><updated>2011-03-14T00:37:44.244-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='recover'/><category scheme='http://www.blogger.com/atom/ns#' term='removal'/><category scheme='http://www.blogger.com/atom/ns#' term='reformat'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Multicast Technology</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/TLOhcIXWEqI/AAAAAAAAALw/OwkCscoKHy8/s1600/computer-doctor.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 362px; DISPLAY: block; HEIGHT: 330px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5526938672367538850" border="0" alt="" src="http://4.bp.blogspot.com/_-RTTc4l_elM/TLOhcIXWEqI/AAAAAAAAALw/OwkCscoKHy8/s400/computer-doctor.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;"&lt;em&gt;We Pickup, We Repair, We Deliver&lt;/em&gt;"&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* Customize Software &amp;amp; Maintenance&lt;br /&gt;* Computer Software &amp;amp; Hardware Maintenance&lt;br /&gt;* Networking&lt;br /&gt;* Repair &amp;amp; Services&lt;br /&gt;* Antivirus&lt;br /&gt;* Reformat&lt;br /&gt;* Computer Virus Specialize&lt;br /&gt;* On Site repair (Minor Problem)&lt;br /&gt;&lt;br /&gt;Call Us :&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Razi - 014 8736005&lt;/strong&gt; (&lt;em&gt;Universiti Malaysia Sabah,Putatan, Taman Pantai Lokkawi, Lokkawi Height, Kinarut area&lt;/em&gt;)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Azlan - 016 8455756&lt;/strong&gt; (&lt;em&gt;Universiti Malaysia Sabah, Alam Mesra, Sepanggar, Likas, Kingfisher area&lt;/em&gt;)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Anuar - 016 8470478&lt;/strong&gt; (Universiti Malaysia Sabah, Inanam, Kalansanan, Sepanggar, kolombong, Putatan area)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.kerja-kerajaan.com/index.php?ref=ladingmerah"&gt;&lt;img src="http://www.kerja-kerajaan.com/images/468x60.gif" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-6421531288520383068?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/6421531288520383068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=6421531288520383068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6421531288520383068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6421531288520383068'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/10/multicast-technology.html' title='Multicast Technology'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-RTTc4l_elM/TLOhcIXWEqI/AAAAAAAAALw/OwkCscoKHy8/s72-c/computer-doctor.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-8333390945017203887</id><published>2010-11-14T18:23:00.000-08:00</published><updated>2010-11-22T22:38:35.131-08:00</updated><title type='text'>Trojan.Win32.FraudPack.bkhe</title><content type='html'>&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This Trojan has a malicious payload. It is a Windows dynamic link library (DLL) file. It is 361216 bytes in size.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once launched, the program will display a message stating that the computer has been infected by malicious programs:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/TOCaY44GJhI/AAAAAAAAANw/n2M87scvFRA/s1600/1.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 338px; height: 103px;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/TOCaY44GJhI/AAAAAAAAANw/n2M87scvFRA/s400/1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597294040917522" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The message is displayed even if there are no other malicious programs on the computer.&lt;br /&gt;&lt;br /&gt;If the user clicks the message, the program will display a license agreement in a new window:&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCaiZEFXMI/AAAAAAAAAN4/rEAs3k3AwCk/s1600/2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 186px;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCaiZEFXMI/AAAAAAAAAN4/rEAs3k3AwCk/s400/2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597457299954882" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The program then starts to load a fake antivirus solution without waiting for the user’s consent:&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCavARWX3I/AAAAAAAAAOA/ndFOsrGYIuo/s1600/3.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 186px;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCavARWX3I/AAAAAAAAAOA/ndFOsrGYIuo/s400/3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597673983008626" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is downloaded from one of the following addresses (depending on the file which contains the malicious program): &lt;br /&gt;&lt;br /&gt;http://searchbad.org&lt;br /&gt;http://searchfinddeliver.org&lt;br /&gt;http://finderwid.org&lt;br /&gt;http://searchannoying.org&lt;br /&gt;http://fastoutostop.com&lt;br /&gt;&lt;br /&gt;The following files are downloaded: &lt;br /&gt;&lt;br /&gt;/avt/avt_db&lt;br /&gt;/avt/avt_ext&lt;br /&gt;/avt/avt_hook&lt;br /&gt;/avt/avt_un&lt;br /&gt;/avt/avt_main&lt;br /&gt;&lt;br /&gt;The downloaded program is then installed into the directory: &lt;br /&gt;&lt;br /&gt;%ProgramFiles%\AnVi&lt;br /&gt;&lt;br /&gt;In order to ensure that it is launched automatically when the system is rebooted, the Trojan adds a link to the program which has just been installed to the system registry autorun key: &lt;br /&gt;&lt;br /&gt;[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"Antivirus"="%ProgramFiles%\AnVi\avt.exe\ -noscan"&lt;br /&gt;&lt;br /&gt;At the time of writing the following program could be downloaded and installed from the above addresses: &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCbMpfc2NI/AAAAAAAAAOo/yatMHWldKhE/s1600/4.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/TOCbMpfc2NI/AAAAAAAAAOo/yatMHWldKhE/s400/4.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539598183264213202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This program informs the user of the presence of various malicious programs in the system even if there are no such programs on the computer. In addition, it displays alerts about a network attack on the computer and the existence of a keylogger in the system:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/TOCa4pohavI/AAAAAAAAAOQ/2kdc9dBOmRM/s1600/5.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 256px; height: 344px;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/TOCa4pohavI/AAAAAAAAAOQ/2kdc9dBOmRM/s400/5.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597839704877810" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/TOCa9IFt0QI/AAAAAAAAAOY/xZ4-x70T3Qg/s1600/6.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 309px;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/TOCa9IFt0QI/AAAAAAAAAOY/xZ4-x70T3Qg/s400/6.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597916599865602" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The program states that the full version has to be activated in order to remove these supposed “threats”. The user is prompted to make an electronic transaction using a bank card.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/TOCbA0SMVdI/AAAAAAAAAOg/wCU_XjfBdE0/s1600/7.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 311px;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/TOCbA0SMVdI/AAAAAAAAAOg/wCU_XjfBdE0/s400/7.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5539597980002964946" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The program also prevents Windows Task Manager from being launched by modifying the following system registry key values: &lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;"DisableTaskMgr"=dword:00000001&lt;br /&gt;[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]&lt;br /&gt;"DisableTaskMgr"=dword:00000001&lt;br /&gt;In addition, the malicious program creates the following system registry key: &lt;br /&gt;[HKLM\SOFTWARE\AnVi]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Remove&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: &lt;br /&gt;&lt;br /&gt;1. Delete the original malware file which is usually located in the &lt;br /&gt;%TEMP%&lt;br /&gt;folder named as &lt;br /&gt;eapp32hst.dll&lt;br /&gt;&lt;br /&gt;2. Enable the launch of Task Manager by restoring the following system registry key values: &lt;br /&gt;&lt;br /&gt;3. [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]&lt;br /&gt;4. "DisableTaskMgr"=dword:00000000&lt;br /&gt;5. [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]&lt;br /&gt;6. "DisableTaskMgr"=dword:00000000&lt;br /&gt;7. Use Task Manager to terminate the process. &lt;br /&gt;8. Delete the &lt;br /&gt;&lt;br /&gt;%ProgramFiles%\AnVi&lt;br /&gt;folder with all its contents. &lt;br /&gt;&lt;br /&gt;9. Delete the following system registry key parameters: &lt;br /&gt;10. [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;11. "Antivirus"="%ProgramFiles%\AnVi\avt.exe\ -noscan"&lt;br /&gt;12. [HKLM\SOFTWARE\AnVi]&lt;br /&gt;13. Delete all files from the %Temp% directory.&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/160x600.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-8333390945017203887?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/8333390945017203887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=8333390945017203887' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/8333390945017203887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/8333390945017203887'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/11/trojanwin32fraudpackbkhe.html' title='Trojan.Win32.FraudPack.bkhe'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-RTTc4l_elM/TOCaY44GJhI/AAAAAAAAANw/n2M87scvFRA/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-5259164288209250245</id><published>2010-11-14T18:08:00.000-08:00</published><updated>2010-11-22T22:39:14.620-08:00</updated><title type='text'>Rootkit.Win32.Stuxnet.a</title><content type='html'>&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;It is a rootkit which is designed to launch malicious code in the user’s system. It is an NT kernel mode driver. It is 26616 bytes in size.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Infection&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The rootkit copies its executable file as: &lt;br /&gt;%System%\drivers\mrxcls.sys&lt;br /&gt;&lt;br /&gt;In order to ensure that it is launched automatically when the system is rebooted, the rootkit creates the following service registry key: &lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls]&lt;br /&gt;"Description"="MRXCLS"&lt;br /&gt;"DisplayName"="MRXCLS"&lt;br /&gt;"ErrorControl"=dword:00000000&lt;br /&gt;"Group"="Network"&lt;br /&gt;"ImagePath"="\\??\\%System%\Drivers\\mrxcls.sys"&lt;br /&gt;"Start"=dword:00000001&lt;br /&gt;"Type"=dword:00000001&lt;br /&gt;&lt;br /&gt;It creates the file: &lt;br /&gt;&lt;br /&gt;%System%\drivers\mrxnet.sys&lt;br /&gt;&lt;br /&gt;– 17400 bytes, defined as Rootkit.Win32.Stuxnet.b &lt;br /&gt;&lt;br /&gt;To ensure that it is launched automatically when the system is rebooted, the rootkit creates the following service registry key: &lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet]&lt;br /&gt;"Description"="MRXCLS"&lt;br /&gt;"DisplayName"="MRXNET"&lt;br /&gt;"ErrorControl"=dword:00000000&lt;br /&gt;"Group"="Network"&lt;br /&gt;"ImagePath"="\\??\\%System%\Drivers\\mrxnet.sys"&lt;br /&gt;"Start"=dword:00000001&lt;br /&gt;"Type"=dword:00000001&lt;br /&gt;&lt;br /&gt;It also creates the following files: &lt;br /&gt;&lt;br /&gt;%windir%\inf\mdmcpq3.pnf  - 4633 bytes.&lt;br /&gt;%windir%\inf\mdmeric3.pnf  - 90 bytes.&lt;br /&gt;%windir%\inf\oem6c.pnf  - 323848 bytes.&lt;br /&gt;%windir%\inf\oem7a.pnf – 498176 bytes.&lt;br /&gt;which contain the code and encrypted rootkit data. &lt;br /&gt;&lt;br /&gt;The rootkit spreads via removable USB devices exploiting the zero-day vulnerability CVE-2010-2568 in LNK files (for more details see here).&lt;br /&gt;&lt;br /&gt;For this purpose the malicious code running in the services.exe process monitors the connection of new USB storage devices to the system and if a connection is detected, creates the following files in the root folder of the device: &lt;br /&gt;&lt;br /&gt;~wtr4132.tmp&lt;br /&gt;– 513536 bytes, identified as Trojan-Dropper.Win32.Stuxnet.a &lt;br /&gt;&lt;br /&gt;~wtr4141.tmp&lt;br /&gt;– 25720 bytes, identified as Trojan-Dropper.Win32.Stuxnet.b &lt;br /&gt;&lt;br /&gt;These DLL files are downloaded when the vulnerability is exploited and install the rootkit on the system. Together with these files the shortcuts to the vulnerability are placed in the root of the infected disk: &lt;br /&gt;&lt;br /&gt;"Copy of Shortcut to.lnk" &lt;br /&gt;"Copy of Copy of Shortcut to.lnk" &lt;br /&gt;"Copy of Copy of Copy of Shortcut to.lnk" &lt;br /&gt;"Copy of Copy of Copy of Copy of Shortcut to.lnk"&lt;br /&gt;&lt;br /&gt;The files are 4171 bytes in size and are detected as Trojan.WinLnk.Agent.i. The vulnerability will be exploited if the user attempts to view the contents of the removable media’s root directory using the file manager with file icons enabled. Once the vulnerability is exploited the rootkit is activated, which instantaneously hides the malicious files. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The rootkit is designed to inject the malicious code into user mode processes. The rootkit downloads the DLL dynamic library to the following system processes:&lt;br /&gt; &lt;br /&gt;svchost.exe&lt;br /&gt;services.exe&lt;br /&gt;lsass.exe&lt;br /&gt;&lt;br /&gt;After this DLLs are displayed in their module lists with the following names: &lt;br /&gt;kernel32.dll.aslr.&lt;br /&gt;shell32.dll.aslr.&lt;br /&gt;&lt;br /&gt;Where rnd stands for a random hexadecimal number. The code being injected is contained in the file: &lt;br /&gt;&lt;br /&gt;%WinDir%\inf\oem7A.PNF&lt;br /&gt;It is encrypted. &lt;br /&gt;&lt;br /&gt;The injected code contains the main functionality of this malicious program. This includes: &lt;br /&gt;&lt;br /&gt;• Propagation via removable media. &lt;br /&gt;• Monitoring of the Siemens Step7 system. For this purpose the rootkit driver injects its intermediary library to the s7tgtopx.exe process instead of the original s7otbxsx.dll, which emulates the work of the following API functions: &lt;br /&gt;• s7_event&lt;br /&gt;• s7ag_bub_cycl_read_create&lt;br /&gt;• s7ag_bub_read_var&lt;br /&gt;• s7ag_bub_write_var&lt;br /&gt;• s7ag_link_in&lt;br /&gt;• s7ag_read_szl&lt;br /&gt;• s7ag_test&lt;br /&gt;• s7blk_delete&lt;br /&gt;• s7blk_findfirst&lt;br /&gt;• s7blk_findnext&lt;br /&gt;• s7blk_read&lt;br /&gt;• s7blk_write&lt;br /&gt;• s7db_close&lt;br /&gt;• s7db_open&lt;br /&gt;• s7ag_bub_read_var_seg&lt;br /&gt;• s7ag_bub_write_var_seg&lt;br /&gt;collecting various information on the work of the system. &lt;br /&gt;• Performing SQL requests. The rootkit receives a list of computers in the local network and checks if the Microsoft SQL server, which services the visualization system for Siemens WinCC operational processes, is launched on any of them. If the server is found, the malware attempts to log in to the database using the WinCCConnect/2WSXcder username and password and then tries to acquire data from the following tables:&lt;br /&gt; &lt;br /&gt;• MCPTPROJECT&lt;br /&gt;• MCPTVARIABLEDESC&lt;br /&gt;• MCPVREADVARPERCON&lt;br /&gt;• It collects information from files with the extensions: &lt;br /&gt;• *.S7P&lt;br /&gt;• *.MCP&lt;br /&gt;• *.LDF&lt;br /&gt;&lt;br /&gt;which are created using Siemens Step7. The entire computer hard drive is searched for the files. &lt;br /&gt;&lt;br /&gt;• It sends the collected data via the Internet to the cybercriminals’ servers in encrypted format. &lt;br /&gt;&lt;br /&gt;The rootkit file is signed with the digital signature of Realtek Semiconductor Corp. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Remove Virus&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: &lt;br /&gt;&lt;br /&gt;1. Delete the original rootkit file (the location will depend on how the program originally penetrated the victim machine). &lt;br /&gt;2. Delete the system registry keys &lt;br /&gt;3. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet]&lt;br /&gt;4. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls]&lt;br /&gt;5. Delete the following files: &lt;br /&gt;6. %System%\drivers\mrxnet.sys&lt;br /&gt;7. %System%\drivers\mrxcls.sys&lt;br /&gt;8. %windir%\inf\mdmcpq3.pnf &lt;br /&gt;9. %windir%\inf\mdmeric3.pnf&lt;br /&gt;10. %windir%\inf\oem6c.pnf &lt;br /&gt;11. %windir%\inf\oem7a.pnf&lt;br /&gt;12. Reboot the computer &lt;br /&gt;13. Disable the display of icons in the file manager to avoid repeated infection. &lt;br /&gt;14. Delete the following files from removable media if there are any: &lt;br /&gt;15. "Copy of Shortcut to.lnk" &lt;br /&gt;16. "Copy of Copy of Shortcut to.lnk" &lt;br /&gt;17. "Copy of Copy of Copy of Shortcut to.lnk" &lt;br /&gt;18. "Copy of Copy of Copy of Copy of Shortcut to.lnk"&lt;br /&gt;19. ~wtr4132.tmp&lt;br /&gt;20. ~wtr4141.tmp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/125x125.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-5259164288209250245?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/5259164288209250245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=5259164288209250245' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5259164288209250245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5259164288209250245'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/11/rootkitwin32stuxneta.html' title='Rootkit.Win32.Stuxnet.a'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-599528440625461403</id><published>2010-10-25T17:29:00.000-07:00</published><updated>2010-10-25T17:33:43.826-07:00</updated><title type='text'>D-link DIR-300 Wireless G Router (For Sale)</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhxkXk73I/AAAAAAAAANY/iFngGDALNP4/s1600/Image0428.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhxkXk73I/AAAAAAAAANY/iFngGDALNP4/s400/Image0428.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5532146327731105650" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYht-_7GnI/AAAAAAAAANQ/A3Ve6Y5Cgbw/s1600/Image0427.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYht-_7GnI/AAAAAAAAANQ/A3Ve6Y5Cgbw/s400/Image0427.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5532146266160175730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhpLnKVpI/AAAAAAAAANI/gRRjax4bQps/s1600/Image0426.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhpLnKVpI/AAAAAAAAANI/gRRjax4bQps/s400/Image0426.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5532146183646631570" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhhVjxKsI/AAAAAAAAANA/ysW5sgaEelc/s1600/Image0424.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 400px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhhVjxKsI/AAAAAAAAANA/ysW5sgaEelc/s400/Image0424.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5532146048877800130" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/TMYhbsBDsTI/AAAAAAAAAM4/iBQNs0OGmA4/s1600/Image0423.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 400px;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/TMYhbsBDsTI/AAAAAAAAAM4/iBQNs0OGmA4/s400/Image0423.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5532145951827013938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;For Sale - RM 75&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;- IEEE 802.11b/g Wireless LAN Compliant&lt;br /&gt;- Built-in 4 port switch&lt;br /&gt;- Advanced firewall &amp; Security&lt;br /&gt;- Advanced scheduling &amp; user level control&lt;br /&gt;- Supports VPN passthrough&lt;br /&gt;- WPA (TKIP) &amp; WPA2 (AES) support&lt;br /&gt;- Interactive install guide&lt;br /&gt;- UPnP support&lt;br /&gt;&lt;br /&gt;Call/SMS :&lt;br /&gt;&lt;br /&gt;Razi - 014 8736005&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-599528440625461403?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/599528440625461403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=599528440625461403' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/599528440625461403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/599528440625461403'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/10/d-link-dir-300-wireless-g-router-for.html' title='D-link DIR-300 Wireless G Router (For Sale)'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-RTTc4l_elM/TMYhxkXk73I/AAAAAAAAANY/iFngGDALNP4/s72-c/Image0428.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-1312180584341419007</id><published>2010-10-06T19:29:00.001-07:00</published><updated>2010-11-22T22:41:15.416-08:00</updated><title type='text'>Virus change your data into shortcut (Shortcut Virus)</title><content type='html'>This Virus Widely spread within Universiti Malaysia Sabah Main Campus. It was built using Visual Basic Programming language that take advantage of 'autorun' function inside Microsoft Windows.&lt;br /&gt;&lt;br /&gt;This virus will automatically close the application such as Internet Explorer, Task Manager and most of your .exe file cannot be open even your antivirus.&lt;br /&gt;&lt;br /&gt;It spread rapidly because we always share file using ThumbDrive. When your thumbdrive infected with the virus and you plug in into a Computer. That Computer will get Infected too. then, When another ThumbDrive plugged in to that Computer, that Thumbdrive will get infect. All data inside will be hidden &amp; A shortcut that link to the virus file will appear. Clever virus.&lt;br /&gt;&lt;br /&gt;This virus trigger a panic especially for them that need the actual data inside the thumbdrive.&lt;br /&gt;&lt;br /&gt;Most of them who infected with the virus bring their computer to computer shop for reformatting the Operating System (Windows). this computer virus infection &lt;span style="font-weight:bold;"&gt;can be&lt;/span&gt; disinfect without reformatting your Computer.&lt;br /&gt;&lt;br /&gt;I know a personal that can help you remove the infection without reformatting your computer. &lt;span style="font-weight:bold;"&gt;With a Charge as low as RM25&lt;/span&gt;, he can remove it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;If u interested, Please Call Mr. Razi - 014 8736005&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/160x600.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-1312180584341419007?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/1312180584341419007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=1312180584341419007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1312180584341419007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1312180584341419007'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2010/10/virus-change-your-data-into-shortcut.html' title='Virus change your data into shortcut (Shortcut Virus)'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-2752917743048035068</id><published>2009-05-19T23:24:00.000-07:00</published><updated>2009-06-03T19:59:10.261-07:00</updated><title type='text'>Worm.Win32.Kido @ Conficker Worm</title><content type='html'>also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008. The worm uses a combination of advanced malware techniques which has made it difficult to counter, and has since spread rapidly into what is now believed to be the largest computer worm infection since the 2003 SQL Slammer.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html"&gt;check whether Your computers are infected with Conficker Worm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4shared.com/file/109752542/a543e000/Full_Virus_Report_Net-WormWin32Kido.html" target=_blank&gt;Download Full Virus Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4shared.com/file/109753060/c70c4620/klwk.html" target=_blank&gt;Download Kido Malware Remover&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-2752917743048035068?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/2752917743048035068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=2752917743048035068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2752917743048035068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2752917743048035068'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/05/conficker-worm.html' title='Worm.Win32.Kido @ Conficker Worm'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-7875311171096866389</id><published>2009-04-26T20:08:00.000-07:00</published><updated>2009-04-27T04:07:08.204-07:00</updated><title type='text'>Sality Virus Removal</title><content type='html'>&lt;strong&gt;Description: &lt;/strong&gt;&lt;br /&gt;Sality is a family of file infecting viruses that spread by infecting exe and scr files. The virus also includes an autorun worm component that allows it to spread to any removable or discoverable drive. In addition, Sality includes a downloader trojan component that installs additional malware via the Web.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Symptom: &lt;/strong&gt;&lt;br /&gt;As with many other malware, Sality disables antivirus software and prevents access to certain antivirus and security websites. Sality can also prevent booting into Safe Mode and may delete security-related files found on infected systems. To spread via the autorun component, Sality generally drops a .cmd, .pif, and .exe to the root of discoverable drives, along with an autorun.inf file which contains instructions to load the dropped file(s) when the drive is accessed.&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Removal&lt;/strong&gt;&lt;br /&gt;- I managed to remove this virus using &lt;strong&gt;Kaspersky Virus Removal Tool &lt;/strong&gt;With &lt;strong&gt;Latest Virus Definition&lt;/strong&gt;.&lt;br /&gt;- U can easily Download this Tools From &lt;strong&gt;Kaspersky lab Website &lt;/strong&gt;Or From &lt;strong&gt;Softpedia.com&lt;/strong&gt; ... It's Free .. &lt;br /&gt;- just install the tools and run it ... &lt;br /&gt;BUT BE CAREFUL.. &lt;br /&gt;- when it detect the Sality Virus ... Please CHOOSE &lt;strong&gt;disinfect&lt;/strong&gt;.&lt;br /&gt;Never CHOOSE &lt;strong&gt;Delete&lt;/strong&gt;. or else all your program inside your PC will disappear because sality infect all your .EXE program files and system files.&lt;br /&gt;If u choose to delete, nothing is working on ur PC after that...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-7875311171096866389?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/7875311171096866389/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=7875311171096866389' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7875311171096866389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7875311171096866389'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/sality-virus-removal.html' title='Sality Virus Removal'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-574412344432607355</id><published>2009-04-24T18:02:00.000-07:00</published><updated>2009-04-24T18:22:15.857-07:00</updated><title type='text'>Restore printer Spool service after Bulubebek Infection</title><content type='html'>First Of all you need to remove the Bulubebek infection,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ladingmerah.blogspot.com/2009/03/virus-bulu-bebek-removal.html"&gt;&lt;em&gt;&lt;strong&gt;Click Here and Please follow this step&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;then after that,&lt;br /&gt;&lt;br /&gt;*let assume that the Bulubebek infection is clean and your PC is not infect with another virus*&lt;br /&gt;&lt;br /&gt;to restore your Print spool Service :- &lt;br /&gt;&lt;br /&gt;1. click &lt;strong&gt;Start&lt;/strong&gt; &gt; &lt;strong&gt;Run&lt;/strong&gt;&lt;br /&gt;2. type &lt;strong&gt;services.msc&lt;/strong&gt; and hit &lt;Enter&gt;&lt;br /&gt;3. On right Panel of Services, try to find &lt;strong&gt;Print Spooler&lt;/strong&gt; service and make sure it's Started.&lt;br /&gt;4. If the &lt;strong&gt;Print Spooler&lt;/strong&gt; service is not listed, &lt;br /&gt;5. click &lt;strong&gt;Start&lt;/strong&gt; &gt; &lt;strong&gt;Run&lt;/strong&gt;&lt;br /&gt;6. type &lt;strong&gt;regedit&lt;/strong&gt; and hit &lt;Enter&gt;&lt;br /&gt;7. On left panel of Registry Editor, Expand &lt;br /&gt;   HKEY_LOCAL_MACHINE &gt; SYSTEM &gt; CurrentControlSet &gt; Services &gt; Spooler&lt;br /&gt;&lt;br /&gt;8. on the right panel, you should see &lt;strong&gt;Start&lt;/strong&gt; and &lt;strong&gt;Type&lt;/strong&gt;. Delete both of this key.&lt;br /&gt;9. create new key by right clicking on the right panel, select &lt;strong&gt;New&lt;/strong&gt;&lt;br /&gt;10. Select &lt;strong&gt;DWORD Value&lt;/strong&gt;. rename it as &lt;strong&gt;Start&lt;/strong&gt;.&lt;br /&gt;11. Double click it and add value &lt;strong&gt;2&lt;/strong&gt; and base &lt;strong&gt;Hex&lt;/strong&gt;&lt;br /&gt;12. create new key by right clicking on the right panel, select &lt;strong&gt;New&lt;/strong&gt;&lt;br /&gt;13. Select &lt;strong&gt;DWORD Value&lt;/strong&gt;. rename it as &lt;strong&gt;Type&lt;/strong&gt;.&lt;br /&gt;14. Double click it and add value &lt;strong&gt;110&lt;/strong&gt; and base &lt;strong&gt;Hex&lt;/strong&gt;&lt;br /&gt;15. you should get like this :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SfJljVjvjgI/AAAAAAAAAKw/kmyBSuFbvE4/s1600-h/print+spool.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 277px;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SfJljVjvjgI/AAAAAAAAAKw/kmyBSuFbvE4/s400/print+spool.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5328432966889606658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;16. Reboot your PC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-574412344432607355?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/574412344432607355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=574412344432607355' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/574412344432607355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/574412344432607355'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/restore-printer-spool-service-after.html' title='Restore printer Spool service after Bulubebek Infection'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-RTTc4l_elM/SfJljVjvjgI/AAAAAAAAAKw/kmyBSuFbvE4/s72-c/print+spool.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-6287417264859310866</id><published>2009-04-24T17:06:00.000-07:00</published><updated>2009-06-03T20:48:23.839-07:00</updated><title type='text'>Restore Audio after Bulubebek Infection</title><content type='html'>First Of all you need to remove the Bulubebek infection,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ladingmerah.blogspot.com/2009/03/virus-bulu-bebek-removal.html"&gt;&lt;em&gt;&lt;strong&gt;Please follow this step&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;then after that,&lt;br /&gt;&lt;br /&gt;*let assume that the Bulubebek infection is clean and your PC is not infect with another virus*&lt;br /&gt;&lt;br /&gt;to restore your PC's audio :- &lt;br /&gt;&lt;br /&gt;1. click &lt;strong&gt;Start&lt;/strong&gt; &gt; &lt;strong&gt;Run&lt;/strong&gt;&lt;br /&gt;2. type &lt;strong&gt;services.msc&lt;/strong&gt; and hit &lt;Enter&gt;&lt;br /&gt;3. On right Panel of Services, try to find &lt;strong&gt;Windows Audio&lt;/strong&gt; service and make sure it's Started.&lt;br /&gt;4. If the &lt;strong&gt;Windows Audio&lt;/strong&gt; service is not listed, &lt;br /&gt;5. click &lt;strong&gt;Start&lt;/strong&gt; &gt; &lt;strong&gt;Run&lt;/strong&gt;&lt;br /&gt;6. type &lt;strong&gt;notepad&lt;/strong&gt; and hit &lt;Enter&gt;&lt;br /&gt;7. Copy the Script below and save it as &lt;strong&gt;audio.reg&lt;/strong&gt; (save it on c:\):-&lt;br /&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv]&lt;br /&gt;"DependOnService"=hex(7):50,00,6c,00,75,00,67,00,50,00,6c,00,61,00,79,00,00,00,\&lt;br /&gt;  52,00,70,00,63,00,53,00,73,00,00,00,00,00&lt;br /&gt;"Description"="Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start."&lt;br /&gt;"DisplayName"="Windows Audio"&lt;br /&gt;"ErrorControl"=dword:00000001&lt;br /&gt;"Group"="AudioGroup"&lt;br /&gt;"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\&lt;br /&gt;  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\&lt;br /&gt;  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\&lt;br /&gt;  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00&lt;br /&gt;"ObjectName"="LocalSystem"&lt;br /&gt;"Start"=dword:00000002&lt;br /&gt;"Type"=dword:00000020&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Parameters]&lt;br /&gt;"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\&lt;br /&gt;  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\&lt;br /&gt;  61,00,75,00,64,00,69,00,6f,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,\&lt;br /&gt;  00&lt;br /&gt;"ServiceDllUnloadOnStop"=dword:00000001&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AudioSrv\Enum]&lt;br /&gt;"0"="Root\\LEGACY_AUDIOSRV\\0000"&lt;br /&gt;"Count"=dword:00000001&lt;br /&gt;"NextInstance"=dword:00000001&lt;br /&gt;&lt;br /&gt;8. Run the file by double click it ( &lt;br /&gt;9. click &lt;strong&gt;Yes&lt;/strong&gt; &lt;br /&gt;10. Reboot your PC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4shared.com/file/109755620/8286a04a/audio.html"&gt;Download Audio.Reg&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-6287417264859310866?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/6287417264859310866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=6287417264859310866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6287417264859310866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6287417264859310866'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/restore-audio-after-bulubebek-infection.html' title='Restore Audio after Bulubebek Infection'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-3997068288948827973</id><published>2009-04-11T03:33:00.000-07:00</published><updated>2009-04-11T03:37:05.176-07:00</updated><title type='text'>2.BAT Cloaked Malware</title><content type='html'>&lt;strong&gt;File Behavior&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• The Process is packed and/or encrypted using a software packing process &lt;br /&gt;• Executes a Process &lt;br /&gt;• Writes to another Process's Virtual Memory (Process Hijacking) &lt;br /&gt;• This process creates other processes on disk &lt;br /&gt;• This Process Deletes Other Processes From Disk &lt;br /&gt;• Creates a new Background Service on the machine &lt;br /&gt;• Injects code into other processes &lt;br /&gt;• Copies files &lt;br /&gt;• Registers a Dynamic Link Library File &lt;br /&gt;&lt;br /&gt;2.BAT also:&lt;br /&gt;&lt;br /&gt;• Created as a process on disk &lt;br /&gt;• Deleted as a process from disk &lt;br /&gt;• Executed as a Process &lt;br /&gt;• Has code inserted into its Virtual Memory space by other programs &lt;br /&gt;• Added as a Registry auto start to load Program on Boot up &lt;br /&gt;&lt;br /&gt;also using the following file names: &lt;br /&gt;&lt;br /&gt;• 1.BAT &lt;br /&gt;• 44546234.SVD &lt;br /&gt;• 3.BAT &lt;br /&gt;• 52632502.SVD &lt;br /&gt;• OLHRWEF.EXE &lt;br /&gt;• 32616742.SVD &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;File Activity&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;One or more files with the name 2.BAT creates, deletes, copies or moves the following files and folders:&lt;br /&gt;&lt;br /&gt;• Creates c:\windows\system32\drivers\klif.sys &lt;br /&gt;• Deletes c:\windows\system32\drivers\klif.sys &lt;br /&gt;• Deletes c:\windows\system32\olhrwef.exe &lt;br /&gt;• Deletes c:\windows\system32\nmdfgds0.dll &lt;br /&gt;• Creates c:\windows\system32\nmdfgds0.dll &lt;br /&gt;• Deletes c:\2.ba &lt;br /&gt;• Copies filec:\windows\system32\olhrwef.exe to c:\2.ba &lt;br /&gt;• Deletes c:\autorun.in &lt;br /&gt;• Creates c:\autorun.in &lt;br /&gt;• Deletes d:\2.ba &lt;br /&gt;• Copies filec:\windows\system32\olhrwef.exe to d:\2.ba &lt;br /&gt;• Deletes d:\autorun.in &lt;br /&gt;• Creates d:\autorun.in &lt;br /&gt;• Deletes c:\docume~1\user\locals~1\temp\help1.rar &lt;br /&gt;• Creates c:\docume~1\user\locals~1\temp\help1.rar &lt;br /&gt;• Creates c:\docume~1\user\locals~1\temp\help.exe &lt;br /&gt;• Deletes c:\docume~1\user\locals~1\temp\help.exe &lt;br /&gt;• Copies filec:\docume~1\user\locals~1\temp\help.exe to c:\windows\system32\olhrwef.exe &lt;br /&gt;• Deletes c:\windows\system32\nmdfgds1.dll &lt;br /&gt;• Creates c:\windows\system32\nmdfgds1.dll &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Registry Activity&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;One or more files with the name 2.BAT creates or modifies the following registry keys and values:&lt;br /&gt;&lt;br /&gt;• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run cdoosoft C:\WINDOWS\system32\olhrwef.exe &lt;br /&gt;&lt;br /&gt;• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Hidden value: &lt;br /&gt;&lt;br /&gt;• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ShowSuperHidden value: &lt;br /&gt;&lt;br /&gt;• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NoDriveTypeAutoRun [REG_DWORD, value: 00000091] &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Website Activity&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;One or more files with the name 2.BAT interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.&lt;br /&gt;&lt;br /&gt;• TCP:127.0.0.1:1056 Port:17 &lt;br /&gt;• Port 80 IP:221.1.204.243 &lt;br /&gt;• TCP:127.0.0.1:1064 Port:17&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-3997068288948827973?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/3997068288948827973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=3997068288948827973' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3997068288948827973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3997068288948827973'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/2bat-cloaked-malware.html' title='2.BAT Cloaked Malware'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-1025904839420523078</id><published>2009-04-03T05:29:00.002-07:00</published><updated>2009-04-03T05:30:27.780-07:00</updated><title type='text'>TCP/IP</title><content type='html'>Also Known as Internet Protocol suite or Networking Model. TCP/IP model Is Set of communications protocols used for the Internet and other similar networks. Divided to 4 layer protocol.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/STOBpQp7spI/AAAAAAAAAI8/EKf_C1c_qW4/s1600-h/tcpip.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 201px; height: 353px;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/STOBpQp7spI/AAAAAAAAAI8/EKf_C1c_qW4/s400/tcpip.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274702134426448530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Application Layer Protocol&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/STOBzH29GoI/AAAAAAAAAJE/IcsqdiVVFHw/s1600-h/apllication.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 328px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/STOBzH29GoI/AAAAAAAAAJE/IcsqdiVVFHw/s400/apllication.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274702303863839362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* Computer program will talk to the Application layer. Each kind of program talks to a different Application protocol, depending on the program purpose such as SMTP or FTP. &lt;br /&gt;&lt;br /&gt;* After processing the program request, the protocol on the Application layer will talk to another protocol from the Transport layer, usually TCP. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Transport Layer&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/STOCRLNSnaI/AAAAAAAAAJM/hOGkz1rbG5U/s1600-h/transopt.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 254px;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/STOCRLNSnaI/AAAAAAAAAJM/hOGkz1rbG5U/s400/transopt.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274702820158905762" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* Transport Layer in charge of getting data sent by the upper layer, dividing them into packets and sending them to the layer below.&lt;br /&gt;&lt;br /&gt;* Also, during data reception, this layer is in charge of putting the packets received from the network in order and also checking if the contents of the packets are intact. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Internet Layer&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/STOC9ObwUeI/AAAAAAAAAJc/h_bojjAtT90/s1600-h/ip2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 250px;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/STOC9ObwUeI/AAAAAAAAAJc/h_bojjAtT90/s400/ip2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274703576939123170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/STOC2wZmfTI/AAAAAAAAAJU/VKBIjISnqug/s1600-h/ip1.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 208px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/STOC2wZmfTI/AAAAAAAAAJU/VKBIjISnqug/s400/ip1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274703465797811506" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* IP (Internet Protocol) gets the packets received from the Transport layer and adds virtual address information. &lt;br /&gt;     - the address of the computer that is sending data. &lt;br /&gt;     - the address of the computer that will receive this data. &lt;br /&gt;&lt;br /&gt;* Then the packet is sent to the lower layer.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Network Access&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/STODT9YnsLI/AAAAAAAAAJk/jMXQ4PP3qsM/s1600-h/NA.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 242px;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/STODT9YnsLI/AAAAAAAAAJk/jMXQ4PP3qsM/s400/NA.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5274703967499563186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* The Network Access Layer will get the packets sent and send them over the network.&lt;br /&gt;  &lt;br /&gt;                  OR&lt;br /&gt;&lt;br /&gt;* Receive the packets from the network and send it to Internet Layer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-1025904839420523078?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/1025904839420523078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=1025904839420523078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1025904839420523078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1025904839420523078'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/tcpip.html' title='TCP/IP'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-RTTc4l_elM/STOBpQp7spI/AAAAAAAAAI8/EKf_C1c_qW4/s72-c/tcpip.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-5124880586643840797</id><published>2009-04-03T05:29:00.001-07:00</published><updated>2009-04-03T05:29:42.775-07:00</updated><title type='text'>Computer Operating System</title><content type='html'>&lt;strong&gt;Definisi&lt;/strong&gt; &lt;br /&gt; &lt;br /&gt;Koleksi program2 komputer yg menyatukan sumber2 hardware komputer tersebut (tetikus, pencetak, peranti storan dan ingatan) &amp; membolehkan sumber2 hardware sentiasa bersedia digunakan oleh pengguna.&lt;br /&gt;&lt;br /&gt;Membenarkan pengguna  mengakses komputer secara produktif, tepat pada masa &amp; efisyen.&lt;br /&gt;&lt;br /&gt;Dgn kata lain, bertindak sbg org tengah di antara pengguna dgn sistem komputer.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Konsep&lt;/strong&gt; &lt;br /&gt;&lt;br /&gt;Berfungsi sbg pengurus sistem, mengawal setiap h/ware &amp; software serta bertindak sbg antaramuka antara pengguna &amp; sistem.&lt;br /&gt;&lt;br /&gt;OS mengandungi koleksi2 program di mana ianya bekerjasama secara berkumpulan utk m’laksanakan pelbagai jenis tugas.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Fungsi OS&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/SMRtYzZWkyI/AAAAAAAAAGM/Fyxi6cyrDJ4/s1600-h/fungsi+OS.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/SMRtYzZWkyI/AAAAAAAAAGM/Fyxi6cyrDJ4/s400/fungsi+OS.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243436139046933282" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Menyediakan antaramuka kpd penggun utk menggunakan komputer.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Terdpt 2 jenis antaramuka : antaramuka baris-perintah dan antaramuka grafik.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;a)Antaramuka baris-perintah : pengguna perlu menaip perintah. OS yg b’asaskan baris perintah ialah MS-DOS. &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;       Cth : C:\&gt; copy c:\myfile a:\yourfile&lt;br /&gt;&lt;br /&gt;       Baris perintah mengarahkan komputer utk menyalin satu fail dr cakera keras C ke cakera liut A.&lt;br /&gt; Antaramuka baris perintah lebih sesuai utk pengguna mahir.&lt;br /&gt; OS spt Unix dan Linux juga menggunakan baris perintah.&lt;br /&gt; Antaramuka baris perintah semakin kurang digunakan ttp masih digunakan dlm sistem kerangka utama * sistem pelayan yg menggunakan platform Unix.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;b)Antaramuka grafik : bergantung kpd perisian berasaskan grafik yg membolehkan teks disepadukan dgn imej grafik.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Antara komponen dlm antaramuka grafik ialah icon, kotak dialog &amp; menu.&lt;br /&gt; Cth perisian yg menggunakan antaramuka grafik ialah BeOS, Macintosh dan Windows.&lt;br /&gt; Pengguna GUI berinteraksi dgn OS dan lain2 pakej perisian dgn menggunakan peranti penuding spt tetikus dan papan kekunci utk memasukkan arahan.&lt;br /&gt; GUI byk memudahkan pengguna krn tdk perlu utk menghafal dan memasukkan semua arahan rumit spt antaramuka baris perintah.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Mengurus Perkakasan :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Perkakasan adalah seperti peranti input (tetikus, papan kekunci, pengimbas), peranti output (pencetak, skrin, audio, video), storan sekunder (cakera keras) dan ingatan utama (RAM)&lt;br /&gt;&lt;br /&gt;OS berfungsi utk menyelaras dan menjejaki/mengikuti aturcara mana yg memerlukan perkakasan mana.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Menguruskan sistem fail cakera keras&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;OS menguruskan perjalanan data dari komponen input (papan kekunci) kepada output (monitor) &lt;br /&gt;&lt;br /&gt;OS menguruskan perjalanan data dari storan sekunder kepada ingatan utama serta dari ingatan utama ke storan sekunder.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Menguruskan proses atau perjalanan perisian lain :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Andaikan perlaksanaan satu perisian sbg satu proses. Jika pengguna menggunakan 3 perisian serentak (cth menghasilkan grafik dgn Adobe Photoshop, melayari Internet dgn IE &amp; mendengar muzik menggunakan Windows Media Player) maka terdapat 3 proses yg berbeza sedang dilaksanakan dlm komputer.&lt;br /&gt;&lt;br /&gt;OS bertanggungjawab agar ketiga-tiga proses tersebut berjalan lancar dan tdk berlaku apa2 yg boleh menyebabkan pemprosesan komputer tergantung.&lt;br /&gt;&lt;br /&gt; Fungsi OS yang lain :&lt;br /&gt;&lt;br /&gt;1. Utk membantu interaksi antara komputer dan pengguna.&lt;br /&gt;2. Utk membantu komunikasi antara komponen2 komputer&lt;br /&gt;3. Utk mengurangkan masa bg menjalankan arahan pengguna.&lt;br /&gt;4. Utk mengoptimakan penggunaan sumber sistem komputer&lt;br /&gt;5. Utk menjejak semua fail dlm storan cakera&lt;br /&gt;6. Utk memastikan keselamatan kpd sistem komputer&lt;br /&gt;7. Utk memantau semua aktiviti sistem dan memberi amaran kpd pengguna tentang sebarang masalah pd sistem.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ciri-ciri OS&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. Multitugasan&lt;br /&gt;2. Multipengguna&lt;br /&gt;3. Multipemproses&lt;br /&gt;4. Kelompok/Batch&lt;br /&gt;5. Ingatan Maya&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Multitugasan&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Keupayaan sesuatu sistem komputer utk mengendalikan lebih dr satu tugasan pd satu masa scr serentak.&lt;br /&gt; Membolehkan seorg pengguna melaksanakan tugasan baru tanpa perlu keluar dr tugasan yg sedang dilaksanakan dan menggunakan hasil dari tugasan kedua dalam tugasan pertama. &lt;br /&gt; Cth : pengguna boleh menghasilkan carta dlm MS Excel semasa menggunakan MS Word dan memasukkan carta tersebut dlm dokumen yg sedang ditulis iaitu dlm MS Word.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-5124880586643840797?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/5124880586643840797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=5124880586643840797' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5124880586643840797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5124880586643840797'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/computer-operating-system.html' title='Computer Operating System'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_-RTTc4l_elM/SMRtYzZWkyI/AAAAAAAAAGM/Fyxi6cyrDJ4/s72-c/fungsi+OS.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-4850355066867902972</id><published>2009-04-03T05:27:00.000-07:00</published><updated>2009-04-03T05:28:44.263-07:00</updated><title type='text'>Computer External Storage</title><content type='html'>&lt;strong&gt;STORAGE DEVICES&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Optical Drive&lt;br /&gt;• Hard Drive&lt;br /&gt;• Floppy Drive&lt;br /&gt;• Network Attachment Storage (NAS)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;OPTICAL DRIVE&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• CD-ROM&lt;br /&gt;• CD-R&lt;br /&gt;• CD-RW&lt;br /&gt;• DVD-ROM&lt;br /&gt;• DVD-R&lt;br /&gt;• DVD-RW&lt;br /&gt;&lt;br /&gt;Both technologies (CD-R and CD-RW) use a small laser in the drive to record. &lt;br /&gt;&lt;br /&gt;New on the market are CD-Rs that burn reliably at up to 16X speed and discs that can hold up to 700MB of data, rather than the more common 650MB. &lt;br /&gt;&lt;br /&gt;When buying media, make sure that you match the media speed to that of your drive. Trying to burn an 8X CD-R at 12X is a sure way to ruin a disc. &lt;br /&gt;&lt;br /&gt;Most CD-RW drives come with both software to burn a CD-R and packet-writing software, which lets you use a CD-RW just the same way that you use a hard or floppy disk, dragging and dropping files to the disc.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CD-ROM&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• uses laser technology.&lt;br /&gt;• It contains of text, graphic, video and sound.&lt;br /&gt;• Read Only means that data cannot be erased or modified.&lt;br /&gt;• For a computer to read the items on a CD-ROM, you must place it into a CD-ROM drive.&lt;br /&gt;• A CD-ROM can hold up to 700 MB of data.&lt;br /&gt;• CD-ROM drive speed influence the quality of display and it is measured by its data transfer rate, which is the time it takes the drive to transmit data from CD-ROM. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CD-RECORDABLE (CD-R)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Allows the user to read data on all format CD.&lt;br /&gt;• Allows user to write on a compact disc using own computer. &lt;br /&gt;• Data can be written on discs in stages. &lt;br /&gt;• Stored data cannot be deleted. User must have CD-R software and also CD-R drive to use it.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CD-REWRITABLE (CD-RW)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Allows the user to read data on all format CD.&lt;br /&gt;• Allows the user to write on multiple times. &lt;br /&gt;• To use it user must have CD-RW software and CD-RW drive.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;DVD-ROM&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• A high-capacity compact disc ranges 4.7 GB to 17 GB data. Suitable to store large items such as video.&lt;br /&gt;• In order to read a DVD-ROM the user must have a DVD-ROM drive or DVD player.&lt;br /&gt;&lt;br /&gt;• Finally, some DVD- ROMs are double-sided. The user must remove the DVD-ROM and turn it over to read the other side.&lt;br /&gt;• Available in a variety of formats, one of which stores digital or audio data.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;DVD- RECORDABLE (DVD-R)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Allows user write once on it and read it many times.&lt;br /&gt;• Specifications (e.g)&lt;br /&gt;• Capacity - 4.7GB&lt;br /&gt;• Speeds (DVD) - 2x write/ 1x rewrite/ 6x read&lt;br /&gt;• Speeds (CD) - 8x write/ 8x rewrite/ 24x read&lt;br /&gt;• Interface - IEEE 1394&lt;br /&gt;• Buffer Size - 2 MB&lt;br /&gt;• Access Time - 180-200 ms&lt;br /&gt;• Warranty - 1 Year&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;System Requirements:&lt;/strong&gt; &lt;br /&gt;(e.g)&lt;br /&gt;&lt;strong&gt;For Windows Users&lt;/strong&gt; &lt;br /&gt;•  800 MHz processor or greater &lt;br /&gt;•  128MB of RAM&lt;br /&gt;•  Built-in FireWire port &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;For Macintosh Users&lt;/strong&gt;&lt;br /&gt;•  G4 &lt;br /&gt;•  128MB of RAM&lt;br /&gt;•  Built-in FireWire port&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;HARD DRIVE&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Hard disks store the majority of information on today's modern computer. &lt;br /&gt;• Can be stored and delete.&lt;br /&gt;• The hard disk retains information stored on it, with or without power. &lt;br /&gt;• Hard Drive capacity is measured in GigaBytes, or 1 million megabytes (MB).&lt;br /&gt;• Hard Drives connect to the motherboard (or sometimes an expansion card) through one of two special interfaces: &lt;br /&gt;1. Integrated Drive Electronics (IDE) &lt;br /&gt;2. Small Computer Systems Interface (SCSI, pronounced "scuzzy").&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;How  a hard disk works&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Most hard disks have multiple platters stacked on top of one another and each platter has two read/write heads, one for each side. &lt;br /&gt;• The hard disk has arms that move the read/write heads to the proper location on the platter. &lt;br /&gt;• The location of the read/write heads often is referring to by its cylinder. Cylinder is the location of a single track through all platters. &lt;br /&gt;• While the computer is running, the platters in the hard disk rotate at a high rate of speed. Usually 5,400 to 7,200 revolutions per minute. &lt;br /&gt;• Access time is from 5 to 7 milliseconds, can be increased with disk caching. Cache Disk is a portion of memory that the CPU uses to store frequently accessed items. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SMRp610HLhI/AAAAAAAAAFY/_Fg6jX5ExPM/s1600-h/Cylender+On+Disk.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SMRp610HLhI/AAAAAAAAAFY/_Fg6jX5ExPM/s400/Cylender+On+Disk.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243432325765082642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;REMOVABLE HARD DISK&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Can be inserted and removed from a hard disk drive&lt;br /&gt;• Advantages:&lt;br /&gt;– Used to store larger files&lt;br /&gt;– To do backup&lt;br /&gt;– For data security issue, user can remove the hard disk and leaving no data on the computer for secret files. &lt;br /&gt;• Networks, minicomputers and mainframe computers often use disk packs. &lt;br /&gt;• Disk Packs is a collection of removable hard disks mounted in the same cabinet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Maintaining data stored on a hard disk   &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Hard disk came lasts somewhere between three and five years, although many last much longer with proper care. &lt;br /&gt;• To prevent the loss of items stored on a hard disk, you should perform preventative maintenance such as defragmenting or scanning the disk for errors.&lt;br /&gt;• Operating systems such as Windows XP provides many maintenance utilities. &lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;FLOPPY DISKS &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• A floppy or diskette is a portable, inexpensive storage medium that consists of a thin, circular, flexible plastic disk enclosed in a square-shaped plastic shell. &lt;br /&gt;• The term portable means the storage medium can be moved from one computer to another computer. &lt;br /&gt;Floppy disk drive is a device that can read from and write to a floppy disk. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRquSALp7I/AAAAAAAAAFg/1dN80LKwORs/s1600-h/Flopy.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRquSALp7I/AAAAAAAAAFg/1dN80LKwORs/s400/Flopy.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243433209505228722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SMRrXvA8sWI/AAAAAAAAAFw/lCsFJ5M1yIQ/s1600-h/Inside+flopy.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SMRrXvA8sWI/AAAAAAAAAFw/lCsFJ5M1yIQ/s400/Inside+flopy.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243433921667707234" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;HIGH-CAPACITY FLOPPY DISKS&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Can store large files containing graphics, audio or video.&lt;br /&gt;• To make a backup. Backup is a duplicate of an original file and can be used if the original is lost or damaged. &lt;br /&gt;• SuperDisk™ drive with capacity 120MB is developed by Imation.&lt;br /&gt;• Sony Electronics Inc. has developed HiFD™ (High Capacity FD) with capacity 200 MB.&lt;br /&gt;• Zip® drive developed by Iomega Corporation, with capacity 250 MB.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRrntkKRPI/AAAAAAAAAF4/0d3aUHz85OU/s1600-h/High+floppy.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRrntkKRPI/AAAAAAAAAF4/0d3aUHz85OU/s400/High+floppy.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243434196156433650" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Network Attachment Storage (NAS)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Traditional methods of solving a problem of shortage of disc space (extension of a capacity of a server's disc subsystem or a purchase of a new server)&lt;br /&gt;• The NAS technology was developed as an alternative to universal servers carrying a lot of functions (printing, applications, fax server, e-mail etc.). &lt;br /&gt;&lt;br /&gt;• NAS servers implement only one function - a file server function, thus fulfilling it better, simpler and faster.&lt;br /&gt;• Advantages of the NAS: &lt;br /&gt;1. Easy installation and administration&lt;br /&gt;2. Lower cost &lt;br /&gt;3. Access restriction standards support &lt;br /&gt;4. Universality for clients (one server can service MS, Novell, Mac,  Unix clients)&lt;br /&gt;5. Support for the most of backup copying programs &lt;br /&gt;6. Possibility to access data in case a master server is out of order &lt;br /&gt;7. Transmission of huge amount of information (multimedia, presentations etc.)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRrw7LI-EI/AAAAAAAAAGA/sdDU-tmpH5g/s1600-h/NAS.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRrw7LI-EI/AAAAAAAAAGA/sdDU-tmpH5g/s400/NAS.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243434354428409922" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;STORAGE SOLUTION&lt;/strong&gt;&lt;br /&gt;• Data Replication &amp; Mirroring&lt;br /&gt;• Email Archiving&lt;br /&gt;• Hot Failover&lt;br /&gt;• IP Based Storage&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;EMAIL ARCHIVING&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• An e-mail archive is a repository kept in a non-production environment to provide secure retention of messages for compliance and operational purposes. &lt;br /&gt;• It is not good policy to treat backups made for disaster recovery as archives. &lt;br /&gt;• It makes sense to establish the difference between archives and backups in everyone's mind and in day-to-day practice.&lt;br /&gt;• Use backups to restore e-mails at users' request&lt;br /&gt;• Keep backups for long periods of time&lt;br /&gt;• To search tapes in response to an opponent's discovery request. &lt;br /&gt;• On the other hand, backups used solely for business continuity and routinely overwritten at short intervals — say, 90 days or less — have a fighting chance to be excluded from legal discovery. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;HOT FAILOVER&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Failover is a backup operational mode in which the functions of a system component (such as a processor, server, network, or database, for example) are assumed by secondary system components when the primary component becomes unavailable through either failure or scheduled down time. &lt;br /&gt;&lt;br /&gt;• Used to make systems more fault-tolerant, failover is typically an integral part of mission-critical systems that must be constantly available. &lt;br /&gt;&lt;br /&gt;• The procedure involves automatically offloading tasks to a standby system component.&lt;br /&gt;&lt;br /&gt;• Failover can apply to any aspect of a system: &lt;br /&gt;&lt;br /&gt;1. Personal computer : for example, failover might be a mechanism to protect against a failed processor&lt;br /&gt;&lt;br /&gt;2. Network; failover can apply to any network component or system components, such as a connection path, storage device, or Web server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-4850355066867902972?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/4850355066867902972/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=4850355066867902972' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/4850355066867902972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/4850355066867902972'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/computer-external-storage.html' title='Computer External Storage'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-RTTc4l_elM/SMRp610HLhI/AAAAAAAAAFY/_Fg6jX5ExPM/s72-c/Cylender+On+Disk.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-184527795775542770</id><published>2009-04-03T05:26:00.000-07:00</published><updated>2009-04-03T05:27:32.468-07:00</updated><title type='text'>Computer Server</title><content type='html'>Merupakan computer software application yang menjalankan beberapa tugas(i.e. menyediakan perkhidmatan) &lt;br /&gt;&lt;br /&gt;Khusus untuk penyimpanan data&lt;br /&gt;&lt;br /&gt;Menyediakan kemudahan yang mahal. Cth : pencetak pantas, e-mail, remote login&lt;br /&gt;&lt;br /&gt;Direka untuk menyediakan prosesan maklumat kepada berbilang pengguna dan melaksanakan berbilang aplikasi program secara serentak.&lt;br /&gt;Membenarkan &gt; 100 pengguna untuk berinteraksi dengan sistem komputer secara serentak.&lt;br /&gt;&lt;br /&gt;Kelebihan : &lt;br /&gt;1.Kurangkan kos keseluruhan pusat komputer utk membeli peranti dan persisian komputer.&lt;br /&gt;2.Komputer pelayan tidak memerlukan sebarang peranti I/O sekiranya terdapat penyambungan ke rangkaian.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Client Server&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Komputer Pelanggan &amp; Pelayan (client/server) diperlukan dlm rangkaian Pelanggan/Pelayan.&lt;br /&gt;&lt;br /&gt; Satu atau lebih komputer sebagai komputer pelayan (server). Selebihnya sbg komputer pelanggan (client).&lt;br /&gt;&lt;br /&gt; Komputer pelayan mengawal capaian ke atas perkakasan &amp; perisian termasuk perkongsian ruang storan untuk menyimpan data &amp; maklumat.&lt;br /&gt;&lt;br /&gt; Setiap komputer perlu ada NIC (Network Interface Card) utk membolehkan setiap komputer dihubungkan di antara satu sama lain.&lt;br /&gt;&lt;br /&gt; Komputer pelayan perlu dipasang sistem pengendalian rangkaian. Cth : Window Server 2003, Window NT&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRzAoA1pBI/AAAAAAAAAGY/c1TlV_h-vFs/s1600-h/Client+server.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRzAoA1pBI/AAAAAAAAAGY/c1TlV_h-vFs/s400/Client+server.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243442320744227858" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Local Area Network&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRzGn_tuyI/AAAAAAAAAGg/WCzEX1x0Vkg/s1600-h/LAn.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SMRzGn_tuyI/AAAAAAAAAGg/WCzEX1x0Vkg/s400/LAn.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243442423818730274" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Server Type&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Jenis-jenis komputer pelayan :&lt;br /&gt;1. Pelayan Aplikasi&lt;br /&gt;2. Pelayan Tahap Masukan&lt;br /&gt;3. Pelayan Web&lt;br /&gt;4. Pelayan E-mel&lt;br /&gt;5. Pelayan Kerangka Utama&lt;br /&gt;6. Pelayan Kerangka Pertengahan.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pelayan Aplikasi (Application Server)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Merupakan pelayan dalam rangkaian komputer untuk melarikan (running) beberapa aplikasi perisian.&lt;br /&gt;&lt;br /&gt; Bertindak sebagai perantara (middleware) kepada program lain &lt;br /&gt;&lt;br /&gt; Berkomunikasi dengan web pada borang HTML dan XML, menghubungkan beberapa database dan menghubungkan sistem dgn peralatan yang tidak dapat diwarisi oleh pelayan aplikasi.&lt;br /&gt;&lt;br /&gt; Cth : Portal adalah mekanisma pelayan aplikasi yg paling biasa di mana orgn tersebut yg akan mengurus maklumat.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pelayan Mel Elektronik (E-mail Server)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Set up sistem mesej yang membenarkan pengguna untuk menggunakan aplikasi mel elektronik over LAN atau Internet&lt;br /&gt;&lt;br /&gt; Contoh :Yahoomail, Hotmail&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pelayan Web (Web Server)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Merupakan host apabila menggunakan/melarikan salah satu daripada multiplatform servers. &lt;br /&gt;&lt;br /&gt; Contoh : Apache HTTP Server&lt;br /&gt;&lt;br /&gt; Contoh client : IE,Netscape, Mozilla Firefox&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pelayan Kerangka Utama (Mainframe Server)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Merupakan komputer pelayan yang sangat besar dan berkuasa tinggi.&lt;br /&gt;&lt;br /&gt; Digunakan untuk mengawal urusan perniagaan yang besar.&lt;br /&gt;&lt;br /&gt; Juga dipanggil "Enterprise Servers" atau "Super Computers."&lt;br /&gt;&lt;br /&gt; Mengandungi bebrapa CPU, memory, dan disk drive. &lt;br /&gt;&lt;br /&gt; hot-swapable power supplies (mudah alih power supply) , and uninterrupted power supplies yang semuanya terpasang terus pada mesin.&lt;br /&gt;&lt;br /&gt; Syarikat yang terlibat dalam mengeluarkan pelayan jenis ini ialah IBM, Sun Microsystems, HP, SGI &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pelayan Julat Pertengahan&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; VAX (Virtual Address eXtension) ialah pelayan yang dilancarkab oleh  Digital Equipment Corporation (DEC).&lt;br /&gt; VAX mengandungi pemproses 32-bit dan virtual memory. &lt;br /&gt; Bersaing dengan Hewlett-Packard dan IBM computers dalam small enterprise dan pasaran university-scientific.&lt;br /&gt; Pada masa sekarang, pelayan jenis ini lebih dekenali sebagai minicomputer.&lt;br /&gt; Kini, VAX dan pesaing-pesaingnya menjual "servers" untuk tujuan rangkaian perniagaan yang menggunakan client/server computing model. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Pelayan Tahap Masukan&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Contoh Server Matrix &lt;br /&gt; Lebih berkeupayaan untuk mengendalikan high traffic websites dan processor intensive applications&lt;br /&gt; Mampu menyelesaikan masalah datacenter facilities dan tier-one network. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRzRVEnz7I/AAAAAAAAAGw/SZpfJK3qFNA/s1600-h/Matrix.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SMRzRVEnz7I/AAAAAAAAAGw/SZpfJK3qFNA/s400/Matrix.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5243442607717601202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-184527795775542770?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/184527795775542770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=184527795775542770' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/184527795775542770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/184527795775542770'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/computer-server.html' title='Computer Server'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_-RTTc4l_elM/SMRzAoA1pBI/AAAAAAAAAGY/c1TlV_h-vFs/s72-c/Client+server.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-6895309447081323008</id><published>2009-04-03T05:21:00.000-07:00</published><updated>2009-04-03T05:23:28.830-07:00</updated><title type='text'>Computer RAID</title><content type='html'>&lt;strong&gt;RAID&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; RAID is an acronym for "Redundant Array of Inexpensive Disks". &lt;br /&gt;&lt;br /&gt; Configuration for multiple hard drives which provide fault tolerance and improved data access times.&lt;br /&gt;&lt;br /&gt; RAID was traditionally only found in the domain of servers&lt;br /&gt;&lt;br /&gt; But inexpensive IDE RAID solutions now mean many desktop computers can benefit from the same data redundancy, and performance increases for applications like video editing.  &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Implement RAID&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; RAID is a technology that uses multiple hard drives to increase the speed of data transfer to and from hard disk storage.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; Also to provide instant data backup and fault tolerance for any information you might store on a hard drive.&lt;br /&gt;&lt;br /&gt; The hard drives are joined in an array (a single logical drive, as far as the operating system is concerned) and all disks share the data written to them in some form. &lt;br /&gt;&lt;br /&gt; There are several different implementations, or 'levels' of RAID, ranging from RAID 0 to RAID 53.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAID array:&lt;/strong&gt; &lt;br /&gt;&lt;br /&gt; A group of hard drives linked together as a single logical drive. &lt;br /&gt;&lt;br /&gt; Must be connected to one or more hardware RAID controllers&lt;br /&gt;&lt;br /&gt; or be attached normally to a computer using a RAID capable operating system, such as Windows XP Professional. &lt;br /&gt;Striping: &lt;br /&gt;&lt;br /&gt; A procedure in which data sent to a RAID array is broken down and portions of it written to each drive in the array. &lt;br /&gt;&lt;br /&gt; This can dramatically speed up hard drive access when the data is read back, since each drive can transfer part of the data simultaneously.&lt;br /&gt;&lt;br /&gt; Striping data on two or more drives actually reduces reliability &lt;br /&gt;&lt;br /&gt; If a single drive in the array fails, all data is lost as each physical hard disk only contains a fragment of the data which is useless without the rest.  &lt;br /&gt;Mirroring:&lt;br /&gt;&lt;br /&gt; A procedure in which data sent to a RAID array is duplicated and written onto two or more drives at once. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Parity &amp; Common Types of RAID&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; In the majority of RAID implementations, a whole drive, or an area of one or more of the drives in the array is dedicated to storing parity information. &lt;br /&gt;&lt;br /&gt; Each time a bit of information (a digital 1 or 0) is written to every drive in a striped RAID array, an additional parity bit is generated and stored. &lt;br /&gt;&lt;br /&gt; If one of the data drives fails, a new drive can be added and by comparing the information present on the surviving data drive with the corresponding parity information from the parity drive, &lt;br /&gt;&lt;br /&gt; The missing information can be written onto the replacement drive a bit at a time.&lt;br /&gt;&lt;br /&gt; RAID technology began as a method to provide additional data security to business servers&lt;br /&gt;&lt;br /&gt; Many of the RAID levels are still almost exclusively used in the business domain, due to the cost of the required hardware. &lt;br /&gt;&lt;br /&gt; Since the lower levels of RAID are easily implemented on modern computers and need only a pair of drives and a RAID-capable drive controller (hardware) or operating system (software)&lt;br /&gt;&lt;br /&gt; RAID 0 and RAID 1 implementations have become common in the high end desktop/PC&lt;br /&gt;&lt;br /&gt; RAID 0 is used to gain additional performance from conventional drives by pairing them up &lt;br /&gt;&lt;br /&gt; While RAID 1 provides a very simple and effective form of backup by duplicating or 'mirroring' all data on a second drive. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Types of RAID&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Most Hardware RAID controllers intended for the enthusiast or small business markets support only three levels of RAID; RAID 0, 1 and 0+1. &lt;br /&gt;&lt;br /&gt; These are the only levels of RAID that do not require the use of parity, as this feature adds greatly to the complexity and expense of the controller. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAID 0&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• RAID 0 uses multiple hard drives to stripe data over one large logical drive.&lt;br /&gt;&lt;br /&gt;• While there are physically two drives, the computer logically sees just one. &lt;br /&gt;&lt;br /&gt;• The RAID 0 configuration is typically used when there are data-intensive applications because it offers the fastest data access, though no redundancy&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SMmjQee2uOI/AAAAAAAAAHI/L3nO1coZkUA/s1600-h/Raid+0.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SMmjQee2uOI/AAAAAAAAAHI/L3nO1coZkUA/s400/Raid+0.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5244902744505366754" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; RAID 0 can essentially combine two hard drives into one using striping, and greatly increase the speed that the drives transfer data.&lt;br /&gt;&lt;br /&gt; This has one obvious disadvantage. There is no fault tolerance.&lt;br /&gt;&lt;br /&gt; If any drive fails, all the data is lost.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAID 1&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Fault tolerance is the cornerstone of RAID 1. &lt;br /&gt;&lt;br /&gt;• In this configuration, two identical physical drives are used, with one drive mirroring the information on the other. &lt;br /&gt;&lt;br /&gt;• A RAID 1 configuration is ideal for data redundancy, though storage is more costly as only 1/2 the total drive space of both hard drives is available. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SMmjT8qbHdI/AAAAAAAAAHQ/-TWTRaU_btQ/s1600-h/raid+1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SMmjT8qbHdI/AAAAAAAAAHQ/-TWTRaU_btQ/s400/raid+1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5244902804146560466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; A mirrored disk array is composed of a set of two physical hard drives, each of which contains a full copy of all data sent to the logical drive that represents the array. &lt;br /&gt;&lt;br /&gt; This has a couple of advantages :&lt;br /&gt;&lt;br /&gt;1. Any data stored on a RAID 1 array is completely and automatically backed up, and in the event of the failure of one drive, the other can be substituted without a hitch. &lt;br /&gt;&lt;br /&gt;2. Secondly, data can be read from both drives simultaneously, increasing the speed of data retrieval. &lt;br /&gt;&lt;br /&gt; In the event one of the drives in the array fails, a new drive can be added, the array rebuilt, and the RAID controller will duplicate the information onto the new blank drive.&lt;br /&gt;&lt;br /&gt; The disadvantage of RAID 1 is that unlike striping, a mirrored array can use only half of its total free space for storage, since one disk is an exact duplicate of the other.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAID 1+0&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; This RAID level combines the best features of RAID 0 and 1. (Striped array with mirroring)&lt;br /&gt;&lt;br /&gt; It requires a minimum of four physical drives to implement, so it is not cheap. &lt;br /&gt;&lt;br /&gt; Essentially, two pairs of striped drives are mirrored together to provide fault tolerance. &lt;br /&gt;&lt;br /&gt; The mirroring provides the fault tolerance, though if any drive is lost, it must be immediately replaced and the array rebuilt, since it cannot handle the loss of more than one drive. &lt;br /&gt;&lt;br /&gt; Intended for business use, these levels of RAID use the parity system as explained above to provide varying levels of fault tolerance. &lt;br /&gt;&lt;br /&gt; RAID solutions at this level generally come as an add-in controller card or a dedicated storage rack and are intended to work hand-in-hand with hot-swappable hard drive mountings. &lt;br /&gt;&lt;br /&gt; With this setup, any failed drives can be swapped out for new ones on the fly, and the missing data quickly restored by using the parity data. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Hardware &amp; Software RAID&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; Depends on your means and expectations.&lt;br /&gt;&lt;br /&gt; Windows XP Pro at least, much easier to set up and much more flexible in terms of disk use than a hardware based system.  &lt;br /&gt;&lt;br /&gt; A second factor to consider is whether you want your operating system disk to be part of the RAID array you create? &lt;br /&gt;&lt;br /&gt; The software solution provided by Windows 2000 or XP as it is easier and cheaper. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Using RAID :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt; To store  a high capacity of data&lt;br /&gt;&lt;br /&gt; Suitable for server&lt;br /&gt;&lt;br /&gt; A system back up&lt;br /&gt;&lt;br /&gt; Many level of RAID from RAID 0 to RAID 53&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-6895309447081323008?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/6895309447081323008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=6895309447081323008' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6895309447081323008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6895309447081323008'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/computer-raid.html' title='Computer RAID'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_-RTTc4l_elM/SMmjQee2uOI/AAAAAAAAAHI/L3nO1coZkUA/s72-c/Raid+0.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-6866338123911548228</id><published>2009-04-03T05:15:00.000-07:00</published><updated>2009-04-03T05:19:05.269-07:00</updated><title type='text'>Computer Sound &amp; Graphic Card</title><content type='html'>&lt;strong&gt;What is sound card&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Sound cards are special expansion cards enabling computers to play audio.&lt;br /&gt;&lt;br /&gt;• Consist of one or more chips used to convert digital sound data to analog sounds played through the speakers.&lt;br /&gt;&lt;br /&gt;• 2 types of sound card :&lt;br /&gt;&lt;br /&gt; a. built-in sound card&lt;br /&gt;&lt;br /&gt; b. sound card in the motherboard.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Built-in sound card&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Built-in on the computer system.&lt;br /&gt;&lt;br /&gt;• External speakers are not required.&lt;br /&gt;Sound card on the motherboard&lt;br /&gt;&lt;br /&gt;• And external speaker are required.&lt;br /&gt;&lt;br /&gt;• The sound jack(PS/2 for speaker) are needed to connect the external speaker and the motherboard.&lt;br /&gt;&lt;br /&gt;• All the PCs used these sound cards.&lt;br /&gt;&lt;br /&gt;• Used for laptop/notebook&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Graphic Card&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Enable to use Graphic Standard.&lt;br /&gt;&lt;br /&gt;• To appear the video graphic on the screen&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What is a Bus?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Signal Pathways&lt;br /&gt;&lt;br /&gt;• A way of passing information between components inside and outside the computer.&lt;br /&gt;&lt;br /&gt;• A modular way of expanding the functions or capabilities of the computer.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;PC Bus Architectures&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• ISA&lt;br /&gt;• MCA&lt;br /&gt;• EISA&lt;br /&gt;• VL-Bus&lt;br /&gt;• PCI&lt;br /&gt;• AGP&lt;br /&gt;• PC Card&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Peripheral Component Interconnect (PCI)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Developed for Pentium-class processors&lt;br /&gt;• 32-bit and 64-bit data path versions&lt;br /&gt;• 33-MHz Clock&lt;br /&gt;• Processor Independent&lt;br /&gt;• Plug and Play with Bus Mastering&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SdX-gy8mTkI/AAAAAAAAAKE/Xu0WkTe4FFY/s1600-h/PCI.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 248px;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SdX-gy8mTkI/AAAAAAAAAKE/Xu0WkTe4FFY/s400/PCI.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320438374193319490" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Accelerated Graphics Port (AGP)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Developed for high speed graphics cards&lt;br /&gt;• Frees the PCI bus from making video transfers&lt;br /&gt;• Used only for video cards&lt;br /&gt;• Considered a port rather than a bus&lt;br /&gt;• 66 MHz, 32-Bit&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SdX-ar1ZDVI/AAAAAAAAAJ8/9iRmu2REFU8/s1600-h/AGP.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 259px;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SdX-ar1ZDVI/AAAAAAAAAJ8/9iRmu2REFU8/s400/AGP.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5320438269204827474" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Computer Cooling&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;• Cooling vents are usually in the front and rear of the case, but in some newer cases can be elsewhere as well. &lt;br /&gt;&lt;br /&gt;• These allow air to be circulated by the power supply fan and any auxiliary fans used by the case.&lt;br /&gt;&lt;br /&gt;• The most common location of additional cooling fans is the front of the case, opposite the main power supply fan, but some larger cases have cooling fan mounting locations in many places.&lt;br /&gt;&lt;br /&gt;• These cases use plastic ducts or tubes to concentrate air flow in a specific direction, which may help the fans do a better job than would be accomplished through standard case air convection.&lt;br /&gt;&lt;br /&gt;• The devices that require the cooling aspects :&lt;br /&gt;&lt;br /&gt;1. Processor &lt;br /&gt;2. Computer case&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-6866338123911548228?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/6866338123911548228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=6866338123911548228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6866338123911548228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/6866338123911548228'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/computer-sound-graphic-card.html' title='Computer Sound &amp; Graphic Card'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-RTTc4l_elM/SdX-gy8mTkI/AAAAAAAAAKE/Xu0WkTe4FFY/s72-c/PCI.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-2728905396037217176</id><published>2009-04-03T05:13:00.002-07:00</published><updated>2009-04-03T05:14:29.528-07:00</updated><title type='text'>Your PC</title><content type='html'>&lt;strong&gt;Windows vs. Mac vs. Linux &lt;/strong&gt;- Windows vs. Mac has long been a perennial debate, and it's still a personal decision as to whether that OS is right for you. But now desktop Linux is on the rise, complicating things even further. It's all very confusing, but here's some advice: Don't jump from Windows to a Mac or Linux without spending a little hands-on time with the OS, either at a physical store or a friend's house. Both are very similar to Windows in many ways, but some substantial differences remain. I regularly recommend both alternatives for readers, but not unless they've experienced Mac OS or Linux in the flesh first.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Desktop vs. Laptop &lt;/strong&gt;- Most people know this answer coming in, but many are still confused about whether they should go portable. A key issue is price: Expect to pay an extra $500 for a comparably equipped laptop vs. a similar desktop (sans monitor). Is that premium worth it to you for the extra mobility? If so, make the jump to laptop. Don't forget, though: Your laptop will be dead after anywhere from one to three years of use, depending on how rough you are with it. A good desktop PC will last you five years or more, and even longer with appropriate upgrades.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;CPU &lt;/strong&gt;- I'm assuming we're talking a Windows Vista or XP PC from here on out, as that represents the vast majority of computer buyers. (Linux and Mac PCs have far fewer choices when it comes to specs, so just roll with what's available.) As for CPU, right now Intel Core 2 Duo is the way to go, especially on laptops. The AMD Athlon 64 or Phenom are still solid choices for desktops, especially if you're on a budget. Don't get Celeron- or Sempron-based systems if you can help it. Also, it's not worth buying the very fastest CPU on the market. A good rule of thumb is to get a CPU that is two rungs down from the top, speedwise. You'll be getting great performance at a very good price.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAM &lt;/strong&gt;- This one's easy. In the Vista world, you need 2GB of RAM. Less will slow down your computer. More will do you no additional good. Don't worry about the speed of the RAM, cache, front side bus, or any of that stuff. &lt;br /&gt;Hard Drive - Even an entry-level drive is more than enough for most people, unless you do loads of video editing on your computer. Even starter computers usually come with 250GB of hard drive space or more now. Upgrade as you need it.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Optical Drive&lt;/strong&gt; - Unless you are set on high-definition DVD, a dual-layer DVD writer (standard on most machines now) is all you need.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Graphics&lt;/strong&gt; - Unless you're spending under about $1,000 (laptops) or $600 (desktops), avoid integrated or "shared" graphics. They will noticeably slow your system under Vista and any gaming will be impossible. You don't need to break the bank to get a good graphics card; an Nvidia GeForce 8500GT supports DirectX 10 and can be found for a mere $70, for example. PC makers tend to offer only a couple of video card options with new computers, so get what you can afford, Nvidia or ATI, as long as it's DirectX compatible. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Laptop Screen Size&lt;/strong&gt; - 15.4-inch laptops are the mainstream now. You'll find the best deals on machines at this size. However, plenty of smaller options abound, at 14 inches, 13.3 inches, and even smaller, but I personally find the lack of screen real estate makes me less productive below 15.4 inches. Again, it's up to you... and remember that those sexy ultraportables have stripped-down components (to keep them light) and can cost much more than larger laptops. 17-inch laptops (aka "desktop replacements") are another option, but they are not terribly feasible if you travel with them.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-2728905396037217176?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/2728905396037217176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=2728905396037217176' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2728905396037217176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2728905396037217176'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/your-pc.html' title='Your PC'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-2355572936473411491</id><published>2009-04-03T05:13:00.001-07:00</published><updated>2009-04-03T05:13:39.576-07:00</updated><title type='text'>Choosing Your Computer</title><content type='html'>&lt;strong&gt;How to Choose a PC&lt;/strong&gt;&lt;br /&gt;In today's market, there are almost infinite variables when choosing a PC. How can you choose a PC when you walk into any computer store and there are 5-10 major brands that all seem similar other than slight appearance and incentives? As I stated in the processors article, most of the big guys use proprietary equipment that is slow, detrimental to your computers longevity and does not leave cost effective options for upgrading. I will be ignoring any and all computers with proprietary equipment. I feel they are an insult to consumers and take advantage of an overcrowded market with underhanded marketing tricks. Most do not even offer support anymore, they outsource it to the lowest bidder, usually overseas. Choosing a PC can be tricky because of all the confusing information made available. I know most of you are not going to read all my articles on components, but I suggest reading Buss Speed and Motherboards, as they are very relevant and informative to choosing a new PC. Your goal is a well balanced PC. By balance I mean that the transfers inside the computer are all the correct speeds to make sure the information from component to component can flow smoothly and not get stuck, causing bottlenecks, backups and lag. Picture your PC as a network of pipes. What will happen if you have a big 4" pipe flowing at full capacity into a small 2" pipe? It will not slow down for the 2" pipe, it will backup and flood. Same with PCs, the data will flood the components and finally cause them to freeze, cause blue screens and other critical errors. I’m going to teach you two things:One of them is that ANY PC can do the basic features. Trading pictures, photo editing, music etc... I will show you the statistics that determine how well they do these functions and what software and operating systems control the features. Also a PC, even purpose built, can and will do other things, it just may perform better at its purpose.The other is how to identify and buy a well balanced PC that will lower the total cost of ownership. What this means is that I will show you how to build a PC that will last upwards of five to seven years (over the two year average of most proprietary builders) before it becomes "to slow". We will start with a question.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What do you use your PC for? &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Gaming Computers:&lt;br /&gt;&lt;strong&gt;This is the majority of our customers. You want fast, high resolution gaming for cheap. But you also seem to want bragging rights. We see the component lists and wish lists on the forums from retailers showing your builds and the choices are made almost strictly on model numbers and marketing, instead of performance. This is bad. We also see you make huge cuts in components to make room for a video card that is way too large for the PC. This will not get you more performance. It will actually overwork the rest of your choking components and lag you more. We constantly see computers with some fast components built at home that score lower then our Gamer LvL 1 in Future Mark tests. This is because of the dangers of a build at home environment versus a clean room, and the fact that you are not choosing balanced components.&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Business Computers:&lt;br /&gt;&lt;/strong&gt;This were we see a lot of people get victimized. Business PCs do not have to be that powerful in most cases, but they need to be reliable and able to stand up to constant data changing, long hours and multiple users with little or no updates. You want a tank, not a Ferrari. Keep in mind tanks can cruise at 40-60 miles per hour on any terrain, so they are not slow. You also want to lower your total cost of ownership with low electric usage from computers that will last for years and offer low cost upgrading options.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Home Computers:&lt;/strong&gt;&lt;br /&gt;Home users actually have it easy. Most component makers are so caught up in the war to be the fastest, you can use almost anything and be very happy with the performance. The problem lies when companies sell low priced stuff targeted to your market. This is usually "to good to be true" items. There is a minimum cost for building a PC, anything less is a lot less then you want. Component prices usually only change three times. They come out priced high, then settle when their competitor releases a competing product, then finally go to their final pricing when newer technology replaces it. Thats where they sit for about a year or two until they become obsolete. When this happens any leftover components are sold at an extremely reduced cost to free up space. This is not a bargain sale! This is outdated stuff that cannot survive in todays environment, if it could, it would still be on the shelf! I know it sounds like I contradicted myself because L2 claims our computers last 5-7 years, but our components choice usually stay on the shelf for 3-5 years. See the problem here? You are buying almost a decade old component!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Now You are ready to choose your PC&lt;/strong&gt;&lt;br /&gt;The basis for any good PC is a solid motherboard and PSU (power supply unit). You should demand a specification sheet on the motherboard to see if supports the processor that is included with the PC. Motherboards will run faster processors then they can support, but only at the maximum supported speed. So if you buy a computer with 3.2MHz processor and a 1333FSB (Front Side Buss) and the motherboard only supports 2.8 with a 1066FSB, it will run the 3.2, but at 2.8/1066. Is the PSU that important if I don't plan to upgrade? Yes! This is a common belief that is very wrong. While it is true you should plan ahead if you ever want to upgrade, making sure the PSU has enough power and the proper connections, it is also true you should check it out even if you don't plan to upgrade. A lot of companies just assume you will never push your PC hard enough make the PSU work. But over time as the PC gets bogged down and/or the internet updates the latest java or flash programs you use every day while browsing, the PSU is now stressed all the time. As the PSU becomes stressed it will cause locking, freezing, lagging etc., and it is extremely hard to trace these symptoms back to the PSU. This will seriously decrease the time you own the PC. Look for a PSU that is 80+ certified, or use the Thermaltake power supply calculator HERE and add about 40% if it's not 80+ certified (80+ means that is 80% efficient or better). So if it says 500watts you get 400, unlike some lesser quality PSUs that will give much less. Other notable statistics:Processing power measured in MHz. For example: 3.2MHz.How important is processing power? The sad answer is not very for most users. While it is the heart of the computer because everything does need to be processed at some point, it is not what I call a "choke point". A choke point is my name for the weakest part of the component or PC, that part that is most likely to cause lag and delays. Processing speed has not changed for some time. What has changed is how many cores (or mini processors are inside one physical chip). We see dual and quad core a lot now. So that same 3.2 MHz processor is essentially two 3.2 MHz processors or a 6.4 in the case of dual core. This is still not the most important statistic. The FSB (Front Side Buss) is by far the most important and most crucial decision. Also the cache (pronounced cash) will speed up processes, but only if your RAM can support it (I will explain later).The FSB is how much information your processor can accept at one time. The more information that comes in, the more information that is processed and sent out, then the faster the rest of your components can do their job. The processor can be as fast as it wants, but if you can't get the information into the processor then you are wasting your money.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RAM &lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;measured in MB or GB (GB = 1000MB)&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;This is the director of traffic for your PC. This has to be fast enough to transfer all the internal information to where it needs to go, while having enough power to make sure it reads the data and sends it to the right place. This is where a lot of people get cheap, especially gamers. People want the highest quad core processor, with a massive FSB and cache, but no RAM to get the data to it. The most notable statistics of RAM are the MHz, CL and DDR rating (example: 2 GB of 800 MHz CL3 DDR2). Ram is extremely technical, so I will oversimplify this. The DDR can be thought of as a bandwidth benchmark. DDR stands for double data rate, so it is essentially double the bandwidth, or transfer rate, of the previous model that was SDR (Single Data Rate). DDR2 is another improvement to bandwidth, as is DDR3. There are changes to voltage and architecture, but for the sake of just choosing a PC, I will stick to the easy meat and potatoes of the deal. So the higher the DDR number and the MHz the better right? No, sorry, not that easy. There is the CL to consider also. The CL is the amount of time it takes to get information into the chip, process it and get it back out. So we need to factor four variables. Cost, bandwidth, processing power and CL. Best general advice is to have enough of it. This would be a budget minded decision. Gamers need to pay closer attention to CL, although it still should be a factor for everyone else. I usually recommend half of the motherboards maximum RAM. So if your motherboard can handle 8GB, I would recommend 4GB. This is very general, but a good guideline.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Video Card&lt;/strong&gt;&lt;br /&gt;Is a video card is necessary? The answer is no. If your processor and RAM are strong enough and your onboard video chip has the proper drivers, shaders, DX level etc., you can replicate the results of a video card. Gamers and home users are the ones that get victimized by this the most. Yes, home users. Just because you don't play games, doesn't mean you don't want to pay attention to graphics, and gamers put all their emphasis on the video card, which is also wrong. A video card is a small computer that is dedicated to rendering video and video effects. The problem is that this information must be still be processed by the rest of the computer. If you were to take the fastest video card out and put it in a mid level computer, your PC would choke and be very slow. The key to choosing the proper video is balance. For a home user, you want to make sure you have good drivers, features and capable resolution. Think about how many monitors you will be running also, make sure your video can handle it and can handle the resolution. For gamers. Pay attention to the specs, not the model number. Stop buying a video card that is more than the PC can handle. Pick a budget and pay attention to RAM and the FSB of the processor, not the processing power itself as this means very little to a gamer. Then fit a video card with good transfers into the budget last to assist those components. A video card is made to assist, not dominate.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Hard Drive&lt;/strong&gt;&lt;br /&gt;Hard drive usually gets some attention because most people want to be able to store all their information. However, even the most famous online builders, ignore speed. The things we pay attention to are the RPMs of the drive (7200RPM for example), but ignore the transfer rate and cache of the drive. Everything you load comes from the HDD and goes into the RAM, no exceptions. Look for a fast transfer and nice buffer on the HDD, this, in some cases, will be faster than platter speed.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;br /&gt;We hope this has been informative. The market is dominated by lies, deception and marketing to the point where even benchmark software can be a lie. A computer can be programmed to do anything, even appear more than it is. Your only defense is education. I know, who wants to learn everything?!&lt;br /&gt;&lt;br /&gt;But look at this way: You do own and will buy another computer. Compare our computer to a proprietary build of the same price. Not only will our computer runs circles around it in performance, you will (on average) keep our computer 150% longer then the proprietary. We look at that as 150% cheaper.&lt;br /&gt;&lt;br /&gt;There are very few of us left that haven't been run out, bought up or simply bullied off the net by the powers that be. If you don't like us, please contact us so that we may refer you to another boutique company and help keep freedom of industry truly free.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-2355572936473411491?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/2355572936473411491/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=2355572936473411491' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2355572936473411491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2355572936473411491'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/choosing-your-computer.html' title='Choosing Your Computer'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-468685284245040819</id><published>2009-04-03T05:11:00.000-07:00</published><updated>2009-04-03T05:12:48.006-07:00</updated><title type='text'>How To Choose Your Computer</title><content type='html'>First, you should decide what you are going to use the computer for. Then, you need to mind the configurations and your budget.&lt;br /&gt;&lt;br /&gt;Computers are getting really inexpensive these days. Buy the most powerful computer your budget allows is always a good idea.&lt;br /&gt;&lt;br /&gt;Computer prices do go down with time. However, that doesn't mean that you should wait forever to use it, to learn from it, and, most of all, enjoy it. Computer is the best investment money can buy now! Why do I say that, knowing that the value of a computer goes down significantly with time? What a computer can help you is limitless.&lt;br /&gt;&lt;br /&gt;The most powerful computers these days are for gamers, servers, and rocket scientists. The priority is probably true in that order.&lt;br /&gt;&lt;br /&gt;Do not buy a so-called "name-brand" or "major-brand" if upgrading may be on your mind a couple of years down on the road. These brands are specifically designed to hook you on buying only their highly priced components to maximize their 40-60% profit margin. Most "clone" makers are operating only with a 5-25% margin. Go figure where you could save money. Besides, most major PC makers are not really "manufacturers." They are just "box-makers" -putting components together- like every body else.&lt;br /&gt;&lt;br /&gt;Clone or house-brands are often based on open structures, which means easier and cheaper upgrading, using "universal" components. You pretty much can go anywhere to have the computer served, upgraded, or repaired.&lt;br /&gt;&lt;br /&gt;You should consider putting a computer together yourself only if you have some computer knowledge and some spare time. It is not that easy the first time. However, it does get easier once you have started. The satisfaction you get from putting a computer together is difficult to describe with words. Besides, you could sell a few of them and try to become the next Michael Dell. Who knows…&lt;br /&gt;&lt;br /&gt;Rule of thumb: It is a better deal to buy a new one instead of upgrading an old one if the old one is more than three years old.&lt;br /&gt;&lt;br /&gt;If all you need to do is word processing, spreadsheet, home finance, some basic windows games, e-mails, and browsing the Internet, you are an average user. Nothing really "high end" is needed. Consider a mid-grade computer that includes 350-500MHz microprocessor, 32 or 64 MB of memory, 8MB video, 4-8GB hard drive, 56K Modem, and any sound card. A 15” or larger monitor is recommended.&lt;br /&gt;&lt;br /&gt;Servers are a lot more complex than any other computer systems. Normally servers should have as high a CPU speed as possible, preferably Pentium III microprocessor with 512K cache, a minimum of 128MB memory and 9.1GB or higher hard disk drives, often SCSI along with a network adapter. SCSI hard drives are better designed for simultaneous data access and not limited to just four hard drives as their IDE counterpart. Since servers rarely deal with a complex graphics, a 4 or 8MB video card would do the job, unless it is a Terminal Server. Use a large case with tons of cooling. Don't forget an uninterruptible power supply (UPS) and a tape backup drive to protect your data and investment. Well, the price tag could go up quickly.&lt;br /&gt;&lt;br /&gt;Designing a gaming computer is more fun than anything. Currently high-end and hardware-demanding games include QuakeII, QuakeIII, Hexen, StarCraft and Half-Life. These games run well only on intense gaming engines. Go with top of the line processor, such as 500-600MHz, Pentium III or AMD K6-3. Take a minimum of 128MB Memory and at least 8.4GB hard drive. IDE with ultra DMA/ATA66 is OK. The deciding factor is the video card for all the 3D actions. You need the best video card your budge allows! Examples are STB Voodoo3 3500, ATI-128, and Matrox G400 with 16-32MB video memory. A DVD drive is a must these days. Depending on how the end-user plans to game you might need a network adapter or a modem. PC gaming is a lot of fun, so be sure design a computer that you can enjoy it for a long time. Do get a nice sound card. For game machines, do not even think about systems with integrated components such as video and audio. You will hate it when the next version of your favorite game is released.&lt;br /&gt;If you are choosing a computer for normal office work, only the mid-range computer is necessary. I actually recommend Intel Celeron for workstations. Celeron is quite more inexpensive with less cache than their Pentium cousins but is almost equally powerful. You really do not need that much cache for word processing, spreadsheet, and e-mail. Consider 350-500MHz, 64MB, 4-8GB hard disk drive and 4-8GB video card&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-468685284245040819?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/468685284245040819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=468685284245040819' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/468685284245040819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/468685284245040819'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/04/how-to-choose-your-computer.html' title='How To Choose Your Computer'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-1113934918594859420</id><published>2009-03-31T03:10:00.000-07:00</published><updated>2009-03-31T03:55:16.191-07:00</updated><title type='text'>1 April Worm Attack (this is not april fool)</title><content type='html'>&lt;strong&gt;KETERANGAN ANCAMAN &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Nama dan Jenis Ancaman &lt;/strong&gt;&lt;br /&gt;Worm W32.downadup.KK [Trend Micro] &lt;br /&gt;W32.Downadup.C                       [Symantec] &lt;br /&gt;Worm:W32/Downadup.DY        [F-Secure] &lt;br /&gt;Win32/Conficker.C                      [Computer Associates] &lt;br /&gt;Mal/Conficker-B                           [Sophos] &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tarikh Dikesan &lt;/strong&gt;&lt;br /&gt;18 Mac 2009 &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Bilangan Agensi Terlibat&lt;/strong&gt; &lt;br /&gt;&lt;br /&gt;Semua agensi yang menggunakan sistem pengoperasian Microsoft Windows &lt;br /&gt;Sistem Pengoperasian/Aplikasi Berisiko &lt;br /&gt;&lt;br /&gt;    *  Ms Windows 95 &lt;br /&gt;    *  Ms Windows 98 &lt;br /&gt;    *  Ms Windows NT &lt;br /&gt;    *  Ms Windows Me &lt;br /&gt;    *  Ms Windows XP &lt;br /&gt;    *  Ms Windows 2000 &lt;br /&gt;    *  Ms Windows Vista &lt;br /&gt;    *  Ms Windows Server 2003 &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Kaedah Serangan &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;i.    Worm W32.downadup.KK merebak dengan mengeksploitasi kelemahan pada &lt;br /&gt;sistem pengoperasian Microsoft Windows yang tidak dilengkapi dengan &lt;br /&gt;tampalan keselamatan (security patch) MS08-067. &lt;br /&gt;ii.  Worm ini dipercayai akan mula aktif pada 1 April 2009. Ia akan &lt;br /&gt;menyerang komputer dengan cara: &lt;br /&gt;a.      Connects to various time servers to determine the current date and &lt;br /&gt;time. &lt;br /&gt;b.      Register itself as a system service to ensure auto execution every &lt;br /&gt;startup. &lt;br /&gt;c.      Deletes a registry key to prevent system startup in safe mode. &lt;br /&gt;d.      Terminates security-related processes (i.e. procexp, regmon, &lt;br /&gt;autoruns, gmer etc.) &lt;br /&gt;e.      Blocks access to security and antivirus websites. &lt;br /&gt;f.        Generates 50,000 malicious URLs and attempts to connect to &lt;br /&gt;around 500 random generated URLs at a time. &lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Kesan Serangan&lt;/strong&gt; &lt;br /&gt;&lt;br /&gt;i.    Worm ini boleh menyebabkan serangan/pencerobohan yang lebih parah ke &lt;br /&gt;atas komputer/server memandangkan ia mampu mematikan ciri-ciri keselamatan &lt;br /&gt;pada komputer/server. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cadangan Tindakan Pengukuhan &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;i.    Memasang patch MS08-067 dari Microsoft &lt;br /&gt;(&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx&lt;/a&gt;). &lt;br /&gt;ii.  Memastikan perisian antivirus dilengkapi dengan virus signature yang &lt;br /&gt;terkini dan jalankan full system scan. &lt;br /&gt;iii. Memastikan semua storan mudah alih (removable storage) di imbas &lt;br /&gt;terlebih dahulu sebelum digunakan; cth: USB drive, mobile hard disk, dll. &lt;br /&gt;iv. Memastikan HIPS dan perlindungan buffer overflow diaktifkan. &lt;br /&gt;v.  Memastikan imbasan masa sebenar (real-time scanning) dan imbasan 'on &lt;br /&gt;write' diaktifkan &lt;br /&gt;&lt;br /&gt;Maklumat Lanjut &lt;br /&gt;&lt;br /&gt;1.http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOWNAD.KK&amp;VSect=T &lt;br /&gt;2.http://www.sophos.com/security/analyses/viruses-and-spyware/malconfickerb.html &lt;br /&gt;3.http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-1113934918594859420?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/1113934918594859420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=1113934918594859420' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1113934918594859420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/1113934918594859420'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/03/1-april-virus-attack-this-is-not-april.html' title='1 April Worm Attack (this is not april fool)'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-272207659481338569</id><published>2009-03-23T04:31:00.000-07:00</published><updated>2010-11-22T22:42:21.025-08:00</updated><title type='text'>Virus Bulu Bebek Removal</title><content type='html'>Bulubebek Virus&lt;br /&gt;Main File :&lt;br /&gt;&lt;br /&gt;&lt;Drive&gt;:\Autorun.inf&lt;br /&gt;&lt;Drive&gt;:\bulubebek.ini&lt;br /&gt;&lt;br /&gt;Virus Running Process&lt;br /&gt;&lt;br /&gt;Script.exe&lt;br /&gt;LSASS.exe&lt;br /&gt;&lt;br /&gt;Virus Simptom&lt;br /&gt; &lt;br /&gt;Duplicate every folder on Drive and change it to .EXE file with ‘folder’ Icon.&lt;br /&gt;Hide the origin folder on Drive.&lt;br /&gt;Hide Task Manager &amp; Folder Option on your PC.&lt;br /&gt; &lt;br /&gt;Remove Bulubebek Virus.&lt;br /&gt;* Assume that your PC is infected by bulubebek virus Only(this step is useless if your PC is infected with multiple virus infection)&lt;br /&gt;&lt;br /&gt;1. Disconnected From Internet (LAN or Wireles)&lt;br /&gt;2. Turn Off System Restore&lt;br /&gt;3. Use Third party software such as Process Explorer or Security Task Manager, to View and Kill process tree for &lt;strong&gt;LSASS.exe &lt;/strong&gt;and &lt;strong&gt;Script.exe&lt;/strong&gt;.&lt;br /&gt;*delete&lt;br /&gt;  - c:\windows\LSASS.exe&lt;br /&gt;  - c:\windows\LSASS.ini&lt;br /&gt;  - c:\windows\system32\SCRIPT.exe&lt;br /&gt;  - c:\windows\system32\SCRIPT.ini &lt;br /&gt;&lt;br /&gt;4. Repair Windows registry using this script:&lt;br /&gt;&lt;br /&gt;[Version]&lt;br /&gt;Signature="$Chicago$"&lt;br /&gt;Provider=Vaksincom Oyee&lt;br /&gt;&lt;br /&gt;[DefaultInstall]&lt;br /&gt;AddReg=UnhookRegKey&lt;br /&gt;DelReg=del&lt;br /&gt; &lt;br /&gt;[UnhookRegKey]&lt;br /&gt;HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""&lt;br /&gt;HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"&lt;br /&gt;HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;br /&gt;HKLM, SYSTEM\ControlSet002\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;br /&gt;HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Command Processor, AutoRun,0,&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, CheckedValue, 0x00010001,1&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL, DefaultValue, 0x00010001,2&lt;br /&gt;HKCU, Software\Microsoft\Command Processor, AutoRun,0,&lt;br /&gt; &lt;br /&gt;[del]&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NOFind&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NORun&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PAYXX.exe&lt;br /&gt;HKCU, Software\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress&lt;br /&gt;HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions&lt;br /&gt;HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. Copy and paste this script into Notepad and save it as &lt;strong&gt;Removebulubebek.inf&lt;/strong&gt;.&lt;br /&gt;6. Right Click &lt;strong&gt;Removebulubebek.inf &lt;/strong&gt;and Click install.&lt;br /&gt;7. LogOff and Logon Computer.&lt;br /&gt;8. ‘Show Hidden file and folder’ on your Folder Option.&lt;br /&gt;9. Delete autorun.inf and bulubebek.ini on your drive (Drive C, Drive D, Removable Drive)&lt;br /&gt;10. Search and remove virus duplication file by using ‘Windows Search”. &lt;br /&gt;Duplication file always &lt;br /&gt;• using ‘folder’ icon, &lt;br /&gt;• 53Kb in size, &lt;br /&gt;• .EXE file,&lt;br /&gt;• File Type ‘Application’&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;11. To unhide the origin folder on your drive (Drive C, Drive D, Removable Drive)&lt;br /&gt;&lt;br /&gt;• Use  ATTRIB –s –h –r /s /d On Command Prompt, &lt;br /&gt;&lt;br /&gt;c:\ ATTRIB –s –h –r /s /d&lt;br /&gt;Or&lt;br /&gt;d:\ ATTRIB –s –h –r /s /d&lt;br /&gt;Or &lt;br /&gt;&lt;USB drive&gt;:\ ATTRIB –s –h –r /s /d&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;its done ... as simple as that .. unless u'r facing a multiple virus infection&lt;br /&gt;&lt;br /&gt;there is a few time, im facing a multiple virus infection (bulubebek,sality &amp; 2.bat) .. its a bit disaster but i managed to remove it by using safemode or administrator account.&lt;br /&gt;&lt;br /&gt;for Vista user, &lt;br /&gt;if bulubebek infected ur pc, u will not enter ur desktop(u will only see dark screen), it is because ur system cannot run 'explorer.exe' after the virus added value 'SCRIPT.exe' at the back of it on winlogon shell. so what i always do is :-&lt;br /&gt;&lt;br /&gt;1. press &lt;em&gt;CTRL-ALT-DE&lt;/em&gt;L and run &lt;em&gt;task manager&lt;/em&gt;,&lt;br /&gt;2. on menu bar, click &lt;em&gt;FILE &lt;/em&gt;-&gt; &lt;em&gt;NEW TASK (RUN)&lt;/em&gt;&lt;br /&gt;3. type &lt;em&gt;explorer.exe&lt;/em&gt; to enter your desktop&lt;br /&gt;4. after entering ur desktop, follow the step i show u earlier ...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4shared.com/file/109756977/787c297f/RemoveBulubebek.html" target=_blank&gt;Download RemoveBulubebek.inf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4shared.com/file/109758299/edcdb124/procexp.html" target=_blank&gt;Download process explorer.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/120x240.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-272207659481338569?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/272207659481338569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=272207659481338569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/272207659481338569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/272207659481338569'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/03/virus-bulu-bebek-removal.html' title='Virus Bulu Bebek Removal'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-69096661608184778</id><published>2009-02-25T19:30:00.000-08:00</published><updated>2009-02-25T19:36:54.760-08:00</updated><title type='text'>Net-Worm.Win32.Kido</title><content type='html'>&lt;strong&gt;&lt;br /&gt;Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This malicious program exploits the MS08-067 vulnerability to spread via network resources and removable storage media. &lt;br /&gt;&lt;br /&gt;This modification of the worm is a Windows PE DLL file. The file is 158110 bytes in size. It is packed using UPX. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Infection&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The worm copies its executable file with random names to the following directories:&lt;br /&gt;&lt;br /&gt;%System%\&lt;rnd&gt;dir.dll&lt;br /&gt;%Program Files%\Internet Explorer\&lt;rnd&gt;.dll &lt;br /&gt;%Program Files%\Movie Maker\&lt;rnd&gt;.dll &lt;br /&gt;%All Users Application Data%\&lt;rnd&gt;.dll &lt;br /&gt;%Temp%\&lt;rnd&gt;.dll &lt;br /&gt;%System%\&lt;rnd&gt;tmp &lt;br /&gt;%Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;&lt;br /&gt;&lt;rnd&gt; is a random string of symbols.&lt;br /&gt;&lt;br /&gt;In order to ensure that the worm is launched next time the system is started, it creates a system service which launches the worm’s executable file each time Windows is booted. The following registry key will be created:&lt;br /&gt;&lt;br /&gt;[HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;&lt;br /&gt;The name of the service will be created from combining words from the list below:&lt;br /&gt;&lt;br /&gt;Boot &lt;br /&gt;Center &lt;br /&gt;Config &lt;br /&gt;Driver &lt;br /&gt;Helper &lt;br /&gt;Image &lt;br /&gt;Installer &lt;br /&gt;Manager &lt;br /&gt;Microsoft &lt;br /&gt;Monitor &lt;br /&gt;Network &lt;br /&gt;Security &lt;br /&gt;Server &lt;br /&gt;Shell &lt;br /&gt;Support &lt;br /&gt;System &lt;br /&gt;Task &lt;br /&gt;Time &lt;br /&gt;Universal &lt;br /&gt;Update &lt;br /&gt;Windows&lt;br /&gt;&lt;br /&gt;The worm also modifies the following system registry key value:&lt;br /&gt;&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs" = "&lt;original value&gt; %System%\&lt;rnd&gt;.dll"&lt;br /&gt;&lt;br /&gt;The worm hides its files in Explorer by modifying the registry key value shown below:&lt;br /&gt;&lt;br /&gt;[HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;"Hidden" = "dword: 0x00000002"&lt;br /&gt;"SuperHidden" = "dword: 0x00000000"&lt;br /&gt;&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] &lt;br /&gt;"CheckedValue" = "dword: 0x00000000"&lt;br /&gt;&lt;br /&gt;The worm flags its presence in the system by creating the unique identifier shown below:&lt;br /&gt;&lt;br /&gt;Global\%rnd%-%rnd%&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Propagation&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In order to spread quickly via networks, the worm uses tcpip.sys functions to increase the number of potential network connections. &lt;br /&gt;&lt;br /&gt;The worm connects to the servers shown below in order to determine the external IP address of the victim machine:&lt;br /&gt;&lt;br /&gt;http://www.getmyip.org&lt;br /&gt;http://www.whatsmyipaddress.com&lt;br /&gt;http://www.whatismyip.org&lt;br /&gt;http://checkip.dyndns.org&lt;br /&gt;&lt;br /&gt;The worm then launches an HTTP server on a random TCP port; this is then used to download the worm's executable file to other computers.&lt;br /&gt; &lt;br /&gt;Copies of the worm have the extensions listed below:&lt;br /&gt;.bmp &lt;br /&gt;.gif &lt;br /&gt;.jpeg &lt;br /&gt;.png &lt;br /&gt;&lt;br /&gt;The worm gets the IP addresses of computers in the same network as the victim machine and attacks them via a buffer overrun vulnerability (MS08-067) in the Server service. The worm sends a specially crafted RPC request to TCP ports 139 (NetBIOS) and 445 (Direct hosted SMB) remote machines on remote machines. This causes a buffer overrun when the wcscpy_s function is called in netapi32.dll, which launches code that downloads the worm's executable file to the victim machine and launches it. The worm is then installed on the new victim machine. &lt;br /&gt;&lt;br /&gt;The worm then hooks the NetpwPathCanonicalize API call (netapi.dll) to prevent buffer overruns caused by the absence of a check on the size of outgoing strings. By doing this, the worm makes repeat exploitation of the vulnerability impossible. &lt;br /&gt;&lt;br /&gt;In order to speed up propagation, the worm modifies the following registry value:&lt;br /&gt;&lt;br /&gt;[HKLM\ SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]&lt;br /&gt;"TcpNumConnections" = "dword:0x00FFFFFE"&lt;br /&gt;&lt;br /&gt;In order to exploit the vulnerability described above, the worm attempts to connect to the Administrator account on the remote machine. It searches the network for an appropriate machine and gets a list of users. &lt;br /&gt;&lt;br /&gt;In order to gain administrator access, the worm copies itself to the following shared folders:&lt;br /&gt;&lt;br /&gt;\\*&lt;name of host&gt;\ADMIN$\System32\&lt;rnd&gt;.&lt;rnd&gt; &lt;br /&gt;\\&lt;name of host&gt;\IPC$\&lt;rnd&gt;.&lt;rnd&gt; &lt;br /&gt;&lt;br /&gt;The worm can then be launched remotely or scheduled for remote launch using the following commands:&lt;br /&gt;&lt;br /&gt;rundll32.exe &lt;path to worm file&gt;, &lt;rnd&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Spreading via removable storage media&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The worm copies its executable file to all removable media under the following name:&lt;br /&gt;&lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;- &lt;br /&gt;%d%&gt;-%d%&gt;\&lt;rnd&gt;.vmx, rnd is a string of random lower case letters; d is a random number; X&lt;br /&gt;is the disk&lt;br /&gt;&lt;br /&gt;In addition to its executable file, the worm also places the file shown below in the root of every disk:&lt;br /&gt;&lt;X&gt;:\autorun.inf&lt;br /&gt;&lt;br /&gt;This file will launch the worm's executable file each time Explorer is used to open the infected disk. &lt;br /&gt;&lt;br /&gt;When launching, the worm injects its code into the address space of one of the “svchost.exe” system processes. (The worm may also write its code to the “explorer.exe” and “services.exe” processes.) This code delivers the worm's main malicious payload and:&lt;br /&gt;&lt;br /&gt;1. disables the following services: &lt;br /&gt;2. Windows Automatic Update Service (wuauserv) &lt;br /&gt;3. Background Intelligent Transfer Service (BITS) &lt;br /&gt;4. Windows Security Center Service (wscsvc) &lt;br /&gt;5. Windows Defender Service (WinDefend, WinDefender) &lt;br /&gt;6. Windows Error Reporting Service (ERSvc) &lt;br /&gt;Windows Error Reporting Service (WerSvc) &lt;br /&gt;7. blocks access to addresses which contain any of the strings listed below: &lt;br /&gt;8. nai &lt;br /&gt;9. ca &lt;br /&gt;10. avp &lt;br /&gt;11. avg &lt;br /&gt;12. vet &lt;br /&gt;13. bit9 &lt;br /&gt;14. sans &lt;br /&gt;15. cert &lt;br /&gt;16. windowsupdate&lt;br /&gt;17. wilderssecurity&lt;br /&gt;18. threatexpert&lt;br /&gt;19. castlecops&lt;br /&gt;20. spamhaus&lt;br /&gt;21. cpsecure&lt;br /&gt;22. arcabit&lt;br /&gt;23. emsisoft&lt;br /&gt;24. sunbelt&lt;br /&gt;25. securecomputing&lt;br /&gt;26. rising&lt;br /&gt;27. prevx&lt;br /&gt;28. pctools&lt;br /&gt;29. norman&lt;br /&gt;30. k7computing&lt;br /&gt;31. ikarus&lt;br /&gt;32. hauri&lt;br /&gt;33. hacksoft&lt;br /&gt;34. gdata&lt;br /&gt;35. fortinet&lt;br /&gt;36. ewido&lt;br /&gt;37. clamav&lt;br /&gt;38. comodo&lt;br /&gt;39. quickheal&lt;br /&gt;40. avira&lt;br /&gt;41. avast&lt;br /&gt;42. esafe&lt;br /&gt;43. ahnlab&lt;br /&gt;44. centralcommand&lt;br /&gt;45. drweb&lt;br /&gt;46. grisoft&lt;br /&gt;47. eset&lt;br /&gt;48. nod32&lt;br /&gt;49. f-prot&lt;br /&gt;50. jotti&lt;br /&gt;51. kaspersky&lt;br /&gt;52. f-secure&lt;br /&gt;53. computerassociates&lt;br /&gt;54. networkassociates&lt;br /&gt;55. etrust&lt;br /&gt;56. panda&lt;br /&gt;57. sophos&lt;br /&gt;58. trendmicro&lt;br /&gt;59. mcafee&lt;br /&gt;60. norton&lt;br /&gt;61. symantec&lt;br /&gt;62. microsoft&lt;br /&gt;63. defender&lt;br /&gt;64. rootkit&lt;br /&gt;65. malware&lt;br /&gt;66. spyware&lt;br /&gt;virus&lt;br /&gt;&lt;br /&gt;In Windows Vista, the worm will disable autoconfiguration of the TCP/IP stack in order to speed up propagation via network channels by using a fixed window size for TCP packets:&lt;br /&gt;&lt;br /&gt;netsh interface tcp set global autotuning=disabled&lt;br /&gt;The worm also hooks the following API calls (dnsrslvr.dll) in order to block access to the list of user domains:&lt;br /&gt;&lt;br /&gt;DNS_Query_A &lt;br /&gt;DNS_Query_UTF8 &lt;br /&gt;DNS_Query_W &lt;br /&gt;Query_Main &lt;br /&gt;sendto &lt;br /&gt;&lt;br /&gt;The worm may also download files from links of the type shown below:&lt;br /&gt;http://&lt;URL&gt;/search?q=&lt;%rnd2%&gt;&lt;br /&gt;&lt;br /&gt;rnd2 is a random number; URL is a link generated by a special algorithm which uses the current date. The worm gets the current date from one of the sites shown below:&lt;br /&gt;&lt;br /&gt;http://www.w3.org&lt;br /&gt;http://www.ask.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.yahoo.com&lt;br /&gt;http://www.google.com&lt;br /&gt;http://www.baidu.com &lt;br /&gt;http://www.myspace.com&lt;br /&gt;http://www.msn.com&lt;br /&gt;http://www.ebay.com&lt;br /&gt;http://www.cnn.com&lt;br /&gt;http://www.aol.com &lt;br /&gt;&lt;br /&gt;Downloaded files are saved to the Windows system directory under their original names. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Removal Guide&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus solution, or does not have an antivirus solution at all, you can either use a special removal tool (which can be found here or follow the instructions below:&lt;br /&gt;More details about the vulnerability can be found here: &lt;br /&gt;http://www.kaspersky.ru/support/wks6mp3/error?qid=208636215&lt;br /&gt;Or follow the instructions below:&lt;br /&gt;&lt;br /&gt;1. Delete the following system registrykey: &lt;br /&gt;[HKLM\SYSTEM\CurrentControlSet\Services\netsvcs]&lt;br /&gt;&lt;br /&gt;2. Delete “%System%\&lt;rnd&gt;.dll” from the system registry key value shown below: &lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] &lt;br /&gt;"netsvcs"&lt;br /&gt;&lt;br /&gt;3. Revert the following registry key values: &lt;br /&gt;[HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] &lt;br /&gt;"Hidden" = "dword: 0x00000002"&lt;br /&gt;"SuperHidden" = "dword: 0x00000000"&lt;br /&gt;to&lt;br /&gt;[HKCR\ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] &lt;br /&gt;"Hidden" = "dword: 0x00000001"&lt;br /&gt;"SuperHidden" = "dword: 0x00000001"&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] &lt;br /&gt;"CheckedValue" = "dword: 0x00000000"&lt;br /&gt;to&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] &lt;br /&gt;"CheckedValue" = "dword: 0x00000001"&lt;br /&gt;&lt;br /&gt;4. Reboot the computer. &lt;br /&gt;&lt;br /&gt;5. Delete the original worm file (the location will depend on how the program originally penetrated the victim machine). &lt;br /&gt;&lt;br /&gt;6. Delete copies of the worm: &lt;br /&gt;&lt;br /&gt;7. %System%\&lt;rnd&gt;dir.dll&lt;br /&gt;&lt;br /&gt;8. %Program Files%\Internet Explorer\&lt;rnd&gt;.dll &lt;br /&gt;&lt;br /&gt;9. %Program Files%\Movie Maker\&lt;rnd&gt;.dll&lt;br /&gt;&lt;br /&gt;10. %All Users Application Data%\&lt;rnd&gt;.dll &lt;br /&gt;&lt;br /&gt;11. %Temp%\&lt;rnd&gt;.dll &lt;br /&gt;&lt;br /&gt;12. %System%\&lt;rnd&gt;tmp &lt;br /&gt;%Temp%\&lt;rnd&gt;.tmp&lt;br /&gt;&lt;rnd&gt; is a random string of symbols. &lt;br /&gt;&lt;br /&gt;13. Delete the files shown below from all removable storage media: &lt;br /&gt;&lt;br /&gt;&lt;X&gt;:\autorun.inf&lt;br /&gt;&lt;X&gt;:\RECYCLER\S-&lt;%d%&gt;-&lt;%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;-%d%&gt;- &lt;br /&gt;%d%&gt;\&lt;rnd&gt;.vmx,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-69096661608184778?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/69096661608184778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=69096661608184778' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/69096661608184778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/69096661608184778'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2009/02/net-wormwin32kido.html' title='Net-Worm.Win32.Kido'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-2661092177006064505</id><published>2008-12-09T19:00:00.000-08:00</published><updated>2008-12-09T19:07:47.074-08:00</updated><title type='text'>Trojan-PSW.Win32.OnLineGames.sxa / Kavo.exe</title><content type='html'>&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This malicious program is a Trojan. It is a Windows PE EXE file. It is 118103 bytes in size.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Infection&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Trojan copies its executable file to the Windows system directory: &lt;br /&gt;&lt;br /&gt;%System%\kavo.exe&lt;br /&gt;&lt;br /&gt;In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"kava" = "%System%\kavo.exe"&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Trojan also extracts the file shown below from its body:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;%System%\kavo0.dll&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This file is 114176 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.OnLineGames.szc.&lt;br /&gt;&lt;br /&gt;The Trojan also extracts the file shown below from its body:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;%Temp%\&lt;random symbols&gt;.dll&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This file is 29815 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-GameThief.Win32.OnLineGames.stcw.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The Trojan loads the .dll file to all processes launched in the system. &lt;br /&gt;The Trojan intercepts mouse and keyboard events if any of the processes below have been launched: &lt;br /&gt;&lt;br /&gt;maplestory.exe&lt;br /&gt;dekaron.exe&lt;br /&gt;gc.exe&lt;br /&gt;RagFree.exe&lt;br /&gt;Ragexe.exe&lt;br /&gt;ybclient.exe&lt;br /&gt;wsm.exe &lt;br /&gt;sro_client.exe&lt;br /&gt;so3d.exe&lt;br /&gt;ge.exe&lt;br /&gt;elementclient.exe&lt;br /&gt;&lt;br /&gt;It sniffs traffic sent to the following addresses:&lt;br /&gt;&lt;br /&gt;61.220.60.***&lt;br /&gt;61.220.62.***&lt;br /&gt;61.220.56.***&lt;br /&gt;61.220.62.***&lt;br /&gt;203.69.46.***&lt;br /&gt;220.130.113.*** &lt;br /&gt;&lt;br /&gt;It does this in an attempt to harvest account data for the following games:&lt;br /&gt;&lt;br /&gt;ZhengTu&lt;br /&gt;Wanmi Shijie or Perfect World&lt;br /&gt;Dekaron Siwan Mojie&lt;br /&gt;HuangYi Online&lt;br /&gt;Rexue Jianghu&lt;br /&gt;ROHAN&lt;br /&gt;Seal Online&lt;br /&gt;Maple Story&lt;br /&gt;R2 (Reign of Revolution)&lt;br /&gt;Talesweaver&lt;br /&gt;and some other games. The Trojan also analyses the configuration files of the games above and attempts to harvest information about gamers' accounts on the web &lt;br /&gt;server. &lt;br /&gt;&lt;br /&gt;Harvested data is sent to the remote malicious user's site.&lt;br /&gt; &lt;br /&gt;The Trojan also modifies the following system registry key parameter values: &lt;br /&gt;&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol&lt;br /&gt;der\Hidden\SHOWALL] &lt;br /&gt;"CheckedValue" = "0"&lt;br /&gt;&lt;br /&gt;[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;"Hidden" = "2"&lt;br /&gt;"ShowSuperHidden" = "0"&lt;br /&gt;&lt;br /&gt;[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]&lt;br /&gt;"NoDriveTypeAutoRun" = "0x91"&lt;br /&gt;&lt;br /&gt;The Trojan also attempts to terminate the following processes:&lt;br /&gt;KAV&lt;br /&gt;RAV&lt;br /&gt;AVP&lt;br /&gt;KAVSVC&lt;br /&gt;&lt;br /&gt;The Trojan also has worm functionality, making it able to propagate via removable storage media. The Trojan copies its executable file to the root of each drive as follows:&lt;br /&gt;&lt;br /&gt;&lt;X&gt;:\n6j.com&lt;br /&gt;&lt;X&gt; indicates the relevant disk.&lt;br /&gt;&lt;br /&gt;In addition to its executable file, the Trojan also places the file shown below in the root directory of every disk:&lt;br /&gt;&lt;x&gt;:\autorun.inf&lt;br /&gt;&lt;br /&gt;This file will launch the Trojan executable file each time the user opens the infected disk using Explorer. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Removal Guide&lt;/strong&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;&lt;br /&gt;1. Delete the following file: &lt;br /&gt;        %System%\kavo.exe &lt;br /&gt;&lt;br /&gt;2. Reboot the computer. &lt;br /&gt;&lt;br /&gt;3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). &lt;br /&gt;&lt;br /&gt;4. Delete the following system registry key parameter: &lt;br /&gt;        [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] &lt;br /&gt;        "kava" = "%System%\kavo.exe"&lt;br /&gt;&lt;br /&gt;5. Restore the original system registry key values: &lt;br /&gt;        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Fol&lt;br /&gt;der\Hidden\SHOWALL] &lt;br /&gt;        "CheckedValue" = "0"&lt;br /&gt;&lt;br /&gt;        [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]&lt;br /&gt;        "Hidden" = "2"&lt;br /&gt;        "ShowSuperHidden" = "0"&lt;br /&gt;&lt;br /&gt;        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Pocilies\Explorer]&lt;br /&gt;        "NoDriveTypeAutoRun" = "0x91"&lt;br /&gt;&lt;br /&gt;6. Delete the following file: &lt;br /&gt;        %System%\kavo0.dll&lt;br /&gt;&lt;br /&gt;7. Empty the temporary directory (%Temp%). &lt;br /&gt;&lt;br /&gt;8. Delete the files shown below from all removable disks: &lt;br /&gt;        &lt;X&gt;:\n6j.com&lt;br /&gt;        &lt;x&gt;:\autorun.inf&lt;br /&gt;        &lt;x&gt; stands for the letter of the removable disk. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.emailcashpro.com/?r=ladingmerah"&gt;&lt;img src="http://www.emailcashpro.com/images/emailcashpro1.gif" border="0" alt="http://www.emailcashpro.com"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.bio-asli.com/?id=ladingmerah" target="_blank"&gt;&lt;img src="http://i521.photobucket.com/albums/w337/buluhmaskk/bio-asli468.gif" border="0" alt="Pendaftaran Percuma"&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-2661092177006064505?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/2661092177006064505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=2661092177006064505' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2661092177006064505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2661092177006064505'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/12/trojan-pswwin32onlinegamessxa-kavoexe.html' title='Trojan-PSW.Win32.OnLineGames.sxa / Kavo.exe'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-8604039513227968946</id><published>2008-12-09T18:49:00.000-08:00</published><updated>2008-12-09T18:59:59.681-08:00</updated><title type='text'>Trojan-Downloader.JS.Small.fi</title><content type='html'>&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This Trojan downloads other files via the Internet and launches them for execution on the victim machine. The program is an HTML page which contains Java Script scenarios. It is 1432 bytes in size.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The Trojan downloads a file from the URL shown below by exploiting a vulnerability (CVE-2006-1359) in the processing of "createTextRange" in Microsoft Internet Explorer:&lt;br /&gt;&lt;br /&gt;http://195.62.***.21/a.exe&lt;br /&gt;&lt;br /&gt;The Trojan saves this file to its working directory as shown below:&lt;br /&gt;&lt;br /&gt;%WorkDir%\a.exe&lt;br /&gt;&lt;br /&gt;The downloaded file will then be launched for execution. &lt;br /&gt;At the time of writing, the link was not active. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Removal Guide&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;&lt;br /&gt;1. Use Task Manager to terminate the process shown below: &lt;br /&gt;        a.exe&lt;br /&gt;&lt;br /&gt;2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). &lt;br /&gt;&lt;br /&gt;3. Delete the following file: &lt;br /&gt;&lt;br /&gt;        %WorkDir%\a.exe&lt;br /&gt;&lt;br /&gt;4. Delete all files from %Temporary Internet Files%.&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.emailcashpro.com/?r=ladingmerah"&gt;&lt;img src="http://www.emailcashpro.com/images/emailcashpro1.gif" border="0" alt="http://www.emailcashpro.com"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.bio-asli.com/?id=ladingmerah" target="_blank"&gt;&lt;img src="http://i521.photobucket.com/albums/w337/buluhmaskk/bio-asli468.gif" border="0" alt="Pendaftaran Percuma"&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-8604039513227968946?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/8604039513227968946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=8604039513227968946' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/8604039513227968946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/8604039513227968946'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/12/trojan-downloaderjssmallfi.html' title='Trojan-Downloader.JS.Small.fi'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-7004713664817575189</id><published>2008-10-27T18:23:00.000-07:00</published><updated>2008-11-05T17:04:00.480-08:00</updated><title type='text'>Trojan-Downloader.Win32.Delf.cgx</title><content type='html'>&lt;strong&gt;Tecnical Details&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 48128 bytes in size. It is packed using PECompact. The unpacked file is approximately 131KB in size. It is written in Delphi.&lt;br /&gt;&lt;br /&gt;Simpton&lt;br /&gt;&lt;br /&gt;Once launched, the Trojan downloads files from the following URL:&lt;br /&gt;&lt;br /&gt;http://paginas.terra.com.br/*****/down2/code.jpg&lt;br /&gt;http://paginas.terra.com.br/*****/down1/lzma.jpg&lt;br /&gt;http://paginas.terra.com.br/*****/down1/branch.jpg&lt;br /&gt;http://paginas.terra.com.br/*****/down1/7z2.jpg&lt;br /&gt;http://paginas.terra.com.br/*****/down1/7z.jpg&lt;br /&gt;&lt;br /&gt;These files will be saved to the Windows root directory as follows:&lt;br /&gt;&lt;br /&gt;%WinDir%\krn.7z&lt;br /&gt;%WinDir%\7z\Codecs\lzma.dll&lt;br /&gt;%WinDir%\7z\Codecs\branch.dll&lt;br /&gt;%WinDir%\7z\Formats\7z.dll&lt;br /&gt;%WinDir%\7z\7z.exe&lt;br /&gt;&lt;br /&gt;The saved files are then launched for execution&lt;br /&gt;&lt;br /&gt;Removal instructions&lt;br /&gt;&lt;br /&gt;1. Use Task Manager to terminate the Trojan process. &lt;br /&gt;&lt;br /&gt;2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine). &lt;br /&gt;&lt;br /&gt;3. Delete the following files: &lt;br /&gt;&lt;br /&gt;%WinDir%\krn.7z&lt;br /&gt;%WinDir%\7z\Codecs\lzma.dll&lt;br /&gt;%WinDir%\7z\Codecs\branch.dll&lt;br /&gt;%WinDir%\7z\Formats\7z.dll&lt;br /&gt;%WinDir%\7z\7z.exe&lt;br /&gt;&lt;br /&gt;4. Delete all files from %Temporary Internet Files%&lt;br /&gt;&lt;br /&gt;&lt;!-- nuffnang --&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt; &lt;br /&gt;nuffnang_bid = "bd0703e8c892d1dae75d0fd3bd1daac4";&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://synad2.nuffnang.com.my/j.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;!-- nuffnang--&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.emailcashpro.com/?r=ladingmerah"&gt;&lt;img src="http://www.emailcashpro.com/images/emailcashpro1.gif" border="0" alt="http://www.emailcashpro.com"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-7004713664817575189?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/7004713664817575189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=7004713664817575189' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7004713664817575189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7004713664817575189'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/10/trojan-downloaderwin32delfcgx.html' title='Trojan-Downloader.Win32.Delf.cgx'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-3584736434129968498</id><published>2008-09-02T16:58:00.000-07:00</published><updated>2008-09-21T18:16:28.411-07:00</updated><title type='text'>Trojan-Downloader.Win32.Banload.dcd Virus</title><content type='html'>This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 113152 bytes in size. It is not packed in any way. This Trojan is written in Visual Basic.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;INSTALLATION&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Once launched, the Trojan copies its body to the Windows program files directory as "lsass.exe":&lt;br /&gt;&lt;br /&gt;%Program Files%\Microsoft Studio Files\lsass.exe&lt;br /&gt;&lt;br /&gt;In order to ensure that the Trojan is launched automatically each time the system is rebooted, the Trojan registers its executable file in the system registry:&lt;br /&gt;&lt;br /&gt;[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;&lt;br /&gt;"lsass" = "%Program Files%\Microsoft Studio Files\lsass.exe"&lt;br /&gt;&lt;br /&gt;The Trojan then creates a command interpreter file called "vcdg.bat" in the same directory:&lt;br /&gt;&lt;br /&gt;%Program Files%\Microsoft Studio Files\vcdg.bat&lt;br /&gt;&lt;br /&gt;It writes the following strings to this file:&lt;br /&gt;netsh.exe firewall add allowedprogram PROGRAM="%Program Files%\Microsoft Studio &lt;br /&gt;Files\lsass.exe" NAME="Session Win32" MODE=ENABLE PROFILE=ALL&lt;br /&gt;&lt;br /&gt;In doing so, the Trojan modifies the configuration of the Windows XP firewall, permitting any network activity created by the malicious process. &lt;br /&gt;&lt;br /&gt;"%Program Files%\Microsoft Studio Files\vcdg.bat" is then launched for execution. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;PAYLOAD&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Once installed, the Trojan downloads files from the following URLs:&lt;br /&gt;&lt;br /&gt;http://www.club-vw.cl/*****/modules/subsmanager/api_apache.tar&lt;br /&gt;http://www.*****-consult.net/rcss.res&lt;br /&gt;http://www.photo-*****.ru/images/exhibition_moll2005_file0031.jpg&lt;br /&gt;&lt;br /&gt;At the time of writing, these links were not active.&lt;br /&gt; &lt;br /&gt;http://www.cemm*****ac.at/img/nav/plus19a_RO.jpg&lt;br /&gt;&lt;br /&gt;This file is 2603325 bytes in size. It will be detected by Kaspersky Anti-Virus as Trojan-Spy.Win32.Banbra.bak. &lt;br /&gt;&lt;br /&gt;Files which are downloaded are saved to the Trojan's installation directory under random names and launched for execution.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;REMOVAL GUIDE&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;&lt;br /&gt;1. Use Task Manager to terminate the Trojan process.&lt;br /&gt; &lt;br /&gt;2. Delete the following system registry key parameter: &lt;br /&gt;[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"lsass" = "%Program Files%\Microsoft Studio Files\lsass.exe"&lt;br /&gt;&lt;br /&gt;3. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).&lt;br /&gt; &lt;br /&gt;4. Delete the following directory and its contents: &lt;br /&gt;%Program Files%\Microsoft Studio Files&lt;br /&gt;&lt;br /&gt;5. Delete all files from %Temporary Internet Files%.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.modelbisnesinternet.com/index.php?ref=ladingmerah&gt; &lt;strong&gt;&lt;em&gt;Ingin Mengetahui Meningkatkan Traffik bagi perniagaan internet anda???&lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.pancutkanisteri.com/index.php?ref=ladingmerah&gt;&lt;strong&gt;&lt;em&gt;Ingin Mengetahui Cara untuk Menjadi 'Pria Terhebat' ??????&lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.rajaadsense.com/index.php?ref=ladingmerah&gt;&lt;em&gt;&lt;strong&gt;Ingin Mengetahui Rahsia Membuat Duit Tanpa Modal Dengan Google Adsense???&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.modelbisnesinternet.com/index.php?ref=ladingmerah&gt;&lt;strong&gt;&lt;em&gt;Ingin Mengetahui bagaimana caranya individu menjana pendapatan lumayan melalui Internet??? &lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-3584736434129968498?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/3584736434129968498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=3584736434129968498' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3584736434129968498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3584736434129968498'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/09/trojan-downloaderwin32banloaddcd-virus.html' title='Trojan-Downloader.Win32.Banload.dcd Virus'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-2672078832271739238</id><published>2008-08-27T19:44:00.000-07:00</published><updated>2008-08-27T19:46:26.245-07:00</updated><title type='text'>Backdoor.Win32.Agent.ich</title><content type='html'>&lt;strong&gt;Details&lt;/strong&gt;&lt;br /&gt;This Trojan provides a remote malicious user with access to the victim machine. It is a Windows PE EXE file. It is 48640 bytes in size. It is packed using UPX. The unpacked file is approximately 360KB in size. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Installation&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Trojan extracts the following file from its body:&lt;br /&gt;%System%\aspimgr.exe&lt;br /&gt;&lt;br /&gt;This file is 73728 bytes in size. Kaspersky Anti-Virus does not detect this file as malicious. &lt;br /&gt;&lt;br /&gt;The original file will then be deleted.&lt;br /&gt;&lt;br /&gt;The backdoor creates a service called "Microsoft ASPI Manager" which ensures the backdoor executable file will be launched each time the victim machine is restarted.&lt;br /&gt;The Trojan launches a HTTP proxy server on the victim machine on TCP port 80. It then sends notification that the victim machine has been infected to the addresses shown below:&lt;br /&gt;&lt;br /&gt;66.199.241.98&lt;br /&gt;82.103.140.75&lt;br /&gt;203.117.175.124&lt;br /&gt;72.21.63.114&lt;br /&gt;66.232.102.169&lt;br /&gt;66.96.196.53&lt;br /&gt;&lt;br /&gt;It does this by sending HTTP requests. Once infected, the victim machine becomes part of a zombie network and can be used to send spam or to conduct DoS attacks. &lt;br /&gt;&lt;br /&gt;The backdoor creates the following log files:&lt;br /&gt;&lt;br /&gt;%WinDir%\ws386.ini&lt;br /&gt;%WinDir%\db32.txt&lt;br /&gt;%WinDir%\s32.txt&lt;br /&gt;%WinDir%\f32.txt&lt;br /&gt;&lt;br /&gt;It creates the following registry key:&lt;br /&gt;&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Sft]&lt;br /&gt;&lt;br /&gt;and saves its configuration to this key.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Removal Guide&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;&lt;br /&gt;1. Use Task Manager to terminate the malicious process &lt;br /&gt;&lt;br /&gt;2. Delete the following registry key: &lt;br /&gt;&lt;br /&gt;[HKLM\SOFTWARE\Microsoft\Sft]&lt;br /&gt;&lt;br /&gt;3. Delete the "Microsoft ASPI Manager" service. &lt;br /&gt;&lt;br /&gt;4. Delete the following files: &lt;br /&gt;&lt;br /&gt;%WinDir%\ws386.ini&lt;br /&gt;%WinDir%\db32.txt&lt;br /&gt;%WinDir%\s32.txt&lt;br /&gt;%WinDir%\f32.txt&lt;br /&gt;%System%\aspimgr.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tips about How to Choose Computer&lt;br /&gt;&lt;br /&gt;Check Out &lt;br /&gt;&lt;br /&gt;&lt;a href="http://choosingcomputer.blogspot.com"&gt;http://choosingcomputer.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-2672078832271739238?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/2672078832271739238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=2672078832271739238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2672078832271739238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/2672078832271739238'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/backdoorwin32agentich.html' title='Backdoor.Win32.Agent.ich'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-4260278045185123094</id><published>2008-08-27T19:37:00.000-07:00</published><updated>2008-08-27T19:43:52.273-07:00</updated><title type='text'>Trojan.Win32.Agent.dcc</title><content type='html'>Once launched, the Trojan copies its executable file as shown below:&lt;br /&gt;%System%\drivers\runtime.sys&lt;br /&gt;&lt;br /&gt;In order to ensure that the Trojan is launched each time the system is started, it creates a system service called "Runtime" which launches the Trojan executable file each time Windows is booted. The following registry key will be created:&lt;br /&gt;&lt;br /&gt;[HKLM\System\CurrentControlSet\Services\runtime]&lt;br /&gt;&lt;br /&gt;Once installed, the Trojan deletes its original file. &lt;br /&gt;&lt;br /&gt;This Trojan has a malicious payload. It is a Windows PE EXE file. It is 20480 bytes in size.&lt;br /&gt;&lt;br /&gt;The Trojan contains a rootkit driver which masks the presence of Trojan files on the hard disk, and also the presence of the files listed below:&lt;br /&gt;&lt;br /&gt;%System%\ntoskrnl.exe&lt;br /&gt;%System%\ntkrnlpa.exe&lt;br /&gt;%System%\ntkrnlmp.exe&lt;br /&gt;%System%\ntkrpamp.exe&lt;br /&gt;&lt;br /&gt;It also masks the presence of processes related to these files. &lt;br /&gt;The Trojan also launches a hidden process called "iexplore.exe". It injects its code into this process, which will then download files from the following addresses:&lt;br /&gt;&lt;br /&gt;208.66.194.*** &lt;br /&gt;66.246.252.*** &lt;br /&gt;208.66.195.*** &lt;br /&gt;74.53.42.*** &lt;br /&gt;74.53.42.*** &lt;br /&gt;&lt;br /&gt;Downloaded files will be saved as:&lt;br /&gt;&lt;br /&gt;%TEMP%\&lt;rnd&gt;.exe&lt;br /&gt;&lt;br /&gt;with &lt;rnd&gt; standing for a random sequence of numbers. &lt;br /&gt;&lt;br /&gt;Once downloaded, the files will be launched for execution. &lt;br /&gt;&lt;br /&gt;Removal Guide&lt;br /&gt;&lt;br /&gt;If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:&lt;br /&gt;&lt;br /&gt;1. Use Task Manager to terminate the malicious program’s process. &lt;br /&gt;&lt;br /&gt;2. Delete the following system registry key: &lt;br /&gt;&lt;br /&gt;[HKLM\System\CurrentControlSet\Services\runtime]&lt;br /&gt;&lt;br /&gt;3. Delete the following file: &lt;br /&gt;&lt;br /&gt;%System%\drivers\runtime.sys&lt;br /&gt;&lt;br /&gt;4. Delete the contents of %Temp% &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tips about How to Choose Computer&lt;br /&gt;&lt;br /&gt;Check Out &lt;br /&gt;&lt;br /&gt;&lt;a href="http://choosingcomputer.blogspot.com"&gt;http://choosingcomputer.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-4260278045185123094?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/4260278045185123094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=4260278045185123094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/4260278045185123094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/4260278045185123094'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/trojanwin32agentdcc.html' title='Trojan.Win32.Agent.dcc'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-7354669600362221096</id><published>2008-08-26T16:12:00.000-07:00</published><updated>2010-11-22T22:43:12.312-08:00</updated><title type='text'>DriveGuard.exe Or FlashGuard.exe Virus</title><content type='html'>This virus also known as Worm.Win32.Autoit.au - kaspersky, this worm tries to impersonate a friendly application one that wants to protect your removable drives from other pieces of malware.&lt;br /&gt;&lt;br /&gt;It also includes a readme file that reads:&lt;br /&gt;"This tiny software is used to protect removable storage devices from&lt;br /&gt;worms that are spread from one PC to another. "&lt;br /&gt;&lt;br /&gt;But at the same time it will download backdoor files..&lt;br /&gt;&lt;br /&gt;You can locate the virus at c:\Program Files\FlashGuard\FlashGuard.exe only if you unhide hidden files already(How to Unhide Hidden Files Guide)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSSFESeFwI/AAAAAAAAAB8/-tNIQSKAmqU/s1600-h/Flash.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSSFESeFwI/AAAAAAAAAB8/-tNIQSKAmqU/s320/Flash.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5238972882286941954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The malicious file would copy itself to :&lt;br /&gt;&lt;br /&gt;c:\Program Files\FlashGuard\FlashGuard.exe &lt;br /&gt;c:\Program Files\FlashGuard\ReadMe.txt&lt;br /&gt;c:\DocumentsandSettings\**UserProfile\LocalSettings\Temp\DriveGuard.tmp.exe &lt;br /&gt;c:\DocumentsandSettings\**UserProfile\LocalSettings\Temp\gHmpg.tmp.exe&lt;br /&gt;&lt;br /&gt;It create folders in your pendrive &amp; copy itself to :&lt;br /&gt;&lt;br /&gt;f:\System\Security\DriveGuard.exe *&lt;br /&gt;f:\autorun.ini *&lt;br /&gt;&lt;br /&gt;*[f:\] drive letter could vary depend on how Windows assign/mount your pendrive&lt;br /&gt;&lt;br /&gt;Create startup launcher(Registry) :&lt;br /&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FlashGuard&lt;br /&gt;&lt;br /&gt;To see these virus you must set Windows to show hidden files - Guide&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Removal Guide :&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Press Ctrl+Alt+Del to open 'Task Manager', select FlashGuard.exe &amp; click 'End Process'&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/SLSSO8SePtI/AAAAAAAAACE/-aK6O2rdyZU/s1600-h/Task.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/SLSSO8SePtI/AAAAAAAAACE/-aK6O2rdyZU/s320/Task.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5238973051938160338" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can browse to the folder mentioned above or you can find it quickly by using 'Search' feature(Start Menu&gt;&gt;Search). In the search box type, flashguard.exe or flashguard. Don't hit the search button yet..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSScshsi-I/AAAAAAAAACM/xGh5Xs6HLpY/s1600-h/search.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSScshsi-I/AAAAAAAAACM/xGh5Xs6HLpY/s320/search.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238973288225213410" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Scroll down &amp; expand 'More Advanced Options'.Check the all the box as you see in the screenshot below &amp; hit 'Search' button..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_-RTTc4l_elM/SLSS05nmNfI/AAAAAAAAACU/8Tu3XHbkz4I/s1600-h/search2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_-RTTc4l_elM/SLSS05nmNfI/AAAAAAAAACU/8Tu3XHbkz4I/s320/search2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238973704056485362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Delete all the files found..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSTAlIgsdI/AAAAAAAAACc/-CYRd1rauN4/s1600-h/result.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_-RTTc4l_elM/SLSTAlIgsdI/AAAAAAAAACc/-CYRd1rauN4/s320/result.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238973904715821522" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also serch for .tmp.exe, delete DriveGuard.tmp.exe &amp; gHmpg.tmp.exe files found..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SLSTNtqeC8I/AAAAAAAAACk/afhO795oheY/s1600-h/result2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SLSTNtqeC8I/AAAAAAAAACk/afhO795oheY/s320/result2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238974130344037314" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The virus files can easily recognized with pendrive like icon..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SLSTa3WMxQI/AAAAAAAAACs/6kWib95Znjw/s1600-h/pendrive.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SLSTa3WMxQI/AAAAAAAAACs/6kWib95Znjw/s320/pendrive.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238974356281672962" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Your pc now clean from the virus, since the virus load at startup, it left an entry in your registry, you can delete it in registry or you can go to Start Menu&gt;&gt;Run, type msconfig &amp; click 'Ok'.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-RTTc4l_elM/SLSTeNubpuI/AAAAAAAAAC0/jkKpN90ZjNM/s1600-h/msconfig.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_-RTTc4l_elM/SLSTeNubpuI/AAAAAAAAAC0/jkKpN90ZjNM/s320/msconfig.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238974413828499170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Select 'Startup' tab, select &amp; uncheck FlashGuard. Click 'Apply' to take effect..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Delete Registry Entry : Go to Start Menu&gt;&gt;Run, type regedit &amp; click 'Ok'&lt;br /&gt;Browse to :&lt;br /&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FlashGuard&lt;br /&gt;Select FlashGuard, right-click on it &amp; delete..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_-RTTc4l_elM/SLSThFusQpI/AAAAAAAAAC8/bosUaUpr9PU/s1600-h/regedit.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_-RTTc4l_elM/SLSThFusQpI/AAAAAAAAAC8/bosUaUpr9PU/s320/regedit.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5238974463221711506" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;FlashGuard.exe cleaned..&lt;br /&gt;If you new on manually on removing virus, this guide also useful for other type of virus too, especially the type that infecting removable drive(pendrive/flashdrive/memory card). It also depend on how strong the viruses, some viruses replicate itself with random/different file name(hard to find). As you can see FlashGuard.exe replicate itself as DriveGuard.tmp.exe &amp; gHmpg.tmp.exe.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.kerja-kerajaan.com/index.php?ref=ladingmerah&gt;&lt;img src=http://www.kerja-kerajaan.com/images/125x125.gif&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-7354669600362221096?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/7354669600362221096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=7354669600362221096' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7354669600362221096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7354669600362221096'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/driveguardexe-or-flashguardexe-virus.html' title='DriveGuard.exe Or FlashGuard.exe Virus'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_-RTTc4l_elM/SLSSFESeFwI/AAAAAAAAAB8/-tNIQSKAmqU/s72-c/Flash.JPG' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-7194076337890227436</id><published>2008-08-26T15:41:00.000-07:00</published><updated>2008-08-27T16:54:58.460-07:00</updated><title type='text'>system.exe backdoor spyware</title><content type='html'>&lt;strong&gt;System.exe is a Backdoor W32.Spybot.OBB. &lt;br /&gt;System.exe spreads by e-mail and via network shares.&lt;br /&gt;System.exe monitors user Internet activity and private information.&lt;br /&gt;It sends stolen data to a hacker site&lt;/strong&gt;&lt;br /&gt;Related files :&lt;br /&gt;&lt;br /&gt;"c:\Windows\system.exe" or "c:\Windows\system32\system.exe"&lt;br /&gt;&lt;br /&gt;Solution : &lt;br /&gt;&lt;br /&gt;1. update your antivirus and scan it ... ehehehe&lt;br /&gt;2. Manual Removal &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MANUAL REMOVAL&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Step 1: Use Windows File Search Tool to Find system.exe Path&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. Go to Start &gt; Search &gt; All Files or Folders. &lt;br /&gt;2. In the "All or part of the the file name" section, type in " system.exe" file name(s). &lt;br /&gt;3. To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button. &lt;br /&gt;4. When Windows finishes your search, hover over the "In Folder" of " system.exe", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete system.exe in the following manual removal steps.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 2: Use Windows Task Manager to Remove system.exe Processes&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC. &lt;br /&gt;2. Click on the "Image Name" button to search for " system.exe" process by name. &lt;br /&gt;3. Select the " system.exe" process and click on the "End Process" button to kill it.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Step 3: Detect and Delete Other system.exe Files&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;1. To open the Windows Command Prompt, go to Start &gt; Run &gt; cmd and then press the "OK" button. &lt;br /&gt;2. Type in "dir /A name_of_the_folder" (for example, C:\Spyware-folder), which will display the folder's content even the hidden files. &lt;br /&gt;3. To change directory, type in "cd name_of_the_folder". &lt;br /&gt;4. Once you have the file you're looking for type in del "name_of_the_file". &lt;br /&gt;5. To delete a file in folder, type in "del name_of_the_file". &lt;br /&gt;6. To delete the entire folder, type in "rmdir /S name_of_the_folder". &lt;br /&gt;7. Select the " system.exe" process and click on the "End Process" button to kill it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tips About Choosing Your Computer&lt;br /&gt;Check Out &lt;br /&gt;&lt;br /&gt;&lt;a href="http://choosingcomputer.blogspot.com"&gt;http://choosingcomputer.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-7194076337890227436?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/7194076337890227436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=7194076337890227436' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7194076337890227436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/7194076337890227436'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/systemexe-backdoor-spyware.html' title='system.exe backdoor spyware'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-3273129868983931398</id><published>2008-08-26T02:54:00.000-07:00</published><updated>2008-08-27T16:56:23.161-07:00</updated><title type='text'>Virus "81u3f4nt45y - 24.01.2007 - Surabaya”</title><content type='html'>Jika anda dipaparkan dengan message seperti dibawah setiap kali anda menghidupkan komputer anda bererti anda sudah terkena virus: &lt;br /&gt;&lt;br /&gt;“Surabaya in my birthday&lt;br /&gt;Don’t kill me, i’m just send message from your computer&lt;br /&gt;Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti&lt;br /&gt;Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku&lt;br /&gt;Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan dalam sesal&lt;br /&gt;Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0″&lt;br /&gt;&lt;br /&gt;Cara untuk membuang virus pesanan ini: &lt;br /&gt;&lt;br /&gt;1.klik ke &lt;em&gt;start&lt;/em&gt;-&gt; &lt;em&gt;run&lt;/em&gt; kemudian taip &lt;em&gt;regedit&lt;/em&gt; dan enter.&lt;br /&gt;&lt;br /&gt;2.Setelah program register editor muncul, sila klik urutan berikut pada window kiri :&lt;br /&gt;&lt;br /&gt;“HKEY_LOCAL_MACHINE” -&gt; “SOFTWARE” -&gt; “Microsoft” -&gt; “Windows NT” -&gt; “Current Version” -&gt; “WinLogon”.&lt;br /&gt;&lt;br /&gt;dibahagian kanan window, delete item “LegalNoticeCaption” dan “LegalNoticeText”.&lt;br /&gt;&lt;br /&gt;3. selesai&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tips About Choosing Your Computer&lt;br /&gt;Check Out &lt;br /&gt;&lt;br /&gt;&lt;a href="http://choosingcomputer.blogspot.com"&gt;http://choosingcomputer.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-3273129868983931398?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/3273129868983931398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=3273129868983931398' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3273129868983931398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/3273129868983931398'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/virus-81u3f4nt45y-24012007-surabaya.html' title='Virus &quot;81u3f4nt45y - 24.01.2007 - Surabaya”'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4042542981961052657.post-5686582627272006370</id><published>2008-08-26T02:42:00.000-07:00</published><updated>2008-08-27T16:57:42.620-07:00</updated><title type='text'>HOW TO REMOVE PC-OFF.BAT Trojan</title><content type='html'>1. Open "task manager" by pressing CTRL-ALT-DEL. Under tab 'processes', select 'password_viewer.exe' or 'bar311.exe' or 'photo.zip.exe' and Click ‘End Process’&lt;br /&gt;&lt;br /&gt;2. Open "register editor"( click 'START’--&gt; ‘RUN’ ,  type “regedit”) .&lt;br /&gt;&lt;br /&gt;• GO TO ‘HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon’&lt;br /&gt;&lt;br /&gt;FIND KEY &lt;br /&gt;"Userinit" = C:\WINDOWS\system32\userinit.exe,bar311.exe" &lt;br /&gt;----&gt; remove value ‘bar311.exe’ ONLY!!!!&lt;br /&gt;  OR&lt;br /&gt;"Userinit" = C:\WINDOWS\system32\userinit.exe,photo.zip.exe" &lt;br /&gt;----&gt; remove value ‘photo.zip.exe’ ONLY!!!!&lt;br /&gt;  OR&lt;br /&gt;"Userinit" = C:\WINDOWS\system32\userinit.exe,password_viewer.exe" &lt;br /&gt;----&gt; remove value ‘password_viewer.exe’ ONLY!!!!&lt;br /&gt;&lt;br /&gt;*/DO NOT REMOVE “USERINIT.EXE” VALUE OR “USERINIT” KEY, OR ELSE YOUR PC CANNOT ENTER YOUR WINDOWS/*&lt;br /&gt;&lt;br /&gt;• GO TO ‘HKEY_CURRENT_USER \software\microsoft\windows\currentversion\explorer\advanced’&lt;br /&gt;Change Value data for Key As Shown Below :- &lt;br /&gt;&lt;br /&gt;  "Hidden"=dword:00000001 (1)    - Change to ‘1’&lt;br /&gt;   "HideFileExt"=Dword:00000000 (0) - Change to ‘0’&lt;br /&gt;   "ShowSupperHidden"=Dword:00000001 (1) – Change to ‘1’&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;• GO TO&lt;br /&gt;‘HKEY_CURRENT_USER \software\microsoft\Command Processor’&lt;br /&gt;&lt;br /&gt;FIND KEY&lt;br /&gt;  &lt;br /&gt;"autorun=c:\windows\pc-off.bat" &lt;br /&gt;-----&gt; Remove "c:\windows\pc-off.bat" or Delete autorun key&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;. go to ThumbDrive DRIVE(Do not doubleclick the drive,Use Address panel to view file inside DRIVE)&lt;br /&gt;&lt;br /&gt;4. delete -  autorun.inf&lt;br /&gt;  password_viewer.exe&lt;br /&gt;  bar311.exe&lt;br /&gt;  photo.zip.exe&lt;br /&gt;&lt;br /&gt;5. Open Notepad and Type - &lt;br /&gt;&lt;br /&gt;@echo off&lt;br /&gt;del /a /f c:\windows\bar311.exe &lt;br /&gt;del /a /f c:\windows\password_viewer.exe&lt;br /&gt;del /a /f c:\windows\photo.zip.exe&lt;br /&gt;del /a /f c:\windows\pc-off.bat&lt;br /&gt;pause&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. Save As "remove.bat"&lt;br /&gt;&lt;br /&gt;7. Run remove.bat&lt;br /&gt;&lt;br /&gt;8. GO TO &lt;br /&gt; C:\Windows\&lt;br /&gt;&lt;br /&gt; Find bar311.exe OR password_viewer.exe OR photo.zip.exe OR pc-off.bat and delete it.&lt;br /&gt;&lt;br /&gt;Tips About Choosing Your Computer&lt;br /&gt;Check Out &lt;br /&gt;&lt;br /&gt;&lt;a href="http://choosingcomputer.blogspot.com"&gt;http://choosingcomputer.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4042542981961052657-5686582627272006370?l=ladingmerah.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ladingmerah.blogspot.com/feeds/5686582627272006370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4042542981961052657&amp;postID=5686582627272006370' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5686582627272006370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4042542981961052657/posts/default/5686582627272006370'/><link rel='alternate' type='text/html' href='http://ladingmerah.blogspot.com/2008/08/how-to-remove-pc-offbat-trojan.html' title='HOW TO REMOVE PC-OFF.BAT Trojan'/><author><name>LadingMerah</name><uri>http://www.blogger.com/profile/16626844920928861259</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://4.bp.blogspot.com/_-RTTc4l_elM/TLQUGlAzOlI/AAAAAAAAAMY/i7Qm5MCB--g/S220/computer-doctor.jpg'/></author><thr:total>1</thr:total></entry></feed>
