ODG Trojan any.exe file will not run

September 1st, 2009

This rootkit virus is nasty.  Upon arrival, any .exe file would not run.  The work around was to open for instance, malwarebytes.exe.  The standard "choose program to open this with dialog" comes up.  You have to browse to the original file, ie, malwarebytes and then it would open.  Annoying, but effective as most people wouldn't know to do this.

Once again, ONLY NOD32 detects it.  SO does GMER rootkit, but ONLY combofix removed it and it's not fast, it took about 30 to 45 minutes to get combofix to complete remove it.

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

Treesize and JDiskReport for Mac

August 21st, 2009

I love treesize for seeing the size of all the stuff on a PC.

For Mac's there a nice free utility that does about the same thing.

http://www.jgoodies.com/freeware/jdiskreport/

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

Recycle Bin Icon missing on Brand New Dell right out of the box.

August 17th, 2009

Method 1: Use the program that removed the Recycle Bin to restore the Recycle Bin

Note If you used the TweakUI program to hide the Recycle Bin, follow these steps to restore the Recycle Bin to the desktop. If you did not use the TweakUI program, see Method 2 or Method 3.

Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

322756  (http://support.microsoft.com/kb/322756/ ) How to back up and restore the registry in Windows
  1. Click Start, click Run, type regedit, and then click OK.
  2. If you are using the standard Windows XP Start menu
    1. Locate the following registry key:
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel
    2. In the right pane, right-click the following registry DWORD value, and then click Modify:
      {645FF040-5081-101B-9F08-00AA002F954E}
    3. In the Value data box, type 0, and then click OK. (The TweakUI utility sets this value to 1 to hide the Recycle Bin icon.)

    If you are using the classic Windows XP Start menu

    1. Locate the following registry key:
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu
    2. In the right pane, right-click the following registry DWORD value, and then click Modify:
      {645FF040-5081-101B-9F08-00AA002F954E}
    3. In the Value data box, type 0, and then click OK. (The TweakUI utility sets this value to 1 to hide the Recycle Bin icon.)
  3. Click Exit to exit Registry Editor.




Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

iPhone supports gmail contact and calendar sync

July 23rd, 2009

An ‘exchange’ account can be added to an iPhone for OTA calendar and contact syncing.  A gmail or google apps account is needed.

 

http://www.google.com/mobile/products/sync.html#p=apple

 

It works pretty well, but it will wipe the contacts that are on the phone.

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office
kurt@mobilecomputerwizard.com

MCWgif
www.mobilecomputerwizard.com

 

Vista User Profile Corrupt repair

July 15th, 2009

This was quite a ‘Hail Mary’ Fix, but it worked.  I had a client who randomly lost all of her personalized profile settings for itunes, outlook, desktop etc.  It was like she got a fresh profile.  After creating a second profile.  I got prompted with “The User Profile Service service failed the logon. User profile cannot be loaded.”

 

Anyway, I successfully repaired the userprofile by doing the below.  The original link to all this with a few other options is.

 

http://www.vistax64.com/tutorials/130095-user-profile-service-failed-logon-user-profile-cannot-loaded.html

 

 

1. Open the Start menu.

2. In the white line (Start Search) area, type regedit and press Enter.

3. If prompted, either click on Continue or enter the password for the Administrator account.

4. In regedit, go to: (See screenshot below step 5)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

5. In the left pane, look for the S-1-5….. folder (SID key) with the long number that has .bak at the end of the numbers.
(See screenshots below steps 6A and 7B)
NOTE:
A) In the right pane, look at the ProfileImagePath to verify that this is the user account profile that has the error.
B) You may have another S-1-5….. folder (SID key) above it with the exact same number without the .bak at the end of it.

6. For Two S-1-5….. folders (SID key) with the same Number -
NOTE: This is if you have two S-1-5….. folders (SID key) with the exact same numbers, but the second (below) one has the .bak at the end of the numbers.

A) In the left pane, right click on the first (top) S-1-5….. folder (SID key) that does not have .bak at the end of the numbers and click Rename. (See screenshot below)

repair.jpg

B) Add .bk to the end of the numbers. (See screenshot below)

repair_bk.jpg

C) In the left pane, right click on the second S-1-5….. folder (SID key) with .bak at the end of the numbers and click Rename. (See screenshot above)

D) Remove only .bak from the end of the numbers and press Enter. (See screenshot below)

E) Now go back and Rename the first one with .bk to .bak now at the end of the numbers and press Enter.

repar_bak.jpg

F) Go to step 8.

7. For Only One S-1-5….. Folder (SID key) with .bak -
NOTE: This is if you only have one S-1-5….. folder (SID key) for your user account with .bak at the end of the numbers.

A) In the left pane, right click on the S-1-5….. folder (SID key) with .bak at the end of the numbers and click Rename. (See screenshot below)

B) Remove only .bak at the end of the numbers and press Enter. (See screenshot below and below step 10)

repair_reg2.jpg

8. In the right pane of the one without .bak now, right click on RefCount and click on Modify. (See screenshot below step 10)
NOTE: If you do not have RefCount, then right click on a empty space in the right pane and click New and DWORD (32 bit) Value, then type RefCount and press Enter. This value for this entry will reset and return back to the original value after you have restarted the computer and logged on to the account.

A) Type 0 (number) and click on OK. (See screenshot below)

Name:  Modify_RefCount.jpg
Views: 166168
Size:  31.1 KB

9. In the right pane of the one without .bak now, right click on State and click on Modify. (See screenshot below step 10)
NOTE: This value for this entry will reset and return back to the original value after you have restarted the computer and logged on to the account.

A) Type 0 (number) and click on OK. (See screenshot below)

Name:  Modify_State.jpg
Views: 165871
Size:  30.6 KB

10. The registry will now look like this for the one without .bak now. (See screenshot below)

Click image for larger version

Name:	Repair_Reg2.jpg
Views:	55111
Size:	162.2 KB
ID:	2737

11. Close regedit.

12. Restart the computer.

13. See if you can logon now.

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

www.mobilecomputerwizard.com

 

ODG.Trojan virus removal

July 10th, 2009

Just a few notes about a virus called the ODG Trojan.

 

As of July 9th, 2009   The following programs do NOT detect it.  Malwarebytes, SuperAntispyware and AVG.

NOD32 does detect aspects of it, but will not remove it.

 

The virus is a rootkit infection and the visible result is slow performance in Firefox (even 3.5) and the search results are greatly affected and bogus. 

 

GMER detects it attached to a variety of services.

 

Removal was done by Kurt using ComboFix.  Chip has knowledge of certain .sys files that it uses and creates and he removed it manually using ERD

 

Side note: somehow, and I don’t know how, but the infected user actually received a PHONE call related to this infection from someone in India.

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office
kurt@mobilecomputerwizard.com

www.mobilecomputerwizard.com

 

Compact Outlook Express Messages in XP or reset the counter

June 15th, 2009

Compacting OE messages works 95% of the time.  When the dbx files get large, it can make a chunk of messages go away.

 

Outlook Express will prompt you to compact your messages every 100 times the program is opened and closed.  See the attached photo to learn how and what registry key to go to reset the counter.  You will need to do this once you start getting asked if you want to compact messages.

 

I do not know of a way to recover or repair the missing messages other than to use a backup to restore them. 

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

www.mobilecomputerwizard.com

 

Make a Bootable USB Thumb Drive to do BIOS update

June 9th, 2009

This is an easy USB makeable download for computers that boot off of a USB device.

 

The file is called ‘Make bootable usb.zip’ and it’s in the online Utilities folder.

 

The reason I needed it was to do a BIOS update on a PC that wouldn’t boot to windows.  Many BIOS update programs run off windows or only a bootable DOS device.  I copied the BIOS I downloaded from Dell onto the thumb drive after I made it into a bootable device.

 

Of course, adjust the BIOS on the computer to boot to a USB device and also, the HP installer to make the boot USB device will ask you to point to the DOS directory for making it boot, that is in the same directory as what you downloaded, so don’t look too hard.  It just needs the ‘command’ file to boot.

 

After it booted to the DOS thumb drive, I just typed the name of the BIOS update file and it worked great.

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office

www.mobilecomputerwizard.com

 

XP install with no Floppy for SATA RAID drivers

June 9th, 2009

This was done on a 2006 ish XP Home Dell Dimension 9150 with SATA and an onboard RAID controller.  All I wanted to do was reinstall XP Home on to a single SATA drive.  A standard XP boot cd wants  you to load SATA drivers off a floppy and that is a giant pain if you don’t have a floppy installed.  If you do not, basically the computer boots off the CD, then gets to set up and tells you to push F3 because NO DRIVE WAS FOUND.  I double and triple checked, used multiple drives and other means like the BIOS, and a Hiren’s CD verified that the SATA drive was correctly installed. 

 

Bottom line, the SATA drivers needed to be loaded into the XP CD.  A free program call nLite allows you to add the SATA drivers that you can download from a different PC and add them to the XP install CD.

 

http://paparadit.blogspot.com/2007/06/installing-sata-hard-drive-with-windows.html

 

Here is a link to download n-lite   , also for Wizards it’s in the utilities folder in out online directory, I’m being sly here as to not make our directory public.

http://www.nliteos.com/download.html

 

I added the SATA drivers, integrated them into the XP boot CD and did nothing more than boot off the modified XP Home CD and now I’m in business!

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office
www.mobilecomputerwizard.com

 

Gumblar Virus

May 22nd, 2009

The gumblar virus is a very silent virus that does strange things. Most of what the computer does is still normal and web browsing appears to be largely OK, but the following happened.   It was removed using malwarebytes after doing a manual update of the .refs file (definitions).  See the other blog post for instructions how to do that.  The infection was nothing more than a 6 character file in the windows/systme32 folder.

1.      AVG would not update

2.      Malware Bytes will not update

3.      Quickbooks multiuser mode will not complete the load

4.      Firefox crashed when adding plugins

Gumblar.cn is a website is listed to be suspicious and contains several exploit scripts and trojans that might harm and infect computers.

 

 

Kurt Rein
Mobile Computer Wizard
858 345-0382 Cel
619 255-1215 Office
kurt@mobilecomputerwizard.com