Rabu, 12 Maret 2008

WowFX Problems - TROJ_RENOS.MQ

Solution:

Important Windows ME/XP Cleaning Instructions

Users running Windows ME and XP must disable System Restore to allow full scanning of infected computers.

Users running other Windows versions can proceed with the succeeding solution set(s).

Restarting in Safe Mode

This malware has characteristics that require the computer to be restarted in safe mode. Go to this page for instructions on how to restart your computer in safe mode.

Restoring Autostart Entry from the Registry

This solution deletes/modifies registry keys/entries added/modified by this malware. Before performing the steps below, make sure you know how to back up the registry and how to restore it if a problem occurs. Refer to this Microsoft article for more information about modifying your computer's registry.

  1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
  2. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
    Control>SecurityProviders
  3. In the right panel, locate the entry:
    SecurityProviders = "msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,wowfx.dll"
  4. Double-click the value name of this enty and choose Modify. Change the value data of this entry to:
    msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
  5. Close Registry Editor.

Deleting the Malware File(s)

  1. Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
  2. In the Named input box, type:
    wowfx.dll
  3. In the Look In drop-down list, select My Computer, then press Enter.
  4. Once located, select the file then press SHIFT+DELETE.

*NOTE: This malware is a DLL file that may come with a main component detected by Trend Micro as another malware. It may also be used by several variants of a certain malware family. If your Trend Micro product detects another malware on your system, refer to the manual removal instructions of that detected malware.

Running Trend Micro Antivirus

Restart your computer normally before performing the following solution.

Scan your computer with Trend Micro antivirus and delete files detected as TROJ_RENOS.MQ. To do this, Trend Micro customers must download the latest virus pattern file and scan their computers. Other Internet users can use HouseCall, the Trend Micro online threat scanner.




Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business, mobile device or home PC.

Minggu, 17 Februari 2008

Configure WSUS

Step 8a: Access the WSUS administration console

Use the following procedure to access the WSUS administration console. You can also open the administration console from Internet Explorer on any server or computer on your network by going to http://WSUSServerName[:portnumber]/WSUSAdmin/.

You must be a member of the local Administrators group or the WSUS Administrators group on the server on which WSUS is installed in order to use the WSUS console.

To open the WSUS console

  • On your WSUS server, click Start, point to All Programs, point to Administrative Tools, and then click Microsoft Windows Server Update Services.

Note: If you are running Windows Server 2003 and do not add http://WSUSWebsiteName to the list of sites in the Local Intranet zone in Internet Explorer, you might be prompted for credentials each time you open the WSUS console.

If you change the port assignment in IIS after you install WSUS, you need to create a new shortcut on the Start menu to access WSUS from the Start menu.


Step 8b: Configure WSUS to use a proxy server

If you use a proxy server on your network, use the WSUS console to configure WSUS to use the proxy server. This is necessary in order to synchronize the server with Microsoft Update.

To specify a proxy server for synchronization
  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. In the Proxy server box, click Use a proxy server when synchronizing, and then enter the server name, and port number (port 80 is the default) of the proxy server in the corresponding boxes.
  3. If you want to connect to the proxy server under specific user credentials, click Use user credentials to connect to the proxy server, and then enter the user name, domain, and password of the user in the corresponding boxes. If you want to enable basic authentication for the user connecting to the proxy server, click Allow basic authentication (password in clear text).
  4. Under Tasks, click Save settings, and then click OK when the confirmation box appears.

Step 8c: Select Products and Classifications

After you specify the proxy server, you are ready to select the products you want to update and the types of updates you want to download. There is a description of why you might want to do this in "Filtering Updates," in Determine Bandwidth Options to Use for Your Deployment earlier in this guide.

To specify update products and classifications for synchronization
  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. In the Products and Classifications box, under Products, click Change.
  3. In the Add/Remove Products box, under Products, select the products or product families for the updates you want your WSUS server to download, and then click OK.
  4. Under Update classifications, click Change.
  5. In the Add/Remove Classifications box, under Classifications, select the update classifications for the updates you want your WSUS server to download, and then click OK.
Note: You may have to do an initial synchronization to get some products to appear in the list of product classifications.

Step 8d: Synchronize the WSUS server

After you select products and update classifications, you are ready to synchronize WSUS. The synchronization process involves downloading updates from Microsoft Update or another WSUS server. WSUS determines if any new updates have been made available since the last time you synchronized. If this is the first time you are synchronizing the WSUS server, all of the updates are made available for approval.


To synchronize the WSUS server
  • On the WSUS console toolbar, click Options, and then click Synchronization Options.
  • Under Tasks, click Synchronize now.

After the synchronization finishes, you can click Updates on the WSUS console toolbar to view the list of updates.

Step 8e: Configure advanced synchronization options

Advanced synchronization features include various options to manage bandwidth and store updates. There is a description of each of these features, including reasons why these features are useful, and their limitations, in Determine Where to Store Updates and Determine Bandwidth Options to Use for Your Deployment earlier in this guide.

Update storage options

Use the Update Files section to determine if updates will be stored on WSUS or if client computers will connect to the Internet to get updates. There is a description of this feature in Determine Where to Store Updates earlier in this guide.

To specify where updates are stored

  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. Under Update Files and Languages, click Advanced, then read the warning and click OK.
  3. If you want to store updates in WSUS, in the Advanced Synchronization Options dialog box, under Update Files, click Store update files locally on this server. If you want clients to connect to the Internet to get updates, then click Do not store updates locally; clients install updates from Microsoft Update.

Deferred downloads options

Use the Update Files section to determine if updates should be downloaded during synchronization or when the update is approved. Find a description of this feature in "Deferring the Download of Updates," in Determine Bandwidth Options to Use for Your Deployment earlier in this guide.

To specify whether updates are downloaded during synchronization or when the update is approved

  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. Under Update Files and Languages, click Advanced, then read the warning and click OK.
  3. If you want to download only metadata about the updates during synchronization, in the Advanced Synchronization Options dialog box, under Update Files, select the Download updates to this server only when updates are approved check box. If you want the update files and metadata during synchronization, clear the check box.

Use the Update Files section to determine if express installation files should be downloaded during synchronization. Find a description of this feature in "Using Express installation files," in Determine Bandwidth Options to Use for Your Deployment earlier in this paper.

To specify whether express installation files are downloaded during synchronization

  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. Under Update Files and Languages, click Advanced, then read the warning and click OK.
  3. If you want to download express installation files, in the Advanced Synchronization Options dialog box, under Update Files, select the Download express installation files check box. If you do not want express installation files, clear the check box.
Filtering updates options

Use the Update Files section to select the language of the updates to synchronize. There is a description of this feature in "Filtering updates," in Determine Bandwidth Options to Use for Your Deployment earlier in this guide..

To specify language options

  1. On the WSUS console toolbar, click Options, and then click Synchronization Options.
  2. Under Update Files and Languages, click Advanced, then read the warning and click OK.
  3. In the Advanced Synchronization Options dialog box, under Languages, select one of the following language options, and then click OK.
    • Download only those updates that match the locale of this server (Locale) where Locale is the name of the server locale. This means that only updates targeted to the locale of the server will be downloaded during synchronization.
    • Download updates in all languages, including new languages. This means that all languages will be downloaded during synchronization. If a new language is added, it will be automatically downloaded.
    • Download updates only in the selected languages. This means that only updates targeted to the languages you select will be downloaded during synchronization. If you choose this option, you must also choose each language you want from the list of those available.

Kamis, 22 November 2007

Aktivasi Windows Vista

Aktivasi Windows Vista dengan cara :

1. Dari Start, Klik Accesories dan Klik kanan Command Prompt
2. Pilih Run As Administrator
3. Jika installasi Windows Vista dengan ghost maka dapat dilakukan terlebih dahulu penggantian Activation key dengan perintah :

C:\>slmgr.vbs -ipk

note :
- Activation key diisi lengkap dengan huruf besar dan tanda minus (-)

4. Untuk aktivasinya, dilakukan dengan perintah :

C:\>slmgr.vbs -ato