Google Ad

Traffic Mapper


Visitor Map
Showing posts with label windows tweaks. Show all posts
Showing posts with label windows tweaks. Show all posts

Thursday, August 2, 2007

Tracing a Hacker



Sometimes, it's just not enough to simply know that there's a Trojan or Virus onboard. Sometimes you need to know exactly
why that file is onboard, how it got there - but most importantly, who put it there.

By enumerating the attacker in the same way that they have enumerated the victim, you will be able to see the bigger picture and
establish what you're up against. But how can you do this? Read on...

## Connections make the world go round ##

The computer world, at any rate. Every single time you open up a website, send an email or upload your webpages into cyberspace,
you are connecting to another machine in order to get the job done. This, of course, presents a major problem, because this simple act
is what allows malicious users to target a machine in the first place.

# How do these people find their victim?

Well, first of all, they need to get hold of the victim's IP Address. Your IP (Internet Protocol) address reveals your point of entry to the
Internet and can be used in many ways to cause your online activities many, many problems. It may not reveal you by name, but it may be
uniquely identifiable and it represents your digital ID while you are online (especially so if you're on a fixed IP / DSL etc).

With an IP address, a Hacker can find out all sorts of weird and wonderful things about their victim (as well as causing all kinds of other trouble,
the biggest two being Portnukes/Trojans and the dreaded DoS ((Denial of Service)) attack). Some Hackers like to collect IP Addresses like badges,
and like to go back to old targets, messing them around every so often. An IP address is incredibly easy to obtain - until recently, many realtime chat
applications (such as MSN) were goldmines of information. Your IP Address is contained as part of the Header Code on all emails that you send and
webpages that you visit can store all kinds of information about you. A common trick is for the Hacker to go into a Chatroom, paste his supposed website
address all over the place, and when the unsuspecting victim visits, everything about your computer from the operating system to the screen resolution
can be logged...and, of course, the all important IP address. In addition, a simple network-wide port scan will reveal vulnerable target machines, and a
war-dialler will scan thousands of lines for exposed modems that the hacker can exploit.

So now that you know some of the basic dangers, you're probably wondering how these people connect to a victim's machine?

## Virtual and Physical Ports ##

Everything that you recieve over the Internet comes as a result of other machines connecting to your computer's ports. You have two types;
Physical are the holes in the back of your machine, but the important ones are Virtual. These allow transfer of data between your computer and
the outside world, some with allocated functions, some without, but knowing how these work is the first step to discovering who is attacking you;
you simply MUST have a basic knowledge of this, or you won't get much further.

# What the phrases TCP/UDP actually mean

TCP/IP stands for Transmission Control Protocol and Internet Protocol, a TCP/IP packet is a block of data which is compressed, then a header is put
on it and it is sent to another computer (UDP stands for User Datagram Protocol). This is how ALL internet transfers occur, by sending packets. The
header in a packet contains the IP address of the one who originally sent you it. Now, your computer comes with an excellent (and free) tool that allows
you to see anything that is connected (or is attempting to connect) to you, although bear in mind that it offers no blocking protection; it simply tells you
what is going on, and that tool is NETSTAT.

## Netstat: Your first line of defence ##

Netstat is a very fast and reliable method of seeing exactly who or what is connected (or connecting) to your computer. Open up DOS (Start/Programs/MS-DOS
Prompt on most systems), and in the MSDOS Prompt, type:

netstat -a

(make sure you include the space inbetween the "t" and the "a").

If you're connected to the Internet when you do this, you should see something like:


Active Connections

Proto Local Address Foreign Address State
TCP macintosh: 20034 modem-123.tun.dialup.co.uk: 50505 ESTABLISHED
TCP macintosh: 80 proxy.webcache.eng.sq: 30101 TIME_WAIT
TCP macintosh MACINTOSH: 0 LISTENING
TCP macintosh MACINTOSH: 0 LISTENING
TCP macintosh MACINTOSH: 0 LISTENING


Now, "Proto(col)" simply means what kind of data transmission is taking place (TCP or UDP), "Local address" is your computer (and the number next
to it tells you what port you're connected on), "Foreign Address" is the machine that is connected to you (and what port they're using), and finally "State"
is simply whether or not a connection is actually established, or whether the machine in question is waiting for a transmission, or timing out etc.

Now, you need to know all of Netstat's various commands, so type:

netstat ?

You will get something like this:


Displays protocol statistics and current TCP/IP network connections.

NETSTAT [-a] [-e] [-n] [-s] [-p proto] [-r] [interval]

-a Displays all connections and listening ports.
-e Displays Ethernet statistics. This may be combined with the -s option.
-n Displays addresses and port numbers in numerical form.
-p proto Shows connections for the protocol specified by proto; proto may be TCP or UDP. If used with the -s option to display per-protocol statistics, proto may be TCP, UDP, or IP.
-r Displays the routing table.
-s Displays per-protocol statistics. By default, statistics are shown for TCP, UDP and IP; the -p option may be used to specify a subset of the default.


Have a play around with the various options, but the most important use of these methods is when you combine them. The best command to use is

netstat -an

because this will list all connections in Numerical Form, which makes it a lot easier to trace malicious users....Hostnames can be a little confusing if
you don't know what you're doing (although they're easily understandable, as we shall see later). Also, by doing this, you can also find out what your
own IP address is, which is always useful.

Also,

netstat -b

will tell you what ports are open and what programs are connecting to the internet

Re: Tracing A Hacker Options

--------------------------------------------------------------------------------

## Types of Port ##

It would be impossible to find out who was attacking you if computers could just access any old port to perform an important function; how could you
tell a mail transfer from a Trojan Attack? Well, good news, because your regular, normal connections are assigned to low, commonly used ports, and in
general, the higher the number used, the more you should be suspicious. Here are the three main types of port:

# Well Known Ports These run from 0 to 1023, and are bound to the common services that run on them (for example, mail runs on channel 25 tcp/udp,
which is smtp (Simple Mail Transfer Protocol) so if you find one of these ports open (and you usually will), it's usually because of an essential function.

# Registered Ports These run on 1024 to 49151. Although not bound to a particular service, these are normally used by networking utilities like FTP
software, Email client and so on, and they do this by opening on a random port within this range before communicating with the remote server, so don't
panic (just be wary, perhaps) if you see any of these open, because they usually close automatically when the system that's running on them terminates
(for example, type in a common website name in your browser with netstat open, and watch as it opens up a port at random to act as a buffer for the remote
servers). Services like MSN Messenger and ICQ usually run on these Ports.

# Dynamic/Private Ports Ranging from 49152 to 65535, these things are rarely used except with certain programs, and even then not very often. This is
indeed the usual range of the Trojan, so if you find any of these open, be very suspicious. So, just to recap:


Well Known Ports 0 to 1023 Commonly used, little danger.
Registered Ports 1024 to 49151 Not as common, just be careful.
Dynamic/Private Ports 49152 to 65535 Be extremely suspicious.


## The hunt is on ##

Now, it is essential that you know what you're looking for, and the most common way someone will attack your machine is with a Trojan.
This is a program that is sent to you in an email, or attempts to bind itself to one of your ports, and when activated, it can give the user your
passwords, access to your hard drive...they can even make your CD Tray pop open and shut. At the end of this Document, you will find a list
of the most commonly used Trojans and the ports they operate on. For now, let's take another look at that first example of Netstat....



Active Connections

Proto Local Address Foreign Address State
TCP macintosh: 27374 modem-123.tun.dialup.co.uk: 50505 ESTABLISHED
TCP macintosh: 80 proxy.webcache.eng.sq: 30101 TIME_WAIT
TCP macintosh MACINTOSH: 0 LISTENING
TCP macintosh MACINTOSH: 0 LISTENING
TCP macintosh MACINTOSH: 0 LISTENING


Now, straight away, this should make more sense to you. Your computer is connected on two ports, 80 and 27374. Port 80 is used for
/http/www transmissions (ie for all intents and purposes, its how you connect to the net, although of course it's a lot more complicated than that).
Port 27374, however, is distinctly suspicious; first of all, it is in the registered port range, and although other services (like MSN) use these, let's assume
that you have nothing at all running like instant messengers, webpages etc....you're simply connected to the net through proxy. So, now this connection
is looking even more troublesome, and when you realise that 27374 is a common port for Netbus (a potentially destructive Trojan), you can see that something
is untoward here. So, what you would do is:


1) run Netstat , and use:

Netstat -a

then

Netstat -an

So you have both Hostnames AND IP addresses.


## Tracerouting ##

Having the attacker's IP is all well and good, but what can you do with it? The answer is, a lot more! It's not enough to have the address, you also need to
know where the attacker's connections are coming from. You may have used automated tracerouting tools before, but do you jknow how they work?

Go back to MSDOS and type


tracert *type IP address/Hostname here*


Now, what happens is, the Traceroute will show you all the computers inbetween you and the target machine, including blockages, firewalls etc.
More often than not, the hostname address listed before the final one will belong to the Hacker's ISP Company. It'll either say who the ISP is somewhere
in there, or else you run a second trace on the new IP/hostname address to see who the ISP Company in question is. If the Hostname that you get back
doesn't actually seem to mention an actual geographical location within its text, you may think all is lost. But fear not! Suppose you get a hostname such as

/http://www.haha.com


Well, that tells us nothing, right? Wrong....simply enter the hostname in your browser, and though many times you will get nothing back, sometimes it will
resolve to an ISP, and from there you can easily find out its location and in what areas they operate. This at least gives you a firm geographical location to
carry out your investigations in.

If you STILL have nothing, as a last resort you COULD try connecting to your target's ISP's port 13 by Telnet, which will tell you how many hours ahead or
behind this ISP is of GMT, thus giving you a geographical trace based on the time mentioned (although bear in mind, the ISP may be doing something stupid
like not having their clocks set correctly, giving you a misleading trace. Similarly, a common tactic of Hackers is to deliberately have their computer's clock set
to a totally wrong time, so as to throw you off the scent). Also, unless you know what you're doing, I wouldn't advise using Telnet (which is outside the
parameters of this tutorial).

## Reverse DNS Query ##

This is probably the most effective way of running a trace on somebody. If ever you're in a chatroom and you see someone saying that they've "hacked
into a satellite orbiting the Earth, and are taking pictures of your house right now", ignore them because that's just bad movie nonsense. THIS method is
the way to go, with regard to finding out what country (even maybe what State/City etc) someone resides, although it's actually almost impossible to find
an EXACT geographical location without actually breaking into your ISP's Head Office and running off with the safe.

To run an rDNS query, simply go back to MS-DOS and type

netstat

and hit return. Any active connections will resolve to hostnames rather than a numerical format.

# DNS

DNS stands for Domain Name Server. These are machines connected to the Internet whose job it is to keep track of the IP Addresses and Domain
Names of other machines. When called upon, they take the ASCII Domain Name and convert it to the relevant numeric IP Address. A DNS search
translates a hostname into an IP address....which is why we can enter "www.Hotmail.com" and get the website to come up, instead of having to actually
remember Hotmail's IP address and enter that instead. Well, Reverse DNS, of course, translates the IP Address into a Hostname (ie - in letters and words
instead of numbers, because sometimes the Hacker will employ various methods to stop Netstat from picking up a correct Hostname).

So, for example,

298.12.87.32 is NOT a Hostname.
mail6.bol.net.au IS a Hostname.

Anyway, see the section at the end? (au) means the target lives in Australia. Most (if not all) hostnames end in a specific Country Code,
thus narrowing down your search even further. If you know your target's Email Address (ie they foolishly sent you a hate mail, but were silly
enough to use a valid email address) but nothing else, then you can use the Country codes to deduce where they're from as well. You can also
deduce the IP address of the sender by looking at the emails header (a "hidden" line of code which contains information on the sender)...on Hotmail
for example, go to Preferences, and select the "Full Header's Visible" option. Alternatively, you can run a "Finger" Trace on the email address, at:

/www.samspade.org

Plus, some ISP's include their name in your Email Address with them too (ie Wanadoo, Supanet etc), and your Hacker may be using
an email account that's been provided by a Website hosting company, meaning this would probably have the website host's name in the
email address (ie Webspawners). So, you could use the information gleaned to maybe even hunt down their website (then you could run
a website check as mentioned previously) or report abuse of that Website Provider's Email account (and thus, the Website that it goes with) to

abuse@companynamegoeshere,com

If your Hacker happens to reside in the USA, go to:

/www.usps.gov/ncsc/lookups/abbr_state.txt

for a complete list of US State abbreviatons.

## List of Ports commonly used by Trojans ##

Please note that this isn't a complete list by any means, but it will give you an idea of what to look out for in Netstat. Be
aware that some of the lower Ports may well be running valid services.

UDP: 1349 Back Ofrice DLL
31337 BackOfrice 1.20
31338 DeepBO
54321 BackOfrice 2000


TCP: 21 Blade Runner, Doly Trojan, Fore, Invisible FTP, WebEx, WinCrash
23 Tiny Telnet Server
25 Antigen, Email Password Sender, Haebu Coceda, Shtrilitz Stealth, Terminator, WinPC, WinSpy, Kuang2 0.17A-0.30
31 Hackers Paradise
80 Executor
456 Hackers Paradise
555 Ini-Killer, Phase Zero, Stealth Spy
666 Satanz Backdoor
1001 Silencer, WebEx
1011 Doly Trojan
1170 Psyber Stream Server, Voice
1234 Ultors Trojan
1243 SubSeven 1.0 - 1.8
1245 VooDoo Doll
1492 FTP99CMP
1600 Shivka-Burka
1807 SpySender
1981 Shockrave
1999 BackDoor 1.00-1.03
2001 Trojan Cow
2023 Ripper
2115 Bugs
2140 Deep Throat, The Invasor
2801 Phineas Phucker
3024 WinCrash
3129 Masters Paradise
3150 Deep Throat, The Invasor
3700 Portal of Doom
4092 WinCrash
4567 File Nail 1
4590 ICQTrojan
5000 Bubbel
5000 Sockets de Troie
5001 Sockets de Troie
5321 Firehotcker
5400 Blade Runner 0.80 Alpha
5401 Blade Runner 0.80 Alpha
5402 Blade Runner 0.80 Alpha
5400 Blade Runner
5401 Blade Runner
5402 Blade Runner
5569 Robo-Hack
5742 WinCrash
6670 DeepThroat
6771 DeepThroat
6969 GateCrasher, Priority
7000 Remote Grab
7300 NetMonitor
7301 NetMonitor
7306 NetMonitor
7307 NetMonitor
7308 NetMonitor
7789 ICKiller
8787 BackOfrice 2000
9872 Portal of Doom
9873 Portal of Doom
9874 Portal of Doom
9875 Portal of Doom
9989 iNi-Killer
10067 Portal of Doom
10167 Portal of Doom
10607 Coma 1.0.9
11000 Senna Spy
11223 Progenic trojan
12223 Hack´99 KeyLogger
12345 GabanBus, NetBus
12346 GabanBus, NetBus
12361 Whack-a-mole
12362 Whack-a-mole
16969 Priority
20001 Millennium
20034 NetBus 2.0, Beta-NetBus 2.01
21544 GirlFriend 1.0, Beta-1.35
22222 Prosiak
23456 Evil FTP, Ugly FTP
26274 Delta
30100 NetSphere 1.27a
30101 NetSphere 1.27a
30102 NetSphere 1.27a
31337 Back Orifice
31338 Back Orifice, DeepBO
31339 NetSpy DK
31666 BOWhack
33333 Prosiak
34324 BigGluck, TN
40412 The Spy
40421 Masters Paradise
40422 Masters Paradise
40423 Masters Paradise
40426 Masters Paradise
47262 Delta
50505 Sockets de Troie
50766 Fore
53001 Remote Windows Shutdown
54321 SchoolBus .69-1.11
61466 Telecommando
65000 Devil

## Summary ##

I hope this tutorial is useful in showing you both how to secure yourself against unwanted connections,
and also how to determine an attacker's identity. The Internet is by no means as anonymous as some people think it is,
and although this is to the detriment of people's security online, this also works both ways....it IS possible to find and stop
even the most determined of attackers, you just have to be patient and keep hunting for clues which will help you put an end to their exploits.

Or when All else fails.....Get Linux

Monday, July 23, 2007

Folder Size - The One Addition That Windows Has Needed Since Day One

Hard to believe that even with the release of Windows Vista, Microsoft forgot one feature they’ve needed since Windows 95, oh wait, nevermind, it’s easy to believe. One could only guess the reasoning behind not adding the option for Folder Size when viewing the details for files and directories, but fortunately someone in our favorite open source website, Sourceforge, has come with what all users and system administrators need. An application to add the size of a directory/folder, simply called “Folder Size“.

Rid Of The Annoying “Restart Now” In Windows XP

I was browsing through various blogs, watching some of my favorite shows from HBO, all the while being annoyed by the ever present:


I thought, there must a way to get rid of this annoying pop-up. Of course, unlike many of Windows annoyances, there is a quick and easy way to get rid of this repetive nagging.

While your small yellow shield is running in the system tray, you also have a process running called “wuauclt.exe”. You can easily kill this process via your task manager, but you’ll see it come back within a few minutes, so here is how to rid of this process permanently:

How to open Windows DUMP .DMP files.

It’s been true since the beginning, the Windows Event Viewer is essentially useless to the average everyday Tech Support employee. Even Ids, Sources, and codes of Hexadecimal errors tell most non-Microsoft programming users, absolutely nothing, although EventID.net, can be very helpful.

This is where a underground hidden Microsoft application comes to the rescue for opening the mysterious DMP(Dump) files created during the still present BSOD(Blue Screen of Death) and located in “c:\windows\minidump”. The application is called “Debugging Tools for Windows”.

Once installed, go to FILE>OPEN CRASH DUMP


This produces the following screen and following cause of the crash:

Removing CD/DVD scratches with Toothpaste?

Some young entrepreneur over at Metacafe has posted a simple but what appears to be highly affective way of removing scratches from your CD/DVDs with Tootpaste.

1. Smear toothpaste throughout disc
2. Wash toothpaste off with running water.
3. Dry disc clean with soft towel or t-shirt.
4. Brand new disc for your enjoyment.

Emergency Boot CD(EBCD) - Reset Any Password In Windows…Including Administrator

There are several different options when it comes to bootable operating systems. Whether they be virtual Windows, Linux or even MAC OS environments, but most have several different confusing settings, some just don’t work as designed and some just don’t plain work at all. The ones that do work however, work very well, and they can perform many tasks that just can’t be done in the Windows GUI. Emergency Boot CD is just one example, but it get’s you back up and running fast and is the king of simplicity when it comes to any of the following:


- Changing the password of any Windows users, including the Administrator
- Recovering the master boot record
- Performing an Emergency boot for NT, 2000 or XP
- Partitioning
- Recovering files from a formatted drive, an emptied recycle bin, or an unreadable floppy disk

The EBCD is simply the most efficient way to get any of these done. Since it doesn’t boot into a GUI, it boots much faster, the navigation is incredibly simple(once you get the hang of it) and the support from their site is top notch. So, if you’re a system administrator, a desktop support technician or a son/daughter just simply trying to get your Mom to remember her password, Emergency Boot CD is the way to go.

Check it Out: Emergency Boot CD

Windows XP Home and Professional Command Line Commands | Run Line Commands

One big negative of being a desktop specialist can be the daunting task for browsing through multiple directorys and/or shortcuts to find many of the consistently used adminstratives apps, such as Device Manager, Event Viewer or Services. Well, Windows XP does make it much easier for someone to access many of these internal applications by using run line commands.(Start>Run)

Below is a list of all of the integrated Windows XP applications that have the ability to be run from the run line. For example, in order to access the services currently running in Windows, you just go to START>RUN>and type “services.msc”.

All of these commands have the capability of working in both Windows XP Home AND Professional…with a majority having the ability to work in Windows 2000 as well.

Micellaneous executable files used throughout Windows

  1. ACCWIZ.EXE - Accessibility Wizard
  2. BCKGZM.EXE - Backgammon
  3. CALC.EXE - Calculator
  4. CHARMAP.EXE - Character Map
  5. CHKRZM.EXE - Checkers
  6. CLEANMGR.EXE - Disk Space Cleanup Manager
  7. CLICONFG.EXE - SQL Client Configuration Utility
  8. CLIPBRD.EXE - Clipbook Viewer
  9. CLSPACK.EXE - Class Package Export Tool
  10. CMD.EXE - Command Line
  11. CMSTP.EXE - Connection Manager Profile Installer
  12. CONF.EXE - NetMeeting
  13. CONTROL.EXE - Control Panel
  14. DCOMCNFG.EXE - Component Services
  15. DDESHARE.EXE - DDE Share
  16. DIALER.EXE - Phone Dialer
  17. DRWATSON.EXE - Doctor Watson v1.00b
  18. DRWTSN32.EXE - Doctor Watson Settings
  19. DVDPLAY.EXE - DVD Player
  20. DXDIAG.EXE - DirectX Diagnostics
  21. EUDCEDIT.EXE - Private Character Editor
  22. EVENTVWR.EXE - Event Viewer
  23. EXPLORER.EXE - Windows Explorer
  24. FREECELL.EXE - Free Cell
  25. FXSCLNT.EXE - Fax Console
  26. FXSCOVER.EXE - Fax Cover Page Editor
  27. FXSEND.EXE - MS Fax Send Note Utility
  28. HELPCTR.EXE - Help and Support
  29. HRTZZM.EXE - Internet Hearts
  30. HYPERTRM.EXE - HyperTerminal
  31. ICWCONN1.EXE - Internet Connection Wizard
  32. IEXPLORE.EXE - Internet Explorer
  33. IEXPRESS.EXE - IExpress 2.0
  34. INETWIZ.EXE - Setup Your Internet Connection
  35. INSTALL.EXE - User’s Folder
  36. LOGOFF.EXE - System Logoff
  37. MAGNIFY.EXE - Microsoft Magnifier
  38. MIGWIZ.EXE - File and Settings Transfer Wizard
  39. MMC.EXE - Microsoft Management Console
  40. MOBSYNC.EXE - Microsoft Synchronization Manager
  41. MOVIEMK.EXE - Windows Movie Maker
  42. MPLAY32.EXE - Windows Media Player version 5.1
  43. MPLAYER2.EXE - Windows Media Player Version 6.4.09.1120
  44. MSCONFIG.EXE - System Configuration Utility
  45. MSHEARTS.EXE - Hearts
  46. MSIMN.EXE - Outlook Express
  47. MSINFO32.EXE - System Information
  48. MSMSGS.EXE - Windows Messenger
  49. MSN6.EXE - MSN Explorer
  50. MSPAINT.EXE - Paint
  51. MSTSC.EXE - Remote Desktop Connection
  52. NARRATOR.EXE - Microsoft Narrator
  53. NETSETUP.EXE - Network Setup Wizard
  54. NOTEPAD.EXE - Notepad
  55. NSLOOKUP.EXE - NSLookup Application
  56. NTSD.EXE - Symbolic Debugger for Windows 2000
  57. ODBCAD32.EXE - ODBC Data Source Administrator
  58. OSK.EXE - On Screen Keyboard
  59. OSUNINST.EXE - Windows Uninstall Utility
  60. PACKAGER.EXE - Object Packager
  61. PBRUSH.EXE - Paint
  62. PERFMON.EXE - Performance Monitor
  63. PINBALL.EXE - Pinball
  64. PROGMAN.EXE - Program Manager
  65. RASPHONE.EXE - Remote Access Phonebook
  66. REGEDIT.EXE - Registry Editor
  67. REGEDT32.EXE - Registry Editor
  68. RESET.EXE - Resets Session
  69. RSTRUI.EXE - System Restore
  70. RTCSHARE.EXE - RTC Application Sharing
  71. RVSEZM.EXE - Reversi
  72. SFC.EXE - System File Checker
  73. SHRPUBW.EXE - Create Shared Folder
  74. SHUTDOWN.EXE - System Shutdown
  75. SHVLZM.EXE - Spades
  76. SIGVERIF.EXE - File Signature Verification
  77. SNDREC32.EXE - Sound Recorder
  78. SNDVOL32.EXE - Sound Volume
  79. SOL.EXE - Solitaire
  80. SPIDER.EXE - Spider Solitaire
  81. SYNCAPP.EXE - Create A Briefcase
  82. SYSEDIT.EXE - System Configuration Editor
  83. SYSKEY.EXE - SAM Lock Tool
  84. TABLE30.EXE - User’s Folder
  85. TASKMGR.EXE - Task Manager
  86. TELNET.EXE - MS Telnet Client
  87. TOURSTART.EXE - Windows Tour Launcher
  88. TSSHUTDN.EXE - System Shutdown
  89. USERINIT.EXE - My Documents
  90. UTILMAN.EXE - System Utility Manager
  91. VERIFIER.EXE - Driver Verifier Manager
  92. WAB.EXE - Windows Address Book
  93. WABMIG.EXE - Address Book Import Tool
  94. WIAACMGR.EXE - Scanner and Camera Wizard
  95. WINCHAT.EXE - Windows for Workgroups Chat
  96. WINHELP.EXE - Windows Help Engine
  97. WINHLP32.EXE - Help
  98. WINMINE.EXE - Minesweeper
  99. WINNT32.EXE - User’s Folder
  100. WINVER.EXE - Windows Version Information
  101. WMPLAYER.EXE - Windows Media Player
  102. WRITE.EXE - Wordpad
  103. WRITE.EXE - WordPad
  104. WSCRIPT.EXE - Windows Script Host Settings
  105. WUPDMGR.EXE - Windows Update
All of these CPL files are control panel applets that can ran from the run line. These all require the “.CPL” extension when being run.
ACCESS.CPL - Accessibility Options
APPWIZ.CPL - Add or Remove Programs
DESK.CPL - Display Properties
HDWWIZ.CPL - Add Hardware Wizard
INETCPL.CPL - Internet Explorer Properties
INTL.CPL - Regional and Language Options
JOY.CPL - Game Controllers
MAIN.CPL - Mouse Properties
MMSYS.CPL - Sounds and Audio Device Properties
NCPA.CPL - Network Connections
NUSRMGR.CPL - User Accounts
ODBCCP32.CPL - ODBC Data Source Administrator
POWERCFG.CPL - Power Options Properties
SYSDM.CPL - System Properties
TELEPHON.CPL - Phone and Modem Options
TIMEDATE.CPL - Date and Time Properties

All of these have the “.MSC” file extension. Some, but not all require the .MSC to be typed in when running them.
CERTMGR.MSC - Certificates
CIADV.MSC - Indexing Service
COMPMGMT.MSC - Computer Management
DEVMGMT.MSC - Device Manager
DFRG.MSC - Disk Defragmenter
DISKMGMT.MSC - Disk Management
EVENTVWR.MSC - Event Viewer
FSMGMT.MSC - Shared Folders
LUSRMGR.MSC - Local Users and Groups
NTMSMGR.MSC - Removable Storage
NTMSOPRQ.MSC - Removable Storage Operator Requests
PERFMON.MSC - Performance Monitor
SERVICES.MSC - Services
WMIMGMT.MSC - Windows Management Infrastructure
Other Run Line Commands
CONTROL USERPASSWORDS2 - Conventional User Account Interface

Saturday, July 21, 2007

How to Download anything for free using Google

Rapidshare.de and Megashare.com are the sites which hardly anyone will be unaware of. These sites allow user to upload files but lack the basic functionality of searching the whole database based on the description of the file.

rapidshare

Here is where google advance search technology comes to rescue :

google download anything

Rapidshare has a huge database of files as a considerable number of users connected to it to upload music, pictures, movies and even larger files such as games or important documents. Although the owners encourage you to register and become a paying member, Rapidshare is also available for free so you can use it with only one restriction: you have a download limitation, meaning that you’re not able to download too many files for free. However, the website hosts an impressive number of files and it tends to become a real encyclopedia for music and movies. Similar is the case with magashare also. But since you dont have a search option hence you can just download the file unless you have the link to the file.

You must be knowing two very popular ways of searching google with these keywords :

1. site:www.example.com hello - retrieves all the result matching “hello” only from site example.com , hence limiting the search to a particular site.

2. +intitle:technology - retrieves all pages having “technology” in the web page title.

Let us combine these two advance search technology to search within the site rapidshare.de

So here is what you have to do .

1.http://www.google.com and type in the search box :

For music

+inurl:wma|mp3|ogg site:rapidshare.de

For videos

+inurl:avi|mpg|wmv site:rapidshare.de

For archives

+inurl:exe|rar|zip site:rapidshare.de

For any particular file

(ex-spiderman in this case )

+inurl:spiderman site:rapidshare.de

The same can be used for any other site. Remeber there is no space between “:” and search term.

Speed up your internet speed by 20 percent

This is a nice little tweak to get 20% of bandwidth back.Microsoft reserve 20% of your available bandwidth for their own purposes (suspect for updates and interrogating your machine etc..).

    Click Start–>Run–>type “gpedit.msc” without the ”
  • This opens the group policy editor. Then go to

    Local Computer Policy–>Computer Configuration–>Administrative Templates–>
    Network–>QOS Packet Scheduler–>Limit Reservable Bandwidth

  • Double click on Limit Reservable bandwidth. It will
    say it is not configured, but the truth is under the
    ‘Explain’ tab :

    “By default, the Packet Scheduler limits the system to
    20 percent of the bandwidth of a connection, but you
    can use this setting to override the default.”

  • So the trick is to ENABLE reservable bandwidth, then
    set it to ZERO.

    This will allow the system to reserve nothing, rather
    than the default 20%.

  • works on XP Pro, 2000 and 2003 but not sure about
    other o/s’s.

Here are the screen shots -

increasing the internet bandwidth

increasing the internet bandwidth

increasing the internet bandwidth

Full list of MS Office Shortcut Keys (Word, Exel and Powerpoint)

Have you ever got stuck searching for some shortcut keys for MS word ??Yeah !! I got stuck at times.

Basically with text formatting like Increasing font size (Ctrl + ]), Getting all Caps (Ctrl+shift+A) , Changing fonts(ctrl+shift+f), Apply superscripts(ctrl + shift + =) , subscripts (Ctrl + = ) etc etc.

So just did some googling and got a pdf file downloaded. I dont remember which site I downloaded this, but its a very handy guide. You can download the Pdf from here by clicking and selecting Download fileor “Save target as” in IE and “Save link as” in Firefox. Hope it will be of some use to people who are unaware of such shortcut keys.

Wednesday, June 27, 2007

The folder option in my control panel has been disappeared ! what shoul i do to get it back . i am using xp serv 2 i

Q=the folder option in my control panel has been disappeared ! what shoul i do to get it back ? thank you for your new Blog . i am using xp serv 2 i could not find the customize button .
A=
To get the "Folder Options" button on the Control Panel toolbar--right-click the "Standard Buttons" toolbar--click Customize--under "Available toolbar buttons" -- add it to current...Hope it helps.

OR
For Windows XP:
1. You can download the file from here, double click and add this into your registry:
Download Registry Patch

2. Using NOD32 to scan your computer for virusif the file above is not help. When you go to virus or trojan, then only your antivirus and spyware help you. After you have scanned and deleted all the spyware and virus. Go back to method 1 again.
3. If you are using Windows 2000, then Read here:
http://support.microsoft.com/kb/245732
That's all I can help.

Google Refferal

Host ur Files on Internet

Get a Free File Hosting Account

Important links

1-
2- Professionl Business&Personal Hosting
3-One Year Free Web Hosting
4-VPS Web Hosting for less than $6.95 per month
5-AuctionAds

WebMasters Section

Lunarpages.com Web Hosting WestHost Web Hosting