1. Run regedit.
2. Navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
3. Create a DWORD value under Lsa
LmCompatibilityLevel
4. Set the value to 1
5. quit regedit
5. from Start/Run type gpupdate /force


On Windows 2000 Server: go to start, run, type gpedit.msc and click ok.
Under computer comfiguration, windows settings, security setting, local policies, security options.
Look for LAN Manager Authentication Level. Set it to SEND LM & NTLM - use NTLMv2 session security if negociated.
Click OK.
Then run these commands :
secedit /refreshpolicy user_policy
secedit /refreshpolicy machine_policy

Category: Blog
Share : Share Accessing shares on Windows 2k from Windows 8 to Facebook Share Accessing shares on Windows 2k from Windows 8 to Twitter 

7/11/2012 : Sirefef-FQ Virus

Just got done cleaning my Windows 7 64bit desktop computer of the nasty Sirefef-FQ Virus.  It started with page redirecting in IE/Chrome/Firefox:

http://click.get-answers-fast.com/ads-clicktrack/click/jump1.do?sid=x79GsgboKlt%2B0tVyMIPlzPvlXmss5PpG0NjSn5YABu0%3D&affiliate=46734&subid=229&rc=0&terms=the%20ordinal%201108%20wsock32.dll%20windows%207

Windows Defender was disabled
Security Essentials didn't work
nslookup returned error message: The ordinal 1112 could not be located in the dynamic link library WSOCK32.dll

After hours of searching, the simpliest solution to clean the virus found in:

Gac_32/desktop.ini
Gac_64/desktop.ini

1)        Create another account with administrator rights
2)        Log into newly created account
3)        Enable Windows Defender and scan
4)        Uninstall and reinstall Security Essentials and scan
5)        Do not reboot when asked, but wait for both Gac_32/Gac_64 files to be found and cleaned
6)        PC restored to normal again

Category: Blog
Share : Share Sirefef-FQ Virus to Facebook Share Sirefef-FQ Virus to Twitter 
1 2 3