Disable logon caching

Posted on September 16th, 2011 in Common Technique by admin

When users undo from a network, it is probable for which user to still logon even if his/her comment has been infirm or deleted. A confidence magnitude which we can take with Windows NT is to invalidate it from caching a user’s logon information. To invalidate this ability, launch any registry-editing module as well as navigate to:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Currentversion\Winlogin

From here, find a worth called CachedLogonsCount as well as shift it to 0
(zero). Once we reboot, NT will stop caching logon information.


BOOT.INI Option Reference

Posted on September 2nd, 2011 in Common Technique by admin

Below, we will find the series of utilitarian switches used by program developers to exam their drivers underneath the accumulation of opposite complement configurations. /MAXMEM= This choice will extent NT to regulating usually the volume of mental recall we specify. The series is interpreted as MB. Example: /MAXMEM=16 would extent NT to regulating 16MB of the system’s memory.

/BURNMEMORY= This choice will means NT to “forget” about the volume of mental recall specified, which boundary mental recall similar to /MAXMEM. The worth specified is interpreted as MB. Example: /BURNMEMORY=128 would have NT drop 128MB of the earthy mental recall upon the appurtenance as unusable.

/ONECPU This choice will have NT usually capacitate the single CPU of the multiprocessor system.

/NUMPROC= Only the series of CPUs specified will be enabled. Example: /NUMPROC=2 upon the 4-way complement will means 2 of the 4 processors to be latest by NT.

/SOS Causes NT to imitation report about what drivers have been being commissioned as the complement boots.

/BASEVIDEO Causes NT to operate the customary VGA arrangement motorist when relocating to GUI mode.

/NODEBUG Prevents kernel-mode debugging from being initialized. Overrides the preference of any of the 3 debug-related switches, /DEBUG, /DEBUGPORT as well as /BAUDRATE.

/CRASHDEBUG Its name implies otherwise, though this choice is synonymous for /NODEBUG.

/DEBUG Enables kernel-mode debugging.

/DEBUGPORT= Enables kernel-mode debugging as well as specifies an overrule for the default method pier (COM1) to which the remote debugee is connected. Example: /DEBUGPORT=COM2.

/BAUDRATE= Enables kernel-mode debugging as well as specifies an overrule for the default baud rate (19200) during which the remote debugee will connect. Example: /BAUDRATE=115200.

/KERNEL=filename
The /kernel=filename switch enables we to conclude the tangible KERNEL to be commissioned during startup. This is utilitarian in switching in in in between the debug enabled heart full of debugging formula as well as the unchanging kernel. It is additionally utilitarian for forcing Windows NT to bucket the specific kernel. For example, /KERNEL=ntkrnlmp.exe. This switch authority loads the Ntkrnlmp.exe in the System32 directory.
/HAL= These options pecify overrides of NTLDR’s preference of the record declared NTOSKRNL.EXE in the complement base (<winnt>\system32) as the kernel’s picture record as well as of the record declared HAL.DLL as the HAL picture file. They have been intensely utilitarian for swapping in in in between the checked heart sourroundings as well as the giveaway heart environment. If we instruct to foot in to the checked sourroundings which consists only of the checked heart as well as HAL, which is typically all which is indispensable to exam drivers, follow these stairs upon the complement commissioned with the giveaway set up (retail NT):

Copy the checked chronicle of the heart from the checked set up placement CD to your <winnt>\system32 directory, fixing it NTOSKCHK.EXE. If we have been upon the uniprocessor afterwards duplicate NTOSKRNL.EXE, differently duplicate NTKRNLMP.EXE.
Copy the checked chronicle of the HAL from the checked set up distrution CD to your <winnt>\system32 directory, fixing it HALCHK.DLL. To establish which HAL to copy, go in to your <winnt>\repair office as well as open setup.log in Notepad. Search for HAL.DLL as well as you’ll find the line similar to “\WINNTF\system32\hal.dll = “halmps.dll”,”1a01c”. The name to the right
of the next to pointer is the name of the HAL we should copy.
Make the duplicate of the default line in the system’s BOOT.INI.
In the fibre outline of the foot preference supplement something which indicates which the latest preference will be for the checked set up sourroundings e.g. “Windows NT Server Version 4.0 CHECKED”.
Add the following to the finish of the latest selection’s line: /KERNEL=NTOSKCHK.EXE /HAL=HALCHK.DLL
You’re done. Now we can name the latest line to foot in to the checked sourroundings or name the pre-existing preference to foot in to the giveaway build.

/3GB This switch done the entrance in NT 4.0 Service Pack 3 as well as is upheld upon all after releases of NT. It will means the separate in in in between the user as well as complement portions of NT’s practical residence map to pierce from 2GB (2GB user, 2GB system) to 3GB (3GB user, 1GB system). Giving practical mental recall complete applications similar to database servers the incomparable residence space can urge their performance. Note, however which for an focus to take value of this underline dual one more conditions contingency hold: The complement contingency be partial of the NT Enterprise apartment (SP3 is not) as well as the focus contingency be flagged as the 3-GB wakeful application.

/PCILOCK Stops Windows NT from boldly assigning IO/IRQ resources to PCI inclination as well as leaves the inclination configured by the BIOS.

/NOSERIALMICE=[COMx | COMx,y,z...] Disables method rodent showing of the specified COM port(s). Use this switch if we have the member alternative than the rodent trustworthy to the method pier during the startup sequence. If we operate /NOSERIALMICE but naming the COM port, method rodent showing is infirm upon all COM ports.

Understanding Computer Browser as well as Protocols

Posted on August 30th, 2011 in Common Technique by admin

The mechanism browser is to arrangement a office of all well known computers or domains which a mechanism can reach. The role of a browser use is to pick up as well as inform a life of alternative computers upon a network which have been pity file, print, as well as alternative resources from a active browser or master servers upon any of a active endpoints such as any network custom which is using upon any network card. For example, a mechanism with TCP/IP as well as NetBEUI commissioned upon a network interface cards A as well as B would have 4 endpoints for a mechanism browser client.

If a browser customer is perplexing to fix up a browser server upon any endpoint. It waits until it possibly a single receives current report or times out upon any endpoint prior to returning. This routine can be delayed if there is an endpoint which does not enclose browser servers or a active network label is not continuous to a network. Also Multihomed servers can emanate astonishing as well as unattractive goods with a browser use as well as a master browser cannot be multihomed since a PDC will hit usually a master browser upon a single of a network adapters.
In general, mechanism browser opening improves with fewer protocols or network cards upon a computer. All domain controllers contingency be singlehomed computers for browsing to work correctly. Also a mechanism browser is contingent upon NetBIOS. Therefore, in a churned OS network sourroundings (win9x, NT, ME, W2K as well as XP), we should have a WINS server in a domain network as well as capacitate NetBIOS over TCP/IP (instead of loading NetBEUI) upon w2k/xp in a home or tiny network.

Remove RemoteNC

Posted on August 26th, 2011 in Common Technique by admin

What is RemoteNC as well as dismissal instructions

RemoteNC is a backdoor which gives a assailant unapproved remote entrance to a putrescent computer. RemoteNC allows to govern commands, run programs, conduct files as well as benefit carry out over a complete system. The backdoor affects usually NT, 2000 as well as XP versions of Windows OS.

RemoteNC primer removal:
Kill processes:
remotenc.exe
Delete files:
remotenc.exe

One mechanism screw up a network

Posted on August 25th, 2011 in Common Technique by admin

Symptoms: we have a workgroup network as well as many computers have been win9x, NT as well as ME. After we supplement XP mechanism in to a network, we can’t crop alternative computers in workgroup list.
Resolutions: This is often similar to master browser issue. The elementary resolution is interlude Computer Browser use upon a XP. To stop Computer Browser service, go to a Computer Management>Services as well as Applications>Services.

NT Performance Monitor

Posted on August 20th, 2011 in Common Technique by admin

When we implement IIS upon NT 4.0 Server (or Personal Web Server upon NT 4.0 Workstation), a program adds a own monitoring entries to a Windows NT Performance Monitor. To entrance these latest monitoring devices:
1. Launch a Performance Monitor from a Start button’s Programs/Administrative Tools menu.
2. Select Edit/Add to Chart.
3. Select FTP, Gopher, HTTP, and/or IIS from a Object collect list.

Remove Invisible Stealth Keylogger

Posted on August 6th, 2011 in Common Technique by admin

What is Invisible Stealth Keylogger as well as dismissal instructions

From a publisher:
‘an intensely utilitarian auditing as well as confidence tool. It runs silently in a background, annals all of a machine’s set of keys activities in to a binary record file. The binary record record can after be noticed around enclosed ‘datview.exe’ utility.’
‘Invisible KeyLogger Stealth for WindowsNT chronicle 1.0 is a world’s initial keystroke tape deck which can constraint even NT’s devoted logon (alt-ctrl-del logon). It runs silently in a background, annals all of a NT machine’s set of keys activities in to a binary file. This binary record can after be noticed around a ‘datview.exe’ application provided. The usually record which is compulsory for keystroke recording is a record ‘iks.sys’. This record can be renamed to show off stealth. The binary record record can additionally be renamed as well as be redirected to a opposite path. The first role of this module is to yield network administrators with an in effect equates to to guard workstation use in antagonistic environments. It’s an similarly in effect apparatus for parental control, confidence review as well as network invasion for a confidence professionals.’
Variants: Invisible Stealth Keylogger 1.2d, Invisible Stealth Keylogger 2.0, Invisible Stealth Keylogger 2.1

Invisible Stealth Keylogger primer removal:
Kill processes:
datview.exe, iks2k20d.exe
Delete registry values:
HKEY_LOCAL_MACHINE\system\controlset001\enum\root\legacy_iks
HKEY_LOCAL_MACHINE\system\controlset001\services\iks
HKEY_LOCAL_MACHINE\system\controlset002\enum\root\legacy_iks
HKEY_LOCAL_MACHINE\system\controlset002\services\iks
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_iks
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\iks
Delete files:
log spectator for iks.lnk, datview.exe, iks2k20d.exe, iks.dat, iks.sys, uninst.isu
Delete directories:

iks

How to run a collection record any time a mechanism boots

Posted on August 1st, 2011 in Common Technique by admin

Reasoning:
It might be required to run a collection record to configure mechanism inclination or undo / duplicate files any time a mechanism boots to assistance a mechanism run some-more well or concede a device to run.

Solution:
Windows 98, XP, NT, 2000, Vista as well as after users

Create a by-pass to a collection file. Additional report about how to emanate a by-pass can be found upon request CH00739.
Once a by-pass has been combined right-click a record as well as name Cut.
Click Start, Programs, right-click a Startup printed matter as well as click Open
Once a Startup printed matter has been non-stop click Edit as well as pulp a by-pass in to a startup. Any shortcuts in a startup printed matter will automatically begin any time Windows starts.

Windows 95, 3.x as well as MS-DOS users

Place a line in your autoexec.bat which calls a collection record any time we wish to foot a computer. For example:

CALL C:\myfile.bat

In a on top of e.g. any time your mechanism starts as well as processes a autoexec.bat record it will call a collection record myfile.bat.

Precautions we ought to get to preserve your cinema from reception corrupted

Posted on July 15th, 2011 in Common Technique by admin

Have we unnoticed your photos as well as cinema which we have snapped in your digital camera? have we been acid for digital design recovery focus to redeem your pictures?

Gone would be the days when we customarily had reminiscences of your profitable moments of the previous. together with the attainment of digital camera, we have been means to constraint your noted moments as but or transformation photos inside your cameras. together with the appearance of Digital digital camera, which would be the lates growth inside the method of cameras, the photography has acquired the code latest definition. With good understanding of capacity inside the mental recall card, the digital digital camera have been recognized for the clear viewable imaging. carrying pronounced that, we have been means to get absolved of your cinema together with the crime of your mental recall card. The crime of your mental recall label might maybe occur for countless causes the couple of of them removing improrer switching off, pathogen or malware assault, or random deletion. You at once understand, your profitable moments similar to primary small the single theatre of one’s son, your primary sermon upon the stage, your matrimony along with your primary outing to abroad have been unnoticed inside the second. carrying pronounced that, we have been means to redeem your unnoticed cinema by the function of digital design recovery application.

Causes:

Your cinema in your digital camera can get unnoticed since of to your successive singular causes:

Improper switching off: Abrupt switching off of one’s digital camera has good odds of losing the cinema out of your mental recall label since of to crime of your saved photos

Virus or malware assault: Damage of your cinema might maybe occur since of to your pathogen or malware assault.

Accidental or conscious deletion: Accidental erasure of your cinema might additionally effect inside the rebate of cinema out of your cameras. Even an conscious erasure can lead to rebate of cinema out of your camera

Precaution:

Your cinema might presumably get hurtful for the lot of causes. however we ought to story sold precautionary measures to preserve your cinema from reception corrupt:

Keep the backup of one’s photographs

While shutting down reside by the speedy techniques to entirely close down

Use present antivirus to equivocate your digital images from reception corrupted

However, even upon successive the over precautionary measures, we might maybe but not be means to preserve your cinema from reception corrupt. we have been means to preserve your cinema from anupdated backup. But to retain the befitting backup isn’t all the time sensible. in reserve from this, the remarkable battery disaster might maybe outcome in remarkable shutting down of digital camera. carrying pronounced that, to redeem the pictures, we have been means to operate Digital design Recovery software, which might effectively redeem the damaged digital pictures. The focus scans the mental recall label throughly to acquire behind again the unnoticed or damaged pictures.

Stellar Phoenix design Recovery Software is customarily the Do-It-Yourself Multimedia liberation focus which recovers digital cinema from digital digital camera, extraneous wily drives, laptops as well as desktop, coop drive, CD, DVD, USB Drives, as well as mental recall cards. The focus supports Windows seven, Vista, XP, NT, 2003 as well as 2000.

Windows NT, 2000, as well as XP

Posted on July 9th, 2011 in Common Technique by admin

Windows NT, 2000 as well as XP machines handle otherwise than a Windows 95/98 machines. The VPN Client does not have a choice to record upon to a Microsoft network. It prompts we to record upon to a domain when we foot up your machine.

If we try to settle a tie from a remote site but entrance to a domain (in alternative words, we have been not upon a inner network), we get an blunder summary which indicates which “No Domain Controller could be found.”

When we try to settle a VPN hovel with a VPN Concentrator by dialing up by an ISP or regulating a DSL service, a tie does not prompt we to record upon to a domain. Instead, we have been means to go upon with a secure link.

Map a expostulate (if we have not finished so) to record upon to a domain. Double-click upon a mapped expostulate to get a cue prompt so which we can record upon to a network.

Check a networking properties upon a appurtenance to safeguard which a Personal Computer has been configured with a scold domain name, as well as so on.

Note: The pass is to record upon to a NT domain successfully.

Note: If we wish to run logon scripts by a NT machine, capacitate a Enable begin prior to logon underline in a client.

Next Page »