Monday, July 18, 2011
Creation of Rules to block Junk Mails..
I.Worm-Kido
KIDO
THERE ARE FIVE VARIANTS OF KIDO AS PER SOURCE OF MICROSOFT
THEY WERE REPORTED TO MICROSOFT ON FOLLOWING DATES:
1. W32/CONFICKER.A IT WAS REPORTED ON (November 21 2008)
2. W32/CONFICKER.B IT WAS REPORTED ON (December 29 2008)
3. W32/CONFICKER.C IT WAS REPORTED ON (February 20 2009)
4. W32/CONFICKER.D IT WAS REPORTED ON (March 4 2009)
5. W32/CONFICKER.E IT WAS REPORTED ON (April 8 2009)
THIS HOW THE WORM SPREADS

Digital Protection Spyware Removal...
Description of Digital Protection consequences of its residing on your PC
That would be futile to remove Digital Protection (DigitalProtection) adware and give no regard to other parasites inhabiting your PC. The remark is made to emphasize that Digital Protection is rather a dependent program as the most common way of its downloading and installation is based on prior introduction of BHO (browser helper object) or trojan, and those infections are equally dangerous oar even more destructible and annoying than Dig
ital Protection. Upon introduction of preliminary infection things go as follows:
- in case of BHO infection , web-browser is exploited as alerts generator so that users are lured to download the adware of Digital Protection and the alerts are linked with Digital Protection website suggesting to get a copy of Digital Protection and providing relevant link. It is possible to buy the adware instantly passing by the stage of its trialware. However, you need to remove Digital Protection activated adware as it remains adware no matter you have paid for its activation;
- in case of trojan infection the rogue is downloaded in no agreement with user, nor the user is aware of infection until the downloading is complete.
Get rid of Digital Protection as there is no use to have a program that is unable to protect you from current virus attacks and remove already present in the memory of your PC malware, viruses and worms.![]()
![]()
![]()
![]()
Digital Protection Technical Details
· Full name: Digital Protection, DigitalProtection, Digital-Protection
· Version: 2010
· Type: Rogue anti-spyware, Trojan horse
· Origin: Russian Federation
Digital Protection screenshot (click to enlarge):

Signs of being infected with Digital Protection:
Digital Protection is ordinary fake antispyware that is designed to start automatically and attempts to be the first program that appears on the monitor after Windows warming up. That might result in its conflicts with computer system and other self-initiating apps.
Digital Protection runs a show that its developers want us to treat as a scan for viruses. That is not actually a search for threats but just a show when all names of infections are actually selected randomly or invented by hackers to misleading purposes. Besides, there are alerts in abundance that appear at seemingly random intervals, but in fact they are arranged in precise sets and their appearance frequency is increasing according to the schedule specified by the hackers. Remove Digital Protection upon observing any sign of its presence. Case may occur when you may remove Digital Protection hijacker and ignore relevant suggestions to upload the trialware of Digital Protection. The hijacker betrays itself as its business is to make you visiting the website of Digital Protection so that the website is often downloaded by your browser.
Click here to remove Digital Protection and related parasites having performed the free scan.
Automatic Removal of Digital Protection from your PC:
No matter whether Digital Protection removal is an adequate measure to purify your PC of any infections, follow the link below as there is unlikely to be another way to establish if you need to remove Digital Protection only or to remove Digital Protection plus additional parasites.
Digital Protection Removal Tool
Manual Removal of Digital Protection:
Even if there is a solely of Digital Protection to remove, yet you are recommended to equip your PC with Digital Protection removal tool as that would ensure your future protection and optimize your PC configuration.
If you are going to start Digital Protection removal in manual mode, please reboot prior to the beginning of Digital Protection removal process in order that Safe Mode could be selected. Once the Safe Mode is set, make sure you have Internet connections enabled and no apps running while Digital Protection removal steps are executed.
Remove Digital Protection files and dll’s:
c:\Documents and Settings\All Users\Application Data\fiosejgfse.dll
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Digital Protection.lnk
%UserProfile%\Desktop\Digital Protection Support.lnk
%UserProfile%\Desktop\Digital Protection.lnk
%UserProfile%\Start Menu\Programs\Digital Protection
%UserProfile%\Start Menu\Programs\Digital Protection\About.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Activate.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Buy.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Digital Protection Support.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Digital Protection.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Scan.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Settings.lnk
%UserProfile%\Start Menu\Programs\Digital Protection\Update.lnk
c:\Program Files\Digital Protection
c:\Program Files\Digital Protection\about.ico
c:\Program Files\Digital Protection\activate.ico
c:\Program Files\Digital Protection\buy.ico
c:\Program Files\Digital Protection\dig.db
c:\Program Files\Digital Protection\digext.dll
c:\Program Files\Digital Protection\dighook.dll
c:\Program Files\Digital Protection\digprot.exe
c:\Program Files\Digital Protection\help.ico
c:\Program Files\Digital Protection\scan.ico
c:\Program Files\Digital Protection\settings.ico
c:\Program Files\Digital Protection\splash.mp3
c:\Program Files\Digital Protection\Uninstall.exe
c:\Program Files\Digital Protection\update.ico
c:\Program Files\Digital Protection\virus.mp3
%Temp%\4otjesjty.mof
%Temp%\asd1.tmp
%Temp%\c865.tmp
%Temp%\davclnt.exe
%Temp%\dhdhtrdhdrtr5y
%Temp%\dig.dat
%Temp%\digr.dat
Unregister Digital Protection registry values:
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_LOCAL_MACHINE\SOFTWARE\Digital Protection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Digital Protection
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Digital Protection”
Thursday, November 18, 2010
Find out what your Windows Hotfixes do
First, you need to go to your Control Panel, Add/Remove Programs. Next, scroll down toward the bottom and you will see "Windows XP Hotfix..."
Click the hotfix and it will expand to show "Click here for support information".
Clicking there will bring up another screen with a URL that takes you to a description of what that hotfix does (make sure you're online when you do it).
Now you can satisfy your curiosity when those updates happen. This also helps let you know if you have a security patch needed to prevent a worm/virus.
Thursday, July 16, 2009
Services Used By Malware...
A common misconception when working on removing malware from a computer is that the only place an infection will start from is in one of the entries enumerated by HijackThis. For the most part these entries are the most common, but it is not always the case. Lately there are more infections installing a part of themselves as a service. Some examples are Ssearch.biz and Home Search Assistant.
When cleaning a computer the standard approach is to clean up the Run entries and the other more common startup entries first. For the most part, that will be enough to remove the infection. The problem arises when the log looks clean and yet there are still problems. One place to continue looking for the infection is in the operating system's services to see if there is a service that does not belong there and could possibly be loading the infection. A service is a program that is automatically started by Windows NT/XP/2000/2003 on startup or through some other means and is generally used for programs that run in the background.
Service Configuration
A service is loaded on startup by either using svchost.exe or by windows directly launching the application. If a service is loaded directly by windows, the associated file name that launches the service can be found in the ImagePath value under the following registry entry
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\servicename
When the service is being launched by svchost.exe, it will be placed in a particular service group, which is then launched by svchost.exe. A listing of these groups and the services that are launched under them can be found here:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Svchost
Under this key you will find various groups (netsvcs, LocalServices, etc) in which each contain multiple services that will be launched when the group is loaded by svchost.exe. These groups are loaded by the following command:
svchost.exe -k netsvcs
It will load all the services found under the netsvcs group in the above key and appear as one process under the process list. So each time a new group is loaded by svchost.exe, you will find a new svchost.exe process listed in memory. It is for this reason why there are multiple svchost.exe processes listed on a machine. If you are using Windows XP, as this command is not available on Windows 2000, you can see what services each svchost.exe process is controlling by running the following command from a command prompt: tasklist /SVC
When a service is launched in this way, the actual filename for the service can be found here:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\servicename\Parameters\\ServiceDll
The value of ServiceDLL is the actual service file that we want to be concerned with.
Listing and Analyzing the services
A simple batch file that I created uses the SysInternals PSSERVICE program to get a list of the services and open a notepad. Nothing fancy, but saves time when diagnosing.
This file can be found here:
Getservices.zip
To use the script, you simply unzip the file to your C: drive and you will now find a directory called c:\getservice. Inside that directory is a batch file called getservice.bat and the psservice.exe file. Simply double-click on the getservice.bat file and it will create a notepad containing a list of services installed on the computer you are running it on.
Note: You must be running as a user with Administrator privaleges or this script will either not work or not give enough information.
The output of the script will contain information about each service installed on your computer. The important information to look at in the service entries are::
SERVICE_NAME This is the name the service goes by and is what it is stored in the registry under.
BINARY_PATH_NAME This is the actual file that is being used to launch the service.
DISPLAY_NAME This is the name the service appears under in the services.msc in the control panel.
START_TYPE This tells you if the service is disabled, manually started, or automatically started.
Below are examples of how an entry would look for two different types of infections explanations of how to interpret the information given:
SERVICE_NAME: O? ’ŽrtñåȲ$Ó
(null)
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\WINDOWS\system32\d3xi.exe /s
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Remote Procedure Call (RPC) Helper
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem
Home Search Assistant Example
The Home Search Assistant uses a service, among standard Run entries, as part of its infection. The important attributes we can gather from the above information are as follow:
1. It's display name in the Services control panel is Remote Procedure Call (RPC) Helper
2. It has a service name of O? ’ŽrtñåȲ$.i in the registry.
3. It is started automatically on boot up
4. The file that starts this service is C:\WINDOWS\system32\d3xi.exe
Armed with this information we now know what registry entries the service is stored in and the file that is being used as part of the Home Search Assistant infection.
The next example is for the Ssearch.biz hijacker, but it is loaded in a slightly different way, causing us to work a little more in finding out what the infection file is.
SERVICE_NAME: pnpsvc
Provides plug and play svc devices support
TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Plug and Play svc service
DEPENDENCIES :
SERVICE_START_NAME: LocalSystem
SSearch.biz Example
The SSearch.biz hijacker uses a service as part of its infection as well. The important attributes we can gather from the above information are as follow:
1. It's display name in the Services control panel is Plug and Play svc service
2. It has a service name of pnpsvc in the registry
3. It is started automatically on boot up
4. The file that starts this service is C:\WINNT\system32\svchost.exe -k netsvcs
Now this information, though helpful, is somewhat useless without digging around further in the registry. We know that the file that starts the service is svchost.exe, but that is a legitimate program, so we do not want to delete it. How then can we find the appropriate file to remove? Remember what we discussed above about how svchost.exe works?
From the BINARY_PATH_NAME we know that the file is part of the netsvcs group. That means that when svchost loads that group, which may contain many services, it will also load the file associated with this service. To find the actual file name for this particular service, we need to check the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pnpsvc\Parameters\\ServiceDll
The value of the ServiceDLL key is the actual file that we want to get rid of.
In the next section we will discuss how to remove the service via deleting entries in the registry.
Removing a service
Removing a service manually requires removing entries from the registry. This can be a dangerous task for the health of your computer. If you do not feel comfortable doing this, then please ask someone else to help with this step of the cleanup procedure as making a mistake can cause the computer you are working on to not work properly.
Service entries are stored in the registry under a section called ControlSet. A ControlSet are located under the following key:
HKEY_LOCAL_MACHINE\SYSTEM
A ControlSet is a complete copy of the configuration that is used to successfully launch services and other critical files & drivers for Windows. When you look under the above key there will always be at least two ControlSets and one CurrentControlSet. For the sake of this tutorial I will use what I have on my machine, which is ControlSet1 and ControlSet2 (there may be more up to a maximum of 4). One of these numbered control sets refers to the default configuration that is used when the computers normally boots. The other numbered control set refers to the one used when you choose to boot up using the Last Known Good Configuration. The last one, CurrentControlSet, is an exact mirror of the ControlSet we had used to boot into Windows, so that if you make a change CurrentControlSet it will automatically appear in the ControlSet it is mirroring and vice-versa.
If you wanted to know for sure which ControlSet the CurrentControlSet is pointing to you can examine the following key:
HKEY_LOCAL_MACHINE\SYSTEM\Select
This key gives us important information as to which ControlSet was used on the last boot, which is used by default, and which is designated for LastKnownGoodConfiguration. This key contains the following values:
Current:This will contain the number of the ControlSet that we are currently using and which CurrentControlSet points to.
Default:This will contain the number of the ControlSet that Windows uses by default when booting.
Failed: This will indicate with ControlSet was the one that failed on last boot. If it is 0, then there was no failures.
LastKnownGood: This will contain the number of the ControlSet that Windows uses when we choose the Last Known Good Configuration
If we wanted to manually remove a service from the registry we would only need to remove it from the numbered ControlSets (remember CurrentControlSet is a mirror of one of the numbered ones). For example, to remove the service for a SSearch.biz hijacker on my computer, we would simply delete from the registry the following entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pnpsvc\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\pnpsvc\
Once we reboot, these services will no longer be listed in the Services control panel.
At times though, the malware will also install itself under these keys:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root
as subkeys called LEGACY_svcname. These LEGACY_svcname entries should be deleted as well, but will usually require you to change the permissions on them in order to delete them. Simply change the security permissions on these keys to Everyone (Full) and then delete them.
Conclusion
Knowing how to diagnose a service running as a malware is an important part of fighting spyware. As more and more spyware and viruses use this technique , the understanding of how services work and are configured in the Registry will make the difference between fixing a computer and not fixing it.
Sunday, May 31, 2009
How to install and use the Recovery Console in Windows XP
SUMMARY
To recover your operating system when your computer does not start correctly or does not start at all, you may want to install and use the Windows Recovery Console. However, Microsoft recommends this method of system recovery for advanced users only. Also, learn about the Recovery Console command prompt, command actions, rules, how to remove the Recovery Console, and how to install it during an unattended installation.
INTRODUCTION
Microsoft recommends that you use the Recovery Console only after Safe mode and other startup options do not work. The Recovery Console is recommended only if you are an advanced user who can use basic commands to identify and locate problem drivers and files. Additionally, you must be an administrator to use the Recovery Console.
MORE INFORMATION
How to install the Recovery Console
You can install the Recovery Console on your computer to make it available if you cannot restart Windows. You can then select the Recovery Console option from the list of available operating systems during startup. Install the Recovery Console on important servers and on the workstations of IT personnel. This article describes how to install the Recovery Console to your Microsoft Windows XP-based computer. To install the Recovery Console, you must be logged on as an administrator.
Although you can run the Recovery Console by starting directly from the Windows XP CD, it is generally more convenient to set it up as a startup option on your startup menu. To run the Recover Console directly from the CD, see the "How to use the Recovery Console" section.
To install the Recovery Console, follow these steps:
1. Insert the Windows XP CD into the CD-ROM drive.
2. Click Start, and then click Run.
3. In the Open box, type d:\i386\winnt32.exe /cmdcons where d is the drive letter for the CD-ROM drive. In the case of 'Microsoft Windows XP Professional x64 Edition, typed:\amd64\winnt32.exe /cmdcons where d is the drive letter for the CD-ROM drive.
4. A Windows Setup Dialog Box appears. The Windows Setup Dialog Box describes the Recovery Console option. To confirm the installation, click Yes.
5. Restart the computer. The next time that you start your computer, "Microsoft Windows Recovery Console" appears on the startup menu.
Alternatively, you can use a Universal Naming Convention (UNC)-established connection to install the Recovery Console from a network share point.
How to use the Recovery Console
You can enable and disable services, format drives, read and write data on a local drive (including drives that are formatted to use the NTFS file system), and perform many other administrative tasks. The Recovery Console is particularly useful if you have to repair your computer by copying a file from a disk or CD-ROM to your hard disk, or if you have to reconfigure a service that is preventing your computer from starting correctly.
If you cannot start your computer, you can run the Recovery Console from the Microsoft Windows XP startup disks or the Windows XP CD-ROM. This article describes how to perform this task.
After Windows XP is installed on your computer, to start the computer and use the Recovery Console you require the Windows XP startup disks or the Windows XP CD-ROM.
Note To start the computer from the Windows XP CD-ROM, you must configure the basic input/output system (BIOS) of the computer to start from your CD-ROM drive.
To run the Recovery Console from the Windows XP startup disks or the Windows XP CD-ROM, follow these steps:
1. Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.
Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
3. If you have a dual-boot or multiple-boot computer, select the installation that you must access from the Recovery Console.
4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.
5. At the command prompt, type the appropriate commands to diagnose and repair your Windows XP installation.
For a list of commands that are available in Recovery Console, type recovery console commands or help at the command prompt, and then press ENTER.
For information about a specific command, type help commandname at the command prompt, and then press ENTER.
6. To exit the Recovery Console and restart the computer, type exit at the command prompt, and then press ENTER.
How to use the Recovery Console command prompt
When you use the Recovery Console, you are working at a special command prompt instead of the ordinary Windows command prompt. The Recovery Console has its own command interpreter. To enter this command interpreter, you are prompted by Recovery Console to type the local Administrator password.
When the Recovery Console starts, you can press F6 to install a third-party SCSI or RAID driver, in case you need such a driver to access the hard disk. This prompt works the same as it does during installation of the operating system.
The Recovery Console takes several seconds to start. When the Recovery Console menu appears, a numbered list of the Windows installations on the computer appears. (Generally, only c:\Windows exists.) Press a number before you press ENTER, even when only one entry appears. If you press ENTER without selecting a number, the computer restarts and begins the process again.
When you see the prompt for %SystemRoot% (generally C:\Windows), you can start using the available commands for the Recovery Console.
Command actions
The following list describes the available commands for the Recovery Console:
• Attrib changes attributes on one file or subdirectory.
• Batch executes commands that you specify in the text file, Inputfile. Outputfile holds the output of the commands. If you omit the Outputfile parameter, output appears on the screen.
• Bootcfg modifies the Boot.ini file for boot configuration and recovery.
• CD (Chdir) operates only in the system directories of the current Windows installation, removable media, the root directory of any hard disk partition, or the local installation sources.
• Chkdsk The /p switch runs Chkdsk even if the drive is not flagged as dirty. The /rswitch locates bad sectors and recovers readable information. This switch implies /p. Chkdsk requires Autochk. Chkdsk automatically looks for Autochk.exe in the startup folder. If Chkdsk cannot find the file in the startup folder, it looks for the Windows 2000 Setup CD-ROM. If Chkdsk cannot find the installation CD-ROM, Chkdsk prompts the user for the location of Autochk.exe.
• Cls clears the screen.
• Copy copies one file to a target location. By default, the target cannot be removable media, and you cannot use wildcard characters. Copying a compressed file from the Windows 2000 Setup CD-ROM automatically decompresses the file.
• Del (Delete) deletes one file. Operates within the system directories of the current Windows installation, removable media, the root directory of any hard disk partition, or the local installation sources. By default, you cannot use wildcard characters.
• Dir displays a list of all files, including hidden and system files.
• Disable disables a Windows system service or driver. The variable service_or_driver is the name of the service or driver that you want to disable. When you use this command to disable a service, the command displays the service's original startup type before it changes the type to SERVICE_DISABLED. Note the original startup type so that you can use the enable command to restart the service.
• Diskpart manages partitions on hard disk volumes. The /add option creates a new partition. The /delete option deletes an existing partition. The variable device is the device name for a new partition (such as \device\harddisk0). The variable drive is the drive letter for a partition that you are deleting (for example, D). Partition is the partition-based name for a partition that you are deleting, (for example: \device\harddisk0\partition1) and can be used instead of the drive variable. The variable size is the size, in megabytes, of a new partition.
• Enable enables a Windows system service or driver. The variable service_or_driver is the name of the service or driver that you want to enable, and start_type is the startup type for an enabled service. The startup type uses one of the following formats:
SERVICE_BOOT_START
SERVICE_SYSTEM_START
SERVICE_AUTO_START
SERVICE_DEMAND_START
• Exit quits the Recovery Console, and then restarts the computer.
• Expand expands a compressed file. The variable source is the file that you want to expand. By default, you cannot use wildcard characters. The variable destination is the directory for the new file. By default, the destination cannot be removable media and cannot be read-only. You can use the attrib command to remove the read-only attribute from the destination directory. The option /f:filespec is required if the source contains more than one file. This option permits wildcard characters. The /y switch disables the overwrite confirmation prompt. The /d switch specifies that the files will not be expanded and displays a directory of the files in the source.
• Fixboot writes a new startup sector on the system partition.
• Fixmbr repairs the startup partition's master boot code. The variable device is an optional name that specifies the device that requires a new Master Boot Record. Omit this variable when the target is the startup device.
• Format formats a disk. The /q switch performs a quick format. The /fs switch specifies the file system.
• Help If you do not use the command variable to specify a command, help lists all the commands that the Recovery Console supports.
• Listsvc displays all available services and drivers on the computer.
• Logon displays detected installations of Windows and requests the local Administrator password for those installations. Use this command to move to another installation or subdirectory.
• Map displays currently active device mappings. Include the arc option to specify the use of Advanced RISC Computing (ARC) paths (the format for Boot.ini) instead of Windows device paths.
• MD (Mkdir) operates only within the system directories of the current Windows installation, removable media, the root directory of any hard disk partition, or the local installation sources.
• More/Type displays the specified text file on screen.
• Rd (Rmdir) operates only within the system directories of the current Windows installation, removable media, the root directory of any hard disk partition, or the local installation sources.
• Ren (Rename) operates only within the system directories of the current Windows installation, removable media, the root directory of any hard disk partition, or the local installation sources. You cannot specify a new drive or path as the target.
• Set displays and sets the Recovery Console environment variables.
• Systemroot sets the current directory to %SystemRoot%.
Recovery Console rules
Several environment rules are in effect while you are working in the Recovery Console. Typeset to see the current environment. By default, these are the rules:
• AllowAllPaths = FALSE prevents access to directories and subdirectories outside the system installation that you selected when you entered the Recovery Console.
• AllowRemovableMedia = FALSE prevents access to removable media as a target for copied files.
• AllowWildCards = FALSE prevents wildcard support for commands such as copy anddel.
• NoCopyPrompt = FALSE means that you are prompted by the Recovery Console for confirmation when overwriting an existing file.
How to delete the Recovery Console
To delete the Recovery Console:
1. Restart your computer, click Start, click My Computer, and then double-click the hard disk where you installed the Recovery Console.
2. On the Tools menu, click Folder Options, and then click the View tab.
3. Click Show hidden files and folders, click to clear the Hide protected operating system files check box, and then click OK.
4. At the root folder, delete the Cmdcons folder and the Cmldr file.
5. At the root folder, right-click the Boot.ini file, and then click Properties.
6. Click to clear the Read-only check box, and then click OK.
Warning: Modifying the Boot.ini file incorrectly may prevent your computer from restarting. Make sure that you delete only the entry for the Recovery Console. Also, change the attribute for the Boot.ini file back to a read-only state after you finish this procedure. Open the Boot.ini file in Microsoft Windows Notepad, and remove the entry for the Recovery Console. It looks similar to this:
C:\cmdcons\bootsect.dat="Microsoft Windows Recovery Console" /cmdcons
7. Save the file and close it.
How to install Recovery Console during an unattended installation
To install the Recovery Console during the unattended installation of Windows, you must use the [GuiRunOnce] section of the unattend.txt file.
Command1="path\winnt32 /cmdcons /unattend"
For more information about how to use the Unattend.txt file, see the Deployment Planning Guideof the Windows 2000 Server Resource Kit.
Friday, April 10, 2009
This article describes how to convert a FAT16 file system or a FAT32 file system to an NTFS file system in Microsoft Windows XP. The requirements or the conditions for converting your file system are explained first to minimize problems. A troubleshooting section is provided at the end of the article in case you experience any problems while trying the conversion.
INTRODUCTION
Microsoft Windows XP supports the following three file systems for fixed disks:
• FAT16
• FAT32
• NTFS
We recommend that you use NTFS with Windows XP because of its advanced performance, security, and reliability features. This article describes how to convert a FAT16 volume or a FAT32 volume to NTFS.
Requirements
Before you start to convert a FAT volume or a FAT32 volume to NTFS, consider the following limitations and requirements:
• UDF and CDFS are only used with optical media and cannot be converted to NTFS.
• FAT12 is the only format used on floppy diskettes.
• Some earlier programs that were not written for Microsoft Windows NT 4.0 or for Microsoft Windows 2000 may exhibit slow performance after you convert the FAT32 file system to NTFS. This issue does not occur on a clean partition of NTFS.
• You can use the convert command (Convert.exe) to convert an existing FAT volume or FAT32 volume to NTFS. Because this conversion retains all your files (unlike a format operation), use Convert.exe when you want to keep existing files on your volumes intact.
• The conversion to NTFS is a one-way process. After you convert a drive or a partition to NTFS, you cannot convert it back to FAT or to FAT32. To restore the volume to the previous file system, you must reformat it as FAT or as FAT32. This action erases all existing data including your programs and personal files. In this case, you must either restore your data from a backup, or reinstall your operating system and programs.
• Convert.exe requires that you have some free space on the drive or on the partition to convert it. If Convert.exe determines that there is not sufficient free space on the volume, it does not convert the volume.
• If you run other Microsoft Windows operating systems on your computer in addition to Windows XP, note the following issues:
o Only Windows 2000 and Windows XP have full access to files on an NTFS volume.
o Windows NT 4.0 Service Pack 4 (SP4) or later can access files on an NTFS volume. However, there are some limitations with files that are stored by using features from the latest version of NTFS.
o Microsoft Windows Millennium Edition (Me), Microsoft Windows 98 Second Edition and earlier, and MS-DOS cannot access files on an NTFS volume.
How to convert a FAT volume or a FAT32 volume to NTFS
Note Although the chance of corruption or data loss during the conversion is minimal, we recommend that you perform a backup of the data on the volume that you want to convert before you start the conversion.
To convert an existing FAT or FAT32 volume to NTFS, follow these steps:
1. Click Start, point to All Programs, point to Accessories, and then click Command Prompt.
2. At the command prompt, type the following, where drive letter is the drive that you want to convert:
convert drive letter: /fs:ntfs
For example, type the following command to convert drive E to NTFS:
convert e: /fs:ntfs
Note If the operating system is on the drive that you are converting, you will be prompted to schedule the task when you restart the computer because the conversion cannot be completed while the operating system is running. When you are prompted, click YES.
3. When you receive the following message at the command prompt, type the volume label of the drive that you are converting, and then press ENTER:
The type of the file system is FAT.
Enter the current volume label for drive drive letter
4. When the conversion to NTFS is complete, you receive the following message at the command prompt:
Conversion complete
5. Quit the command prompt.
Troubleshooting
• When you try to convert a volume to NTFS, you receive the following error message at the command prompt:
Convert cannot gain exclusive access to the drive letter drive, so it cannot convert it now. Would you like to schedule it to be converted the next time the system restarts?
This issue occurs when the volume that you are trying to convert is in use, for example, if the drive that you want to convert is the same drive where Windows XP is running.
To resolve this issue, type Y at the command prompt. The volume or drive is converted to NTFS the next time that you start your computer.
• When you try to convert a volume to NTFS, you receive the following error message at the command prompt:
Convert cannot run because the volume is in use by another process. Convert may run if this volume is dismounted first. ALL OPENED HANDLES TO THIS VOLUME WOULD THEN BE INVALID. Would you like to force a dismount on this volume?
This issue occurs when there are files that are being used on the volume that you are trying to convert. This includes files that are accessed by users over the network.
To resolve this issue, use one of the following methods:
o Quit all the programs that are using the files on the drive, and then type y at the command prompt to convert the drive to NTFS.
o At the command prompt, type Y.
You receive the following error message:
Convert cannot gain exclusive access to the drive letter drive, so it cannot convert it now. Would you like to schedule it to be converted the next time the system restarts?
Type Y at the command prompt. The volume or drive is converted to NTFS the next time that you start your computer.
REFERENCES
For more information about Convert.exe, follow these steps to view a list of command line parameters:
1. Click Start, point to All Programs, point to Accessories, and then click Command Prompt.
2. At the command prompt, type help convert, and then press ENTER.
A list of command line parameters for Convert.exe appears. For more information about how much free space is required to convert FAT to NTFS, click the following article number to view the article in the Microsoft Knowledge Base: 156560 Free space required to convert FAT to NTFS
APPLIES TO
• Microsoft Windows XP Home Edition
• Microsoft Windows XP Professional