Sunday, September 30, 2007

Microsoft Excel Bug

In a blog post, Microsoft employee David Gainer said that when computer users tried to get Excel 2007 to multiply some pairs of numbers and the result was 65,535, Excel would incorrectly display 100,000 as the answer.

Gainer said Excel makes mistakes multiplying 77.1 by 850, 10.2 by 6,425 and 20.4 by 3,212.5, but the program appears to be able to handle 16,383.75 times 4.

''Further testing showed a similar phenomenon with 65,536 as well,'' Gainer wrote Tuesday.

He said Excel was actually performing the calculations correctly, but when it comes time to show the answer on the screen, it messes up.

Gainer said the bug is limited to six numbers from 65,534.99999999995 to 65,535, and six numbers from 65,535.99999999995 to 65,536, and that Microsoft is working hard to fix the problem.


Saturday, September 15, 2007

Break the chain (Olympic Torch Virus)





Virus warning e-mails harken from the Internet's infancy, when the only reliable defense against the malicious programs was vigilance and knowledge. Viruses have become more sophisticated, and so have the defenses against them. Since most e-mailed virus warnings today, like this one, are bogus, relying on these through-the-grapevine defenses is both unnecessary and unadvisable.

SAMPLE CHAIN LETTER TEXT

Please read the attached warning issued today .

PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS:

You should be alert during the next days:

Do not open any message with an attached filed called "Invitation" regardless of who sent it. It is a virus that opens an Olympic Torch which "burns" the whole hard disc C of your computer. This virus will be received from someone who has your e-mail address in his/her contact list, that is why you should send this e-mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it. If you receive a mail called "invitation", though sent by a friend, do not open it and shut down your computer immediately. This is the worst virus announced by CNN, it has been classified by Microsoft as the most destructive virus ever. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus. This virus simply destroys the Zero Sector of the Hard Disc, where the vital information is kept.

FORWARD THIS E-MAIL TO EVERYONE YOU KNOW . . . REMEMBER: IF YOU SEND IT TO THEM, YOU WILL BENEFIT ALL OF US.

END CHAIN LETTER TEXT

The text above first surfaced in February, 2006, just days before the opening ceremonies of the XX Olympic Winter Games in Turin, Italy. It is a reworking of early hoaxes around since 2002 that warned against opening e-mails titled A Card For You and WTC Survivor, and is no more true.

Virus warnings play on common societal fears that something we do, such as unknowingly opening an infected file, will cause us a great deal of heartache and not just a little embarrassment, since your infection will undoubtedly spread to others. Just as many legitimate viruses key in on current events to coax their victims into unleashing their bugs, so do hoax creators use newsworthy names and events in increase the 'fear factor' and perceived timeliness of the tome. Then, they tell you that you could be key not only into protecting your own, but also that you have a responsibility to your friends and family to share the information with them - that you are their only defense against malicious hackers.

Yet, in the 'real world,' relying on e-mailed virus warnings to ensure the safety of your computer and the data it contains is foolhardy at best and suicidal - technologically speaking - at worst. The so-called advisories are almost always false. Even when they do have an ounce of truth to them, they are either blown out of proportion (such as in the case of the Osama Bin Laden virus warning) or devoid of any real information or advice that would truly help you avoid or clean an infection. They serve only to make us paranoid and, in some cases, can do more harm than good (e.g., forwarding them increases your exposure to spam and scams).

True protection from unwanted intrusions on your data and hardware comes from active, up-to-date, real-time antivirus software. These programs are inexpensive, effective and easy to install. If you are currently browsing the internet without current antivirus protection, you are asking for trouble - trouble that all the forwarded e-mail warnings in the world won't prevent. For more that you can do to make sure your computer is as safe as it can be, please read Protecting Your PC in the Chain-Breaker's Library. Then, never forward another virus warning. Break this chain.

Removing Orkut\Mozilla Virus

Run the task manager,in processes tab you'll see two processes svchost.exe running under your user name, end them.
then go to

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\Explorer\Run
delete winlogon key



then go to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
here set the checked value to 1

AND IF you are not administrator, the virus couldnt access the registry, so you'll see an invisible icon in the startup menu of start menu, delete it

DO ALL THIS AFTER YOU END THE TWO PROCESSES otherwise they'll be RESTORED every 10 seconds

After all this go to folder options uncheck hide protected files
you'll see C:\heap41a folder, delete it and you'll see microsoftpowerpoint.exe in your pen drives along with autorun.inf , delete them


Removing Fake microsoftpowerpoint.exe virus from your computer

Hello friends,

From today onwards i ll be continuously posting all my experiences here. I found the ways to remove orkut/mozilla virus on net (though i wasn't infected by this). But i had a little problem in my PC. I trust on sysinternals, believe me guys if you download process explorer from there then you can fight with any virus with applying some logic. My process explorer was showing a dirty entry of svchost.exe, here i ll tell what does this dirty entry mean. It means this svchost.exe was not generic, i.e. doesn't have a Microsoft signature. So then process explorer told me the path of this svchost.exe. I traced the path and found that this file was stored in

c:\Documents and Settings\Administrator\Local Settings\Temp\MsData\

after unhiding i found that there are some more files like microsoftpowerpoint.exe etc. which were the root cause for the problem.

so .. here you go..

  1. Kill the process svchost.exe(not the generic one) with the help of task manager, or the same with the help of process explorer. http://www.microsoft.com/technet/sysinternals/SystemInformation/ProcessExplorer.mspx
  2. Delete folder c:\Documents and Settings\Administrator\Local Settings\Temp\MsData
  3. Delete file c:\windows\system32\Winlogons.exe (remeber its winlogons.exe, not winlogon.exe)
  4. Reboot your system, and you are done.
Please comment on the post...

thanks and regards,

Surya Prakash Garg