Thursday, March 22, 2018

AV Notes

Has list of ransomware decryption tools
https://www.tomsguide.com/us/ransomware-what-to-do-next,news-25107.html

Has list of one user's suggestions
https://community.spiceworks.com/topic/2120006-using-free-antivirus-on-a-corporate-network?from_forum=216

   Nuke and Reimage, or..

1.  Corporate anti-virus all the time.  Scan with company AV.

2.  Clear all Temp internet cookies/files.

3.  Scan with Hitman pro and pay small cost for a license if needed.  No reboot

4.  Scan with Malwarebytes.  No reboot

5.  Check and clean the MSCONFIG if needed, no reboot

6.  Run TDSS killer to look for root kits.

7.  Check for rogue start-up entries and uncheck as needed

8.  Reboot - then run Hitman again to verify no further infection post reboot.

9.  Any additional issues results in a reformat of the PC (with Windows 10 it's super easy to go back to factory defaults)

- -
Avast is killed by Windows 10 1709 Creator Upgrade
https://community.spiceworks.com/topic/2120137-windows-10-spring-creators-update-is-incompatible-with-avast-endpoint-protect?from_forum=216

- - - - - -
Panda Dome discussion 12/2017
https://malwaretips.com/threads/panda-18-04-new-design-and-name-panda-dome.78121/

quite a graph of AVs ability to detect
https://malwaretips.com/attachments/capture_12152017_181000-jpg.176076/
- - - -

Wow, haha
"But we both know that its better to get $80 out of someone for 30min-1 hour of work then a $135 for a fresh reinstall which takes about 3-4 hours depending on how easy it is to find drivers and install programs."
https://lifehacker.com/5527475/thwart-antivirus-crippling-malware-by-changing-file-extensions

Sunday, March 18, 2018

Intel Storage Raid Manager - In Case.....

In case...the motherboard gets reset (to/from AHCI mode) and the drives aren't "really" failed...but the configuration may be incorrect.

See
http://blog.quindorian.org/2013/07/repair-incorrectly-reported.html/

Tuesday, March 13, 2018

Backup Image Tools

See

Aside from Acronis
consider....

https://www.provendatarecovery.com/blog/10-free-disk-imaging-software-tools-for-harddrive/
    AOMEI
    Paragon
    Drive Image XML
    PING
    Clonezilla
    Seagate
    Pro
    disk-image.com
    O&O

Macrium
https://www.ghacks.net/2017/09/29/backup-tool-macrium-reflect-7-free-edition-released/

Monday, March 12, 2018

Excel Tips

See
https://www.reddit.com/r/AskReddit/comments/83wbqh/what_are_some_useful_excel_formulas_to_know/

IndexMatch
INDEX(MATCH()) is the best for indexing items. More versatile than H- or Vlookup.
Concat is fantastic to put data into strings for overview of your work.
=CONCAT("There are ";F3;" uncategorised expenses") for instance.


..
A SUM() won't work if you apply a filter. You need to use SUBTOTAL() instead
E.g. =SUBTOTAL(9, A1:A50)
sums values visible in the filter in column A between rows 1 and 50.
(There are a bunch of Subtotal functions. #9 is Sum)



see also
https://excelmacromastery.com

Wednesday, March 7, 2018

Hard Dive Filling Up With Many Files in Windows\Temp?

Do you have cab files of 130M and zero size filesin between?

It seems,Windows wasn't able to zip (makecab.exe) one of the .log files.
The solution was:
   in windows\Logs\CBS folder delete the oldest .log file (you can also delete them all)
   in windows\temp folder delete every cab_xxxx
in the following regeneration process, the remaining (CBS) logs were zipped correctly, and windows\temp was left clean


Reference, see Skyfx's answer
https://answers.microsoft.com/en-us/windows/forum/windows_7-files/cabxxxx-files-found-in-windowstemp-folder/2e86137e-7e6b-4cb7-9a3c-4ee73f665742

Windows 7 as Server

Error 2017
Source: srv
 Event ID: 2017
 Level: Error
 The server was unable to allocate from the system nonpaged pool because the server reached the configured limit for nonpaged pool allocations.


Set the following registry key to ’1′:

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\LargeSystemCache

Set the following registry key to ’3′:
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\Size


Reference
https://tips.paddyonline.net/registry-hacks/windows-tips-tricks/registry-hacks/windows-7-nonpaged-pool-srv-error-2017