Showing posts with label Window`s Hacking. Show all posts
Showing posts with label Window`s Hacking. Show all posts

15 August, 2011


To Lock a folder in windows XP


To Lock a folder in windows XP without any software. Follow the steps Below.
  1. Make a Folder in C drive rename it as "abc" without quotes.
  2. Now open Command Prompt from Start Menu.
  3. Type "attrib +s +h C:\abc" without quotes and press enter.
  4. This command will Make your folder invisble and it can not be seen even in hidden files and folders
  5. To make it visible again type "attrib -s -h C:\abc"
  6. You can lock any other folder also by changing the location C:\abc to address of your folder.

# To boost performance of your PC or to increase RAM virtually,


  • To boost performance of your PC or to increase RAM virtually,
    Right click on My Computer Icon on Desktop
    >> Go to Properties
    >> Go to Advanced
    >> Go to Performance - Settings
    >> Go to Advanced
    >> Go to Virtual Memory - Change
    Keep the initial size same as recommended and maximum size double of it then restart your system.
    It will improve speed of windows and you can play some games which require higher RAM.


  • Minimise all the application

    To Minimise all the application and running windows press the "Windows + M " key together.

    Windows Tricks : Changing Startup and Log-off screens


    Startup Screen

    1. Create a 320x400 bitmap in the root directory and name it LOGO.SYS
    2. You can use LOGOW.SYS file in the Windows directory as a starter
           Logoff Screens
    1. There are many system file that constitutes Lofoff screen.
    2. They are actually bitmaps 320x400 that just have a different extension
    3. The hidden file in the root directory LOGO.SYS is the startup logo.
    4. There are two files in the Windows directory.
    5. LOGOW.SYS is the Wait while Shutting down ... screen.
    6. LOGOS.SYS is the You may now shut-off or Reboot screen.
    7. Make two new image files of your chice in Paint and name it as LOGOW.SYS and LOGOS.SYS and replce the actual windows file by this two.
    8. But make sure they should be of the same size

    Disabling Display of Drives in My Computer :

    1) Disabling Display of Drives in My Computer :
    This is yet another trick you can play on your geek friend. To disable the display of local or networked drives when you click My Computer go to :
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    Now in the right pane create a new DWORD item and name it NoDrives. Now modify it's value and set it to 3FFFFFF (Hexadecimal) Now press F5 to refresh. When you click on My Computer, no drives will be shown. To enable display of drives in My Computer, simply delete this DWORD item. It's .reg file is as follows:
    REGEDIT4
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoDrives"=dword:03ffffff

    Pop a banner each time Windows Boots :

    2) Pop a banner each time Windows Boots :
    To pop a banner which can contain any message you want to display just before a user is going to log on, go to the key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
    Now create a new string Value in the right pane named LegalNoticeCaption and enter the value that you want to see in the Menu Bar. Now create yet another new string value and name it: LegalNoticeText. Modify it and insert the message you want to display each time Windows boots. This can be effectively used to display the company's private policy each time the user logs on to his NT box. It's .reg file would be:
    REGEDIT4
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon]
    "LegalNoticeCaption"="Caption here."

    Secure your Desktop Icons and Settings

    3) Secure your Desktop Icons and Settings :
    You can save your desktop settings and secure it from your nerdy friend by playing with the registry. Simply launch the Registry Editor go to:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    In the right pane create a new DWORD Value named NoSaveSettings and modify it's value to 1. Refresh and restart for the settings to get saved

    Cleaning Recent Docs Menu and the RUN MRU :

    5) Cleaning Recent Docs Menu and the RUN MRU :
    The Recent Docs menu can be easily disabled by editing the Registry. To do this go to the following Key:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    Now in the right pane, create a new DWORD value by the name: NoRecentDocsMenu and set it's value to 1. Restart Explorer to save the changes.
    You can also clear the RUN MRU history. All the listings are stored in the key:
    HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
    You can delete individual listings or the entire listing. To delete History of Find listings go to:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU and delete

    Other Similar Useful Tricks :

    Launch Regedit and go to the following Registry Key:
    HKEY_CURRENT_USER/Software/Microsoft/CurrentVersion/Policies
    Under this key, there will definitely be a key named explorer. Now under this explorer key we can create new DWORD values and modify it's value to 1 in order to impose the restriction. If you want to remove the Restriction, then you can simply delete the respective DWORD values or instead change their values to 0. The following is a list of DWORD values that can be created under the Explorer Key-:
    NoDeletePrinter: Disables Deletion of already installed Printers
    NoAddPrinter: Disables Addition of new Printers
    NoRun : Disables or hides the Run Command
    NoSetFolders: Removes Folders from the Settings option on Start Menu (Control Panel, Printers, Taskbar)
    NoSetTaskbar: Removes Taskbar system folder from the Settings option on Start Menu
    NoFind: Removes the Find Tool (Start >Find)
    NoDrives: Hides and does not display any Drives in My Computer
    NoNetHood: Hides or removes the Network Neighborhood icon from the desktop
    NoDesktop: Hides all items including, file, folders and system folders from the Desktop
    NoClose: Disables Shutdown and prevents the user from normally shutting down Windows.
    NoSaveSettings: Means to say, 'Don't save settings on exit'
    DisableRegistryTools: Disable Registry Editing Tools (If you disable this option, the Windows Registry Editor(regedit.exe) too will not work.)
    NoRecentDocsHistory: Removes Recent Document system folder from the Start Menu (IE 4 and above)
    ClearRecentDocsOnExit: Clears the Recent Documents system folder on Exit.
    Nolnternetlcon: Removes the Internet (system folder) icon from the Desktop
    Under the same key:HKEY_CURRENT_USER/Software/Microsoft/CurrentVersion/Policies you can create new subkeys other than the already existing Explorer key. Now create a new key and name it System. Under this new key, system we can create the following new DWORD values(1 for enabling the particular option and 0 for disabling the particular option):
    • NODispCPL: Hides Control Panel
    • NoDispBackgroundPage: Hides Background page.
    • NoDispScrsavPage: Hides Screen Saver Page
    • NoDispAppearancePage: Hides Appearance Page
    • NoDispSettingsPage: Hides Settings Page
    • NoSecCPL: Disables Password Control Panel
    • NoPwdPage: Hides Password Change Page
    • NoAdminPaqe: Hides Remote Administration Page
    • NoProfilePage: Hides User Profiles Page
    • NoDevMgrPage: Hides Device Manager Page
    • NoConfigPage: Hides Hardware Profiles Page
    • NoFileSysPage: Hides File System Button
    • NoVirtMemPage: Hides Virtual Memory Button
    Similarly, if we create a new subkey named WinOldApp, we can add the following DWORD values under it(1 for enabling the particular option and 0 for disabling the particular option): Disabled: Disable MS-DOS Prompt
    NoRealMode: Disable Single-Mode MS-DOS.

    How to recover a Boot Record in Windows?

    The boot record stores the first bits of software executed once the system BIOS hands control of the computer over to software.
    The boot record stores instructions used to start Windows XP. Each drive partition can store a boot record.
    Occassionally a boot record will be damaged and need to be repaired. This damage may be caused by a hardware error, software error, user error, or even malware such as a boot sector virus.

    How to Recover a Boot Record in XP:

    To recover the boot record in XP, use the fixboot command in the Recovery Console. The fixboot command will write a new boot sector to the partition.
    Steps : 
    1. Boot with the XP installation CD.
    2. When prompted, press R to repair a Windows XP installation.
    3. If repairing a host with multiple operating systems, select the appropriate one (XP) from the menu. If you have only one operating system, enter 1 to select it.
    4. Enter the administrator password if prompted.
    5. To fix the MBR, use the following command:
      fixmbr
      This assumes that your installation is on the C:\ drive. You will be presented with several scary warning lines the reading of which will make you want to say no. Microsoft is exceptionally vague regarding the conditions under which fixmbr can cause problems although they are clear about the consequences (losing all data on the hard drive), so use this at your own risk. Type Y and ENTER to fix the MBR.

      Type exit to leave the recovery console and reboot.

    Using Driver Verifier to identify issues with Windows drivers for advanced users


    SUMMARY

    Driver Verifier is included in Windows 7, Windows Server 2008 R2, Windows Vista, Windows Server 2008, Windows 2000, Windows XP, and Windows Server 2003 to promote stability and reliability; you can use this tool to troubleshoot driver issues. Windows kernel-mode components can cause system corruption or system failures as a result of an improperly written driver, such as an earlier version of a Windows Driver Model (WDM) driver. This article describes how to use Driver Verifier to isolate and troubleshoot a driver in the system.

    MORE INFORMATION

    This article discusses the following topics:
    • Driver Verifier Capabilities
    • I/O Verifier
    • Driver Verifier Requirements
    • Enabling Driver Verifier
    • Debugging Driver Verifier Violations
    • Driver Verifier and Graphics Drivers
    • Driver Verifier Manager (Verifier.exe)
    • Global Counters
    • Pool Tracking
    • Settings
    • Volatile Settings
    • Command-Line Interface
    • Additional Information for Driver Developers

    Driver Verifier Capabilities

    You can use Driver Verifier by running Verifier.exe and then restarting your computer. You do not need to make any other changes to begin analyzing drivers in the system.

    Driver Verifier provides the following capabilities.


    Pool Allocations

    Attempt to allocate all of a driver's pool allocations from special pool. Instead of sharing pool allocations with the rest of the system, this driver's allocations are isolated and bound by No Access permissions. This capability determines if a driver allocates more than its share of the pool and therefore causing corruption and system instability as a result. When you enable this capability and the target computer has enough physical and virtual memory, all of the driver's allocations are automatically redirected into special pool.

    Provide Extreme Memory Pressure

    Extreme memory pressure can be provided on a specific driver without affecting other drivers (regardless of system memory size). You can do this by instructing memory management to invalidate all of the driver's pageable code and data, as well as system paged pool, code, and data. This lets you detect a driver that incorrectly holds spin locks or raises IRQL and then gains access to paged code or data. You can use Extreme Memory Pressure to detect intermittent problems and isolate the cause.

    Parameter Validation

    All spin lock, IRQL, and pool allocation calls the driver makes receive automatic parameter validation. This means that checks are made to ensure the following things:
    • A raised IRQL really is a raised IRQL (the current IRQL is less than the target IRQL).
    • A lower IRQL really is a lower IRQL.
    • Double release of a spin lock.
    • Spin lock acquisitions/releases are made at the proper IRQL.
    • Paged pool allocations/frees are made at the correct IRQL (APC_LEVEL or below).
    • Non-paged pool allocations/frees are made at the correct IRQL (DISPATCH_LEVEL or below).
    • No random (uninitialized) values are specified to these application programming interfaces (APIs).

    Pool Allocation Injection Failures

    Pool allocations that are not marked MUST_SUCCEED by the driver can be randomly failed to ensure the driver can correctly handle a low memory situation.

    Pool Being Freed

    All pool being freed is examined to ensure no pending timers are inside the pool allocation as these cases would cause extremely hard to track down system crashes.

    Pool Leakage Detection

    All of the driver's pool allocations are automatically tracked. At driver unload time, a bug check occurs if any of the allocations are not freed. You can then use the!verifier 3 kernel-debugger command to show all the allocations that are not freed. You can also use this command before unloading to view the outstanding allocations the driver has at any point in time.

    Driver Unload Checking

    Driver unload checking is performed to catch drivers that unload and do not clean up resources used (which increases the possibility of a system bug check shortly after the driver unloads). Resources that the driver may not delete include look-aside lists, pending deferred procedure calls (DPCs), worker threads, queues, timers, and other resources.

    I/O Verifier

    If you turn on the I/O Verifier flag using the Verifier tool or the VerifyDriverLevel registry key (for more information, refer to the "Enabling Driver Verification" section of this article), some I/O Manager verifications are turned on. This includes:
    • All IRPS allocated through IoAllocateIrp are allocated from special pool.
    • Checks are made in IoCallDriver, IoCompleteRequest, and IoFreeIrp to catch driver error messages.
    • All I/O Verifier failures bug check with the code DRIVER_VERIFIER_IOMANAGER_VIOLATION (0xC9).

    Driver Verifier Requirements

    The only requirement is that you must install Windows 7, Windows Server 2008 R2, Windows Vista, Windows Server 2008, Windows 2000, Windows XP, or Windows Server 2003. You can enable Driver Verifier on both retail and checked versions of Windows. See Microsoft Knowledge Base article 251233 for information about what to consider before you enable Driver Verifier Manager on production servers. If Norton Antivirus is installed, do not enable Driver Verifier's Deadlock Detection because of the recommendations in Microsoft Knowledge Base article 325672.

    Enabling Driver Verifier

    You can enable Driver Verifier by using Verifier.exe. Verifier.exe is included with every copy of Windows and automatically installed into the System32 folder. Verifier.exe has both command-line and graphical user interface (GUI) interfaces, so you can specify drivers and appropriate levels of verification. You can also see Driver Verifier statistics in real time. For additional information, refer to the "Driver Verifier Manager" section of this article.

    Debugging Driver Verifier Violations

    Both the !verifier command in the kernel debugger and the Verifier.exe tool show the current Driver Verifier configuration and statistics in real time.

    All Driver Verifier violations result in bug checks, the most common ones (although not necessarily all of them) are:
    • IRQL_NOT_LESS_OR_EQUAL 0xA
    • PAGE_FAULT_IN_NONPAGED_AREA 0x50
    • PAGE_FAULT_IN_NONPAGED_AREA 0x50
    • ATTEMPTED_WRITE_TO_READONLY_MEMORY 0xBE
    • SPECIAL_POOL_DETECTED_MEMORY_CORRUPTION 0xC1
    • DRIVER_VERIFIER_DETECTED_VIOLATION 0xC4
    • DRIVER_CAUGHT_MODIFYING_FREED_POOL 0xC6
    • TIMER_OR_DPC_INVALID 0xC7
    • DRIVER_VERIFIER_IOMANAGER_VIOLATION 0xC9

    Driver Verifier and Graphics Drivers

    Windows kernel-mode graphics drivers (such as printer and display driver DLLs) are restricted from calling the pool entry point directly. Rather, pool allocations are performed indirectly using graphics device driver interface (DDI) callbacks to Win32k.sys. For example, EngAllocMem is the callback that a graphics driver calls to explicitly allocate pool memory. Also, other specialized callbacks such as EngCreatePalette and EngCreateBitmap return pool memory.

    To provide the same sort of automated testing for the graphics drivers, support for some of the Driver Verifier functions is incorporated into Win32k.sys. However, because graphics drivers are more restricted than other kernel-mode drivers, they require only a subset of the Driver Verifier functionality. Specifically, IRQL checking and I/O verification are not needed. The other functionality, namely using special pool, random failure of pool allocations, and pool tracking, are supported to varying degrees in the different graphics DDI callbacks.

    Random failures are supported for the following graphics DDI callback functions:
    • EngAllocMem
    • EngAllocUserMem
    • EngCreateBitmap
    • EngCreateDeviceSurface
    • EngCreateDeviceBitmap
    • EngCreatePalette
    • EngCreateClip
    • EngCreatePath
    • EngCreateWnd
    • EngCreateDriverObj
    • BRUSHOBJ_pvAllocRbrush
    • CLIPOBJ_ppoGetPath
    In addition, the use of special pool and pool tracking is supported for EngAllocMem.

    Enabling Driver Verifier for the graphics drivers is identical to the other drivers (refer to the "Enabling Driver Verifier" section of this article for additional information). Unsupported flags such as IRQL checking are ignored. In addition, you can use the !gdikdx.verifier kernel-debugger command to examine current Driver Verifier state and pool traces for graphics drivers.

    NOTE: You should only use the random allocation failure setting for robustness testing. Use of this setting may cause rendering error messages, so you should not use this setting with verification tests to check the correctness of the graphics driver's implementation (for example, by comparing the graphics driver output to a reference image).

    Driver Verifier Manager (Verifier.exe)

    The Driver Verifier Manager tool (Verifier.exe) is the preferred way to create and modify Driver Verifier settings and to gather statistics from Driver Verifier. Verifier.exe is located in the %WinDir%\System32 folder for every Windows installation.

    Driver Status

    The Driver Status property page gives you an image of the current status of Driver Verifier. You can see what drivers the verifier detects. The status can be one of the following:
    • Loaded: The driver is currently loaded and verified.
    • Unloaded: The driver is not currently loaded but it was loaded at least once since you restarted the computer.
    • Never Loaded: The driver was never loaded. This status can indicate that the driver's image file is corrupted or that you specified a driver name that is missing from the system.
    You can click the list header to sort the list by driver names or status. In the upper-right area of the dialog box, you can view the current types of the verification that are in effect. The status of the drivers is updated automatically if you do not switch to manual refresh mode. You can modify the refresh rate using the radio buttons in the lower-left area of the dialog box. You can also force an update of the status by clicking Update Now.

    If you enable the Special Pool flag and less than 95 percent of the pool allocations went to the special pool, a warning message is displayed on this page. This means that you need to select a smaller set of drivers to verify or add more physical memory to the computer to obtain better coverage of the pool allocations verification.


    Global Counters

    The Global Counters property page shows the current value of some counters maintained by Driver Verifier. A zero value for a counter can indicate that the associated Driver Verifier flag is not enabled. For example, a value of 0 for the Other/Faults counter indicates that the low resource simulation flag is not enabled. You can monitor the activity of the verifier because the values of the counters are updated automatically (by default). You can change the refresh rate, switch to manual refresh, or force a refresh using the group of controls in the lower-left area of the dialog box.

    Pool Tracking

    This property page shows more statistics gathered from Driver Verifier. All of the counters shown on this page are related to the Pool Tracking flag of the verifier. Most of them are per-driver counters (for example, current allocations, current allocated bytes, and so on). This means you must select a driver name from the top combination box to view the counters for that specific driver.

    Settings

    You can use this page to create and modify Driver Verifier settings. The settings are saved in the registry and you must restart the computer for the settings to take effect. You can use the list to view the currently installed drivers. Each driver can be in one of the following states:
    • Verify Enabled: The driver is currently verified.
    • Verify Disabled: The driver is currently not verified.
    • Verify Enabled (Reboot Needed): The driver is verified only after the next restart.
    • Verify Disabled (Reboot Needed): The driver is currently verified but is not verified after the next restart.
    You can select one or several drivers from the list and switch the status using the two buttons under the list. You can also right-click a driver name to display the context menu, which lets you perform state toggling.

    In the bottom of the dialog box, you can specify additional drivers (separated by spaces) that you want verified after the next restart. You typically use this edit control when you want to install a new driver that is not already loaded.

    If the radio button group on the top of the list is set to Verify all drivers, the list and the Verify and Don't Verify buttons and the edit control are unavailable. This means that after the next restart, all the drivers in the system are verified.

    You can set the verification type using the check boxes in the upper-right area of the dialog box. You can enable I/O Verification at level 1 or at level 2. Level 2 verification is stronger than level 1.

    You must save any modification to the settings by clicking Apply. There are two more buttons in this page:
    • Preferred Settings: This selects some commonly used settings (with all drivers verified).
    • Reset All: This clears all the Driver Verifier settings so that no drivers are verified.
    After you click Apply, you must restart the computer for the changes to take effect.

    Volatile Settings

    You can use this property page to change the Driver Verifier flags immediately. You can only toggle the state of some of the Driver Verifier flags and you cannot change the list of the drivers that are being verified. After you change the status of some check boxes, you must click Apply for the changes to take effect. The changes take effect immediately and they last until you make additional changes or until you restart the computer.

    The Command-Line Interface

    You can also run Verifier.exe from a command line (for more information, typeverifier.exe /? at a command prompt). The following list shows the most commonly used command line flags:
    • verifier.exe /flags value [/iolevel 2]
      Specifies a decimal value of the Driver Verifier flags and possibly the level for the I/O verification (for a list of available flags, type verifier.exe /? at a command prompt or refer to the "Enabling Driver Verifier" section of this article).

      Replace the value parameter with one of the following verification bit values:
      0 - Special pool checking
      1 - Force IRQL checking
      2 - Low resources simulation
      3 - Pool tracking
      4 - I/O verification
      5 - Deadlock Detection
      6 - Enhanced I/O verification
      7 - DMA verification
      For example, type the following command:
      c:\verifier /flags 3 /iolevel 2
      NOTE: The default I/O verification level is 1. The value is ignored if the I/O verification bit is not set in flags.
    • verifier.exe /all
      Verifies all the drivers in the system.
    • verifier.exe /volatile /flags value
      Changes verifier flags immediately.
    • verifier.exe /reset
      Erases all current Driver Verifier settings.
    • verifier /query
      Dump the current Driver Verifier status and counters to the standard output.
    • verifier.exe /log LOG_FILE_NAME [/interval seconds]
      Logs the Driver Verifier status and counters to a log file (where secondsis the period of time you specify).

    Additional Information for Driver Developers

    The sections that follow describe additional details about driver verifier settings that may be of interest to driver developers. These settings are not generally required by IT professionals.
    Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
    322756  How to back up and restore the registry in Windows

    To enable Driver Verifier by editing the registry, follow these steps:
    1. Start Registry Editor (Regedt32).
    2. Locate the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\VerifyDrivers
    3. Edit the REG_SZ key.
    Set the REG_SZ key to the case-insensitive names of the drivers that you want to test. You can specify multiple drivers, but only use one driver. By doing so, you can make sure that available system resources are not prematurely exhausted. Premature exhaustion of resources does not cause any system reliability problems, but it can cause some driver checking to be bypassed.

    The following list shows examples of values for the REG_SZ key:
    • Ntfs.sys
    • Win32k.sys ftdisk.sys
    • *.sys
    You can specify the level of driver verification in the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\VerifyDriverLevel The following list shows the bit-field values for this key. You can freely combine these values:
    • 0x01: Tries to satisfy all allocations from special pool.
    • 0x02: Applies memory pressure to this driver to validate IRQL usage about accessing pageable code and data.
    • 0x04: Randomly fails various pool allocation requests. This action is only performed after the system has started and reached a point where the problem can be treated as reasonable situations that must be handled.
    • 0x08: Enable pool allocation tracking. Every allocation must be freed before the driver unloads or the system performs a bug check.
    • 0x10: Enable the I/O verifier.
    NOTE: The default value is 3 if the key does not exist, or if you do not specify a level of driver verification. The default value is 0x1B if you use the Preferred settings in the Verifier Utility. To track memory leaks, try a value of 0xB. This value is most easily obtained by clicking to select the preferred setting check box and clicking to clear the I/O verification check box.