It's a long story as to why, but I needed to use the £ symbol in my web.config
On my local windows 7 IIS setup, it was happy to just use £. On our windows 2003 staging server, the same was true. But under Windows 2008, IIS threw it's teddy out of the pram and just errored saying invalid xml file.
A few places suggested using & pound; instead, but this did not work.
What did work though was using the unicode value of & # 163;
Wednesday, 5 June 2013
Tuesday, 30 October 2012
Row not found or changed
Today whilst working with what had been a stable piece of LINQ for some weeks, I had to use the data connection in a separate application. I thought this would be straightforward as I'd been using it in its current application for quite some time.
Upon trying to update a row, to merely save a string value, I received the "Row not found or changed" error.
Doing the usual Googling and finding many many people complaining about this on StackOverflow, I tried all the suggestions of changing the datefield in the table to never complain about it updating, checking that no count wasn't enabled for the database, re-dragging the table into the DBML to update it etc, but nothing seemed to work.
In final desperation, I just happened to be sat with SQL Management Studio open and that particular table expanded so I could see the fields, and also the dbml open and the what appeared to in the end be the offending field, properties open. I noticed that even though I had re-dragged the table to the DBML that the specification for nullable was different. On the server null was valid, but in the DBML it was Varchar(500) NOT NULL.
So there we have it. The row couldn't update because LINQ interpreted the definition it had to be different to the database.
And the strangest thing? I was trying to update it so that it wasn't null, and in the database there is a default value for it.
If you've come to brick wall with this, I hope this helps you too!
Upon trying to update a row, to merely save a string value, I received the "Row not found or changed" error.
Doing the usual Googling and finding many many people complaining about this on StackOverflow, I tried all the suggestions of changing the datefield in the table to never complain about it updating, checking that no count wasn't enabled for the database, re-dragging the table into the DBML to update it etc, but nothing seemed to work.
In final desperation, I just happened to be sat with SQL Management Studio open and that particular table expanded so I could see the fields, and also the dbml open and the what appeared to in the end be the offending field, properties open. I noticed that even though I had re-dragged the table to the DBML that the specification for nullable was different. On the server null was valid, but in the DBML it was Varchar(500) NOT NULL.
So there we have it. The row couldn't update because LINQ interpreted the definition it had to be different to the database.
And the strangest thing? I was trying to update it so that it wasn't null, and in the database there is a default value for it.
If you've come to brick wall with this, I hope this helps you too!
Thursday, 22 March 2012
ASP DataPager double click to move page
I have only just got around to using the .NET 4.0 DataPager control, and whilst impressed at the simplicity of setting it up, I was annoyed with two features:
1) You have to bind it to a ListView, it does not work with a Repeater control which is a little strange as exactly what I was achieving in the repeater I can do with no code change to get it to work in the ListView
2) When you want to page, say from page 1 to page 2 of the results, you have to double click the "next" button twice to move forward.
Nothing I can do about 1) above, but as for 2), just ensure that the listview it is being re-bound during the pagination by adding the OnPagePropertiesChanged attribute to the ListViews markup, e.g:
and in the code behind, bind on the event
1) You have to bind it to a ListView, it does not work with a Repeater control which is a little strange as exactly what I was achieving in the repeater I can do with no code change to get it to work in the ListView
2) When you want to page, say from page 1 to page 2 of the results, you have to double click the "next" button twice to move forward.
Nothing I can do about 1) above, but as for 2), just ensure that the listview it is being re-bound during the pagination by adding the OnPagePropertiesChanged attribute to the ListViews markup, e.g:
OnPagePropertiesChanged="lstSearchResult_OnPagePropertiesChanged"and in the code behind, bind on the event
protected void lstSearchResult_OnPagePropertiesChanged(object sender, EventArgs e)
{
lstSearchResult.DataBind();
}
Tuesday, 13 March 2012
Jquery ajax call to WCF stops working when upgrading to jquery 1.7.1
This had me puzzled for ages. When upgrading the version of jquery we use from 1.5 to 1.7.1 so that we could use Bootstrap popovers, any calls to our WCF .NET service would fail with a blank error message returned.
What I found was that within out Ajax call we had set:
jsonp: "callback", dataType: "json"
In 1.5 this worked fine, however in 1.7.1 it had noticed that the response type was supposed to be jsonp (JSON with padding) and thus bombing out with a mismatch.
Changing this to the correct format of:
jsonp: "callback", dataType: "jsonp"
Fixed the problem.
What I found was that within out Ajax call we had set:
jsonp: "callback", dataType: "json"
In 1.5 this worked fine, however in 1.7.1 it had noticed that the response type was supposed to be jsonp (JSON with padding) and thus bombing out with a mismatch.
Changing this to the correct format of:
jsonp: "callback", dataType: "jsonp"
Fixed the problem.
Tuesday, 22 November 2011
Wordpress php.ini settings to load external url
A friend of mine had an issue with a vanilla wordpress install that he had that was using a premium theme.
Upon loading the theme, the page showed many errors relating to servers security setting would not allow the loading of data from external urls.
The information we were given was to set the php.ini in the directory of the calling page, so that the setting could be overridden - so we did, no change.
The solution is that the php.ini file in the wp-admin folder needs setting, not in the calling page, because the calling page in this case is a settings page itself that is being imported into the wp-admin/index.php file.
The settings in php.ini are then:
allow_url_fopen = 1
allow_url_include = 1
Upon loading the theme, the page showed many errors relating to servers security setting would not allow the loading of data from external urls.
The information we were given was to set the php.ini in the directory of the calling page, so that the setting could be overridden - so we did, no change.
The solution is that the php.ini file in the wp-admin folder needs setting, not in the calling page, because the calling page in this case is a settings page itself that is being imported into the wp-admin/index.php file.
The settings in php.ini are then:
allow_url_fopen = 1
allow_url_include = 1
Wednesday, 4 May 2011
PHP .htaccess redirect
I have been helping a neighbour of mine who is an Optician in Spalding, and he was trying to make sure that when people were searching for "Opticians in Spalding" they would make sure that the old pages on his website that were already listed in Google, would still link through to his new site that he's spent ages on.
Being a windows server man, I know how to do this in IIS, but as his new website is hosted on a linux server, it needed to be compatible with that. So anyway, I found out that you can do 301 redirects on Apache using a .htaccess file.
In this case, it was real simple, create a blank file called .htaccess and the place an entry for each for each file that needs redirecting, i.e:
Redirect 301 /HTML/Consultations.htm http://www.molsom.co.uk/eye-tests.htm
Excellent, and I now know that visitors to my local Optician in Spalding will still get there from any old bookmarks!
Tuesday, 1 March 2011
EventType clr20r3 system.io.filenotfoundexception
I had this error today when trying to launch a .net application on a remote host machine. The file io exception threw me somewhat as it made me think that the issue was with loading a config file.
In fact the culprit of this error was not the config files, it was in fact missing dlls that are normally referenced from the GAC.
As I had no idea which dll it didn't know about, I just set each dlls reference to say copy to local = true, and then deployed the whole contents.
In fact the culprit of this error was not the config files, it was in fact missing dlls that are normally referenced from the GAC.
As I had no idea which dll it didn't know about, I just set each dlls reference to say copy to local = true, and then deployed the whole contents.
Wednesday, 22 December 2010
List.Sort() alphabetically
I was faced with the challenge today of sorting a list of objects, where one of the properties was a string. My objects were lists of keywords, and I wanted to sort the keywords alphabetically.
I came across some example of lambda expressions, and found that rather than having to write complicated sort methods for my class, I could just do the following:
Awesome, works a treat!
I came across some example of lambda expressions, and found that rather than having to write complicated sort methods for my class, I could just do the following:
keywords.Sort((a,b) => String.Compare(a.keyword, b.keyword)):
Awesome, works a treat!
Wednesday, 24 November 2010
SQL Server could not spawn FRunCM thread. Check the SQL Server error log and the Windows event logs for information about possible related problems.
I encountered this error this morning when my SQL Server instance wouldn't start after I made some connection changes yesterday. I had to make the changes because a needed an ODBC connection, and that would only seem to work if I configured it to use named pipes.
After checking the logs, I received the error "SQL Server could not spawn FRunCM thread. Check the SQL Server error log and the Windows event logs for information about possible related problems.".
So, I went back to undo each change I had made, and noticed that the last change I made was to enable VIA as a protocol for my SQL Server instance. Disabled that, and hey presto, SQL Server now starts fine.
The strange thing is that enabling VIA in my SQL Express instance didn't seem to cause the same issue on that server though.
After checking the logs, I received the error "SQL Server could not spawn FRunCM thread. Check the SQL Server error log and the Windows event logs for information about possible related problems.".
So, I went back to undo each change I had made, and noticed that the last change I made was to enable VIA as a protocol for my SQL Server instance. Disabled that, and hey presto, SQL Server now starts fine.
The strange thing is that enabling VIA in my SQL Express instance didn't seem to cause the same issue on that server though.
Tuesday, 27 April 2010
asp.net checkbox modalpopupextender checkbox doesn't check or uncheck
There is an apparent bug in asp.net that when you have a checkbox inside a panel that is acting as a modal popup with the modalpopupextender, that when you try to check or uncheck it, it doesn't work!
I found the following thread, and it seems that quite a few people have had this very same problem.
From reading many posts, it seems that this happens if you do not set the TargetControlID property of the extender correctly.
However, this becomes an issue if you have multiple links, all that show the same extender. To get round this, you can simply create a fake button:
And then in your modal extender, set TargetControlID="btnFakeButton". With your links / buttons to active this, simply in the code behind for the event for each link / button, do mdlExample.Show() to display the modal.
I found the following thread, and it seems that quite a few people have had this very same problem.
From reading many posts, it seems that this happens if you do not set the TargetControlID property of the extender correctly.
However, this becomes an issue if you have multiple links, all that show the same extender. To get round this, you can simply create a fake button:
And then in your modal extender, set TargetControlID="btnFakeButton". With your links / buttons to active this, simply in the code behind for the event for each link / button, do mdlExample.Show() to display the modal.
asp.net button not posting back
I have a modalpopup extender attached to a panel, inside which resides two asp.net buttons. Each of these had the normal "Onclick" attribute assigned to them. However, when they were clicked, no postback was occuring.
From some reading around, it appears that this is by design, and that the buttons are there for this to be closed.
So how do you get round this?
You can attach a javscript client side event that mimmicks the behaviour of what happens with asp anyway, by forcing the postback to take place.
Firstly, in the head of your page, define a function that ensures that the page is valid first, and then causes the postback to take place (the validation part is crucial for this to work.
function doPostback(sender,e)
{
if(Page_IsValid)
{
__doPostback(sender,e);
}
else
{
return false;
}
}
Now in your code behind, tell your buttons to call this:
btnSaveUserDetails.OnClientClick = "javascript:return doPostback('" + btnSaveUserDetails.UniqueID + "');";
It is important here that the uniqueID is used, as this ensures that any controls that are nested pass the right details to the postback function.
And ta da, they now work!
From some reading around, it appears that this is by design, and that the buttons are there for this to be closed.
So how do you get round this?
You can attach a javscript client side event that mimmicks the behaviour of what happens with asp anyway, by forcing the postback to take place.
Firstly, in the head of your page, define a function that ensures that the page is valid first, and then causes the postback to take place (the validation part is crucial for this to work.
function doPostback(sender,e)
{
if(Page_IsValid)
{
__doPostback(sender,e);
}
else
{
return false;
}
}
Now in your code behind, tell your buttons to call this:
btnSaveUserDetails.OnClientClick = "javascript:return doPostback('" + btnSaveUserDetails.UniqueID + "');";
It is important here that the uniqueID is used, as this ensures that any controls that are nested pass the right details to the postback function.
And ta da, they now work!
Monday, 26 April 2010
modalpopupextender event fires but does not show
I lost half a day of my life to this silly mistake today.
I had on my page a panel, with a modal popupextender. When I clicked a link that ran a serverside mdlPopup.show() or a client side $('mdlPopup').show(), the events fired, but no modal popup showed.
The reason for this was because I had set the "visible" attribute of my panel to "false", rather than setting the style of it to "display:none"!
Silly....
I had on my page a panel, with a modal popupextender. When I clicked a link that ran a serverside mdlPopup.show() or a client side $('mdlPopup').show(), the events fired, but no modal popup showed.
The reason for this was because I had set the "visible" attribute of my panel to "false", rather than setting the style of it to "display:none"!
Silly....
Tuesday, 30 March 2010
The process cannot access the file because it is being used by another process. (Exception from HRESULT: 0x80070020)
When starting IIS 7 under Vista or Windows 7, you receive the error from the IIS Manager saying "The process cannot access the file because it is being used by another process. (Exception from HRESULT: 0x80070020)"
The reason for this is well documented, and it is because you have another site setup with the same binding - in english, this means you have two sites setup that are configured to use the same port (probably 80).
In my circumstances, this was confusing because I had only one IIS instance and this was bound to port 80, but wouldn't start.
So, to find out what was conflicting, I went to the command prompt and typed:
NETSTAT -ano
This showed an entry of address 0.0.0.0 using port 80 up!
This also showed the process ID of 4400, so I looked in task manager and found that this was Skype.exe
After digging through the advanced settings in Skype, it appears that by default, Skype decides to listen on ports 80 and 443 for incoming connections (probably to appeas firewalls), so unticking this allowed my IIS to start.
Useful to find out, but it took a while!
The reason for this is well documented, and it is because you have another site setup with the same binding - in english, this means you have two sites setup that are configured to use the same port (probably 80).
In my circumstances, this was confusing because I had only one IIS instance and this was bound to port 80, but wouldn't start.
So, to find out what was conflicting, I went to the command prompt and typed:
NETSTAT -ano
This showed an entry of address 0.0.0.0 using port 80 up!
This also showed the process ID of 4400, so I looked in task manager and found that this was Skype.exe
After digging through the advanced settings in Skype, it appears that by default, Skype decides to listen on ports 80 and 443 for incoming connections (probably to appeas firewalls), so unticking this allowed my IIS to start.
Useful to find out, but it took a while!
Tuesday, 5 January 2010
ie don't print filename
I needed to convert a webpage into a pdf today, and using PDFCreator, this is normally a doddle.
However, whenever I did, it printed the address to the footer of the page.
After much faffing around, I found that under the page setup are "headers" and "footers". If you delete what is in those fields, it stop ie and firefox printing the filenames and page numbers.
However, whenever I did, it printed the address to the footer of the page.
After much faffing around, I found that under the page setup are "headers" and "footers". If you delete what is in those fields, it stop ie and firefox printing the filenames and page numbers.
Monday, 4 January 2010
XPath select attributes containing a string
I needed to find a way to use XPath to select items from within a html document, that would return back to me all UL tags that had an id that contained the word "menu".
To find all the UL's, it is simple enough to do:
However, to select the id of "menu", I then found:
What I ended up with, to find any ULs that contained the word "menu" in the id attribute was:
To find all the UL's, it is simple enough to do:
//UL
However, to select the id of "menu", I then found:
//ul[@id='menu']
What I ended up with, to find any ULs that contained the word "menu" in the id attribute was:
//ul[contains(@id,'menu')]
Thursday, 31 December 2009
Reset AutoIncrement Number in MySQL
To reset your autoincrement number, you can simply run the following SQL:
ALTER TABLE 'table_name' AUTO_INCREMENT = X
Where X is the ID number you want to set the increment start point to, so running
ALTER TABLE 'table_name' AUTO_INCREMENT = 0
resets the ID increment process, and
ALTER TABLE 'table_name' AUTO_INCREMENT = 1023
Would set the start seed to 1023 - sometimes useful for making things looked "used", for example with order systems.
ALTER TABLE 'table_name' AUTO_INCREMENT = X
Where X is the ID number you want to set the increment start point to, so running
ALTER TABLE 'table_name' AUTO_INCREMENT = 0
resets the ID increment process, and
ALTER TABLE 'table_name' AUTO_INCREMENT = 1023
Would set the start seed to 1023 - sometimes useful for making things looked "used", for example with order systems.
Making changes to overall_header.php in phpBB do not take effect
I have been, for some time, trying to make changes to the code in the header file for phpBB. These were not changes for functionality, rather links required to other parts of the site.
Anyway, I had made the changes locally in my local copy of the overall_header.php file of the prosilver theme, but I ftp'd them up, the changes didn't happen.
Frustrated, I spent some time checking what phpBBs admin area said was in the file using the built in editor, and it said my changes were done.
However, what it doesn't say is that once you've made any changes to page files or style documents, you have to run the PURGE ALL feature from the admin control panel to flush out cached copies!
Ran that, and hey presto, fixed.
Anyway, I had made the changes locally in my local copy of the overall_header.php file of the prosilver theme, but I ftp'd them up, the changes didn't happen.
Frustrated, I spent some time checking what phpBBs admin area said was in the file using the built in editor, and it said my changes were done.
However, what it doesn't say is that once you've made any changes to page files or style documents, you have to run the PURGE ALL feature from the admin control panel to flush out cached copies!
Ran that, and hey presto, fixed.
Thursday, 17 December 2009
Person [user@example.com] on behalf of Another Person [user@otherexample.com]
Today I had a query whereby a user was sending emails after outlook had been reinstalled, and was getting this in the emails he was sending, even if it was from his normal account.
The problem seemed to be that the default email being sent from was incorrect, so setting the correct mailbox cured it.
The problem seemed to be that the default email being sent from was incorrect, so setting the correct mailbox cured it.
Tuesday, 17 November 2009
PHP C# WCF Rijndael
I have been working with .NET and webservices for some time, but a colleague of mine has now moved over to using WCF instead of basic webservices.
After many, many problems dealing with simple soap message exchanges, we finally got our WCF service to talk to PHP (using NuSOAP) by setting the encoding to UTF8 and the binding to type basicHttpBinding.
My next problem was why when I was encoding data using Rijndael, was the encoded data returned from WCF not being decoded by mcrypt in PHP correctly.
Eventually, after some digging around, I found a really good article at http://benvanmol.blogspot.com/2009/10/secure-communication-between-net-and.html that summises the following points:
• You need to enable padding in the .net rijndael class. This ensures any blocks are padded with 0’s to fill them. This is done with Padding.Zeros
• Specifically set Cipher Block Chaining in the .Net class.
• The Initialisation Vector (IV) needs to be 16 bytes.
• You need to specifically set the encryption to the MD5 Hash algorithm, and change this to return the 32 character hash.
• Setup base64 encoding either end.
So, from this article by Ben van Mol I was able to produce a class from his code as follows:
In WCF I expose this in my endpoint as:
Note: Both of these are expose on the interface as OperationContracts inside the ServiceContract.
Now, in the PHP world, we need to create a page to call this, so inside a normal html form, we do the following:
And hey presto - finally! a working php to WCF communication in Rijndael!
After many, many problems dealing with simple soap message exchanges, we finally got our WCF service to talk to PHP (using NuSOAP) by setting the encoding to UTF8 and the binding to type basicHttpBinding.
My next problem was why when I was encoding data using Rijndael, was the encoded data returned from WCF not being decoded by mcrypt in PHP correctly.
Eventually, after some digging around, I found a really good article at http://benvanmol.blogspot.com/2009/10/secure-communication-between-net-and.html that summises the following points:
• You need to enable padding in the .net rijndael class. This ensures any blocks are padded with 0’s to fill them. This is done with Padding.Zeros
• Specifically set Cipher Block Chaining in the .Net class.
• The Initialisation Vector (IV) needs to be 16 bytes.
• You need to specifically set the encryption to the MD5 Hash algorithm, and change this to return the 32 character hash.
• Setup base64 encoding either end.
So, from this article by Ben van Mol I was able to produce a class from his code as follows:
public class PhpRijndael
{
System.Security.Cryptography.Rijndael r = null;
public void InitializePhpRijndael(string iv, string key,int blockSize)
{
byte[] keyBytes = Encoding.ASCII.GetBytes(EncodeTo64(key));
byte[] hash = MD5.Create().ComputeHash(keyBytes);
string ret = "";
foreach (byte a in hash)
{
ret += a.ToString("x2");
}
string iv64 = EncodeTo64(iv);
byte[] ivBytes = Convert.FromBase64String(iv64);
r = System.Security.Cryptography.Rijndael.Create();
r.Padding = PaddingMode.Zeros;
r.BlockSize = blockSize;
r.Key = Encoding.ASCII.GetBytes(ret);
r.IV = ivBytes;
}
public string Decrypt(string str)
{
byte[] encryptedBytes = Convert.FromBase64String(str);
byte[] decryptedBytes = transformBytes(
r.CreateDecryptor(), encryptedBytes);
string plaintext = Encoding.ASCII.GetString(decryptedBytes);
int idx = plaintext.IndexOf("\0");
if (idx > -1)
plaintext = plaintext.Substring(0, idx);
return plaintext;
}
public string Encrypt(string plaintext)
{
byte[] plainBytes = Encoding.ASCII.GetBytes(plaintext);
byte[] encryptedBytes = transformBytes(
r.CreateEncryptor(), plainBytes);
return Convert.ToBase64String(encryptedBytes);
}
private byte[] transformBytes(ICryptoTransform transform,
byte[] plainBytes)
{
MemoryStream memStream = new MemoryStream();
CryptoStream cryptStream =
new CryptoStream(memStream, transform,
CryptoStreamMode.Write);
cryptStream.Write(plainBytes, 0, plainBytes.Length);
cryptStream.Close();
byte[] encryptedBytes = memStream.ToArray();
memStream.Close();
return encryptedBytes;
}
private string EncodeTo64(string toEncode)
{
byte[] toEncodeAsBytes = System.Text.ASCIIEncoding.ASCII.GetBytes(toEncode);
string returnValue = System.Convert.ToBase64String(toEncodeAsBytes);
return returnValue;
}
}
In WCF I expose this in my endpoint as:
private string passPhrase = "secret";
private string initVector = "ujkrtadxcfrzpj1Bs5fpM18doZQDGYS4";
private int keySize = 256;
public string EncryptData(string value)
{
PhpRijndael r = new PhpRijndael();
r.InitializePhpRijndael(initVector, passPhrase, keySize);
string ret = "";
ret = r.Encrypt(value);
return ret;
}
public string ReturnTestData()
{
return EncryptData("Test Encrypted Data");
}
Note: Both of these are expose on the interface as OperationContracts inside the ServiceContract.
Now, in the PHP world, we need to create a page to call this, so inside a normal html form, we do the following:
if( isset($_POST['Submit']) )
{
//Show me all errors please
error_reporting(E_ALL);
ini_set('display_errors', '1');
//load nusoap
require_once('../lib/nusoap.php');
//client config to CZ
$client = new nusoap_client('http://example/Service?wsdl',true);
$client->setEndpoint("http://example/Service/EndpointName");
$client->setUseCurl(0);
//set utf-8, or else it breaks.
$client->soap_defencoding='UTF-8';
$client->setDebugLevel( 1 );
//any errors?
$err = $client->getError();
if ($err) {
echo 'Constructor error
' . $err . '
';
echo 'Debug
' . htmlspecialchars($client->getDebug(), ENT_QUOTES) . '
';
exit();
}
// This is a paramter list that can be used later, but not used at the moment
$params = array(
'value' => "666"
);
//Call dummy method for some test info
$result = $client->call('ReturnTestData',$params);
//is there a fault?
if ($client->fault) {
echo 'Fault
'; print_r($result); echo '
';
} else {
$err = $client->getError();
if ($err) {
echo 'Error
' . $err . '
';
} else {
echo 'Result
'; print_r($result); echo '
';
}
}
//decode the base sixty four encoded data returned
$bsf = base64_decode(trim($result["ReturnTestDataResult"]));
//setup auth
$key = 'secret';
$iv='ujkrtadxcfrzpj1Bs5fpM18doZQDGYS4';
//a function to configure Rijndael from the afforementioned article
function init_rijndael ($key,$iv) {
$rj = mcrypt_module_open('rijndael-256', '', 'cbc', '');
if ($rj !== FALSE)
{
$expected_key_size = mcrypt_enc_get_key_size($rj);
$key = substr(md5(base64_encode($key)), 0, $expected_key_size);
mcrypt_generic_init($rj, $key, $iv);
}
return $rj;
}
//setup Rijndael
$rj = init_rijndael($key,$iv);
//decrypt result
$decryptedResult = mdecrypt_generic($rj, $bsf);
//print out.
echo 'Result
'; echo($decryptedResult); echo '
';
}
And hey presto - finally! a working php to WCF communication in Rijndael!
Friday, 6 November 2009
203.117.91.73 sdra64.exe
My eset firewall started complaining last night about connections going outbound to the IP address 203.117.91.73
After a call to ESET, I found out that that I had a trojan virus called sdra64.exe on my machine!
How do you get rid of it?
The guy from ESET firstly check for the virus using a program called RootAlyzer. This confirmed the infection. Next he downloaded procexp.exe from Microsoft to see what dependancies sdra64.exe had. Using another program called Process Unloader, he then closed the handles to sdra64.exe, and all files located in c:\windows\system32\lowsec. Once this was done, he created blank executable from notepad, and overwrote sdra64.exe, then deleted the lowsec folder.
Finally, in the registry under windowsnt\winlogon, he removed the reference to sdra64.exe in the userinit key.
A nasty little beast of a virus, and apparently acquired randomly from visiting a website!
After a call to ESET, I found out that that I had a trojan virus called sdra64.exe on my machine!
How do you get rid of it?
The guy from ESET firstly check for the virus using a program called RootAlyzer. This confirmed the infection. Next he downloaded procexp.exe from Microsoft to see what dependancies sdra64.exe had. Using another program called Process Unloader, he then closed the handles to sdra64.exe, and all files located in c:\windows\system32\lowsec. Once this was done, he created blank executable from notepad, and overwrote sdra64.exe, then deleted the lowsec folder.
Finally, in the registry under windowsnt\winlogon, he removed the reference to sdra64.exe in the userinit key.
A nasty little beast of a virus, and apparently acquired randomly from visiting a website!
Subscribe to:
Posts (Atom)