Wednesday, December 26, 2007

Changing OEM Branding Logo for Windows Vista Part 1

Here some cool stuff to share again.

For those who find out this cool stuff and play in Windows XP before, you will found out the setting in Windows Vista for this OEM Branding is totally different compare to Windows XP.

Let me make it simple...
Copy the statement below and paste into Notepad:

Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OEMInformation]

"Logo"="Your Logo Path"
"Manufacturer"="Your Manufacturer"
"SupportHours"="Your Support Hours"
"supportPhone"="Your Support Phone"
"SupportURL"="Your Support URL"
"Model"="Your Model"

**You will need to create a picture with 96x96 pixel and save it as OEMLOGO.bmp. The picture file should be saved in %windir%\system32 folder. In this case, your logo path will be: C:\\Windows\\System32\\OEMLogo.bmp

Save as .reg file. Here i named it as OEMInfo.reg

Double click on the OEMInfo.reg and the system will ask for confirmation to modify the entry in your regisry. Press OK to continue.

Once done, you will see the effect as below:


Now you will find out an additional information has been added into your System Properties

Enjoy!!!

Related Topic:

Changing OEM Branding Logo for Windows Vista Part 2

Monday, December 24, 2007

My Next Targeted Collection

hmmm, is been a while since i brought Starscream and galvatron. I wonder which one will be my next collection for transformers. Even thought collecting such kind of models is very expensive, but don't you think it is too attractive to have it. However, i'm not dare to think about buying transformers again for the time being as I almost penniless because of collecting transformers. Haha. Sound terrible...

Still, I will continue to make survey and research on the prices and model and I hope one day I can purchase transformers again on my next targeted models as below.
  • Master Galvatron from Galaxy Force (approximately RM420 market price)


  • Galaxy Convoy from Galaxy Force (approximately RM499 market price)


  • Mega zarak From Superlink (unknown price)


  • StarScream from Master Piece Generation 1 (approximately RM340-500[vary from different toy shop])


  • Megatron from Armada (unknown price)

Up to now, I only targeted 5 models here. NOT hope to added the list as it will make me die faster. I think this list won't be fullfil at least 1-2 years later. Haiz~~~

God bless me!!!

Wednesday, December 19, 2007

Infected by Viruses again??? No worries...

Hi. for those who get infected by virus before, it would be annoyned, irritated and frustated to known that our machine has been infected by virus.

On this blog, I would like to share out some simple knowledge on how to stop and fix the virus.

Let us take some example: flash.10.exe and macromedia.10.exe is one of the virus I infected before which it's normally spread via removable devices like pendrive.

Basically, the common behavior that the virus normally will do is to disable three important features inside our machine.

  • Folder Option
  • Regedit
  • Task Manager

Once infected by this kind of virus, you will no longer able to use those features mentioned above. No worries!!!

How we going to trace the viruses since the useful features has been disable?

Firstly, what we need to do is to enable back our Regedit. How to know it's already been disable?

Run -> Type regedit, then you should see something like screenshot below.

So, follow the steps below to enable your regedit:

  1. Run gpedit.msc (must have administrator privileges)
  2. Navigate "User Configuration\Administrative Templates\System"
  3. Go to "Prevent Access to Registry Editing Tools"
  4. "Disable" it if the current status is "not configured" or "enable"

Once done, you will allow to use back your regedit.

Secondly, what we need to do is to recover back our Folder Option on Explorer Toolbar. The Folder Option is important for us to enable and disable features like "Show Hidden Files and Folders" and "Hide Protected Operating System Files (Recommended)". Since the Folder Option already disable, how you going to use it? Simple...

For those who don't know where is the Folder Option located:

Screenshot below is the one that has been disable, so you will not see it inside Toolbar.

No worry, follow the steps to get it enable back:

  1. Run regedit (must have administrator privileges)
  2. Navigate "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer"
  3. Create "NoFolderOptions" using DWORD (32bit value). 1 to enable and 0 to disable
  4. Reboot

or

  1. Run gpedit.msc (must have administrator privileges)
  2. Navigate "User Configuration\Administrative Templates\Windows Components\Windows Explorer"
  3. Go to "Removes the Folder Option menu item from the tools menu"
  4. "Disable" it if the current status is "not configured" or "enable"

You will have your Folder Option recover after reboot.

Lastly, to enable task manager that use to view running processes and services.

How to know it's already been disable?
Run -> Type taskmgr, then you should see something like screenshot below.

Follow the steps to get it enabled:

  1. Run regedit (must have administrator privileges)
  2. Navigate "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System"
  3. Create "DisableTaskMgr" using DWORD (32bit value). 1 to enable and 0 to disable
  4. Reboot

or

  1. Run gpedit.msc (must have administrator privileges)
  2. Navigate "User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options"
  3. Go to "Remove task Manager"
  4. "Disable" it if the current status is "not configured" or "enable"

Once you enabled all the features that we need. Then is time to find the virus...

  1. Go to Folder Option -> view, radio button on "Show hidden Files and folders" and unchecked "Hide Protected Operating System Files (Recommended)"
  2. Go to your pendrive (if the main source spread from your pendrive), check is there any suspicious file hidden. Normally contain one executable (.exe) file, 1 autoexec file or .inf file or .vbs file presence. Please be aware of this.
  3. Is advisable to check the content inside the inf or vbs file (cause it might contains some useful information on how it runs the virus) by using notepad.
  4. Just recently, my machine get infected by one virus called KB915865.exe via my pendrive. After I unhide the file, it contain 1 folder named MSOCache and 1 inf file. When you open the file with notepad, it will show something as below:

[AutoRun]

open=.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe

shellexecute=.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe

shell\AutoOpen\command=.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe

shell=AutoOpen

  1. Base on the script, you will notice that it will perforn autorun once you plug in you devices. Hence, open your regedit, search for KB915865.exe. From your search, you will find out something as below:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0233621-5515-11dc-9b8a-00116b31ca63}]"BaseClass"="Drive"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0233621-5515-11dc-9b8a-00116b31ca63}\shell]@="None"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0233621-5515-11dc-9b8a-00116b31ca63}\shell\Autoplay]"MUIVerb"="@shell32.dll,-8507"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0233621-5515-11dc-9b8a-00116b31ca63}\shell\Autoplay\DropTarget]"CLSID"="{F26A669A-BCBB-4E37-ABF9-7325DA15F931}"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0233621-5515-11dc-9b8a-00116b31ca63}\shell\AutoRun]@="Install or run program""SetWorkingDirectoryFromTarget"=""
"ShellExecute"="KB915865.exe"

Notes: Different machine will have different ID ({d0233621-5515-11dc-9b8a-00116b31ca63})

  1. Delete it. But bare in mind, this virus is strong enough to auto generated itself each time you plug in your pendrive even though you have formatted your pendrive for n of time.
  2. Reason is the virus in earlier stage already copied some files into your machine without your acknowledgement.
  3. To confirm the truth, run msconfig -> Startup tab -> check is there any suspicious system run during startup.
  4. For this case, I found out that my machine startup "userinit" item in C:\Windows\System32\cologsver.exe which I found out to be a problematic file which always auto-generated the virus file inside my pendrive no matter how many times i formatted.
  5. Hence, disable the item -> reboot -> go to C:\Windows\System32 to delete "cologsver.exe". Or delete the entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Cologsver.exe" from your registry.
  6. Solved. Repeat the steps above if you worried that the virus still remain inside your machine.

Important notes:

  • The finding and solution provided will not guarentee your machine 100% clean from viruses. It's only my own finding, solution and experience. Use at your own risk!!!
  • Please use the registry wisely as it will cause a serious damage to your machine Operating System and setting.
  • Please back up your data 1st.
  • Solution provided is only apply to certain virus, it may not apply to other viruses.
  • If you encounter any other strong viruses, you are recommended to consult your senior, use trusted anti-virus or worst come to worst, format your machine immediately.

C&C are welcome. Please let me know if you unclear of certain steps provided.

Thanks for reading this blog.

Monday, December 17, 2007

Finally... Cybertron Starscream falls into my hand!!!

09th December 2007... the day after I finish took my dinner in Jogoya, Starhill. Right away I need to rush back to Berjaya Time Square as my car was parking inside BTS. When the time I entered BTS, my mind started to struggle again whether to buy the transformers model which I already spotted long time ago before brought Galvatron.

Because of the price is too expensive and not affordable, so it has been pending quite a long time.

Finally on that day before I went back home, i spent around 30 minutes inside the shop stuggle again on the decision make whether to buy it or not.

At last, I make up my mind and grap the box to the counter. And here it is:

"Starscream from Transformers Cybertron"!!!

Box Front View:



Box Back View:


Now what, again I brought this model in Berjaya Time Square but in the different Toy Shop. One of the model shop named "Grafiti Toys" which located on 5th floor (same floor with Mc Donalds).

This time, it cost me around RM400!!! and this model is HUGE!!! compare to Galvatron at least X2.



At 13'' tall, Starscream is big and chunky. Starscream has a ton of cool little features. He comes with a removable crown, a light up gimmick, spring loaded weapons, and he even fires missiles. Two Cybertron Planet keys activate the translucent weapons beside each arm. Insert the keys and the arms spring out. One side is a blade, the other a missile launcher. When the keys are not in use they are stowed in small compartments behind the head. Starscream also features 2 cannons on the chest that you can move up and down.

Starscream also comes with light and sound features that can be activated by pressing a button behind Starcream’s head but required 2 “AAA” batteries which are not included.

Robot Mode:


Closer View:


Robot Mode (With weapon):


Jet Mode:


Specification Card:


Please take note that there are some differences with my Starscream and the Starscream inside the Specification Card. There are some differences on the designs. The reason is the one I brought is manufactured by Hasbro(US) and the one inside the card is manufactured by Takara(JP).

Even the anime title is different:

  • Transformers Galaxy Force (JP)
  • Transformers Cybertron (US)
Although he looks like a brick in the package, Starscream is fairly poseable. He has joints in the shoulders, elbows, waist, knees and feet. The head also turns and his eyes light up. Everything clicks when you move it, and everything stays where you put it.




Even dying postures make me impress. Haha

My overall expression on this model is SUPER awesome and the design is damn GREAT!!!
Hence, I rated this model for 10/10.

How about you?

For more information:
http://www.takaratomy.co.jp/products/galaxyforce/index2.html
http://www.tv-aichi.co.jp/TF/

My 1st Collection on Transformers

20th October 2007... is the date where I purchase my very 1st collection on transformers.

That's "Galvatron from Transformers Superlink"!!! Haha

Box Front View:


Box Back View:


hmmm, this model i brought in Berjaya Time Square. One of the model shop named "Time Machine" which located on 7th Floor.

Inside the shop, there's a lot of transformers model and from there, I spotted Galvatron and started to love it in the 1st sight. Cool!!!

It cost me around RM240 and luckily the shop owner give me RM10 cheaper from the actual price (but it still expensive for me). At the end, I purchase this model for RM230.

Let me go through the items inside the box. Inside this box, it contains one Galvatron's Sword and a tank which resembles Galvatron in "Transformers Micron Legend". The tank able to produce sound during launching the missiles and during attach the sword into the tank coming with red light.

  • The tank and the sword which attach together with tank on Galvatron Arm


For the transformation, this model of Galvatron can transforms into a Jet.


Robot Mode:



Closer view:



Jet Mode (With winged open wide):



Jet Mode(With tank attached):



Specification Card:



The postures for this model is quite limited compare to the Transformers MasterPiece model. But at least, it still can perform some of the cool postures.



My overall expression on this model is awesome and the design is great!!!
Hence, I rated this model for 9/10.

For more information:
http://www.takaratomy.co.jp/products/superlink/index2.html