False Positive Downloader Virus Caused by WP-Stats

Recently, I was getting a false positive virus detection from Symantec Antivirus on one of my blogs. I had just upgraded this particular blog to WordPress version 2.3.2. The file in question was wp-stats[1].htm located in my temporary internet files. The file was never found and therefore could not be removed. It was driving me crazy!

First I called my web hosting service and asked them to scan my blog for viruses. I was told they don’t do that. So I downloaded my current blog files and scanned all the files locally and did not find any viruses. Just as I suspected, this might be a false positive virus detection.

I searched the entire internet for any information on this issue and didn’t find anything directly related to my specific problem. So I decided to completely remove my blog and install a fresh new downloaded copy of WordPress version 2.3.2 and, after all that, I still found I was getting the same Downloader virus detection caused by the wp-stats[1].htm file.

Now I was completely frustrated to no end. For some crazy lucky reason I decided to go through all my blog option settings and when I deleted the Blog address (URL): found under Options then the General tab within WordPress administration and then saved my updated settings. Wordpress automatically populates the blog address field back in upon saving. This fixed the false positive Downloader virus detection that was occurring anytime somebody visited my blog and was using Symantec Antivirus and maybe any other antivirus software.

My guess is that I must have mistyped the blog address url entry at some point and that was causing the problem.

CORRECTION: The issue returned shortly after I posted this blog entry. So I went back through my blog piece by piece and located an entry in one of my blog postings that looks like what is posted at this link:

http://wordpress.org/support/topic/151888

It is a traffic statistics script that was inserted into one of my blog postings.

I removed this entry from my post and the downloader virus detection issue went away.

If this information helps anyone else experiencing this issue please leave a comment on our blog to let us know. Thank you!

Regards, Jared Blake

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , , , ,

Display Wordpress 2.3.x Tags On Your Current Theme

Some of you may be struggling as I did when trying to display tags on your current postings within the latest 2.3.x versions of WordPress. Rather then using an external plugin such as Ultimate Tag Warrior (it was awesome). WordPress now has it’s own tagging system built in.

You must place the following code within your WordPress pages were you want your tags to display, such as: index.php, single.php, etc.

You may have to experiment a little, to find the exact location you want to place this code.

This command gives you the default comma separated format that looks like this:

Tags: tag1, tag2, tag3, tag4

For other formats of displaying your tags, check out the following WordPress help page at: http://codex.wordpress.org/Template_Tags/the_tags

Regards, JDHL_Tech

Technorati Tags:
, , , ,

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , , ,

Completely remove default games from Windows 2000

Microsoft has hidden a few applications from the add/remove Windows Components Wizard that can be found within the Add or Remove Programs area. You may want to remove programs such as games and other components that are sometimes hidden from you. If you’re in a corporate environment you may want to remove the default games from your employees computers. Here are the steps for removing games if they are currently hidden in the add/remove Windows Components Wizard. After going through these steps you can unhide any of the other components you may want to remove from your system.

Does Accessories and Utilities currently show in the add/remove Windows Components Wizard.? If yes then click on details and see if games appears. If it does then you can uncheck to remove it and then click OK.

Otherwise Modify the following file - c:\winnt\inf\sysoc.inf

Now Accessories and Utilities should show in the Windows Components Wizard.

You can now select details and remove games!

You should not be able to run the following game files now:
C:\WINNT\System32\freecell.exe
C:\WINNT\System32\sol.exe
C:\WINNT\System32\winmine.exe
C:\Program Files\Windows NT\Pinball\PINBALL.EXE

Note: there maybe copies of these files located in the following directory:
C:\WINNT\system32\dllcache

Regards, JDHL_Tech

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , ,

User types in url but is taken to another site

Anastasia, sounds like you have been infected by a browser hijacker.

A browser hijacker modifies your browser settings so when you type in a URL you are redirected to another site.

Off the top I was thinking you should try the following steps:

1. Delete all temporary internet files and browsing history.
2. Run a full system scan using Symantec Antivirus with the latest NAV def’s.
3. Run a full system scan using Ad-aware by Lavasoft with the latest updated def’s.

One of my tech friends suggested using Spyware Doctor by pc-tools and run the scan.

Follow any directions given by Symantec if a virus/trojan/hijacker is found. This may include modifying the registry or running a fix file found on Symantec’s website.

The last time my wife’s computer was infected with a bad virus I had to rebuild it. Meaning I saved all her data then completely formatted the hard drive thus removing everything. Then I re-installed the operating system and all her applications and of course her special fonts. :) Then I restored all her data. Very time consuming but of course this completely eliminated the virus.

Anastasia, please post back here if you had any success after completing the first three steps.

To any techs reading this blog, please leave your solutions and comments here.

Thank you!….Regards, JDHL Tech

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , ,

Windows Explorer does not display the left folder pane

Tech Tips:

Problem: Windows Explorer does not display the left folder pane (all grayed out).

Solution: Login to your computer with admin rights and from the run command or dos prompt, run the following command:

regsvr32 /i shdocvw

After command successfully runs, restart your computer.

Windows Explorer should now display the left folder pane properly again.

Regards, JDHL_Tech

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , ,

Windows could not start because the following file is missing or corrupt: \winnt\system32\config\systemced

Tech tip fix for “Error Message: Windows could not start because the following file is missing or corrupt: \winnt\system32\config\systemced”

The fix is to boot-up on a special system boot disk and complete the following:
1. change directory to c:\winnt\system32\config
2. rename system to system.old
3. rename system.alt to system
4. re-boot pc

You should now be able to boot up your computer using this older backup copy of the registy file.

Regards, JDHL_Tech

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • BlinkList
  • Blue Dot
  • Bumpzee
  • De.lirio.us
  • Fark
  • Furl
  • Ma.gnolia
  • Netscape
  • NewsVine
  • PlugIM
  • RawSugar
  • Reddit
  • Shadows
  • Simpy
  • Spurl
  • StumbleUpon
  • Technorati

Tags: , , ,

Next Page »