A 19GB Outlook .pst file.

I’ve been getting a lot of calls regarding unresponsive Microsoft Outlook. After a few troubleshooting, I found out two of the callers have a 19GB .pst file. So what I’m doing right now is archiving the folders based on the date.

After the archiving done, it is necessary to compact the current working folder. It will reduce the size of the .pst file.

Malware Alert: Cloud AV 2012

On Wednesday November 23rd, 2011; the day before Thanksgiving Day I received a call.

“Hey, just want to let you know I was using my computer and Cloud AV 2012 just installed itself.”

Yeah, that’s a Malware.

I was getting ready for my Thanksgiving trip, so I had to work on this malware problem later. Bleeping Computer has a great instructions on removing Cloud AV 2012.

I am documenting what I’m doing to remove Cloud AV 2012.

  • I want to know if  Combofix can completely remove Cloud AV 2012. I ran Combofix in Safe Mode with Networking. It took about 15 minutes for Combofix to find some malware and removing them, unfortunately it is not enough.
  • The next step is to run Malwarebytes’ Anti-Malware.
  • I ran Spybot – Search and Destroy to clean up whatever part of malware it can find.
  • I ran Combofix again, and it found a few leftover Cloud AV 2012 files.
  • Reboot the computer a few times and so far I do not see any suspicious activities.

I’m going to put this computer on quarantine for a few days and see if Cloud AV 2012 is completely gone.

 

VMware Fusion 4.1 now supports installations of Mac OS X Leopard and Snow Leopard client.

UPDATE:
VMware said that this should not be the case, the next update will check the version of Mac OS X before installation. Only OS X Lion and Mac OS X Server are allowed for virtualization.

From MacNews:

One thing that was revealed is that you could run earlier versions of Mac OS X as a client under 4.1 (this was not previously possible with version 4.0.1). Given the licensing, we were incredibly surprised (although delighted) to see this. Unfortunately, while incredibly useful for developers wanting to test on multiple versions, this turns out to be an oversight.

——-

VMware has just updated VMware Fusion 4.1 with added support for installing Mac OS X Leopard and Snow Leopard client in addition to OS X Lion as noted by many including The Mac Observer.

This is certainly a good news for many Mac users, especially the ones who really need Snow Leopard and Rosetta support. Now you can have iCloud and Rosetta support in one Mac.

Buy VMware Fusion from Amazon.com.

Still broken this Safari 5.1.1

Safari 5.1.1 is still suffering from hang-ups and excessive memory usage despite of what Apple claimed. In OS X Lion, Safari 5.1.1 hangs up when opening multiple tabs or windows. Safari 5.1 becomes unresponsive as phantom page reloads occur.

I noticed this as I was downloading files in the background. The download was interrupted as the phantom page reloads happened.

Persistence of bootkit

Platform: Windows XP, Windows Vista and Windows 7.

Symptoms, but not limited to:

  • Search results using browser search box including Chrome and Internet Explorer 9 Omnibox are redirected to other sites.
  • Internet Explorer is running in the background on login, using large amount of memory.

After long troubleshooting sessions I figured out that a bootkit was present on this computer.

A bootkit hides itself by modifying the master boot record.

The particular bootkit I was dealing with was not detected by Combofix, Malwarebytes’ Anti-Malware and many others. The only anti-malware program detected the bootkit was Hitman Pro 3.5.

If you are dealing with a persistent malware infection that redirects search results, try using numbers of anti-malware softwares. In addition to that, search for “Google redirect virus” using an uninfected computer. The malware redirects search result system-wide. On the infected system, search results were redirected on Internet Explorer, Safari, Chrome and Firefox. The malware will redirect search results on any browsers installed on the system.

It is almost 5 o’clock in the morning. I have not had a minute of sleep. I’ll clean up this post later.