## WannaCry — Decrypting files with WanaKiwi + Demos – Comae Technologies

Posted by jpluimers on 2017/05/19

[Archive.is] Working Windows XP & 7 demos. #FRENCHMAFIA: WannaCry — Decrypting files with WanaKiwi + Demos – Comae Technologies:

### TL;DR;

DO NOT REBOOT your infected machines and TRY wanakiwi ASAP*!

*ASAP because prime numbers may be over written in memory after a while.

Via:[WayBack] A French researcher says he’s found a tool that could help some fraction of victims running that older Windows version. Just don’t reboot!  WannaCry Ransomware Victims Might Have Some Hope–If They’re on Windows XP | WIRED

–jeroen

## Two Quick Methods for Finding Shared Folders in Windows

Posted by jpluimers on 2017/05/01

In addition to the two methods mentioned at Two Quick Methods for Finding Shared Folders in Windows (use net share or compmgmt.msc) I like this one:

fsmgmt.msc

It directly gets you to the “Shared Folders” inside compmgmt.msc

–jeroen

## Reducing the size of your Windows.edb (Search) and DataStore.edb (Update) databases

Posted by jpluimers on 2017/01/30

### Windows Search: Windows.edb

If you use Windows Search (I don’t: I use Everything by VoidTools), your Windows.edb can grow ridiculously large. It is a single file, though it appears to be in two places because there is a symbolic link from C:\Users\All Users to C:\ProgramData :

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb 

This is how to reduce its size:

#### How to offline defrag the index

1. Change the Windows Search service so that it does not automatically start. To do this, run the following command in cmd.exe:
sc config wsearch start=disabled
2. Run the following command to stop the Windows Search service:
net stop wsearch
3. Run the following command to perform offline compaction of the Windows.edb file:
esentutl.exe /d %AllUsersProfile%\Microsoft\Search\Data\Applications\Windows\Windows.edb
4. Run the following command to change the Windows Search service to delayed start:
sc config wsearch start=delayed-auto
5. Run the following command to start the service:
net start wsearch

Notes:

1. I did not perform the last 2 steps as I’ve kept Windows Search disabled.
2. If you want to reduce the size of the C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\ directory:
1. Before step 1, choose what kind of Windows Search indexing options you want
2. Between step 3 and 4, delete the directory

### Windows Update: DataStore.edb

Windows Update uses the same database structure and is a single file:

C:\Windows\SoftwareDistribution\DataStore\DataStore.edb

This is how I reduced its size:

net stop wuauserv
net stop bits
esentutl.exe /d C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
net start bits
net start wuauserv


Talking about Windows Update: you might also want to Clean Up the WinSxS Folder

–jeroen

## permissions – recursively change owner windows 7 – Super User

Posted by jpluimers on 2016/10/27

Slightly updated the answer the /D Y part will recursively accept taking ownership when directory listing is denied in the permissions:

To fix really broken permissions, the best is to run these two commands one after the other:

takeown /F /D Y "C:\path\to\folder" /R
icacls "C:\path\to\folder" /reset /T

The first one will give you ownership of all the files, however that might not be enough, for example if all the files have the read/write/exec permissions set to “deny”. You own the files but still cannot do anything with them.

In that case, run the second command, which will fix the broken permissions.

–jeroen

## FileZilla on Windows is waaaay faster than WinSCP

Posted by jpluimers on 2016/10/21

Not sure why yet, but on a gigabit network between a Windows 2008 R2 Server and a Proxmox KVM machine, WinSCP gets around 10 megabit/second and FileZilla > 30 megabit/second.

Others seem to agree that filezilla faster than winscp.

–jeroen