Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Vista mods. Show all posts
Showing posts with label Vista mods. Show all posts

Sunday, January 3, 2010

Windows Things…

Posted on 1:02 PM by Unknown

image 

cc attribution: "4 Windows" on Flickr by gmahender

Odds-n-ends for Windows things.

  • Enable the secret ‘GodMode’ in Windows 7 –ithinkdifferent.  Spotted in Tweakfest! Enable God Mode in Windows 7  - TechBlog. This pretty cool for admins and heavy system tweakers.  I’ve been using the free utility Windows Access Panel for quick-jumps to commonly-used Windows 7 elements, but this looks mongo-cool.  I set my view to “small icons” after checking out the different views and it is grouped by type (to some degree).  Still, there’s a lot to sort out.  While Vista and Win7 share many of the same feature and setting locations, I’m still learning them after all these years with Vista.  Anything that helps round them up into a more browse-able format is a plus in my book.  Update: See Ed Bott’s take on the tweak and what is really going on.  That "God mode" Explorer trick does less than you think .  I still think its a useful way to find control items as I haven’t mastered the type-search-n-find method quite yet…

  • Folder Sharing between Windows 7 and VM – Windows Virtual PC blog – sharing folders isn’t as intuitive under Virtual PC now as it was under Virtual PC 2007.  This post lists two tricks you can easily follow to set up a simple folder sharing connection between your VM and Windows 7 host system.

  • Elevation PowerToys for Windows - blog.  There is some really, really cool and powerful stuff in this new-to-me blog.  Elevation PowerToys allow focused rights elevations for specific scenarios and contexts that just don’t quite work smoothly using normal techniques.  For some coolness applications see these links:
    • Explore as Administrator PowerToy  - tool plus tips to set up an elevated file-explorer browser alternative.
    • Free Elevation PowerToys for working with User Account Control – CMD prompt here as System.  Wow.
    • Utility Spotlight: Script Elevation PowerToys for Windows Vista – CMD prompt here as Administrator 

  • Virus scanning recommendations for computers that are running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Windows 2000, Windows XP, Windows Vista, or Windows 7 – Microsoft Help and Support Article ID: 822158.  Long title but gist is that by configuring your anti-virus app to exclude these files and locations from scanning you can speed up the scan and possibly avoid corruption as your AV app and the OS fight out over control to these locations/files.  Which means that virus writers now have targeted locations to try to drop their apps into.

  • Win7 Library Tool – freeware - Zorn Software. Windows Libraries are like smart folders.  They contain references to other folders and display the content as if it existed in the library folder.  But it’s really not there, it’s still in the original location.  However, you can’t add network locations to a library folder.  This tool makes it possible.  Spotted via Lifehacker post.

  • Customize Windows 7 Screensavers with the Help from System Screensavers Tweaker  - freeware - Windows 7 hacker.  Maybe you don’t need a third-party screen saver but you are finding the options for the Windows screen savers a bit lacking.  This free utility allows you to fine-tune the existing Microsoft screen savers for Windows 7 a lot more than the native options allow.  More bubbly anyone?

  • How To Sync Your iTunes Library With Your Music Folders – Make Use Of blog clearly sorts out a new iTunes 9 feature of allowing iTunes to manage all your music folders.  Its easier than it looks and this guide makes it pretty clear with great screen shots.

  • The (Near) Final Word on Multi-Monitor Taskbars for Windows 7 - Ultramon vs. DisplayFusion – Scott Hanselman’s Computer Zen – Scott does a real-world comparison by a hard-core mulit-monitor user.  I’m running the mentioned 3.0.8 Ultramon beta on my dual-monitor desktop system at home and finding it very smooth and compatible with Windows 7.  Since I already own a license for it, it’s a no-brainer for me. However if I did want a freeware solution, DisplayFusion has much going for it.  As Scott shows, however, neither is perfect.

  • Celebrate the Arrival of 2010 with a New Windows 7 Theme! - Windows Experience Blog.

  • Desktop Wallpaper Calendar: January 2010 - Smashing Magazine.

  • win7utils - Windows 7 ISO Disc Image Utilities. From the developer’s page…   (as spotted via Lifehacker)

The Windows 7 ISO Image Edition Switcher is a set of small binary patches (and a tool to apply these patches) that will convert an official Windows 7 ISO disc image into an official Windows 7 ISO disc image of another edition. The resulting ISO images are bit-for-bit identical with those posted on MSDN or TechNet, and their SHA-1 hashes should match the official hashes posted by Microsoft.

The ei.cfg Removal Utility is a simple tool that will remove the ei.cfg from any Windows 7 ISO disc image, thereby converting the image into a "universal disc" that will prompt the user to select an edition during setup. This tool works by toggling the deletion bit in the UDF file table, eliminating the need for unpacking and rebuilding the ISO, which means that this is extremely fast (the process of patching the ISO to remove ei.cfg takes only a fraction of a second), and the process is easily reversible (running the utility on a disc image patched by this utility will restore the disc image to its original state).

Please note that these won’t allow your Windows Home Premium key to suddenly activate a Windows Ultimate install that you converted your install disk to offer…  Right key for right product version is still required….

  • Notepad2 Modifications - Kai Liu (developer of the W7 ISO disk image utility above, also offers a modded version of notepad2.  Not only that, he also has a tool that allows you to swap out the Microsoft Notepad with notepad2 automagically.  It can be done manually but is a royal pain.  This tool offers to make that process a lot easier.

  • Open Command Prompt Shell Extension – also offered by Kai Liu.  Like the Elevation PowerToys mentioned above, this autoconfig tool adds the ability to add the “open CMD here” and “open as Admin CMD here” to the right-click menu.  That reminded me of these native tricks as well; Windows 7 Trick: How to Open Command Prompt in Your Current Directory by a Single KeyStroke and Copy Path of a File to the Clipboard in Windows 7 or Vista.  The secret to get these to open on demand?  No, no “Alohomora” required.  Just hold down the “Shift” key when right-clicking and these options appear.

  • Microsoft prepares Windows 7 for external SP1 testing - Within Windows – Rafael Rivera uncovers evidence that Win7 systems are being seeded for qualification testing of the Win7 SP1 beta.  Per the post:

Similar to previous external beta service pack rollouts, Microsoft has enabled – via updates you already installed – a beta ‘candidacy check’ within its Windows Update software. Just like Windows Vista, a registry key and value pair need to be added prior to being authorized to download the new software.

Lots of coolness here.  Just be careful how you apply the power!

--Claus V.

Read More
Posted in anti-virus software, command-line interface, hacks, Link Fest, Microsoft, utilities, Vista, Vista mods, wallpapers, Windows 7 | No comments

Saturday, January 2, 2010

Opening Ports in Windows Firewall from Batch files

Posted on 6:23 PM by Unknown

All of our systems run a single application/service that is auto-(re)-installed from a user login event script.

No biggie.  It’s kinda overkill but it is a critical application that could be deleted accidently.

It does require that we add some Windows Firewall port exceptions for custom IP addresses so it can have a clear shot through the Windows Firewall if the user accidentally or purposefully (say our laptop users) enable the firewall.

All of my own built system images for some time have had the custom port opening rules added in by default.

However, some older systems didn’t deploy with my image and didn’t have the port configured by default.  Since we are not an AD shop, it has meant going, upon request, to the users’ systems, verifying the application/service is running correctly, and then manually going into the Windows Firewall GUI to set the open port rule and custom scope.

Usually it’s not a big deal but sometimes it can be as it is disruptive to an end-user when we drop in and start suddenly adding Firewall port rules/exceptions to the system from the GUI.  Some end users are fairly PC savvy and it can generate some raised eyebrows and questions that add more time to the service job.

Recently I had completed another such assignment and wondered if I could just skip all the drama of having someone watch me set custom Windows Firewall port rules.  Maybe I could just make a silent-running and innocuous batch file that could quietly do all the work for me in the background while I focused on checking other system things.

Sure enough…I could…and it’s pretty easy as well.

GUI-based Windows Firewall Port Exceptions

Some applications and services need to be able to get out through the firewall.  Sometime “mothership” applications need to signal down to the client-side application/service.  Firewalls work to prevent those communications.

However if the communications inbound/outbound are legitimate and mission-critical, you need to open up a hole to talk-through.

Normally opening a hole in your security wall is dangerous as maybe someone unwanted could sneak in.  Windows uses communication “holes” called ports.  Actually I guess they are more like “channels” or frequencies rather than ports (windows) on the side of a ship.  Certain programs and services only talk on certain ports/channels.  Generally the firewall locks these down so the call can’t go through.  However, these can be opened up so that anyone/anything could talk on that port.

Sites like GRC | ShieldsUP! or McAfee’s Test Your Firewall, or SecurityMetrics Free Port Scan or PC Flanks can be used for free to test your system for open ports.

But what if you don’t want’ to leave a port open to everyone, even though you need to?  You can then set one more level of protection on your port by setting a custom rule to only allow traffic of a certain type and/or trusted IP address (or range) to flow through.

Firewalls are great but they can interfere with applications, games, and other communications from trusted programs that by design need to reach the network/Internet. 

  • Windows Firewall may block some programs from communicating over the Internet after you install Windows XP Service Pack 2 – Microsoft Help and Support Article ID: 842242

Luckily Windows XP and higher does allow you to set these kind of special exceptions.  For most folks using the GUI method is simple enough and easy to do.

  • Open a port in Windows Firewall – Microsoft

Unlike an exception, which is only open during the time that it is needed, a port stays open all the time, so be sure to close ports that you don't need anymore.

  1. Open Windows Firewall by clicking the Start button, clicking Control Panel, clicking Security, and then clicking Windows Firewall.

  2. Click Allow a program through Windows Firewall.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

  3. Click Add port.

  4. In the Name box, type a name that will help you remember what the port is used for.

  5. In the Port number box, type the port number.

  6. Click TCP or UDP, depending on the protocol.

  7. To change scope for the port, click Change scope, and then click the option that you want to use. ("Scope" refers to the set of computers that can use this port opening.)

  • How to manually open ports in Internet Connection Firewall in Windows XP – Microsoft Help and Support Article ID: 308127

Which works just fine but takes a while to click through, enter the correct values (assuming you still remember them), and isn’t very discreet, particularly if the rule name sounds suspicious.

But a silent-running batch-file now that would be quick, surgical, and endoscopic.

I did find that Gammadyne’s Free DOS Utilities offers a free command-line tool FIREWALL.EXE for adding exceptions to the Windows Firewall but it wasn’t quite as granular as I was looking for.

Luckily, Windows XP (and a more advanced one in Vista/Windows 7) does contain just the command-line tool I needed.

NETSH to the CLI Firewall configuring rescue!

It didn’t take me too much effort to find the NETSH command and the wonderful tricks it could do:

  • Michael Howard’s Web Log : The joy of netsh. – Michael Howard’s Web Log

  • Using Netsh with Windows Firewall – Windows Networking

  • Configuring network settings from command line - LanToolbox.

  • Enable or disable Windows firewall from command prompt – Help Desk Geek

These were great and gave me the basics that I needed to see my goal was possible to accomplish.

Then I found Penn State U’s fantastic page How To Add Programs and Ports to Windows XP SP2 Firewall Exceptions List. Not only did it have some basics, but it also has a unpackable collection of batch-files tailor-made for configuring Windows Firewall rules with these techniques; including both prompted and silent-running batch files with netsh commands.  It provides some great examples to use as starting points.

In the end, the heart of my own custom Windows XP Firewall batch file will contain a line like this:

netsh firewall add portopening TCP <my target port #> OPRule_<port#> ENABLE ALL CUSTOM <ip address #1,ip address #2>

where <my target port #"> is the specific one that our application/service communicates through, and where <ip address #1,ip address #2> are the specific IP addresses used the the “mothership” application that only will be allowed to solicit requests to the local client application through that specific port.

NETSH CLI References

The links above were great but they didn’t really help me understand and add the details like “ALL” which set the Windows Firewall port exception rule for all profiles on the system. Nor did it help me with the “CUSTOM” argument to detail which IP’s I needed to open up when setting the rule.  While the examples found showed how to open up a port number, it didn’t deal with setting the port to use the specific IP ranges that I wanted to only allow.

For those details I had to turn to these wonderful resources.

  • Appendix B: Netsh Command Syntax for the Netsh Firewall Context – Microsoft TechNet.

In my case specifically this portion (though the Appendix is rich with Netsh CLI goodness) is what I was interested in.

…

add portopening

Used to create a port-based exception.

Syntax:

Note Some parts of the following code snippet have been displayed in multiple lines only for better readability. These should be entered in a single line.

add portopening
[ protocol = ] TCP|UDP|ALL    
[ port = ] 1-65535    
[ name = ] name    
[ [ mode = ] ENABLE|DISABLE       
    [ scope = ] ALL|SUBNET|CUSTOM      
    [ addresses = ] addresses      
    [ profile = ] CURRENT|DOMAIN|STANDARD|ALL      
    [ interface = ] name ] 
Adds firewall port configuration. 
Parameters: 
protocol - Port protocol.    
    TCP  - Transmission Control Protocol (TCP).    
    UDP  - User Datagram Protocol (UDP).    
    ALL  - All protocols. 
port - Port number. 
name - Port name. 
mode - Port mode (optional).    
    ENABLE  - Allow through firewall (default).    
    DISABLE - Do not allow through firewall. 
scope - Port scope (optional).    
    ALL    - Allow all traffic through firewall (default).    
    SUBNET - Allow only local network (subnet) traffic through firewall.
    CUSTOM - Allow only specified traffic through firewall. 
addresses - Custom scope addresses (optional). 
profile   - Configuration profile (optional).    
    CURRENT  - Current profile (default).    
    DOMAIN   - Domain profile.    
    STANDARD - Standard profile.    
    ALL      - All profiles. 
interface - Interface name (optional). 
Remarks: 'profile' and 'interface' may not be specified together. 'scope' and 'interface' may not be specified together. 'scope' must be 'CUSTOM' to specify 'addresses'. 
Examples:    
     add portopening TCP 80 MyWebPort    
     add portopening UDP 500 IKE ENABLE ALL    
     add portopening ALL 53 DNS ENABLE CUSTOM 157.60.0.1,172.16.0.0/16,10.0.0.0/255. 0.0.0,LocalSubnet    
     add portopening protocol = TCP port = 80 name = MyWebPort    
     add portopening protocol = UDP port = 500 name = IKE mode = ENABLE scope = ALL    
     add portopening protocol = ALL port = 53 name = DNS mode = ENABLE scope = CUSTOM addresses = 157.60.0.1,172.16.0.0/16,10.0.0.0/255.0.0.0,LocalSubnet

You can also use “netsh set portopening” to modify an existing port rule or “netsh delete portopening” to remove one from a batch-file or command line.

  • Download details: Deploying Windows Firewall Settings for Microsoft Windows XP with Service Pack 2 – This Microsoft white paper “…describes the methods used to deploy Windows Firewall settings in a managed environment.”   I found it to be a helpful reference.

  • Chapter 8 - Locking Up the Ports : Windows Firewall – PDF – I found this amended chapter on the Google.  Had some great tips and examples of Netsh in action in Windows.

  • Microsoft Windows XP - Using Netsh - Windows XP Professional Product Documentation.  Turns out that Netsh can operate like a “nested” command tool, similar to DiskPart.  Run NETSH alone and you go into the Netsh> command level and can then pass arguments accordingly.  Similarly, when using in batch-files above, just pass the entire netsh command string with arguments and it will work just fine.

NETSH in Vista/Windows 7

Netsh is still present in Vista/Windows 7 but advances in the Windows Firewall design have demanded it be expanded to keep with the times.

In XP, you have to call the “netsh firewall” context when placing your add or set or delete portopening commands and arguments (along with all the other firewall-specific supported netsh commands). 

In Vista and Windows 7 that changes to now require "netsh advfirewall firewall" context to control Windows Firewall behavior.

  • How to use the "netsh advfirewall firewall" context instead of the "netsh firewall" context to control Windows Firewall behavior in Windows Server 2008 and in Windows Vista – Microsoft Help and Support Article ID: 947709.

    The netsh advfirewall firewall command-line context is available in Windows Server 2008 and in Windows Vista. This context provides the functionality for controlling Windows Firewall behavior that was provided by the netsh firewall context in earlier Windows operating systems.

    This context also provides functionality for more precise control of firewall rules. These rules include the following per-profile settings:

    Domain

    Private

    Public

      The netsh firewall command-line context might be deprecated in a future version of the Windows operating system. We recommend that you use the netsh advfirewall firewall context to control firewall behavior.

      Note The netsh firewall command line is not recommended for use in Windows Vista.

    And then there is this…

    • Netsh Commands for Windows Firewall with Advanced Security – Microsoft TechNet.

      Applies To: Windows 7,Windows Server 2008,Windows Server 2008 R2,Windows Vista

      Netsh advfirewall is a command-line tool for Windows Firewall with Advanced Security that helps with the creation, administration, and monitoring of Windows Firewall and IPsec settings and provides an alternative to console-based management. This can be useful in the following situations:

      When deploying Windows Firewall with Advanced Security settings to computers on a wide area network (WAN), commands can be used interactively at the Netsh command prompt to provide better performance than gnraphical utilities when used across slow-speed network links.

      When deploying Windows Firewall with Advanced Security settings to a large number of computers, commands can be used in batch mode at the Netsh command prompt to help script and automate recurring administrative tasks that must be performed.

      You must have the required permissions to run the netsh advfirewall commands:

      If you are a member of the Administrators group, and User Account Control is enabled on your computer, then run the commands from a command prompt with elevated permissions. To start a command prompt with elevated permissions, find the icon or Start menu entry that you use to start a command prompt session, right-click it, and then click Run as administrator.

    From there (at least in my specific need) you then need to move on to either the

    • Netsh AdvFirewall Firewall Commands page on Microsoft TechNet for the specific command line arguments required.

    or the

    • Download details: Introduction to Windows Firewall with Advanced Security – Microsoft Downloads offers a great whitepaper detailing the changes and examples of managing the Vista/Win7 firewall, including from the command line.

    Good stuff all the way round.

    Can’t wait to start deploying…

    Claus V.

    Read More
    Posted in command-line interface, firewalls, Microsoft, networking, security, Vista, Vista mods, Windows 7, XP, XP mods | No comments

    Sunday, August 16, 2009

    Utility Gumbo

    Posted on 9:33 PM by Unknown

    There’s a lot in this pot.  Probably something everyone can find to enjoy.

    I’m serving it up tonight out of the back of the truck on the side of the road.  So it will be short on dialog, full on flavor.

    Feel free to pick-around.  Just wash your hands first.

    And yes..bring your own bowl because unless noted, it’s all free

    RE: Windows Roux

    • TinyApps.Org Blog : Computer hardware chart – Amazing find from TinyApps.  Great image detailing lots of different forms of connectors, ports, memory chips, CPU’s, etc.  Real work of love there.  Download and keep that image handy.
    • Mark’s Blog : The Case of the Temporary Registry Profiles. – More advanced than usual investigation of a software-error message.  Great tutorial on advanced troubleshooting techniques.
    • Debug 101: What does !analyze do? and Debug 101: What does !analyze do? – Ask the Performance Team blog continues its Debugging theme.
    • Updates: Autoruns v9.52, VMMap v2.2, procdump v1.2, procmon v2.5 – Microsoft Sysinternals tools update notices.
    • Updates: Autoruns v9.53, ProcDump v1.3, Process Monitor v2.6 – Microsoft Sysinternals tools update notices.
    • Updates: Zoomit 4.0, procdump v1.2 – Microsoft Sysinternals tools update notices.   Whew! Got em all?
    • PowerGUI 1.9 RTMs - Dmitry’s PowerBlog: PowerShell and beyond. Much updated version of a GUI manager for Windows PowerShell script building and management.
    • Upgrading from Windows 7 RC to RTM… you had to try it didn’t you? – MarkWilson.IT – Me? I’m planning on just copying my data off to a USB drive, doing a clean install, then reinstalling as needed.  Though I will make an ImageX image of all my systems’ partitions.  That way if I miss anything I can just mound the WIM’s and extract the data as needed.  Clean installs are always the way to go in my book.
    • WinFontsView: View samples of Windows fonts installed on your system. – New clever tool from NirSoft.  Very fast and handy.  I’ve personally been using the slick NexusFont tool but what Nir’s lacks in GUI polish it more than makes up in size and speed.
    • Update: UserAssist Tool Version 2.4.3 and see also UserAssist -- Didier Stevens – “The UserAssist utility displays a table of programs executed on a Windows machine, complete with running count and last execution date and time. Windows Explorer maintains this information in the UserAssist registry entries. My program allows you to display and manipulate these entries.”  Keep it handy as it’s portable.
    • LockHunter – A freeware utility that comes in both x32 and x64 bit flavors to delete stubborn locked files.  This version supports Win7.  Runs as application directly or from the Windows Shell integration.  For more locked file and process killers see grand stream dreams: I will kill thee a hundred and fifty ways ... post.
    • Sunbelt Blog: The 40 Most Popular Tools for Your System Admin Bag.  Excellent list and great descriptions.  I’m saving this to go back and explore some more.  Many tools are (proudly) found on my USB sticks.  There are some that are new to me as well in this list.  Can’t wait to start checking them out.  One of these day’s I’m going to take up an off-line challenge and work with a fellow blogger to come up with a collection of our own as my Portable SysAdmin Tools list is still good, it is quite light to what I now carry around and needs significant updating
    • What’s My Pass? » Tech Toolkit 2.0. – Amazing collection of sysadmin-worthy tools that are all USB portable in various forms.  Developer gets around the issue that others have run-afoul of in building such collections by using Ketarin to have the end-user (you) download all the tools directly from the developer’s own sites, rather than packaging them up himself.  Good stuff, but be aware, depending on your AV solution, many of the tools included (particularly those of Nir’s) may set off AV/AM alarms as hacktools or potentially unwanted programs (sigh).  Poor Nir.  Send him some love guys and gals.  I’d be lost without his brilliant tools and generosity in sharing with the community.
    • Malware causes "Access is denied" error – TinyApps blog.  Nice and simple tip for dealing with malware that renders exe’s un-executable.  Great CLI and CALCS info.

    RE: “Prettification”

    • Rainmeter – x32/x64 bit Windows desktop customization package.  Really amazing stuff.  Spotted via Rainmeter 1.0 Brings the Enigma Desktop to Everyone – Lifehacker post.  My desktops are covered almost full time when I am in front of them so I don’t get as much value out of these as I would wish. Thus give me a nice wallpaper, a good icon-dock (RocketDock), and maybe a larger calendar/task-manager (Rainlendar) and from time-to-time, stickys (PNotes Portable), a non-standard “official” MS theme (XP Embedded Theme – Cool Blue!) and my desktop is good to go on XP. I have found the default themes in Vista/Win7 sufficient, though the apps above come along for the ride.
    • Samurize.com – The above statement aside, the only time I really went “wild” trying to trick out my desktop with extra gadgets, I found Samurize to be my preferred desktop gadget-building tool of choice. Of course there are a lot more tools as well. See these older GSD posts: A BIG List of 34 Free XP and Vista Tweaking Apps and 20 Free Ways to Pimp Windows XP if you are curious.

    RE: A Hard Drive to Crack

    • Tableau Disk Monitor – free with registration – nice tool for providing information on hard-disks. Particularly from a forensics perspective.  Interfaces with supported read-write blocker devices as well (it appears).  I registered and downloaded it.  Requires installation. Has some handy extra features when used in conjunction with a Tableau disk bridge device. For more see these Pocket Hard-Drive Utilities post and more newer finds at this Tweak SharePoint and NAS Links post.
    • Atola Insight - ($6990 - $8990) (not free) – I have to confess I wasn’t really sure what to make of this.  From a feature-standpoint it definitely seems to have all the bells-and-whistles for just about any hard-drive servicing needed under the sun including firmware backup/restore and hard-drive password display/recovery/blanking. Atola Technology blog has more information and demos.  Before you run off because of the price, give them credit as they also are the producers of the free/pro versions of Partition Find and Mount — free partition recovery software which is simply an amazing piece of software and something every sysadmin should be familiar with.
    • Acronis® True Image Home 2010 Beta II – TinyApps blog recently brought to my attention that Acronis is accepting beta-tester signups for this application.  I’m mostly an ImageX guy for my imaging needs at work, as well as use a basic backup solution that came with my FreeAgent drive, but I must confess I haven’t really deployed an effective data-backup solution at home.  I hope I have some time to kick the tires on this one.
    • O&O Software - O&O DiskImage 4 Express – free version for home users – More of a real-time imaging/backup solution than a real-time backup solution.  Nonetheless, it still might provide a certain level of ease-of use and recovery for home users.  Version 4 reports some good feature updates.

    RE: Other Stuff

    • Java SE 6 Update 16 Is Here – SDN Program News.  Wasn’t auto-picking up on my systems with the Java Control Panel tool.  Manually get the update here..
    • ATI/AMD Catalyst 9.7 - first unified Vista and Windows 7 WHQL driver - Aaron Tiensivu’s Blog.  - I’ve been accepting the default drivers for Windows 7/Vista provided by Microsoft Updates.  However if both our systems did continue to have BSOD issues with the video driver (Catalyst…you would know), I might try this fix.  So far only been having them on Vista.  Win7 x64 bits (RC) is rock-solid stable so far
    • Recuva – file recovery app – lots of updates of late: View full version change history...
    • Paint.NET v3.5 Enhanced for Windows 7 - Windows Experience Blog – I love Paint.NET. Will be designed to use a special Win7 API to enhance some performance and rendering.  You can download an alpha build (build 3509) of Paint.NET v3.5 here.

    RE: Browsers

    • Namoroka, Portable Edition 3.6 Alpha 1 - PortableApps.com - “Standalone” portable version of the next-gen release of Firefox.  Use this to play with it without installing or changing your current version of Firefox.
    • Mozilla Security: Opt-in security with ForceTLS (Firefox add-on introduced) – Donna’s SecurityFlash.  Read carefully to understand the concept and impact of using this. Locking up the valuables: Opt-in security with ForceTLS at Mozilla Security Blog and Force-TLS :: Add-ons for Firefox.  For some reason I want to say I saw some comments that suggested that early adopters found some weird behavior (not malicious but just unexpected) when using this as it seems to be cutting-edge stuff.
    • Tab previews in Firefox 3.6. Third time the charm? - Mozilla Links.  Nice but I’d rather have a trim and fast browser in a small footprint.  I’m concerned about built-in bloat in Firefox growing. (As opposed to the bloat I add via my selected/desired Add-ons.)
    • Practicing safe surfing can derail attempts to cruise ‘Net anonymously - Network World.  I’m not sure this qualifies as “new” news, but is a good reminder that even anonymous web-browsing isn’t really all that anonymous.  Good read.

    RE: A/V Sweetness

    • hype-free: Basic multi-media (post)processing.  Great tips from cdman83 on post-processing along with some great freeware/OpenSource tools listed in the post as well as below.  Go read it and get better output.  See also this related “hype-free” post No codec packs please!
    • The Levelator – drag-n-drop processor to auto-adjust sound-levels in audio files. Sweet! 
    • VLC Media Player Portable – Who needs Windows Media Player? Not Me!.
    • The KMPlayer – My personal preference.  Seems to have all the codecs I need to play the audio/visual files I regularly encounter at work and home. Nice interface also.
    • ffdshow tryouts -  “ffdshow tryouts is a DirectShow and Video for Windows codec with support for a wide range of audio and video formats, such as Xvid, DivX, and H.264. It includes a powerful filter set that can enhance the video quality - with filters for resizing, deinterlacing, and displaying subtitles - as well as audio quality through normalization, down-/upmixing, and resampling.”  Bleeding edge versions also available that now support x64.

    Thanks cdman83!  Great tools all the way round.

    Cheers

    --Claus V.

    Read More
    Posted in browsers, Chrome/Chromium, Firefox, forensics, Link Fest, Microsoft, music, security, software, troubleshooting, tutorials, utilities, video, Vista mods, Windows 7, XP, XP mods | No comments

    Monday, May 25, 2009

    Kon-Boot: Bypass Windows Login Security (and some helpful blocking solutions)

    Posted on 11:41 AM by Unknown

    A number of weeks ago I received a tip from TinyApps.Org Blog that has become a real safari event.

    • KON-BOOT - ULTIMATE WINDOWS/LINUX HACKING UTILITY – free boot utility from Piotr Bania

    From the developer’s description:

    Kon-Boot is an prototype piece of software which allows to change contents of a linux kernel (and now Windows kernel also!!!) on the fly (while booting). In the current compilation state it allows to log into a linux system as 'root' user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password. It was acctually started as silly project of mine, which was born from my never-ending memory problems :) Secondly it was mainly created for Ubuntu, later i have made few add-ons to cover some other linux distributions. Finally, please consider this is my first linux project so far :) Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0.

    …it provides support for Microsoft Windows systems and also the Linux systems listed in the next sections. Kon-Boot for Windows enables logging in to any password protected machine profile without without any knowledge of the password. This tool changes the contents of Windows kernel while booting, everything is done virtually - without any interferences with physical system changes. So far following systems were tested to work correctly with Kon-Boot (however its quite possible other versions of listed Windows systems may be suitable as well):

    Windows versions of logins that it supports/bypasses are: Server 2008 Standard SP2 (v.275), Vista Business, Vista Ultimate, Server 2003 Enterprise, XP, Windows 7.

    Although not a “well-known” tool (yet), notice of Kon-Boot is slowly beginning to show up around the blog-o-sphere and security blogs.

    • Kon-Boot "root a box" on the fly .. it’s a kind of magic ! – Security Database Tools Watch

    • KON-BOOT for Windows and Linux (Password Bypassing Utility for Forgetting Heads) - DailyDave

    • Login to Windows Administrator and Linux Root Account Without Knowing or Changing Current Password - Raymond.CC Blog

    • Kon-Boot CD:110KB Floppy image/CD ISO to remove your Windows admin and Linux root pwd – Hacker News

    I’ve avoided posting on it for some time as (like TinyApps blogger Miles) I’ve felt compelled to first try to understand what it is, how it may be working, and what impact (negative/positive) it might have on a system.

    To use it, download one of the image files (I used the CD ISO) and burn the ISO file to a disk.

    Boot your target Windows system from the CD and you will get the Kon-Boot splash screen.

    Hit <Enter> or the spacebar to start the injection process.  If the BIOS/system “supports” Kon-Boot some programming checks will be displayed and the boot will hand off to the normal Windows loader processes.

    Once at a Windows login screen, enter the user account name you wish to access and bypass the password.  Note: you must know this ahead of time unless the user name is set to save/display automatically.

    Then you can either leave the password-field blank and click on through, or you can enter whatever garbage you want for the password. It doesn’t matter.  The password has been magically bypassed!

    I have tried it on a number of systems once I had some firmer knowledge of the tool and in my cases; it worked as promised.  Completely bypassing the Windows GINA login on XP systems as well as Vista and Windows 7 (of which the login’s don’t actually use the GINA method of XP/W2K, but it works anyway).

    Cool.  Very frightening from a sysadmin standpoint, but cool nonetheless.

    In my mind, it would be irresponsible to post a “come and get it” call for this tool without first trying to see if it left any malicious files, root-kits, or other “baddies” behind in it’s wake.  As well as to offer some mitigation suggestions.

    Thus begins the journey.

    What Kon-Boot Does on the Surface

    Many business (and some home users) who run Windows decide that one good method to protect their system from unauthorized access is to set up one or more (local system) user accounts.  These accounts then have passwords placed on them which (theoretically) should discourage unauthorized users from logging onto the system and accessing the applications and data.

    System administrators and Windows security folks know this is actually a pretty weak model.

    If that is the only security measures implemented on the system, then a penetrator/hacker/administrator just needs to apply one of a number of well known and documented methods to bypass the authentication.  Some of these methods include:

    • Ophcrack (and L0phtcrack 6) – cracking the password SAM files with tables

    • Offline NT Password & Registry Editor – blanking the password,

    • Yanking the drive and placing in another system to access the files directly, bypassing the OS, or

    • Booting with a “LiveCD” and accessing the files in place, again bypassing the OS.

    However, these techniques have some drawbacks.

    Ophcrack can/does work but unless the passwords are fairly simple, the attack can take some time to work and is not always successful in a reasonable amount of time.

    The Offline NT Password & Registry editor is quite successful in its methods, but by “blanking” the password, leaves evidence to the primary user that something has been breached.

    Yanking the drive or booting with a LiveCD are quite doable but may not be time-practical or hardware-practical solutions.

    Kon-Boot would allow someone to drop in, boot the system directly, bypass any Windows account login security, poke around under the local account, then pull-out without letting the end-user be any wiser.  Of course an incident response investigation might find some evidence tracks afterwards, but with the password left intact, it might take a while to notice the breach.

    On the other hand, sysadmins and Windows gurus who have to service systems often find user’s who have forgotten to provide them the password so I suppose it could be a useful tool for legitimate and authorized situations.

    What it Is / What it (May) be Doing Deeper

    Turns out Kon-Boot fits nicely into a class of hack/security tools called boot kits.

    These are an old and well-established small class of tools.  They have recently started to gain notoriety in security circles again with a number of newer exploit proof of concepts released.

    • eEye BootRoot – “…presented at Black Hat USA 2005 by researchers Derek Soeder and Ryan Permeh, as an exploration of technology that custom boot sector code can use to subvert the Windows kernel as it loads.”

    • eEye SysRQ2 – “…a bootable CD image that allows a user to open a fully privileged (SYSTEM) command prompt on Windows 2000, Windows XP, and Windows Server 2003 systems by pressing Ctrl+Shift+SysRq at any time after startup. It was first demonstrated at Black Hat USA 2005 by researchers Derek Soeder and Ryan Permeh as an example of applied eEye BootRoot technology.”

    • NVlabes Vbootkit 2.0 – a proof of concept tool which grants various abilities to elevate permissions to SYSTEM level, as well as start telnet server automatically and do some user-password manipulations.

    While similar to root kits, boot kits operate (generally speaking) a bit differently.  Depending on the specific boot-kit code they might inject themselves into the OS kernel during the boot process, patch memory registers, and then do their deed.  Some may be persistent.  By that I mean once loaded on a system they stay present after reboot.  Others may be memory-persistent only.  They are “installed” in memory, function, but when the system is reset no trace is left behind.

    Kon-Boot purports to be the later.

    Turns out there is a quite a lot of great and highly technical material on understanding the principles of boot kit methodologies.

    • 0wning Vista from the boot – SecurityFocus interview with Nitin Kumar and Vipin Kumar, developers of Vbootkit.

    • Nitin Kumar & Vipin Kumar: "please remember to give necessary credit to the authors" PKB. - [Dailydave] – Dave Korn analyzes the code in the Kumar’s Vbootkit and finds many close similarities with eEye BootRoot code.

    • VLAD Magazine - Issue #2 - ARTICLE.4_4 - BIOS Meningitis Source – BIOS-based resident boot kit.

    • eEye BootRoot BlackHat presenation  (PDF) – Detailed presentation by Derek Soeder and Ryan Permeh on the technical process behind the Windows boot process, and how BootRoot subverts the Windows Kernel.  Very, very good reading.

    • MBR Rootkit paper from VB2008 - Malicious Code - STN Peer-to-Peer Discussion Forums – Symantec also has an excellent technical paper (quite readable) on boot kit development and operation: The Rise of MBR Rootkits (PDF).

    • Stealth MBR rootkit – In depth analysis of a MBR root kit based on the eEye BootRoot code.  Not only shows code in comparison, but how the MBR root kit has evolved to avoid detection techniques.  Also provides links to MBR boot kit detection tools mbr.exe and GMER.

    • Vbootkit whitepaper (PDF) - Nitin Kumar and Vipin Kumar explain their boot kit exploit at Black Hat 2007.  See also their Vbootkit Presentation (PowerPoint).

    • D2T2 (PDF) - Nitin Kumar and Vipin Kumar explain their boot kit method in another presentation.

    • Dubai 2009 - NVlabs | Analyzing Security. Link to the Kumar brother’s presentation of Vbootkit 2.0 at Hack-in-the-Box Dubai 2009.  Note: this article links to the presentation notes Vbootkit 2.0 Attacking Windows 7 (x64) via Boot Sectors (ODP) which is an Open Office presentation format document.  Get OpenOffice, or OpenOffice Portable.  Microsoft also has a converter for ODP files.

    • MBR rootkit: VirTool:WinNT/Sinowal.A report – Microsoft Anti-Malware Engineering Team

    • MBR/Mebroot/Sinowal/Torpig is back – better than ever – TrustDefender Labs

    • MBR Rootkits – Securology Blog

    • Bootkit: the challenge of 2008 – Viruslist – Excellent historical review of boot kit history.

    • Malware evolution: January – March 2008 – Viruslist – Even more material on boot kit exploits.

    • Building malware defenses: From rootkits to bootkits – Noah Schiffman article from 2007. Light but good overview.

    Unlike eEye’s BootRoot and the Kumars’ Vbootkit, the developer of Kon-Boot, Piotr Bania, has decided not to release the Kon-Boot source code so examination is based (currently) on known technologies and examination of systems on which Kon-Boot was used.

    IANMR (I am not Mark Russinovich) but it seems that the process by which most root kits work is fairly well understood now.

    Based on what I have read and the research others have done on this and other boot kit tools that are "open" in the code, it likely hijacks the memory during the BIOS to bootloader process. From there it hooks INT 0x13 to control content of memory sectors loaded by NTLDR and begins patching areas of the kernel specifically dealing with the security profiles and user SAM files dealing with user logon authentication and the GINA/login-authentication processes. With these patched, the operator can access these profiles without any password input needed. What makes this tool (and Vbootkit) interesting is that they take the normal stay-resident MBR boot kit design and do it all on the fly (apparently) leaving no trace on the system behind. That's pretty sophisticated stuff. Particularly when it has been coded to work on both Windows as well as Linux kernels.

    Because of the BIOS memory injection it appears to perform, some system BIOS’s may not be supported and could cause Kon-Boot to fail. So it isn’t a 100% success in all possible conditions.  Also some users have said it BSOD their systems in various comments around the web.  Some have even reported it nuked their systems for unknown reasons.

    That certainly hasn’t been my experience. It was easy for me to get on a disk and booted all systems I tested it on with no ill effect (continue reading).

    Many of the links posted above referencing boot kits have great illustrations and diagrams on how this works exactly.  I wasn’t able to get permission to use material from those presentations, so go check them out for all the great pictures, descriptions and technical details.

    It is really fascinating and cool stuff on how the BIOS memory is hijacked, and how next the injected code in memory patches the kernel and tells it to ignore password requirements for the user accounts.

    It is also this shared similarity with MBR boot kits likely leaves some (as seen in various comments around the web) that it must be leaving a MBR boot kit behind.

    Does it Leave a Root Kit Behind?

    This is the million-dollar question.

    Many folks think so.

    Limited testing seems to suggest that, as Piotr claims, it does not leave any lasting or persistent changes to system on which it is executed.

    It is conceivable and technically possible it could infect the BIOS, MBR, as well as allocated/unallocated hard-drive space.  It might also change/patch critical Windows system files.

    I tested Kon-Boot post-usage via a suite of root-kit scanners and found nothing amiss.  But that may or may not mean anything.  What was really needed was a detailed baseline system scan using change-detection program, reboot and use Kon-Boot, then reboot and take another system scan to check for file/folder changes. 

    Fortunately for us, Miles Wolbe from TinyApps.Org Blog has taken this task upon himself to try to explore.

    He has graciously given me permission to post his findings.

    Miles’s plan was structured as follows:

    1. Save images of BIOS, CMOS, Video BIOS, and MBR with NSSI (run from bootable CD) and save snapshot of Windows install with InstallWatch Pro
    2. Boot with Kon-Boot, be amazed at password bypass, turn off computer
    3. Repeat step 1
    4. Perform diffs

    And his results were as follows (as combined from numerous emails):

    Here are the results of my Kon-Boot tests:

    Computer:

    Dell Inspiron 600m

    Changes to system after running Kon-Boot and then rebooting:

       MBR: none
       Video BIOS: none
       BIOS: none
       File system / registry: see attached ZIP file

    Tools used:

    Phoenix WinPhlash and dumpvgabios (BIOS and Video BIOS) as described here:

    http://icrontic.com/forum/showthread.php?t=30777

    NSSI (MBR and Video BIOS) Also dumps BIOS, CMOS, PCI, and more, but these did not work well for me.

    diff and md5 (comparison of dump files)

    InstallWatch Pro (file and registry changes)

    EFS file encryption is not circumvented by Kon-Boot. That is, if you bypass the login password for "Joe" via Kon-Boot and he has an EFS encrypted file named "doc.txt", you will not be able to open it ("Access is denied" message is returned).

    After bypassing login password with kon-boot, the user accounts applet shows "create a password" for the current user instead of "change password". if you try to enter a
    password, the following error appears: "Windows cannot change the password."

    Just to clarify: the strange user accounts behavior persists only while kon-boot is
    active.

    Please note that while Kon-Boot will let a user into the password protected Windows account, it will not allow access to any encrypted/password-protected files that would also have to be authenticated.  I guess that is something.

    Also, it does not seem to allow password-bypassing of Domain configured accounts or other network GINA supported authentication requirements. It only seems to work on Local Windows user accounts.

    I haven’t had the time to try it, but I would also like to capture a memory-image ( Tools:Memory Imaging - Forensics Wiki) of a system running normally, then recapture the memory-image while Kon-Boot is running, then difference the results.

    That might point out any memory resident changes Kon-Boot makes.

    So, as far as we can tell at the moment it appears--based on limited testing--that Kon-Boot should be “safe” to run on a Windows system you might be authorized to access.  However, I highly encourage you to do your own controlled and protected testing before making any such deployments organization-wide.  Don’t blame us if something bad happens.

    Messing around with boot kits and root kits is always a dangerous and dicey prospect.

    As someone once said, “Trust, but Verify.”

    Defeating Kon-Boot (Easy but Crippling Stuff)

    So how can the system administrator defeat Kon-Boot deployments and enhance security.

    Well some easy methods come to mind:

    • Set a password on the BIOS to require entry before booting,

    • Set a password on the Hard Drive (modern drives may support this) to prevent access before accessing from the hard-drive,

    • Disable USB/Firewire booting of a system,

      • Physical memory attacks via Firewire/DMA - Part 1: Overview and Mitigation (Update) | Uwe Hermann

      • www.storm.net.nz Projects

      • Burn ISO Image to USB Flash Pen Drive (Kon-Boot to USB) - Raymond.CC Blog

    • Disable PXE booting of a system,

    • Change the boot order to prevent (or disable) booting from CD/DVD ROM drives.

    Basically lock down the system so Kon-Boot can’t be used to boot the system.

    Yeah.  It will annoy your users to hell, but it will assist with security.

    However that may not be enough, or you may want to leave a certain amount of usability to the system.

    BitLocker and TPM Protection

    In a discussion with cdman183 at his Hype-Free blog he put me on another technique that seems very successful in blocking Kon-Boot/boot kit operation (assuming the MBR hasn’t been pre-infected); disk encryption / pre-boot authentication.

    Microsoft offers its Trusted Platform Mode (TPM) and BitLocker solutions that help authenticate supported OS versions during the boot process to ensure they have not been modified.

    • Trusted Platform Module - Wikipedia, the free encyclopedia

    • Windows Trusted Platform Module Management Step-by-Step Guide – Microsoft TechNet

    • Enabling Vista Bitlocker (without a TPM chip) – I Think I Broke It site

    • Using Vista’s Boot Manager to Boot Linux and Dual Booting with BitLocker Protection with TPM Support - Port 25: The Open Source Community at Microsoft

    • VBootkit vs. Bitlocker in TPM mode – Robert Hensing’s Blog contains some very good stuff so I’ve copied the items below from the above post (images not directly linked).

    Before explaining how BDE mitigates this attack the following picture may help set some context for the scenario. 

    This is what a 'normal' OS boot from a hard drive looks like when BDE has been configured to use a TPM 1.2 module.

    (NOTE:  There may be some slight innacuracies in the 'All boot blobs unlocked' column according to Jamie but they aren't really important for the concept I'm trying to illustrate. :))

    In a VBootkit system boot - I believe the boot process flow looks like this (any mistakes are mine)

    In the picture above - you can see that the boot process has been detoured a bit by the presence of a Vbootkit CD causing an additional MBR to be read during the OS boot (this MBR presumably then jumps back to the one on the HDD after hooking INT13).

    Well it is my understanding, based on my discussion with Jamie - that this will cause BDE in TPM mode to fail to boot the OS because the 'measurements' stored in the PCR in the TPM will be incorrect or will be unexpected in value - which will cause the TPM to fail to unseal the VMK which will lead to a boot failure. 

    What this all means is that when the boot manager (BOOTMGR.EXE) goes to unseal the VMK stored in the TPM 1.2 module - the TPM will respectfully decline. :)

    • BitLocker, TPM won’t defend all PCs against VBootkit 2.0 – Techworld – Basically the augment here is that it doesn’t work because many (most?) Windows OS versions are home/consumer version that do not contain the TPM support found in Windows Enterprise/Enthusiast versions.  Nor does all (mostly older) hardware support TMP solutioning.

    Solutions for the rest of us

    So what if you have a system that doesn’t support TPM mode protection against boot kit high-jacking and you don’t want to disable all the CD/USB/etc booting methods?

    Well, like I said, go with whole-disk encryption and/or pre-boot authentication.

    • PGP Whole Disk Encryption – This commercial solution offers protection against Kon-Boot.  I tested Kon-Boot against PGP WDE system. 

    The system allowed Kon-Boot to load normally, Kon-Boot injected itself into the BIOS memory handoff, and then I was presented with the PGP WDE loader.  It did not change the requirement to enter a valid passphrase at all. You could not bypass this requirement.  So I entered a valid passphrase and the Windows system booted normally. It appeared that the PGP to Windows boot loading process completely scrubbed Kon-Boot’s memory presence away as I was not able to log into the local Windows accounts (which Kon-Boot bypasses) unless I entered a valid password.

    Hurray.

    PGP is a commercial solution. While they do offer lighter versions for home/SOHO users, it may not be practical for folks on a budget.

    Fortunately at least two well known and trusted solutions are available for free.

    • TrueCrypt - “freeware” – This product offers whole-disk encryption and requires pre-boot authentication.

    In my test of this solution, I used a Virtual PC session of XP Pro.  I set a password and verified I could not log onto the account unless the correct password was used. Then I booted it with Kon-Boot and successfully bypassed the password.

    Then I used TrueCrypt to fully encrypt the drive, set a volume password and tested again.

    I booted the system again with Kon-Boot

    2009-05-09_113947

    Note that TrueCrypt could not boot the system and gave the following error:

    Error: BIOS reserved too much memory: 569

    It seems that once Kon-Boot had injected itself into the boot memory, there wasn’t enough left for TrueCrypt to do its thing and bring the system up.  So the boot kit hack failed.

    It is possible that different system BIOS may offer different amounts of available memory so this might not be fool-proof.

    But it is a start.

    The third solution is awesome:

    • CE-Infosys CompuSec – This German company offers a wonderful whole-disk encryption with pre-boot authentication solution.  It is 100% free.

    In my test of this solution, I used a Virtual PC session of XP Pro.  I set a password and verified I could not log onto the account unless the correct password was used. Then I booted it with Kon-Boot and successfully bypassed the password.

    Then I used CompuSec to fully encrypt the drive and set up pre-boot authentication with a password and tested again.

    I booted the system again with Kon-Boot

    2009-05-09_133053

    CompuSec caught a checksum error and refused to let the system boot.

    Rebooted without Kon-Boot, entered the pre-boot authentication password, and was on my way back to the protected system.  No Windows password bypassing was allows.

    Granted, CompuSec takes a while to configure once installed (it does install quickly).

    However, the developers provide almost unheard-of documentation and manuals on how to deploy, use and operate their product.

    It would be good advice to read all such things before using/installing such a product, but even more so for those that deal with encrypting your entire system.

    You don’t want to make a mistake here!

    Final Thoughts

    I don’t feel that I have done a good job really digging into Kon-Boot and boot kit threats.  There is so much technical information to process and a single blog post really can’t do it justice.

    I do hope that this humble post might lead the curious into exploring those better technical materials I posted by real security field experts, as well as encourage others to do like Miles did and perform their own system testing and validations of the tool.

    This is not new technology, though the implementations may be repackaged a bit. The security implications remain.

    General Windows Local user accounts are inherently insecure to knowledgeable penetrators and a variety of proven methods exist to breach these accounts.

    Solutions exist but they generally (by design) reduce the functionality and present numerous barriers for easy and convenient operation of Windows systems by users.

    Pre-boot authentication, TPM, and whole disk encryption methods might be the best (current) solution to protect against boot kits.

    It remains unknown it me (at this point) what would happen if a pre-MBR boot kit infected system had any of these solutions applied, post-infection.  Would the configuration fail? Would the MBR infection remain resident?  Would it work afterwards?

    Special thanks and public gratitude to both Miles and cdman183 for their work and guidance in helping me to understand the implications, verifications of, and mitigation solutions for this current round of boot kit attack.

    Like I said, really cool, but kinda frightening…

    Cheers.

    --Claus V.

    Read More
    Posted in boot-cd's, forensics, hacks, malware tools, Microsoft, security, utilities, Vista, Vista mods, Windows 7, XP, XP mods | No comments

    Saturday, May 16, 2009

    Updated: Goin' Win7 64-bit – It Rocks!

    Posted on 1:03 PM by Unknown

    Update

    This is pretty scary, in a good way.  Install of Win7-64 bit went off without a hitch.  Had it fully running in about an hour and half.  Performance is outstanding.  I can’t get a performance rating in that I am running off a VHD file drive.  However, subjectively, the laptop performance feels much snappier and crisper than in Vista Home Premium 32-bit.  I did have to spend an extra fifteen minutes figuring out my wireless setup.  I manually added my wireless network device, but Win7 just wouldn’t pick it up.  Then I found the setting to auto-connect to the router even if SSID broadcasting is off (it is on my router).  That did the trick.  During the on-line update process the system found a compatible NVidia video driver which is working fantastic.  The Vista 64bit printer driver is doing fine.  Because the vast majority of my applications are “portable” I just have to create new shortcuts to my “standalone” programs from their folder on the main drive.  The system isn’t having any trouble jumping out and running them from outside the VHD drive it is running directly from.

    Imagine that. Jumping to a Windows 7 64-bit install and zero, yes, ZERO driver issues so far.

    I’ve got quite a lot of “tweaking” of Win7 to do, but if it continues to run this smoothly, I’ll almost assuredly be standing in line to upgrade both our Vista Home Premium 32-bit systems to Windows 7 Home Premium 64-bit.  The XP desktop system will likely remain that way for the foreseeable future.  And the jury is still out on whether to upgrade the third laptop (XP Home) that Alvis uses or not.  I probably will.

    I’ve found that the XdN Tweaker that I have previously mentioned for XP/Vista tweaking has just released an updated version that is compatible with Windows 7.

    Lavie’s asking when her laptop gets the dual-boot upgrade to Win7 64-bit next.  I’ve got a whopper of a post planned for tomorrow, but maybe tomorrow night I will give her Compaq laptop the treatment as well.

    Two enthusiastic thumbs up for Windows 7 (RC) 64-bit! 

    --Cheers!  CV.

    original post below….

    Of course I would pick an inopportune time to do so.

    Leaving in about an hour and a half to take mom out for a belated-Mommy's Day dinner in Houston.

    Not the best timing to do a major OS dual-boot configuration.

    I'm setting my laptop up on Windows 7 RC with the 64-bit flavor this time, just to see if there is any real performance benefit in doing so.

    To keep things flexible, I'm choosing to dual-boot and retain my existing Vista Home Premium 32-bit system installation.

    I'm applying the steps in this GSD post:

    • GSD How To: Dual Boot Windows 7 on Vista via VHD file

    So far so smooth. It's going on very fast and no errors have been encountered.

    Lavie is already asking me when I'm going to set her laptop up that way!

    I'll give a report later tonight (if I'm not too full and tired from the dinner outing)!

    Cheers!

    --Claus V.

    PS--been watching the Shuttle servicing mission live today on NASA TV. Really cool and amazing stuff.

    Read More
    Posted in Microsoft, virtualization, Vista, Vista mods, Windows 7 | No comments

    Sunday, April 5, 2009

    Economic Stimulus Package Linkfest

    Posted on 2:59 PM by Unknown

    Lots of links. Just spreading the wealth around…

    • Tenable Network Security: Root Is Just A Few Clicks Away – Reminder on why I prefer to pave systems (and OEM partitions) and build a system OS load from scratch.

    • Comodo EasyVPN Software Download for Free VPN Network Encryption – I didn’t know that Comodo provides a free turnkey VPN solution. They do. Sure it is closed-source, but for non-technical folks who are looking for a simple and free solution and don’t want to configure one of the many Open Source VPN solutions out there, this might be worth looking into.

    • hype-free: How does the Panda USB vaccination work? – Ooooh! Really great and well done analysis on the behind-the-curtain mechanics of this tool. Well worth reading before using.

    • How To Change Windows 7 Logon Screen Easily [Without Using Hacks & Tools] | Into Windows – Because you know you want to scratch that itch.

    • Virtual PC Guy’s WebLog : Quick Fixed VHD Creation Tool – Pretty clever little tool. Of course, turns out Windows 7’s DISKPART Tool can do a similar trick via CLI.

    • VHD tool – Home - (see above). Main tool source if you are in a hurry to create your own VHD’s

    • Copy Multiple Files On Your Computer With RichCopy (Windows) | MakeUseOf.com – I’ve downloaded it and installed it. I’ve played with it very little so far. Lack of shell integration is the biggest drawback.

    • Keith Combs’ Blahg : RichCopy bulk file copy tool released – get it here - (see above). Main tool source if you are in a hurry and want a bit more background information.

    • Drive Tools for Windows – lots of niche CLI tools for drive work. See also the AutoRun Settings tool on that page. Nice GUI based tool that lets you manipulate many autorun configuration elements.

    • TinyApps.Org Blog : A better NOD32? – Great find and perspective of a new micro-scan tool. I say “micro-scan” as this A/V-A/M tool uses a single EXE file that is remarkably small to get the entire job done. Only “drawback” is that the DAT files are pulled down “real-time” so you must have a live network connection to make it work effectively. Pretty refreshing approach after many of the other bloated applications with file counts running into the hundreds or more.

    • Prevx Edge - (see above). Main tool source if you are in a hurry to get on with it.

    • Eraser – Freeware secure erasing tool has gotten a radical site update.

    • Eraser 6-rc4 released! – Amazing new and fresh GUI to Eraser. Still has some bugs to be worked out. Looks like it will be a great update when finally released. Not sure if it will survive in a “portable” mode release as I think .NET will be required moving forward.

    • InstallingBetas – Eraser – Read this page as well as you need to download a signed security certificate to install the latest Eraser beta versions. Not that big a deal, but a bit of work.

    • Disk Redactor – New free disk freespace wiping tool (portable) that I found this week. I like the interface and it seems to run very fast.

    Side note: Is it just me or do none of these freespace wiping program tools seem to work under Vista very well. I think I’m missing something here. I’ve been playing with them and I can run DiskDigger and find a large number of deleted (but recoverable) files. Then I do a freespace wipe (as admin level) using either of these tools. Then I rerun DiskDigger and the files are still all there and recoverable. Surely I’m doing something wrong? It’s not just the “names” but the actual files themselves as I can preview most of them just fine in the clear. Thoughts?

    Update -- Turns out this issue looks like a "Doh!"moment. I went back and re-read the DiskDigger product info and on the page (linked above) found this tidbit: "Because DiskDigger bypasses the file system of the device being read, it will detect files that haven’t been deleted in addition to files that have. This means that you might have to sift through files that still “exist” in the file system before you find a file that’s actually been deleted. However, the Preview feature makes this process quick and painless."

    Looks like the freespace was probably getting wiped effectively after all. DiskDigger is just displaying all files it finds. I'm going to have to retest with Recuva as I believe it only reports truly "deleted" files. That and do some sector-based testing as well (create file, observe sector location, delete file, wipe freespace, go back with sector viewer tool and see if now gone).

    • HelixCE Community Edition - Download HelixCE200401brc1.iso RC1!!! – The community edition of Helix looks to be near relase. For some reason the ISO link isn’t working at the moment. Maybe it will be up early this week? Looking forward to seeing how the efforts are playing out here.

    • DEFT Extra (Windows Forensics GUI 1.0) and DEFT v4.2 DEFT Linux - Computer Forensics live cd – The DEFT crew is getting ready to release what looks to be a bang-up version this week. Looks to have an exciting “run-on-Windows” launching tool like CAINE or HELIX3 both have.

    • Ophcrack – New version with some new features is released.

    • Offline NT Password & Registry Editor – If you can’t crack it, reset it. I somehow missed that an updated version of this Windows 2000/XP/Vista/(Windows 7?) tool got released in August 08. Had to snag this newer version.

    • Offline-Update 5.2 with Internet Explorer 8 – New version now supports IE8 deployments (or not). Arguably one of the two or three best off-line Windows system updating and patching tools out there. If you are a sysadmin, you had better be familiar with this tool. If you are the family-IT support guy or gal, it is well recommended to keep an updated and packed version handy on your USB stick or CD before you go visiting.

    • PDFiD « Didier Stevens – Neat free tool to look for exploits in PDF files. Cool!

    See ya!

    --Claus

    Read More
    Posted in anti-virus software, boot-cd's, command-line interface, forensics, hacks, Link Fest, security, utilities, Vista, Vista mods, Windows 7, XP | No comments

    Saturday, March 21, 2009

    GSD How To: Dual Boot Windows 7 on Vista via VHD file

    Posted on 4:22 PM by Unknown

    I love and depend on virtual machines to test software and system configurations.

    In most cases, it is sufficient for my testing purposes.

    One drawback of this is that it isn’t a “true” test of the operating system’s performance since the hardware used is being virtualized via software.

    There are lots of guides around the net as well as utilities that can assist you in configuring a system to “multi-boot” different OS versions off the hardware, but these can be a bit challenging to set up for average folks.

    Recently, while I’ve been playing with Windows 7 Beta in Virtual PC 2007 sessions, I’ve been itching a bit more to try the performance on real hardware, but I haven’t wanted to commit to wiping one of my systems entirely clean first.  Nor did I want to fuss with a pure Vista/W7 “dual-boot” configuration as they traditionally are done.

    Instead, I knew that Windows 7 brings with it an exciting new feature, that is perfect for this particular case; it supports booting a system from a VHD file.

    However, I’ve got a slight issue.  Windows 7 uses updated bootloader files to make that happen.  Windows Vista uses similar files, but those versions don’t support VHD booting.

    I don’t want to install Windows 7 to be able to boot a VHD of Windows 7; that kind of defeats the intended purpose for me.  Most all the guides on doing this only describe how to pull it off that way. No, what I want to do is to keep my local Vista install intact, and somehow boot into a VHD of Windows 7…thus running it “live” on the real system hardware instead of on virtualized hardware.

    Can it be done?

    Yep.

    I’ve had to pick at a number of posts to spin this thing together.  Credits for source material in all their fantastic goodness at the post end but up front, prime props and hat tips go to Aviraj Ajgekar and Adrian Kingsley-Hughes. I’ve copied some of their steps because they were so good, I had little to add.

    You will need a couple of things first:

    Ensure you have a copy of a Windows 7 beta setup DVD handy. You can use the ISO file itself to get started however you will need the burned DVD at some point.

    I also found it helpful to use my WinPE 3.0 custom boot disk.  This is optional, but could be handy.

    And you will need a Vista-installed system.

    Warning: proceed at your own risk. You might tank your Vista system if not performed correctly.  I recommend practicing on a Virtual PC VHD with a Vista install first a few times.  What has worked fine for my on my system might be an issue for you. The screen shots included in this post were obtained from a walkthrough of these steps as performed in a Virtual PC session with the free Microsoft Vista IE App Compat VHD as the primary OS.

    Step One: Extract the key Windows 7 system boot files.

    We need two key files from a Windows 7 system to get things started on our Vista system.

    They are the BootMgr file located on the root of the Windows 7 system as well as the BCDEdit.exe file from the Windows 7 Windows\System32 folder.

    There are a couple methods you can use to get them:

    • from an already installed Windows 7 system,
    • from a virtual Windows 7 installed system,
    • extract them from the Windows 7 DVD/ISO.

    The first one is easy, assuming you are running as an “administrator” and have enabled the ability to show hidden and system files, you could just copy them to a USB stick.

    The second method is a bit more tricky.  Virtual PC does not support USB devices, so you will have to change the settings to allow it to mount a local “real” system folder, then copy them into there so you can off-load them to a USB stick.

    For both of these options you basically can follow the following steps:

    From the Windows 7 desktop, open an elevated command prompt with Administrator Privileges and type the following commands.

    C:\windows\system32>xcopy /h /y bcdedit.exe f:\   

    (Note: In this case, F: is the external USB stick.  /H - Copies hidden and system files.  /Y  suppresses prompting to confirm you want to overwrite an existing destination file.)

    C:\>cd\

    C:\>xcopy /h /y bootmgr f:\

    If you can’t find the second file,even as an elevated admin, you will have to use a Vista or Windows 7 boot DVD to boot the system and then do a Shift-F10 to get a sufficiently elevated command prompt to access it.

    The third option is involved, but I found it easy as well.  On your Vista system, use an application that allows you to mount the Windows 7 beta setup DVD ISO as a drive letter.  I used SlySoft Virtual CloneDrive as it is a free and stable tool.

    Once the ISO is mounted, you will find the bootmgr file on the root of the drive. Copy it to your USB drive and you should be able to do so using a file manager that has been set to show hidden/system files.

    Then using ImageX, go into the mounted ISO directory structure and mount the \sources\install.wim file. 

    Once mounted, browse into the folder you set as your mounting folder and look in the Windows\System32 folder for the BCDEdit.exe file.  Copy it to your USB drive.

    Then go back and dismount both the WIM file and the ISO file in turn.

    Got em both?  Good.

    Step Two: Back up the original Vista boot file versions

    Now it gets a bit scary.

    First you want to make backup copies of the Vista versions on your Vista system:

    Boot your Vista system and once on your desktop, open an elevated command prompt with Administrator Privileges and type the following commands.

    C:\windows\system32>cd\

    C:\>xcopy /y /h bootmgr bootmgr.sav

    Press f after prompted

    C:\>cd Windows\System32

    C:\windows\system32>xcopy /y /h bcdedit.exe bcdedit.sav

    Press f after prompted

    Step Three: Replace the original Vista boot file versions with Windows 7 versions

    Now it gets a bit scary.

    We must replace the Vista versions of BootMgr and BCDEdit.exe which do not support VHD based booting source with the Windows 7 ones we copied earlier, which do. 

    You may use a WinPE 3.0 boot disk or your Windows 7 Boot DVD and Boot into Windows Recovery Environment.  This is important as WinPE 2.0 and the Vista setup DVD don’t have the updated Windows 7 version of DiskPart that we will need. 

    Insert the USB drive you have copied the Windows 7 versioned files onto into the system as well.

    If you use a standard WinPE 3.0 disk, you should be greeted with the CMD window.

    If you are using a Windows 7 setup disk then boot the system from the chosen disc. Once the Windows installer is up and running, choose your language and once you’re on the Install now screen, press SHIFT+F10 to bring up a Command Prompt.

    Open the Elevated Command Prompt and type the following commands.

    C:\>attrib bootmgr –s –h –r                    

    (Note:  in this case C: is the local Windows Vista OS Partition and the attribute command with –s –h –r changes the System, Hidden and Read Only attributes of our target file.)

    C:\>e: 

    (Note:  in this case E: is our USB stick.  You might need to check to make sure what your USB stick is showing up as.  Note as well that depending on where you copied it onto the USB stick, you might have to add additional file directory information.  The examples below assume both Windows 7 files were copied to the root of the USB stick.)

    E:\>xcopy /y /h bootmgr c:\bootmgr

    E:\>xcopy /y /h bcdedit.exe c:\windows\system32

    image

    (Note: in the above screen-shot I took, I made a slight change in the instructions above and had pre-copied the Win7 boot files to a C:\win7 folder on my Vista system.  That’s why those commands vary slightly from the ones provided above.  Adjust accordingly.)

    Step Four: Create the VHD file we will be installing Windows 7 into

    We are committed now!

    Note: Adjust the MAXIMUM value as needed but note, you better have enough free space on your local hard drive to support it!  I would recommend somewhere between 15000 and 25000 to create an (approximately) 15 GB to 20 GB VHD partition to install Windows 7 into.  Choose your VHD location wisely.  I put mine on the local system hard-drive root.

    We should still be in the Windows 7 CMD prompt box so type the following commands.

    DISKPART

    CREATE VDISK FILE = "c:\win7.vhd" MAXIMUM = 20000

    SELECT VDISK FILE = "c:\win7.vhd"

    ATTACH VDISK

    CREATE PARTITION PRIMARY

    ASSIGN LETTER = G

    FORMAT QUICK LABEL = Windows7

    EXIT

    This just created the VHD file of primary partition into which we will next install Windows 7.

    image

    (Note:  In the above example I first tried to assign drive letter = X but that would not work as X was already assigned as the RAM disk used by the Windows 7 Setup DVD boot.  That’s why I switched to “G” instead"!)

    Step Five: Install Windows 7 into the VHD file

    Type Exit again to get out of the command prompt and return to the Windows 7 installer Wizard.

    Continue with the installation steps as normal and when prompted, choose “Custom install” so we can tell it where to place it.

    When prompted by the “Where do you want to install Windows” if all is well, you should now find a Disk1 reporting in as Windows7 free space = to approximately what you selected for the MAXIMUM amount in the preceding step.

    Select that one and continue on.

    image

    You may see a warning of sorts about Windows7 not being able to be installed to (or boot from) that disk.  Just ignore it and after selection, hit “next” and continue with the installation process.

    Step Six: Boot Windows Vista or Windows 7

    After you reboot, you should see the Windows Boot Manager prompt you to select Windows Vista or Windows 7 to boot into.

    image

    Select Windows 7 to boot into your Windows 7 VHD and run off the real hardware.

    Select Windows Vista to boot into your original Windows Vista installation.

    Cool!

    image

    Note in the above screen shot, the “primary” hard-disk shows up as drive letter D: with all the files\folders accessible while the Windows 7 VHD file “win7.vhd” becomes the “new” drive C:.

    Remediation

    I haven’t had to “roll back” to Vista only, but basically you will use the techniques listed here to simply restore the original Vista versions of the boot files you made (you did follow that step right?) over the Windows 7 versions after rebooting the system with the Windows 7 DVD again.  You shouldn’t have to reuse diskpart to detach the VHD.

    Note also that even though you replace the bootmgr and bcdedit.exe files back to the original Vista versions, a reboot will still show that Windows7 is listed along side the original Vista install.

    To remove that out, you will have to also (from the Shift-F10 elevated command prompt with either a Vista Setup DVD, Windows 7 Setup DVD, or a Win PE 2.0/3.0 boot disk, run a bcdedit.exe command.

    This is what I did on mine, but you need to be careful it is accurate for yours.

    Run bcdedit.exe first to list the boot stores and figure out which one Windows7 is reporting as.  In my case it was {default}.

    So to remove Windows7 from the boot configuration data store list I issued the following command:

    bcdedit /delete {default}

    Rerunning the bcdedit command showed all was back to normal and the Vista boot store information had been updated as the default (and only) OS boot choice again.

    A reboot and all was restored to the normal Vista only booting.

    Then once you are up and running Vista alone again, delete (if desired) the Windows 7 VHD file you created if you feel you no longer need it.

    For more tips on Vista/Windows7 boot configuration management tool BCDEDIT (as well as an incredible GUI alternative EasyBCD) see these links:

    • BCDEdit Command-Line Options – Microsoft TechNet

    • Remove boot menu item ,bcdedit – TechArena Community - Operating Systems forum

    • EasyBCD 1.7.2 - NeoSmart Technologies

    Additional Reading and Credits

    I found the following posts very informative about both the VHD booting support feature of Windows 7 as well as how to apply this to a Vista installed system.  I recommend reading and understanding them first before you set off to follow this post.

    They also contain great screen-shots of much of this process, as well as few variants of the technique I outlined here.  You might find things more clear after reviewing them as homework before life-fire application of this hack.

    • Boot Windows 7 from a VHD – 4sysops blog

    • Mount, attach and create VHD files in Windows Vista and Windows 7 – 4sysops blog

    • Windows 7: Boot from VHD First Impression: Part 3 (Booting VHD from Vista SP1 or later) - Aviraj Ajgekar’s Blog

    • Windows 7: Boot from VHD First Impression: Part 1 - Aviraj Ajgekar’s Blog

    • Windows 7: Boot from VHD First Impression: Part 2 - Aviraj Ajgekar’s Blog

    • How-to: Getting started with .VHD files in Windows 7 - Adrian Kingsley-Hughes Hardware 2.0 ZDNet

    • Virtual Hard Drive VHD File - Create and Start with at Boot – “Brink” at Windows 7 Forums

    • Boot from VHD and WDS – The Development Guys

    • Installing Windows 7 using usb thumb drive - Aviraj Ajgekar’s Blog

    And once again, I strongly encourage you to try this out on a Vista VHD file in Virtual PC first, to make sure you can follow and successfully pull off these steps.  It’s easy to practice until you are sure of yourself before taking on your “real” Vista installation.

    Now get out there and have some fun, and see the difference in system performance between Vista and Windows 7 on your real desktop or laptop system!

    Cheers.

    --Claus V.

    Read More
    Posted in boot-cd's, hacks, Microsoft, tutorials, virtualization, Vista, Vista mods, Win PE, Windows 7 | No comments
    Older Posts Home
    Subscribe to: Posts (Atom)

    Popular Posts

    • New Year’s Day - First Post 2011
      Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
    • Oscar watch Linkpost
      Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
    • Finally! Time to Post! New material list
      After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
    • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
      A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
    • iodd : Multi-boot madness!
      Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
    • Network Capture Tools and Utilities
      At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
    • It just has to be bigger on the inside…
        Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
    • Mostly Minor Network Notes
      Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
    • Windows Live Mail error 0x80041161
      Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
    • FireCAT 1.5 “Plus” Add-On Collection
      In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

    Categories

    • Active Directory
    • anti-virus software
    • Apple
    • architecture
    • art
    • AVG
    • Blogger
    • blogging
    • books
    • boot-cd's
    • browsers
    • cars
    • cell-phones
    • cheat sheets
    • Chrome/Chromium
    • command-line interface
    • cooking
    • crafts
    • crazy
    • curmudgeon
    • DHC
    • Dr. Who
    • E-P1
    • Education
    • family
    • Firefox
    • firewalls
    • For the Gentleman
    • forensics
    • Gmail
    • Google
    • graphics
    • hacks
    • hardware
    • humor
    • hurricanes
    • imagex
    • Internet Explorer
    • iOS
    • iPhone
    • iPod
    • iTunes
    • Kindle
    • Learning
    • Link Fest
    • Linux
    • malware tools
    • Microsoft
    • movies
    • music
    • networking
    • NewsFox
    • NFAT
    • Nook
    • Opera
    • organization
    • PDF's
    • photography
    • politics
    • PowerShell
    • recipes
    • Remote Support
    • RSS
    • science
    • Scripting
    • search engines
    • security
    • Shuttle SFF
    • software
    • Texana
    • Thunderbird
    • troubleshooting
    • TrueCrypt
    • tutorials
    • utilities
    • VBscript
    • video
    • Virtual PC
    • virtualization
    • viruses
    • Vista
    • Vista mods
    • wallpapers
    • Win FE
    • Win PE
    • Win RE
    • Windows 7
    • Windows 8
    • Windows Home Server
    • Windows Live Writer
    • Windows Phone
    • writing
    • XP
    • XP mods
    • Xplico

    Blog Archive

    • ▼  2013 (83)
      • ▼  November (8)
        • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
        • ForSec Linkfest - 2013 DST Fallback Edition
        • CryptoLocker Ransomware Info & Free Prevention Sol...
        • Linkfest for the SysAdmins
        • Microsoft Security Essentials/Defender & PowerShell
        • Miscellaneous TrueCrypt linkage
        • PowerShell 4.0 and a tiny “gotcha”
        • New Software Updates + VMware Tools Update fix
      • ►  October (8)
      • ►  September (14)
      • ►  August (6)
      • ►  July (10)
      • ►  June (10)
      • ►  April (11)
      • ►  March (6)
      • ►  February (7)
      • ►  January (3)
    • ►  2012 (96)
      • ►  December (8)
      • ►  November (4)
      • ►  October (9)
      • ►  September (8)
      • ►  August (12)
      • ►  July (4)
      • ►  June (3)
      • ►  May (7)
      • ►  April (13)
      • ►  March (3)
      • ►  February (5)
      • ►  January (20)
    • ►  2011 (41)
      • ►  December (8)
      • ►  November (7)
      • ►  September (4)
      • ►  August (4)
      • ►  July (2)
      • ►  June (6)
      • ►  March (5)
      • ►  February (1)
      • ►  January (4)
    • ►  2010 (69)
      • ►  December (1)
      • ►  October (3)
      • ►  September (2)
      • ►  August (13)
      • ►  July (17)
      • ►  June (3)
      • ►  May (3)
      • ►  April (3)
      • ►  March (11)
      • ►  February (1)
      • ►  January (12)
    • ►  2009 (177)
      • ►  December (20)
      • ►  November (11)
      • ►  October (7)
      • ►  September (7)
      • ►  August (21)
      • ►  July (17)
      • ►  June (7)
      • ►  May (18)
      • ►  April (9)
      • ►  March (17)
      • ►  February (23)
      • ►  January (20)
    • ►  2008 (35)
      • ►  December (23)
      • ►  November (12)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile