Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, August 15, 2009

Adobe Tip: Add filename to footer

Posted on 12:23 PM by Unknown

Quick tip:

I create and receive quite a few Adobe PDF files in the course of my work.

Most are “complete” documents with names/descriptions prominently placed in the header or as a “title” somewhere on the page.

However, more than a few times I have been sent documents that are pretty similar in content and style but don’t really have any other distinguishing features to help me tell them apart when printed out

I wanted a way to quickly add the file-name of the document to the footer.  Having a date would be useful as well.

I use Adobe Acrobat Professional v8.0 at work for (most of) my PDF processing.  I checked all the information and screens I could, but nowhere in the print/page setup or options could I find that feature.

I turned to the Adobe forums and found this thread.

Adobe Forums: Print File Name with pdf Document

LReinhardF (Reinhard Franke) responded that the solution must be “hand-made” via a Javascript routine that is added to the Adobe program’s javascript folder.

He posted the last version of his code at http://www.refob.de/downloads/Acrobat/SetRemoveFooter.js

Right-click on that link and save it to the appropriate folder. \program files\adobe\acrobat "X"\javascript

Restart Adobe and it will appear as a option pick under the File menu approximately above the Print section.

It was a fast and simple solution that now allows me to better manage the hard-copy PDF printouts I use.

Note: this doesn’t apply to Adobe Reader.

There are some additional tips and Javascripting tweaks on the first page of that forum post.  The second page also has some more tips and information on doing the same thing but with header-inserts.  I was happy with the original solution, but if you are looking for more, keep reading the forum thread onto the 2nd page.

Cheers!

Claus V.

Read More
Posted in hacks, PDF's | No comments

Monday, August 10, 2009

Focus on Forensics Linkfest

Posted on 6:41 PM by Unknown

Last week was wild at work.

Not only did I get to borrow some neat hardware for drive work, I also tried to provide some perspectives and opinions on “forensically-sound” image capture.

On top of that, I also had just enough time to really play with Harlan Carvey’s RegRipper on a real (non-investigation related) image capture.  More on that later in the post.

It was a very crazy week but I felt oddly satisfied; that I had begun to get a handle on some nagging things.

Documentation is Everything

Shop-talking this week about incident-response in general, and “what-if” scenarios, I had the opportunity to share the importance of establishing and documenting what was done when a suspect system is focused upon.  Please note: I am not a forensic expert (IANAFE) but there are some some basic common sense things that need to be done.  Particularly when it isn’t clear at the onset if the system drive will just be wiped and reimaged or if it needs to be officially escalated to internal or external law-enforcement groups.

As such, it seems imperative that the responder approach the system with the thought in mind of preservation of the machine state as well as documentation of what was done; just in case one has to explain what occurred with the drive/system along the way.

As I don’t personally have any such standard templates that would fit the bill, I had to go looking for some that we could use in a pinch.  Luckily I found enough to get me covered for now, and certainly will inspire me when I have the time to design our own.

  • forensic it chain of custody document – docstoc – search page for related documents of that theme.  There were quite a number of good looking forms.  I didn’t have time to try to figure out the download process, but even then, I was able to view them and get a better sense of what I was looking for.

  • Forensic Bibliography – E-Evidence Information Center – great resource page with lots of direct links to PDF and other documents related to evidence collection worksheets, search-warrant templates, and chain-of-custody tracking.  I snagged more than a few forms from this site.

  • NHTCU Good Practices Guide for Computer based Electronic Evidence - (PDF) – Useful whitepaper that discusses issues and processes needed around electronic evidence collection.

  • Sample chain of custody form – United States Department of the Navy.

  • USSS Best Practices Guide to Seizing Electronic Evidence v3 – United States Secret Service “pocket-guide”. Update: it has been noted and observed in the post comments that information in this guide seems dated (internal pdf properties give a document year of 2006).  And as commenter Erik notes the guide mentions pulling network connectivity and powering system off. Yet as incident responders know; obtaining network traffic captures (at least for a period) as well as running system memory dump/image, and process/port/endpoint mappings could provide additional clues and information that will be irrevocably lost if the system is simply powered off almost immediately upon seizure. -cv.

  • Authors for Hacking Exposed Computer Forensics – WaybackMachine Internet Archive – The original site of this book appears gone, but some of the links back to forensic checklists, kit suggestions, and forms still live on. Found a few more goodies here.

  • Technology Pathways Resource Center – Technology Pathways – Simply one of the best collections of updated and current forensic documentation, whitepapers, tool downloads, and general subject material there is out there; period.  A must-bookmark page.  I only wish it had an RSS feed to monitor for updates.

Image Capture: Forensic Style: Part One

As I mentioned, I finally got my hands on a Windows system that seemed great to use as a test-bed.  I had worked the better part of a morning a few weeks ago prepping a special-build XP Pro system-deployment to be used for hand-on-testing of applicants to our team.  I took a base system image for the hardware used, then stripped off all the non-essential applications, removed some accounts, set it up to auto-log-in to a restricted user account desktop (after a successful boot by the applicant).  It worked great and I dusted off some cobwebs from my brain in the process.  When done I captured an ImageX WIM of the system, to make redeployment easy in the future of this particular one-use system.

Before I wiped and reimaged it (I use it for image-building for that particular hardware model) I figured now was a great chance to try to practice capturing a “forensic” image file and then have it to practice on.

The first step was getting a forensically “sound” image of the drive.

To do that corrected with no doubt, it is clear that the preferred method is to use a physical write-block device in-line between the drive and the OS used to capture the image.  Something I don’t (yet) have.

I’ve been looking between two primary models:

  • Tableau T35es eSATA Forensic Bridge – Tableau Forensics Products – Seems to support just about any type of drive type there is. I’m not sure if all the drive type connectors are included or extra.

  • Forensic ComboDock™ v4 and the Combo Adapter kit  from WiebeTech.  This seems to be one of the standard-issue devices mentioned in many forensic blogs.

I’m not sure which would be better but luckily I was able to find a very current review by a forensic professional that seemed to provide a great comparison between the two.

  • Computer Forensics - Write Blocker Review - 23/07/09 – reviewed by David Kovar of NetCerto, Inc.

It seemed to find both very good choices, though the Tableau product seemed to have the edge.

They are pricy (if self-bought) seeming to fall in the $250 - $300 range (with cable sets). But seem a critical piece of hardware for forensic-level system captures.

A non-forensically-sound alternative would be a USB drive adapter such as one of these.

  • Rosewill RCW-608 USB2.0 Adapter For IDE/SATA Device (Include Protection case) - Adapters & Gender Changers – Newegg.com.

  • VANTEC CB-ISATAU2 SATA/IDE to USB 2.0 Adapter - Adapters & Gender Changers – Newegg.com.

Definitely, these provide NO physical write-block protection, though they do offer a convenient way for a support technician or analyst to test and recover files/system off a drive externally. 

In fact, I was able to borrow Mr. No’s Vantec device and test a slew off drives we’ve had on the shelf and sort the good from the bad, in addition to wiping the good ones. I’ll be ordering the Rosewill model soon for my own personal use.  Price for these ranges from $15-$35 depending on brand and features.  Local deals may be even better.

Image Capture: Forensic Style: Part Two

Since I didn’t have a real write-block device, and it was just a test-system capture, I chose to just use a forensic LiveCD to capture the drive-image from the internal drive and save the image to a USB attached storage drive. In theory these disks attempt to provide a software-based OS write-blocked access to the suspect drive for image capture and/or examination.  As I have learned, that may be nice but only a physical write-block device (properly used) can guarantee no write-back to the suspect drive.

For a free solution here are the ones I considered for this exercise…certainly not a complete list of options and some well-known names have not been included in this particular post.

I could have used a  Windows FE boot disk to do the work, then run Data Recovery Software by ADRC to capture a RAW or IMG single-file image, including all the sector info from the physical drive.  It isn’t specifically for “forensic” grade image capture but it would have given me a single-file image in a format I could mount as a virtual drive for examination.

Or I could also have used the Win FE/PE disk along with FTK Imager / FTK Imager Lite from AccessData.  It allows capture of a physical drive in several forensic formats along with dd format. (For more info see this Forensics 101: Acquiring an Image with FTK Imager – SANS forensics blog post).

Or I could also have used the Win FE/PE disk along with ProDiscover Basic from Technology Pathways.  It allows capture of a physical drive in the Pro Discover format along with dd format.

Or I could have used the Win FE/PE disk along with the DEFT Extra pack on a USB stick.

Then for a non-Windows “forensics” level option, I considered using my copy of the RAPTOR Forensic LiveCD maintained by Forward Discovery.  See this excellent post Unsung tools - Raptor Forensics by hogfly at his Forensic Incident Response blog for a how-to.  Hogfly covers the MAC edition of the disk, but I use the Windows version.  Process is pretty much identical.

Or I could also have used the CAINE Live CD for a forensic image capture. Its collection tool set includes both Automated Image & Restore (AIR) as well as Guymager to capture a physical drive in several supported formats, including dd format.

In the end, however, I went with the DEFT Linux forensic LiveCD distro and the guymager application.

With that, I captured a single dd file image of the 165 GB SATA internal physical disk 0 to the USB attached hard-drive in just over an hour.

Easy Peasy.

Mounting the captured (dd) image file

I wanted to now mount the single dd image file to my primary Windows system as a virtual physical drive so I could look at the sector information, run some tools against it, etc.

What to do?

Harlan Carvey covers most all the bases at his Windows Incident Response: Mounting a DD image post. It excellently covers all the major bases.

I first tried ProDiscover Basic and it certainly had no problems handling the task.  In addition it provides some at-hand tools and features for examination and case-notation of findings.  However I wanted something a bit more “seamless”.

In the end I went with incredible (and free) ImDisk Virtual Disk Driver.  It installed like a champ and provides read-only mounting options to a slew of different “image-file” formats; including dd.

I also found this dd2vmdk: dd image to vmdk virtual disk image P2V converter (though not what I was focusing on as I rarely use VMware virtualization).  It seems to stand out from others Mr. Carvey mentioned in his post as it is an “on-line” web-based conversion tool. I guess it could be a handy option if you were in a bind somehow for such a tool.

Once mounted with ImDisk, I then proceeded to verify I could (and did) see all the info captured at the sector level with one of my sector-viewer utilities. I could run GREP routines, as well as various forensic first-pass tools.

Then I tossed Harlan’s RegRipper at it.

Previously I had only flirted with the tool. This was the first time I had a “real” system to play with.

I pointed it at some of the target registry-hive files and let it, well, rip!

Looking at the log results I was astounded.  Not so much by how it performed, I understood that already.  What amazed me was what it discovered about the base image I use to build the systems for imaging.

You’ll have to wait for another post just on that, but suffice it to say, there were a tremendous number of artifacts from the image’s former life before I adopted and built upon it.  I was quite stunned by what RegRipper uncovered.

It convinced me then and there that although this tool was designed for the forensics crowd, it has unrealized value for desktop system administrators, builders, and analysts.  Amazingly informative little tool it is!

Forensic Tips and Treats from across the Webs

As the above illustrates, system admins can find value in the field of forensics.  The following are a series of posts that could be of interest to both groups.

  • De-mystifying Defrag: Identifying When Defrag Has Been Used for Anti-Forensics (Part 1 - Windows XP) – SANS Computer Forensics blog.  Good info for defraggers as well.

  • Alternative Artifact Timeline Generation Tool (Link Files, Prefetch, Userassist, Recycle Bin, and more) – SANS Computer Forensics blog.

  • Memory forensics: A practical example  – SANS Computer Forensics blog. Great “real” application of the technique.  Could be useful in memory capture/analysis of a malware-infected system.

  • You wait all day for a bus then two come along at once.... – Forensics from the sausage factory. DC1743 provides some EnCase script linkage for Internet search-term word usage.

  • Maine State Police CP Project – Lance Mueller at his Computer Forensics, Malware Analysis & Digital Investigations blog provides “The Top 265 hex keywords” for CP investigation GREP’ing along with additional EnScriptresource linkage.

  • EnScript to convert individual OSX .emlx files into MBOX format so EnCase can parse it. post also provided by Lance Mueller.

  • EnScript to Export files based on Extension v1.1 also by Lance Mueller has been nagging me.  I don’t use EnCase so EnScript’s don’t seem useful.  However I wish I could find (tips anyone?) a Windows utility (freeware?) or VBS script that would perform the same functionality.  This would be dead-useful in a Windows system file-recovery response when a user’s drive/system is going south (or did) and you need to quickly recover targeted file-types.

  • EnScript to Compare evidence against hash set(s) and export files not in the hash set(s) – Finally Lance Mueller provides this EnScript on his forensics blog as well.  Busy but generous guy that Lance!

  • Pentester trick #3: using Cain without installing it – NewSoft’s Tech Blog – Clever trick to re-package Cain to a semi-useful degree of functionality without needing to install it on a compromised or target system.

  • log2timeline, artifact timeline analysis – Part I – IR and forensic talk blog – Interesting post on timeline analysis of a system.  Again could be useful info for system admins.

Did I mention I found some new tools?

Yep. I did.  And I was taught how to share!  Lucky you!

  • Forensic Focus Blog – OK. Not really a “tool” but does provide great regular blog linkage to tools as well as software and hardware reviews of a forensics bent.

  • List of Cell Phone Forensic tools — PenTestIT – I’m only interested in Windows forensics and really don’t have a need for cell-phone forensics.  However this is a important field in electronic forensics and should be given the time it deserves.  So this is a great post for the curious or to get some basics.  I suppose some of these might apply to flash-based storage cards (often found in use on cell phones) which would apply just a bit as they sometimes are seen in/with Windows systems as well.

  • Announcing OffVis 1.0 Beta. – Microsoft Research & Defense – Free tool from the MS folks to examine and visualize “…the binary file format used by Microsoft Word, PowerPoint, and Excel.”  Neat particularly when looking at malware-tainted/exploited files of those formats.

  • Open Source Digital Forensics page. Great link resource maintained by Brian Carrier that includes (among many other things) pages with Open Source Windows Forensic Tools and Unix-based Tools.  Bookmark this site fast!

  • Sophos updates free Anti-Rootkit tool - H Security – news that there is a new (and free) Sophos Anti-Rootkit tool available. Registration is required for download but you can never have enough updated rootkit tools at your disposal to scan a target system.  It’s important not just to avoid self-infection but also to see if a possible “a trojan/root-kit did it, not me” defense is possible or supported.

Speaking of Rootkits…

There was news at Black Hat this year of a new boot-kit that could subvert TrueCrypt WDE systems. Please see this GSD Security and Forensics Linkfest: Duck & Cover edition post for the background info if you aren’t familiar with Stoned-Vienna.

Well, the (generally respectable) debate between the TrueCrypt camp and the author and the security folks continues.  It’s been very informative to me on the whole as I work with WDE solutions and find boot-kits particularly fascinating; more-so when paired with WDE protection.

With that in mind, here are some updated/current discussions on the whole thing worth looking at.

  • .Security Database Tools Watch - Stoned Bootkit released – Yep, get your own copy to play with. Carefully.

  • TrueCrypt Foundation is a joke to the security industry, pro Microsoft – Peter Kleissner’s blog.  Peter is the author of this particular boot-kit and comes out guns-a-blazing on the latest discussions.

  • TrueCrypt hard disk encryption cracked – Nero disc burning free – Windows 7 adoption – Windows 7 activation cracked – 4sysops blog – This is an unexpected find. Michael posted this as a mini-linkfest and ended up collecting a very good comment-thread discussion between him and some TrueCrypt users.

For the record I see accuracy in both side’s positions on the matter.

Whew!

Glad to get these links up.

Cheers for now.

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, cell-phones, cheat sheets, forensics, hardware, Linux, malware tools, security, tutorials, utilities, virtualization, Win FE, Win PE | No comments

Blog reboot – version 4.0

Posted on 1:41 PM by Unknown

OK.

I have to say, while I liked the v 3.0 design overall, I just wasn’t feeling the lovin’ when it came down to the way the posts were separated.

It was difficult to tell where one began and the other ended.  And colors/fonts were still a bit off.

And I hadn’t really thought through the impact of the floating main content body for wide-screen monitor users.

So I eventually found  the Concept Nova template over at BTemplates.  I liked the overall feel.

The template code was a lot easier to tweak as well for my design.

So here it is…seems to render properly in Mozilla, Chrome and IE (though the lower-case “grand stream dreams” in the grey bar is clipped in IE).  Still need to check how it looks in Safari and Opera but I expect that will be well.

update: Opera also renders it fine although in Safari for Windows, if the text zoom is set at “normal” then the top-most heading punches a line gap between the images. Setting the text zoom for the page down one notch resolves the issue but it a bit harder to read. All else seems fine.

Hope everyone is pleased.

I still need to download and “self-host” the image files that make up the template elements just in case they get nuked or changed (doubtful but it could happen).

Feedback is welcome.

--Claus V.

Read More
Posted in Blogger, blogging | No comments

Sunday, August 9, 2009

Around the (MS) Office pool

Posted on 10:13 PM by Unknown

Lavie and I must have used Microsoft Office 97 forever.  Years upon years.

It was the primary communication application we used at work.

Eventually we picked up a “Home and Student” version of Office 2003 a few years ago for our home systems.  Even Alvis used it in her Jr. High technology learning class.

That was long-after Office 2007 was released.  Both our places of work still hadn’t migrated to 2007.  Why bother? 2000/2003 was ubiquitous.

About a month ago, I finally got around to picking up another copy of “Home and Student” but this time it was the 2007 flavor.  Although we still are deploying 2003 SKUs at work, our newest leased systems are now tricking out with 2007. (Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats to the rescue!)

The church systems are running 2007 so we had to adapt, particularly as the presentations are built on PowerPoint and to ensure the smoothest compatibility when we do them at home, 2007 was the way to go.

Anyway, after a few weeks of bumbling around the “Ribbon” feature introduced in Office 2007, we pretty much had learned all the major navigational issues it caused and were back to doing what we do in Microsoft Office without much thought…though it does still feel weird when I go back to work and shift back to Office 2003.

Lavie remains less-than-impressed with the Ribbon feature.  I just added several of my common use icons up on the top bar by the Office Orb. Surprisingly (or not) Microsoft didn’t seem to offer a “classic” menu-bar option to revert back to the 2003 Office navigation.

Eventually (and it took me a while) I tracked down a utility that (kinda) does that trick.  There were others but this one seemed to be the cream that rose to the top.

  • pschmid.net - RibbonCustomizer™

RibbonCustomizer comes in both a free and a commercial version.  The free one just leaves out a lot of the customizing features and things power-users would find valuable.  However for most home users it more than fits the bill.

It doesn’t change the entire Ribbon back to Office 2003 format. What it does do very well is to simply add an additional tab to the Ribbon at the front. Click on that one and most all of the Office 2003 icon-bar items are comfortingly displayed for your quick and fast access. The “Classic UI” tab which is added can be placed at the front or end of the regular Ribbon tabs.

image

The primary file v1.1 is dated May 15th, 2007, but I chose to download and install the very recent (and alive) Beta Program version which was last updated May 24th, 2009. Paul’s blog is another good source of Office tool information.

It's very impressive and slick.  There are other products and tricks out there besides this one, but this has been the best one I’ve seen yet.

Lavie was overjoyed when she started playing with it.  Granted, the Ribbon is a powerful tool to accomplish a lot of things once you get familiar with it. On the other hand, we both have lost a lot of productivity in trying to figure out how to do some simple task that would have taken just a second in Office 2003; not that Office 2007 couldn’t do it, just we couldn’t find where the command-feature was located in the Ribbon!

I had no idea of the developmental culture and control programming behind the Ribbon.

  • The Story of the Ribbon – Jensen Harris: Office User Interface Blog

  • Office Fluent User Interface – MSDN Office Developer Center

  • Microsoft Office 2010 Engineering – Microsoft Office Product Development Team blog

PowerPoint to Video?

It seems pretty stable but a look in the forum-spam laden forum indicates that a few users have had some issues with the beta.  If that concerns you, go with the older stable version but expect some slower performance as the trade-off.

  • Use Powerpoint Video Converter to Convert Powerpoint to Video – MakeUseOf blog

I hesitated to include this tool as I think it would be less than useful in most cases. What with the PowerPoint Viewer available free for the world.  That said, I guess there could be a need to convert a PowerPoint presenation into a video format.  If so then MakeUseOf blog has found the freeware tool to do it.

Lots of Homes & Students at the Office?

  • Office Home and Student accounts for 85% of US Office retail share -Betanews

Really fascinating story into the real cost of Office and how most folks get around it at the retail level by snagging “Home and Student”.  Considering it allows for installation on up to three qualifying home systems at prices between $150 - $80 range, it’s easy to see why it is such a popular seller.  Only the government and large/enterprise customers can afford the volume licenses and/or regular seat prices for Office.

If it weren’t for “Home and Student” version I doubt we would be able to legally install Microsoft office on our home systems.

Curiously, soon after getting that H&S 2007 version, I was able to pick up a single license of Microsoft Office 2007 Enterprise for $9.99 though our Employee Purchasing Program special offer at work.  Examination of that EULA (find tool to locate all MS product EULA’s here) allows me to install it at home on my desktop system as well as one qualifying “portable” device (my home laptop) under specific conditions.  That suite brings a slew of additional items to my home system that I really don’t need, however it’s a nice excuse to have it all available to play with anyway.

Finally, as we are only now just getting used to regular usage of Office 2007 features and capabilities it seems crazy to be thinking about Office 2010.  But, it is around the corner.

For probably the best source of information on Office 2010 and all the new adjustments that will require I submit the following locations:

  • Microsoft Office and business productivity  - Paul Thurrott’s SuperSite for Windows

And particularly the following in-depth coverage articles from Mr. Thurrott’s SuperSite.

    Office 2010 Technical Preview: A SuperSite Special Report 
    Office 2010 Technical Preview Screenshots
    Microsoft Office 2010 FAQ
    Microsoft Office 14 Web Applications Preview

OO Not Forgotten…

And yes…for you freeware fans (and Microsoft Office is one area I just can’t compromise with) there is the Excellent Open Source office productivity suite OpenOffice.  Also available in a handy  OpenOffice PortableApps version as well. And, alas, it looks like you OO fans will slowly be seeing a OO version of the “Ribbon” creeping its way into future versions.

Cheers!

--Claus V.

Read More
Posted in hacks, Microsoft, utilities | No comments

Drop-Dead-Quick Blue Screen of Death Diagnosis Utility

Posted on 8:34 PM by Unknown

Almost anyone who has been around a Windows system has seen the dreaded BSOD.

It’s a puzzling display of hex-code, and techno-babble that will often cause the sweetest tea-sipping granny to curse the Viking god of war and send him running for cover.

Even many geeks would rather just offer up a “looks like you need to wipe it and reload the system” with a shrug than to try to pick apart the Rosetta Stone of words and code offered.

Sure, with patience and some basic understanding, one can copy down (or pull from a crash dump log) the error, do some Google work, and often find a solution. But come on, how many mere mortals would do that?

Brilliant freeware utility programmer Nir Sofer has just made this process much more delicate and refined.  How easy to get to the bottom of a BSOD you ask? Well, so easy a caveman can…oh…well, you’ve seen the commercials by now.

  • BlueScreenView - View blue screen of death (STOP error) information – freeware utility – NirSoft.

BlueScreenView requires no “installation” thus is portable between systems, and it works with Windows XP, Windows Server 2003, Windows Server 2008, Windows Vista, and Windows 7, “…as long as Windows is configured to save minidump files during BSOD crashes.”  Per Mr. Sofer.

image

Above: Dump display of a particular crash on my Vista system (BSOD XP Style display in lower pane).

image

Above: Dump display showing suspected driver causing crash in detail view in lower pane.

BlueScreenView features as described by Nir on the product page are…

  • Automatically scans your current minidump folder and displays the list of all crash dumps, including crash dump date/time and crash details.
  • Allows you to view a blue screen which is very similar to the one that Windows displayed during the crash.
  • BlueScreenView enumerates the memory addresses inside the stack of the crash, and find all drivers/modules that might be involved in the crash.
  • BlueScreenView also allows you to work with another instance of Windows, simply by choosing the right minidump folder (In Advanced Options).
  • BlueScreenView automatically locate the drivers appeared in the crash dump, and extract their version resource information, including product name, file version, company, and file description.

That 4th one there is really cool.  I actually was running the tool on my VHD booted Win7 system (x64 bit). Unfortunately, the tool doesn’t currently support x64 bit system dumps, but I simply pointed it to the minidump folder on my Vista system (showing in the program’s title bar as on the D: drive (really the C: but as I’m VHD booting, it becomes the "D:”) and it was able to pull up the records just fine.

That’s very important if, say the system does a hard-crash, and you can’t get it up.  Or maybe the system crashed and your significant-other/customer didn’t bother to leave any notes for you and just reset the system leaving you nothing but a scowl and smorgasbord of “it BSOD, Fix it!” on the table before you.

Now you can maybe boot the system with a Win PE disk, with this app unpacked on a USB stick, point it at the minidump folder and retrieve the BSOD history, along with the details.  Save the results in a log file back to the attached USB stick and then do your research and plan your solution-attack. Sweet!

While this information would be very useful to a system admin or desktop support tech, it could also be of use to an forensic examiner as it might provide some clues on the system history or patterns of operating system issues or remnants.

Armed with the information obtained from the BlueScreenView utility, just drop in any any one of these awesome BSOD decoding websites (or Google) and you are good to start the solutioning.

  • Troubleshooting Windows STOP Messages - James A. Eshelman

  • Understanding and Decoding BSOD (blue screen of death) Messages - Taranfx: Technology Blog

  • The ABC of Blue-Screen Dump Analysis - All Your Base Are Belong To Us

Miscellany

Not directly related but seemed better to post here then in the previous Microsoft Linkfest post.

  • Two Minute Drill: Debugging – lm, not just Alphabet Neighbors – Ask the Performance Team blog

  • Two Minute Drill: Debugging and the k* Commands  – Ask the Performance Team blog

  • Converting Perfmon timestamps to a readable format in Excel - the back room tech

Thank you Nir!

--Claus V.

Read More
Posted in Microsoft, troubleshooting, utilities | No comments

Windows Linkfest Mowdown

Posted on 12:39 PM by Unknown

CC photo credit "mower" by todbaker on flickr

More Microsoft bits and pieces…

Upgrading to Windows 7 is as clear as, well…

  • What do you get with Windows 7 – DelaneySoft’s Blog – really nice chart that lines up all the included features in each version of Windows 7.  It took me a while to figure out how to see both pages of the chart.  In Firefox I had to enable NoScript to run all the scripts.  Then when I clicked on it it floated above the page and I could select the next page icon at the bottom right corner.  Nice chart just not an intuitive way of launching it.  No real surprises.  The only elements that I don’t find present in Windows Home Premium that are in Windows Ultimate that I will miss are both XP Mode and Boot from VHD.  That last one surprises me.  However, as I was able to use the Windows 7 Ultimate RC bootloader with Vista just fine, I’m hoping that I will be able to swap out the same ones, using the same technique, in Win7 Home Premium.

  • Deciphering Windows 7 Upgrades: The Official Chart - Walt Mossberg’s AllThingsD – Bless Mr. Mossberg’s heart. It was in the right place.  The MS chart-designers were just too enthusiastic for everyone’s own good!  It was highly detailed and too confusing.  Just what was wrong with it? Let’s hop next to Betanew’s take.

  • Windows 7 Upgrades: Are they going to be too much trouble or just about right? -  Betanews.  Quoting from the post:

    ”Out of 66 upgrade scenarios, only 14 allow for "in-place" upgrades. The majority of scenarios require "custom install," which means either installing Windows 7 to a new directory or onto a clean hard drive. While data can be backed up and recovered, applications would need to be reinstalled.”

In our enterprise, we don’t in-place upgrade, we migrate.  That means we copy the user-data to a safe location (server/USB drive), wipe the system, then install a fresh, pre-configured image, and then put the user’s data back in the profile locations.  At home, being a techie, I want a clean-install so I take a similar tack on our systems.  I just don’t like the idea of trying to keep all the apps/data in place and upgrading the whole OS over an existing installation.  However, considering the chart and the options, I’m wondering if more than a few average home users are going to find the upgrade process frustrating or particularly daunting to handle.  Betanews’s article seems to wonder that same thing…

  • Microsoft blunders with a confusing Windows 7 upgrade chart - Ed Bott’s Microsoft Report.  Ed Bott redoes the chart into a much more simple to understand version.  Basically, if you are going from XP to Win7, you are facing a custom install.  If you are going from x32 of anything to x64 of any Win7 version you are facing a custom install.  If you are going from Vista to Win7 (same bits) you can pull off some form of in-place upgrade.

  • Windows 7 Easy Upgrade Path Truth Table/Chart – Scott Hanselman’s Computer Zen – takes a closer but easy-to-understand look at Ed’s own migration table.

  • A major Windows 7 upgrade question gets an answer – TechBlog – And Dwight clears up one final question…what about Win7 RC users? The answer: Basically you are facing a “custom-install” like XP users and those going from x32 to x64 bit versions. What does a “custom-install” entail you ask?  Dwight succinctly sums it up thusly:

This is essentially a clean install, but your existing operating system, programs and data are squirreled away in a folder labeled WINDOWS.OLD. You end up with a fresh Windows 7 setup, but you can access that folder to get to any needed data. (Sorry, the programs in there won't work - you'll need to reinstall them.)

So What Am I Facing as an XP User?

Let’s take a look at what an typical (?) XP user will confront when getting ready to upgrade their system to Windows 7

  • Step-By-Step: How To "Upgrade" from Windows XP to Windows 7 - Scott Hanselman’s Computer Zen -  Scott has a screen-shot rich walkthrough that covers all the gotcha’s.
    1. With XP running, follow Scott’s first section after reading this Microsoft Upgrading from Windows XP to Windows 7 TechNet article.  The trick is to run the Windows Easy Transfer utility buried in the Win 7 setup disk.  Too bad it isn’t included as an option directly off the Windows 7 setup process…
    2. Follow the steps, identify an off-system-disk location to back the files up to, then let it run (it took Scott about an hour).
    3. When done you get a single “.MIG” (MIGration) file that has all the stuff you are tucking away.
    4. Reboot the system with the Win7 disk and follow the setup steps to do a Win7 install.
    5. When done, log into the starting account you created and re-run the Windows Easy Transfer utility from the Win7 Start Menu.  Follow the steps and feed it the .MIG file from earlier.
    6. When done you will be presented with a list reminding you of software applications you must manually install (if not pre-included in the Win7 install).

So it really isn’t an upgrade but a user-data migration.

  • The Complete Guide to Windows Easy Transfer - Channel 9 – If you are a very visual-learner, you can check out this video from Microsoft’s Channel 9 showing you exactly how it works. 

Windows Easy Transfer is the consumer version of the User State Migration Tool (USMT) that Microsoft provides to enterprise users.  It’s heavier duty and much more technically needy.  I actually have a ton of links about USMT that that are in a standby post I hope to get to very soon!

I think the important thing here is that while you are able to (generally) save all your data, documents, pictures, videos, etc. in this manner (assuming they are stored in the expected places) you still aren’t getting your applications transferred over this way. Those must still be reinstalled.

Vista users will have it much easier and could in most cases install Win7 on top of Vista, preserving all their settings and applications in the process.  Though I’d still do a clean-install anyway myself.

  • Windows 7 Support, Deployment, Resources – Microsoft TechNet – More technical links and helps for the migration process including the additional links:
    • Windows 7 Deployment FAQ
    • Step by Step Windows 7 Migration/Upgrade
    • Step-by-Step: Basic Windows Deployment for IT Professionals
    • Step-by-Step: Basic Windows Migration for IT Professionals
    • Windows Automated Installation Kit for Windows 7 RC
    • Windows 7 Desktop Deployment Overview

For the Technically Impressed…

  • HOWTO: Improve Startup & Shutdown Performance on Windows Vista SP1 - Windows Live - Kurt Shintaku's Blog – Probably not recommended but if you are a power-user and/or just desperate to eek out every last millisecond of performance…YMMV.

  • HOWTO: Use ALL cores of your multi-core processor during Startup of Windows Vista - Windows Live - Kurt Shintaku's Blog – Again, just because you can…not because you need to...

  • Step-By-Step: Turning a Windows 7 DVD or ISO into a Bootable VHD Virtual Machine  – Scott Hanselman’s Computer Zen – Use the WAIK 7 to take a Win7 install WIM and turn it into a sysprepped VHD file, ready for mounting and final-pass setup.  Why? Because it’s cool and if you are hard-core into booting from VHD in Windows 7, it will really allow faster turnover as you discard/deploy fresh VHD systems for your testing purposes.

  • User Account Control Data Redirection - Windows 7 for Developers – For software developers a great walkthrough and test scenarios of UAC information and workings…also useful to sysadmins trying to better understand now UAC functions.

  • Download details: Windows® AIK for Windows® 7 – Now that Win7 is RTM, get the final WAIK 7 set for your PE 3.0 building needs.  Sweet boot-disk building awaits!

Bug? Not so much…

First it was a potential Win 7 RTM blockbusting show-stopper, then it wasn’t, now it’s a yawn.

  • Testers claim discovery of serious CHKDSK bug in Windows 7 RTM build | Security News - Betanews.

  • Testers claim discovery of serious CHKDSK bug in Windows 7 RTM build | Security News - Betanews.

  • A killer Windows 7 bug? Sorry, no | Ed Bott’s Microsoft Report | ZDNet.com.

And then cdman83 points out this "feature” of Win7.  I’ve run into it as well and it is more of an annoyance than anything else.  Why does it have to be so hard to get the correct right-click context menu to appear under Win7?

  • Windows 7 UI glitch – Hype-free blog.

And while poking around on Channel 9, I found this neat video that provides background perspectives on the cool Windows 7 backgrounds.

  • A Look Behind the Backgrounds of Windows 7 - LarryLarsen | Channel 9

So will that be x32 or x64?

The last item for some consumers/geeks who are upgrading existing systems to Windows 7 will be trying to decide if they will go with the x32 or x64 bit version.  I suppose if your hardware doesn’t support x64-bit processing then the decision is easy.

But for others, it might need some due consideration.

Three of our systems (all laptops) support x64 bit OS.  After installing x64 bit Win7 RC on them all, I have been astonished at the stability and ease of use.  While all of them are pegged at a 2GB system RAM max due to the hardware limitation, in the future, having systems that support more will eventually allow us to run 4GB or greater RAM amounts and access all of it.  Performance is fast, but not really any more so than under x32 bit for now.  As more x64-bit optimized applications are released however, that will certainly change for the better.

So I will be going ahead and installing the x64 bits of Windows 7 when we go with the final versions.

Here are a few more posts from technical bloggers extolling the virtues of x64 Windows 7 installs.

  • More Windows 7 RTM impressions, 64-bit edition – TechBlog

  • Experiences with Windows Vista 64-bit – 4sysops Blog

  • Windows 7: 64-bit or 32-bit? Memory and performance – 4sysops Blog

Claus V.

Read More
Posted in Link Fest, Microsoft, tutorials, Vista, Windows 7, XP | No comments

Saturday, August 8, 2009

Browser Linkfest Blowout

Posted on 12:44 PM by Unknown

Like there hasn’t been enough web-browser news lately….

  • Google Chrome Blog: A New Beta: Why slow down when you can speed up? – Google Chrome Blog – Nice roundup with lots-o-pics of all the newest features to be found in Google Chrome.
  • Google Chrome Themes Gallery – I’m liking the “Earthy” theme myself.  How do you install them? It’s a bit confusing (and not clearly documented) but you click the “Apply Theme” button for the one you want and let the “csx” file download to your system.  Then Chrome will find and apply the theme and delete the file.  Worked OK on XP/Vista, though it took just a bit longer to “automagically” apply on the Win7 systems. 
  • Google Chrome 3 continues to accelerate even as it adopts themes - Betanews. Accelerate as in rendering speed.
  • Rethinking Chrome – TechBlog – Dwight likes it! He really, really likes it!
  • Chromium Memory Usage – Chromium Blog – Some technical-level details on how memory is being used and how to better monitor it.

Claus’s thoughts on Chrome/Chromium.  I’ve got Chromium loaded on all my systems and use Dirhael’s (portable) Chromium Nightly Updater to keep my builds of Carsten Knobloch’s portable Chrome packages updated.

I really do like Chrome/Chromium.  It is fast, clean and each tab runs in its own process.  However it doesn’t have the extensibility/Add-ons that I just demand and rely upon daily at work and home with Firefox.  So it continues to be my go-to browser when doing presentations or viewing most on-line media for relaxation due to the simple (non-distracting) interface.  For production work, Firefox still wins hands-down; speed or no-speed.

  • Newsfox the Firefox RSS reader I use has received a minor version update to V1.0.5.2.  mozdev.org - newsfox: installation
  • Firefox 3.6a1 Released - The Firefox Extension Guru’s Blog – I’ve not yet had time to build a “portable/standalone” package of this alpha build.  Maybe I’ll have the chance soon.  The only issues I generally find are breaking of my fav add-ons.  Speed and responsiveness,including startup seem to be the primary focus of this build.
  • Sure it’s Fast, But How Does it Handle? – Alex Faaborg’s blog.  Is speed everything in a browser..maybe but possibly not much longer. See also his What’s Next for the Perception of Performance? post.
  • Mozilla Thunderbird, Portable Edition 3 Beta 3 Released - PortableApps.com.  Lavie and I are still using the public version of Thunderbird 2.x to manage our home/Gmail accounts. 

I’ve not yet bitten the bullet but will likely be migrating our primary email store from the desktop system to my laptop as I rarely go in there to turn it on and pull down all the email locally. (The Valca girls have taken over the study where it is installed and it is becoming the laundry/storage room now…anyway they like my company in the family-room space when I am typing away at the blog.)  I’m considering bumping over to the version 3 build for kicks and grins.  Any GSD readers using it and have any insights or gotcha’s I should consider?

  • Opera Desktop Team - Time to try Unite again! – Opera Desktop Team – Tweaks announced to Opera’s Unite product.  I’m still not sure how convinced I am on this “feature” that turns a computer running Opera into both a client and a server to provide content to other systems across the web.  Seems handy for some but a security administration challenge for system admins….  The Valca jury-foreman will be out in deliberations on this one for a while.
  • Unite - Opera Unite – The Opera Unite team blog.
  • Another day, another snapshot  – Opera Desktop Team – Another Opera 10 beta snapshot. Now adds stability to Unite as well as a Unite-based service called, wait-for-it, “Messenger” so you can chat on Opera with your pals. Other visual features also getting adjusted.

Now I’m not attacking Opera here.  It is a very nice alternative web-browser, behind Firefox, Chrome, IE, and Safari for Windows.  Really.  Very polished and fast in performance.  It’s got it’s own unique interface and lots of positives.  I do install it on most of my systems at home.  That said, I just see it continuing the “more-is-more” value march rather than going back to simplicity.  I wish “Unite” could be unbundled from the main Opera browser (can it?) for those of us who don’t want it. And I wish add-ons were truly integrated like Firefox extensions rather than this “widget” framework that is used.  I' guess I just don’t fully “get” Opera and the browsing experience they are designing for.  Once past those personal feelings, the interface and speed are very, very nice.

Cheers!

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Firefox, Opera, Thunderbird | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile