Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, July 3, 2010

Firefox 4.0b2 – “Official” x64 Bit Edition Available

Posted on 10:15 AM by Unknown

…for the brave and daring only!  These are not necessarily “stable” things by any means.  You’ve been warned.

OK…first things first…x64 bit versions of Firefox have been kicking around in the wings for many, many years.  However none of them have been “mainstream” or really official builds.  Just quiet labors of love.

I’ve been running the latest stable builds of Firefox 3.6.6/7 now with no issues on my x64 Windows 7 system.  And though I’ve had a long history here at this blog of playing with the Minefield/beta versions, I’ve really been relying on the stability and compatibility with add-ons that the stable builds provide.

That said, I still keep some portable versions of the Minefield/Nightlies around just for piddling.

I was recently reading this post, A Look At Firefox 3.7a6pre (Minefield) over at The Firefox Extension Guru’s Blog and was impressed enough by the well-organized list of items detailed by the Guru in 3.7 that I decided to go ahead and update my playbox builds.

So I hopped over to Mozilla Developer Preview, Portable Edition 3.7 Alpha 5 and Alpha 6 Pre Released (Firefox Preview) at PortableApps.com and downloaded the nightly build of Minefield 3.7 Alpha 6 Pre.

What these do is pretty clever, they extract the portable structure and helper files, then access/download the actual Firefox package directly from Mozilla and extract it into the correct folder.

However, for some reason, that second part kept failing and it couldn’t download the actual build.

No biggie.  I’ve been rolling my own portable builds of Firefox for a long time; grand stream dreams: Build your Own: Firefox 3 (alpha/beta) Portable.

So I hopped over to the Index of /pub/mozilla.org/firefox/nightly/latest-trunk and prepared to find the firefox-4.0b2pre.en-US.win32.zip file to download and unpack, then manually seed the %\FirefoxPortable\App\Firefox folder with the contents of the extracted “Firefox” folder from the zip file.

Only…what’s that lurking at the bottom of the list?  Oh my!

firefox-4.0b2pre.en-US.win64-x86_64.zip

So, I downloaded this one instead of the x32 version, unpacked it, and seeded the portable Firefox structure with this instead.

When launched I was greeted with the familiar Firefox 4.0 “pre” interface.  But what lay underneath?

A quick check with Process Explorer showed the story; 64-bit execution, baby.

image

Some observations;

  • no matter how many tabs are open, they are still hosted in a single process, unlike Chromium and IE8.  Opera and Safari also still seem to be using a single process to host multiple tabs/pages.
  • Memory usage seems fairly low…although I wasn’t using it with any additional extensions.
  • It seemed stable…but sometimes it temporarily “stalled” when dragging it around the desktop.
  • Just because it is x64 doesn’t necessarily mean it is any “faster” than the x32 bit versions.
  • No x64 bit Flash player…yet.
  • I’m not aware of many x64-bit add-ons.  Not sure how x32 bit add-ons will impact x64 bit Firefox.
  • Depending on your system, you may need to also install the Visual Studio Runtimes for x64 which you can grab here.  ( I did not as my system was already prepped with them from some previous application download/configuration.)

All that said…it is very cool to see this “official” x64 bit version of Firefox kicking around and I will be playing with this one as much as I do the Google Chromium Nightlies (which I like very much despite the lack of a bookmark sidebar…).

Even More

  • User:Armenzg/Win64 – MozillaWiki – Official Mozilla Wiki page for x64 bit builds of Firefox.
  • Pre-release Firefox Windows 64-bit builds now available (testing purposes) – Armen Zambrano’s Battlefield blog – First notice and lots of links for supporting downloads.
  • Firefox for Windows starts 64-bit transition - Deep Tech CNET News – Stephen Shankland provides perspective.
  • Firefox Alpha (Minefield) now has an official Windows x64 build available - with working Java x64 and Office 2010 x64 plugins - Aaron Tiensivu’s Blog. As ever, Aaron gives an awesome rundown and background.
  • Benchmark Firefox 3.7a6 (Minefield) x86 vs. x64 – Stefan Polte/PolteIT – Initial benchmarkings of x64 to x32 Firefox performance.
  • Firefox Takes First Steps Into 64-Bit Territory - Webmonkey | Wired.com.  More thoughts on what this means.
  • Manually Updating Add-ons to Work - The Firefox Extension Guru’s Blog and grand stream dreams: Hacking the Fox – tips on how to (maybe) get non-supported versions of add-ons working in the Nightly builds. YMMV.
  • grand stream dreams: Resolving a “Nightly” Firefox Issue… old post explaining the different build nomenclature.

Rolling your own portable x64 Firefox version

This has been covered before, but just in case you don’t want to skip around, here is how you can build your own “portable” version of a x64 Firefox nightly build for your Windows system.  I really prefer using these versions so I can run them along-side my current “stable” build with no ill effects or getting the add-ons all mucked up together.

  1. Download the PortableApp Minefield launcher package Minefield, Portable Edition 3.7 Alpha 6 Pre Nightly which includes the launcher and portable Firefox structure files.
  2. Run the executable, and select a location to “extract” the files to a "FirefoxPortableNightly" folder location.  I used my system Desktop, but you pick wherever you wish.
  3. You will likely get a “The installer was  unable to download Current Minefield Trunk Build…” error dialog box.  That’s great.  (Really!).  Tell the error box “OK” and keep going.  All we needed was the launcher and portable folder structure extracted for us. And that should have been accomplished before the error.
  4. Download the latest nightly (Minefield) trunk release.  Look at the bottom of the  list for the latest firefox-4.0(something).en-US.win64-x86_64.zip file version!  (Note the (something) name will change as new builds come out.)
  5. Extract this file somewhere on your system.
  6. Go to that extracted folder location and inside find the “Firefox” folder/contents.
  7. Copy that "firefox" folder and contents.
  8. Now browse to the the  \FirefoxPortableNightly\App\ subfolder created in step #2 above.
  9. Paste the folder you copied in step #7 over the “Firefox” folder found in step #8.  It is OK to overwrite/replace anything it might find in the process.
  10. Run the FirefoxPortable.exe file in the FirefoxPortableNightly folder and away you go!

As previously noted, you might also find you need to install the Visual Studio Runtimes for x64 which you can grab here.

Easy!

Bonus Tip: Running Multiple Versions of (portable) Firefox concurrently

One of the drawbacks to PortableApps Firefox is that it balks at running concurrent versions of Firefox.  So typically you can’t do a side-to side run of x32 bit and x64 bit Firefox.

However, if you create and add a custom “FirefoxPortable.ini” file to the same location as your “FirefoxPortable” executable launcher, you can do so.

  1. Browse into your \FirefoxPortableNightly\Other\Source folder and find the “FirefoxPortable.ini” file.
  2. Copy it.
  3. Paste it into the \FirefoxPortableNightly folder.
  4. Open it in Notepad or other other favorite text-file editor.
  5. Find the line with “AllowMultipleInstances=false” and change the “false” to “true”.
  6. Save the file.

Do this for each/all of the PortableFirefox versions you wish to run at the same time.

Now when you launch your x32 and x64 versions of PortableFirefox, you can run them concurrently.

image

For more tips with this file, and illustrations, see the great guide: Customize Your Own Portable Firefox Six Pack – over at Lifehacker.

Happy x64 Firefox surfing!

--Claus V.

Read More
Posted in browsers, Firefox, hacks | No comments

Sunday, June 20, 2010

On Watch: Forensically Focused…

Posted on 6:40 PM by Unknown

4705595191_451ab59e55

“Black Hawk watch” CC image on flickr by The U.S. Army

Wow.  Can’t believe how long it has been since I’ve been able to find enough free time to do do a forensic focused link-fest post.

Rest assured, I’ve been hard at work in the trenches, ever vigilant for tips and tricks to help both forensic pros and sysadmins find common ground in responding to Windows system incidents.

I hope you won’t leave disappointed…

QCC Information Security “CaseNotes” Updated

I’ve been using QCC’s CaseNotes for some time and find it really does an excellent job fitting my needs. The Digital Standard: Case Notes had a recent post that highlighted many of the best features of this freeware tool and that got me thinking.  Has it been updated lately?

Yep.  Pleasantly so!

  • More CaseNotes Updates – QCC blog post on the latest (June 8, 2010 ish) version of this application..

  • CaseNotes Updated! – and the QCC blog post from May 2010 that had some earlier fixes with in-depth explanations.

Major fixes include:

  • Case file backups only made during explicit user initiated saves
  • Backup copies now stored in a dedicated sub-folder
  • Number of case file backups increased from 3 to 10
  • Greater assistance for the corrupt case file 'password' issue
  • New menu item to reset screen position data to fix maximised windows
  • Fix for Open File dialog not recognising .Notes files in Windows 7
  • New dedicated 32 & 64 bit versions (emphasis mine! Woot!)
  • Supporting documentation still needs to be updated - coming soon.

I’ve found it challenging to keep up with updates on many such tools and utilities, fortunately, I was able to find RSS/Atom feed links this time so if you RSS feed-read, take these down:

  • ATOM feed for CaseNotes posts.

  • ATOM feed for (QCC) Free Tools posts.

MANDIANT Update Madness!

  • M-unition » Blog Archive » Web Historian: Reloaded.  Yep.  MANDIANT has gone wacky and updated their already wonderful Web-Historian application and taken it to a whole new level!  So far I’ve been using it in full “installed” mode. But I suspect that with some tweaking of the custom/advanced path settings it might be supported in a “portable” mode.  New version supports FF2/3+, Chrome, and IE 5-8. Man!  The GUI has been majorly re-worked and can scan both local and “off-line” sources. Thumbnail previews are supported on compatible browsers. It also can export a “sanitized” version of history usage for sharing.  This is a really advanced tool now and worth of checking out.  Did I mention it was free?  Tip: Read the PDF that comes with it.  Saves a lot of of time on the learning curve. From the blog post….
    • Collects web history, cookie history, file download history, and form history into data sets  
    • Perform a live artifact scan of the local system
    • Perform an artifact scan of one or more arbitrary history files from all supported browsers
    • Data displayed in gridview style with full search, sort, and filter capabilities
    • Export data sets to XML, HTML or CSV
    • Extract and export history files used in live artifact scan
    • Customizable scan settings can tweak the scan to target specific browsers and data sets
    • View page thumbnails and indexed content
    • Export sanitized version of history results to distribute to others
    • Website Analyzer provides visualization of datasets using bar graphs, pie charts and timelines
    • Website Profiler shows a quick “report card” of artifacts for various websites

  • Web Historian 2.0 – download – register if you wish or just click the “Download Now” arrow at the bottom.

  • M-unition » Blog Archive » New Memoryze, Audit Viewer, and Training.  Yep. Memorize and Audit Viewer also got updated!  Lots of new features and stuff.  From the post….

So what is included in Memoryze and Audit Viewer 1.4? Well, here is the short of it.

Memoryze:

  • Support for Windows 2003 x64 SP2
  • Improved support of Vista SP1 and SP2 including port enumeration and a better installer
  • Enumeration of digital signatures for all loaded modules in a processes’ address space, hooked and hooking drivers, and all drivers found by driver signature scans
  • Enumeration of MD5/SHA1/SHA256 hash on disk for all loaded modules in a process’ address space and all drivers found by driver signature scans
  • Updated documentation
  • Single installer for 64-bit and 32-bit versions

Audit Viewer:

  • Improvements to the Malware Rating Index (MRI)
  •      Report visualization of MRI results
  •      MRI rule editors that will allow users to graphically edit the MRI rule file
  •      Handle Trust view to help identify suspicious handles
  • Ability to search results within a specific process
  • Multi-select with copy
  • Multi-select and export to a CSV file

  • Memoryze – download link.

  • Audit Viewer – download link.

I also see tantalizing teases about possible future public releases of MANDIANT tools for Memoryze/Audit Viewer for x64-bit Windows, and free tools to analyze Windows Vista/2003 (64-bit)

Forensic LiveCD Updates

  • DEFT Linux 5.1 is ready for download -- DEFT Linux - Computer Forensics live cd.

What’s new?

      • Update: Sleuthkit 3.1.1 and Autopsy 2.24
      • Update: Xplico to 0.5.7 (100% support of SIP – RTP codec g711, g729, g722, g723 and g726, SDP and RTCP)
      • Update: Initrd
      • Bug fix: Dhash report (reports were not generated)
      • Bug fix: DEFT Extra bug fix (a few tools did not work if the operator click on their icons, added the dd tool for x64 machines)
  • CAINE 1.5 – CAINE forensic LiveCD is out. See this Release page for details.

  • CAINE 2.0 (code name "NewLight") is cooking – CAINE news blog.

WinFE Developments

WinFE is not my primary forensic LiveCD.  I’ve got a few others that come first in point-rotation. However, it still has a very warm and dear place in my heart.

So I was excited to see the hard work Brett Shavers has done in keeping this tool not only active, but expanding the knowledgebase and ability of others to use and build this WinPE kissing-cousin.  Provided below is the main page as well as great WinFE resources and posts to peruse.

Well done, Brett!

  • Windows Forensic Enviroment Blog – Brett Shavers.

  • More Windows FE and triage notes (WindowsRipper?) – video on using RegistryRipper/WindowsRipper to triage a PC with WinFE.

  • Current and Future Development of Windows FE.

  • Batch File – Brett’s project to help automate the process of rolling your own WinFE build.  It’s not rocket-science but this really can help for the more non-technical users.

  • Using WinFE – Brett’s tips and tricks for using WinFE.  See also this WinFE - Guide (PDF) Brett prepared. 

  • Videos – Yep. Brett’s got-em.

  • Posts (Atom) – Again because I’m having a hard time finding the site feed links.  Here you go! .

Also, though not part of Brett’s project, the following Praetorian Prefect post is a great and fresh primer on WinPE and forensic work. I particularly found useful the tips on DiskPart with read-only mounting of the off-line mounted volumes/drives.

  • Praetorian Prefect | WinPE 3.0 & Forensics.

Kon-Boot News 

While Kon-Boot might not be a tool for most forensic folks, sysadmins could have great use for it.  I’ve mentioned it a bit here on GSD and have been quite fascinated with the tricks it can perform as a bootkit.

  • Kon Boot – Kryptos Logic – This latest version is fully commercial and (reasonably so) you now need to pay-to-play, though a 1-user personal license is just $15.99 and a 1 year 1 user commercial license is just $60 more.

  • What’s My Pass? » Kon Boot 1.1 – What’s MY Pass blog has a roundup of some of the newer features in the commercial version.

  • All this said, the original KON-BOOT - ULTIMATE WINDOWS/LINUX HACKING UTILITY is still offering up free downloads of that earlier build so go grab them while they are still kickin’ free.

Windows Incident Response Blog: Link Madness!

I sometimes feel guilty for cross-linking to Harlan’s most-excellent adventuring forensics blog, who in turns cross links back here to the humble GSD blog but hey, good things often go full circle!

Here are some of the wonderful posts I’ve found extremely resourceful in content.

  • Some more stuff....

  • Timelines.

  • Stuffz – particularly juicy post with tool and utility updates.

  • Anti-forensics - musings.

And though not a Windowsir blog post, this seemed the best place to put this quick-reference gem from Tim Mugherini…

  • Security Braindump: Forensics Analysis: Windows Shadow Copies.

Rolling on with RegRipper…

Since I’m still exhaling from Harlan’s site…seems worth-while to drop these links on morphing the incredible RegRipper (which got a site design refresh as well).

  • Turning RegRipper into WindowsRipper -- SANS Computer Forensic Investigations and Incident Response blog.  Basically this explains how to set up RegRipper into a Windows system triage tool.  Any sysadmins besides me find how useful this capability could be…especially when now able to be used to work against a mounted drive?

  • YouTube - From RegRipper to WindowsRipper – see the process in action in this sub-5-minute video including integration with a NirSoft tool for IE history reporting for each system user.  I suspect this be the tip o the iceberg! 

  • RegRipper Program File Downloads.

  • RegRipper against a mounted drive -- (DOC file) Adam James’s documentation.

There is a whole lot to find and examine on the new RegRipper site so put some time in there.

  • RSS Feed – RegRipper site.  New as well the ability to RSS feed news and updates.  Sweet step-mother of baby Jebus! .

Please forgive me while I pause to get a fresh cool minty beverage and recover for a moment.

Command Line Goodness Series

CLI tips and tricks from cepogue on The Digital Standard blog that can’t be ignored.

  • Command Line Goodness Part 1 – The hunt begins with sample searches for credit card numbers, IP addresses, email addies, URL’s. The stage is set. 

  • Command Line Goodness Part II. – A case is on! 

  • Command Line Goodness Part III – Moving on to web-work.
  • Command Line Goodness Part IV – CLI utilities can be your friend.

A Big TinyApps way…

Not to be out-done, TinyApps bloggist is laying down the whack of his own.

  • Extract strings from raw disk device or image.

  • Hard drive enclosure with write protect switch which would be the ACP-2127 at around $20 or so depending on source.

And in case you missed in embedded in the the previous GSD post…

  • TinyApps.Org Blog : Boot any and all ISO images from USB drive. Seriously!  Now pause for just a minute and image having a tool (with write-protect switch) that you could jog-select any ISO boot image file you have on board, and then boot the system with.  CAINE, DEFT, HELIX, RAPTOR, WinFE, WinPE, etc and so forth.  All on in a single enclosure.  Yummy indeed!  See below…. 

  • The iodd 2501 External HDD. Product page.  Seed with your ISO’s and you can select any of them to boot from.  Oh yeah, it also comes with a write-protect switch.  Sounds like the perfect tool for sysadmins and forensic experts with more boot images in ISO format than they know what to do with!  Discard the disks!  Resellers that were noted (not meant as endorsements of any kind) :  LinITX.com - iodd 2501 Portable Virtual ROM – Silver , Amazon.com: iodd 2501 Portable Virtual Rom: Electronics, and Welcome to I-Odd USA.

SANS Computer Forensic Investigations and Incident Response blog

Yet another source of amazing tips and linkage. Oh my.

  • First forensics work – Part 1: Organized chaos and panic – Touch n Go on image acquisition.

  • First forensics work – Part 2: Sure it’s big enough … but look at the location. – Using Sysinternals PsExec with remote image capture.  Please read the excellent discussion in the comments below the post on the challenges and issues with network-based captures. 

  • WMIC for incident response – Another alternative to PsExec.

  • Timestamped Registry & NTFS Artifacts from Unallocated Space.

  • Digital Forensic Case Leads: Forensic 4Cast Voting is Open – Lots of tips, tools, and material to read at leisure.

  • Windows 7 MFT Entry Timestamp Properties

And because I can’t remember if I found it on WindowsIR blog or here at SANS…

  • nabiy.sdf1.org offers a great tool (USB History Dump) and article about extracting USB Trace Evidence from the Windows registry.  See also the NirSoft tool USBDeview and the Woanware tool USBDeviceForensics.

Security/Response Checklists 

  • Log Review Checklist For Responders Under Fire - Evil Bytes Blog - Dark Reading.  I’m a sucker for good cheat-sheets and checklists.

John mentions these Lenny Zeltser productions in particular and encourages tweaking these CC v3 licensed works to fit your own needs.

  • Information and Security Cheat Sheet and Checklist References by Lenny Zeltser.

  • Critical Log Review Checklist for Security Incidents.

Who’s been cooking Sausage?!!

Why it’s DC1743 of course over in the Forensics from the Sausage Factory blog!

  • Prefetch and User Assist.

  • Safari browser cache - examination of Cache.db.

  • Recovering Safari browser history from unallocated.

  • Safari History - spotlight webhistory artefacts.

Alvis and I prefer a pork/venison mix, steamed.  Go figure.

The Final Four

Yep four more links to go.

  • NTPWEdit – Reset Windows password – 4sysops blog – Tool that works very well in WinPE/FE builds. Not that any of you forensic guys would be making such changes to a suspect system.  However syadmins may need to if malware or sheer local-user maliciousness boggled out the Admin password.

  • Forensic Pagefile: SAM Cracking using Ophcrack and Encase – I’ve not used Encase to do so, but I have followed a modified method to extract SAM files from an off-lined system, brought them over into a VM running the installed version of Ophcrack, then cracked dem profile passwords to accomplish my l33t sysadmin needs (…self-mocking there guys…).

  • Tableau Revision History – TIM. In case you didn’t get the email, Tableau’s Imager (TIM) software product has had a few updates that are pretty important to get and upgrade to; involving both critical bug fix as well as minor ones.

  • (IN)SECURE Magazine issue 26 released – Chock full of security tips, news, and other goodness.  Related:  Harlan offers this free new issue link (PDF) to Hakin9 magazine.  Get the read on!

Be safe, be thorough, be fair and objective.  Be ever vigilant.

Cheers.

--Claus V.

Read More
Posted in boot-cd's, cheat sheets, command-line interface, forensics, Link Fest, Linux, security, tutorials, utilities, Win FE, Win PE | No comments

Father’s Day Linkfest: Slowly Smoked Goodness…

Posted on 3:57 PM by Unknown

Here is quite the collection of Windows-related links.  Although it has been quite a while since the last one, I promise I’ve been diligently collecting the most promising links I could find, and slowly roasting them over the past weeks.

The fat has dripped out and burned on the bottom of the smoker pit leaving only these tender, flavor-laden morsels behind.

Savory.

Plate up!

Windows System Utilities

  • Sysinternals Updates: Coreinfo v2.1, Process Monitor v2.91, Disk Usage v1.34 – Start updating your tool-chest!

  • Sysinternals Updates: Process Explorer v12.04, Sigcheck v1.7, ProcDump v1.8 and a new Case of the Unexplained – Yes! Even more Sysinterals utility updating goodness!  Plus check out that last one from Mark Russinovich’s examination of a IE crash and trace out to a rouge toolbar DLL file.  Process Explorer can now generate full/mini-dump process crash dump files. Nice.

  • Sysinternals Update: Autoruns v10.01 – Whew! version 10.00 brought in a major update to this must-have utility; the ability to scan offline Windows systems.  I’m not sure about the default setting now to auto-hide Windows (MS) entries…I prefer to see the buggers out of the box.

  • Network Monitor : Network Monitor 3.4 Beta Released on Connect! and BETA: Microsoft Network Monitor 3.4 - Windows Live – Network Monitor 3.4 brings with it some major GUI interface improvements and column customization. However, even more exciting are claims that parsing performance has been dramatically improved.  Couple that with a new high-performance filter to avoid dropping frames, as well as more granular time-stamps.  Yes, Wireshark and a few other network capture utilities seem to be king, but this is definitely packet-capture tool on the move.  Because it is free there aren’t many valid excuses for Windows sysadmins to not co-load this tool along side the others.

  • Sysinternals New Tool: RAMMap v1.0. and Where has your Windows memory gone? Check the map (Ed Bott’s Windows Expertise) – Amazing new tool (let Ed take you on the walking tour) from Sysinternals that will clearly display just how Windows is allocating the physical memory of a system.  Really, really cool.  For Vista/Windows 7, and Server 2008 OS only.  As Ed notes, XP memory management doesn’t support the features this tool interfaces with.

  • Windows 7 SP1 public beta download to be available in July – Download Squad – Probably not as exciting a new OS SP release as was Vista SP1 & 2.  Word is that this SP really just rolls up the updates that have been flowing to Windows 7.  Windows 7 seems pretty great out of the gate so there hasn’t been nearly as much buzz ‘bout this one.

  • Newsletter #89:  Changing Win 7 Default Profile and Sysprep Tricks – Mark Minasi’s Windows Networking Tech Page – Mark has a really good must-read article regarding Windows 7’s Default User Profile as well as some accompanying Sysprep tricks.  We are no where near to an enterprise deployment of Windows 7 at work so I’m probably going to be Syprepping XP Pro for a few more years to come.

  • Complete Guide to Virtual Hard Disks (VHD) in Windows 7 & Windows Server 2008 R2 - The Windows Club – Nice summary and link to the official Microsoft VHD Guide document.  Probably a good reference paper to keep nearby for any VHD jockeys.

  • DOWNLOAD: Windows Server 2008 R2 Hyper-V Component Architecture poster - Windows Live.  Who doesn’t love a super-geeky IT poster particularly when it talks about Hyper-V, virtual networking and virtual machine snapshots.  Links on that page to other related posters as well.

Freaking and Tweaking Windows

  • Customize & change explorer backgrounds with Windows 7 Folder Background Changer -- The Windows Club -- and Windows 7 Folder Background Changer personalizes Explorer views – Download Squad.  Simple utility to add images/textures to the background of Windows 7 Explorer page views.  Not for everyone, but find the right texture…say at 40 Fresh Free Texture Packs – Noupe…and it might be neat.

  • WinBubbles via UnlockForUs Say what you will about the web-page, but this has to be among one of the most complete Windows tweaking tools there is.  It’s been a while since I did a post on Windows tweaking tools, but this will be among them when it comes.  If you can wade through all the links to finally find where to download the utility (sigh) your search will be rewarded.  It comes in both a localized install version as well as a portable one.  FREE: WinBubble – Tweak Windows 7 – 4sysops gives a good review as well.

  • FREE: Network Password Recovery – Windows password recovery - 4sysops.  Michael Pietroforte tips us to a great network utility just for sysadmins, Nir Sofer’s Network Password Recovery v1.24.  I’ve actually used this to help me pin down why network drive mapping wasn’t working on a particular system at the local church-house.  It save me hours of work…but that’s another post!

Remote Desktop Management: Reloaded

  • Microsoft Download: Remote Desktop Connection Manager (RDCMan) – This is a really neat tool (though not the only out there) that allows you to manage all the different Remote Desktop connection accounts you have.  It presents them in a tree/list format on the left and then shows them in thumbnail format (or active in a single pane) on the right. (4sysops blog has great screenshots of it in action in his post Free RDP client.)  I’m using it right now to manage multiple remote packet capture systems across our network and it makes hopping between them a breeze.  Natively supported on Windows 7; Windows Server 2003; Windows Server 2008; Windows Server 2008 R2; Windows Vista, folks with Windows XP or Windows Server 2003 will need to obtain version 6 or newer of the Remote Desktop Connection client software. See Description of the Remote Desktop Connection 7.0 client update for Remote Desktop Services (RDS) for Windows XP SP3, Windows Vista SP1, and Windows Vista SP2 for more information and the download links at the bottom of the page.

  •  mRemote -- (free version) – Was a similar multi-remote connection management tool I found mentioned in a few comments about the above application.  I had never heard of it before but it seems to support a very wide range of remote protocols, and allows uniform management of them all, including RDP, VNC, SSH, Telnet, HTTP/S, Rlogin and a few others.  What was nice was that once you download and install, it will then assist you in locating/sourcing any additional downloads to support other protocols it can handle that it doesn’t find pre-loaded on your system.  Seems to have a strong fanbase. Overview

  • chriscontrol - Project Hosting on Google Code -- (freeware) – ChrisControl was another interesting remote control tool I rediscovered in it’s new home on GoogleCode pages.  The Beta 2 version was released in January 2010 so the author is still hard at work refining it.  ChrisControl is curious in that as long as you have the target system’s IP address/hostname and a valid account id/pw, then you have a good chance of connecting to it.  First it see if RDP or VNC is installed/running.  if RDP is available, it uses that to connect.  If VNC is present it will use that.  If neither, then it prompts the user to remote install VNC server on the target system!  You have options to uninstall the VNC server when done. 

  • I’d recently posted this link to the Remotely Enable Remote Desktop :: IntelliAdmin - (free tool) – but it seems appropriate to re-include it again.  This utility automates a trick to get RDP started when not enabled on the box.. Get the micro-file from this link: Enable Remote Desktop – Remotely (exe download-link from IntelliAdmin).  I tend to avoid direct links but the download link from their blog-post page actually points to their full-featured application, and not the standalone tool.  I’ve had the opportunity over the past few weeks to use this tool a few times and every time it save my bacon.

  • TeamViewer 5 is now out (free for personal (non-commercial) usage) and has some new enhancements.  Check out the TeamViewer Download page.  There is also a TeamViewer Portable version.  I found really cool that if you download the setup installer and run it, it gives you two options; “Install” to fully install on the system or “Run” to execute TeamViewer on the system “portably/temporarily” (and without the need for the user profile to have “admin” privileges on the system.  That’s a cool feature that calls to mind the way ShowMyPC offers the exe download of it’s own product which when executed, unpacks and runs…rather than installs.  ShowMyPC, btw, was updated recently to v3050.  Speaking of TeamViewer, I had been able to use TeamViewer on WinPE builds with great success.  However, the newest versions didn’t seem to execute well. I did manage to create an ugly work-around that again lets me keep use of TeamViewer as an option to remote-connect to a WinPE 3.0 booted system.  Yes, another blog post awaits on this one…

  • 2X Client Portable 8.1.870 Released -- PortableApps.com. This multi-connection management tool has also been recently updated.  It also is similar to the Microsoft RDC-Manager and does support RDP connections.  I’ve dipped my feet into using it a bit as well and was pleasantly surprised with the performance.  I really like the “tabbed” remote system display arrangement.  While the “client” tool is free, you can also use it to connect to systems running the 2x Application Server.  Check out the 2X ApplicationServer download page for more information on that side of operations.

Free Microsoft Money!

No. Seriously!  I mean it!  Get Microsoft Money free.  This “Sunset” version doesn’t require any on-line activation.  It is really slick and for a former Quicken user, is very mature and polished.  Lavie and I love it.  What don’t you get with this wonderful and sophisticated yet approachable financial management tool?  Well, as well as I can tell, almost nothing is missing except integration with Microsoft’s own on-line “Live” capabilities, which for the poor folk like Lavie and I, isn’t much we would be using currently anyway.  It is simply an amazing opportunity.

Even if you don’t really think you would use it, if you don’t already have a personal finance management (banking/credit/loans/etc.) software, download this and play around.  Heck, at least download the installer and keep it handy.  Read the download details page linked below carefully for full details.

  • DOWNLOAD: Money Plus Deluxe Sunset… FREE – Kurt Shintaku’s Windows Live blog.
  • Download details: Money Plus Sunset Deluxe – Microsoft Download Center

“From the MS download page Overview

All versions of Money Plus sold at retail and online, required users to perform an “Online Activation” step in order to keep using the product, even if online services had already expired. Online Activation was also required for every machine onto which Money Plus was installed. Now that Money Plus is no longer available for purchase, the online activation step will eventually become unnecessary and unsupported. This Money Plus Sunset package is targeted at removing the activation dependency. There are two versions of Money Plus Sunset. The Money Plus Sunset Deluxe version is meant to replace Premium, Deluxe, and Essentials versions of Money Plus. The Money Plus Sunset Home and Business version is meant to replace Money Plus Home and Business. Please note that Money Plus Sunset versions come preconfigured with: · No online services (no online quotes, no bill payment, no statement downloads initiated by Money, no data sync with MSN Money online services, etc…) · No support services (support services are limited to online self-help only, see Money Plus Sunset EULA and Microsoft’s Support Lifecycle pages for more details) · No need to activate the product.

Don’t let all that scare you off.  You can still manually import transactions from banks (if they support MS Money or compatible formats) down into this version of MS Money to save time from hand-entering them.

Seriously…Microsoft is giving away Money for free.  Who would have ever thunk?

Google Sites

So a while back I was working on another side project and found some tips on using Google Sites to host files and other materials for downloading by your blog’s fans.  Sounded like a clever idea although I do have a handy and free Box.net account already with a few publically made shared folders like that one that contains reg.keys for enabling/disabling InPrivate Mode for IE 8.

Eventually I came back to Google Sites and figure it had enough features and such to be worthwhile to set up a basic GSD site page. Nothing there worth seeing for now, but in time I might be able to use it to make a more technically organized website of tips and such.

There are lots of pre-built templates to get started with.  I chose a “project tracking” format for some reason.   We’ll see what happens.

  • Uploading a Document for Viewers to Download - Google Sites Help.

  • Google Sites Help.

A Tiny, TinyApps Diversion

The succinct TinyApps bloggist has been hard at work finding “outside the box” solutions for external storage media and usages.

Get your crazy on with these amazing tips and hardware finds!

  • TinyApps.Org Blog : Boot any and all ISO images from USB drive. 

  • The iodd 2501 External HDD. Product page.  Seed with your ISO’s and you can select any of them to boot from.  Oh yeah, it also comes with a write-protect switch.  Sounds like the perfect tool for sysadmins and forensic experts with more boot images in ISO format than they know what to do with!  Discard the disks!  Resellers that were noted (not meant as endorsements of any kind) :  LinITX.com - iodd 2501 Portable Virtual ROM – Silver , Amazon.com: iodd 2501 Portable Virtual Rom: Electronics, and Welcome to I-Odd USA.

  • TinyApps.Org Blog : Hard drive enclosure with write protect switch which would be the ACP-2127 at around $20 or so depending on source.  Seems like a can’t miss trick with spare 2.5” SATA drives littering up the shelves.

Of course, all the USB HDD talk has got me crazy thinking about other related items.

  • Into The Boxes: Issue 0×0 had a great tip from Don C. Weber on page 14 regarding re-purposing the controller/connecter from external HDD enclosures .  Sure, toss (destroy/hammer) the bad 2.5” HDD, but keep the USB mini-port to SATA  hardware adapter in your kit.  It’s a dead-simple way to access SATA drives and is a “green-recycling” solution to boot.

  • USB Boot Without BIOS Support – Kent Hall’s “What the….?” blog – Although most all “modern” BIOS systems support booting from external USB devices (properly configured of course), some hardware you encounter might not.  Chris’s trick involves using PLoP Boot Manager and RawWrite (if making a floppy) to create a bootable floppy/CD pre-booter if you will, that then leverages up the USB device to do the actual post-pre-booting from.  Not an everyday need but so simple it wouldn’t hurt to have such a boot-CD pre-crafted, just in case.  PLoP Boot Manager supports a number of features and is worth looking at even if this scenario doesn’t fit your need.

Free Firewalls for Windows

Currently, the Windows 7 firewalls and my own home router are providing me sufficient firewall protection for my comfort zone.  Maybe in a while I will revisit my Windows Firewall post roundup and see which ones still remain and if any new-comers of late are present.

In the meantime, snack on these….

  • The Three Best Free Firewalls for Windows – according to the MakeUseOf blog.

  • TinyApps.Org Blog : Excellent freeware firewall for Vista and Windows 7.  Yep.  While those three are medium/large sized, leave it to TinyApps to come in with an amazing l33t and lightweight free find; Windows 7 Firewall Control 3.5.  And in both 32 and 64-bit flavors, AND a portable version as well.  Zowsers!  There is also a “Plus” version that is not free, but much more fully featured.

Graphically Seen and Heard

  • Tintii: free, standalone selective coloring/color popping filter for your images – (freeware) – Review and linkage via freewaregenius.com.

  • RasterVect Softwarescan. – (freeware) – Great tool to convert raster images into vector formats.  See also Vector Magic which can “vectorize” bitmap images online for free or the $ desktop version.  I really love and depend on Vector Magic.

  • Bing’s Best-3, Windows 7 Themepack Released – The Windows Club.  I love to download these themepacks and extract the wallpapers from them.  I’ve got a massive wallpaper folder I run now with these best-of images.  Beautiful stuff.

  • 40 Fresh Free Texture Packs - Noupe.  Previously mentioned in this post.  Great and free texture packages. 

  • Identify audio & video codecs required, with VideoInspector – The Windows Club  see also GSpot Codec Information Appliance and the Shark007.net - Windows 7 Codecs - WMP12 Codecs and ffdshow tryouts.  Course you can always cross-match what codecs you need against which ones you got using InstalledCodec from Nir Sofer.

  • Sculptris – (freeware) – Check out Download Squad’s take on this …insanely cool, free 3D modeling software.

Utility Gumbo.

It’s all in the pot today!

  • FREE: NTPWEdit – Reset Windows password - 4sysops.  Yep.  Used it quite successfully on a few WinPE booted systems where someone “cleverly” changed the admin password. Bugger. 

  • How to recover lost ADSL password or other ISP password – Tips and techniques by Nir Sofer with his own tool roundup..

  • Network Password Recovery v1.24 – (freeware) – NirSoft tool to review your saved passwords for Windows Network shares or .NET Passport account.

  • Universal Extractor at LegRoom.net – Version 1.6.1 fresh out of the oven!  See this FileHippo.com page for all the changes baked in to this release.
  • RouterPassView  – (freeware) – NirSoft tool to recover your router password and wireless keys from supported router models. 

  • BulkFileChanger  – (freeware) – NirSoft tool to do some major and fun things for files/file-lists such as change their time-stamps or file attributes.   CybernetNews likes the RegexRenamer: Bulk File and Folder Renaming Using Regex.  
  • DiskDigger – Newly updated file-recover program that (unfortunately) isn’t free any longer (see tool blog page The move to shareware for the breakdown).  It still will work, but just not as conveniently.  The Portable Freeware Collection - Disk Digger page does contain a link to the last really “free” version 0.8.3, so while you don’t get the added features and spanking GUI from the new v1.0, you still can get much of the same functionality.
  • WhatInStartup v1.21  -- Updated NirSoft auto-run/startup manager tool.

  • Back4Sure -- (freeware) – Yet another good (file/folder) backup program, updated as of 5-16-10. Hop over to UK’s Homepage and check the side-bar for the feature and download links.

  • How To Force Uninstall Unwanted Windows Programs Using IObit Uninstaller – MakeUseOf blog tip.

  • ISOBuddy converts and burns disc images -- including DMG, MDF, PDI, and more – DownloadSquad tip.

  • TMonitor – CUPID – (freeware) – neat utility that will display the active CPU clock speed for each system core.  Seen via this  Download Squad Post

  • USB Drive Letter Manager 4.5.0: unbelegte Laufwerke ausblenden – German blog page from Stadt-Bremerhaven which really points out the USB drive letter manager - USBDLM utility.

  • Speccy and Recuva both were recently updated by Piriform software.  Get the newest releases!

And the Browser Wars continue…. 

  • There is the Opera 10.60 alpha preview – Try the latest version and the Opera 10.60 Alpha 1 and the very latest edition can be found in this Weekend fixes post for you Opera die-hard fans.

  • SRWare Iron - The Browser of the Future is based on Chrome/ium.

  • Internet Explorer 9: Platform Demos are still popping up newer versions regularly.  This latest one included IE Diagnostics features as explained by the IEBlog crew. 

  • Apple - Safari 5 is also recently set loose among the Web. Dwight Silverman at the TechBlog has his take in the Safari 5 for Mac and Windows is out post and Ars Technica dives deeper in their Safari 5: faster, less clutter, secure browser extensions review.

  • For Chrome/ium goodness, I’m relying on the amazing Portable Google Chrome 4.1.249.1059 as packaged by Stadt-Bremhaven.  The thing that has won me over with this particular portable-ization is the inclusion of the additional Neue Version des Portable Chrome Updaters which is an exe that when run offers to download/unpack/update your portable Chrome; in your favorite flavor as long at it is “Dev Channel”, “Beta Channel” “Release Channel” or my personal taste pick “Chromium”. Quench that thirst! 

  • Meanwhile…Firefox trundles on, slowly inching the way to the next major release..be it Firefox 3.6.4 or Firefox 4.0. Firefox Release Recap: June 2010 Week 3 « The Firefox Extension Guru’s Blog and also see this informative Firefox 3.7/Gecko 1.9.3 Alpha 5 Released post from the Guru as well.
  • How to Improve Extension Startup Performance – Mozilla Add-ons Blog is an interesting read on maybe the roadmap to come and the love/hate relationship with Firefox extensions; something great for customization and making a really practical browser, but potentially performance impacting with weigh-down.

  • Internet Explorer 9 and Safari 5 – The Windows Blog team.  Of course IE guys would have a bone or two to pick with Safari 5 in a side-by-side comparison, wouldn’t they? I’m sure it is 100% objective.

  • How to enable extensions for Safari 5 on OS X and Windows – Download Squad tip.  Safari 5 (will) support extensions as well.  Only it isn’t fully armed on the current release. However you can do so following that guide, then head over to this Tumblr page where you can find a number of early releases if you really want to.  I wonder if Safari will take a performance hit like Firefox has a tendency to once they start getting added-on…

Whew!

Happy Father’s Day!

--Claus V.

Read More
Posted in boot-cd's, browsers, Chrome/Chromium, Firefox, Google, graphics, hacks, hardware, Internet Explorer, Link Fest, Microsoft, Opera, Remote Support, utilities, video, Win PE, Windows 7, XP | No comments

Saturday, June 19, 2010

Slick Script solution for imagex DVD-based (or USB bootable-based) deployments

Posted on 4:01 PM by Unknown

No worries dearest GSD blog friends.

I’ve been very busy, hard at work for the taxpayers of Texas who pay my salary, making sure they get the most bang-for-the-buck with their own hard-earned dollars.  Thank you kindly.

I’m also grounded on my primary system…the silly Gateway laptop.  Seems the DC plug fix about a year ago failed again in the past couple of months so now I’ve had to rig the laptop up on my desk…static-style…to keep it running.  Kinda defeats the purpose of a laptop.  However I’m not willing to invest another $250 in a 2nd solder repair.  So I’m negotiating with Lavie and doing some shopping/dream-system config-ing on the Dell site.  I’m bouncing back-n-forth between a Alienware system or a Studio 17 build.  I think the Alienware case is a bit cheezy for my tastes. I’m open to other suggestions as well. Looking around at $1,300 price point or so which still seems like a LOT of money to this penny-pincher.  Leaning to the Dell line as I’ve supported these at work for 10 years or so and they are very reliable and sturdy systems.  Loving my new Latitude E6400 system at work (though it is still running XP Pro).

Dream features:

Quad-core Intel i5 processor (or higher to 8 processor threads with an Intel i7 chip perhaps?), 6GB RAM, 500 GB SATA drive, 512-1GB video system. Blu-ray support and a true 1080 HD supported screen.  I really would hope to find a modular DC-plug solution such that if the jack fails, its not hard-mounted on the system-board.  This is a lot of fire-power but I do lots of virtualization and hope to crank up some higher-end digital video/photo processing work as well.  Besides…it may be the first chance I’ve had to actually design and select my very own laptop system, so as an investment, it makes sense to get something I really would be proud to use.

Only sticking thing is I have a pair of beautiful Samsung LCD screen monitors.  I’d love to find an internal video-card solution that would output to both, while still allowing use of the laptop monitor.  However I will probably have to consider a Matrox DualHead2Go: Three Monitors, One Laptop : The Matrox DualHead2Go type solution, which really wouldn’t be bad at all. (for self reference: Matrox Graphics - Products - Graphics eXpansion Module – DualHead2Go )

Anyway, I digress. On to this post’s “meat-n-potatoes”…

The Setup

As noted, our shop is beginning a round of system refreshes for our end users.  In the end we are looking at close to 1000+ systems.  Our sub 20-person team would be greatly challenged to deliver this so a vendor was contracted to assist.

The factory images are “fresh” but not out of the oven fresh.  So the vendor setup/migration times are running 2-4 hours per system.  I know. Right?  So one of the things we do to minimize migration time for our own techs are deploy the fresh-baked images I prepare for our systems.  These are fully updated with all MS and third-party software patches, as well as contain our own system tweaks that are done post-install.  As such we can deploy a system in less than 1 hour.

Typically we deploy the images using bootable USB HDD’s and manually feeding the disk-prep and image application commands manually.

I’ve always toyed with the idea of scripting the process but with close to ten different images, and different HDD system configurations it is a bit challenging.  So we’ve kept with the manual model for now.

One drawback is that if the techs aren’t paying attention to drive lettering in DiskPart, more than one has wiped the portable HDD they are serving the images from. Oops!

Imaging for the Vendor

However, we wanted to retain some control over the images provided to our vendor, and giving them the system images (2 system configurations at this point) on a HDD wasn’t a popular idea.  Luckily each image would fit on a DVD and handing out/collecting DVD’s is much easier than USB HDD…and much more durable.

So I did some research and came up with a slick scripted mix of command-line batch goodness, ImageX/Diskpart fun, and WinPE to boot; literally!

I found an elegant solution offered by Neil “Frawlz” Frawley on MS Windows Client TechCenter: Scripts to deploy imagex images.

He uses a series of batch files and a text file to automate the process.

I did have some issue with the version/commands offered in his 2007 version and the choices.exe file used at that time and the newer ones.  For lots of sources on additional “choices.exe” background check out this About choice.com and choice.exe page.

However, I eventually got it armed and working.

Construction

I did a stock WinPE 3.0 build in a winpe_x86 folder and added three additional folders under the “ISO” folder; “images”, “scripts”, and “tools”.

In the “images” folder I placed the WIM file for the particular system the DVD was designed for use in image deployment.

In the “scripts” folder I placed the “choice.exe” file I got working, a “deployimage_localimage.bat” file, a deployimage_networkimage” file, a ”diskpartcmds.txt” file and finally a “menu.bat” file.

The choice.exe file I used reports as 19.5 KB and dated 12/9/1994.  I have some more work to do on this but this one works for now.

Although pulling the WIM image file from the network or a USB drive could be supported, I’ve tweaked it at bit to just support the DVD-based local image disk prepping and imaging.

In the “tools” folder, just my “imagex.exe” file is present.

The menu.bat file consists of the following, slightly tweaked from Neil’s OEM script.  It is this batch file that is called once the PE reaches the CMD prompt.

Note: the blog template is doing some text-wrapping here so double check against Neil’s original and also copy/paste any actual batch scripts below into Notepad or your fav. text editor to ensure you get the full line formats.  Line-breaks in incorrect places can cause the processes to fail.

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SOE DEPLOY SCRIPT
::
:: Language     Win32/MS-DOS compatible Batch File
::
:: Title menu.bat
::
:: Parent:     
::
:: Purpose:     Displays a menu in Windows PE to deploy an imagex image
::
:: Comments: UFD stands for USB Flash Drive
::
:: Author: Neil Frawley
::
:: Version: 1.0
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
@ECHO OFF

::VARIABLES
SET title=DEPLOY IMAGEX IMAGE MENU
SET script_dir=%0\..

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Display Title
cls
ECHO %title%
ECHO.

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Menu
ECHO Press the number to select the option
ECHO.
ECHO 1) DEPLOY IMAGEX IMAGE, IMAGE ON UFD OR DVD
ECHO 2) DEPLOY IMAGEX IMAGE, IMAGE ON NETWORK SHARE -- not supported
ECHO.

%script_dir%\choice /C:12

ECHO.
IF ERRORLEVEL 2 GOTO :NETWORK
IF ERRORLEVEL 1 GOTO :LOCAL

:LOCAL
%script_dir%\deployimage_localimage.bat
goto END

:NETWORK
%script_dir%\deployimage_networkimage.bat
goto END

:END

Then the “deployimage_localimage.bat” file gets called up

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SOE DEPLOY SCRIPT
::
:: Language     Win32/MS-DOS compatible Batch File
::
:: Title deployimage_localimage.bat
::
:: Parent: menu.bat
::
:: Purpose:     Deploy an imagex image, with the image being on a UFD or DVD
::
:: Comments: UFD stands for USB Flash Drive
::  This script could be run from a CD instead of a DVD, but it is unlikely the imagex image will fit on a CD
::
:: Author: Neil Frawley
::
:: Version: 1.0
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
@ECHO OFF

::VARIABLES
SET title=DEPLOY IMAGEX IMAGE, IMAGE ON DVD OR UFD
SET script_dir=%0\..

SET diskpart_script=diskpartcmds.txt
SET local_drive=C:
SET image_name=imagenamehere.wim

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Display Title
cls
ECHO %title%
ECHO.

ECHO Press the number to select the option
ECHO.
ECHO 1) I AM USING A DVD
ECHO 2) I AM USING A UFD -- not supported

ECHO.

%script_dir%\choice /C:12

IF ERRORLEVEL 2 GOTO :UFD
IF ERRORLEVEL 1 GOTO :DVD

:UFD
SET tools_drive=E:
SET image_path=E:\images
ECHO WinPE run from UFD
GOTO :PREP

:DVD
SET tools_drive=D:
SET image_path=D:\images
ECHO WinPE run from DVD
GOTO :PREP

:PREP
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Prepare hard-drive
ECHO **** PREPARE HARDDRIVE ****
ECHO.
%script_dir%\choice /N "diskpart will now wipe the contents of your hard-drive erasing all data. Do you wish to continue?"
IF ERRORLEVEL 2 GOTO :END
diskpart /s %script_dir%\%diskpart_script%

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Apply Image to hard-drive
ECHO **** APPLY IMAGE ****
D:\tools\imagex.exe /apply D:\images\LatE6400_04-10.wim 1 C:\

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: SECTION: Reboot computer
ECHO We are now ready to reboot the computer to continue system setup; remove DVD and
pause
ECHO **** REBOOT ****
wpeutil reboot

:END

Were the imagenamehere.wim matches the filename of your image WIM file located in the “images” sub-folder.

You will notice the clever bit is the call to the disk preparation text file “diskpartcmds.txt” which is the following:

select disk 0
clean
create partition primary
select partition 1
active
assign letter = C
format FS=NTFS quick
exit

You can pop over to the original link I provided to find the network imaging deployment batch file if you want.

Final Thoughts

Using an optical-based DVD source for the image does take a bit longer to access/copy the data rather than a portable HDD or flash-media based source.  So keep that in mind.  If you had a few 4-6 GB flash drives you could easily make them bootable and apply this solution to them instead.  DVD’s are relatively cheap and easy to make duplicates of.  And if one is damaged no biggie.  Plus you don’t have to worry about files getting overwritten!

I’m sure there are more sophisticated and elegant solutions.

Because you can “stack” images inside an imagex wim file, with some more work you could easily create a single wim file that could support multiple systems.  Then with some clever updates to the batch file and image-picker lines, you could call whichever image package you wanted from a single wim file.  Depending on how big your base image was and the add-on levels, it might not fit on even a DVD, but still, it would probably work out for an 8-16 GB flash drive; and be crazy-easy on a bootable USB HDD drive.

Pretty cool…

Claus V.

Read More
Posted in boot-cd's, command-line interface, imagex, Win PE | No comments

Saturday, May 22, 2010

OSTff revisited

Posted on 10:23 AM by Unknown

In the last post (gosh has it been that long ago?) Blasting the blasted Outlook Secure Temporary file folder… I outlined a number of free utilities that would assist with deletion of the contents of that folder.

The user who had the issue leading us on this learning adventure eventually called back with the same problem again.  Additional monitoring of the user as well as the processes she was doing illustrated to me that some kind of Outlook error and/or interaction with Voltage was causing the opened attachments to remain “orphaned” even when closed out “properly.”

We then were faced with deploying one of the solutions noted.  I was leaning heavily towards OutlookTempCleaner and calling it at startup via a scheduled task or simple bat-file in the Startup folder.

However, in the end, the suggestion was made to just do a batch-file that cleaned it up without any additional third-party code.  OK, I’m game.

There were a number of approaches I could have taken, primarily just making a direct, hard-coded identification to the user’s particular Outlook Secure Temporary file folder location, but if that “randomly” generated location ever got changed, say if Outlook had to be reinstalled, then it might break.

Instead after a bit of research I found a suggested solution offered by GuruGary in this Experts-Exchange post: Outlook Secure Temp Folder Full : outlook, folder, temp, secure.

For a solution how about this in a batch file (that can be run as a scheduled task, or at logoff, etc.:
@echo off
for /f "tokens=3 delims=      " %%a in ('reg.exe query hkcu\Software\Microsoft\Office\11.0\Outlook\Security /v OutlookSecureTempFolder ^|findstr REG_SZ') do rd "%%a" /q /s

Depending on which version of Outlook she is running, you may need to change the 11.0 in the registry key.

However, try as hard as I could in testing, it just didn’t seem to execute correctly.

It was very clever; using the reg.exe utility to query the registry and obtain the key value holding the actual path to the user’s Outlook Secure Temp folder location, then doing a deletion of it.

I then proceeded to rework the batch file using Rob van der Woude’s link: Batch files - Reading NT’s Registry with REG.EXE.

In the end I crafted the following batch file that did work perfectly on our own XP Pro SP3 systems for the problem at hand.

@ECHO OFF

::Place batch file in C:\Windows\32 location so it can find the reg.exe utility.

::Place shortcut to this batch file in the user's Startup folder to run upon login.

::Will auto-clean the user's Outlook Secure Temporary File folder location of all "orphaned" files so gets a clean-slate.

::Queries registry location of that folder location, then uses information to delete all the files present.

:: Note: delims is a TAB followed by a space

FOR /F "tokens=2* delims=     " %%A IN (' REG QUERY "HKCU\Software\Microsoft\Office\11.0\Outlook\Security" /v OutlookSecureTempFolder') DO SET Location=%%B

DEL /s /f /q "%Location%\*.*"

Depending on which version of Outlook you have, you will have to modify the “11.0” number according to this Microsoft Support article 817878 --Attachments remain in the Outlook Secure Temporary File folder when you exit Outlook 2003 or Outlook 2007.

Yes, just having the end user periodically run a free utility when needed probably was much easier, but this will run almost silently in the background at each login and clean things out.  Also, because it queries the actual registry key location each time before running, if that does ever get changed, it can adjust, rather than had I simply “hard-coded” that specific path to begin with.

Rob’s website contains a wealth of detailed and helpful information for CLI junkies and batch-file writers:

  • Rob van der Woude’s Scripting Pages - Home
  • Batch files
  • Scripting Tools

He also has lots of great WMI Scripting information as well as an added bonus: Getting Started with WMI Scripting

Wayne Martin has another collection of lots of useful command-line models over at his WWoIT – Wayne’s World of IT blog.

  • WWoIT – Wayne’s World of IT: Command-line - post tag.
  • WWoIT – Wayne’s World of IT: Useful command-lines – Part I
  • WWoIT – Wayne’s World of IT: More useful command-lines – Part II
  • WWoIT – Wayne’s World of IT: More useful command-lines – Part III

Lots of inspiring commands and operations here…

Cheers.

--Claus V.

Read More
Posted in command-line interface, troubleshooting | No comments

Saturday, May 1, 2010

Blasting the blasted Outlook Secure Temporary file folder…

Posted on 11:14 AM by Unknown

Despite the challenge of the RDC issue last posted about, we did have one small but significant Windows system troubleshooting victory last week.

One of our end-users was working with Voltage to pull mail out of a shared mailbox into the local Outlook client.

When she attempted to open the attached file, the following error was seen:

Can't create file: message_zdm.html. Right click the folder you want to create the file in and then click properties on the shortcut menu to check your permissions for the folder

Several field techs attempted to resolve the issue during multiple site visits, to no avail.

So crack network analyst “Mr. No” and I dropped by while in the neighborhood on an unrelated special project to take a look.

Based on the error message, we doubly-checked the permissions on the user’s Outlook folders. We reloaded different versions of Voltage and fiddled with the enrollment certifications. Checked disk space. Ensured no permission or size limits found on the folders.  Purged the IE temp cache location. Nothing seemed to work.  Comparing this user’s settings in Voltage/Outlook to a co-worker who was similarly configured but not having the issue found nothing different.

So, in a brilliant move, Mr. No decided to Google the error message…and found this:

  • Voltage Security Solutions Portal :: Can’t create file: message_zdm.html. Right click the folder you want to create the file in and then click properties on the shortcut menu to check your permissions for the folder

Turns out the user’s “Outlook Secure Temporary file folder” was filled up and needed to be flushed.

Once those steps were followed, the attachments could be opened again with no fuss.

Problem solved.

However, that wasn’t enough for Mr. Valca here.  What was going on and why was this user, out of the thousand-plus we support, having this particular problem?

Greetings Outlook Secure Temporary File Folder…Nice to meet you.

When I got back to the office I did more research and while not an unknown issue (and not limited to Voltage users by the way), it does seem to be rather uncommon.

I found a few posts in particular that described the issue and potential solutions.

  • Outlook Secure Temporary File Folder | Another Tech Blog – Andy at Another Tech Blog

  • Attachment Can’t Create File Permission Denied – IT Support Notes.

  • Tech Tip #1: The Case of the Vanishing Inline Attachments – Brazenly sassy, Claire M. Jackson’s account of the issue.

  • Outlook SecureTemp Files Folder – Slipstick Systems

  • Attachments remain in the Outlook Secure Temporary File folder when you exit Outlook 2003 or Outlook 2007 – Microsoft Support Article ID 817878

These (and other forum posts) referenced the root-cause as Andy well summarizes from his above-linked post:

“…outlook has a limit on the number of files of the same name that it can store.  If you have 99 “orphaned” files in the temp folder whose source attachment have the same name, when you try to open the 100th, you will get an error saying you can not open any attachments.”

Only my mind was a bit confused.  How you you have up to 99 files with the same name in the same folder location?  That didn’t seem to make sense. And what was our particular user doing so well to cause that many to accrue in the first place?

And how were they being “orphaned” in the first place? The user stayed in Outlook all day long with no Outlook crashes found or reported.

The Experiment

I fired up my own system, dove into Regedit, burrowed down to the location (Outlook 2003) HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\Security and copied the folder location found in the Value Name: OutlookSecureTempFolder key.

Then I pasted it into the address-bar of Windows Explorer and was taken to that folder location.

I had a few items in there, but none indicating duplicate names.  So I deleted them all to get a fresh slate.

I then popped into Outlook and sent myself a simple Outlook email with a dummy text file attachment called…wait for it…”dummy.txt”

With Windows Explorer still open to my Outlook Secure Temporary (OST) file folder location on the left, I double-clicked the test message to open it in its own window.  Then I double-clicked the attachment to open it.  Voilla!  the file dummy.txt was showing in the OST folder.  I closed the attachment and then closed the message and the file disappeared, automatically removed as expected by Outlook.

Next I repeated the process.  But this time I kept the attachment open but closed the message.  Then I closed the attachment.  To no surprise, the dummy.txt file was left behind and not deleted.

Then I repeated the process…only this time the file in the OST was automatically re-named to dummy_(1).txt (or something like that…I’m having trouble reading my notes).  Repeated testing found that if the email message Window was closed before the attachment, I could quickly add many more dummy_(#).txt files and leave them “orphaned” and preserved in the OST location.

So it seems that while “technically” the file names are not duplicate names…the attachment name is a duplicate and diff’ed by the addition of the “_(#)” name portion.  When the same file-name is present but the counter reaches “_(99)” then upon reaching the 100th instance, the error happens and the file attachment cannot be opened.  Now that made sense.

What I didn’t test, (and am curious as to) is what would have happened if I just created a file “dummy_(99).txt” in an otherwise emptied OST folder (that’s the only file present) and then tried to open my “dummy.txt” attachment, if the error would trigger due to the “_(99)” counter presence, and not an actual count of files really present.  I’ll try that one on Monday back in the shop but I’m pretty sure I already know the answer…

Knowing this, it is easy to understand the process by which this particular user was tripping over the error when almost nobody else is.

The user is receiving a high volume of inbound messages in the shared mailbox to process as part of her job duty.  These messages include a standard internal form attachment.  That attachment is frequently NOT renamed to something different by the sender. So even though the content of the form attachment is different, the file name is the same.

This end user opens the message, opens the attachment, closes the message (with the attachment still open…now “orphaned”) and proceeds to process the information in the form into another application.  Once done, the attachment gets closed.  This works fine for a while but eventually, enough identically named forms are processed/orphaned and the error trips upon #100.

Again, in our case it was Voltage attachments.  It could easily be PDF files/forms, Excel sheets, Word documents, whatever in your shop.  The attachment type isn’t the issue, it is the attachment “name” and how many times the attachment gets “orphaned” due to Outlook crash or (more likely) closure of the message body Window before the opened attachment itself gets closed.

Mitigation and Utilities

Because the default OST file folder location is typically “super-hidden”, it’s not easy to instruct most end users to browse into the registry and do a copy/past of the key value into Windows Explorer to empty things out.

In this case, it just required showing the end-user that she should either “save as” the attachment first before opening into a different location with an amended name before opening, or consider leaving the email message open, then when done with the attachment, close it, then the message body.

However, there are also some cool utility “toys” that can automate the process to various degrees as well:

  • OutlookTempCleaner -- (freeware) -- HowTo-Outlook. This simple exe file automatically finds and cleans the folder out when run.  What is particularly nice is that it supports CLI options for use in a login batch-file for automated cleaning if needed.  Also cool is the “big-brother” Outlook utility OutlookTools (also free) which brings extra Outlook support options to the table. NYC Tech Guys mentioned OutlookTempCleaner in their Empty Outlook’s secure temp folder post.

  • CleanAfterMe -- (freeware) –NirSoft.  This power-cleaning tool for Windows also has an option in it to clean that folder location, among many other deep-level things. 

  • CCleaner -- (freeware) -- Piriform.  More than one forum post also recommended use of CCleaner (newest versions) to clean this location.  I didn’t see it specifically noted/identified in the options, so maybe it falls into one of the general cleaning options.  Not sure.

  • Outlook Temporary File Cleaner – MSDN by anthonyrsc.  very small exe file (23K) with source-code provided.

So now I and our team are all much wiser to the Outlook Secure Temporary file folder and its solution.

Too bad the error message couldn’t be a bit clearer. I’m sure more than one sysadmin called in on this one has taken a while to check folder sizes and permissions in both Outlook and the local system before eventually associating the issue/solution with the blasted Outlook Secure Temporary File folder.

Cheers!

--Claus V.

Read More
Posted in Microsoft, troubleshooting, utilities | No comments

In the trenches…

Posted on 8:06 AM by Unknown

Been burning extra time working out a nagging Remote Desktop issue.  Still unresolved but I am stubbornly pressing on to solution it.

At the local house of worship, there is a pretty nice LAN setup.  At the sound/video desk we recently installed two Windows 7 Ultimate systems.  These are brawny multi-core systems, x64 bit OS, 8GB RAM systems.  More than enough muscle to power video/sound editing and projection work.

However the desk area itself is very limited.  So we dropped one box (with no monitor) under the desk. Then we use the second workstation on the desk to do a Windows RDC session to the 2nd (headless) workstation as needed.

Only the RDC sessions are a bit “wonky”.

Typically after the first RDC session is started, the login goes through, the remote system desktop is displayed, then the following error message appears on the workstation I am initializing the RDC session from:

“Microsoft Visual C++ Runtime Library
Program C:\Windows\system32\mstsc.exe
R6025
-pure virtual function call”

And the RDP session terminates.

If I try again, each time the connection gets briefly established, then kicks off, and the error appears.

After about 7-10 attempts, I am then able to get a “stable” RDC session established with no more kick-offs or errors.  So it does “work”.

I checked the remote system logs and found the following errors noted:

“Event ID: 9015
Desktop Windows Manager was unable to start because the remote client does not support desktop composition remoting.”

and

“Event ID:9003
Desktop Window Manager was unable to start because a composited theme is not in use.”

I’ve already made sure RDC exceptions are enabled on both systems in Windows Firewall.

I have tried reducing the headless system’s theme to “Classic” and disabling all Aero effects as far as I can tell.

I’ve made sure all the theme management services are running “automatic”.

I’ve tried disabling the various extra RDC “experience” options before connecting.

Same behavior.  Only after seven or more aborted RDC connections is a stable RDC session established.

I’ve tried using the RD client files from a “portable” build based on another system’s Win7 RDC files but same thing, so it doesn’t appear to be a corruption issue with the mstsc executable.

I’m still trying to research the root cause.  Other things I need to pursue this weekend:

  • I did have to turn off “Aero peek” on the system I am RDC’ing from as that was pulling “system focus” away from running presentations if accident hovered over.  Not cool during a service…  I’ve not yet re-enabled it to see if that has any bearing.  I don’t think so as the other geek seems to have the same issue from his own independent Win7 system RDC’ing to the target box.
  • I’ve seen lots of forum threads on similar issues.  In many of those cases the posters felt the issues was a bug in the Win7 RDP client itself.  They felt that way as connecting with a “portable” older set of RDP files from, say, XP SP3 didn’t demonstrate the issue.  I think they are using Remote Desktop Connection (Terminal Services Client 6.0).  I need to grab a set of that version to try to see if that makes a difference.

The facts that I see the error start just after the remote system’s desktop get displayed, that the event logs all mention “composition theme” in some fashion even though all settings seem to support a compatible rendering experience, and that with enough attempts, it eventually “works” suggests to me that it might, in fact, be some kind of network issue.  Could it be that the systems are “talking” too fast to keep up with each other as the different services interact and link-up?  I did find this tantalizing post on tweaking RDP network performance: Remote Desktop slow problem solved which tweaks the Receive Windows Auto-Tuning settings in Windows Vista…need to make sure it carries over to Win 7 as well first.

And yes, of course, we could go with a TVNC based remote desktop solution…or one of many others.  However, connection establishment error excepted, RDC fits the internal need just fine.

It doesn’t look like I am the only one wrestling with this issue.

When I finally get it resolved, I’ll post an update.

BTW, one early bonus from this “project” has been the discovery of the Remote Desktop Services (Terminal Services) Team Blog.  Lots of good info there for you Remote Desktop fans….

Cheers!

--Claus V.

Read More
Posted in Remote Support, troubleshooting, Windows 7 | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile