Posts Tagged ‘REG’

Microsoft Office 2010 Beta

So I am going through my email yes­ter­day and I come across an email from Tech­Net announ­cing the beta of Mic­ro­soft 2010.

Even though I am a huge sup­por­ter of Open Office, I deci­ded to give it a try. Since I already had a Hot­mail account, the regis­tra­tion was very sim­ple and within 5 minu­tes I was down­loa­ding the installer.

One of the first things I noti­ced when I began to ins­tall the appli­ca­tion, was the options that were not selec­ted. As seen in this screenshot, very few fea­tu­res are ins­ta­lled by default.

The ins­tall did seem to take a bit lon­ger than nor­mal, how much was part of the ins­ta­ller ver­sus my test machine is unde­ci­ded. None the less the ins­ta­ller did not take more than 20 minu­tes or so. Since I spend more time in the Word appli­ca­tion that was where I hea­ded first. It does appear that MS did lis­ten to a lot of users con­cer­ning the start orb and has repla­ced it with the File tab. The remain­der of the rib­bon bar looks remar­kably the same.

When you do go to the file tab, you get a lot more infor­ma­tion at your mouse point without having to do a lot of digging.

So off I go. As I men­tio­ned I use Open Office by default, so the first thing I did was open one of my docu­ments crea­ted in Wri­ter. It did take a few moments to bring the docu­ment up, but all of my for­mat­ting (such as it was) remai­ned. I could even save it back into the .odt exten­sion. There was the war­ning that the for­mat was not com­ple­tely com­pa­ti­ble. I ope­ned the file in Wri­ter again and everything was gol­den. That was a big check mark in my books right there. Mic­ro­soft has been drug over the coals (right­fully so) for not being more com­pa­ti­ble with other appli­ca­tions, this is a good step forward.

The next thing I wan­ted to look at was how it hand­les wri­ting to a blog (not just Mic­ro­soft Live spa­ces). I rea­li­zed how happy I was for the file menu to be back. With a cou­ple of clicks I was being promp­ted to setup my blog con­nec­tion. I selec­ted Word­press and ente­red the ser­ver and login infor­ma­tion. Next time I know, I am wri­ting the entry right now. One of the great fea­tu­res is the screenshot fea­ture. Like the snip­ping tool in Vista and Win­dows 7, the screenshot tool is won­der­ful. When you go to insert you see the option screenshot, with the down arrow, you have the abi­lity to just grab a full win­dow or use the snip­ping tool. All of the ima­ges in this post were crea­ted using this format.

So far, I must say I am actually impres­sed with the direc­tion of at least the Word por­tion. I will play with the excel por­tion later. Check back…

Be the first to comment - What do you think?  Posted by Diego - November 19, 2009 at 9:06 am

Categories: Reviews   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Cool Google Interfaces

Goo­gle has always been known for not being the norm. An exam­ple is chan­ging the ban­ner image every­day for one event or another. Take today (Octo­ber 7th) as an exam­ple. It is the date that bar­co­des were inven­ted. They made the ban­ner image a large bar code.

In addi­tion to the logos, they have every lan­guage repre­sen­ted for their trans­la­tion ser­vi­ces as well as gene­ral search. For most, that would be enough. Not Goo­gle. Try this.

Go to Google.com, type Goo­gle L337 hit “I’m Fee­ling Lucky”.

You should see:

Googlel337

Direct Link: http://www.googoth.co.in/

There are a few more lis­ted below. Please remem­ber to go back to the main Goo­gle site before try each one:

Search Term: Goo­gle Gothic
GoogleGoth
Direct Link: http://www.googoth.co.in/
Search Term: Goo­gle Linux
GoogleLinux
Direct Link: http://www.google.com/linux
Search Term: Goo­gle BSD
GoogleBSD
Direct Link: http://www.google.com/bsd
Search Term: Goo­gle Ewmew
GoogleEwmew
Direct Link:http://www.google.com/intl/xx-elmer/
Search Term: Goo­gle Klingon
GoogleKlingon
Direct Link: http://www.google.com/intl/xx-klingon/
Search Term: Goo­gle Piglatin
GooglePigLatin
Direct Link: http://www.google.com/intl/xx-piglatin/
Search Term: Goo­gle Eas­ter Egg
GoogleEasterEggs
Direct Link: http://www.google.com/Easter/feature_easter.html
Search Term: Goo­gle Bork
GoogleBork
Direct Link: http://www.google.com/intl/xx-bork/

2 comments - What do you think?  Posted by Diego - October 7, 2009 at 9:22 am

Categories: Browsers   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Clampi Virus targets online banking

In the modern world, most peo­ple never see their bank (with the excep­tion of ATM with­dra­wals).  We use bill pay, direct depo­sit and bank debit cards.  This is the exact beha­vior that the Clampi virus is living on.

Clampi is a very stealthy virus, just biding it’s time on a com­pro­mi­sed machine and watching for con­nec­tions to online finan­cial web­si­tes.  So many so that the Lon­don Times Online reports:

The tro­jan has a list of more than 4,500 finance-related web­si­tes that it moni­tors, inc­lu­ding Bri­tish high street banks. Secu­rity experts war­ned that it was one of the stealthiest and most per­va­sive threats to com­pu­ters using the Mic­ro­soft Win­dows ope­ra­ting systems.

The virus appears to be gea­red with more of the busi­ness users ins­tead of the nor­mal home user (though it does infect home users).  If the virus does end on a work com­pu­ter, it will attempt to cap­ture login cre­den­tials admi­nis­tra­tors and spread itself through the net­work.  As it spreads, it con­ti­nually moni­tors for login infor­ma­tion to the watch list of finan­cial web­si­tes.  If this virus does infect the finance group of a com­pany, it will attempt to send wire trans­fers from that account.  You can ask Slack Auto Parts.  It has been repor­ted that they lost $75,000 July 3–7, says owner Henry Slack. Clampi-infected com­pu­ters sent nine pay­ments to six dif­fe­rent mules � and fai­led to trans­fer an addi­tio­nal $69,000 in eight other attempts.

A word of war­ning, if your com­pu­ter is desig­na­ted for finan­cial usage, please do not surf the inter­net or use social media sites to mini­mize the risk of infections.

Since this virus has been out for a while, all the major anti­vi­rus ven­dors have upda­ted defi­ni­tion files that inc­lude the scan for this par­ti­cu­lar virus.  Make sure your sys­tem is always upda­ted and scan­ned on a regu­lar basis.  If you would like to run a quick check, using a dif­fe­rent ven­dor, I recom­mend these online scanners:

Trend­Micro: http://housecall65.trendmicro.com/
Syman­tec: http://security.symantec.com/sscv6/WelcomePage.asp
McA­fee: http://home.mcafee.com/downloads/freescan.aspx?cid=60447
Panda: http://www.pandasecurity.com/activescan/index/

Be the first to comment - What do you think?  Posted by Diego - September 21, 2009 at 8:54 am

Categories: Malware   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

What’s old is new again

Yes­ter­day, Mic­ro­soft put out an advi­sory to a secu­rity vul­ne­ra­bi­lity spe­ci­fic to the Win­dows Vista, Win­dows Ser­ver 2008 SP2, and Win­dows 7 RC ope­ra­ting sys­tems.  No other Win­dows ope­ra­ting sys­tems, inc­lu­ding Win­dows 7 RTM are impacted.

Holy cow, once again the older sys­tems (you go XP) are more secure then the new sys­tems.  Why is that you say?  Well this exploit was first found a decade ago.  Yes, you did read that correct, in 1999 this was dis­co­ve­red and patched for the ope­ra­ting sys­tems at the time.  Yet no one thought to put that into the: Newest, Most Secure, Latest and Grea­test ope­ra­ting systems.

So what is this vulnerability?

Accor­ding to Microsoft:

What might an attac­ker use this vul­ne­ra­bi­lity to do?
An attac­ker who suc­cess­fully exploi­ted this vul­ne­ra­bi­lity could take com­plete con­trol of an affec­ted sys­tem. Most attempts to exploit this vul­ne­ra­bi­lity will cause an affec­ted sys­tem to stop res­pon­ding and restart.

I like the last four words, “stop res­pon­ding and res­tart”.  We had an acronym for that back in the day.  BSOD.  But out of all of this, the thing that bothers me the most is Microsoft’s response:

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed, poten­tially put­ting com­pu­ter users at risk. We con­ti­nue to encou­rage res­pon­si­ble disc­lo­sure of vul­ne­ra­bi­li­ties. We believe the com­monly accep­ted prac­tice of repor­ting vul­ne­ra­bi­li­ties directly to a ven­dor ser­ves everyone’s best inte­rests. This prac­tice helps to ensure that cus­to­mers receive com­prehen­sive, high-quality upda­tes for secu­rity vul­ne­ra­bi­li­ties without expo­sure to mali­cious attac­kers while the update is being developed.

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed? Excuse me what?  It’s not new, it was disc­lo­sed pro­perly the first time.  Why do others become res­pon­si­ble for your oversight?

With that said Mic­ro­soft has issued two do it your­self reso­lu­tions until they can get a patch pushed.

The first is to Disa­ble SMB2 in the registry:

Impact of wor­ka­round. Host will not be able to com­mu­ni­cate using SMB2.

  1. Click Start, click Run, type Rege­dit in the Open box, and then click OK.
  2. Locate and then click the follo­wing registry sub­key:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
  3. Click Lan­man­Ser­ver.
  4. Click Para­me­ters.
  5. Right-click to add a new DWORD (32 bit) Value.
  6. Enter smb2 in the Name data field, and change the Value data field to 0.
  7. Exit.
  8. Res­tart the “Ser­ver” ser­vice by per­for­ming one of the following:
    • Open up the com­pu­ter mana­ge­ment MMC, navi­gate to Ser­vi­ces and Appli­ca­tions, click Ser­vi­ces, right-click the Ser­ver ser­vice name and click Res­tart. Ans­wer Yes in the pop-up menu.
    • From a com­mand prompt and with admi­nis­tra­tor pri­vi­le­ges, type net stop ser­ver and then net start ser­ver.

The second is to Block TCP ports 139 and 445 at the firewall:

Impact of Wor­ka­round: Seve­ral Win­dows ser­vi­ces use the affec­ted ports. Bloc­king con­nec­ti­vity to the ports may cause various appli­ca­tions or ser­vi­ces to not func­tion. Some of the appli­ca­tions or ser­vi­ces that could be impac­ted are lis­ted below:

  • Appli­ca­tions that use SMB (CIFS)
  • Appli­ca­tions that use mails­lots or named pipes (RPC over SMB)
  • Ser­ver (File and Print Sharing)
  • Group Policy
  • Net Logon
  • Dis­tri­bu­ted File Sys­tem (DFS)
  • Ter­mi­nal Ser­ver Licensing
  • Print Spoo­ler
  • Com­pu­ter Browser
  • Remote Pro­ce­dure Call Locator
  • Fax Ser­vice
  • Inde­xing Service
  • Per­for­mance Logs and Alerts
  • Sys­tems Mana­ge­ment Server
  • License Log­ging Service

Per­so­nally, I would block those on your inter­net facing fire­wall of you broad­band router.

1 comment - What do you think?  Posted by Diego - September 10, 2009 at 8:43 am

Categories: Windows   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

When is an antivirus really a virus?

Today I recei­ved a call from one of my exter­nal users that was una­ble to access any web­si­tes because some new anti­vi­rus was saying he was unpro­tec­ted and every web­site had mali­cious code.

Since I know that we have McA­fee 8.5 deplo­yed to our users, I knew that this was not a McA­fee issue.  As we dis­cus­sed it a little further he was men­tio­ning that the Anti­vi­rus wan­ted him to purchase the software.

This isn’t the first I have heard of this.  There is a soft­ware com­pany Inno­va­gest 2000 that is pro­du­cing this soft­ware.  They adver­tise it as an antispy­ware appli­ca­tion, but it is the spy­ware.  On some less then savory web­si­tes you will get a pop up that says that your com­pu­ter maybe infec­ted and they offer a free scan.

The fear of being infec­ted moti­va­tes a lot of peo­ple to run this free scan.  Unk­nown to them this appli­ca­tion ins­talls under­neath and now you are stuck.  On that note, I do recom­mend only doing the online scans from repu­ta­ble sites.  I per­so­nally recom­mend the follo­wing: Syman­tec, Panda, and McA­fee.

This appli­ca­tion is extre­mely hard to get rid of.  It rere­gis­ters and ins­talls if it is not com­ple­tely unins­ta­lled correctly.

I hate pro­grams like this.  But it is a fact of life out there.  The modern day snake-oil salesman.

While the pro­gram is run­ning you will see the follo­wing unde­si­ra­ble behavior:

  • A “Win­dows Secu­rity Cen­ter” sta­ting that you should purchase Per­so­nal Antivirus.
  • Nume­rous alerts sta­ting that your com­pu­ter is under attack or that you have mal­ware run­ning on your com­pu­ter. If you click on these alerts, Per­so­nal Anti­vi­rus will be ins­ta­lled, or you will be brought to the purchase page for the program.
  • Your Inter­net Explo­rer brow­ser will be hijac­ked to show secu­rity war­nings when brow­sing the web that stop you from reaching your desi­red page.

As I men­tio­ned before this bug­ger is very hard to get rid off.  But not impos­si­ble.  I found these ins­truc­tions at BleepingComputer.com.

Read more…

5 comments - What do you think?  Posted by Diego - July 3, 2009 at 11:38 am

Categories: Malware   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Export to Excel

One of the nice things of wor­king IT Sup­port is that I get to learn of new fea­tu­res I would not nor­mally use. This actually occu­rred the other day with a func­tion the Mic­ro­soft Excel adds.

We have all loo­ked at web­si­tes that has rows and rows of data that you would like to be able to use a dif­fe­rent sort (Fan­tasy Foot­ball Stats come to mind) or even your Cor­po­rate Intra­net sites that use a lot of tables for data.

Since I never knew it was there I never loo­ked for it, but if you are on a web page and would like to export, you can right click on the web page and when you get the drop down menu, look for the Export to Excel item (usually toward the bottom).

If you do not have the option, there is a registry fix that I have found on the Winhel­pon­line
web­site that is extremly help­ful and keeps you from having to manually edit the registry.

REG Files

To auto­mate the above set­ting, down­load the fileand save to Desk­top. Unzip and run the appro­priate REG file (exporttoexcel07.reg or exporttoexcel03.reg) for the ver­sion of Mic­ro­soft Excel ins­ta­lled. To remove the option, run the file undo.reg.

  Export to Excel Fix (971 bytes, 152 hits)

The full article can be found here.

2 comments - What do you think?  Posted by Diego - June 9, 2009 at 11:15 am

Categories: Microsoft Office   Tags: , , , , , , , , , , , , , , , , ,

8 visitors online now
8 guests, 0 members
Max visitors today: 8 at 08:56 am CST
This month: 16 at 03-05-2010 08:37 am CST
This year: 19 at 02-08-2010 05:10 am CST
All time: 21 at 12-18-2009 02:01 am CST