Friday, February 17, 2012

Malwarebytes Chameleon Works Great

I’ve been a fan of Malwarebytes for years. It’s always been one of the most effective tools against badware on the market. In fact, many other more expensive “security suites”, upper level technical support have been known to remote into a users machine, and install Malwarebytes to rid it of infections the antivirus was unable to get rid of. I’m not mentioning names (Symantec, Adaware), but actually I applaud tech support for doing what it takes to clean a machine.

The good news is Malwarebytes has gotten even better. In the past I’d always rename Malwarebytes as well as other security programs when installing them on an infected machines. The reason is simple, many malware programs will prevent any code that might interfere with it’s nefarious purpose from running, especially Malwarebytes! Now Malwarebytes includes a great new feature, “Chameleon”. Chameleon provides a long list of alternative exe’s to run when your machine is already infected and the virus is preventing Malwarebytes from being started from the standard executable.

To access Chameleon you need the latest version of Malwarebytes, available at http://www.malwarebytes .org. Go to the program in your start menu, right click on Malwarebytes and click on “Open File Location”. Chameleon will be visible, double click on Chameleon and a list of alternative installers appears. Double click on any of them and a command line appears asking you to “click any key to run”,  once started the command line tells you it’s “killing known malicious processes please wait”then it launches the Malwarebytes update which runs automatically. Once updated Malwarebytes launches and does a quick scan. This is usually enough to get your foot in the door so to speak. Then you can continue to run (multiple) full scans with Malwarebytes and your other favorite tools to finish the clean-up.

chameleon

Running Malwarebytes from a USB drive as a portable app isn’t supported at this time but I’m working on that…

So for now to use Chameleon, you need Malwarebytes already installed on your computer. Malwarebytes is a free program but a paid version is available for a lifetime single fee of 24.95 USD and they often offer generous discounts on their paid version if your patient.

Friday, September 10, 2010

Disaster emphasizes the need for Offsite Backup

Right now I’m sitting at home watching the television coverage of a fire storm going on about 25 miles north of me. Hundreds of people  became homeless within minutes of a huge explosion from a natural gas line. The fire has destroyed at least 54 homes an damaged another 124 more. This horrible tragedy which at this time has taken at least one persons life, proves one very important lesson for computer users.

Those houses were so violently consumed many people literally had to run out their front door with only the clothes on their back to save themselves. They certainly had no time to grab their computers or external hard drives, there simply was no time. So adding to the tragedy, many people affected in this no doubt also lost all their digital pictures, their business records, or their doctoral dissertation.  At this time no doubt data is the last thing on their minds, but once the fire is out and they begin to piece their lives together, the loss of pictures of their house and family outings or other precious memories will end up being just another burden to deal with.

So how could this additional loss be avoided, offsite backup. Backing up your most precious or valuable data to “the cloud” is no longer an option. This tragedy has convinced me that  the external hard drive next to your computer is little better than not having any backup, should a huge fire or natural disaster occur. Backing up to a cloud based service can be remarkably easy, an automated system used by a commercial program such as Carbonite  can be very simple.  Others like Amazons S3 require other programs to move the data to safety.

There a few free programs that will work, although the amount of storage is often limited. Mozy, Dropbox, and Windows Skydrive all offer free online storage. While free sounds good be careful, early on in the cloud storage era there were several free online backup services which disappeared suddenly leaving their clients unable to get data they thought was safe. It’s definitely best to stick with established names, like Dropbox or Amazon and maybe pay a little to backup your most precious memories or documents.

Don’t have high speed internet, then take several external hard drives and rotate one to an offsite location that’s a ways off. Weekly change the drive out so no drive is more than a week out of date. While this method works, its often the type of thing people do for a while but then tend to slack off after time. This is why I feel the set it and forget it of an automated backup online is the best.

Additional links: http://mozy.com/home, https://www.jungledisk.com/personal/, http://www.dropbox.com/, http://windowslive.com/Online/SkyDrive, https://one.ubuntu.com/, http://www.carbonite.com/

Wednesday, July 7, 2010

My Latest Malware kit

Over the the years I’ve found malware getting harder to defeat every time I try to disinfect a machine. A few years ago running AVG antivirus and Spybot Search and Destroy, pretty much did the job. But in the last 2 years or so I’ve had to refine my techniques as malware became more prevalent and harder to remove.  It seems organized criminals are now the driving force behind most of the “quality “ malware out there. There’s big bucks out there to be made stealing peoples identities, or turning their computers into spambots.

Last year I blogged about turning away from my old reliable programs and how I had adopted some new tools for doing automated cleanups. This year I’ve picked up some new tools, largely in response to what I was seeing when trying to clean up some really horribly infected machines.

My tools are similar to what I was using last year,Malwarebytes and Superantispyware   are still my favorite tools. Only one change there really, Superantispyware now is my primary malware tool. I was getting consistently better results with Super and it was removing many issues that Malwarebytes could find but not remove. Superantispyware also comes in a portable version, I keep a copy on a thumb drive for emergencies. For an antivirus I’m using Microsoft Security Essentials, its free, lightweight and effective which meets all my requirements. For a paid antivirus I like NOD32 from Eset, NOD32 is the best AV in my opinion and I will install it on users computers who are prone to getting infected. http://www.eset.com/. NOD32 is reasonably priced and if you’re going to pay for an AV, this is the way to go. http://www.superantispyware.com/ , http://www.malwarebytes.org/

These tools are going to do a great job of protecting most peoples computers if they are reasonably competent online. If a computer comes to me that’s really badly infected, I’ll first run Kaspersky rescue boot CD. Kaspersky Rescue CD is a Linux based Live CD that runs the Kaspersky antivirus prior to trying to boot into Windows. This can be very time consuming, in one case it took 27 hours and Kaspersky found over 1500 infections, but afterwards I was able to boot into Windows and run my regular tools which found another 150+ after 3 reboots and scans. But in the end the machine was clean.

Another program I use as a second opinion is called Hitman Pro.http://www.surfright.nl/en/hitmanpro  Hitman Pro is cloud based scanner that uses Esets cloud based scan as well as 3 others to double check your computer after a cleanup. I just started using Hitman Pro, but so far I’m very impressed. Lastly I use Process Explorer and Autoruns from Sysinternals, now a Microsoft property. Learning to use the Sysinternal tools takes time, but its time well spent for anyone who wants to get serious about knowing what goes on, on their computer. http://technet.microsoft.com/en-us/sysinternals/default.aspx

Saturday, May 1, 2010

Palm saved by HP at the last minute

Well I may not exactly be competition for Engadget but I'm just ecstatic that HP has stepped up and bought Palm. Palm has been a great and innovative company since their inception and I would have hated to see them go away. The new Palm operating system has never gotten the popularity it deserved. The WebOS works great, it multitasks and just elegantly goes about its business doing things most mobile operating systems cant.
I admit I'm a bit biassed I own a Pre, I use it on the Verizon network and unlike the At&T network I don't have to drive for a half hour to get a signal. But best of all is the WiFi Hotspot application. To me its the one app "to rule them all and in the darkness bind them"(Sorry JRR).
So keep your 150,000 fart apps on the "Jesus phone", I'll take my Pre and now thanks to HP I'll soon have fart apps to buy on the Pre.

Monday, April 5, 2010

Another Day in the Trenches: killing XP Antivirus 2010

I hate rouge antivirus programs. They seem to be getting more numerous and harder to get rid of all the time. Case in point: At work I noticed a shared computer suddenly popped up a Window announcing to me it was doing a scan and that I was infected with over 4,000 trojans and other forms of malware. Nice try I thought, so I used Control Alt Delete to start task manager and I closed Internet Explorer and all running processes involved. Fortunately it was a limited user account that was infected, and that turned out to be a important factor in removing it. I immediately ran Malwarebytes from that user and found a number of infections including the rogue antivirus product I was afflicted with.
These cretins that come up with this crap can’t even come up with something creative, we’ve seen XP Antivirus for a few years now, each year they just tack on a year to make it look current. Sad thing is I’m sure somewhere out there is someone who renews this crap every year, imagine paying yearly to be infected, oh right we already do that it’s called McAfee, but don’t get me started.

Well back to the task at hand: I rebooted the machine and logged into an administrator account. And updated Malwarebytes and ran it again... and found more junk, actually the same junk. Malwarebytes found it but could not kill it. Next I downloaded Superantispyware, a great application that I always run at home but wasn’t on the work machine. The first thing I do now after I download a anti-malware application is rename the installer, I do this because I often find the malware knows to prevent anti-malware from installing, okay these guys aren’t creative but they re getting smarter To rename a file, right click on the file and select rename and type anything.exe and install the program. Superantispyware did its thing and found a ton of additional files. I removed the infected files and rebooted again, and ran both my programs again. I still found junk! I repeated the sequence two more times until nothing was found. I then ran a scan in all user accounts to confirm “the kill”. So far so good, until I went into the user account where the infection had started, now whenever I tried to launch any program from the desktop I’d get the “Choose what Program you want to use to Open this File” message. This means I had to fix file associations and a great site with XP file association fixes is. //www.dougknox.com/xp/file_assoc.htm I used the .exe file association fix and it worked great. The last thing I did was to run Process Explorer, and Autoruns from Syinternals, these utilities give a great in depth look at what is currently running and starting on your machine at boot-up. Finding nothing suspicious I deemed the computer clean for now.
So a few lessons I learned on that one: Don’t use IE this was caused by a flaw in Internet Explorer I believed it was just fixed this week. Second running as a limited user is still far safer than running as an administrator, even though its trivial to elevate to administrator level, most malware seldom does, and this makes cleaning an infected PC much easier. Next running your cleanup tools multiple times and rebooting after each scan is the only way to give the anti-malware tools a chance against the bad guys.
http://www.malwarebytes.org/
http://www.superantispyware.com/

Thursday, March 25, 2010

Principles of Security:Keeping it Simple

Computing on the Windows platform today can be very rewarding .The problem with Windows applications is that as Microsoft has made improvements in patching security holes in Windows, the Black Hat hackers have begun to focus on third party applications to exploit the platform. Recent highly publicized exploits on the Adobe Acrobat PDF reader have been the tip of the iceberg. According to Secunia creators of PSI a security tool that scans your PC  for out of date software, half their users had 66 or more programs on their PC's. Once all the programs and patches were tabulated it totaled over "75 patch incidents annually". per average PC. "That averages out to a patch every 4.9 days." (Source InfoWorld Security Central http://www.infoworld.com/d/security-central/typical-windows-user-patches-every-5-days-630?source=IFWNLE_nlt_firstlook_2010-03-04InfoWorld)
This obviously puts the average user at risk. Many people do well just to keep their Windows OS patched much less check more than once a week for patches to their other applications. This leads to the crux of my point, keep it simple. Don't download every application you see or hear about. Pick a core of useful applications that allow you to use your computer in the way you need and stop! Your computer is a tool that can be very useful, so treat it seriously. You still can have fun with your computer, but you don't need 5 different media players, choose one and stick with it. If you find one you prefer uninstall the old one first. Many people use old out of date programs because they don't like the "feature creep" of many newer applications. This is a mistake, keep what programs you have up to date, this especially true with PDF readers, browsers, email clients, and media players. Keeping your flash player up to date is extremely important, Adobe Flash is a major exploit vector and I frequently run with it disabled.
Trying new applications can however be fun and rewarding, the best way to try new applications though is in a virtual machine. Using a program like Virtual Box from Oracle Systems is a great way to safely try new applications without committing yourself to a new program or loading your hard drive with a ton of unnecessary applications that need to be constantly updated. And lastly run Secunia’s free PSI it will help you keep your applications up to date and add another layer of security to your computer.http://download.cnet.com/1770-20_4-0.html?query=Secunia+Personal+Software+Inspector&searchtype=downloads

Saturday, January 23, 2010

Kaspersky Rescue Disk

You find your computer getting slower and slower to boot, and when it finally does boot it's so slow everything runs at a crawl. So you try running the antivirus you have and just get a message that says the definitions are out of date and you can't connect to the update server. Or you may find an annoying pop-up coming up every time you boot telling you PC Antivirus has found 70,278 infections and for $49.99 they will remove them for you. Well my friend, you are hosed! Your machine is so badly infected that you have to try desperate measures. At this point you can try pulling your hard drive out of the machine and putting it in another mounting it as a slave and using your other machine to try to clean it.

Another way to get this thing up and running is to try some kind of bootable rescue disk to clean it. Bootable rescue disks are bootable CD's/DVD's that contain small operating systems with some preinstalled tools contained for repairing your computer. When you turn on your computer hit F10 or F12, select your CD/DVD drive and your computer boots into an operating system contained on that CD. There are a lot of great rescue disks out there, the problem is most are very complicated and some take forever to boot. I found one great exception to this though. Kaspersky labs creator of the very capable Kaspersky Antivirus line of products has built a great free bootable rescue CD that is simple to use. Unlike many other bootable rescue disks it has one purpose, to clean your system. To create a Kaspersky Rescue Disk, download the ISO image from this link http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/ then burn the image to a CD. Depending on what operating system you are using you may need to download a CD burning program if you don't already have one. If you are running Windows 7 it has a built in, burning program that's simple to use and works great. If you are running XP or Vista, I like Image Burn http://www.cdburnerxp.se/ or CD BurnerXP http://www.cdburnerxp.se/ both do a great job of burning .ISO images and are free.

Once you have your rescue CD built, start your infected machine pushing F12/F10 to get it to the boot selection screen. Boot to the CD Rom drive as I stated earlier and relax, although faster than most rescue disks it's hardly fast. Follow the prompts and when it boots into the Kaspersky Rescue system you first need to update the virus definitions. Once updated do a scan, and go read the newspaper or get some coffee, it takes a while. Once it completes the scan go ahead and let it remove or quarantine all the files it has found. I've never had it delete anything that caused the machine it was fixing not to boot. But of course before you do anything like this, BACK UP YOUR DATA!!!!! But you already did that so proceed. Do the scan, remove the junk and log off Kaspersky. Just turning off your computer with the power button won't hurt anything when you are running a rescue CD.

The reason rescue CD's are so effective, is you're not trying to disinfect a computer with an infected OS. When you boot to the hard drive of an infected machine, you're playing on the bad guy's home turf. They control the machine and in many cases they've hidden the infected files so your antivirus can't see them. The rescue CD can scan your boot sector, and you hard drives from the outside looking in. The malware doesn't have a chance to hide if it's not running. It's become the first step I now use when I'm dealing with an infected machine. There are other rescue disks out there and many are very complicated and take a very long time. The Kaspersky Rescue Disk is the fastest and easiest I've found to clean an infected machine enough to allow me to boot back into Windows and complete the process by adding my favorite automated antimalware tools to keep the system clean going forward.

Friday, November 27, 2009

Login Security Tips

Today many of us live online, we bank, shop, and communicate with old friends via the internet. The problem with online life is that your identity is out there in so many places eventually one of the sites will be compromised. To protect ourselves we come up with passwords that supposedly only we know. Problem is people don't take the time to use properly secure passwords because they are too difficult to remember. How many people use the word "password" for their password? It happens all the time. So to combat this many sites require passwords of minimum lengths, this is fine except if you are using a word out of the dictionary, it is fairly trivial to crack. So to really get a secure password, we need to use a password with more than a few characters and it needs to include letters, numbers, and if the site allows it, symbols to make a decently secure password. Another problem then arises how do you remember your password? Security expert Bruce Schneier http://www.schneier.com/ recommends people can write them down and post them by their computer. This may sound crazy, but his point is simple, it's more important to have a secure password you'll never remember than one that's easily discovered by hackers. The fact is if someone has physical access to your computer all bets are off anyway.

My only problem with this idea is many people need to access their secure information while they're away from home or the office. Having your passwords written down while you're on the road is not a good idea, so you need to devise a way to create secure passwords that can be remembered. Doing this isn't as difficult as it sounds, devise a method that makes sense for you and use it consistently. One method I've used is to take a line you remember from a song you like and take the first letter of the line and then add numbers or symbols to it that make sense to you. I use lines from old songs I remember and I add numbers of old addresses, birthdates, or a series of numbers I just picked at random but can remember. The important thing is that it be easy to remember and totally random. The length of the password is also important less than 8 characters is too short, ideally 20 characters are considered totally secure most people can come up with a 10 to 12 character password they can remember that will be very secure.

Many people prefer to use a program to remember their passwords. A couple of very good programs I've used that are secure and easy to use are Roboform, http://www.roboform.com/ and KeePass http://keepass.info/ . While I don't use them anymore I think both offer a great service and should be considered by anyone looking for a simple way to manage your passwords in a secure fashion.

Another and potentially more serious problem which I see everywhere online, is the vulnerability in resetting your passwords. Several public figures have had their accounts hacked by the use of poor authentication protocols that websites use to reset your password in case you forget, or lose it. Sara Palin the Vice Presidential candidate in last year's national election in the United States is a great example. Her Yahoo mail account was hacked into because the security question was easily guessable and available on Wikipedia. This problem is perhaps the single largest login security hole we are facing. Typically websites ask questions like your mother's maiden name, or your first home town. This information can be often found in publically available locations. A better protocol is for sites to have the user to set their own "secret question". This is better but you still need to be careful not to use questions which can be guessed or known by others. On a more delicate note people need to realize that identity theft occurs most frequently by people that you know personally. It's not a good feeling, but it's statistically a fact, and shouldn't be ignored.

So how do you get around this problem of authentication? Simple, you lie. If you have to use your mother's maiden name, make up one you can remember. Use the name of someone else you may know or use a color you hate. There's no law that says your mom's maiden name isn't pink or you have to be truthful. Just make sure you remember the fake name you choose.

Logging into websites we use is easy to take it for granted. The problem is once your identity is compromised it can be a nightmare to fix all issues that will arise. Take the time to use good, secure passwords and remember, that your security questions you are asked are just as important as your passwords.

Thursday, November 26, 2009

When it comes to malware removal use a shotgun not a rifle.

Cleaning an infected computer is a challenge, unfortunately the malware writers are getting talented which translates to real trouble if your machine gets infected. Many computers ship with large all in one security suites. These all in one programs look good on a checklist comparison in PC Magazine but I prefer to use a variety of programs from different vendors, each using a slightly different method of cleaning your machine to give you the best chance of finding all the of the bad files.

Recently I had to deal with a Lenovo Thinkpad my daughter had been using. The laptop was recently given a clean install of Windows XP and is a spare machine I use only occasionally. After my daughter had finished using it, I did a routine scan using Malwarebytes a very good free anti-spyware program. The scan found 15 infections including some Rootkits, which can be very difficult to remove. So Malwarebytes told me I needed to reboot the computer to finish the removal, I complied and rescanned. Same results, same Trojans, same Rootkits, so I scanned with Microsoft's Security Essentials, a new free anti-virus Microsoft recently released. Security Essentials found nothing at all, so I tried a new (to me) website, virustotal.com. Virustotal allows you to upload suspicious files to scan to determine if they are a threat or possibly a false positive. I uploaded the file that was showing up the most frequently on the quick scans, virustotal scans the file using over 40 different malware removal engines, only one McAfee Virus scan found the file to be suspicious so I was beginning to think I might have a false positive. The fact that the file kept reappearing was very suspicious so I needed to get serious.

The next step was to run CCleaner a very good registry, and temporary file cleaner. CCleaner will make virus scans faster and may delete files that are allowing a possible payload to reload when you restart the computer. After using CCleaner I installed Superantispyware, a program I always install as one as my primary tools to combat spyware. The fact that this computer was a fresh rebuild was the only reason I hadn't installed it yet. Installing and running Superantispyware goes very fast, it's a great program that is the favorite of many computer technicians. Super lived up to it reputation and found a number of problems including one Trojan with multiple registry entries. Rebooting the machine after Superantispyware finally yielded some results. Additional scans from Superantispyware and Malwarebytes came up clean. My next test is to run a HijackThis. HijackThis is a very powerful tool which must be handled with care. Installing HijackThis is simple, using it effectively is another story. The best way for most people is to run HijackThis which will create a log file. Next post this file to a web site where experts can parse your results and determine if you still have any suspicious files remaining. My preferred site is http://www.hijackthis.de/ the site is primarily in German, don't let that deter you though, they have a scanner that will scan your log file in real time and give you a good idea right away if HijackThis has found anything.

If you have run and re-run your scanning tools run a HijackThis and everything comes up looking okay, you're probably malware free. But for the next few reboots you should continue to make sure your anti-malware programs are up to date and keep rescanning periodically. Most malware these days wants to hide in the background. You may be infected and never know your machine is stealing your passwords and draining your bank account. So stay safe, keep your data backed up and if you get infected use as many tools as it takes to get secure again.

http://www.malwarebytes.org/

http://www.microsoft.com/Security_Essentials/

http://www.superantispyware.com/

http://www.virustotal.com/

http://free.antivirus.com/hijackthis/

Sunday, November 8, 2009

Windows 7 Security Essentials

Windows 7 is a big deal, many people in the tech industry believe it will be the catalyst for the next tech boom in hardware sales. Could be, Windows 7 is a great OS. Staying secure in Windows 7 however still requires users to be careful. If you upgrade to Windows 7 one of the first things I recommend most users do is go to UAC in their start search click on "Change User Account Control Settings" . Once the UAC window appears use the new slider interface to move your security settings all the way to the top to "Always Notify Me", the most secure setting you can have. The reason is obvious the UAC is there for a reason, to protect you. There's no point in turning down your protection you have built in to your computer.

To back up this point I found a post from Sophos, a security software company that found a random sample of 10 malware samples 7 infected Windows 7 running UAC at its default mode. It also ran the test on a machine running no security software. http://www.sophos.com/blogs/chetw/g/2009/11/03/windows-7-vulnerable

Neowin a popular Windows blog however cried fowl, and ripped the methodology of the "study" and I admit Sophos sells sell security software so their motives might be questionable. But I still think it's prudent and wise to turn up your UAC. http://www.neowin.net/news/main/09/11/04/sophos-windows-7-vulnerable-to-810-viruses-fud-alert

So the next step after turning up UAC is to make sure you have an antivirus program. The free Microsoft Security Essentials is a fine, free program and I'm running it on several machines. I'd also get Malwarebytes anti Malware software and top it off with Superantispyware another great antispyware program. Another common item on the security checklist is to type "Folders" into the start search, open "Folder Options" and select "View". Uncheck "Hide Extensions for known File Types" this way when someone sends you a picture you normally see as a .jpg file you will see the jpg.exe it really is. Pictures don't normally have executables in them, and for some unknown reason Microsoft continues to hide known extensions by default.

Security threats being what they are, a few quick techniques will help keep you safe, even with the latest and greatest from Microsoft.

Upgrading to Windows 7

Windows 7 was finally released to the public on October 22nd. The release followed over a year of Pre-beta's, beta's, and release candidates all open for public consumption. The strategy of allowing the public plenty of access to Windows was a sign of confidence that was well placed. Windows 7 is a hit; it's a great improvement over Windows Vista and has received great reviews in the tech press.

The one question that remained unanswered prior to the release was how the upgrade version would work. Would users be able to do a clean install with the upgrade media, and how would Windows 7 install on computers running Windows XP which isn't supported for doing in place upgrades?

Fortunately the upgrade version of Windows 7 for any legitimate install works just fine. For my own use I installed 3 copies of Windows 7 which I purchased last June during the special half off sale Microsoft ran for a limited time.
The first install I did was a clean install using a hard drive that had Windows Vista already installed on it. Booting from the install media I was given the option of doing either a Upgrade Install or a Custom Install. Choosing the Custom Install, you then click on advanced options, and then choose which partition to install on. At this point you can choose, as I did to format the C drive and do a clean install over the previous version. The other option is to parallel install and end up with a windows.old folder on your C drive. Installing over the old version is useful if you're not sure you have a good backup of your data. The windows.old folder can be explored and files can be dragged into the new install with no problems. Once you're done with the windows.old folder it can be deleted with no problems.

On this install the process went very fast, it took maybe a half hour to complete. This machine is running a Core i7 and a 10,000 RPM Western Digital Velociraptor Hard Drive, so a fast install wasn't surprising. Reinstalling my old applications took longer than the install but I was up and running at full steam in no time. The next install I did was an in place upgrade of a 2 year old Dell Inspiron 1420 laptop. This required a lot more time and work before and during the install. Prior to the install I ran the "Windows 7 Upgrade Advisor" available from Microsoft. This saves you from potential hardware and software conflicts when doing the install. The advisor indicated I needed to uninstall several programs including iTunes and NOD32 antivirus. This also turned out to be a good time to get rid of a few other programs I hadn't used for a while so once I had cleaned up my Program and Features in Vista I ran the install. The upgrade took about 2 hours and once completed I was able to reinstall iTunes and NOD32 and things have been running great ever since.

My last upgrade was for my HP Mini 2140 Netbook running the standard Atom 1.6 GHZ Atom Processor. This was a fairly new computer and had little if anything to be backed up. So I just used the upgrade install disc to format my C drive and do a full clean install. Once again it went without any issues at all.

Overall my experience with doing both clean installs and in place upgrades went great. Some issues have come up for some people though. When using a upgrade version of Windows 7 and installing it on a new or previously formatted hard drive you will not be able to get past the point in the install where you are prompted to enter the product key. Instead, you need to continue on without entering your key. Once the install is complete type activate in your Start Search and click on activate Windows. You will be prompted to either activate online or by phone, choose phone and then answer the questions you are asked. As long as your computer came with a copy of Windows you are entitled to the upgrade price.

Some links for Windows 7 the upgrade advisor download: http://www.microsoft.com/downloads/details.aspx?FamilyID=1b544e90-7659-4bd9-9e51-2497c146af15&displayLang=en and a great tutorial for upgrading XP to Windows 7: http://www.butterscotch.com/tutorial/Upgrading-From-XP-To-Windows-7-An-Overview-Of-Whats-In-Store

Thursday, October 1, 2009

Superantispyware Pro Version

About a year ago I reviewed Malwarebytes  antispyware program and I gave it a great review. One of the comments I received was from Mike Duncan Director of Business Development from Superantispyware, a program I’ve used for a couple of years now. The representative offered me a free license for SuperAntispyware Professional Edition. I was delighted with the offer since I’ve always been pleased with free version. So I took him up on his offer and gave it a try, and that’s where my problems began. I installed the program put in the license and all seemed fine. It worked fine until the next reboot, at this point Superantispyware would ask me for a license key each and every time I restarted the computer. So I uninstalled the pro version and forgot about it.

Eventually Mr. Duncan emailed to ask me how it was going. I let him know what happened and suggested try the latest version. So I gave it another shot and this time the program worked fine. With no issues with the license SuperAntispyware Pro began to show it stuff!

SuperAntispyware free version had always impressed me with its low resource use, the Pro version carries on this behavior using only 4280K in memory when running in the background according to the “task Manager” for all users. Running a scan bumps ram use up to 6352k, on my Dell Inspiron 1420 with a 2.2 GHZ core 2 duo. The ram usage is very lightweight and impressive, as is the free version. The real time protection you get from the Pro version is very good. It can prevent you from getting into trouble when you go to a website that’s been compromised and it does a good job of cleaning a computer that’s been infected. The “quick scan” took a while, close to a half hour on a 320 gig hard drive with about 76 gigs free. The quick scan took a little too long for my tastes but it is really more of a full scan compared to the quick scan of other programs.

SuperAntispyware Professional edition is an amazing value, for just 29.99 it provides the user a lifetime license. For this price its really hard to pass up the Pro license, no yearly subscription just a one time payment. It can be used with other antispyware programs and it makes a great combination with Malwarebytes.

SuperAntispyware Professional is a great program for a terrific price, I consider it a great value and its definitely what I consider one of the best of the new breed of anti-malware programs available today.


Get SuperAntispyware Professional at http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWARE

Sunday, July 19, 2009

HP Mini Note 2140

Recently I purchased a MSI Wind U115, this is a great little netbook with a very innovative hybrid hard drive that delivered incredibly fast boot times and very snappy performance in general. Unfortunately the keyboard was just to small for me to get use too, and I returned it.

After looking around at the various retailers I realized that the HP netbooks all had one thing in common, great keyboards. The large sized keys and 92% full sized keyboards make typing much easier so I looked around for the model I wanted and found I wasn’t able to find the model I wanted anywhere locally so I ordered it online from CDW a large technology reseller. The service from CDW was awesome, they as good as you will get from an online retailer, enough said.

The model I ordered was a HP Mini Note 2140 It has a 10 inch screen and the aforementioned keyboard and a great aluminum case that has a much nicer finished than many of the plastic netbooks  I looked at. The boot up times and performance aren’t bad at all, not quite as snappy as the U115 but quite acceptable. I am currently removing much of the trialware that comes with the computer and I expect performance to improve once I’ve replaced things like the McAfee’s security suite with an antivirus that will be lighter weight. Right now I’m pleased with the size and build quality, the keyboard is smaller than normal but for me useable, unlike the MSI Wind keyboard and its little tiny keys.

So for initial impressions I’m quite happy I already find the size has me bringing the 2140 places I wouldn’t have bothered with before and I find it useful having it around. Netbooks don’t replace full sized desktops or laptops but they fill a niche I have wanted for some time.

Free Cloning software Part 1: Easus Disk Copy

Upgrading your hard drive can be a rewarding and simple procedure for the everyday computer user. Cloning your hard drive or making a exact copy is the easiest way to get the new hard drive up and running quickly, It’s also a popular tool for many professional IT people to backup a computer setup to be instantly restored in case of a disaster.

There is a number of paid commercial programs that serve this purpose, Norton Ghost is very popular as is my favorite, Acronis True Image. Both do a great job and have a number of useful options besides the cloning function. They are great programs but they cost money, and money is tight right now so I thought I try out a few free cloning programs that do the job just as well, albeit without the options the paid programs include.

The first program I tried successfully was Easus Disk Copy.  Disk Copy allows a user to replicate their hard drive on to a external hard drive, the only option besides a full copy is to choose an individual partition a useful feature that I didn’t test.

Easus Disk Copy is simple to use, you download the program and burn the iso image to a CD. You then boot to the CD and follow a simple set of windows guiding you through the process. Once your target disks are selected you simply wait for the process to take place. This is where Easus falls short of the paid programs I’ve used. The entire operation took over 3 hours to clone a drive with about 140GBs of data to the new drive, not a big deal for most situations but if you’re in a hurry you’ll want a different program.

Another issue which was no big deal but could be for some people, was that out of the 3 drives I cloned 2 required me to repair the Windows Boot Loader using an install disk. No big deal for me but if you don’t have an install disk for the operating system you have or don’t feel comfortable doing this, it would be a real hassle.

Overall I think Easus Disk Copy did a fine job, it’s free and relatively simple. Since hard drives have become so inexpensive it seems silly to pay for software if you’re only using it on rare occasions. I give it a conditional “fully recommend” rating’ the condition being the user knows how to burn an ISO file and is able to repair the boot loader if needed.

Get Easus Disk Copy here http://download.cnet.com/Easeus-Disk-Copy/3000-2248_4-10867157.html

Monday, July 6, 2009

The MSI Wind U115

The MSI Wind U115 is in a class of its own in the world of netbooks. Unfortunately it’s destined to stay exclusives a few months after being released, MSI is discontinuing the U115 due to the nuances of Microsoft’s licensing policies. The Wind U115 features a bit of technology people have been asking for, for some time. The U115 has a combination of a solid state drive 8 gigabytes in size with a 160 gig spinning hard drive for data.

This hybrid technology delivers a fast booting extremely responsive  little computer that gets up to 12 hours battery life running several applications at a time, wireless on, with the screen brightness turned up all the way. Right now I’ve got 81% battery life left after almost 4 hours of use showing 9:35 remaining.

Like I mentioned this great little machine will not be available long, thanks to Microsoft. The guys from Redmond have decided that the standard netbook pricing for Windows won’t apply to models running the two drive hybrid configuration. Its a shame looking at the U115 no one would ever  aware of the quick launching of programs and the excellent battery life.

The U115 works very well, but its 8 GB SSD drive is almost full when you get the machine. So you start getting nag screens telling you that your C drive is almost full after installing just a few applications to the C drive. The 8GB C drive is the U115’s biggest weakness, to make this design work the SSD needs to be at least 16GB and preferably 32. 32 would allow you to install Windows 7 and a number of applications without running into the space issues. The other negative to the little MSI is the keyboard, its just way to small for my hands. The keyboard is better than the early Eee PC’s but much smaller than some netbooks, and it may be the  deal breaker for me. The touchpad isn’t bad many netbooks do strange things with their touchpads, like sat them to one side and put the  buttons in the front, MSI keeps it conventional clicking is a bit stiff and requires a deliberate push to click on something.

The finish quality of the Wind is quite good, it looks nice and has a solid feel to it. I really like the U115, but you have to be selective about the apps you install unless you want to put them on the D drive. If your going to install iTunes or the Zune software you have to put it on your D drive. I’ll continue to use the U115 but the time to return it for a refund is drawing near and I’ll have to seriously consider if I can live with the keyboard and C drive limitations.

Tuesday, June 23, 2009

Extreme Tech Website and Podcast has been given the axe

Over the last few years Extreme Tech the great enthusiast website for computer builders and do it yourself guys and gals has been one of my top reads on a daily basis. Lloyd Case, Jason Cross, Joel Durham and Jim Lynch have done a great job over the last few years and they will be missed. PC Magazine which was the corporate parent (Under Ziff Davis) has been going downhill for some time. It started with the Departure of Bill Machrone former Editor in Chief a few years ago and ended up going to online only at the end of 2008.

Also gone is the Extreme Tech podcast hosted by the same crew. The podcast was quite informative but it seems PC Mag has ended all its west coast content and is going to run entirely by the east coast branch. Too bad, from what I've seen of the PC Magcast lately they could use some substance. The new "After Dark" iteration of the show is a quick fast forward, once I figure out what it is. The regular show is fine but not really for enthusiast who build their own PC's or think slightly differently from "conventional wisdom".

So it's quite disappointing to see where PC Magazine has gone, there's nothing there for me anymore, nothing I can't get in a million other places. Anandtech, Tom's Hardware, and Maximum PC all do a great job reviewing computer hardware, they don't do the "best bang for the buck" type articles in the same way Extremetech did but, they will have to do.

So to Lloyd, Jason, Joel and the rest of the Extreme Tech crew, goodbye and good luck! And thanks for all the great information over the tears. I'm sure they'll all do fine as cream rises to the top, I look forward to visiting their new sites which I'm sure will be up soon.

Tuesday, April 28, 2009

Troubleshooting a uninstall gone bad

Today I was doing a little maintenance on my daughters Gateway laptop, uninstalling one ant-spyware program and upgrading another to real-time protection. It seemed to go fine, I ran the Uninstall from Programs and Features in Vista and enabled the full time protection in Malwarebytes with the registration codes and rebooted. When the computer shut down I noticed it installing several updates, I didn’t think much of it at the time but when the machine restarted, the brown stuff hit the fan. I didn’t have any mouse! The trackpad was totally unresponsive so I plugged in a old USB trackball mouse, success! So I clicked on the admin account I keep on the machine and went to type my password, nope the keyboard didn’t work either. So I rebooted after plugging in my usb keyboard. Windows went through its usual routine and told me the keyboard had installed and was ready to use, except, it wasn’t. It wouldn’t work at all.

Basically I was hosed, I couldn’t run the device manager from the limited account, or do a system restore. I had to get into the admin account or I was stuck. So I did what any red-blooded geek would do I Googled “resetting a password in Vista”. I came up with usual Microsoft solution, you know the one where you use the password reset CD you made when you set up the com-pu-ter, yep that one, the one no-one ever makes! Fortunately for me I also found a reference to TRK or the Trinity Rescue Kit. TRK is a Linux based bootable CD, that can be used for resetting passwords, recovering files and a few other things relating to Windows calamities. It took a few tries, TRK is command Line based tool and none of the instructions worked exactly as they said they would. Once the CD booted normally I ended up typing winkey u admin, this started TRK searching and mounting all the files in the system. I choose 2/enter in the next dialog then typed an * confirmed with a y, and this created a new administrator account with no password.

I was able to log into the Administrator account and then began the next phase of fixing the corrupted drivers. This took a while longer than I anticipated, I tried deleting the trackpad and keyboard in Device Manager , both had the little caution signs next to them indicating a damaged or corrupted driver, rebooted but this didn’t work. I finally resolved the problem but using a restore point, fortunately you can get there with just a few clicks of the mouse. So I got lucky, the USB mouse worked and the TRK worked after some trial and error. Get the Trinity Rescue Kit here http://trinityhome.org/Home/index.php?wpid=1&front_id=12, I recommend it for your toolkit, it definitely saved my bacon.

Sunday, April 12, 2009

Repair Install in Vista

I’ve heard a number of tech experts including the esteemed Mr. Lloyd Case from Extreme Tech podcast as well as others like Steve from the Podnutz podcast state that there is no way to do “repair install” in Windows Vista similar to XP, or all recent editions of Windows for that matter. Actually Microsoft has given Vista users a way to repair Vista with the install DVD, they're just hiding it a little. And although Vista doesn’t make it obvious like it used to be, it still exists.

So here’s where they're hiding it, you get a repair install in Vista by doing a “In-Place Upgrade”.

1. Start the computer boot to Vista OS.

2. Insert the Windows Vista DVD in the computer's DVD drive.

3. Use one of the following procedures, as appropriate:

If Windows automatically detects the DVD, the Install now screen appears. Click Install now.

If Windows does not automatically detect the DVD, follow these steps:

a. Click the Start Button, type Drive:\setup.exe in the start search box and then click OK.

Note: Drive is the drive letter of the computer's DVD drive.

b. Click Install now.

4. When you reach the "Which type of installation do you want?" screen, click Upgrade to upgrade the current operating system to Windows Vista. Please make sure the edition of Windows Vista is selected correctly.

I didn’t get these instructions by reading a 1000 page manual, I got them from Microsoft when I needed tech support installing SP1. I followed the instructions and it worked great for me. Of coarse if you’re doing anything this extreme make sure you have a full backup and are using the correct disk. If you have SP1 already installed you need have a SP1 disk to do what Microsoft calls an In-Place upgrade (Repair install) in Vista.

Thursday, April 9, 2009

Using Malwarebytes Antispyware Program

I spend a lot of my day listening to podcasts and one of favorites is Podnutz and Podnutz Daily hosted by Steve Cherubino. In his latest episode Steve talks to Bruce Harrison lead researcher for Malwarebytes which is the best antispyware product currently out there, in my humble opinion. The biggest eye opener for me was that Bruce kind of squashed two old habits I've had for running antimalware programs, since I started using them. Bruce stated that Malwarebytes should be run in normal user mode, not safe mode as I've done for ages. He also stated that for the vast majority of users need only run the "Quick Scan" and not the deep scan which can take hours, especially on my Terabyte desktop drive. Bruce stated that Malwarebytes concentrates on folders where malware is targeted these days and ignores folders not targeted in the quick scan. He also gives good advice about running as limited user, and actually sounds pretty optimistic about the war against the cretins who create this junk. For once someone not spreading FUD, it was refreshing.

Check out Podnutz at http://podnutz.com/ and take a look at all of Steve's great content. He's a regular working stiff who still finds the time to put together an amazing amount of online audio and now video content for tech junkies interested in either fixing their own computers or people with their own computer repair business.

Saturday, March 21, 2009

PC-BSD Best Unix for Beginners?

I recently downloaded and installed the latest versions of PC-BSD http://www.pcbsd.org/ and I have to say I’m extremely impressed. The install went fast (18 minutes), and it was extremely simple and straight forward. I downloaded the 7.02 version using the DVD option. Downloading using http went fairly quickly, I tried to use bit-torrent and there were simply not enough seeders to make it reasonable. During the install you get the option of adding various additional components already on the DVD including Firefox 3.0, Thunderbird, and Open Office 3.0. Based on FreeBSD version 7.0 PC-BSD is stable and secure, the GUI is the new KDE 4.1.2 and I really enjoy it. Installing new apps is far easier and straight forward than Linux in my opinion and I’m comparing it side by side with Kubuntu 8.10 which also uses the new version of KDE.

The secret to improving usability in PC-BSD is the PBI or Push button Installer or PC-BSD Installer. The .pbi extension has all the files needed to install the applications by simply double clicking the file, this is essentially the same as an setup.exe file in Windows or the .DMG file in OSX. The pbi applications can be found at http://pbidir.com/ where an great variety of programs can be had. For more hard core Unix geeks the FreeBSD Ports are also available. FreeBSD Ports are similar to the apt-get found in Linux systems and any FreeBSD Port can be downloaded with all their packages and dependencies to install them in PC-BSD. But for beginners everything you’ll need not on the install DVD will be found at pbi.dir.com site.

The default browser in KDE is Konqueror which is what the Safari browser was originally based on, it’s a very fast browser but I vastly prefer Firefox. Firefox on PC-BSD came with all the plug-ins installed to play you tube video’s and to render most web pages as they were meant to be seen.

PC-BSD seems like the perfect OS for a netbook, it’s lightweight and simple, and has great applications like the  Flock browser available which are perfect for social networking sites and cloud based email. Unfortunately a netbook isn’t in the budget right know  but I’d love to hear from anyone who’s installed it on one.

I’ve tried at least a dozen different Linux distros over the past few years and although they all worked fine, I really feel PC-BSD has surpassed them in ease of use for the  beginner. There were a few issue’s though. Although it runs flawlessly on my desktop, PC-BSD did have a few problems on my Thinkpad R60. The Ati video card isn’t supported for 3D graphics and the proprietary driver available on Linux builds doesn’t work. It also had a issue with my wifi card, although it would connect it never showed better than a 25% signal despite being in the same room as the router. The signal would also occasionally drop out only to reappear shortly afterward. So It’s worth looking through their support page and checking to see if your hardware is supported. If your trying it on a laptop with network cards not supported I’d hold off. It’s main feature is simplicity, but that will go away quickly if your hardware has know issues, in that case Ubuntu or Kubuntu might be a better choice.

Despite the few glitches I still recommend PC-BSD it’s well worth a try especially if your the sort of person who always like to try new Linux builds or are looking for a secure and stable operating system to put on your machine without shelling out for Windows.pc-bsd