Wednesday, April 15, 2009

Combating Malware

I have many friends who have asked what they should do if they think their computer might have a virus or malware. They'll often ask me to repair it but the reality is that I'd like to think that I can scrub it but, like the ones John mentions in his blog, there are some that are so deeply imbedded that you'll never truly know if you have eradicated the infection.

Best Buy's Geek Squad charges ~$200 - $400 to scrub your home PC if it has an infection. When I do it on the side, I charge $150/hr and if it looks like it's bad or is going to take more than 2 hours, I advise the guardian, ahem, owner, of their choices of which I prefer a clean installation.

Anyhow, John describes how deep these things can get and how much time you can sink on them.

Combating Malware: "Every day we're reading about new viruses, trojans, spyware and other malware on the internet. I was recently asked about the need to reinstall the operating system from scratch on a virus infected machine. Here is the answer from Security Officer at BIDMC:

Is there a valid technical reason for requiring a rebuild? The answer to this is yes. The thing to focus on here is the Anti in the title of Anti-Virus. These applications are intended to stop an infection. Most of them also include a cleaning component and there are many products marketed solely as cleaning products - spybot-SD is a good example. The problem with these products is that malware is constantly morphing. You see this often in the names of the malware , they will contain .a, .b. .c etc. The longer the malware is out the more variants. This means that the cleaning tools need to keep up as well. The fact of the matter is is that they can not. If a system has critical content on it and it appears to be compromised the only way to ensure it is clean is to completely rebuild the system. The more sophisticated viruses will hide in the boot sector of a drive, others will replace O/S files with variants that contain the virus. The former will load on system startup and have not tracks for the AV or file cleaning applications to locate and clean. The later will look like standard files and be skipped over. We also take the precaution of a system rebuild here at BIDMC when we have a system with clinical or privacy content on it that is believed to have been compromised.

On the discovery component - we are also seeing a uptick in Torpig and mebroot. Torpig and mebroot are of the same family - sinowal. These trojans are a high risk trojan as their objective is to steal identity information - and they are good at it. These are of the type that imbed themselves in the boot sector of the system. As I mentioned above it is very difficult to both detect and to clean this type of trojan. I had a family member with this. As an exercise I attempted to clean the boot sector rather then rebuild. I logged over 40 hours of labor on this effort with a wide range of tools - even down to using a disk sector editor to attempt to clean it with no success.

There is no way to determine the original source of the infection without detailed examination of the system. But, this system is used to browse the web, it has Google desktop loaded and it is running MS Office. The infection could be sourced from a web site that is believed to be good. We saw this on Boston.com not to long ago. These pages link to active advertising sites that are not in their control. Those advertising sites can and often do have malware in them. Google desktop in itself is not an issue - but the actions/benefits it provides automatically link the system to sites in a more automated fashion that increases the exposure of a system. Lastly is Windows itself. During the time between the discovery of a vulnerability and the release of a match all systems are vulnerable. In many cases the exposure time is lengthy. Keeping up with patches is critical but in itself does not ensure protection.

There are companies that offer system analysis. In general you can look to pay $350 - $400 per hour from a quality service. For an 80 Gig drive you are looking at about 4 hours of time for a basic pass over the system. A more detailed analysis will take in excess of 10 hours. As an example we are performing an analysis now on a system. The forensic copy of the disk to perform the analysis took 2 hours. The first pass analysis took an additional 6 hours. We are now starting the second pass and that will be 10 to 12 hours. Our times are about 30% more then a commercial provider due to the equipment we use. This is not a cheap process in money or time.

Due to the high risk that the torpig and mebroot trojans present I would highly recommend to completely rebuild the system ensuring that the boot sector is wiped and re-written. I would then ensure before the system goes back into usage that all windows, Internet Explorer, and office patches are applied.

"



(Via Clippings.)

Tuesday, April 14, 2009

Toddler talk, baby names

Alayne had a great post, the Oscar-the-Grouch reference was hysterical!

Toddler talk, baby names: "From the toddler’s mouth. As Leo’s verbal skills improve, so does his ability to make us laugh. Here are a few examples:

While flipping through a Sesame Street book at the library, we came across a picture of Oscar the Grouch, all green and disheveled sitting inside his garbage can. Leo immediately pointed to Oscar and exclaimed, [...]"



(Via Clippings.)

Monday, April 13, 2009

In Depth: 10 of the most annoying Vista irritations solved

In Depth: 10 of the most annoying Vista irritations solved: "

Like any operating system, Vista has its irritations.

Things have been helped a great deal by Microsoft's updates - updating issues such as slow file transfers - but, even so, there are still several things that niggle us. And we're sure you feel the same way.

So, in order to remedy this, we've gathered together the 10 most common Vista itches that need a scratch - and solved them for you.

1. UAC is always getting in my way

There's nothing worse than having your progress slowed right down when the User Account Control security prompt pops up, but it happens a lot of the time. You can easily disable it, however, provided that you're confident that you won't accidentally uninstall something (you might want to reconsider if younger, less savvy members of your family have access to your computer).

To do this, open the Control Panel, click User Accounts and Family Safety\Turn User Account Control on or off. Then, in the window that opens, clear the Use User Account Control (UAC) to help protect your computer box and click OK.

2. The Start menu power icon doesn't shut down Windows Vista

When you want to shut down your PC, you click on the Windows Vista Start button, then at the bottom of the menu you see three icons – a power symbol, a padlock and an arrow. Now, it looks as though the power button would shut down your PC, but it actually puts it to sleep instead. It's quite easy to change what this button does, however, so you can make it shut down your computer if that's what you would prefer.

To do this, click the Start button and type cmd to open up a command prompt. Now type powercfg.cpl,1 to open up the advanced power settings. You'll see an item called Power buttons and lid. Click the + symbol to expand it, then click the + symbol next to Start menu power button. It should say Sleep. Simply click on this and change it to Shut down instead.

3. My computer keeps waking when I've put it to sleep

Sleep mode in Windows Vista is a real boon when you want to save energy (and money) but don't want to waste time shutting down and starting up your computer every time you stop using it. The majority of the time it works just fine, but occasionally your USB devices will wake it unnecessarily or – conversely – they won't wake your computer when you want them to.

If it's the latter, type Device Manager in Start Search. Expand the tree for the device that won't wake up your computer (such as a mouse or a keyboard), right-click it and choose Properties. Under Power Management, ensure Allow this device to wake the computer is ticked. If your computer immediately wakes up after going into sleep, unplug all devices connected to your PC, then plug them back in one at a time until you find the one responsible.

Try plugging the offending device into a different port, and if this doesn't work, open the Device Manager again and clear the Allow this device to wake the computer box.

4. My PC makes annoying clicking sounds

When you click a link in Internet Explorer or make a selection in Windows Explorer, it makes a clicking sound. If you're listening to music and your speakers are turned up quite high, this can eventually become quite irritating.

To fix the problem, right-click the speaker icon in the right-hand corner of the Taskbar and select Sounds. In the window that appears next, scroll down the list until you get to Start Navigation and click it. In the drop-down Sounds menu just below, select None from the list to get rid of the clicking sounds.

5. My preferred folder view keeps getting changed

One thing that really annoys us in Windows Vista is when you go into a folder, make the size of the icons bigger – such as thumbnails – and when you come back to the folder at a later date, all the icons have reverted back to their standard small size.

It's easy enough to fix this so it doesn't happen again. Launch the Control Panel and click Appearance and Personalization\Folder Options\View, then scroll down and check the Remember each folder's view settings option. Windows Explorer won't even try to save your folder settings until this is checked.

Sometimes, however, folder settings get corrupted. Click the Start button and type regedit, then navigate to HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell.

Click Bags and select Edit\Delete\Yes. Delete the BagMRU key as well, then restart. To avoid problems in the future, increase your folder view cache by navigating to HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell, then double-click BagMRU Size, select Decimal, and set it to 10000. This uses more RAM, but should prevent future memory loss.

6. I can't tell what's happening when I do a disk defrag

The Disk Defragmenter tool keeps your hard drive running at its best, which in turn makes your PC run faster, but it's been simplified since the days of Windows XP. Before, you knew roughly how long you had to wait until it had finished, but now you simply have to wait because there's no way of telling.

One solution to this annoyance is to use a third-party application, such as Power Defragmenter (downloadable here). Once you've unzipped the file, double-click the Power Defragmenter icon to run the program.

You're given four options; choose Defragment Disk. Select the disk you want to defragment and press Defragment. Not only will you be able to tell when your defragmentation operation will finish, but it will be a little bit faster, too.

7. I've accidentally deleted desktop icons and I want them back

We've all done it before – you know, when you're having a little tidy up and you decide to give your desktop a bit of a spring clean. It seems like a good idea at the time, but a couple of weeks later you regret it because every time you want to empty the Recycle Bin or look through your files, you have to find the relevant link buried somewhere else.

Life was so much easier when they were easily accessible, so how do you get them back to your desktop? It's easier than you think – right-click anywhere on the desktop and select Personalize. In the window that opens, click the Change desktop icons link in the left hand area under Tasks.

If you want a system icon back on your desktop for good, just click the check box next to the icon you want to restore and then select OK.

8. I don't know why my PC keeps crashing

The most common type of crash your PC will suffer is when an application shuts down unexpectedly and you get a message from the application or Windows Vista telling you that this has happened. System crashes or BSODs (Blue Screens of Death) are rare, but still happen and are almost always caused by bad drivers or failing hardware.

For either type of crash it's best to start by enabling and examining the reporting tools and then using the information you find to get to the solution. This can be seen in the Reliability and Performance Monitor as Application, Windows or Miscellaneous failures, marked with a cross.

If you're seeing regular crashes, go to Problem Reports and Solutions and select See problems to check\Check for new solutions to report the issue. Some of the issues are diagnosed here and a solution recommended. In these cases, following the instructions will end your crashes. If you need to do more digging, look at the problem history and see if the crashes have anything in common.

Failing hardware often causes random and disparate failures, so if the problems are consistent, it's more likely to be caused by software. Go to the Problem Reports and Solutions section and look at Problem History. Here you can see each crash, which you can examine by double-clicking. By looking at the signatures, you should be able to see if the problems are consistent. If not, try doing a memory and disk scan.

9. Windows Update keeps interrupting me

Whenever Windows Vista installs updates, it asks you to restart your PC once it's done. This is fine in normal circumstances, but when you're hard at work and don't want to restart, it's an annoying interruption, especially when it keeps popping up every five minutes to ask you again.

You can postpone it for anywhere from 10 minutes up to four hours, but if you want to get rid of it altogether, you need to be a little more creative. Click the Start button and type cmd into Start search – but don't press Enter as usual; hold down Ctrl + Shift, and then press Enter.

Now type net stop 'windows update'. This will disable the restart while you're on your PC.

10. Logging in takes ages

Whenever your PC starts up, you have to type your password on the log-in screen so you can get into Windows Vista. This is fine if you share your PC with other people and you want to stop them from accessing your files, but if you're the only person using it, then you don't really need it.

To get rid of this and speed up the log-in process dramatically, click the Start button and type control userpasswords2. Then, simply remove the tick against Users must enter a user name and password to use this computer and click OK.

You'll now have to enter your current password, confirm it and click OK. Now, whenever you start your PC, the log-in screen will be bypassed.



"



(Via Clippings.)

Friday, April 10, 2009

The hidden features in Apple's latest iPhoto '09 update - Image Gallery

For those of you using iPhoto '09, some very helpful features, at least for those of you anal enough to want to include as much photo information as possible. Unfortunately there's still no embedding of faces metadata into the file itself but that's not Apple's deal, it's the JPEG standard. It will however embed the geolocation data.....

Now, where is Aperture 3.0 with faces and places???

The hidden features in Apple's latest iPhoto '09 update - Image Gallery: "Apple did more than bolster stability in iPhoto '09 with its recent update: It also added some cool and useful features to the Faces and Places features. Computerworld columnist Ryan Faas details what's new.



Add to digg
Add to StumbleUpon
Add to Twitter
Add to Slashdot


"



(Via Clippings.)

FriendFeed Is In Danger Of Becoming The Coolest App No One Uses (Michael Arrington/TechCrunch)

This is sad but true. It's really a useful Web 2.0 app but requires a little more active involvement on RSS than most users actively do. Sign up, check it out, keep it around!

FriendFeed Is In Danger Of Becoming The Coolest App No One Uses (Michael Arrington/TechCrunch): "

Michael Arrington / TechCrunch:

FriendFeed Is In Danger Of Becoming The Coolest App No One Uses' —' FriendFeed is a wonderful application that allows users to track what their friends are doing online.' Photos, videos, blog posts and anything else that's published online with a RSS feed can be brought into the service …

"



(Via Clippings.)

What Your Personal E-Mail Provider Says About You

This is pretty funny. I can't say that I disagree. Horoscopes for techies!

What Your Personal E-Mail Provider Says About You: "Almost everyone has a personal e-mail account today, and which provider you choose says a lot about who you are and what you stand for.



Add to digg
Add to StumbleUpon
Add to Twitter
Add to Slashdot


"



(Via Clippings.)

Tuesday, April 7, 2009

More from Trent on the Modern Music Model

The guy just 'gets it'; yet again he is shaping things for the future. He must be the antichrist as far as the RIAA is concerned!

Monday, April 6, 2009

The 10 most important things to teach your users

The 10 most important things to teach your users: "

Your users don’t need an encyclopedic knowledge of how their computers work or how your network is configured — but they may need a little technical enlightenment here and there. This list includes some of the basics that will help them (and you) work more effectively.





This article is also available as an article and as a PDF download.


To be effective in their jobs and contribute value to the business, users need at least a minimal grasp of information technology. Exactly what they need to know varies greatly from environment to environment. But in most organizations, they should at least be able to understand and follow certain computing best practices, including how to effectively report problems and how to safeguard their data.


Frequently, it becomes the responsibility of the support tech to impart this information. Here are the things I believe are most important for support techs to teach their users. Feel free to challenge these suggestions and add some of your own.


1: Rebooting before calling for help


Although telling users to reboot when they experience a problem may seem like a cop out or delaying tactic, it’s an uncomfortable fact that rebooting apparently fixes a multitude of both real and perceived errors. Even if a reboot does not solve the problem, the mere fact that the problem recurs after a reboot can give the canny support tech significant diagnostic information. Rebooting is not a panacea for all computer ailments, and it’s even contraindicated in some cases, but appropriately and correctly applied it’s a useful and simple tool with which to arm your users.


2: Reporting a computer problem


In addition to knowing the correct procedure for reporting computer problems - -e.g., e-mailing the help desk — users need to know what information will help expedite the resolution process. They can easily be trained to effectively report problems if they’re provided with a form that gathers the appropriate information, such as any error messages, open applications, what were they doing when the problem occurred, and whether they can reproduce the problem. Consistently asking users these questions will also serve as training and will help prevent them from either giving too little information or from offering their diagnosis of the problem instead of the symptoms.


3: Keeping passwords safe


There is little point in having a password if it’s written down in an unsecured location or shared among co-workers. I have seen passwords written on post-it notes attached to monitors, inscribed in permanent ink on the side of computer cases, written on the backs of hands, pinned to notice boards, and even displayed as the text of the Marquee screensaver. Instructing users not to write down or share passwords has little impact, however, if they don’t understand why that’s risky or if the password policy is unnecessarily onerous for the environment. On the other hand, an intelligently conceived password policy, suited to the current security needs and well communicated to users, will definitely cut down on the incidence of password carelessness.


4: Constructing secure passwords


While educating users about the importance of securing passwords, take advantage of the opportunity to provide instruction in the art of secure password formation. To a certain extent, password construction is dictated by the constraints implemented through the security system, but in most cases these constraints aren’t sufficient to prevent users from creating easily deciphered passwords.


What constitutes a secure password will vary depending on the environment, but typically, names of family members, sequencing numbers, and obvious words and phrases should be avoided. Random numerals and a mix of cases, punctuation, and spaces is generally encouraged. Obviously, a balance between security and convenience must be found. If the requirements for complexity are too stringent, users will simply revert to writing down their passwords. For more information on secure password construction, check out the PowerPoint presentation ‘Raise user awareness about password security’ and the article ‘Help users create complex passwords that are easy to remember.’


5: Practicing safe computing while traveling


Taking a notebook, PDA, or other device on the road requires increased vigilance to prevent unauthorized access. Users need to know how to protect their data while out of the office and they need the appropriate tools to do it. For example, remote access tokens should not be carried in the same case as the computer; access codes, names, and passwords should not be written down; sensitive data should be encrypted and/or stored on removable data storage devices, also carried separately from the computer; computers should never be left unattended; and consoles should be secured when not in use. See ‘10 things you should do before letting users take their laptops out the door’ and ‘End user laptop: Lock it down in 10 steps’ for more best practices.


As a footnote, this might also be an opportune time to remind notebook users that they will keep us very happy if they remember to remove all solid objects, usually pens, from their keyboards before slamming down their lids.


6: Preventing loss of data


Users need to know that backups don’t happen by magic, and that if they delete a file before it has been backed up, it may not be recoverable. In most environments, individual users are at least partially accountable for regularly backing up their data, regardless of whether it resides in discrete files or within an application. Users need to know what’s backed up and when and not simply assume that every file they create or modify, regardless of location, will be backed up. This is particularly true for users with notebooks, removable drives, and other mobile devices.


Making users aware of backup routines may also have the usually desirable side effect of reducing the number of non-work related personal files saved to backed up locations. ‘10 things you can do to protect your data’ will give your users a good overview of the basic concepts of data security.


7: Observing usage policies (No, it’s not okay to hide pornography in Word docs or install Dr. Seuss Reading Games on ‘your’ computer…


…for your five-year-old to play over the weekend and then remove it before returning to the office on Monday.) When it comes to personal use of corporate IT resources, most organizations have some sort of policy, more or less stringently enforced, defining what is and what is not acceptable usage. Generally speaking, such policies are put in place to protect the company from lawsuits and to protect the integrity of the IT infrastructure. To be effective, such policies must be appropriate for the environment, be clearly communicated, and be enforceable with well-defined consequences for violators.


Regardless of the strength or content of the policy, we would like our users to know that it is not acceptable to violate it, especially not in sneaky ways that insult our intelligence. In addition to knowing the policy, users need to know that we have measures in place for detecting attempts at violation. As much as we don’t wish to play the role of compliance police, we are forced to do so to protect our network and our jobs.


8: Exercising care in sending e-mails


How many times have you been asked to recall an e-mail accidentally sent to the wrong person or persons? Over the years I have seen the following messages misdirected: termination notices, pay raise denials, extremely personal medical information about a girlfriend sent to the user’s wife, and images of a questionable nature accidentally sent to the director of human resources. Regardless of an organization’s e-mail policy, users need to be aware of this danger and be taught to exercise appropriate caution: Think before pressing Reply To All, double-check addressees before clicking Send, refrain from using the corporate e-mail system for non-business related messages, and in general, regard e-mail messages as postcards instead of letters.


9: Protecting against viruses, phishing, malware, and other nasties


Although it is usually the responsibility of the IT professionals to protect corporate resources, this protection can never be 100 percent foolproof, so we are forced to depend on the vigilance of the user. Users need to be taught to recognize and handle threats and the consequences of not doing so. They need to be provided with specific information on how to identify phishing and how malicious e-mail can appear to be from a legitimate contact. They should be warned not to open e-mails from unknown sources, not to open unidentified attachments, not to enter their corporate e-mail address on Web sites, and not to turn off any protection on their computer. They should understand the need to stay on top of antivirus updates. Frequent reports of new threats and statistics of how many viruses have been caught within your organization can also help raise their security awareness.


10: Remembering that support techs work most effectively when adequately supplied with chocolate


This requires no further explanation.





Finally: 10 Things… the newsletter!


Get the key facts on a wide range of technologies, techniques, strategies, and skills with the help of the concise need-to-know lists featured in TechRepublic’s 10 Things newsletter, delivered every Friday. Automatically sign up today.







"



(Via Clippings.)

Portable Internet

A few months ago I picked up the AutoNet Mobile portable router to have Internet access while camping and vacations. I was very optimistic particularly since it uses the Verizon network which advertises such comprehensive coverage. Now I also have a work-supplied AT&T iPhone. In virtually all instances of camping, from the northern California coast, the Sierra foothills, and Yosemite, I have NOT had any coverage on the Verizon side but my AT&T network has had at least a couple of bars in all instances. Now this is key to me since I need to keep tabs on things even while on vacation and camping.

The nice part about the AutoNet device was that it is a WWAN receiver as well as a WiFi router that works on 12 volts (perfect for automotive/RV applications). Unfortunately, with where I go, the coverage off the Interstates was virtually non-existent.

I've now transitioned to a 2 part solution... An AT&T Mercury (Sierra Wireless 885) WWAN 3G device along with a Cradlepoint PHS300 'personal hotspot'. The Mercury is a USB WWAN modem that works directly with Macs and PCs and is quite quick and has a slot for a Micro-SD card. It's otherwise pretty unremarkable but it works fine and is quick to connect to the cell network. The Cradlepoint PHS300 is a portable hard drive sized box and can be charged via the included AC charger or the optional travel charger. It works with a bunch of WWAN USB cards and has more options on the router/network configuration than most of the Linksys/D-link/Netgear routers that you'd use at home. It's a slick device, but you'll be hard pressed to find one for much less than $160.

So with the new solution, I can run virtually anyone's WWAN USB, it has a batter or car charger option and is smaller, offers more security options, and the total hardware cost is actually lower than the AutoNet. It gives you more flexibility and security.

This is a great combo for those of you who want mobile Internet.

Wednesday, April 1, 2009

The Hive Mind

John has a very good article on the Hive Mind. There's been a movement toward 'it's not what you know but being able to find what you need to know.' One of my beliefs is that a successful characteristic will be the ability to quickly locate the necessary information. Anyway, John's more eloquent than I am this morning so please do read on...

The Hive Mind: "Over the past few years, I've radically redesigned my approach to learning. In the past, I memorized information. Now, I need to be a knowledge navigator, not a repository of facts. I've delegated the management of facts to the 'Hive Mind' of the internet. With Web 2.0, we're all publishers and authors. Every one of us can be instantly connected to the best experts, the most up to date news, and an exobyte multimedia repository. However, much of the internet has no editor, so the Hive Mind information is probably only 80% factual - the challenge is that you do not know which 80%.

Here are few examples of my recent use of the Hive Mind as my auxiliary brain.

I was listening to a 1970's oldies station and heard a few bars of a song. I did not remember the song name, album or artist. I did remember the words 'Logical', 'Cynical', 'Magical'. Entering these into a search engine, I immediately retrieved Supertramp's Logical Song lyrics. With the Hive Mind, I can now flush all the fragments of song lyrics from my brain without fear.

My daughter asked me a question from her chemistry homework about calculating the mass of nitrogen gas gathered over water. I did remember the ideal gas law (PV=nRT), but I did not recall how to correct for the partial pressure of water using Dalton's Law. One quick search for 'nitrogen collected over water' yield sample problem sets from colleges that refreshed my memory with all I needed to know.

While writing, I'm constantly looking up words, concepts, maps, and dates. I know how to look for them and where to find them.

There are a few times when the Hive Mind yields surprising results. I wanted to learn more about the Stimulus Bill's 'Healthcare IT Standards Committee'. I wanted to check out the 'ARRA privacy timeline'. Finally, I was looking for information about the 'healthcare CIO'. All three of these searches returned my own writing as the first hit. The blessing and the curse of Web 2.0 is that blogs are the news and personal opinions can become facts.

At the moment I have a balanced separation between my own mind and the Hive Mind. However, as we Twitter, Facebook, and LinkedIn, I wonder if the separation between our human mind and our network mind will blur.

I remember an Outer Limits episode Stream of Consciousness (actually, I found it in Wikipedia by searching Google for 'outer limits episode stream') in which everyone in society is connected to the 'Stream' and shares a network connected existence based on information, not knowledge. In the end, the Stream is destroyed and mankind has to re-learn how to think for themselves.

As the closing dialog of that episode notes

'We make tools to extend our abilities, to further our reach, and fulfill our aspirations. But we must never let them define us. For if there is no difference between tool and maker, then who will be left to build the world?'

Words to live by as we use the Hive Mind of the internet.

"



(Via Life as a Healthcare CIO.)