Wednesday, December 3, 2008

Sandboxie - It just might save your PC one day

With the ever increasing amount of malware and spyware on the internet, it is really hard to keep your pc free from all the baddies. I still remember that evening when I was trying to look for a program that I desperatly needed when I by mistake clicked on a link that I shouldnt have. Just a second after the ill fated click, my mouse pointer grew a brain of its own, my desktop turned scarlet and my taskbar was mine no more! Being the adventure seeker that I am, I took this to be one of those "learning" moments in my life and spent around 3 hours trying to fight the malware Trojan.Vundo . It surely was stubborn but it finally realised that I was more stubborn. Charging like a mad rhinocerous, I finally subdued it and managed to banish it to the dark realms it had creapt out of. Well the tiresome exercise did leave me with alot of experience and red eyes of course. I finally returned to bed, satisfied that I had avenged my pc.

Now, being a few months wiser, I have got McAfee Total Protection 2008 installed on my pc and I religiously check it every day to ensure that it is up to date as far as the virus definitions are concerned. But for those of you that are techie enough, know that you could have the best antivirus/antispyware/antimalware software installed on your pc, with the latest updates installed, but your system can still get compromised. These protection softwares use an engine that uses history and heuristics to find virus patterns. So at times they might not identify malware/viruses that do not have the same patterns as any that were previously seen. And you might be the first of the few that might get their machine toasted by them! By the time your security software vendors find out about it and release the updates, your pc might have flat lined!

Dont you just wish at those times, you had a universal UNDO button that you could use to reverse all the damages that that virus/malware did to your system?

Well say no more because there is just such a software called Sandboxie . It runs programs in a space of its own. In this way everything that the program does is partitioned from the actual system and can be easily reversed because these changes are not committed. It is a really good software to check out. I have just started using it and I love the concept of it.

Have a safe festive season

Sunday, September 7, 2008

Week 36 Article 01 - Whats with this Microsoft Ad?

I was left scratching my head after looking at this Windows Advertisement. Is it that Windows will be come more Delicious in the future? Delicious to who? Hackers, pirates or customers?



Some of the things that this advertisement has left behind with me are as follows
1. Are you for real? Bill Gates at a mall Shoe shop with no security guards? If I knew Bill was coming to town, I would be there to either catch a glimpse of him or to pass on my pages of woes about Windows, and Microsoft as a whole. And I bet there will be others with the same mentality.
2. Whats with the shop name .. Shoe Cirus? Is that supposed to make me think that Microsoft is made of clowns?
3. Seinfeld? Ahem wasnt he in the ad for apple some time back?


4. I dont hear anything about Windows till the last few seconds, even that is unclear. Is this another of Microsoft's tricks to dupe people?
Ahem does the Mojave Experiment come to mind? Lets discuss a few things about this experiment. First of all, are these people off the street or paid actors? What was the spec of the machines Vista was installed during the experiment? Was it just any pc picked from the crowd or was it a new machine bought especially for this experiment that had twice of everything in the Recommended Systems Requirements pasted on the Vista box? Did they even test Vista with all the printers out there? How about those programs that have broken after upgrading from XP to Vista?



I have a feeling that Microsoft is now realising that it is not the choice of the millions any more. There has been competition in the past from linux and apple but not to the extent that it is these days. Microsoft is now trying to pull people back after pushing their crap onto them for years. With the new Internet Explorer rival from Google, Microsoft is standing again on shaky ground. Google has employed what MS did some years back when they brought out Internet Explorer. They bundled IE with Windows, and people found it easier to use that than download a browser from any other place. Now that most of the search happens on google, why wouldn't you go for a browser that gives you more customized response for your searches? Googles dream of creating a cloudsphere has started with the release of Chrome , which is said to be a Web OS

R.I.P Microsoft :(

But I must say, had it not been for Microsoft, I would be without a job. I spend my days fixing problems created by Micrsoft, so I guess I shouldnt be complaining hehe. Thumbs up on the good job Microsoft. Please introduce more software bugs so that I can make a killing providing support to all the MS users.

Tuesday, August 26, 2008

Week 35 Article 03 - Cannot login to Symantec Endpoint Protection Manager Console Aaargh!! But I solved it at last

The latest Symantec Corporate Antivirus product in the market is Symantec Endpoint Protection v11. Since almost all my customers are using Symantec for Antivirus protection, this year, as part of their upgrades, Symantec Endpoint Protection (SEP) was installed.

SEP is Symantec's attempt at controlling the client pcs using policys as found in Windows domains. If you were to look at the policy structure, it looks so familiar to the group policy found in Windows 2000.

Now, lately I have noticed that I am unable to login to the Symantec Endpoint Protection Manager (SEPM). This is the administration console for SEP, where you can monitor and roll out new clients, just to name a few functions. The message shown when I try logging on is as follows



Investigating further, I found that the Symantec Endpoint Protection Manager service was stopped. I restarted this but within a few seconds, it stopped again. Looking through the Windows event logs I found the following entries
EventID: 4096 Source: SemSrv
The Java Virtual Machine has exited with a code of -1, the service is being stopped.

EventID: 5 Source: SemSrv
The semsrv service has stopped.


After countless hours of trolling google for answers, I finally managed to get this solved myself. And as for Symantec support, well it would be good if they knew they product abit better!!

Listed below are the steps to rectify this problem.
1. Ensure that you have a copy of the SEPM installer
2. Be aware that you will have to re-add all clients to the server. Dont worry you dont have to reinstall the antivirus client. There is an easier way and I will tell you that towards the end of this document.
3. Check your IIS on the server hosting SEPM to see what website is currently using tcp port 80 for incoming traffic. The fix forces SEPM to use tcp port 80, thereby disrupting any other websites that might be expecting traffic on the same tcp port.
4. Go to Add/Remove Programs and click on Change beside Symantec Endpoint Protection Manager. When the uninstaller starts, click on Remove.
5. During the next few screens you will be asked if you want to remove the database files and the backup files. Leave these unticked.
6. Once the uninstall has finised, start the installer for SEPM.
7. When you come to the selection for selecting a Web Site, Use the default Web site is selected by default. Choose the one below that choice, which is Create a custom website.
8. Follow through with the default settings for the rest of the choices.
9. Once installed, you will be able to login to SEPM.
10. Now you have to go into IIS and change the listening port for the website that was originally listening on port 80. Once you have changed it, start this website and check to ensure that it comes up alright. If you still get an error saying that some other program is using the new tcp port but you are sure that none is (you did a netstat -a -o), then in the website properties, click on advanced beside the IP address to ensure that that website is not listening on multiple ports.
11.Now, you have to re-add all the clients back into your SEPM domain. This can be done using the steps listed in document found at http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007082009543848?Open&seg=ent

Have fun and yeah you can always email me your thanks at nivleshc@yahoo.com or just leave a nice comment.

Cya