<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="b2evolution/2.4.1" -->
<rss version="0.92">
	<channel>
		<title>Back and Forth</title>
		<link>http://www.forthphaze.com/blogs/</link>
		<description></description>
		<language>en-US</language>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
				<item>
			<title>Fake Antivirus Removal Tips</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=fake-antivirus-removal-tips&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;The battle against the fake antivirus programs has intensified int he past few months, and unfortunately there&amp;#8217;s no end in sight. Blair Fritz, ForthPhaze Support Specialist, cleaned up an infection this week on an XP system, and we thought it might be interesting to explain the process we use to fix these infections. &lt;/p&gt;

&lt;p&gt;&lt;b&gt;1.&lt;/b&gt; The first thing we have to do is stop the part of the attack that prevents installing or opening programs on your system. There are a couple of ways to go about this. The easiest way is to open the startup tab in msconfig (Start/Run/msconfig) and find the part of the virus that loads when you start your computer. The entries on the startup tab can be cryptic, but there are two ways to tell which is the bad program. Under the Command column, look for any entry that points to C:\Documents and Settings. Legitimate programs will be installed in C:\Windows or C:\Program Files. Anything that loads out of C:\Documents and Settings should raise a red flag. Another marker is a Startup Item name that&amp;#8217;s just a random collection of eight letters and numbers. If you find these, click off the check mark next to it and click apply, then restart the computer. &lt;/p&gt;

&lt;p&gt;If you have a simple infection, this will stop the program that was blocking your other programs. If it doesn&amp;#8217;t work, plan B is to restart the computer again but this time press F8 while the computer is restarting. This will load the Windows startup option page. Select Safe Mode with Networking and press enter. Safe mode only installs the basic Windows components and drivers, no add-on software is installed and this stops the infection from loading most of the time. &lt;/p&gt;

&lt;p&gt;If this doesn&amp;#8217;t work, you&amp;#8217;ll need to run a program that kills the blocking program from the desktop. We are huge fans of a program called &lt;a href=&quot;http://www.bleepingcomputer.com/forums/topic308364.html&quot;&gt;rKill&lt;/a&gt;. Download it on an uninfected computer (only from that page!) to a thumb drive, copy it to the desktop, and then double click to run it. It might take a few minutes to complete, but when it&amp;#8217;s finished you should be able to open all the programs on your computer that you weren&amp;#8217;t able to open before. &lt;/p&gt;

&lt;p&gt;One important note: Once you get to this point, do not restart your computer or you might go back to square one. &lt;/p&gt;

&lt;p&gt;Now that we can open programs, it&amp;#8217;s on to step two&amp;#8230;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;2.&lt;/b&gt; This one is short and easy. We need to make sure we can get to the internet. Open your web browser of choice. If it connects to your homepage and you can get around the web, you&amp;#8217;re ready for step three. &lt;/p&gt;

&lt;p&gt;If you can&amp;#8217;t get online, the infection has tried to redirect your connection to the web. Fortunately it is an easy fix. Open the Control Panel and click Internet Options. Under the Connections tab, click the button for LAN Settings, and then uncheck the box for &amp;#8220;Use a proxy server for your LAN.&amp;#8221; Click OK to exit and restart your browser, it should open on your home page and you should be able to visit any website. &lt;/p&gt;

&lt;p&gt;&lt;b&gt;3.&lt;/b&gt; Now we&amp;#8217;re ready to install the software we use to remove the virus from a system. &lt;/p&gt;

&lt;p&gt;We use three different programs. The first is &lt;a href=&quot;http://www.bleepingcomputer.com/download/anti-virus/combofix&quot;&gt;Combofix&lt;/a&gt;. (Again, only download it through that page.) It&amp;#8217;s an amazing virus and malware removal tool. Download it, and double click it to run. There will be a pop-up screen warning that it might conflict with your antivirus program, but we always click to continue and have never had a problem.&lt;/p&gt;

&lt;p&gt;Combofix will ask to install Microsoft&amp;#8217;s Windows Recovery Console as part of its installation. Let it. This is an add-on that should be on every Windows system by default. After that, just let Combofix run. Depending on the infection it might take up to a half-hour to clean the system, and you might be prompted to reboot. (If so, return to safe mode by pressing F8 like before.) When Combofix is finished it will generate a text report that is going to be gibberish unless you&amp;#8217;re a security specialist. Don&amp;#8217;t worry about it. &lt;/p&gt;

&lt;p&gt;The second program we use is &lt;a href=&quot;http://www.filehippo.com/download_malwarebytes_anti_malware/&quot;&gt;Malwarebytes Anti-Malware&lt;/a&gt;, or MWB for short. We use MWB as part of a virus infection repair to double check for infections, but it&amp;#8217;s really good at removing tracking cookies and other spyware that everyone gets on their computers. Running MWB every couple of weeks is a great habit to get into. &lt;/p&gt;

&lt;p&gt;We do a full system scan with MWB after running Combofix. In almost all cases it comes back clean, but there have been a couple of times when it&amp;#8217;s found infections that were missed by Combofix. &lt;/p&gt;

&lt;p&gt;You can remove these with MWB, but infected files showing up in MWB after Combofix has always meant a deeper infection in our experience. If you delete them with MWB, the infection will probably return the next time you restart your computer. &lt;/p&gt;

&lt;p&gt;The fix is in a good antivirus program. We have become big fans of &lt;a href=&quot;http://www.microsoft.com/security_essentials/&quot;&gt;Microsoft Security Essentials&lt;/a&gt; for home users. It has yet to let us down on cleaning up an infected system, even when Combofix didn&amp;#8217;t work, and it&amp;#8217;s tested very well on preventing infections. &lt;/p&gt;

&lt;p&gt;You might be wondering, if Microsoft Security Essentials is so good then why not skip Combofix and Malwarebytes and just install MSE? It&amp;#8217;s about time. It takes us less time to use Combofix and MWB to clean up a system, and then install MSE (or AVG Network Edition for our business clients) for future protection. Even when we have to use MSE to clean up an infection, we still do a second scan. It&amp;#8217;s not clean until you have a clean scan.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;4.&lt;/b&gt; The final step is doing what you can to prevent another attack. &lt;/p&gt;

&lt;p&gt;Use a comprehensive antivirus program. We recommend Microsoft Security Essentials for home systems and AVG Network Edition for business networks. &lt;/p&gt;

&lt;p&gt;Make sure your system has the most recent Microsoft, Adobe and Sun/Java updates installed. It&amp;#8217;s hard to use a computer without Adobe Acrobat Reader and Flash, or Sun&amp;#8217;s Java programming, but all three have been the source of security problems. Keep them updated.&lt;/p&gt;

&lt;p&gt;Set your browser to block all pop ups. Firefox and Google Chrome have this setting by default, but it has to be changed on Internet Explorer through Tools/Internet Options/Privacy. Make sure the box for &amp;#8220;Turn on Pop-Up Blocker&amp;#8221; is checked, then click the Settings button and change the Blocking Level to High: Block all pop ups.&lt;/p&gt;

&lt;p&gt;You can use the browsing history to see which site you were at when you got the infection, but it&amp;#8217;s not going to be a lot of help in preventing a future infection. These attacks come from a pop-up ad. Most websites use third-party companies to sell and place ads on their site. The ad brokers scan submissions for viruses, but the virus writers get around this by creating an innocent looking fake ad that opens a pop up window when the page loads or you roll your mouse over it. The virus is in the pop up window, and this is beyond the control of the web site and the ad broker. The best defense is a good antivirus program to stop the program before it loads on your computer and setting your web browser to block all pop ups.&lt;/p&gt;

&lt;p&gt;If you have tried doing the above steps but are still having trouble cleaning up the system, or you are uncomfortable performing any of these tasks, feel free to &lt;a href=&quot;http://www.forthphaze.com/index.php?page=ContactUs&quot;&gt;contact us&lt;/a&gt;.  We are here to help!  (and our rates are not as high as the Geek Squad)&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=fake-antivirus-removal-tips&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>Dropbox Your Windows Server Shares</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=dropbox-your-windows-server-shares&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;I&amp;#8217;ve read several posts on how to use @DropBox on a Windows Server.  The information seems to be fragmented, and not always accurate.  I&amp;#8217;m going to summarize two things today. First, I&amp;#8217;ll cover setting up @Dropbox on a Windows server, and second, I&amp;#8217;ll briefly discuss security considerations.  I&amp;#8217;ll be working with Windows 2008, you can do the same with Windows 2003.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;strong&gt;Setting Up @DropBox&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Logon to the Widows Server as administrator&lt;/li&gt;
  &lt;li&gt;Download and install DropBox from their website&lt;/li&gt;
  &lt;li&gt;Copy contents of C:\Users\Administrator\AppData\Roaming\Dropbox\bin to a new folder C:\Program Files\Dropbox&lt;/li&gt;
  &lt;li&gt;Obtain the Windows 2003 Resource kit files instsrv.exe and srvany.exe.  It is perfectly safe to install the Windows 2003 Resrouce Kit on Win2008.&lt;/li&gt;
  &lt;li&gt;Copy instsrv.exe to C:\Program Files\Dropbox&lt;/li&gt;
  &lt;li&gt;Copy srvany.exe to C:\Program Files\Dropbox&lt;/li&gt;
  &lt;li&gt;Open Command Prompt&lt;/li&gt;
  &lt;li&gt;Execute &amp;#8220;C:\Program Files\Dropbox\instsrv.exe&amp;#8221; Dropbox &amp;#8220;C:\Program Files\Dropbox\srvany.exe&amp;#8221;&lt;/li&gt;
  &lt;li&gt;Execute REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Dropbox\Parameters /v Application /d &amp;#8220;C:\Program Files\Dropbox\Dropbox.exe&amp;#8221;&lt;/li&gt;
  &lt;li&gt;Execute REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Dropbox\Parameters /v AppDirectory /d &amp;#8220;C:\Program Files\Dropbox&amp;#8221;&lt;/li&gt;
  &lt;li&gt;Delete or move the shortcut to Dropbox away from the startfolder (Start -&gt; All Programs -&gt; Startup) on the startmenu&lt;/li&gt;
  &lt;li&gt;Launch Services.msc&lt;/li&gt;
  &lt;li&gt;Right-click DropBox service, logon tab, check the Allow service to interact with desktop option&lt;/li&gt;
  &lt;li&gt;Execute net start Dropbox&lt;/li&gt;
  &lt;li&gt;Move your shared folders you need to share with outside users into your DropBox folder location, and reset sharing permissions.  NTFS permissions should be maintained&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;One thing that is a &amp;#8220;quirk&amp;#8221; I&amp;#8217;ve found so far, despite the interact with desktop option in Services, you may need to execute dropbox.exe to get the System Tray icon to appear.  This does cause a second DropBox process, though, so you should kill one of them.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;strong&gt;Security Considerations&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The biggest question to be asked in setting this up, from the Network Administrator&amp;#8217;s point of view is &amp;#8220;Does the convenience of this service create a less secure computing environment?&amp;#8221;&lt;/p&gt;

&lt;p&gt;There are a few things that are well documented in regards to security of @DropBox.   Here are &lt;a href=&quot;https://www.dropbox.com/help/27&quot;&gt;their statements &lt;/a&gt;in regards to security:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Shared folders are viewable only by people you invite&lt;/li&gt;
  &lt;li&gt;All files stored on Dropbox servers are encrypted (AES-256) and are inaccessible without your account password  &lt;br /&gt;
  &lt;li&gt;All transmission of file data and metadata occurs over an encrypted channel (SSL)&lt;/li&gt;
  &lt;li&gt;Dropbox website and client software have been hardened against attacks from hackers &lt;/li&gt;
  &lt;li&gt;Online access to your files require your username and password&lt;/li&gt;
  &lt;li&gt;Public files are only viewable by people who have a link to the file(s). Public folders are not browsable or searchable&lt;/li&gt;
  &lt;li&gt;Dropbox employees aren&amp;#8217;t able to access user files, and when troubleshooting an account they only have access to file metadata (filenames, file sizes, etc., not the file contents)&lt;/li&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;In regards to @DropBox security standards, it does meet the minimum encryption standards for industry compliance, such as HIPAA and SARBOX.  The one well documented problem with the security implementation is that you, the enterprise and owner of your data, have no access to or control of the encryption key.&lt;/p&gt;

&lt;p&gt;The main question that is asked by Network Administrators is, is it as safe as a VPN?  The answer is more a policy answer than a technical answer.  I would say technically, yes, as far as the encryption in place.  However, policy plays a big role here as well:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;How secure are the devices that are accessing the data through DropBox?&lt;/li&gt;
&lt;li&gt;What are the password policies&lt;/li&gt;
&lt;li&gt;What are the lockdown/wipe policies of mobile devices, such as laptops, netbooks,and smartphones?&lt;/li&gt;
&lt;li&gt;Who has access to the account credentials for DropBox?&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Just as an employee can walk out the door to the office and leave it unlocked at the end of the day, similar security breaches can be made with a cloud computing service, or a local computing service.  Any security that is put in place is only as good as the policies and practices of company employees to protect the enterprise.  To provide the best security possible, at a minimum:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Only Network Administrators and authorized management level employees should have access to the credentials for the DropBox account(s).&lt;/li&gt;
&lt;li&gt;Authorized personnel should install and setup the service&lt;/li&gt;
&lt;li&gt;Security harden all devices that will be accessing company data from outside the company network.&lt;/li&gt;
&lt;li&gt;Ensure your Acceptable Use Policies and Procedures up to date&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Training is also important.  Ensure that employees know how to work within @DropBox and manipulate files.  Make sure they have learned and understand the ramifications of sharing folders and files.&lt;/p&gt;

&lt;p&gt;These are a few considerations that need to be made.  There are many more, such as using TrueCrypt or Windows BitLocker to enrypt files at the source and local cache, or how to create a secure publishing mechanism within @DropBox to publish files to your clients.  For these considerations, a professional IT firm should be consulted.  If you have any questions on this topic, feel free to &lt;a href=&quot;http://www.forthphaze.com/index.php?page=ContactUs&quot;&gt;contact us&lt;/a&gt;, and we&amp;#8217;ll be happy to assist.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&amp;#8211;Chris Dickens, Systems Enginner and Owner, ForthPhaze Technology, LLC&lt;/em&gt;&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=dropbox-your-windows-server-shares&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>Preventing a Fake Antivirus Attack</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=preventing-a-fake-antivirus-attack&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;We&amp;#8217;ve seen a big surge recently in fake antivirus attacks. These virus and malware programs have been around for a couple of years but they&amp;#8217;ve recently become much more dangerous and more difficult to remove from infected systems. &lt;/p&gt;

&lt;p&gt;If you&amp;#8217;re not familiar with this kind of attack, it uses a pop up window telling you that your system is infected with multiple viruses or that you no longer have antivirus protection. Google has images of dozens of different examples that you can look through &lt;a href=&quot;http://www.google.com/images?q=fake%20antivirus%20programs&amp;amp;oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;source=og&amp;amp;sa=N&amp;amp;hl=en&amp;amp;tab=wi&quot;&gt;here.&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;The point of this attack is to create a moment of panic and get you to click on the link to repair the problem. If you do that it will install malware on your computer and take you to a page where you hand over your credit card number to &amp;#8220;fix&amp;#8221; it. &lt;/p&gt;

&lt;p&gt;Most users are smart enough to avoid falling for that, but that doesn&amp;#8217;t mean you&amp;#8217;re out of the woods. The creators of this pop up lied about your system being infected, they&amp;#8217;re lying about fixing it if you click on their link - and they&amp;#8217;re lying that clicking the &amp;#8220;X&amp;#8221; in the top right corner will just close the window. Clicking anywhere on the pop up will install its malware and virus programs on your computer. &lt;/p&gt;

&lt;p&gt;One way to close the window without infecting your computer is with the ALT-F4 keystroke, which closes the active window.  However, a safer method is to press Control-Alt-Delete (at the same time) and click on the button to open the Task Manager. A small window should open with tabs for Applications, Processes, Performance, etc. Click on the Applications tab and then close all of the applications running in that window, by clicking on each application once to highlight it and then clicking the End Task button at the bottom. Run a virus scan on your system immediately after the pop up closes. &lt;/p&gt;

&lt;p&gt;The one bit of good news with this kind of attack is that it is easy to prevent. It works through a pop up window and most commonly comes through your internet browser. If you can prevent the pop up, you can prevent the fake warning from ever appearing on your system. &lt;/p&gt;

&lt;p&gt;To prevent fake antivirus attacks, &lt;em&gt;FIRST&lt;/em&gt; you should update to the latest browser of choice.  If you are still using Internet Explorer 7.0 or older, update it immediately to IE8.  Or, switch to Firefox.  Both Internet Explorer and Firefox have good pop up blockers, but Firefox has a couple of advantages. First, the pop-up blocker in IE is set by default to &amp;#8220;block &lt;em&gt;most&lt;/em&gt; automatic pop-ups&amp;#8221; and this has allowed the fake antivirus pop up to get through. (You can change this to block all popups in IE&amp;#8217;s Internet Options/Privacy settings.) Second, the pop-up blocker in Firefox has been more effective at the default settings, but the big advantage Firefox has is a plug in available from their website that &lt;a href=&quot;https://addons.mozilla.org/en-US/firefox/addon/1865&quot;&gt;blocks practically all internet ads.&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;&lt;em&gt;NEXT&lt;/em&gt;, you should also make sure your Windows version is kept up to date. Microsoft now includes a very good malicious software removal tool that can stop these infections before they get on your system, but it only works if your system is kept up to date. &lt;/p&gt;

&lt;p&gt;&lt;em&gt;LAST&lt;/em&gt;, make sure you&amp;#8217;re using a good comprehensive antivirus suite. The variations in these viruses makes it impossible to recommend one brand as the best, but any antivirus and security suite from a reputable company (AVG, Norton, Trend, Microsoft) will give you much better odds of being protected than a basic antivirus program that only scans your email.&lt;/p&gt;

&lt;p&gt;If you do get infected, &lt;a href=&quot;http://www.forthphaze.com/index.php?page=ContactUs&quot;&gt;contact us&lt;/a&gt;. A simple infection can be cleaned up quickly, and if you have a bad infection we&amp;#8217;ll clean it up and help you with the next steps to protect yourself and your identity.&lt;/p&gt;


&lt;p&gt;&lt;em&gt;-Brian Igo, IT Support Specialist&lt;/em&gt;&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=preventing-a-fake-antivirus-attack&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>How to Bypass Traditional Customer Service for a Better Experience</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=how-to-bypass-traditional-customer-servi&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;Last week, I was trying to solve a few technical problems on the job.  One was an issue with a &lt;a href=&quot;http://www.watchguard.com/&quot; target=&quot;_blank&quot;&gt;Watchguard &lt;/a&gt;firewall device.  I won&amp;#8217;t bore you with the details.  My other problem was figuring out a great way to do time tracking on a smartphone that easily integrates with &lt;a href=&quot;http://quickbooks.intuit.com/&quot; target=&quot;_blank&quot;&gt;Quickbooks&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;On &lt;a href=&quot;http://twitter.com/chrisdickens&quot; target=&quot;_blank&quot;&gt;Twitter &lt;/a&gt;last week, I posted a few questions regarding my Quickbooks problem, seeking advice or input from my followers on any suggestions they may have.  I even sent &lt;a href=&quot;http://twitter.com/chrisdickens/status/1136317730&quot; target=&quot;_blank&quot;&gt;a comment &lt;/a&gt; @Quickbooks so that Intuit would respond.  Their &lt;a href=&quot;http://twitter.com/quickbooks/status/1139821471&quot; target=&quot;_blank&quot;&gt;response &lt;/a&gt;was lackluster, but in the posting the questions, I received a recommendation on @Tsheets.  Within a day I also had a &lt;a href=&quot;http://twitter.com/tsheets/status/1139691530&quot; target=&quot;_blank&quot;&gt;response from Jen Harris&lt;/a&gt;, from Tsheets.com and also received a phone call from her.  We talked about their service, but also spent about 10 minutes talking about the power of social media for brand development engaging your target consumer.&lt;/p&gt;

&lt;p&gt;On my Watchguard problem, I wasn&amp;#8217;t necessarily searching for an answer on Twitter.  I posted a &lt;a href=&quot;http://twitter.com/chrisdickens/status/1134629796&quot; target=&quot;_blank&quot;&gt;rhetorical question&lt;/a&gt;, perhaps seeking sympathy from a fellow IT person, or a suggestion on how to find an answer.  What happened next was interesting.  Later that evening, I received an e-mail from Tracy Hillstrom, a product manager for Watchguard.  Someone who knew tracy saw my pondering question on Twitter, and forwarded it.&lt;/p&gt;

&lt;p&gt;The lesson to be learned here is this:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1.) The outsourced India-based call centers are dead.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2.) Companies are watching their brand image on social media.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3.)&lt;/strong&gt; &lt;strong&gt;Because most social media is public, companies are much more responsive to questions, complaints, and customer service inquiries to keep the public opinion of the brand experience positive.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If you have a customer service issue with a company or product, try using a social media platform like &lt;a href=&quot;http://twitter.com&quot; target=&quot;_blank&quot;&gt;Twitter &lt;/a&gt;to get some help.  Even if the appropriate people are not following you, companies can monitor their brands through advanced search tools, because of the public nature of Twitter.&lt;/p&gt;

&lt;p&gt;But there are some protocols that should be applied.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1.) &lt;/strong&gt;&lt;strong&gt;Be honest&lt;/strong&gt;, &lt;strong&gt;but be tactful&lt;/strong&gt;.  If you are frustrated, be frustrated, but don&amp;#8217;t flame the brand, unless there&amp;#8217;s no hope to correct the issue.  A backlash can occur if you are too negative on these types of services.&lt;/p&gt;

&lt;p&gt;2.) &lt;strong&gt;Be timely&lt;/strong&gt;.  Things happen quickly on social media, so if you post a question or inquiry, check back often for responses.  If a customer service person or fellow &amp;#8220;Tweep&amp;#8221; (Twitter Peep, or friend) tries to help, but your trail goes cold for a few days, the desire to assist will fade quickly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2.)&lt;/strong&gt;&lt;strong&gt; Praise the action&lt;/strong&gt;.  If a business or a person comes through for you, be sure to give them their props.  Online brand management is all about managing the image, so if you get good service, let everyone know.&lt;/p&gt;

&lt;p&gt;Here is a &lt;a href=&quot;http://buzzmarketingfortech.blogspot.com/2008/12/brands-that-tweet.html&quot;&gt;list of companies and brands&lt;/a&gt; that are known to be on Twitter.  Next time you have a customer service issue with any of these companies on Twitter, give them chance online to resolve your issue.&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=how-to-bypass-traditional-customer-servi&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>A Tech Industry Bailout</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=a-tech-industry-bailout&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;With all the news about banking and automotive bailouts in the fall, it got me to thinking about following question:&lt;/p&gt;

&lt;p&gt;&amp;#8220;What if the tech industry needed a bailout?&amp;#8221;&lt;/p&gt;

&lt;p&gt;What if we were to wake up one Monday morning to the announcement that &lt;a href=&quot;http://www.microsoft.com&quot;&gt;Microsoft &lt;/a&gt;had run out of cash?  Would the Federal Government just let the Microsoft monopoly collapse?  What if the government bailed out the software and giant, and we suddenly were found ourselves in a situation where the government had a significant ownership stake in the operating system of &lt;a href=&quot;http://marketshare.hitslink.com/report.aspx?qprid=8&quot;&gt;88% of the computers&lt;/a&gt; in production in homes and business throughout this country and worldwide?&lt;/p&gt;

&lt;p&gt;Would you be ok with it?  Or would you switch operating systems?  In your home, that might not be such a daunting task.  But try taking a business with 20 Windows workstations and a &lt;a href=&quot;http://www.microsoft.com/sbs/en/us/default.aspx&quot;&gt;Small Business Server&lt;/a&gt;, with employees who have built work skills and processes around Windows over the years, to &lt;a href=&quot;http://www.ubuntu.com/&quot;&gt;Linux &lt;/a&gt;and &lt;a href=&quot;http://www.apple.com/mac/&quot;&gt;Mac&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Do you believe the U.S. government would abuse the power that it had over your computing environment?  Do you believe that the government would eventually divest at a profit and go away, as we&amp;#8217;ve been led to believe will happen with the banks?  Or do you believe that the government would want to maintain nationalized control of the tech sector, just as many speculate that it wants a permanent nationalized stake in the U.S. banking industry?&lt;/p&gt;

&lt;p&gt;What if Google was also out of cash and needed a bailout to stay afloat?  How would you feel about a government bailout for Google, resulting in the government having ownership and access to all the data and information that Google has collected over the past ten years?&lt;/p&gt;

&lt;p&gt;For IT professionals such as myself, who are tasked with thinking through &amp;#8220;What if &amp;#8220; scenarios to build sound disaster recovery and continuity plans for businesses, the &amp;#8220;What if the operating systems and productivity tools themselves went away, or needed to be eliminated from the equation?&amp;#8221; is one that is quite perplexing.  &lt;/p&gt;

&lt;p&gt;Send me your thoughts.&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=a-tech-industry-bailout&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>Small Business Server 2003 Transition Pack Step-By-Step</title>
						<description>&lt;div class=&quot;tweetmeme_plugin tweetmeme_right&quot;&gt;&lt;script type=&quot;text/javascript&quot;&gt;tweetmeme_url = 'http://www.forthphaze.com/blogs/?title=small-business-server-2003-transition-pa&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1';tweetmeme_service = 'bit.ly';tweetmeme_source = 'ForthPhaze';&lt;/script&gt;&lt;script type=&quot;text/javascript&quot; src=&quot;http://tweetmeme.com/i/scripts/button.js&quot;&gt;&lt;/script&gt;&lt;/div&gt;&lt;p&gt;Saturday night I ran the Microsoft Small Business Server Transition Pack for a client.  This transition pack is not a widely used tool, as most people who have outgrown an SBS are usually in the market for a new server as well.  This particular client had an SBS server installed just about a year ago, so the hardware reinvestment was not a good approach.&lt;/p&gt;

&lt;p&gt;There are several &lt;a href=&quot;http://blogs.technet.com/sbs/archive/2006/01/12/417350.aspx&quot;&gt;blog posts&lt;/a&gt; and &lt;a href=&quot;http://download.microsoft.com/download/b/c/6/bc6a736b-faeb-43e1-ab61-17fed7f9ea40/SBSUnlimitGetStart.htm&quot;&gt;articles&lt;/a&gt; on preparation for the TP, and how &lt;a href=&quot;http://blogs.technet.com/moloyt/archive/2007/10/10/sbs-2003-transition-pack.aspx&quot;&gt;Windows looks different&lt;/a&gt; after the transition, as well as &lt;a href=&quot;http://blogs.technet.com/moloyt/archive/2008/10/16/what-to-do-if-sbs-2003-is-not-fully-transitioned.aspx&quot;&gt;what to do if the transition pack fails&lt;/a&gt;.  However, the documentation seemed to be a big black hole in terms of the step-by-step process itself.  With the documented known issues with running the TP being essentially disaster situations and non-functioning servers, needless to say it made the process quite unsettling going in.  &lt;/p&gt;

&lt;p&gt;Although I&amp;#8217;m lacking in screenshots, here was my step-by-step experience with the transition.  &lt;/p&gt;

&lt;p&gt;1.	Shutdown Backup Exec Services&lt;br /&gt;
2.	Shutdown Symantec Antivirus Services&lt;br /&gt;
3.	Shutdown VMware Services&lt;br /&gt;
4.	Change 3rd party applications to manual startup&lt;br /&gt;
5.	Export  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Small Business key from registry&lt;br /&gt;
6.	Delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Small Business key from registry&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(Documentation suggests that you uninstall Internet Explorer 7 as well, but 6 was still installed on this system.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;7.	Remove Ethernet cable&lt;br /&gt;
8.	Launch TP from disc&lt;br /&gt;
9.	Enter TP key&lt;br /&gt;
10.	Enter administrator password&lt;br /&gt;
11.	Reboot  #1 (all reboots are automated)&lt;br /&gt;
12.	Reboot  #2&lt;br /&gt;
13.	Reboot  #3&lt;br /&gt;
14.	Windows Setup Screen&lt;br /&gt;
15.	Reboot  #4&lt;br /&gt;
16.	Windows Setup Screen&lt;br /&gt;
17.	A prompt for the install.exe file on the SBS 2003 R2 Technologies disc. &lt;strong&gt;HUH??&lt;/strong&gt;&lt;br /&gt;
18.	Found SBS discs and the R2 Tech disc, there is no &amp;#8220;install.exe&amp;#8221; on the CD!!&lt;br /&gt;
19.	&lt;strong&gt;&lt;em&gt;PANIC!!&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;
20.	Found &lt;a href=&quot;http://msmvps.com/blogs/bradley/archive/2008/09/06/sbs-2003-transition-pack-wants-install-exe-file.aspx&quot;&gt;blog post&lt;/a&gt; saying you can ignore or cancel.  &lt;strong&gt;Whew!&lt;/strong&gt;&lt;br /&gt;
21.	Finish automated setup&lt;br /&gt;
22.	Reboot  #5&lt;br /&gt;
23.	Windows 2003 Standard Edition bootup screen&lt;br /&gt;
24.	Activate Windows dialog&lt;br /&gt;
25.	Plug in Ethernet adapter&lt;br /&gt;
26.	Activate YES / Register NO &amp;#8211; activate -&gt; Success!&lt;br /&gt;
27.	Reboot  #6&lt;br /&gt;
28.	TP Finish screen&lt;br /&gt;
29.	Import HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Small Business key to registry&lt;br /&gt;
30.	Start Backup Exec Services change to automatic startup&lt;br /&gt;
31.	Start Symantec Antivirus Services change to automatic startup&lt;br /&gt;
32.	Start VMware Services change to automatic startup&lt;br /&gt;
33.	Add TP CALs&lt;/p&gt;

&lt;p&gt;TOTAL TIME:  1 hour 54 minutes.&lt;/p&gt;

&lt;p&gt;From here you are recommended to reinstall your service packs.  So there is another reboot or two and another hour or two of work.&lt;/p&gt;

&lt;p&gt;After running the Transition Pack, I seem to be questioning the option as a true value add. I am still unclear if the cost and time justifies the value gained in contrast to upgrading. Upgrading is often a harder sell of course, as some business owners are just reluctant to jump on the latest Windows release (I have a client that finally upgraded from Windows 2000 to Windows 2003 in October of this year!).  But if you must use the TP, hopefully this post will help.&lt;/p&gt;

&lt;p&gt;Special thanks to all the people who failed their way through the TP process in the past. You helped to add to the documentation of known issues of the mysterious Transition Pack, so your plight was not in vain!&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=small-business-server-2003-transition-pa&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>A Geek's  Chore List - Don't Forget to Dust-Off</title>
						<description>&lt;p&gt;On Thursday this week I assisted a client in moving their three production servers from a downstairs open office to an upstairs semi-closed environment, which had been converted from a storage closet.  The room had been properly prepped with a thorough cleaning and its own climate controls and HVAC system [The client is an HVAC company in town].  They were also installing a new security system in the same room.   The primary reason for making this move was for disaster purposes.  The building, while not necessarily in a flood plain, had seen some disturbingly close water in the &lt;a href=&quot;http://brightkite.com/objects/aeb87760680833473ccf1ed6bbabc965075ca30c&quot;&gt;spring flood &lt;/a&gt;of Bloomington and southern Indiana.  So they made a decision to move all of their security, I.T., and other electronic systems upstairs.&lt;/p&gt;

&lt;p&gt;The old location of the servers was just inside the office door from the machine shop, where they draft custom duct for HVAC installations.  There is a lot of dust and debris that carries over into the office.  In addition, the office is frequented by their field technicians, who tend to get dirty on the job as they work in construction sites and outside in the dirt and mud.  They frequently carry that dirt into the office on their clothes.  Needless to say, the air in the office was anything but clean, despite a good air system in the office area.&lt;/p&gt;

&lt;p&gt;During the move on Thursday, we popped open the cases of each server and sprayed dust-off inside the servers for the first time in probably a year.  The amount of dust and dirt that came out of those servers was simply shocking.  Shortly upon spraying one down, an employee walked in the office and his first comment was, &amp;#8220;Why is it cloudy in here?&amp;#8221;&lt;/p&gt;

&lt;p&gt;We completed the dusting of Pigpen and his two siblings, and then I proceeded to have a 10 minute sneeze attack.  I probably lost a couple months of life expectancy based on the amount of dirt I inhaled.&lt;/p&gt;

&lt;p&gt;According to &lt;a href=&quot;http://computerdust.com/&quot;&gt;ComputerDust.com&lt;/a&gt;, integrated circuits (ICs) can suffer from overheating as a result of the insulating affect of dust as well as suffer from electrical shorts caused by dust across their contacts.  Tests show that the internal temperature of a CPU can go up as much as 30 degrees due to a buildup of dust.   While we cannot predict the lifespan reduction of operating a PC in an environment that has a higher concentration of dust than what would be considered normal conditions, it can be reasonably concluded that reducing dust in the operating environment and in the CPU case will reduce the risk of failure.  &lt;/p&gt;

&lt;p&gt;There are a few mitigating approaches to reducing dust:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; &lt;em&gt;Use &lt;a href=&quot;http://en.wikipedia.org/wiki/Dust-Off&quot;&gt;Dust-off &lt;/a&gt;regularly.&lt;/em&gt;  You should use dust-off around the open areas of your PC, such as the case vents, the power supply fan, and any other venting fans, on a monthly basis.  PCs should opened up 3-4 times per year for inside cleaning.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; &lt;em&gt;Use a &lt;a href=&quot;http://computerdust.com/products/cpu_covers.html&quot;&gt;dust cover&lt;/a&gt;.&lt;/em&gt;  They are relatively inexpensive and will sufficiently keep dust out of your computer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; &lt;em&gt;Invest in a &lt;a href=&quot;http://www.purapc.com/store/index.html&quot;&gt;PC Air Filter&lt;/a&gt;.&lt;/em&gt;  Also relatively inexpensive, operates just like your air filter in your home&amp;#8217;s heating/cooling system.&lt;/p&gt;

&lt;p&gt;utilizing these options will reduce risk of failure and provide some piece of mind.  Just to be clear, ForthPhaze Technology will do no other chores beyond dusting &amp;#8211; no window cleaning or lawn maintenance! (Unless the rate is good&amp;#8230;)  &lt;/p&gt;

&lt;p&gt;Also, beware of the dangers of Dust-off.  Don&amp;#8217;t try &lt;a href=&quot;http://cockeyed.com/inside/dustoff/dustoff.html&quot;&gt;these tricks &lt;/a&gt;at home!&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=a-geek-s-chore-list-don-t-forget-to-dust&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
				<item>
			<title>Security Notice from Sunbelt Regarding VIPRE Update</title>
						<description>&lt;p&gt;I just received the following email below regarding a problem with a VIPRE update.  &lt;/p&gt;

&lt;p&gt;&lt;em&gt;Last week there was an isolated incident that may compromise an operating system component. It was corrected with the next definition release, however some agents had the definitions long enough to still be affected. The affected computers will not reboot without a system restore. If you experience this in your environment, DO NOT reboot any additional computers until the following utility has been applied.&lt;br /&gt;
 &lt;br /&gt;
We have created steps to remedy this problem. You should follow these steps if you have version 3.1 of any CounterSpy or VIPRE agents installed on computers prior to October 20, 2008.&lt;br /&gt;
 &lt;br /&gt;
The instructions below will use the CSE/VIPRE console deployment to push out a utility. This utility was created specifically to remedy this problem. After this utility is run on the agent, it will be safe to reboot the machines. This utility takes 15 seconds to run (per agent) and will not require a reboot or otherwise change the installed agent or disturb the end user.&lt;br /&gt;
 &lt;br /&gt;
The goal of this utility is to delete these files:&lt;br /&gt;
 &lt;br /&gt;
C:\Windows\System32\sbfc.dat&lt;br /&gt;
C:\Program Files\Sunbelt Software\SBEAgent\definitions\sbts.dat&lt;br /&gt;
 &lt;br /&gt;
1. Stop the Counterspy/Vipre Enterprise Service.&lt;br /&gt;
2. Close the Counterspy/Vipre Console.&lt;br /&gt;
3. Navigate to the Counterspy/Vipre install directory.&lt;br /&gt;
4. Rename the Packages folder to Packages-Clean.&lt;br /&gt;
5. Save &lt;a href=&quot;http://www.sunbeltsoftware.com/support/vipre/stopbootquar/packages.zip &quot;&gt;http://www.sunbeltsoftware.com/support/vipre/stopbootquar/packages.zip &lt;/a&gt;to the CSE/VIPRE install directory.&lt;br /&gt;
6. Extract the new Packages folder.&lt;br /&gt;
7. Start the Counterspy/Vipre Enterprise service.&lt;br /&gt;
8. Log onto the Counterspy/Vipre console.&lt;br /&gt;
9. Change the Deployment Timeout to 15 seconds. (System-&gt;Configuration-&gt;Advanced Settings) &lt;br /&gt;
10. Add &amp;#8220;SBEAgentDeployW.exe&amp;#8221; and &amp;#8220;STOPBO~1.EXE&amp;#8221; to the Admin-defined good for all policies. (Make sure to click the Good tab to prevent accidentally adding these to the Known bad).&lt;br /&gt;
11. Wait for the deferred work to be processed for all Installed agents.&lt;br /&gt;
WARNING: All agents with a status of &amp;#8220;installed&amp;#8221; must process their deferred work before proceeding. Failure to do so will result in this patch NOT being applied.&lt;br /&gt;
12. Deploy to a test agent using the Push method from the console.&lt;br /&gt;
13. Reboot the test agent to verify that the patch was correctly applied.&lt;br /&gt;
14. Apply the patch to each policy by selecting all the agents and then Deploying via the automated push method.&lt;br /&gt;
15. Test at least one machine from each policy before allowing all the agents to reboot. If the patch did not take, double check the exclusions and push it out again.&lt;br /&gt;
 &lt;br /&gt;
Once all machines have the patch applied, you can then replace the install package with the original.&lt;br /&gt;
1. Stop the Counterspy/Vipre Enterprise Service.&lt;br /&gt;
2. Close the Counterspy/Vipre Console.&lt;br /&gt;
3. Navigate to the Counterspy/Vipre install directory.&lt;br /&gt;
4. Delete the Packages folder.&lt;br /&gt;
5. Rename the Packages-Clean folder to Packages.&lt;br /&gt;
6. Start the Counterspy/Vipre Enterprise service.&lt;br /&gt;
7. Log onto the Counterspy/Vipre console.&lt;br /&gt;
8. Change the Deployment Timeout back to 120 seconds. (System-&gt;Configuration-&gt;Advanced Settings)&lt;br /&gt;
 &lt;br /&gt;
You can contact our support department if you have any questions on this or run into any issues. Support can be reached at &lt;a href=&quot;mailto:support@sunbeltsoftware.com&quot;&gt;support@sunbeltsoftware.com&lt;/a&gt; or by calling (877) 673-1153 Monday through Friday 9 a.m. to 6 p.m. EST.&lt;br /&gt;
 &lt;br /&gt;
We apologize for any inconvenience that this may cause.&lt;br /&gt;
 &lt;br /&gt;
Thank you,&lt;br /&gt;
Sunbelt Software&lt;/em&gt;&lt;/p&gt;</description>
			<link>http://www.forthphaze.com/blogs/?title=security-notice-from-sunbelt-regarding-v&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
							</item>
			</channel>
</rss>
