<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Diary of a computer geek</title>
	<atom:link href="http://jen3ral.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://jen3ral.wordpress.com</link>
	<description></description>
	<lastBuildDate>Mon, 30 Jan 2012 04:46:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='jen3ral.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Diary of a computer geek</title>
		<link>http://jen3ral.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://jen3ral.wordpress.com/osd.xml" title="Diary of a computer geek" />
	<atom:link rel='hub' href='http://jen3ral.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Cannot send to email group after accidental deletion</title>
		<link>http://jen3ral.wordpress.com/2012/01/24/cannot-send-to-email-group-after-accidental-deletion/</link>
		<comments>http://jen3ral.wordpress.com/2012/01/24/cannot-send-to-email-group-after-accidental-deletion/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 22:43:54 +0000</pubDate>
		<dc:creator>jen3ral</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Microsoft Outlook]]></category>

		<guid isPermaLink="false">http://jen3ral.wordpress.com/?p=709</guid>
		<description><![CDATA[This happens far too often and is completely understandable. I am sure I would have done it by now if I used our distribution lists. Every few months or so it seems like somebody here in the office goes to edit one of the lists to keep them nice and clean (thank you) but when [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=709&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This happens far too often and is completely understandable. I am sure I would have done it by now if I used our distribution lists. Every few months or so it seems like somebody here in the office goes to edit one of the lists to keep them nice and clean (thank you) but when they go to delete a user from the list they accidentally delete the entire list itself. You can see why below:</p>
<p><a href="http://jen3ral.files.wordpress.com/2012/01/messagemenu.jpg"><img class="aligncenter size-full wp-image-710" title="MessageMenu" src="http://jen3ral.files.wordpress.com/2012/01/messagemenu.jpg?w=600" alt=""   /></a>I completely understand why they would immediately go to delete group instead of remove member. You see the big X signifying delete and just assume that&#8217;s what it will do when you have the user highlighted. I know how to recover the lists when they do delete them. You have to hunt through the deleted items and find it. If you sort by date it will sort the list based on the date it was created, not when you deleted it. Click on the group and drag over to the left where it says contacts or in our case go to folder list view and click and drag it to the appropriate contacts list under public folders.</p>
<p>The next time the person tried to send an email to the group they would get an error that said &#8220;unexpected error.&#8221; *sigh* So I finally got the bright idea to start typing in the group name into the To: field to make the auto-fill show up and delete that entry. I clicked the To: button and added it that way, sent the email and it worked. For some reason the auto-fill entries break if you delete the group and restore it. There must be some way outlook is identifying the auto-fills and when you restore the group it gives it another ID number or something.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jen3ral.wordpress.com/709/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jen3ral.wordpress.com/709/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jen3ral.wordpress.com/709/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=709&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jen3ral.wordpress.com/2012/01/24/cannot-send-to-email-group-after-accidental-deletion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jen3ral</media:title>
		</media:content>

		<media:content url="http://jen3ral.files.wordpress.com/2012/01/messagemenu.jpg" medium="image">
			<media:title type="html">MessageMenu</media:title>
		</media:content>
	</item>
		<item>
		<title>D-Link Shareport Utility and Windows 7 Pro</title>
		<link>http://jen3ral.wordpress.com/2012/01/02/d-link-shareport-utility-and-windows-7-pro/</link>
		<comments>http://jen3ral.wordpress.com/2012/01/02/d-link-shareport-utility-and-windows-7-pro/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 00:53:29 +0000</pubDate>
		<dc:creator>jen3ral</dc:creator>
				<category><![CDATA[Windows Vista and 7]]></category>
		<category><![CDATA[d-link]]></category>
		<category><![CDATA[shareport]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[windows firewall]]></category>

		<guid isPermaLink="false">http://jen3ral.wordpress.com/?p=704</guid>
		<description><![CDATA[I have been using the shareport utility for awhile now but I always had to disable my firewall for it to work properly. It works fine on the Windows 7 home computer, but not on my Windows 7 Pro desktop. I looked around online and it looks like a common problem but I did not [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=704&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have been using the shareport utility for awhile now but I always had to disable my firewall for it to work properly. It works fine on the Windows 7 home computer, but not on my Windows 7 Pro desktop. I looked around online and it looks like a common problem but I did not see anybody post the solution that worked for me. Simply creating a rule in the firewall allowing the utility itself to do whatever it wants did not work. I turned on logging for the Windows firewall and watched what was happening whenever I tried to print something. It was blocking traffic coming from the other computers on the network. So I created a rule to allow UDP traffic from the range of IPs on my network, which is only a handful of machines. That&#8217;s the only shareport related rule I have in the firewall and it works perfectly fine now. The utility will not print if other computers are connected to the printer with shareport, which is why I think the traffic is coming from the other machines on the network &#8211; they are just answering back saying they are not using the printer.</p>
<p>Go to your start menu and type firewall in the search box, then click on Windows Firewall with Advanced Security.</p>
<ol>
<li>Click inbound rules on the left and then new rule on the right</li>
<li>Custom rule, next</li>
<li>All programs, next</li>
<li>You can either leave protocol type to any or change it to UDP, next</li>
<li>Under &#8220;which local IP addressses does this rule apply to?&#8221; choose &#8220;these IP addresses:&#8221; and click add. I just put the range of IPs of the computers on my network. Hit OK.</li>
<li>Then allow the connection, next</li>
<li>Only selecting private should work fine for a home network.</li>
<li>Finally, name the rule so you know what it is. I just called it Shareport Utility. Hit finish.</li>
</ol>
<p>If you want to turn on firewall logging open your command prompt and use either/both of these commands depending on what you want to see:</p>
<p><code>netsh firewall set logging droppedpackets = enable</code><br />
<code>netsh firewall set logging connections = enable</code></p>
<p>By default your log file is <code>%systemroot%\System32\LogFiles\Firewall\pfirewall.log</code></p>
<p>I was having another issue printing where it would print all jumbled up with text overlapping itself and the colors being completely wrong. I saw a post that suggested going into the printer properties to disable spooling. For my printer it&#8217;s under the advanced tab in the printer properties. I told it to print directly to the printer instead &#8211; so far so good.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jen3ral.wordpress.com/704/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jen3ral.wordpress.com/704/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jen3ral.wordpress.com/704/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=704&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jen3ral.wordpress.com/2012/01/02/d-link-shareport-utility-and-windows-7-pro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jen3ral</media:title>
		</media:content>
	</item>
		<item>
		<title>USAA phishing emails</title>
		<link>http://jen3ral.wordpress.com/2011/12/20/usaa-phishing-emails/</link>
		<comments>http://jen3ral.wordpress.com/2011/12/20/usaa-phishing-emails/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 18:27:18 +0000</pubDate>
		<dc:creator>jen3ral</dc:creator>
				<category><![CDATA[Anti-virus and Anti-malware]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Trojan.Zbot.CBCGen]]></category>
		<category><![CDATA[USAA]]></category>

		<guid isPermaLink="false">http://jen3ral.wordpress.com/?p=686</guid>
		<description><![CDATA[I am seeing a new phase of USAA spam hitting us. The ones I am seeing hit our servers the most claim to be deposit notifications that, of course, include an attachment they want you to open. The scary thing is that I am seeing more and more phishing emails that look really good. I&#8217;m [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=686&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I am seeing a new phase of USAA spam hitting us. The ones I am seeing hit our servers the most claim to be deposit notifications that, of course, include an attachment they want you to open. The scary thing is that I am seeing more and more phishing emails that look really good. I&#8217;m actually kind of impressed by them. I can easily see a lot of people, maybe even some in my office, opening this email and downloading the attachment. Of course for me, the dead giveaway is the fact that there&#8217;s an attachment at all &#8211; let alone a zip file that includes an exe file. Luckily our spam filter doesn&#8217;t let exe files through, even if it doesn&#8217;t detect it as a virus.</p>
<p><a href="http://jen3ral.files.wordpress.com/2011/12/email.jpg"><img class="alignright  wp-image-687" title="USAAEmail" src="http://jen3ral.files.wordpress.com/2011/12/email.jpg?w=252&#038;h=256" alt="" width="252" height="256" /></a>Being the curious person that I am I downloaded the attachment to see what was in it. I found an exe file, <code>Deposit_Posted_Details_USAA_122012.exe</code>. I scanned the exe with our corporate version of Malwarebytes and it was detected as <code>Trojan.Zbot.CBCGen</code>. I scanned it with GFI&#8217;s Vipre anti-virus, but it was not detected.  I then uploaded it to virustotal to see what other scanners were detecting it. As of this post, only 3 scanners are seeing it, one of which was added while I was putting this post together &#8211; ByteHero, Kaspersky, and McAfee. You can see the <a href="http://www.virustotal.com/file-scan/report.html?id=c5b77f336c33e5cdb38611ff16df01df839ceaef7c3895f648503a2ebe1e6af4-1324401718" target="_blank">report here</a>.</p>
<p>My next step is do some research based on the names the scanners that detect it have given it to see what kind of infection this is. Hopefully if any of you have it Malwarebytes will just take care of it for you.</p>
<p>Update: It now looks like 6 scanners are able to find this virus. I did some looking around online and from what I see it sounds pretty nasty.</p>
<blockquote><p>It specifically targets passwords used in Internet Explorer, along with those for FTP and POP3 accounts. It also deletes any cookies stored in Internet Explorer. That way, the user must log in again to any commonly visited Web sites, and the threat can record the login credentials at the time.</p></blockquote>
<p>From the report Symantec put together and the report I received from submitting this to GFI&#8217;s sandbox I can see that it creates a file to dump all your login information into and tries to phone home to suck those passwords off your computer. Symantec lists this as a low threat, but if there is any sign of this being on your computer you need to change all your passwords. That is not something I would want to risk. At least it appears to use the same names to create the files and keys over and over, which would hopefully mean that it wouldn&#8217;t be terribly difficult for the anti-virus scanners to find and remove &#8211; once they update their definitions to get this newest variation.</p>
<p>Also, this virus can possibly inject forms into your web browser that make it look like your banking site, or whatever site your logging into, is asking extra security questions to confirm who you are. But if the it&#8217;s something beyond the basic &#8220;what&#8217;s your mother&#8217;s maiden name?&#8221; be careful. I saw on another forum somewhere that when someone tried to log into their banking site it asked them the basic questions, but then asked him what his debit card number is &#8211; why would your banking site be asking that?</p>
<p>Here are the DNS requests from the report that GFI sent me after submitting it to their sandbox.</p>
<p><a href="http://jen3ral.files.wordpress.com/2011/12/dnsrequests.jpg"><img class="aligncenter size-full wp-image-695" title="DNSrequests" src="http://jen3ral.files.wordpress.com/2011/12/dnsrequests.jpg?w=600" alt=""   /></a></p>
<p>In response to Mosey&#8217;s question about whether Filezilla&#8217;s credentials would be at risk: it doesn&#8217;t sound like they would be based off the the Symantec report and a couple others things I found about it (see the two links I added below). It sounds like it is only monitoring what you type into your web browser. I have not seen anything yet that tells me otherwise. But I did find another blog that describes how Filezilla stores your credentials in a plain text file that is very easy to find. This trojan is also known as Zeus, there are a lot of variations &#8211; so I suppose someone out there creating their version of the Zeus trojan could target the Filezilla files that hold your credentials.</p>
<p>Sources:</p>
<ul>
<li><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2010-011016-3514-99&amp;tabid=2" target="_blank">Symantec &#8211; Trojan.Zbot Technical Details</a></li>
<li><a href="http://www.f-secure.com/v-descs/trojan-spy_w32_zbot.shtml" target="_blank">F-Secure &#8211; Trojan-Spy:W32/Zbot</a></li>
<li><a href="http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/" target="_blank">Beware: FileZilla Doesn’t Protect Your Passwords</a></li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jen3ral.wordpress.com/686/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jen3ral.wordpress.com/686/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jen3ral.wordpress.com/686/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=686&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jen3ral.wordpress.com/2011/12/20/usaa-phishing-emails/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jen3ral</media:title>
		</media:content>

		<media:content url="http://jen3ral.files.wordpress.com/2011/12/email.jpg" medium="image">
			<media:title type="html">USAAEmail</media:title>
		</media:content>

		<media:content url="http://jen3ral.files.wordpress.com/2011/12/dnsrequests.jpg" medium="image">
			<media:title type="html">DNSrequests</media:title>
		</media:content>
	</item>
		<item>
		<title>Skype crashes during video call</title>
		<link>http://jen3ral.wordpress.com/2011/12/19/skype-crashes-during-video-call/</link>
		<comments>http://jen3ral.wordpress.com/2011/12/19/skype-crashes-during-video-call/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 22:50:54 +0000</pubDate>
		<dc:creator>jen3ral</dc:creator>
				<category><![CDATA[Windows Vista and 7]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://jen3ral.wordpress.com/?p=681</guid>
		<description><![CDATA[I was having problems trying to Skype with my aunt yesterday afternoon. I logged into Skype, tried to call her, but as soon as she would answer Skype threw the error saying that it stopped working and would look for a solution. I never did try calling without video so I don&#8217;t know if that&#8217;s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=681&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I was having problems trying to Skype with my aunt yesterday afternoon. I logged into Skype, tried to call her, but as soon as she would answer Skype threw the error saying that it stopped working and would look for a solution. I never did try calling without video so I don&#8217;t know if that&#8217;s the issue or not. Whatever the problem is the only way I could fix it was to install the beta version of Skype from their website. I saw on the forums that lots of other people were having the same issue. I looked in the event viewer and saw an error that included:</p>
<blockquote><p>Faulting application name: Skype.exe, version: 5.0.0.152, time stamp: 0x4cb31516<br />
Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385, time stamp: 0x4a5bdaae</p></blockquote>
<p>What does that mean? I have no idea. The only thing I can think of is if maybe recent windows updates broke something for Skype. I haven&#8217;t changed anything else on my computer recently.  I&#8217;m also not sure if this is a Windows 7 thing or not. My aunt has Windows XP still and she was not having any issues, another family member who has Windows 7 also couldn&#8217;t Skype with her. So maybe windows update strikes again.</p>
<p>Anyway, <a href="http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows/beta/" target="_blank">go here</a> and download the beta version. It&#8217;s about half way down the  page under their windows section if you go directly to Skype&#8217;s website.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jen3ral.wordpress.com/681/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jen3ral.wordpress.com/681/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jen3ral.wordpress.com/681/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=681&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jen3ral.wordpress.com/2011/12/19/skype-crashes-during-video-call/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jen3ral</media:title>
		</media:content>
	</item>
		<item>
		<title>Imaging an encrypted drive</title>
		<link>http://jen3ral.wordpress.com/2011/10/11/imaging-an-encrypted-drive/</link>
		<comments>http://jen3ral.wordpress.com/2011/10/11/imaging-an-encrypted-drive/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 02:00:04 +0000</pubDate>
		<dc:creator>jen3ral</dc:creator>
				<category><![CDATA[Computer Forensics and Imaging]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Ghost]]></category>
		<category><![CDATA[imaging]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://jen3ral.wordpress.com/?p=504</guid>
		<description><![CDATA[This is using Ghost Solution Suite 2.5, which is ghost 11.5, to image a hard drive that is encrypted by PGP encryption. But there is a good chance these same steps will work with other encryption software. If you want to bypass all my troubleshooting that it took for me to get this to work [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=504&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is using Ghost Solution Suite 2.5, which is ghost 11.5, to image a hard drive that is encrypted by PGP encryption. But there is a good chance these same steps will work with other encryption software.</p>
<p>If you want to bypass all my troubleshooting that it took for me to get this to work then <a href="#Solution">click here</a> to go straight to the solution.</p>
<h3>July 5, 2011</h3>
<p>This adventure began late last week. I need to figure out how to image our encrypted hard drives in a manner that keeps the encryption intact. I&#8217;m not going to wait hours for a drive to decrypt just so I can image it and then have it spend another few hours, or however long, to re-encrypt it. The plan is to get this to work so that I can pull an image of each of our laptops every time we have huge software changes. I&#8217;m not sure what&#8217;s going to qualify as large enough changes to make me go through this, but I&#8217;ll figure it out when I get there. After I get this process to work properly I&#8217;ll just use the ghost client on the machines to back up the user files every 2 weeks or so.</p>
<p>Well last week I started my experiment with ghosting one of our unused encrypted laptops. It took me forever to realize that I can&#8217;t use the windows client to pull or push an image because ghost doesn&#8217;t like that I have to enter the password before the computer will finish booting up. Even though I was standing at the laptop when the client forced a reboot and typed the password in right when it prompted for it, it wouldn&#8217;t go into the WindowsPE environment. I thought I was being too slow at first, but that wasn&#8217;t the case.</p>
<p>I created a boot disk with the right NIC drivers on it for these laptops and had it boot to the CD. I finally got it imaging and then noticed it was splitting the image into the default 2GB chunks. With these laptops being 500GBs, that just isn&#8217;t going to work. I kept thinking of spanning, not splitting, so it then took me awhile to find the correct switch to add to the settings /facepalm. I finally got it to pull the image, it took 4 or 5 hours to do it and the next day I turned around and pushed the image back out to it &#8211; I&#8217;m using the ghostcast server on one of my servers since I don&#8217;t have a large enough external hard drive for a 500GB image and I don&#8217;t feel like buying one right now.</p>
<p>I came in this morning and rebooted the machine to see if the image worked. Well it prompted me for my encryption password but then it won&#8217;t boot into windows so I need to run the repair command. But I can&#8217;t do that until I decrypt the drive because the repair boot disk won&#8217;t see the hard drive until I do. So now I get to yank the hard drive out and hook it up to another laptop in order to decrypt it, that will take 12-24 hrs.</p>
<p>But, there is one more thing I will try before I become stumped. I used the split=0 switch, but not the switch to force a sector-by-sector copy (-ia). I thought I read in the documentation or in their forum that it would detect whether it needed to be sector-by-sector, but I don&#8217;t know how to find out and it didn&#8217;t work. The last time I had to decrypt a drive by hooking it up to another laptop as an external it took at least 20 hrs to finish. I&#8217;ll start that process shortly and try to image it again tomorrow.</p>
<p>If anybody has any advice please feel free to share it.</p>
<p>To be continued&#8230;.</p>
<p>Continued:</p>
<p>Well I tried imaging it again after waiting 20 hrs for it to decrypt, then 20 more hours for it to encrypt itself again. The image failed. I tried using both the -split=0 and -ia switches and did see an error where it was saying something about -split=0 not being used properly or whatever. So now I have to decrypt it again (20 hrs), run the fixboot command, and let it encrypt itself again (20 hrs). Then I will try imaging one more time only using the -ia switch for sector-by-sector copy. I will report back once this has been attempted. I will figure this out, damn it.</p>
<h3>October 11, 2011</h3>
<p>So 3 months have past since I last spent much time trying to figure this out. I&#8217;m too stubborn to admit defeat and let something like this go without exhausting all resources first. I just knew there had to be a way to get it to work. I came across a <a href="http://www.symantec.com/business/support/index?page=content&amp;id=tech104163" target="_blank">KB article on Symantec&#8217;s website</a> that sounded like exactly what I needed to do. Why this was never mentioned in any forum posts about PGP (or encryption in general) and Symantec Ghost (that I found anyway) is beyond me. I only ever saw mention of sector-by-sector copying and if you read my original post, then you know how well that worked out. I just realized the new article that  I found also refers to the -IR switch, which is a raw disk image, as sector-by-sector. What the hell? Let&#8217;s be a little more confusing please /sarcasm.</p>
<p><a name="Solution"></a><br />
Solution:</p>
<ol>
<li>Use a ghost boot CD or usb drive to get into the WindowsPE environment.</li>
<li>After it boots up and pops the Ghost GUI up, close that so you&#8217;re at the black command prompt.</li>
<li>From here I had to go back a couple directories by typing cd.. to find the directory the ghost executable lives in. I think it&#8217;s Ghost32.exe.</li>
<li>The switches you need to use are -IR, -FRO, and -SPLIT=0. So type ghost32.exe -IR -FRO -SPLIT=0 and hit enter. Now go through the normal steps to select the disk to image and the place to save it.</li>
</ol>
<p>You are going to need a removable hard drive or the ability to ghostcast from a server that has enough space for the image to be the entire size of the hard disk, even if the disk only has 50GB of information on it. Since the image is a raw disk image (the -IR switch) it is imaging the entire disk. You can use the -SPLIT switch to chop the image into smaller bits, but that doesn&#8217;t make the image any easier to manage with hard disks being so large these days. Unless you need to chop the image into files that will fit on DVDs or Blu-Rays, I don&#8217;t see that being useful. Or maybe you have small usb hard drives to split the image onto, I suppose that&#8217;s helpful.</p>
<p>I pulled an image and turned around and pushed it back out and it worked perfectly. I rebooted the laptop this afternoon and it was like nothing happened &#8211; encryption and everything is intact. It looks like, based off the switch descriptions linked below, that the only difference between raw disk image and sector-by-sector is that the raw disk image ignores the partition table. Funny how the KB article still refers to it as sector-by-sector, yet their own switch description page does not.</p>
<p>Sources:</p>
<ol>
<li><a href="http://community.norton.com/t5/Other-Norton-Products/Ghost-and-PGP/td-p/239233" target="_blank">Ghost and PGP &#8211; Norton Community</a></li>
<li><a href="http://www.symantec.com/docs/TECH104163%20" target="_blank">Symantec KB Article TECH104163</a></li>
<li><a href="http://www.symantec.com/docs/TECH130961" target="_blank">Switches: Alphabetical list of switches</a></li>
</ol>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jen3ral.wordpress.com/504/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jen3ral.wordpress.com/504/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jen3ral.wordpress.com/504/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jen3ral.wordpress.com&amp;blog=2300421&amp;post=504&amp;subd=jen3ral&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jen3ral.wordpress.com/2011/10/11/imaging-an-encrypted-drive/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jen3ral</media:title>
		</media:content>
	</item>
	</channel>
</rss>
