Sunday, June 10, 2012

Backup SLBL on IronPort C160 Devices


How do I backup and restore my safelist / blocklist?

Making a backup of the safe list, block list:
  1. Go to the Configuration File option under the System Administration tab on the GUI.
  2. Near the bottom of this screen you will find the section labeled: End-User Safelist/Blocklist Database (IronPort Spam Quarantine).
  3. Press the button labeled "Backup Now". This will save a copy as a .csv file in the configuration directory on your appliance.
Note: If this feature is not enabled, you can enable it by choosing Monitor > Quarantines.
Moving the backup to another box:
  1. Make certain that you have the FTP service enabled on one of your network interfaces. This would typically be the management interface. You can check this in the IP Interfaces section under the Network tab on the GUI.
  2. From your file server, FTP to the IronPort appliance on the above mentioned interface.
  3. Login as an admin user.
  4. The backup file you made earlier should be right there in the root directory.
Restoring the backup:
  1. This is basically the reverse procedure of the backup.
  2. FTP the file from your file server back to the IronPort appliance in the configuration directory.
  3. Go back into the Configuration File section under the System Administration tab.
  4. Press the "Select File to Restore" button.
  5. Select from the list of valid backup files.
     
     

Saturday, June 09, 2012

How to Factory Reset a Wyse T509 Thin Client

I ran into this issue recently and got this answer from Wyse tech support.  Seems easy enough but took a few tries to get it to take.

1.       Power down the unit.

2.       Press AND hold power button and the same time keep hitting ‘p’ key

3.       A UI will be shown with an option to start recovery.

Item 2 is a bit tricky. On the front panel there are 2 LEDs (one right on the power button, another one on the left of power button, let’s call it status LED). You need to keep holding power button and hitting ‘p’ until Status LED blinks. It takes about 4 seconds of holding power button. If you hold power button for 7 seconds device will shut off.

Manually Uninstalling Trend Micro Officescan


Trend Micro OfficeScan is normally deployed in corporate network environment to provide endpoint security. Administrators can remotely uninstall the Office Scan client, and user at the workstation can uninstall the client program using built-in uninstall mechanism too (i.e. Add and Remove Program in Control Panel). If for some reason, the Office Scan client cannot or unable to uninstall, or user doesn’t have the required password to remove the OfficeScan client, try the following workaround to manually uninstall and remove Trend Micro OfficeScan.

1.  Go to Control Panel Services (services.msc), and stop the following services:
  • OfficescanNT Listener
  • OfficescanNT RealTimeScan
  • OfficeScanNT Personal Firewall (if enabled)
2.  Run Registry Editor (regedit.exe).

3.  Navigate to the following registry key hive:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

4.  Delete the following keys (if available):
  • Ntrtscan
  • Tmlisten
  • TmFilter
  • VSApiNt
  • TMPreFilter
  • TM_CFW
  • OfcPfwSvc
5.  Navigate to the following registry hive:
HKEY_LOCAL_MACHINE \SOFTWARE\TrendMicro or HKEY_LOCAL_MACHINE \SOFTWARE \Wow6432Node\TrendMicro (in 64-bit Windows operating system)

6.  Delete the following keys (if available):
  • OfcWatchDog
  • Pc-cillinNTCorp or OfficeScanCorp (depends on the client)
  • RemoteAgent
  • PC-cillin
  • CFW
7.  Browse to the following registry key hive:
HKEY_LOCAL_MACHINE \SOFTWARE \Microsoft\Windows\CurrentVersion\Run

8.  Delete the OfficeScanNT Monitor key.

9.  Navigate to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

10.  Delete the OfficeScanNT key.

11.  Delete the OfficeScan program group (Trend Micro OfficeScan Client) from the Windows Start menu.

12.  Restart the computer.

13.  Delete the directories that contain the OfficeScan Client program files, normally located inside Program Files folder.

NOTE:  The above steps work for OfficeScan 7.x client in Windows 2003/XP/2000/NT/Vista/2008 machine. 
For Trend Micro OfficeScan Corporate Edition (OSCE) – 5.58, OfficeScan Corporate Edition (OSCE) – 6.5, Client / Server / Messaging Suite for SMB – 2.0, follow these manual uninstallation steps instead.

1.  Delete the Trend Micro OfficeScan Client program shortcut in Start Menu, by right click on it and then choose Delete.

2.  Delete the installed files located in the OfficeScan folder under the \Program Files\Trend Micro\OfficeScan Client directory.

3.  Open the Registry Editor (regedit).

4.  Navigate to the following registry key:
HKEY_LOCAL_MACHINE\Software\TrendMicro

5.Delete the following keys:
  • OfcWatchDog
  • PC-cilling
  • PC-cillingNTCorp
6.  Also delete the following registry hives:
◦HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OfficeScanNT Monitor
◦HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OfficeScanNT
◦HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntrtscan
◦HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmfilter
◦HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmlisten
◦HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TmPreFilter (for Win2003)
◦HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSApiNt

7.  Right click on My Computer, click Manage and then select Device Manager.
 
8.  Enable the Show Hidden Devices option.
 
9.Remove the following hidden devices in Non-Plug and Play Drivers tree pertaining to OfficeScan (right-click and select Uninstall):
  • Trend Micro VSAPI NT
  • Trend Micro FILTER
  • Common Firewall Driver
  • NTRTSCAN (if available)
  • TMLISTEN (if available)
10.Restart the OfficeScan client machine.
This has worked for me each and every time I have had to do a manual removal.  Good luck.

Things You Can Open in Windows From the Run Command


With all the work I do on Windows Server knowing these commands is a real time saver instead of always having to run things down through the GUI.  This isn't by any means a full list but here is a list of some of the things you can access in Windows without the mouse (type these at a Run Prompt):

    control = Opens the Control Panel Window
    control admintools = Opens the Administrative Tools
    control keyboard = Opens the Keyboard Properties Window
    control color = Opens the Display Properties (at the Appearance Tab in Windows 7)
    control folders = Opens the Folder Options Window
    control fonts = Opens the Font Policy Management Window
    control international (or intl.cpl) = Opens Regional and Language Options
    control mouse (or main.cpl) Opens mouse properties
    control userpasswords = Opens the User Accounts Editor
    control userpasswords2 (or netplwiz) = Opens User Account Access Restrictions
    control printers = Opens the Printers and Faxes Window
    control desktop (Windows Vista/7 only) = Opens Control Panel>Personalization
    appwiz.cpl = Opens the Add or Remove Programs Utility
    optionalfeatures = opens the Add or Remove Windows Component utility
    desk.cpl = Opens the Display Properties (Themes Tab)
    hdwwiz.cpl = Opens the Add Hardware Wizard
    irprops.cpl = Opens the Infrared utility (does nothing if no IR devices are installed)
    joy.cpl = Opens  Game Controller Settings
    mmsys.cpl = Opens the Sound and Audio device properties window (Volume Tab)
    sysdm.cpl = Opens the System Properties window
    telephon.cpl = Opens the Phone and Modem options window
    timedate.cpl = Opens the Date and Time Properties window
    wscui.cpl = Opens the Windows Security Center in XP (opens the Action Center in Windows Vista/7)
    access.cpl = Opens the Accessibility Options Window (does not work in Windows 7)
    wuaucpl.cpl = Opens Automatic Updates
    powercfg.cpl = Opens the Power Options Properties window
    ncpa.cpl = Opens the Network Connections window
    bthprops.cpl = Opens the Bluetooth Control window (does nothing if no bluetooth devices are installed)
    certmgr.msc = Opens the Certificate Management MMC
    compmgmt.msc = Opens the Computer Management
    comexp.msc (or dcomcnfg) = Opens the Computer Services MMC
    devmgmt.msc = Opens Device Manager
    diskmgmt.msc = Opens Disk Management
    eventvwr.msc (or eventvwr) = Opens the Event Viewer
    fsmgmt.msc = Opens Shared Folders
    napclcfg.msc = Opens the NAP client configuration tool
    services.msc = Opens Service Manager
    taskschd.msc (or control schedtasks) = Opens the Task Scheduler
    gpedit.msc = Opens the Group Policy MMC
    lusrmgr.msc = Opens Local Users and Groups
    secpol.msc = Opens the Local Security Settings window
    ciadv.msc = Opens the Indexing Service Window
    ntmsmgr.msc = Opens the Removable Storage Manager
    ntmsoprq.msc = Opens the Removable Storage Operator Requests
    wmimgmt.msc = Opens the WMI (Windows Management Instrumentation) window
    perfmon.msc (or perfmon) = Opens the Performance Monitor
    mmc = Opens a blank Microsoft Management Console
    mdsched = Opens the Memory Diagnostics tools
    dxdiag = Opens DirectX diagnostics tools
    odbcad32 = Opens the ODBC Data Source Administration window
    regedit (or regedt32) = Opens the Registry Editor (these commands actually open different Registry editors, google for the differences)
    drwtsn32 = Opens Dr. Watson
    verifier = Opens the Driver Verification Manager
    cliconfg = Opens the SQL Server Client Network Utility
    utilman = Opens the Utility Manager (in Windows 7 this opens the Ease Of Access Center)
    msconfig = Opens the System Configuration Utility
    sysedit = Opens the System Configuration Editor
    syskey = Opens the Windows Account Database Security Manager
    explorer = Opens Windows Explorer
    iexplorer = Opens Internet Explorer
    wab = Opens the Windows Address Book
    charmap = Opens the Character Map
    write = Opens Wordpad

Active directory response: 00002098: SecErr: DSID-03150BB9, problem 4003 (INSUFF_ACCESS_RIGHTS)

Active directory response: 00002098: SecErr: DSID-03150BB9, problem 4003 (INSUFF_ACCESS_RIGHTS)

If you're getting this error trying to move mailboxes from Exchange 2003 or 2007 to Exchange 2010 then here's the simple fix.
  • Go into the user's account in AD and go to the Security tab. 
  • Check the box to Inherit permissions. If it's already set, clear it, force an AD update, and then check the box again. 

I had 2 boxes do this on my last Exchange migration. It's a real pain to find out after you've waited on the mailbox to copy but a very easy fix.