Saturday, November 10, 2007

Quick iTunes AAC to MP3 Conversion

Some time ago Lavie and Alvis upgraded their cellular phones to Samsung Sync's.

Overall they have performed very well.  The ladies like the large main screen and they come with quite a lot of custom themes.  The buttons are large and have a tactile rubbery feel.  I was considering upgrading my older Nokia 6102 to one, but never was able to get a good deal, and I found texting on the Samsung too different from the Nokia.

(Alvis somehow damaged the front mini-display on her phone.  It doesn't look cracked but the LCD doesn't display anything but a wicked lightning-like streak across it now.  The primary display is still working fine, however.)

One of the reasons the ladies wanted the Sync was that it was able to play MP3 files.  Since it accepts a 1GB SIM card, they could load a lot of their favorite tunes onto it.

Back when I got my first iPod and was ripping CD's into iTunes, I just accepted the default iTunes format of .AAC without thinking.  Now, all our songs are in that format. Unfortunately, the Sync didn't support that format. MP3's only.

That left me with having to convert their selection choices into MP3 format somehow, before I could copy the files onto their SIM sticks.

I created a special "cell-phone" playlist for each of them in iTunes and had them copy their chosen selections into them.

I figured I would have to burn them to CD, then re-rip them into MP3 format, but that seemed like a lot of work and a waste of media.

I did find NoteBurner which is a fascinating ($) program.  It allows you create a virtual CD to burn/rip songs to convert them without using physical media.  However, while really cool, it was a bit pricey just to move some songs onto a cell phone.

Then I found a beautiful solution...for free.

BonkEnc

BonkEnc is a freeware product that allows you to rip CD's, encode audio, and convert a multitude of formats.

It has a nice GUI, and is very easy to pick up and use.  It is very fast (on my system) as well.

Download either the "installer" file or the plain-zip file and get it on your Windows system.

Run the application, then launch iTunes.

I use playlists to organize collections of music, but you could do the same directly out of your iTunes music library listing...

Now comes the really hard part...ready?

  1. Select your playlist in iTunes.
  2. Select the song-files displayed (any/all) in the detail listing.
  3. Click and drag/drop them into the main window of BonkEnc. They should all appear and be added in.
  4. Select the "Options" and tweak as needed.  I've found good success in using the BladeEnc MP3 Encoder.
  5. Set your Output directory (make sure you have enough drive-space).
  6. Click the "Play" icon to begin encoding.

When done, just go into the Output directory and copy the MP3 files to your SIM card as needed!

What impressed me most was not only how easy and quick the process was, but the fact that it preserved the song info-tags.  When the SIM card with the copied files was inserted into the ladies' Sync's, the song titles and information was displayed.

Note: BonkEnc won't work around any DRM songs you have purchased through iTunes store.  If you want to work with those, I think you will still need to burn those to a CD then re-rip them to get around the DRM.

BonkEnc and iTunes: A very nice and very simple partnership.

And the ladies 'be jammin!

--Claus

Sunday, October 28, 2007

Freeware Software Finds Linkfest

Here is a collection of fine software I've wanted to highlight this month.

I've been running out of time, so feel free to browse the racks at your leisure (just not while in a leisure suit).

Nothing is tagged with electronic or ink-blister inventory-control devices.  So if you see anything you want, don't rush out the door.

Best Find-O-October Department:

Dial-a-fix - "Damn I wish I knew of this sooner."  This clever little utility is a collection of scripted fixes for common and frustrating Windows system issues.  It may be able to repair Windows Update errors and Automatic Update problems, MSI issues, SSL, HTTPS, and cryptography service issues, COM/ActiveX issues, missing registry entries, and quite a few more problems as well.

Graphical Goodies:

Poster Forge - Freeware utility to create your own posters (motivational, inspirational, demotivational, film/movie, old-West, and more).  I can see hundred's of uses for this around work.

3D Box Shot Maker - Want to make a virtual store-shelf product box image? This is your tool.  Take a graphic image and it can be edited, morphed, and cleaned up to a great 3d-style box image.  Really cool and neat. Includes shadows and reflection effects.

Rumshot - Create framed screenshot captures in a variety of frames.  Nice and easy to use program.

Updated Fall Classics:

KeePass Password Safe v1.09  - This perennial password manager favorite o-mine has now been updated.  I really like what it delivers. There is also an alpha-version release 2.03 out for the brave.

Process Explorer v11.03 - Microsoft's Sysinternals tool has been tweaked yet again for improved performance and loads of Vista support fine-tuning.

The PC Decrapifier v1.8.6  -  This handy-dandy tool removes a number of programs commonly installed on many "out-of-the-box" new computer systems.  If you like a plain-system, this tool can save you loads of time instead of manually uninstalling each of the elements one-by-one yourself.

DupKiller v0.8.2 - While I don't normally worry too much about having duplicate files on my 500 GB hard drive, having the ability to quickly and rapidly locate any duplicates is a great thing. DupKiller is one of the fastest utilities I have ever found just for this purpose.

OrphansRemover v1.8.9 - OK. It hasn't been updated since Feb 2006, but it is still a dead-handy tool for scanning your system for "orphaned" shortcut files. I just couldn't leave it out.

AM-DeadLink v3.1 - Well, it was updated to me.  This version supports Windows Vista.  AM-DeadLink quickly scans your bookmarks in Opera, IE, Firefox, and Mozilla/Netscape browsers and looks for invalid links.  You can also use it to download "FavIcons" for Opera, IE, and Firefox.  If you have dead-links, you can remove them and resave your updated bookmark file.  Lots of options and default setting adjustments.  It ripped through my Firefox collection of over 800 bookmark entries in just over a minute's time.

For the Impulsive:

Microsoft Works Converter - Via Lifehacker, this Microsoft utility allows you to open, edit and save those documents you made in Microsoft Works into Office 2003 or Office 2007. This newer version now supports Microsoft Works version 6, 7, 8, and 9 file formats.

Resizeable Form Fields :: Firefox Add-ons - Are you like me and hate being forced to accept web-form-fields that are just too small to be comfortable?  This is Firefox add-on for us!  Allows you to resize (most) form-field boxes to your tastes.

The Man in Blue > FormTextResizer - Don't want to go with a "add-on"?  OK.  Try this bookmarklet version instead.

Come back soon.

--Claus

Freeware Software Uninstallers

OK.

So I might be remiss if I just got done posting utilities to help you keep your installed applications up-to-date if I didn't quickly mention some freeware utilities to help remove installed applications from your system as well.

Sure, you can use the "Add/Remove Programs" list in your Windows Control Panel, but it is sometimes slow to build the list and frequently doesn't display all the applications it really could.

That's why a third-party uninstaller program could be quite handy to have. Not only do all of them allow you to quickly uninstall a program, many also provide you the ability to remove a "broken" item from the list, and quite a few provide incredible detail about the installed application itself.  If you haven't ever used anything else besides the default Windows add/remove tool, you don't know what you are missing.

Here are the freeware uninstall tools I use, in order of preference...

  1. MyUninstaller - Nirsoft's tiny little application quickly scans your system for applications eligible for un-installation.  What really makes it useful is not only does it list the application, but it also provides version number, company name, description (if available), installation path, web-site, installation date, uninstall string, registry key, root key, and the installer software type.  Even if you aren't going to actually uninstall an application, it is great for getting information and doing research on what you do have installed on a given system. You can generate a report. And there are a wealth of "advanced" features for power-uninstallers. USB Portable. 

  2. Free Uninstaller 1.1 - Jacek Pazera's application has really taken me by surprise. Like Nirsoft's above, it provides a great amount of detailed information on each installed application.  In addition, you can run instant web-searches using one of three web-search engines on any item listed if more research is desired. It is very fast.  The interface is very modern but friendly and has a dual-pane view.  You can set a number of program options.  It lists "visible" entries, "invalid" entry items, as well as "system components".  I really like this utility and it may soon become my number-one choice.  USB Portable.

  3. Uninstall Tool (v1.6.6) - This was previously my #1 uninstaller pick.  It was fast, simple and did the job. Besides the normal "uninstall" support, the right-click feature allowed me to view the installed program folder, registry entry, or even the website if available. If you have an entry listed but it is incorrect, you can delete the item from the add/remove list without actually uninstalling the (non-existent) product.  While not something most users would be advised to try, it is great for pros who are cleaning house.  The latest version (v2.2.1) is much more feature-rich, but is no longer freeware. Version 1.6.6 is USB Portable.

  4. Revo Uninstaller - Really an "advanced" uninstall tool. Not only does it allow speedy cataloging and uninstallation of applications, it brings with it some power-tools for system maintenance; an auto-run viewer/editor, quick links to common Windows system tools, MS Office and web-browser cleaners, junk-files (temp) cleaner, and some secure-delete tools.  It also has a "hunter-mode" utility to uninstall, stop, or delete applications using a GUI interface...basically drag-n-drop.  Nice interface and pretty easy to use. USB Portable.

  5. EasyCleaner - ToniArt's wonderful tool. Another "swiss-army knife" utility.  Besides providing uninstall support, it also can scan the Windows registry for invalid entries for removal (be careful!), look for duplicate files, look for unnecessary files, clean invalid shortcuts, display space usage, display startup items, clean IE temp files, cookies, and history, clear the most recently used lists on the Windows system.  USB Portable

  6. Safarp - Small and Fast Add/Remove Programs.  It is pretty small. It is definitely fast..maybe the fastest here.  It doesn't provide all the bells and whistles of the other programs, nor the amount of details of each installed program.  What it does do is quickly list programs you can uninstall/repair and lets you pick what you want to do. Simple and pleasant interface. USB Portable.

Claus

Maintaining Application Updates

Lavie and I purchased our first home pc back in the mid 90's.

We picked up a Gateway tower unit.  It was really fun selecting our choices of memory, processor, drive, software options.

Whoppin Windows 98.

Heady stuff.

One of the applications that came with it was called Oil Change.

It promised to help keep installed software up-to-date by running periodic scans and queries. I used it once or twice but that was it.

Today I keep really close tabs on the operating system updates and patches, along with my web-browsers and security software.  But to be honest, most other software updating takes a back seat.

I wouldn't say I have a "lot" of software installed on my systems, but certainly much more that would be easy to keep up with.

With the exception of DAT (signature) files for anti-virus and anti-malware I generally don't keep a close on versions.  If an application I have installed is running fine and stable, and a newer version doesn't really have any remarkable enhancement over a previous one, I usually remain happy with the status-quo.

I have recently been experimenting with several new freeware applications that promise to help with the task of monitoring your software for updated versions.

Here's what I think, in order of preference:

Free Software Updating Offerings

  1. Microsoft Windows Update - If you are a Windows system user, you MUST make this your number one stop for critical updates.  Check for "Recommended" and "Driver" updates as well from time to time.

  2. Microsoft Office Online - Stop two.  Since we run Microsoft Office, we also must make sure that our Office software is fully patched and updated to avoid exploits.  This is something that many users (home and work) frequently forget to do.

  3. Software Inspector - Secunia - This free on-line scan service fro Secunia checks your Windows system for insecure versions of common software applications.  It can run under Internet Explorer, Opera, or Firefox as long as you have a recent Java installation.  I really, really, really like this service.  It is fast and provides wonderful feedback on insecure findings, offering you information on the vulnerable version as well as (often) links to the latest update. You can perform a "fast" scan or a "full" scan which will look for software installed in "non-standard" locations on your drives.

  4. Personal Software Inspector (PSI) - Secunia - This is a localized version of Secunia's Software Inspector.  Though still in beta-status, it is pretty spectacular and has a number of things going for it.
    1. Secunia claims it scans for over 4,700 software applications,
    2. It identifies insecure versions,
    3. It identifies End-of-Life software versions,
    4. It provides direct-download links to software updates and patches,
    5. It runs in the background, monitoring your system constantly,
    6. You can set the options to skip certain drives or folders if you keep archived older-versions present.
    7. Clicking on any item identified provides a wealth of information on the reason for the alert, including a summary, solution, any installation deviation information, your installation path, and reference links.

  5. filehippo.com Update Checker - FileHippo is one of my most trusted sources for good, quality freeware/shareware applications.  They don't have everything, but what they do offer is high-quality and pretty mainstream software applications.  Download their update-checker which is a single exe file.  When run (requires .NET 2.0) it opens a web-page that will list any newer version updates to software they offer found installed on your system.  They also can provide beta-updates as well.  It is fast and works well for me because since I use many of the applications from this site, I get good match coverage.

  6. AppGet - Download the tool and install.  Once ran, it scans your system for installed versions.  Then hit the "synchronize" button to check your list against that maintained by the AppGet server.  On my system it found 78 applications and 29 that needed updates.  Of those, many were actually "beta" versions, so again, be careful.  It did run very fast and provides a clear link URL to view as to the source location of the file you are downloading (if available). It is community supported so it is only as good as those that contribute and participate.

  7. UpdateStar - This freeware utility is a relatively new kid on the block. It claims to support over 80,000 products. The interface is pretty Web 2.0, but is simple to use.  Here's the thing; like AppGet, it is supported by the community of users.  Right now it says I have 73 matching applications, of those, 4 are out of date and need to be updated.  Two entries report the application Eraser with my installed version as 5.7 (it is the current one) but it claims the current version is 5.84. Same with AVG Free. It says the current version is 7.5 and isn't picking up my 7.5.488.1157 version correctly.  Also, 27 applications it found installed, it doesn't have a corresponding version to offer, me.  Which gets back to the heart of the matter. If you want it to be accurate, you need to participate in the community.  So for any mis-matches, or non-matches, you really would need to do some homework, click the "submit-update" button on each one, enter in the web-form the correct version information, update links, etc and then submit it up to Update Star staff for them to authenticate and repost to an updated database.  The other issue is that you need to check the linkage for the "downloads" pretty careful.  I can hope that they are correct and not pointing to false locations, but for example, on my system, Update Star is pointing to a "S & S Royal Limited" for the latest versions of Eraser not Heidi Computer's Limited.  So while Update Star shows some nice promise, I wouldn't depend on it quite yet as an authoritative source.  Might be good for quick research, then track out on your own to confirm each finding.

  8. AppSnap - This is a clever little tool.  Once ran, it provides a list of popular software applications.  You can select the ones you are interested in, download them, and install them.  There is a little drop-down combo box at the top to display by a certain category.  If you are looking for updated versions, pick the "upgradeable" option.  On my system it only found one match that could be upgraded (EverNote) out of a total of seven applications I have installed that also match it's offerings.  It is a nice tool and useful, assuming you have at least one application installed that matches its database.  I rather like the plain interface.

  9. VersionTracker (website) - this website lists updated versions of many, many applications. The thing is you need to know what you already have installed and then monitor the site frequently.  Registered users get some more bells and whistles.

  10. RSS Feeds - There are a handful of software providers that provide very high-quality software utilities that I depend on (NirSoft and Sysinternals).   To stay up-to-date on these sources, I have subscribed to their RSS feed lists.  Many (though not all) software vendors or download sites have RSS feeds to provide their fans updates.  By monitoring these you can stay up to date on updates!

  11. Honorable Mentions: win-get Repository and Appupdater worth looking into, but not for the average home user.  You need to be comfortable with the command-line for these beauties.

Regardless of the method, find at least a few locations and tools here and use them to periodically assess your software situation.  Keep you Windows system up to date with the latest Microsoft patches and at least run Secunia's on-line Inspector from time to time.  This should at the very least help keep your system free from vulnerable versions of common applications.  Then play with the others as well and see if you might find them useful for keeping an eye out for your other applications.

Claus

Friday, October 19, 2007

Comcast Mysteries: Am I a spambot ? & SMTP Port 25 or 587?

I've been a bit "miffed" lately.

A few nights ago Lavie couldn't find a few of her favorite cable channels. And a few others had gone "static" as well. We program our favorites into the TV's so we can skip the ones we don't watch, so by going though them manually, we figured out where they went and suspected a channel lineup change. This was later confirmed in the local paper.

So it was time to do some reprogramming of the televisions and recording units.

Then we got this mysterious email...

Assessing Abuse-garee

I'll spare you the details but it began a bit suspiciously on several levels.

Dear Comcast High-Speed Internet Customer,

Please read this entire message, review the required action(s) below,
and send a prompt reply message to acknowledge receipt of this email.

Explanation:

We have confirmed that your computer has been involved in attempted
virus propagation, an activity that is in violation of the Comcast Terms
of Service Agreement. The reporting parties have provided logged
information, which identifies the IP address of the computer that was
attempting to transmit the virus. The IP address listed was one that was
assigned to your computer at the date and time in question.
Also were a number of moderately-helpful generic suggestions on how my system may have become infected, mediation steps, and some "helpful" html-weblinks.

Since I have been on the record before about being suspicious about similar emails (Phish bait) I did some checking first before getting into a panic and responding.First I checked the HTML link code. They all seemed legit and did point back to legitimate Comcast website addresses.

Then I checked the IP address of the sender. It was in the range of Comcast owned addresses based on AIRN WHOIS. OK. So far so good. I then did a Google search on abuse-garee and found a handful of hits, including this one that was very helpful: Linux Home Automation - Comcast mail rant!So by now I was pretty comfortable believing that the email was legitimate from Comcast.

Am I compromised?

So, while I didn't think any of my systems were compromised I had to re-verify their status, just for my own personal peace-of-mind.

Alvis's Linux box hasn't been on for weeks, so I quickly discounted that one. How do I know? The pile of teen-detritus on top of her keyboard and blocking her pc cabinet door hasn't moved in that time. Besides, it's Linux. That's kinda like baiting an Apple user and telling them their pc is a virus-factory. Pick a fight elsewhere. You'll generally loose.So that left me a Vista system and two XP Home SP2 systems.

While I doubted I'd find anything, It is important to objectively verify or discount all potential reports of security breaches. My systems are all fully patched and up to date. I run a variety of security applications as well as a firewall (inbound/outbound monitoring), and a hardware-based firewall/router. We don't have a wireless network that someone could have hacked.I went through each system running full system hard-drive scans using AVG Free. Then I went through them and did full-drive scans using a series (four) of my favorite anti-malware scanners. I did rootkit scans. All came back clean. I ran a tool that monitored all my network connections looking for any unexpected findings. All were normal. I finally checked all my autorun entries as well as the running system processes. Nothing out of the ordinary.

So after a lot of work, I was left with two possible conclusions...one of my systems was so compromised that I couldn't even find evidence...and maybe should do complete reformats of every one...or Comcast made a mistake.

Re-View

The automated email that I got from Comcast's abuse-garee wasn't very helpful on the surface. It did appear to be focused on virus propagation activity. As far as I could technically tell I had ruled out that being the case...unless it was an as-yet-unknown variety. Certainly possible.To the best of my knowledge Comcast's cable modems use dynamic IP addresses, so it might be possible that my IP address had been updated recently and now I was assigned one from a previous user that had been infected, and thusly, tag-I'm-it.

Comcast's email was clearly a canned response likely geared to average (non-technical) users.It did not contain any time/date event log information.

It did not contain any information about the file or attachment that was being propagated.I have never received one previously from Comcast, so it didn't seem like the problem (if accurate) had been occurring until just very recently.

It didn't contain information as to the destination(s) of the propagation techniques.Any one of those elements might have been helpful to me.

Just about the only clue I had to go on, was that this "event" appeared to have been reported to Comcast by an outside party...but again, no name or clues for follow-up.

Lavie's Lead

So today, while I was recovering at home from a stomach-bug and Lavie was nursing me to health, she mentioned she was having a problem with her laptop.Turns out she had forwarded several email the other day to me (at work) as well as to her Gmail account from our desktop pc.

Her laptop has Thunderbird configured to pull mail from her Gmail account but although I got them at work, she never got them through her Gmail account and back to her Thunderbird client.I asked her if she had logged in to Gmail, not via Thunderbird client, but directly into the web page. She said she hadn't as she forgot her password and it never made it into our KeePass Password Safe keeper application.

I went to her laptop and pulled Thunderbird up and went into something like Tools --> Options --> Security --> View Saved Passwords. Then in the Password Manager, clicked "Show Passwords."With that information in hand, I logged into Lavie's Gmail account on the web.

None of her emails were in the main window, so I checked under "Spam" and.....There they all were.

We tagged them as "Not Spam" and then sent an email back to our comcast.net account to ensure that email address was in the Gmail contacts and wouldn't be tagged again.

What do you think?

Do you think that Gmail's spam-filtering machine send an automated spam-abuse alert back to Comcast? That would have contained our IP address in the sender's field, and since Lavie forwarded multiple emails at about the same time, it surely could have triggered a "spam-bot" tripwire in Gmail.

The emails were all sent shortly before we got the Comcast warning email. So that fits as well.I also sent one from our desktop account to my own Gmail address and somehow it also ended up in my own Gmail spam folder. Interesting. I had sent emails this way before, but I went ahead and sent one back to ensure it was also in my own Gmail contact list.

Per Comcast's abuse-garee request, I did reply to the original email I got confirming its receipt, as well as outlining my issues with the lack of detail they provided, assurances that my systems appeared clean, requesting more information on the reported event, and my findings above that I suspected triggered the alert in the first place.I'll let you know if I hear anything back.

Which then led me to this...

Bonus: Which SMTP port do you want me to use, Comcast?

Of interest, we are using port 25 for our Outgoing email server setting to send desktop account email to Comcast. Is and has been working just fine.I got that value when we transitioned over from TimeWarner Roadrunner's settings using the following guides from Comcast.

How do I setup Thunderbird for E-mail? - Comcast FAQ's

How to verify Thunderbird settings - Comcast FAQ's. Note in this one, the last screen-shot clearly shows the outgoing mail server stmp server port set as "25"

However, based on this post I mentioned, it seems that Comcast really wants Thunderbird users to use port 587 instead.How to configure Thunderbird to use port 587 for sending e-mail - Comcast FAQ's

This MozillaZine article has a bit more info: Creating accounts in Thunderbird for popular email providers ...

Comcast documents two SMTP configurations, a unsecure connection using port 25 and a secure connection using "TLS if available" and port 587. If you get a error message that the SMTP server may be unavailable or refusing SMTP connections there is a undocumented configuration that several users have gotten to work. Use port 465 , set "use secure connection" to SSL, check the authentication required box and provide your full Comcast address as the username.

I haven't changed it yet, but might just do so if I hear back from Comcast. Funny they didn't specifically ask me to do so...

Looks like a few other Comcast folk have tripped over this:

Comcast Blocking Port 25? ~ usrbingeek’s musings

port 587 - CNET Mac software ForumsPort Of Call And Other Outlook Adventures ~ IT Professionals

"Does my ISP block port 25?" - DreamHost Knowledge Base

With resepct to Mr. Ollivander, "Curious...very curious..."

--Claus

Update..Lavie forwarded another few to her Gmail account and we got a fresh warning message from Comcast. These didn't end up in her Gmail spam pile. I'm thinking Comcast itself is scanning the messages (content/header/subject...who knows) and giving the alert message. I'm going to swap over to the other port this weekend and see what happens.

Monday, October 15, 2007

heise Offline Update 4.0 - Now Serving Vista and Office users!

I've mentioned here (once or twice) the fantastic Windows update tool from heise: Offline Update.

I can't imagine a Windows tech-support shop (hobby or enterprise) that hasn't at least kept a copy of this tool in reserve.

Home users even can benefit.  It's great for fully patching a Windows system without having to connect the computer to the network/Internet to obtain the critical update patches.  This helps ensure that the operating system is as locked down and secure as possible before networking it.  The drawback it that (in the past) you either had to download and keep up with the patches manually one at a time, and install them one at a time, or take your chances and download them from the net(work) with the time associated with that process.  And if you were setting up a new system for a dial-up user...get out the cooler and kick back...you will be sitting there a long, long, time.

Autopatcher...Down but not Out

Previously users might turn to AutoPatcher for an all-rolled-into-one patching solution. It worked great and had a big following. Unfortunately, Microsoft decided they didn't like the model and had to shut down their project in it's current build.  Good news is that Antonis is hard at work making a new version that will hopefully pass Microsoft's smell-test.

heise Offline Update Script

heise Security's Offline Update script does some amazing things.  First you just download and install the latest build version. Then unpack it to any location you wish on your drive.  Run the executable and select which platform(s) and localized language(s) you want to create.  Then decide and select if you want an individual media ISO for each build or a combined platform ISO.

A WGET window opens and the scripts download the latest update catalogs directly from Microsoft's update servers. Then it downloads (again from Microsoft's update servers) the updates needed.  When done it rolls them up in an ISO file ready for burning to disk media with an updater kickoff exe file.  I just unpack the ISO with ISOBuster and put the files directly on a portable USB drive and use that instead.

When it is time to update a system, pull out your current disk/USB media, pop-it-in and update away...no network connection required!

An auto-run kicks in and the apply update window appears. Select your options as appropriate and let-her-rip.  The script then compares it's update catalog list against the updates currently listed on the local system catalog and then proceeds to apply only those updates (automatically) needed to bring the computer current.

Next time you run the "master" updater again, WGET again gets the latest catalog, compares what it finds against what has already been previously downloaded, and only downloads the new ones or patches that have been updated to a newer version.  Then creates a fresh ISO file.

Version 3.2 supported updates for Windows 2000, 2003 Server, and XP (all versions).

Easy-Peasy!

heise Offline Update Script 4.0

With version 4.0 the folks at heise have simply outdone themselves.

They have included Vista System update patches in the list of supported operating systems and have added support for individual support packages for Office 2000, Office XP, Office 2003, and Office 2007!

Check out all these new features!

  • New: Support added for Microsoft Windows Vista
  • New: Support added for Microsoft Office 2000, XP, 2003 and 2007
  • New: Updates which are not listed in wsusscn2.cab any longer will be removed automatically
  • New: Service Packs (statically defined updates) may be excluded from download
  • New: CopyToTarget.cmd added to ease USB device preparation
  • New: Generator and Installer GUIs will be displayed in German on German systems.

I tested the new builds on a freshly (ImageX'ed) XP Pro SP-2 with Office 2003 system.

Before using, I ran an on-line Windows Update check and found the system needed 22 Critical Windows updates for the system and needed 2 office 2003 patches (SP3 and Outlook junk mail filter update).  I did not apply these but just use this to "baseline" the patch status.

Note: I could have also used the Microsoft Baseline Security Analyzer (MBSA) to test the before/after patching state as well.  MBSA 2.1 (beta) now also supports Vista platforms.

Next I ran the XP patch updater installer and it quickly performed the updates "off-line."  I rebooted the system and went back and checked "on-line" how many patches were applied.

Result? All of them. No updates were missed.

Then I tried the Office 2003 updater installer.  It successfully installed the Office 2003 SP3 patch, but didn't catch the junk-mail filter patch.  Still, not to shabby!

The scripts/installers can be customized with include/exclude lists manually if you are willing to do a bit of work.  For my purposes it looks and works great as-is, but it's nice to know you can continue to tweak it out a bit more if you want.

heise Offline Update script 4.0 -- Highly Valca Recommended!

--Claus

Sunday, October 14, 2007

ImageX - Welcome to the Imaging X-Zone

X = ?

The perennial symbol of the unknown variable.

There was Racer X from Speed Racer.

There was Chemical X that professor mixed in when created the Power Puff Girls.

There were those pesky X-Files causing havoc in the FBI for Mulder and Scully.

The search for Planet X has and still causes consternation for some astronomers.

There was that "Man from Planet X."

Now Microsoft enters the realm of "X"....with ImageX.

ImageX = Cool

As I have just posted ( GSD: Drive Imaging and Cloning Solutions ) at our shop we primarily use Ghost as our image/cloning platform.  It is solid and does a good job.  However image captures on our drives can take one to two hours (depending on compression and image placement location). Placing an image on a target pc can take anywhere from thirty-minutes or longer in some cases.  We needed something fast (at least on the deployment side) yet pretty flexible and easy to use.

So we have been playing with Clonezilla which is indeed both fast and flexible.  Image captures take about ten minutes or less for multi-Gig drive.  Image deployments take even less; approximately five minutes or so in some cases.  The reason for the speed is that Clonezilla (unlike Ghost) does only a copy of the drives sectors and data blocks that are actively in use. That means a faster capture time and restoration time.  Good for smaller image files and efficiency, but not so good for forensic work.

So when I recently stumbled upon Microsoft's ImageX utility that has shipped with Vista (and Windows PE 2.0 via the Windows Automated Installation Kit (Windows AIK) I decided to see just how useful this free utility could be in the imaging process.

What is ImageX?

ImageX is a command-line tool that enables original equipment manufacturers (OEMs) and corporations to capture, modify, and apply file-based disk images for rapid deployment. ImageX works with Windows image (.wim) files for copying to a network, or it can work with other technologies that use .wim images, such as Windows Setup, Windows Deployment Services (Windows DS), and the System Management Server (SMS) Operating System Feature Deployment Pack.

What is ImageX? - Microsoft TechNet Reference

What makes ImageX really neat is that it is not a sector-based image method, but copies the source system's partition in a file/structure based format. So image sizes are radically smaller as you don't have all those unused sector blocks.  Also, it "single-instances" the files, so that one file is stored apart from it's multiple location pointers.  That means one file is imaged even though it may exist in multiple locations. When the image is redeployed, the single file is restored to the multiple locations again. 

It is "non-destructive." This is important to consider. When Ghost and other products put their image on the target drive, they destroy the data that currently exists on it.  ImageX just "overlays" the existing data.  That means that to do a truly "fresh" reimage, you must first ensure your disk/partition has been formatted before putting your ImageX image back. In some cases there might be benefits to not doing a format first and just putting the image back.

ImageX supports three compression formats; Fast, Normal (none), and Maximum. As with most compressions of images, time to capture an image increases as compression is higher.

Finally, you can mount an ImageX image file, add and remove files from it, and (with Vista) even inject drives and patch updates directly into the image.

That last thing is really cool!  Currently with most all imaging solutions, you build a "source" pc, load the patches, install your software, tweak it out, run Sysprep then capture an image.  If you need to go back and add more system updates or drivers, you then have to rebuild your source pc with the updates, re-run Sysprep and recapture the image.  With ImageX (for Vista images) you can just work with the image file and continue to maintain it without going back to the source computer. Neat!

It excludes certain system files from the image automatically: recycler, system volume information, pagefile, hiberfile...etc.

You can "span" an ImageX image file across several CD's.

And it is free..assuming you have included it on a copy of a Windows PE 2.0 boot-disk.

Limitations of ImageX

It's not a perfect solution.

You can only use Microsoft's Windows Image (.wim) files with ImageX.

You can only "mount" images in Windows ImageX from XP SP2, Server 2003 and Vista systems. To read/write them you must mount them on an NTFS formatted partition.

You can captures and apply images for any version of Vista, Server 2003, XP, or 2000 Pro system.

You must first use Diskpart and Format utilities to prep a drive/partition prior to restoring an image and if you use Sysprep first, the image must be deployed to the same volume location as the the original.

It is command line based. (We will get around that in a just a bit with the introduction of GImageX.)

Getting ImageX

To get ImageX you must first build a WinPE 2.0 disk.

I've covered the process, ITsVISTA has covered the process, and Svrops has covered the process.

Basically, download the WAIK and install it on your XP or Vista system. Then run the special command-line tool.  Copy the needed source files to the build-folder on your NTFS partition, copy the ImageX utility to your build-folder, make your boot-image with the Oscdimg tool included, then burn the resulting ISO to CD.  It's a bit more detailed than that, but not by much. 

Go read the posts referenced and it should be pretty easy to do.

Using ImageX - Capture Basics

Prep your target Windows machine first by getting it patched and set up just the way you want it.  Delete any unneeded files/folders, run a defrag session, empty the browser cache and any temp folder contents, etc.  I recommend running Sysprep first to tuck your source station into bed.

Next decide where you plan to capture your image to.  This could be a network share, a USB external drive, or maybe another drive/partition on the same system.

Boot the system with your Win PE 2.0 boot disk.

Once up, type:  net use <drive letter to map>  \\Servername\location

With the specifics entered for your server if you are attempting to map a network drive then image to a network share.

If you are using a portable external drive, you can skip that step.  Just be sure you have correctly identified what drive letter the device is mapped to. Win PE 2.0 seems to be very good about picking up and mounting USB storage devices.

To capture the image, type: imagex /compress maximum /capture c:\ z:\images\image.wim "image name"

You can leave off the "/compress maximum" if you want the image at "normal" level or use "/compress fast" for a larger, but faster image capture process.

You must specify the specific full capture drive letter and path to where you want to put the image. I used "z:\images\" as my example, yours will differ.

You can also add the /check and/or /verify switches as well, though these will increase image capture times.

You can name the .wim file whatever you want.

The final part "image name" (with quotation marks) identifies this particular image file in the image.wim image file.  Does that make sense?  See, one .wim file can actually contain multiple images!  How cool is that?

Please review these excellent posts for more examples and details on the ImageX capture process:

Using ImageX - Deployment Basics 

First you must be sure your target drive/partition is prepped.

Here is a "gotcha" for image deployments for ImageX. 

With Ghost, you (usually) just perform a disk-to-disk copy (all) or maybe a partition-to-partition copy and move on. You don't normally think about formatting the disk and/or the partitions.  With ImageX you must, as it overlays the image on the drive/partition.  If stuff is already there and not removed, the image overlays it and leave all the non-matching original remnants behind.

Likewise, you can't take a "naked" and unformatted drive/partition and just put the ImageX image back on it.

So, boot your target system with your Win PE 2.0 disk.

Next, either partition the drive accordingly (if "naked") or format the boot partition.

A basic command would be something like this example: format c: /fs:ntfs

I've seen several mentions that say a "/q" quick format will work fine, and others that say you must do a full format after creating it with diskpart.

Once your target drive and partition have been prepped, put the image back down.

Map to the network drive just like we previously covered, or use your external USB drive or disk media.

Run the following command: imagex /apply z:\images\image.wim 1 c:

You may want to add the extra option /verify at the end to verify your image laydown...just remember that that adds time to the deployment.

Note the "1" we used.  This means to use the 1st image in the .wim file.  If you have multiple images in a single .wim file you will need to know which "index number" image you want and use that number accordingly.

Once done, remove the Win PE 2.0 disk, reboot the system, and your new image should appear.

Because of the imaging technique, the image restoration to the target pc should be much faster than Ghost or many other sector-based imaging applications. This will depend on the hardware and image size so your results may vary.

Here are some more fantastic posts that provide great examples and details on the ImageX image deployment process:

Using ImageX - Advanced WIM Manipulations

As I alluded to earlier, you can do some cool things with ImageX .wim files.  I'm still a bit unclear after reading all the material.  Some seem to suggest you can mount and change XP, Server 2003, Vista, and Windows 2000 Pro .wim and modify them, other places seem to restrict the mounting and modifications to just Vista .wim images. Some sources suggest that only on a Vista system can you mount .wim files, others that  XP, Server 2003, Vista can handle it (assuming the ImageX .wim filter driver is loaded on the system).

I think I have some experimenting to do... the meantime here are some advanced tips.

A single .WIM file can actually contain multiple images in it.

You can add/remove files to certain .WIM images. (...but not actually "install/remove" programs and configuration settings.)

You can inject drivers into a .WIM image file.

You can install "hotfix patches" into a Vista .WIM image file.

Welcome to GImageX - a GUI Front-End

GImageX is a freeware tool that places a GUI front-end on the command-line utility that ImageX is.

This makes it much easier for non command-line folks to use the tool to capture your WIM images, mount the images, and deploy the images.

Just be sure to copy GImageX.exe and the ImageX files (from WAIK) into a directory during your WinPE 2.0 building process.  That way it will be ready to use. 

Then run GImageX and have at it!

ImageX Command Line Basics

There are a wealth of options that come with ImageX.  However, like most command line tools, they are hard to identify without seeing them all broken down first.  I found the following link useful in understanding the features and options ImageX operates under. ImageX Command-Line Options - TechNet

The following points from that article are important to consider:

To modify your volume images, you must install the Windows Imaging File System Filter (WIM FS Filter) driver on a computer running Windows XP with Service Pack 2 (SP2), Windows Server 2003 with Service Pack 1 (SP1), or Windows Vista. Installing the WIM FS Filter driver enables you to mount a .wim file as if it were a directory and to browse, copy, paste, and edit the volume images from a file management tool, such as Windows Explorer, without extracting or recreating the image.

imagex /apply - Applies a volume image to a specified drive.

Important: You must include the parent directory for the /apply option. Otherwise, when the image is applied, it will overwrite everything in that location. For example, if you apply the image to drive C, the /apply option overwrites everything that exists in drive C with your image files.

/check

Checks the integrity of the .wim file. If not provided, existing checks are removed.

/verify

Enables file resource verification by checking for errors and file duplication.

imagex /capture - Captures a volume image from a drive to a new .wim file. Captured directories include all subfolders and data. You cannot capture an empty directory. A directory must contain at least one file.

/compress [maximum | fast | none]

Specifies the type of compression used for the initial capture operation. The maximum option provides the best compression but takes the longest time to capture the image. The fast option provides faster image compression but the resulting files are larger than those compressed using maximum. This is also the default compression type, used if you leave this parameter blank. The none option does not compress the captured image at all.

While the compression type that you choose affects the capture time, it only slightly affects the apply time.

/verify

Enables file resource verification by checking for errors and file duplication.

The /verify option will affect the overall capture time. During a capture operation, the progress bar indicates the status of the capture operation only, not the verify operation. When the capture is complete, the verify process begins. This process takes time even though the progress bar shows 100 percent.

imagex /mount - Mounts a .wim file from Microsoft Windows XP with Service Pack 2 (SP2), Microsoft Windows Server 2003 with Service Pack 1 (SP1), or Windows Vista with read-only permission to a specified directory.

imagex /mountrw - Mounts a .wim file from Microsoft Windows XP with Service Pack 2 (SP2), Microsoft Windows Server 2003 with Service Pack 1 (SP1), or Windows Vista with read/write permission to a specified directory.
Once the file is mounted, you can view and modify all the information contained in the directory.

imagex /unmount - Unmounts the mounted image from a specified directory. If you use the /unmount option without the /commit option, your changes will be discarded. To be able to save your changes, you must mount the image by using the /mountrw option and use the /commit option when unmounting the image.

Quality Linkage for ImageX

Good luck and maybe Microsoft's X-Zone utility known as ImageX may help you in your image deployments.

--Claus