Psychology Home Shop Home
Shop Home Shop Policies How-To's Contact Us
     
 
 

How-To's


How to Connect to the File Share Server Win

How to Connect to the File Share Server

How to connect a networked printer to your computer

How to prune out large emails

Wireless cards that work with NYU-Net Wireless

How to setup wireless on Windows XP with Service Pack 2 (SP2)

How to print a poster in Windows XP (revised 3/11)

How to print a poster in Mac OSX

Windows Powerpoint Poster printing FAQ

How to disable active scripting in Internet Explorer

Backing up files on a laptop

How to setup Eudora for Windows XP

How to adjust the quality of text on your screen in Windows XP

How to buy Office2003 at NYU Pricing

How to remove Spyware from your PC

NYU-Approved Vendor contact info

How to access NYU Pricing of Dell Computers via the web

How to enable/disable NYUHome's SPAM filtering feature

"Ever since the Shop staff set up my laptop for Meyer Bldg networking, it doesn't work on my home network..."

"Do I Have a Virus??" (Windows)

Windows XP, Service Pack 2, and Retrospect Backup software

Is NYUHome mail secure?

Alternative web-browsers for Windows XP

Where is my Mozilla Mail client or Thunderbird user-profile located on my computer? Where are my mail folders stored on my computer?

What to know BEFORE you buy a color-inkjet printer

Endnote and Microsoft Word bug fix

How to use the PC scanner in room 975

How to backup your data onto an external drive using "Iomega Backup Pro" software (WinXP)

How should I run XWindows securely on OSX / UNIX / Linux?

How should I run XWindows securely in Windows?

Shop's WinXP Setup Policies

Shop's Windows 7 Setup Policies

How to download your NYU HOME email NOTE: Its essential to read carefully and skip nothing or you will permanently lose email. The instructions should stress better how important it is to change back to imap after you temporarily use POP.

How to reset Windows Update if WU doesn't work

How to Use Microsoft Sysprep to seal new Norton Ghost Images for distribution on multiple PCs.

How to install Thunderbird email client and how to import from Eudora


How to Investigate and Find Worms, Viruses, Trojans in Windows

How-To for Apple Time Machine Backup software

How to use Windows Remote Desktop to connect to my NYU computer

How To Install Boot Camp from an Image

How to print a poster made in Adobe CS3

How to Buy Toner


Wireless Cards That Work With NYU-Net Wireless

NYU ITS' wireless program has left "beta" and is now available for anyone who has a valid NYU Net ID. Building locations are at a link at the end of the email. However, not all wireless cards are ideal with NYU's type of wireless.

"Apple OSX"

If you have an Apple airport wireless card and OSX, logging on is pretty easy. Look at the link below and navigate to the install directions for OSX.

"But I have a PC laptop"

There are scores of different wireless cards for PC's, and for NYU's type of wireless, some wireless cards are better than others. You should buy one that uses the Cisco's "Orinoco Gold" chipset. Other recent vintage wireless cards will work, but may need additional software. Do not buy the "silver" orinoco, only the "gold."

If you go to www.cdw.com and look for CDW Part# 494359, this is a "cardbus" PCMCIA card that will work with virtually any Cardbus PC laptop made in the last 2 years. Confirm that your laptop uses Cardbus before you buy. This card is "orinoco gold" and supports both b and g wireless.

If you don't care about using NYU-Net wireless, but still want to use the wireless in CNS and Psych, look at the less expensive Linksys or Netgear cards that offer both b and g wireless. Don't buy "a" type wireless cards.

"Why the need for a special brand card for ITS wireless?"

ITS chose a proprietary Cisco architecture that is directly supported in "hardware" in the Cisco gold cards and Apple airport cards.


http://www.nyu.edu/its/wireless/locations.html

http://www.nyu.edu/its/wireless/requirements.html

back to top


Backing Up Files on a Laptop

Several people have had their laptops crash and data was lost. Hard drives are much more likely to crash on laptops (heat/friction inside the drive or simply dropping the laptop).

Memory sticks work best with WinXP and OSX, while CD writers work fine in all versions of operating systems.

One other option if the files are small is to email your important files to yourself as attachments. As long as you don't delete those emails, those files will stay on ITS' mail server as "backups" should something happen to your laptop. If you have one particularly important file that you can't live without, simply email it to yourself.

back to top


How to Setup Eudora for Windows XP

All new Windows XP computers in CNS and Psych have Eudora pre-installed on the system. Eudora is the email client that NYU ITS and the Shop staff support for Windows email. For substantial network security reasons, we do not support any other windows-based email clients.

Here's exactly how to set it up:

If asked when you open Eudora for the first time, go to the "advanced" setup option. If not asked this, go to Tools Menu, then Options.

Be sure to do all of these options we detail here. Some seem innocuous if you choose a different option, but they aren't. Make sure your email works after you follow this How-to and before you change any additional options in Eudora.

++ In Tools, Options, scroll to "Getting Started"

Enter your Real Name as you want others to see it (not your email address, your actual name)

++ Scroll to "Checking Mail"

Mail server is imap.nyu.edu

Login is your NYU net ID but not your email address (i.e. jhf2 but not jhf2@nyu.edu)

Secure Sockets is "Never"

++ Go to Incoming Mail

Choose IMAP
and "move it to Trash" option

++ Go to Sending Mail

Enter your preferred complete email address in "Return email address"

SMTP server is smtp.nyu.edu (NOTE! if you are at home or traveling you MUST use the SMTP of your internet provider otherwise you will not be able to send mail, only receive mail. You will get a "relaying" error message. If you don't know your ISP's SMTP name, then login to home.nyu.edu on a web browser and send mail that way. There is no simple work-around to this issue other than using the web-browser version of NYU HOME. Contact your ISP if you get a relaying error message.

Secure Sockets is "Never"

Do not allow authentication

++ Go to Attachments:

Encoding must be MIME

Click on the attachment directory and pick a place to save your attachments: we strongly suggest making a folder called ATTACH in your "My Documents" folder

++ Go To Viewing Mail

Use Microsoft's Viewer
Do not show preview pane (this is a substantial worm security risk if you do) NEVER allow executables in HTML (an extreme worm risk -- you are 100% guaranteed a worm if this is checked)

++ Go to Styled Text

NEVER EVER use styled text -- it will mess up your attachments if those you send to use old or unusual mail clients. Your sender will get a blank email or garbage text.

Choose "Send Plain text only" and uncheck the formatting toolbar option

++ Close the Options Dialogue box and you are almost done.

1. Confirm that eudora works by going to File and Check Mail. Enter your password. Because this is the first time you are checking mail, it could take several minutes to get all of your mail.

2. All of your incoming mail should appear in the left column and will be located in the folders under the word "Dominant." All of your Sent mail is located in the OUT folder above the word "Dominant"

3. Send a test email back to yourself and see if you get it. If you did, you know your email works receiving and sending mail.

Note: if you can get new mail but get a relaying error when sending, then look at "Sending Mail" above.

Don't change any options unless you have read Eudora's built-in Help first. Some will mess up your email. Go to the HELP menu and choose Topics if you are really curious about all of Eudora's options.

back to top


How to Adjust the Quality of Text on your Screen in Windows XP

Windows XP uses "ClearType" to make text look better on LCD panel displays and also on CRT displays. I find the default setting for ClearType too strong, but you can adjust them to your liking. You can also turn off ClearType entirely. The larger your display, the more likely you will need to use ClearType.

http://www.microsoft.com/windowsxp/pro/using/howto/customize/cleartype/tuner/default.asp

more info about Cleartype:

http://www.microsoft.com/typography/cleartype/default.htm

back to top


How to Buy Office2003 at NYU Pricing

The licenses are $60 per user. The media pack is $27. The version is Office 2003 Pro and there are now no minimums - you can get as little as a one user license. This special pricing is for department purchases only. NYU accounts must be used to process the order. Not directly available to students to buy.

To purchase this software at this price you must contact:

Scott Jackson
Software Buyer/ Asst. Manager
NYU Computer Store
242 Greene Street
New York, NY 10003
(212)998-4591

back to top


How to Remove Spyware from your PC


There are 2 types of software that will greatly reduce the speed and stability of your windows PC -- adware and spyware. We are constantly asked how to remove this stuff after it is installed, so here's how to do it yourself. Be highly wary of all "free" software or anything related to "free" music on the internet. Once installed, the software is
intentionally made so that it is difficult to remove. This academic year will be a banner year for adware and spyware issues on NYU-net. Note that Norton AntiVirus DOES NOT detect adware at all, and only detects some spyware.

"How can I prevent adware and spyware from ever happening on my computer?"

The best way to avoid all of this is to never install free software from the internet and particularly, never search for free music on the internet. If you search for free music, you will invariably be asked to download software. If you say "yes" to that, there's no doubt that you've added adware or spyware or both. I've noticed that Undergrads will read these cautions and install this stuff anyway because they want free music. Faculty should be wary of UG's using important computers.

ADWARE

"Adware" throws up additional pop-up ads when you web surf. Adware runs all of the time in the background and can slow you computer down 20% or more. Adware doesn't collect sensitive information about you while you surf, but it is often badly coded and can break the normal stability of your computer. Removing it is usually easy. There is excellent free software that you can download at the link below. **Just be sure to run Ad Aware's update to get the latest version before you scan your PC. "Ad Aware" has never caused a problem in the last 2 years on at least 100 PC's, so it comes very recommended. You do not need the $20 version of this software. There is no other software better than this for removing adware.

http://www.lavasoftusa.com/support/download/

SPYWARE

"Spyware" is much much more serious. It can collect all of your passwords, both when you websurf and when you login. It will compromise your computer so that someone on the internet can log into it at any time and grab software license keys or your credit card numbers. A hacker will install additional software onto your PC (like use your PC as a SPAM "mail server" or your computer will be used to launch network attacks against other computers somewhere else on the internet). Until NYU ITS firewalls NYU-Net, all of these risks are real and have already happened on our network several times.

Users bear responsibility for spyware installed on computers because spyware usually piggybacks onto some "free" software that users downloaded from the internet, like file-sharing software. All file-sharing software is 100% a bad idea for any PC and it is 100% against Shop policy. It opens up your computer to hackers on the internet. Hackers love it when naive users install file-sharing software and then leave their computer running 24 hour a day on NYU-net.

Removing spyware is much trickier than removing adware. I've tried all of the major software removal tools. Currently the best is PestPatrol. It isn't free but it is worth every penny of the $40 if you have spyware. Running PestPatrol is easy but be sure to read the list of what PestPatrol finds on your computer. If it looks really bad, you should reinstall the operating system.

The problems about spyware:

1. Some spyware breaks the normal function of your PC by changing critical system files. So it is likely that you will need to completely reinstall the operating system to regain normal performance. I recommend reinstalling the operating system if you care about security of your passwords and charge-card #'s.

2. Varieties of Spyware change fast, so no spyware removal program is 100% accurate. It is not unusual for any spyware removal software to miss some spyware. This is another compelling reason to format your computer and reinstall the operating system if you find spyware on your computer.

3. The Shop staff is unhappy about finding spyware since it is usually the result of inappropriate non-academic use of a computer on the network. Spyware poses a huge security risk to the entire LAN, and to your data.

http://www.pestpatrol.com/Products/PestPatrolHE/

back to top


NYU-Approved Vendor Contact Info

CDWG:

John Lauro
CDW*G
Sr. Higher Education Account Manager
The Right Technology. Right Away .(tm)
Ph: 800-508-2394 ext 87225
Direct Ph: 203-851-7225
Direct Fax: 847-990-8090
E-mail   John.Lauro@cdwg.com
URL..   www.cdwg.com/NYU

PCConnection:

GovConnection Information Sheet
Phone:1-800-800-0019
Weekdays, 7:30 a.m. to 7 p.m. EST
Fax: 1-603-683-2482
Mail: GovConnection, Inc.
706 Milford Road
Merrimack, NH 03054-4631
Attn: Higher Education Accounts

TigerDirect:

Juliana Martins - Corporate Account Manager
Tigerdirect.com
Mail: Business to Business Dept.
Attn:  Juliana Martins
7795 W. Flagler St., Suite 35
Miami, FL 33144
Order Phone Number:  1-888-498-4437
Order Fax Number:  305-415-4335 Attn: Juliana Martins
E-mail: juliana.martins@tigerdirect.com

 

back to top


How to Access NYU Pricing of Dell Computers Via the Web

NYU Purchasing made a short PDF about how to log onto Dell's NYU website to get NYU pricing. Please note that the Shop staff should be assisting you with PC hardware purchases and will help you generate a Dell price quote. Several Dell models are very poor choices, and the peripheral choices can have arcane compatibility issues.

http://www.nyu.edu/purchasing.services/pdf/private/DellEquote.pdf

Dell Corporate Sales phone number (less waiting) at (800) 274-7799

back to top


How To Enable/Disable NYUHome's SPAM Filtering Feature

On August 20th 2004, ITS decided to activate automatic "light" spam filtering on all NYU HOME accounts without sufficiently announcing this change. This is potentially a serious problem, especially if you receive email in non-English languages.

2 faculty were dismayed that their outgoing emails landed in the NYU recipient's SPAM folders, so the emails were never seen by the recipients.

If you don't ever want to miss an important incoming email, then you should disable spam filtering of your NYU HOME email account. It is easy to do, see below.

Alternatively, one can enable the filter and then everyday go to your SPAM folder and look in there but, then, what exactly is the point of the SPAM folder if you have to sift thru it everyday?

I don't see any benefit at all in spam filtering, though it is your choice to enable it or not. Be aware of the SPAM folder if you enable it.

ITS' pages about spam filtering:

https://home.nyu.edu/help/mail/spamfilter
https://home.nyu.edu/help/mail/spamfaq

To disable automatic spam filtering on your NYU HOME account:

Point a web browser to home.nyu.edu and log in. Look on the upper-right hand corner on the web page for "preferences" One option is spam filtering. Disable it

back to top


"Ever since the Shop Staff set up my Laptop for Meyer Bldg Networking, it doesn't work on my Home Network..."

In Windows XP, the sole setting that is relevant to your home networking for normal operation is that your laptop MUST be set to "obtain IP address automatically" in the TCP/IP networking control panel. Check that setting by double clicking on TCP/IP in the networking control panel. No other setting should significantly matter.

Didn't work? You should cycle the power on BOTH your mini-router and cable modem (or DSL router), wait 2 minutes, and then try the above again. Note that Shop staff will not extensively troubleshoot your home networking problems. The above solution is easy for any user to do. Many users set up their home-networking poorly and it is not our responsibility to fix your home networking. Per policy, you should contact your broadband ISP and/or your router manufacturer's website about home networking issues.

One handy XP command to troubleshoot networking:

At any time, you can force your laptop to get a new IP address while on your home network. You should try this if all else fails.

1. when you go home, shut the laptop down -- do not leave it in sleep or hibernate mode

2. before you turn it on, insert the net cable -- REPEAT, insert the net cable

Login as normal: Execute this command to force your netcard to get a new IP address

go to start
go to run
type cmd
click OK
a black window appears, type: ipconfig /renew

Still didn't work? Try this:

Add these entries to your DNS list (in TCP/IP control panel): these are NYU DNS entries but should work anywhere in the world and you can use them with any internet service provider that uses standard internet configurations.

DNS entries:
128.122.253.92
128.122.253.37

"None of that worked"

Look at the How-To about spyware and adware; some internet-related software that you downloaded could be mucking up your laptop's network config.

Or, something is wrong with your laptop netcard, the net cables, or your home network configuration. Consult your Broadband ISP or the website of whomever makes your mini-router.

back to top


"Do I Have a Virus??" (Windows)

The simplest way to find out if you have a virus is to look at the Virus History Log in Norton AntiVirus:

Open Norton AntiVirus by double-clicking on the gold shield at the bottom right corner of your screen, or by going to Programs, Symantec (Norton) Antivirus. Go to the menu option HISTORY, then open the VIRUS HISTORY log.

The log includes the dates and names of infections. If the virus was "quarantined," that is good news, but if you see a long list of quarantines including ones of recent date, that means there is something executing on your PC that keeps trying to infect your PC. Email the Shop if you want more info.


NOTE:
The history log is not a fool-proof confirmation; some worms "break" Norton so that they can run undetected. Even worms that intentionally break NortonAV after infection are often logged here on the date when the worm first appeared.

Always make sure the Gold Shield icon is running in the lower-right hand corner of the desktop at all times. NortonAV is your only real protection from viruses and worms. Norton does a great job as long as it is running automatically.

back to top


Windows XP, Service Pack 2, and Retrospect Backup software

Using Retrospect and SP2 on a Client Computer:
To ensure that your Retrospect client computers can be backed up with SP2 installed, perform the following procedure on each client computer.

To adjust settings on a Retrospect client computer:
1. After the SP2 installation is complete, click Start on the taskbar, and then click Control Panel.
2. Click Security Center.
3. Click Windows Firewall. By default, the On (Recommended) radio button is selected. If not, please select this button.
4. Click the Exceptions tab.
5. Click Add Port.
6. In the Name field, type: Retrospect (TCP)
7. In the Port Number field, type: 497
8. Select the TCP radio button if it is not already selected by default.
9. Click OK.
Retrospect (TCP) should appear with a check box selected in the Program and Services window.
10. Select Add Port.
11. In the Name field, type: Retrospect (UDP)
12. In the Port Number field, type: 497
13. Select the UDP radio button.
14. Click OK.


Retrospect (UDP) should appear with a check box selected in the Program and Services window.

back to top


Is NYUHome Mail Secure?

When you log into home.nyu.edu or homemail.nyu.edu with a web browser, none of the pages are encrypted except the first login page. This means your emails are entirely readable as text if a hacker was to sniff and capture data via the internet.

Thankfully there is a very simple way to encrypt the entire email session.

when you use a web browser, type this:

https://homemail.nyu.edu/

Everything works and looks exactly the same, but you'll see that the entire session is using SSL encryption.

The "s" in the link forces the mail server to use SSL. Don't use home.nyu.edu to login since encryption only works with the above link. SSL is very standard and should work in all recent version browser software.

If you are using I.E. browser, look for yellow padlock symbol in the lower right hand corner to confirm SSL encryption.

Note that most modern email clients also support SSL (secure sockets layer), if you want to secure your mail client.

back to top


Alternative Web-Browsers for Windows XP

There has been a lot of media attention (and media hype) regarding Firefox web browser as an alternative to Internet Explorer for Windows XP. We also see that users are installing it onto their windows computers. The short version is "definitely wait until version 1.1 comes out."

Why?

1. There is an independent auto-update engine in FireFox that will install patches to FireFox, but it has yet to be activated even once. If hundreds of PC's in Psych and CNS have Firefox and the auto-engine update fails, this creates a substantial security problem where Shop staff will have to install patches manually in order to protect your computers. Internet Explorer auto-patches every evening and that engine is proven to work reliably. We also have no idea which computers have FireFox installed. Users are usually not aware of the importance of patches to keep computers safe. For all of these reasons, the Shop will not support FireFox until it is at least version 1.1.

2. Recent estimates are that FireFox is installed in 8% of Windows XP computers in the USA. Hackers will become more interested in finding vulnerabilities and exploits to FireFox as market penetration increases.
I wouldn't be using FireFox with credit cards while it still stands at version 1.0.

3. Media hype that Firefox is "safer" than IE is profoundly misguided.
There simply haven't been a substantial interest in creating hacks against it yet.

At this time, FireFox is not a wise idea for our un-firewalled network of over 650 Windows computers. When this software proves itself in six months, we may install it on all new WinXP computers.

"What about Netscape?"
After AOL bought Netscape several years ago, installing new versions of Netscape altered normal computer operation. The Netscape auto-update engine was unwieldy, so users never used it. The later versions of Netscape, including the current version, are quite horrible with the "ad ware" software it installs. Really, avoid Netscape at all costs. The Shop no longer supports any version of Netscape since it offers nothing better for the user.

back to top


Where is my Mozilla Mail client or Thunderbird user-profile located on my computer? Where are my mail folders stored on my computer?

Windows:

On Windows the profile data is per default located in:

bootdrive\documents and settings\[windows login name]\APPDATA\Mozilla(or Thunderbird)\Profiles\[random string].slt\

Mac OS X:

~/Library/Mozilla(or Thunderbird)/Profiles/[profile name]/[random string].slt

NOTES: There will be a few sub-folders representing your IMAP folders and your local mail folders. The files that AREN'T ending in .MSF extensions are pure text files which are caches of your mail folders. If you enabled the "offline folders" option, you will be able to open your IMAP folders and files as pure text files. You will always be able to open your local (non IMAP) mail folders as text files. IMAP refers to those mail folders you see on your NYU HOME account when you login via a web browser. Those folders ALWAYS remain on NYU HOME's mail servers until you manually delete or move them.

back to top

 


What to know BEFORE you buy a Color-Inkjet Printer

1. The ink is surprisingly expensive and it dries out if not used.
2. You get a much better and higher resolution print-out if you use the more expensive paper designed for ink-jet printers. Almost no one ever buys this paper.
3. Printing b&w documents on a color inkjet is pretty expensive on a cost per page basis, versus a laser monochrome printer
4. There is shockingly little difference between a $120 color inkjet and a $400 inkjet. They will have the exact same output resolution. The technology for this type of printing is very standard now, so there's little point in spending a lot of money on the inkjet printer itself.
5. ALL modern printers use USB ports to print, so if you want to hook this up to a PC (or a modern Mac), you should confirm your computer has USB ports. USB2.0 ports will print much faster than USB1.1 ports.

back to top


Endnote and Microsoft Word Bug Fix

Question: Since installing EndNote 6, Microsoft Word XP (2002) or Word 2003 is running slowly or freezing periodically. Word is reporting error messages such as "Unknown Error 0x800A1007" or messages which indicate there are too many edits or not enough resources/memory. Memory usage gradually increases and the CPU usage climbs to 100% and stays there. I cannot save my document and I have to use the Task Manager in order to quit Word.

Answer: There is a known problem that occurs with Word XP and 2003 where the use of certain smart tags in Word triggers a memory leak. Note that this problem was fixed in EndNote 7, but here are the steps to resolve the problem in EndNote 6:

  1. In Word go to Tools / Options / File Locations, select Startup, and click the Modify button. Note the path to the Word Startup folder as indicated under the 'Look In' dropdown box at the top of the window.

  2. Now cancel out of this window, close Word (and Outlook, if running), and navigate to this folder through Windows Explorer or My Computer. (Note: If you cannot find the specified folder, your windows preferences may be set to hide the folder. In Windows Explorer go to Tools / Folder Options / View tab and make sure that "Show hidden files or folders" is selected). You should see at least two files in this folder: EN6Cwyw.WordXP.wll & EN6CWYW.dot. If you do not see the .wll and .dot file extensions, go to the Tools menu and select Folder Options / View tab. Uncheck the box that reads "Hide file extensions for known file types" and click OK. Remove EN6Cwyw.WordXP.wll and place it in the Recycle Bin.

  3. Now navigate to the EndNote 6 program folder (typically C:\Program Files\EndNote) and locate a file called EN6Cwyw.wll. Make a copy of this file and paste it into the Word Startup folder.

  4. Now start Word again and you should be able to insert citations and work with EndNote 6 and Word XP or 2003 without it slowing down, freezing, or crashing.

back to top


How should I run XWindows securely on OS X/ UNIX / Linux ?

To easily and securely run X applications on a remote machine,
simply let ssh do all the work.

    ssh -X remotehost  or  ssh remotehost
    (The latter depends on some settings on the remotehost.)

That is it.  You can now run X applications on remotehost
with the display going to your local console.

On the remotehost, the DISPLAY will automatically be set to
something like  localhost:10.0.  This is the proper DISPLAY
value for X1

1 forwarding.

NOTES:
Do *not* ever use  xhost +  to open your X window server.

  o  Make sure on the remote machine you are not cleverly
     overriding the above default DISPLAY setting.

I am sending this reminder because one of our Exceed X window server
was "cracked" but it can happen on any machine running an insecure
X window server.

How should I run XWindows securely in Windows ?

Securing Exceed - Hummingbird
==============================
The security of Hummingbird Exceed allows connections from any location,
through the local loopback network or any internet connection. The goal is
to only allow connection from the local loopback network. By doing this,
only programs running on the PC computer itself will be allowed access to
the X-windows server. It is assumed that if a connection is coming from
the PC, then it's more likely that it's a legitimate connection.
Hummingbird Exceed will need to be told to disallow all connections
except those coming from the local loopback network. To make the changes,
perform the following actions:

Start the configuration program by clicking on
Start -> Programs -> Hummingbird Connectivity V7.0 -> Exceed -> Xconfig.
If you set a password during the installation, enter the password and
click on OK.
In the configuration window, double-click on the Security icon or
select from the menu Settings -> Security....
In the security settings window, click on Host Access Control List:
Enabled (no host access), then click on OK.
Close the configuration program by click the close button.

SSHWinClient - SSH Communications Security Corp.
================================================
Start the secure telnet window by clicking on
Start -> Programs -> SSH Secure Shell -> Secure Shell Client.
Configure X11 Forwarding and SSH2 protocol.
Click on Settings or select from the menu Edit -> Settings....
Click on Tunneling and put a checkmark next to Tunnel X11 connections
in the Tunneling window.
In the Agent Forwarding section of the Tunneling window, put a
checkmark next to Enable for SSH2 Connections.
Click on OK.
Click on Save or select from the menu File -> Save Settings.

back to top


How to reset Windows Update if WU doesn't work

Method 1 – Rename the Windows Update folder

========================

Please try to rename the following file from Catroot2 to oldCatroot2 which located in “C:\Windows\System32\”.  Then, you can try to testing the Windows Update.


Method 2: Delete the contents of the DataStore folder

========================

1. Click Start.

2. Choose Run.

3. In the Run box, type %windir%\SoftwareDistribution

4. Click OK.

5. Open the DataStore folder.

6. Delete all contents of the DataStore folder.

7. Close the window.


Method 3: Clean up Windows Update temporary folder

================================

One possible cause is that the temporary folder for Windows Update is containing corrupted files. Please erase all the files there to get the system clean.


1. Click Start, Run, type cmd and press Enter. Please run the following command in the opened window.

Net stop WuAuServ

2. Click Start, Run, type %windir% and press Enter.

3. In the opened folder, rename the folder SoftwareDistribution to Sdold.

4. Click Start, Run, type cmd and press Enter. Please run the following command in the opened window.

Net start WuAuServ

Method 4 – Re-register the Windows Update client
========================

1. Quit all programs that are running.
2. Click Start, and then click Run.
3. Type “regsvr32 wuapi.dll” (without the quotation marks), and then click OK.
4. When you receive the “DllRegisterServer in urlmon.dll succeeded” message, click OK.

If this does not resolve the problem, repeat inputting the following commands and click OK after each command.

regsvr32 softpub.dll

regsvr32 wintrust.dll

regsvr32 initpki.dll

regsvr32 dssenh.dll

regsvr32 rsaenh.dll

regsvr32 gpkcsp.dll

regsvr32 sccbase.dll

regsvr32 slbcsp.dll

regsvr32 cryptdlg.dll

regsvr32 Urlmon.dll

regsvr32 Shdocvw.dll

regsvr32 Msjava.dll

regsvr32 Actxprxy.dll

regsvr32 Oleaut32.dll

regsvr32 Mshtml.dll

regsvr32 msxml.dll

regsvr32 msxml2.dll

regsvr32 msxml3.dll

regsvr32 Browseui.dll

regsvr32 shell32.dll

regsvr32 wuaueng.dll

regsvr32 wuaueng1.dll

regsvr32 wucltui.dll

regsvr32 wups.dll

regsvr32 wuweb.dll

regsvr32 jscript.dll

regsvr32 atl.dll

regsvr32 Mssip32.dll

back to top


How to Investigate and Find Worms, Viruses, Trojans in Windows

First check symantec virus history.  anything in the log from the last couple of months is an obvious warning sign that there's an active worm.  If the worm was quarantined there's a chance the PC is OK. But if you see constant quarantining, then you know the worm is active. 
As IT staff, walking away from the PC at this point is not an acceptable level of investigation.  if you aren’t sure there's a worm, you should backup the user's files
and format the PC.  Anything less than that puts the whole LAN at risk.  Strong words but they are needed when it comes to our responsibility for network
security. 

What else to do when investigating:

Check what apps are installed in program files -- sort by date. Google app names and folder names you don’t know.  Google is an excellent resource for this.

Sort c drive by date -- any apps you don’t know? Look in the folder.  What's in there?  Google the app and folder names to find out more.

The active ports utility (look in worm investigation in installers folder) will let you see what apps are opening network ports.  VERY handy. Check the SP2 firewall!  if ports have been opened, Google what you don’t know. Close all ports other than the usual ones. Determine if the user really needs those ports open.

If the user has P2P or other file sharing apps, talk to the user about our policy against them. They are an obvious security risk.  These apps must be uninstalled or the user will have to go on wireless.  No exceptions to this policy.

Check usernames: are any suspicious?  Confirm all have passwords.  Some MS developer apps install additional usernames: Google the usernames to clarify what is legitimate. 
look at msconfig: Yup, Google the file names you don’t know.  Most worms don’t hide in startup anymore but that doesn’t mean you won’t find a worm in there.  The system info utility (look in worm investigation folder on the installers drive) will let you see current
loaded DLL and the app name that is loading that DLL.  This is a very handy way to look for stealthy worm apps. Google dll's that look suspicious (i.e. are in file
paths that are not typical).

back to top