<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>New Technologies System Virtualisation &#187; windows</title>
	<atom:link href="http://www.ntsysv.com/index.php/category/windows/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ntsysv.com</link>
	<description>La théorie rejoint la pratique</description>
	<lastBuildDate>Fri, 02 Dec 2011 13:33:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Réactions Européennes aux Failles d&#8217;Internet Explorer</title>
		<link>http://www.ntsysv.com/index.php/reactions-europeennes-aux-failles-dinternet-explorer</link>
		<comments>http://www.ntsysv.com/index.php/reactions-europeennes-aux-failles-dinternet-explorer#comments</comments>
		<pubDate>Mon, 18 Jan 2010 11:18:57 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Internet explorer]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=418</guid>
		<description><![CDATA[Suite à la publication de son bulletin de sécurité le Jeudi 14 à propos de son navigateur historique Internet Explorer, Microsoft se retrouve face aux réactions de l&#8217;Office fédéral allemand pour la sécurité de l&#8217;information (BSI) et du Certa (Centre d&#8217;expertise de réponse et de traitement des attaques informatiques). Ces derniers font appels à la [...]]]></description>
			<content:encoded><![CDATA[<p>Suite à la publication de son bulletin de sécurité le Jeudi 14 à propos de son navigateur historique Internet Explorer, Microsoft se retrouve face aux réactions de l&#8217;Office fédéral allemand pour la sécurité de l&#8217;information (BSI) et du Certa (Centre d&#8217;expertise de réponse et de traitement des attaques informatiques). Ces derniers font appels à la vigilence des utilisateurs lors de l&#8217;utilisation d&#8217;IE.<span id="more-418"></span><br />
Le BSI a demandé aux utilisateurs de césser l&#8217;utilisation d&#8217;Internet Explorer (versions 6 et +) et d&#8217;utiliser un navigateur alternatif, et par alternatif je vois surtout Firefox qui détient 25% de taux d&#8217;utilisation d&#8217;après les dernières études réalisées, après viendront Google Chrome, Safari&#8230;etc.</p>
<p>Parallèlement, le BSI et le CERTA ont demandé à Microsoft de corriger ces faillent de sécurité qui pourraient avoir de grands impacts sur le grand plublique; les risques d&#8217;impacts sur les achats en ligne riques d&#8217;être gros, et d&#8217;apporter plus à la &#8220;crise&#8221; qu&#8217;aux comptes des commerçants.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-7102278170967072";
google_ad_slot = "2452760370";
google_ad_width = 300;
google_ad_height = 250;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
<br />
Microsoft ont fourni une première réponse et contournement qui limiterait les risques mais ne les annule pas : mettre le niveau de sécurité sur le niveau &#8220;élevé&#8221; pourrait réduire les risques dûs à l&#8217;utilisation des contrôles ActiveX et Javascript. Il va sans dire qu&#8217;en désactivant ces deux fonctionnalités il devient difficile voire même impossible de parcourir quelques sites Internet.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/reactions-europeennes-aux-failles-dinternet-explorer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Scripting : Deux Utilitaires : WUInstall Et Export</title>
		<link>http://www.ntsysv.com/index.php/windows-scripting-deux-utilitaires-wuinstall-et-export</link>
		<comments>http://www.ntsysv.com/index.php/windows-scripting-deux-utilitaires-wuinstall-et-export#comments</comments>
		<pubDate>Sun, 15 Mar 2009 17:30:39 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[scripting]]></category>
		<category><![CDATA[batch]]></category>
		<category><![CDATA[command line]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows update]]></category>
		<category><![CDATA[wsus]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=374</guid>
		<description><![CDATA[Deux Utilitaires pour les mordus des scripts sous Windows : WuInstall et Export.Le Premier est destiné à installer les mises à jour Windows en utilisant des scripts. Le second, bien pratique pour les fichiers batch, sert à exporter le résultat d&#8217;une commande vers une variable d&#8217;environnement. Ces deux utilitaires, quoique n&#8217;ayant pas un lien directe [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Deux Utilitaires pour les mordus des <strong>scripts </strong>sous <strong>Windows</strong> : <strong>WuInstall </strong>et <strong>Export</strong>.Le Premier est destiné à <strong>installer les mises à jour Windows</strong> en utilisant des scripts. Le second, bien pratique pour les fichiers batch, sert à exporter le résultat d&#8217;une commande<strong> vers une variable d&#8217;environnement</strong>.<span id="more-374"></span></p>
<p style="text-align: justify;">Ces deux utilitaires, quoique n&#8217;ayant pas un lien directe d&#8217;utilisation, ont été développés par <a title="hs2n Xeon Website" href="http://www.xeox.com" target="_blank">Hs2n </a>et fournis gratuitement sur le site dans la partie outils. Ci-dessous un passage en revu de leur utilisation.</p>
<h3 style="text-align: justify;">WuInstall</h3>
<p style="text-align: justify;">WuInstall est un outil en ligne de commande pour Windows, qui vous permet d&#8217;installer les mises à jour Windows sur un ou plusieurs postes de travail d&#8217;une manière contrôlée en utilisant un script batch ou VBS au lieu d&#8217;utiliser la fonctionnalité de mise à jour automatique intégrée de Windows.</p>
<p style="text-align: justify;">En effet, il est quelques fois difficile de passer automatiquement les mises à jour quand un applicatif risque de ne plus fonctionner correctement, surtout ceux basés sur une version spéciale d&#8217;un environnement donné (exemple : la CLR .Net)</p>
<p>Ceci dit, WuInstall utilise l&#8217;API standard de Windows Update pour chercher les mises à jour disponibles, que ce soit sur le site publique Microsoft Update, ou bien un serveur WSUS interne à l&#8217;entreprise. Si des mises à jour sont dispobiles, l&#8217;utilitaire peut bien les installer.</p>
<h3>Export</h3>
<p style="text-align: justify;">Comme il est décrit dans l&#8217;introduction, l&#8217;outil export permet d&#8217;affecter le résultat de n&#8217;importe quelle commande en ligne de commande à une variable qu&#8217;elle soit d&#8217;environnement ou de script. Cette fonctionnalité est malheureusement absente en standard sous Windows. Petit exemple : vous voulez créer un fichier avec la date d&#8217;aujourd&#8217;hui dans un fichier batch: j&#8217;ai beau chercher mais il n&#8217;y a pas de méthode directe de le faire; cet outil vient à la rescousse comme le montre la figure ci-dessous prise directement sur le site de l&#8217;éditeur.</p>
<div id="attachment_376" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.ntsysv.com/wp-content/uploads/2009/03/export-example.jpg"><img class="size-medium wp-image-376" title="export-example" src="http://www.ntsysv.com/wp-content/uploads/2009/03/export-example-300x156.jpg" alt="Exemple d'utilisation de l'outil Export" width="300" height="156" /></a><p class="wp-caption-text">Exemple d&#39;utilisation de l&#39;outil Export</p></div>
<p>A noter que cet outil vient en deux versions : pour les versions 32 et 64 bits de Windows.</p>
<p>Voilà, j&#8217;espère que vous avez trouvé ces outils pratiques, Bonne lecture sur Ntsysv.com!</p>
<p style="text-align: justify;">
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/windows-scripting-deux-utilitaires-wuinstall-et-export/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Introduction To DNSSEC : DNS Security Extensions</title>
		<link>http://www.ntsysv.com/index.php/introduction-to-dnssec-dns-security-extensions</link>
		<comments>http://www.ntsysv.com/index.php/introduction-to-dnssec-dns-security-extensions#comments</comments>
		<pubDate>Sun, 01 Mar 2009 00:38:40 +0000</pubDate>
		<dc:creator>Aicha</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[DNSSEC]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=345</guid>
		<description><![CDATA[DNSSEC (short for DNS Security Extensions) adds security to the Domain Name System (DNS). In fact, DNSSEC was designed to protect the Internet from certain attacks, such as DNS cache poisoning. DNSSEC is a specification of an extension to the DNS through the definition of additional DNS Resource Records that can be used by DNS [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><strong>DNSSEC</strong> (short for <strong>DNS Security Extensions</strong>) adds security to the <strong>Domain Name System</strong> (DNS). In fact, <strong>DNSSEC</strong> was designed to protect the Internet from certain attacks, such as <strong>DNS cache poisoning</strong>. DNSSEC is a specification of an extension to the DNS through the definition of additional DNS Resource Records that can be used by DNS clients to validate the authenticity of a DNS response, the data integrity of the DNS response, and where the response indicates no such domain or resource type exists, this negative information can also be authenticated.</p>
<p style="text-align: justify;"><span id="more-345"></span></p>
<p style="text-align: justify;"><strong>DNSSEC </strong>provides:</p>
<p><!-- adman --></p>
<ol>
<li>Origin authentication of DNS data,</li>
<li>Data integrity</li>
<li>Authenticated denial of existence.</li>
</ol>
<p>These functions are based on asymmetric cryptography system</p>
<p style="text-align: justify;">In other words, if an attacker attempts to create a DNS response that has been altered from the original authentic response in some fashion, and the attacker then attempts to pass the response off as an authentic response, then a DNSSEC-aware DNS client should be able to detect the fact that the response has been altered and that the response does not correspond to the authoritative DNS information for that zone. In other words, DNSSEC is intended to protect DNS clients from forged DNS data. This protection does not eliminate the potential to inject false data into a DNS resolution transaction, but it adds additional information to DNS responses to allow a client to check that the response is authentic and complete.</p>
<p style="text-align: justify;">As I said before, dnssec is based on cryptography, especially Public key cryptography which relies on a public and private key pair</p>
<p style="text-align: justify;">Two <em>types </em>of keys are identified for use in zone signing operations. The first type is called</p>
<p style="text-align: justify;">A <em>Zone Signing Key (ZSK)</em> and the second type are called a <em>Key Signing Key (KSK)</em>. The ZSK Is used to sign the RRsets <em>within </em>the zone, and this includes signing the ZSK itself, the KSK is used to sign root of the Zone, which includes the ZSK and the KSK and may also be used outside the zone either as the trusted anchor in a security-aware server or as part of the chain of trust by a parent Name Server.</p>
<p style="text-align: justify;">DNSsec mechanisms require also changes to the <a href="http://www.bind9.net/rfc">DNS protocol</a>. DNSSEC adds four new resource record types: Resource Record Signature (RRSIG), DNS Public Key (DNSKEY), Delegation Signer (DS), and Next Secure (NSEC). These new RRs are described in detail in <a href="http://www.rfc-archive.org/getrfc.php?rfc=4034" target="rfc4034">RFC 4034</a></p>
<h2><strong>What are the uses of each resource record? </strong></h2>
<p style="text-align: justify;">DNSSEC uses public key cryptography to sign and authenticate DNS Resource record sets (RRsets).</p>
<p><!-- adman --></p>
<p style="text-align: justify;">The public keys are stored in DNSKEY Resource records, Digital signatures are stored in RRSIG resource records while, The NSEC resource record lists two separate things: the next owner name (in the canonical ordering of the zone) that contains Authoritative data or a delegation point NS RRset, and the set of RRTypes present at the NSEC RR&#8217;s owner name but for A DS RR it refers to a DNSKEY RR by Storing the key tag, algorithm number, and a digest of the DNSKEY RR, The DS RR appears only On the upper (parental) side of a delegation</p>
<h2><strong>Deploying Dnssec </strong></h2>
<p><strong> </strong></p>
<ol type="1">
<li>Enable dnssec in authorative  and recursive servers : Means that your dns will support dnssec functionality, so you have to add the following line in named.conf file (named configuration file):</li>
<blockquote><p>Options {Dnssec-enable    yes; };</p></blockquote>
<li>Generate zsk and ksk for each zone :
<ul> i/ Create zsk key:</ul>
<blockquote><p>Dnssec-keygen -a rsasha1 -b 1024 -n zone ecole.com</p></blockquote>
<p style="padding-left: 30px;">This command will generate 2 files with the following extensions:</p>
<p style="padding-left: 60px;"><strong>.key</strong> is public portion of the key</p>
<p style="padding-left: 60px;"><strong>.private</strong> is private portion of the key</p>
<ul> ii/ Create the ksk key:</ul>
<blockquote><p>dnssec-keygen -a rsasha1 -b 1400 -f KSK -n zone ecole.com</p></blockquote>
<p><strong> </strong></li>
<li>Include keys in the zone file : we have to add the public portions to the zone file either but just including using this syntax :</li>
<blockquote><p>$INCLUDE keys/Kecole.com.+005+12513.key; KSK</p>
<p>$INCLUDE keys/Kecole.com.+005+03977.key; ZSK</p></blockquote>
<p style="padding-left: 30px;">Or using command line mode :</p>
<blockquote><p>Cat keys/Kecole.com.+005+12513.key &gt;&gt; ecole.db</p>
<p>cat keys/Kecole.com.+005+03977.key &gt;&gt; ecole.db</p></blockquote>
<li> Sign the zone using the following command:</li>
<blockquote><p><strong> </strong>Dnssec-signzone -o ecole.com -t -k Kecole.com. +005+12513 ecole.db Kecole.com.+005+03977</p></blockquote>
<li>Update named.conf file :</li>
<p>Replace :</p>
<p><strong> </strong></p>
<blockquote><p>zone &#8220;ecole.com &#8221; {</p>
<p>file &#8220;ecole .db &#8220;;</p>
<p>};</p></blockquote>
<p>With:</p>
<blockquote><p>zone &#8220;ecole.com &#8221; {</p>
<p>file &#8220;ecole.db.signed &#8220;;</p>
<p>};</p></blockquote>
<li>Creating a secure delegation :</li>
<p style="padding-left: 30px; text-align: justify;">The process for signing a sub domain is essentially similar to that defined for signing a zone with one single difference; A Delegated Signer RR can be added to the ecole.com zone file to create secure delegation.</p>
<p style="padding-left: 30px; text-align: justify;">In fact we have to follow the same steps described before but while singing the zone we have to use the command:</p>
<blockquote><p>dnssec-signzone -o etudiant.ecole.com -t -g -k Ketudiant.ecole.com.+005+64536</p>
<p>etudiant.db Ketudiant.ecole.com.+005+48560</p></blockquote>
<p><strong> </strong></p>
<p style="padding-left: 30px; text-align: justify;">The -g argument is used to generate two special files called dsset-etudiant.ecole.com. (Containing the DS RR for the parent) and keyset-etudiant.ecole.com. (Containing a copy of the public Key DNSKEY RR of the KSK).</p>
</ol>
<p style="text-align: justify;">When the parent administrator receives the dsset-etudiant.ecole.com. and, optionally, the keyset-etudiant.ecole.com. files, they are placed in the same directory where the ecole.com zone is signed. The dsset-etudiant.ecole.com. File is included in the original ecole.com zone. Re-sign the zone by executing the dnssec-signzone command exactly as before</p>
<p style="text-align: justify;">The only thing that has changed is the additional Ds reecords in the new zone file, so that the sub domain zone gets its authentification through the delegation point in ecole.com in the parent zone</p>
<p style="text-align: justify;">You may understand more the use of the Ds record in my next article which will be about DLV System and how to create a trusted anchor within a chain of trust</p>
<p style="text-align: justify;">I hope it was useful and I want to thankyou for your time.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/introduction-to-dnssec-dns-security-extensions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Optimize Disk Usage And Increase Windows Speed</title>
		<link>http://www.ntsysv.com/index.php/optimize-disk-usage-and-increase-windows-speed</link>
		<comments>http://www.ntsysv.com/index.php/optimize-disk-usage-and-increase-windows-speed#comments</comments>
		<pubDate>Wed, 18 Feb 2009 11:40:51 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Non classé]]></category>
		<category><![CDATA[optimization]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=331</guid>
		<description><![CDATA[Disk and Disk Cache are heavily used in all Operating Systems, and specially Windows. There are some easy things to keep in mind and do to Optimize Disk Usage and thus Increase Windows Speed. I will try to give some ideas to achieve this goal, knowing that most people prefer to buy a software to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Disk and Disk Cache are heavily used in all Operating Systems, and specially Windows. There are some easy things to keep in mind and do to Optimize Disk Usage and thus Increase Windows Speed. I will try to give some ideas to achieve this goal, knowing that most people prefer to buy a software to do that for them. In my opinion, this is useful for Registry for example, RAM maybe; but for Disk you can do it all by your self.</p>
<p><span id="more-331"></span></p>
<p style="text-align: justify;">As discussed in the <a title="Have a look in our Forum" href="http://www.ntsysv.com/index.php/forum" target="_blank">Forum</a> ( in a <a title="Forum post about Disk Optimization" href="http://www.ntsysv.com/index.php/forum/windows/administration-a-distance" target="_blank">post</a> about Remote Access), there&#8217;s some actions we can take (I can not list all of them) and that help speeding up Windows.</p>
<h2>Physical Disk Speed</h2>
<p style="text-align: justify;">When choosing a hard disk for your computer or laptop, think in a long term fashion: you may keep some money in your pocket but you will have to get them out sooner than you think when your slow cheap new disk start struggling under whatever software you use. So spend more money and get a good disk for once.</p>
<h2>Disk And File Fragmentation</h2>
<p style="text-align: justify;">Every time you delete or move a huge number of files or big files (an old movie or game) think about Defragmentation. Windows Built-in Disk Defragmentation Tool is not there by chance, it is enough to use with normal files; I say normal files because the tool cannot defrag paging file for example or some system files. The tool is available under  :</p>
<blockquote><p>All Programs/Accessories/System tools</p></blockquote>
<p style="text-align: justify;">and is called <strong>Disk Defragmenter</strong>.</p>
<p style="text-align: justify;">A nice method exists to Defragment disks in Command Line mode, using a batch file for example. The command defrag is here to help scripting all drives defragmentation while sleeping or taking a coffee. The help section of this command is clear and command usage is straightforward as discribed bellow :</p>
<blockquote><p>C:\&gt;defrag /?<br />
Usage:<br />
defrag &lt;volume&gt; [-a] [-f] [-v] [-?]<br />
volume  drive letter or mount point (d: or d:\vol\mountpoint)<br />
-a      Analyze only<br />
-f      Force defragmentation even if free space is low<br />
-v      Verbose output<br />
-?      Display this help text</p></blockquote>
<p style="text-align: justify;">all you have to do is to replace &lt;volume&gt; by drive name (eg. C:, D:&#8230;).</p>
<p style="text-align: justify;">For System and special files, there is many tools available to buy on the net.</p>
<h2>Paging File aka Pagefile.sys</h2>
<p style="text-align: justify;">Paging file (or swap file) helps the Operating System to run more programs than what would only physical RAM do. It is a partition of the Disk (generally for Unix Like systems), or a file constructed in a particular way (possible for both Windows and Linux). All known Operating System need a paging space; an exception are the &#8220;Live&#8221; Systems, that run in available RAM and may not need to swap.</p>
<p style="text-align: justify;">For Windows, the size of the Pagefile.sys file is automatically set and the default location is the system drive. Here, at Windows Setup time or after, it is recommended to create a dedicated drive to host the paging file, so that the heavy I/O load does not affect neither Windows itself nor any running application. For the size of the Pagefile.sys, it is linked to physical memory size and in general 1,5 to 2 times bigger. An easy way to decide is by checking the recommended size calculated by Windows as described in the following animation :</p>

<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
			id="fm_ckeck-and-set-pagefile-size_1893634933"
			class="flashmovie"
			width="400"
			height="300">
	<param name="movie" value="http://www.ntsysv.com/wp-content/uploads/2009/02/ckeck-and-set-pagefile-size.swf" />
	<!--[if !IE]>-->
	<object	type="application/x-shockwave-flash"
			data="http://www.ntsysv.com/wp-content/uploads/2009/02/ckeck-and-set-pagefile-size.swf"
			name="fm_ckeck-and-set-pagefile-size_1893634933"
			width="400"
			height="300">
	<!--<![endif]-->
		
<p>You may have noticed that you can have more than one paging file.</p>
<p>You&#8217;ll have to reboot after changing paging file size or location.</p>
<h2>Software&#8217;s Setup Folder</h2>
<p>You should never install softwares using Disk I/O heavily on the same drive as Windows. For example, if you need to install an SGBD (Oracle, SQL server,MySql&#8230;etc), do not install it in system drive, performances will be impacted on both Windows and Software sides.</p>
<p>Same thing if we talk about any software which uses disk to cache temporary files to speedup its utilization. As example, Photoshop uses caching to make things go fast, and fortunately, it offers the posibility to define cache folder location.</p>
<h2>Windows System Memory Locks</h2>
<p>A great TIP by user Aicha in the same post in the forum talked about sizing Windows System Cache depending on physical memory size. I didn&#8217;t give it a try, but comments are open to you for feedbacks.</p>
<p>The configuration involves registry modification so please make sure you set configuration correctly, I&#8217;ll recommend making a backup before going any further.</p>
<p>So, here is the receip :</p>
<ol>
<blockquote>
<li>open Registry Editor by using &#8220;regedit&#8221; command</li>
<li>Browse to key : <strong>HKEY_LOCAL_MACHINE</strong>\ <strong>SYSTEM</strong>\ <strong>CurrentControlSet</strong>\ <strong>Control</strong>\ <strong>Session Manager</strong>\<strong>Memory Management</strong></li>
<li>Edit (or create) the DWORD Value <strong>IoPageLockLimit</strong></li>
<li>Enter the Decimal value <strong>983040</strong></li>
</blockquote>
</ol>
<p>If you have 2Gb of physical memory you may double this size. In fact, there&#8217;s rules to decide what to put as value : please refer to the following Microsoft Technet <a title="IoPageLockLimit Technet reference" href="http://technet.microsoft.com/en-us/library/cc959494.aspx" target="_blank">article </a>for more details.</p>
<p>You may need to reboot.</p>
<p>Hope you found this interesting and I&#8217;d like to thank you for your time.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/optimize-disk-usage-and-increase-windows-speed/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Your Windows System</title>
		<link>http://www.ntsysv.com/index.php/securing-your-windows-system</link>
		<comments>http://www.ntsysv.com/index.php/securing-your-windows-system#comments</comments>
		<pubDate>Thu, 05 Feb 2009 17:25:57 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[office]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=325</guid>
		<description><![CDATA[Today, increasingly people are using their computers for everything from communication to online banking and investing to shopping.  As we do these things on a more regular basis, we open ourselves up to potential attackers and crackers.  While some may be looking to phish your personal information and identity for resale, others simply just want [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Today, increasingly people are using their computers for everything from <strong>communication </strong>to <strong>online banking </strong>and<strong> investing</strong> to <strong>shopping</strong>.  As we do these things on a more regular basis, we open ourselves up to potential attackers and crackers.  <span id="more-325"></span></p>
<p style="text-align: justify;">While some may be looking to <strong>phish </strong>your personal information and identity for resale, others simply just want to use your computer as a platform from which to attack other unknowing targets.  Below are a few easy, cost-effective steps you will be able to take to make your computer more protected.</p>
<ol style="text-align: justify;">
<li>Always make backups of important information and store in a safe place separate from your computer.</li>
<li>Update and patch your OS, browser and software frequently.  If you have a Windows OS, start by going to <a href="http://www.windowsupdate.microsfot.com" target="_blank">windowsupdate.microsoft.com</a> and running the update wizard.  This program will help you find the latest patches for your Windows computer.  Also go to <a href="http://officeupdate.microsoft.com" target="_blank">officeupdate.microsoft.com</a> to locate possible patches for your Office programs.</li>
<li>Install a firewall.  Without a good firewall, viruses, worms, Trojans, malware and adware can all easily access your computer from the Internet.  Consideration should be given to the benefits and differences between hardware and software based firewall programs.</li>
<li>Review your browser and email settings for optimum security.  Why should you do this?  Active-X and JavaScript are often used by hackers to plant malicious programs into your computers.  While cookies are relatively harmless in terms of security concerns, they do still track your movements on the Internet to build a profile of you.  At a minimum set your security setting for the “internet zone” to High, and your “trusted sites zone” to Medium Low.</li>
<li>Install antivirus software and set for automatic updates so that you receive the most current versions.</li>
<li>Do not open unknown email attachments.  It is simply not enough that you may recognize the address from which it originates because many viruses can spread from a familiar address.</li>
<li>Do not run programs from unknown origins.  Also, do not send these types of programs to friends and coworkers because they contain funny or amusing stories or jokes.  They may contain a Trojans horse waiting to infect a computer.</li>
<li>Disable hidden filename extensions.  By default, the Windows operating system is set to “hide file extensions for known file types”.  Disable this option so that file extensions display in Windows.  Some file extensions will, by default, continue to remain hidden, but you are more likely to see any unusual file extensions that do not belong.</li>
<li>Turn off your computer and disconnect from the network when not using the computer.  A hacker cannot attack your computer when you are disconnected from the network or the computer is off.</li>
<li style="text-align: justify;">Consider making a boot disk on a floppy disk in case your computer is damaged or compromised by a malicious program.  Obviously, you need to take this step before you experience a hostile breach of your system.</li>
</ol>
<p>I hope these recommendations will help you.</p>
<p>Happy staying in Ntsysv Blog!</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/securing-your-windows-system/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>From Backup Restore Strategy To a Physical To Virtual Technic</title>
		<link>http://www.ntsysv.com/index.php/from-backup-restore-strategy-to-a-physical-to-virtual-technic</link>
		<comments>http://www.ntsysv.com/index.php/from-backup-restore-strategy-to-a-physical-to-virtual-technic#comments</comments>
		<pubDate>Tue, 03 Feb 2009 23:55:37 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[Physical to Virtual]]></category>
		<category><![CDATA[virtualisation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[symantec]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=318</guid>
		<description><![CDATA[Being in holidays, I was called in an emergency for an Ldap database restore because an application was no more running. The fact is, even if we had an image of disks of the physical server hosting the application, we didn&#8217;t have backups for files each on by itself available at this time. So the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Being in holidays, I was called in an emergency for an  Ldap database restore because an application was no more running. The fact is,  even if we had an <strong>image of disks</strong> of the <strong>physical server</strong> hosting the application, we didn&#8217;t have backups  for files each on by itself available at this time. So the solution that I proposed was <strong>to restore the  backup</strong> to a new <strong>virtual machine</strong>, that way, we can recover the files we need and  go to run very quickly.</p>
<p><span id="more-318"></span></p>
<p style="text-align: justify;">So, what&#8217;s the facts? The first one is that the application is not working,  and thus, many people cannot work. The server (a <strong>Windows 2003 server</strong>) is a <strong>Dell</strong> server backed up with <strong>Symantec Backup Exec System Recovery</strong> (<a href="http://www.symantec.com/en/us/business/backup-exec-system-recovery-server-edition" target="_blank">BESR</a>), a tool that  takes drives images so that recovery time is the least, and the last save is  available in a network share. I have available too some free resources in an <strong>ESX </strong>enough to create a new virtual machine to host the server image.</p>
<p style="text-align: justify;">As you noticed, the starting idea was to <strong>recover</strong> the image  of the <strong>physical server to  a virtual machine</strong>. What I came up with is a new technique to <strong>virtualize a  physical server</strong>, and transform it to a virtual machine. This is thanks to  &#8220;<strong>Restore Anywhere</strong>&#8221; option available in <strong>BESR</strong>; in normal restore cases, we will  restore to an identical hardware and this option is not needed, but in the  scenario I described, the image is going to a virtual hardware. It is good to  know that <strong>Windows License Product Key</strong> will be needed to be able to Activate  Windows later on. No need for specific drivers as VMware ones are available by  default.</p>
<h3 style="text-align: justify;">So how we do it?</h3>
<p style="text-align: justify;">To be able to &#8220;remake&#8221; a blank server, BESR comes with a <strong>bootable CD</strong> that  configures the basic information needed to work with the new server : we can  configure network interfaces, map network drives,&#8230;etc. Once the IP stack is correctly  configured (you can issue a &#8220;ping&#8221; command to the IP used to check if the server  is responding) you can use the available wizard to map a drive to the network   share hosting the images.</p>
<p style="text-align: justify;">After this basic configuration, you can start recovering the server, or shall  I say building the virtualized server. It will take up to 2 hours to restore  50Gb image if the ESX is &#8220;normally&#8221; used; of course, it may take less time in a  test environment. After the first reboot, the server will start configuring  the new hardware, this may take up to 15 minutes, so you can go and have a  coffee! A question will be asked to you  is that if you need the server to be joined to  a domain or you want to keep it in the &#8220;workgroup&#8221;. It is wise to let it in the  workgroup till it becomes available to configure it at your ease.</p>
<p style="text-align: justify;">The server is now up and running; the new virtual server will keep the  initial name, applications and so on, but no hardware configuration will remain,  neither network configuration. At this point, you can reconfigure your server as  you wish.</p>
<p style="text-align: justify;">For me, I was able to backup specific file using ntbackup tool in the new virtual machine and restore them to  the original physical server. Please note that if you connect you new virtual  machine to the network, and if you keep the same name, it may generate a  &#8220;duplicate name&#8221; TCP/IP error. I bypassed this error by removing any DNS server  IP, Wins server IP from network configuration. Also, you will have to disable  Netbios naming utilization, so the server will only use IPs to communicate in  the network.</p>
<p style="text-align: justify;">I hope you liked this post and found it helpful, and I&#8217;d like to thank you  for your time.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/from-backup-restore-strategy-to-a-physical-to-virtual-technic/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VMware Workstation : Disable Beep In Virtual Machines</title>
		<link>http://www.ntsysv.com/index.php/vmware-workstation-disable-beep-in-virtual-machines</link>
		<comments>http://www.ntsysv.com/index.php/vmware-workstation-disable-beep-in-virtual-machines#comments</comments>
		<pubDate>Fri, 30 Jan 2009 13:58:07 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[virtualisation]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=313</guid>
		<description><![CDATA[Every time an error show up in Windows, a message like : &#8220;at least one service didn&#8217;t start&#8221;, or a command is not existent in Linux, VMware virtual machine will play a loud and noisy Beep sound; This may be embarrassing if you are in a meeting or a presentation. In a previous post I [...]]]></description>
			<content:encoded><![CDATA[<p>Every time an error show up in <strong>Windows</strong>, a message like : &#8220;at least one service didn&#8217;t start&#8221;, or a command is not existent in <strong>Linux</strong>, <strong>VMware virtual machine</strong> will play a loud and noisy <strong>Beep </strong>sound; This may be embarrassing if you are in a meeting or a presentation. <span id="more-313"></span><br />
In a <a href="http://www.ntsysv.com/index.php/vmware-desactiver-la-repetition-automatique-des-caracteres" target="_blank">previous post</a> I talked about How to <strong>Disable chars/letters repetition in virtual machine</strong>s, it is as much annoying as having the pc or laptop screaming for an unknown command or a disabled service. So, what you should do is adding a <strong>noBeep </strong>parameter to your workstation installation&#8217;s configuration file.</p>
<p>The file to update is :</p>
<blockquote>
<p style="text-align: center;">%USERPROFILE%\Application Data\VMware\config.ini</p>
</blockquote>
<p style="text-align: left;">for windows versions of VMware workstation, and :</p>
<blockquote>
<p style="text-align: center;">~/.vmware/config</p>
</blockquote>
<p style="text-align: left;">for Linux one.</p>
<p style="text-align: left;">The parameter you have to add is :</p>
<blockquote>
<p style="text-align: center;">mks.noBeep = &#8220;TRUE&#8221;</p>
</blockquote>
<p style="text-align: left;">Please note:</p>
<ul>
<li>The configuration file is &#8220;profile&#8221; dependent; so if you update it for your profile, other ones in the same computer won&#8217;t have it configured.</li>
<li>You have to stop/close all <strong>Vmware Workstation</strong> running instances.</li>
<li>You may need to restart the &#8220;<strong>VMware Autorization Service</strong>&#8220;</li>
<li>You may not find the config or config.ini files, so just edit a new file.</li>
<li>Under <strong>Linux</strong>, a file or folder for which the name starts with a Dot is hidden, to be able to see it you have to issue an &#8220;<em>ls -a</em>&#8221; to display it.</li>
</ul>
<p>Hope this was helpful.<br /></p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/vmware-workstation-disable-beep-in-virtual-machines/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Deploy Registry Key Using Group Policy Object</title>
		<link>http://www.ntsysv.com/index.php/deploy-registry-key-using-group-policy-object</link>
		<comments>http://www.ntsysv.com/index.php/deploy-registry-key-using-group-policy-object#comments</comments>
		<pubDate>Sun, 25 Jan 2009 21:30:07 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[registry]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=298</guid>
		<description><![CDATA[Setting specific values for registry keys is a usual task for administrators, either to manage users profiles, specific applications settings&#8230;etc. In this article I will give a basic but yet useful example to deploy such configuration using Group Policy Objects (GPO). In a previous article I talked about disabling Autorun facility in Windows using a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Setting specific values for <strong>registry </strong>keys is a usual task for administrators, either to <strong>manage users profiles</strong>, specific applications settings&#8230;etc. In this article I will give a basic but yet useful example to deploy such configuration using<strong> Group Policy Objects</strong> (GPO).<span id="more-298"></span></p>
<p style="text-align: justify;">In a <a href="http://www.ntsysv.com/index.php/howto-disable-autorun-windows-systems-effective-way" target="_blank">previous article</a> I talked about <strong>disabling Autorun</strong> facility in Windows using a <strong>registry value </strong>suggested by US-CERT. To remind the reader, the key and value are :</p>
<blockquote><p>Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf<br />
Value : @=&#8221;@SYS:DoesNotExist&#8221;</p></blockquote>
<p style="text-align: justify;">To <strong>deploy this configuration using GPO</strong>, we need to create a new, or may be update an existing one, administration file. Administration files are normally located in folder :</p>
<blockquote><p>%systemroot%\inf</p></blockquote>
<p style="text-align: justify;">and have .adm extension.</p>
<p style="text-align: justify;">I will not go into details of ADM files syntax, version control and Operating System filtering, as it will need more than one article, but anyway : here is a prototype you can always use with Windows XP (and above?) and you can change the key and values but keep the same syntax. For interested readers, I recommend this document : &#8220;<strong>Using Administrative Template Files with Registry-Based Group Policy</strong>&#8221; from <a href="http://technet.microsoft.com/en-us/library/cc779567.aspx" target="_blank">Microsoft site</a>.</p>
<p>So, the ADM file I propose for this configuration:</p>
<blockquote><p>CLASS MACHINE<br />
CATEGORY !!category<br />
KEYNAME &#8220;SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf&#8221;<br />
POLICY !!policynameautorun<br />
ACTIONLISTON<br />
VALUENAME &#8220;@&#8221;        VALUE &#8220;@SYS:DoesNotExist&#8221;<br />
END ACTIONLISTON<br />
ACTIONLISTOFF<br />
VALUENAME &#8220;@&#8221;        VALUE &#8220;&#8221;<br />
END ACTIONLISTOFF<br />
END POLICY<br />
END CATEGORY<br />
[strings]<br />
category=&#8221;Custom Policy Settings&#8221;<br />
policynameautorun=&#8221;Disable autorun&#8221;</p></blockquote>
<p style="text-align: justify;">save this lines as &#8220;customPolicies.adm&#8221; for example, and import it as an administrative template. To do so, develop &#8220;<strong>computer configuration</strong>&#8220;, then right click on &#8220;<strong>administrative templates</strong>&#8221; group,  and choose &#8220;Add/Remove templates&#8221;, click on &#8220;Add&#8221; and browse for your file. Once selected, validate and close; You&#8217;ll see your new group of policies (that is named &#8220;category&#8221; in the adm file) in the groups tree. You can see this steps in this video.</p>
<p>[kml_flashembed fversion="8.0.0" movie="http://www.ntsysv.com/wp-content/uploads/2009/01/add-administrative-template-file.swf" targetclass="flashmovie" publishmethod="static" width="400" height="300"]</p>
<p><a href="http://adobe.com/go/getflashplayer"><img src="http://www.adobe.com/images/shared/download_buttons/get_flash_player.gif" alt="Get Adobe Flash player" /></a></p>

	<!--[if !IE]>-->
	</object>
	<!--<![endif]-->
</object>
<p style="text-align: justify;">One done, you man not see the new policy as there&#8217;s a default filtering. To disable filtering, right click on &#8220;administrative templates&#8221;, select &#8220;Display&#8221; menu and then &#8220;Filtering&#8221;; uncheck all checkboxes. Have a look here :</p>

<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
			id="fm_disable-policy-display-filtering_1596020517"
			class="flashmovie"
			width="400"
			height="300">
	<param name="movie" value="http://www.ntsysv.com/wp-content/uploads/2009/01/disable-policy-display-filtering.swf" />
	<!--[if !IE]>-->
	<object	type="application/x-shockwave-flash"
			data="http://www.ntsysv.com/wp-content/uploads/2009/01/disable-policy-display-filtering.swf"
			name="fm_disable-policy-display-filtering_1596020517"
			width="400"
			height="300">
	<!--<![endif]-->
		
<p><a href="http://adobe.com/go/getflashplayer"><img src="http://www.adobe.com/images/shared/download_buttons/get_flash_player.gif" alt="Get Adobe Flash player" /></a></p>

	<!--[if !IE]>-->
	</object>
	<!--<![endif]-->
</object>
<p style="text-align: justify;">Some explanations about parameters used in the above example :</p>
<ul style="text-align: justify;">
<li><strong>KEYNAME</strong> : Registry key to change/create.</li>
<li><strong>ACTIONLISTON</strong> : actions to perform when the policy is enabled</li>
<li><strong>ACTIONLISTOFF</strong> : actions to perform when policy is disabled</li>
<li><strong>strings</strong> section : values for substitution variables, noted with double exclamation mark (!!category for example). These varibales are used for portability between different language versions of Windows.</li>
</ul>
<p style="text-align: justify;">Having the adm file imported does not mean it is in use and applied. You need to create a new strategy (or update an existing one) to use the policy. Then you have to link this strategy to the Organisational Unit (OU) you want.</p>
<p style="text-align: justify;">In the client side, you need to run <strong>gpupdate </strong>in the command prompt if you want the modifications to be applied right at the moment without waiting any longer. Gpupdate command replaces <strong>secedit </strong>command available in Windows 2000 and older versions. Please refer to the help of these commands for more details.</p>
<p style="text-align: justify;">I hope you enjoyed reading and it was useful.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/deploy-registry-key-using-group-policy-object/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Disable Autorun In Windows Systems : The Effective Way</title>
		<link>http://www.ntsysv.com/index.php/howto-disable-autorun-windows-systems-effective-way</link>
		<comments>http://www.ntsysv.com/index.php/howto-disable-autorun-windows-systems-effective-way#comments</comments>
		<pubDate>Wed, 21 Jan 2009 09:44:06 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[autorun]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=287</guid>
		<description><![CDATA[Having Autorun enabled in Microsoft Windows systems may help the spread of viruses. This is true because autorun can start any arbitrary code without user interaction. In a previous article we saw how to disable low dik space warnings in Windows systems, in this article we will talk about Autorun. Microsoft Windows come with the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Having <strong>Autorun </strong>enabled in <strong>Microsoft Windows</strong> systems may help the <strong>spread of viruses</strong>. This is true because <strong>autorun can start any arbitrary code without user interaction</strong>.<span id="more-287"></span></p>
<p style="text-align: justify;">In a previous article we saw <a href="http://www.ntsysv.com/index.php/tutoriel-video-desactivation-des-alertes-espace-disque-faible-sous-windows" target="_blank">how to disable low dik space warnings</a> in Windows systems, in this article we will talk about Autorun.</p>
<p style="text-align: justify;">Microsoft Windows come with the <strong>AutoRun </strong>feature which make applications start <strong>automaticaly </strong>when inserting a CD/DVD, mapping a network drive or plugging a USB key. This is the worst case because everyone can plug a usb key to move data, to get pictures from a friend, to copy music &#8230;etc.</p>
<p style="text-align: justify;">When a <strong>Removable Device</strong> is connected to computer, either the autorun launches the exe/.com file to witch a Autorun.inf file point to, or the user double click on the icon to browse the device content. In both cases, a hidden execution happens and make the computer infected. As an example, the Malicious software <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99" target="_blank"><strong>W32.Downadup</strong></a> uses this technique to spread.</p>
<p style="text-align: justify;">In Microsoft, we can read many articles, such :</p>
<ul style="text-align: justify;">
<li><a href="http://support.microsoft.com/?scid=kb%3Ben-us%3B953252&amp;x=17&amp;y=17" target="_blank">How to correct &#8220;disable Autorun registry key&#8221; enforcement in Windows</a> : which details also how to <strong>disable autorun useing Group Policy Object</strong>s (GPO)</li>
<li><a href="http://support.microsoft.com/?scid=kb%3Ben-us%3B155217&amp;x=18&amp;y=12" target="_blank">How to Enable or Disable Automatically Running CD-ROMs</a></li>
<li><a href="http://support.microsoft.com/?scid=kb%3Ben-us%3B823732&amp;x=16&amp;y=11" target="_blank">How to disable the use of USB storage devices</a> (more radical solution!)</li>
</ul>
<p style="text-align: justify;">Today I received an <a href="http://www.cert.org" target="_blank">US-CERT</a> notification to say that those solutions are not effective when a media is first time connected to computer. In the <a href="http://www.us-cert.gov/cas/techalerts/TA09-020A.html" target="_blank">Technical Cyber Security Alert TA09-020A</a> we can read :</p>
<p style="text-align: justify;">
<blockquote>
<p style="text-align: justify;">The <strong>Autorun </strong>and <strong>NoDriveTypeAutorun </strong>registry values are both ineffective for  fully disabling AutoRun capabilities on Microsoft   Windows systems. Setting  the Autorun registry value to 0 <strong>will not prevent newly connected devices</strong> from automatically running code specified in the Autorun.inf file. It will,  however, disable Media Change Notification (MCN) messages, which may  prevent Windows from detecting when a CD or DVD is changed. According to  Microsoft, setting the NoDriveTypeAutorun registry value to 0xFF  &#8220;disables Autoplay on all types of drives.&#8221; Even with this value set,  Windows may execute arbitrary code when the user clicks the icon for  the device in Windows Explorer.</p>
</blockquote>
<p style="text-align: justify;">The proposed solution is to set the following value to registry :</p>
<blockquote><p>Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows  NT\CurrentVersion\IniFileMapping\Autorun.inf</p>
<div style="direction: ltr;">Value : @=&#8221;@SYS:DoesNotExist&#8221;</div>
</blockquote>
<div style="direction: ltr;">You can copy past the following code to a blank text file, and save it as .reg file, name it for example &#8220;disable-autorun.reg&#8221;, you will just have to double click on it to register the value.</div>
<blockquote>
<div style="direction: ltr;">REGEDIT4<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]<br />
@=&#8221;@SYS:DoesNotExist&#8221;</div>
</blockquote>
<div style="direction: ltr;">To have this configuration taken into account, you&#8217;ll have to reboot your system. If it is not possible, you&#8217;ll have to clean pre-cached mounted devices by deleting the following key:</div>
<blockquote>
<div style="direction: ltr;">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2</div>
</blockquote>
<p style="text-align: justify;">Hope you found this post useful, and I&#8217;d like to invite you to subscribe to my feed to keep in touch with future posts.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/howto-disable-autorun-windows-systems-effective-way/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Video Tutorial: Backup And Restore System With PING</title>
		<link>http://www.ntsysv.com/index.php/video-tutorial-backup-and-restore-system-with-ping</link>
		<comments>http://www.ntsysv.com/index.php/video-tutorial-backup-and-restore-system-with-ping#comments</comments>
		<pubDate>Sun, 18 Jan 2009 23:21:55 +0000</pubDate>
		<dc:creator>ElMehdi</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[disk]]></category>
		<category><![CDATA[PING]]></category>
		<category><![CDATA[restore]]></category>

		<guid isPermaLink="false">http://www.ntsysv.com/?p=283</guid>
		<description><![CDATA[Find a tools to save and restore all Operating Systems and also suitable to use with all kind of media is a hard exercice. PING, not &#8220;echo request&#8221; ICMP message, but Partimage Is Not Ghost, is a bloc level backup tool that may help achieve this goal. We saw in a previous article how to [...]]]></description>
			<content:encoded><![CDATA[<p>Find a tools to <strong>save </strong>and <strong>restore </strong>all <strong>Operating Systems</strong> and also suitable to use with all kind of media is a hard exercice. <strong>PING</strong>, not &#8220;echo request&#8221; ICMP message, but <strong>Partimage Is Not Ghost</strong>, is a bloc level backup tool that may help achieve this goal.<span id="more-283"></span></p>
<p>We saw in a <a href="http://www.ntsysv.com/index.php/video-tutorial-windows-2003-ntbackup-asr-backup-restore" target="_blank">previous article</a> how to <strong>save and restore a Windows 2003 system</strong> by using ASR. This is a particular method available in Windows 2003 but not in Windows 2000 and older versions.</p>
<p>Based on a <strong>live linux</strong> 22Mb image, PING offers all needed commands <strong>to map a Windows share</strong>,  <strong>mount an NFS partition</strong>, and maybe make an FTP image. The included automated dhcp client makes it easy for people not used to linux systems to use PING without any problem.</p>
<p>In the officiel Website we can read more details about its advantages; those I find interesting :</p>
<ul>
<li>Backup and Restore the BIOS data as well;</li>
<li>Either burn a bootable CD / DVD, either integrate within a PXE / RIS environment;</li>
<li>Possibility to Blank local admin&#8217;s password;</li>
<li>Create your own restoration bootable DVD</li>
</ul>
<p>and if we compare PING to DOS or Ghost tools :</p>
<ul>
<li>Most network cards automatically recognized by the Kernel;</li>
<li>Most CD/DVD readers automatically recognized by the Kernel;</li>
<li>You don&#8217;t have to run a Ghostcast server to receive images over the network;</li>
<li>More supported filesystems;</li>
<li>You can store an image on several CD/DVD (CD/DVD-spanning);</li>
<li>You can backup and restore BIOS settings too;</li>
<li>Much much smaller than <a href="http://support.microsoft.com/?scid=kb%3Ben-us%3B303891&amp;x=10&amp;y=11" target="_blank">WinPE </a>/ <a href="http://www.nu2.nu/pebuilder/" target="_blank">BartPE</a>;</li>
</ul>
<p>Basic linux commands are also available to run in the text mode. In fact, PING starts a text based assistant to guide the user step by step. It is always possible, if the assistant exits, to start it by using</p>
<blockquote><p>/etc/init.d/rc.ping</p></blockquote>
<p>script.</p>
<p>In the example I expose in this video, I start by making an image of a <strong>Windows 2003 server </strong>to a network share. Then I destroy the existant disk and create a new blank one. Then I restore the saved image to the new disk. Note that source and destination disks may be of different sizes, but necessary the source larger than the destination.</p>
<p>An evident remark is that the tool may be used for any kind of operating system, as it does not look at files level but in blocs one.</p>
<p>Enjoy seeing this video, and I hope it will help!</p>
<p style="text-align: center;">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
			id="fm_backup-and-restore-disk-using-ping_55910883"
			class="flashmovie"
			width="400"
			height="300">
	<param name="movie" value="http://www.ntsysv.com/wp-content/uploads/2009/01/backup-and-restore-disk-using-ping.swf" />
	<!--[if !IE]>-->
	<object	type="application/x-shockwave-flash"
			data="http://www.ntsysv.com/wp-content/uploads/2009/01/backup-and-restore-disk-using-ping.swf"
			name="fm_backup-and-restore-disk-using-ping_55910883"
			width="400"
			height="300">
	<!--<![endif]-->
		
	<!--[if !IE]>-->
	</object>
	<!--<![endif]-->
</object>
<p style="text-align: left;">Obtain HD version by a simple Call or   Paypal</p>
<div style="width: 300px; font-family: Arial,Helvetica,sans-serif; font-size: 10px; background-color: #ffffff; color: #000000;">
<div style="height: 25px; text-align: center;"><img src="http://payment.allopass.com/imgweb/script/fr_uk/acces_title.jpg" alt="Logo" width="300" height="25" /></div>
<div style="height: 137px; text-align: center;"><img src="http://payment.allopass.com/acte/scripts/popup/top.apu?ids=203321&amp;idd=799351&amp;lang=fr" alt="" width="300" height="137" /></div>
<div style="width: 300px; text-align: right;"><img style="float:left" src="http://payment.allopass.com/imgweb/script/fr_uk/acces_left.jpg" alt="" width="79" height="29" /><br />
<a onclick="javascript:window.open('http://payment.allopass.com/acte/scripts/popup/access.apu?ids=203321&amp;idd=799351&amp;lang=fr&amp;country=uk','phone','toolbar=0,location=0,directories=0,status=0,scrollbars=0,resizable=0,copyhistory=0,menuBar=0,width=300,height=340');" href="javascript:;"><img title="UK" src="http://payment.allopass.com/imgweb/common/flag_uk.gif" border="0" alt="UK" width="35" height="29" /></a><a onclick="javascript:window.open('http://payment.allopass.com/acte/scripts/popup/access.apu?ids=203321&amp;idd=799351&amp;lang=fr&amp;country=ca','phone','toolbar=0,location=0,directories=0,status=0,scrollbars=0,resizable=0,copyhistory=0,menuBar=0,width=300,height=340');" href="javascript:;"><img title="CA" src="http://payment.allopass.com/imgweb/common/flag_ca.gif" border="0" alt="CA" width="35" height="29" /></a><a onclick="javascript:window.open('http://payment.allopass.com/acte/scripts/popup/access.apu?ids=203321&amp;idd=799351&amp;lang=fr&amp;country=de','phone','toolbar=0,location=0,directories=0,status=0,scrollbars=0,resizable=0,copyhistory=0,menuBar=0,width=300,height=340');" href="javascript:;"><img title="DE" src="http://payment.allopass.com/imgweb/common/flag_de.gif" border="0" alt="DE" width="35" height="29" /></a><a onclick="javascript:window.open('http://payment.allopass.com/acte/scripts/popup/access.apu?ids=203321&amp;idd=799351&amp;lang=fr&amp;country=be','phone','toolbar=0,location=0,directories=0,status=0,scrollbars=0,resizable=0,copyhistory=0,menuBar=0,width=300,height=340');" href="javascript:;"><img title="BE" src="http://payment.allopass.com/imgweb/common/flag_be.gif" border="0" alt="BE" width="35" height="29" /></a><a onclick="javascript:window.open('http://payment.allopass.com/acte/scripts/popup/access.apu?ids=203321&amp;idd=799351&amp;lang=fr&amp;country=fr','phone','toolbar=0,location=0,directories=0,status=0,scrollbars=0,resizable=0,copyhistory=0,menuBar=0,width=300,height=340');" href="javascript:;"><img title="FR" src="http://payment.allopass.com/imgweb/common/flag_fr.gif" border="0" alt="FR" width="35" height="29" /></a></div>
<form style="text-align:center;clear:both" action="http://payment.allopass.com/acte/access.apu" method="post">
<input name="ids" type="hidden" value="203321" />
<input name="idd" type="hidden" value="799351" />
<input name="lang" type="hidden" value="fr" /><strong>Entrez votre code d&#8217;accès -<br />
Enter your access code</strong></p>
<input style="border: 1px solid #000080; background-color: #e7e7e7; color: #000080; cursor: text; font-family: Arial; font-size: 10pt; font-weight: bold; letter-spacing: normal; width: 70px; text-align: center;" maxlength="10" name="code[]" size="8" type="text" />
<input style="border: 0px none; margin: 0px; padding: 0px; background: transparent url(http://payment.allopass.com/imgweb/common/bt_ok.gif) repeat scroll 0% 0%; width: 48px; height: 18px;" onclick="this.form.submit();this.form.APsub.disabled=true;" name="APsub" type="button" />
</form>
<p>Pour connaître notre solution de micro paiement : <a href="http://fr.allopass.com/" target="_blank">Allopass</a></div>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=11225105"><img class="alignnone size-full wp-image-413" title="pay by paypal" src="http://www.ntsysv.com/wp-content/uploads/2008/10/paypal.jpg" alt="pay by paypal" width="65" height="26" /></a><br />
PING is available to download in <a href="http://ping.windowsdream.com/ping/download.html" target="_blank">the offcial Web Site</a>.</p>
Copyright <b> <a href="http://www.ntsysv.com">Ntsysv.com </a></b>]]></content:encoded>
			<wfw:commentRss>http://www.ntsysv.com/index.php/video-tutorial-backup-and-restore-system-with-ping/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

