Ads

Monday, July 2, 2007

How to get sound working on Virtual PC 2007 with Vista guest OS

How to get sound working on Virtual PC 2007 with Vista guest OS


Virtual PC 2007 added a new sound system specifically for using Vista as a guest and host OS. But when you install Vista as a guest OS, there is no sound! A search on Google and Live Search didn't turn up anything about how to use it.


Eventually I found that after you install the VM Additions, the sound driver is silently copied into the guest OS's "C:\Program Files\Virtual Machine Additions" folder. All you need to do to get sound working is "update" your audio controller driver within your Vista guest OS and tell it you Have Disk... and point it at that folder and voila! Beautiful sound. (without any restarts either).

Tuesday, June 26, 2007

Forget those hard to remember passwords?

Is it hard to remember those complicated passwords you have on each website? Are you tired of having to get your password reset because you couldn't remember it? Well now there is a solution to your problem, It's called called RoboForm.

It will remember your website passwords, forum passwords or any websites that require you to login. its will automatically detect when you are logging in with the username and password, once you do so and you have successfully logged in (Most of the time), it will remember it from there on.

You can download it here for a limited time: http://www.roboform.com/pcw (Thank you PcWorld)

or you can visit their website at: http://www.roboform.com/ and download the free one (Unlimited Time). (I don't know if there is a difference between the 2 download areas, i suggest you use the PcWorld Download While it lasts, or you can get it at their homepage.)

I use this to login to my blog, my forums, to my websites and anything else that requires a login. (So far i have not noticed any way for it to remember you logging into any program on your pc, only websites)

It is Vista, and Internet Explorer 7 supported.
It will also work in Firefox.

Analysts: Vista SP1 Delay Won't Hurt Businesses

Any delay shouldn't affect adoption of Windows Vista by enterprises, analysts say.


Elizabeth Montalbano, IDG News Service

Monday, June 25, 2007 4:00 PM PDT


Although Microsoft Corp. may not have the first service pack for Windows Vista ready at the end of this year as some expected, financial analysts say that a delay should not have a negative effect on enterprise adoption of the OS.


Many large enterprise customers have said they will wait for the first service pack for Vista to deploy the software across their companies. Some were expecting SP1 before the end of the year after Microsoft Senior Vice President Bob Muglia said in a published report last November it would be released with Windows Server code-named Longhorn, due by the end of 2007.


However, rumors swirled last week that the release of the pack would be pushed into 2008 after Microsoft said in a court filing dated June 19 it would have only a test version of Vista SP1 out before the end of the year. According to the document, filed as part of the ongoing antitrust case with the U.S. Department of Justice, the software is to be released by then to answer a complaint by Google Inc. that claims the OS' built-in desktop search capability interferes with the use of Google's competing search technology.


The rumors caused investors to worry about enterprise adoption of Vista being pushed further out, and company stock declined 2.4 percent Friday, opening at US$30.03 and closing at $29.54.


UBS Investment Research analyst Heather Bellini tried to allay investor fears in a research note published Monday, saying that the end of the year release of a beta listed in the document "probably represents a 'drop-dead' date."


"The company most likely has accounted for the possibility of unforeseen delays in this timing," according to Bellini's note. "As such, we believe Vista SP1 could be available sometime before the end of the year barring any material delays."


Andrew Brust, chief, new technology, for consulting firm and Microsoft partner Twentysix New York, who is familiar with the company's plans, said he also believes Microsoft will have SP1 out the door before the end of 2007. He would not disclose specifics, but Brust said that what he's heard "contradicts the chatter."


"Microsoft is quite aware of the need to get an SP out there; I promise you that," he said in an e-mail interview Monday.


Through its public relations team, Microsoft said Monday that it has never committed to a release date for SP1, and confirmed the company will be releasing test builds of the software from now throughout the end of the year. Despite Muglia's comments last year, even a 2008 release for Vista SP1 should not be considered a delay because the company never announced a firm date for release, Microsoft said.


Enterprises are most likely waiting for the release of Windows Server Longhorn -- now known by its official name, Windows Server 2008 -- before deploying Vista, making SP1 less relevant to enterprise deployment than some think, according to a research note from Citigroup Global Markets.



Security Vendors Challenge Antivirus Tests

Makers of security software question the thoroughness and accuracy of evaluations.

Jeremy Kirk, IDG News Service

Tuesday, June 26, 2007 9:00 AM PDT


Antivirus software is frequently tested for performance, so picking a top product should be straightforward: Select the number-one vendor whose software kills off all of the evil things circulating on the Internet. You're good to go then, right? Not necessarily.


The increasing complexity of security software is causing vendors to gripe that current evaluations do not adequately test other technologies in the products designed to protect machines.


Relations between vendors and testing organizations are generally cordial but occasionally tense when a product fails a test. Representatives in both camps agree that the testing regimes need to be overhauled to give consumers a more accurate view of how different products compare.


"I don't think anyone believes the tests as they are run now ... are an accurate reflection of how one product relates to the other," said Mark Kennedy, an antivirus engineer with Symantec Corp.


Representatives of Symantec, F-Secure Corp. and Panda Software SA agreed last month at the International Antivirus Testing Workshop in Reykjavik, Iceland, to design a new testing plan that would better reflect the capabilities of competing products. They hope all security vendors will agree on a new test that can be applied industrywide, Kennedy said.


A preliminary plan should be drawn up by September, Kennedy said.


One of the most common tests involves running a set of malicious software samples through a product's antivirus engine. The antivirus engine contains indicators, called signatures, that enable it to identify harmful software.


But antivirus products have changed over the last couple years, and "now many products have other ways of detecting and blocking malware," said Toralv Dirron, security lead system engineer for McAfee Inc.


Signature-based detection is important, but an explosion in the number of unique malicious software programs created by hackers is threatening its effectiveness. As a result, vendors have added overlapping defenses to catch malware.


Vendors are employing behavioral detection technology, which may identify a malicious program if it undertakes a suspicious action on a machine. A user may unwittingly download a malicious software program that is not detected through signatures. But if the program starts sending spam, the activity can be identified and halted.


Also, a program can be halted if it tries to exploit a buffer overflow vulnerability, where an error in memory can allow a bad program to run. Host-based, intrusion-prevention systems, which can employ firewalls and packet inspection techniques, can also stop attacks.


The ways in which a computer can be infected also make comprehensive testing complex. For example, users may infect their computers by opening malicious e-mail attachments or visiting harmful Web sites designed to exploit known vulnerabilities in a Web browser.


The different modes of attack also involve different defenses, all of which would need to be tested to arrive at an accurate ranking, analysts said.


By contrast, signature-based tests can take as little as five minutes. "This is a very basic test," said Andreas Marx of AV-Test.org, who wrote his master's degree thesis on antivirus testing. "It's easy, and it's cheap."


Other concerns remain, over sample sets of malicious software, the age of the samples and the relative threat those samples pose on the Internet as they become older. Security vendors also think tests should check how well security applications remove bad programs, a process that can affect a computer's performance.


For vendors, a failed test can be embarrassing, since the testing companies often issue news releases highlighting the latest results.


Testing companies make money in various ways. AV-Test.org is often commissioned by technology magazines such as PC World (a magazine owned by IDG). Virus Bulletin licenses its logo to companies for use in promotional material and publishes a monthly online magazine.


Earlier this month, Virus Bulletin announced that its latest round of testing produced some "big-name failures," including products from Kaspersky Lab and Grisoft SRO.


The company's VB100 tests antivirus engines against malware samples collected by the Wildlist Organization International, a group of security researchers who collect and study malware. To pass the VB100, products must detect all samples.


Kaspersky briefly removed a signature for a worm out of its product for "optimization" purposes on the day of the test, wrote Roel Schouwenberg, senior research engineer for Kaspersky, in an e-mail. The signature has since been put back in, he said.


"Obviously, we would have rather passed than failed," Schouwenberg wrote. "Had the test been conducted a day earlier or a day later, we would have passed."


Similarly, F-Secure initially failed its test also because of a technicality, but the failed rating was later reversed. All vendors are told after testing which samples they failed to detect, thus most end up adding signatures to their products.


So what should a user do? John Hawes, a technical consultant for Virus Bulletin, cautioned that the signature-based tests are "not enormously representative of the way things are in the real world."


But Hawes also noted that signature-based tests can indicate the reliability and consistency of a vendor's software. Virus Bulletin also writes reviews of AV suites, which take into account aspects such as usability, which may be just as important as detection for consumers. The company is developing more advanced tests that will test new security technologies.


AV-Test.org is already performing more comprehensive tests, although it uses between 30 to 50 malware samples, a much smaller sample set compared to the Wildlist, which uses more than 600,000 samples, Marx said. Those tests may give a better indication of how a security software suite performs.


At a bare minimum, through, users should install some security software, as computers without it can face high risks, Marx said. Several free suites are available that may be fine for light Internet use, he said.


Ironically, Marx doesn't use any antivirus software. That's because AV-Test.org collects malware for its testing, most of which comes through e-mail from other researchers. "I'm getting about 1,000 viruses a day," he said. "It [antivirus software] would be counterproductive."


Monday, June 25, 2007

Firewall Program results

As you can see here:
http://www.firewallleaktester.com/tests.php
(Scroll to the bottom and hit view results)


Zone alarm is the third best in firewall leak testing (Scroll down the page and look at the bars). Now as you probably noticed, these tests weren't done on vista. Although there isn't much of a difference between Vista and XP when we are talking about firewalls. So if I were you, and you are running Vista, I suggest that you keep Windows Vista's firewall on, along with what ever else you choose to use.

Vista Built in Firewall Results

(1 pts) : This icon means that the firewall is 'passing' sucessfully the leaktests while setup properly.

(0,5 pts) : This icon means that the firewall is using a generic 'block' which is intercepting the leaktest at an earlier step, whereas there is no network access yet. While on one hand it can appear to be safer, on the other hand the technical alert given requires more knowledge from the user to do the right choice, which is less reliable than a sucessfull pass where the alert is about a network access. Moreover, these kind of protection will alert the user about many other legitimate activities which does not access the network.

(0 pts) : This icon means that the firewall is 'failing' the leaktest.
-------------------------------------------------------------------------------------------------


Impact on the leaktests


As you have read, the default 'out of the box' Vista security is very different than Windows XP, and brings some improvements. Below we will see per leaktests the impact on them, if any. The test will simply consist of running the leaktest, without any third party security software installed (no personal firewall, no HIPS), under an administrator account. All tests are done under Windows Vista Ultimate 64bits, with DEP enabled. DEP is not new to Vista, it already exists into Windows XP Service Pack 2 (SP2), Windows XP Tablet PC Edition 2005, and Windows Server 2003.

The tests requiring Internet Explorer are done with IE 32bits, as it is the version that all Vista editions have by default, even on Vista x64. The built-in firewall is left to default settings, blocking only inbound.

Leak test : Vista did not block the leaktest picture
Tooleaky : Vista did not block the leaktest picture
FireHole : Vista did block the leaktest picture
Yalta : Vista did not block the leaktest picture
Outbound : did not run (missing dll)
PCAudit : was hanging
AWFT : is crashing
Thermite : injection and outbound successful, but failed to create the file 'securityfocus.htm' picture
Copycat : injection and outbound successful, but failed to create the file 'exploited.txt'
MBtest : did not run (missing dll)
Wallbreaker : Vista did not block the leaktest picture
PCAudit2 : Vista did not block the leaktest picture
Ghost : Vista did not block the leaktest picture
DNStester : Vista did not block the leaktest picture
Surfer : Vista did block the leaktest picture
Breakout : did not run/was hanging
Jumper : Vista did block the leaktest picture
CPIL : Vista did block the leaktest picture
CPIL suite : Vista did block the leaktest
PCFlank : Vista did not block the leaktest picture
Coat : Vista did not block the leaktest picture
Runner : Vista did block the leaktest picture
OSfwbypass : Vista did block the leaktest picture
ZAbypass : Vista did not block the leaktest picture

Result : 9 leaktests are blocked on Vista, 3 weren't tested due to not being compatible or because WinpCap not being installed (WinPcap 4.0 or newer is required on Vista x64), and 12 leaktests are still working despite new Vista's security features. That means that 37,5% of the leaktests are blocked either from running properly, or from making a successfull outbound leak.
If you look differently the same numbers, we can say also that 50% of the leaktests (12) only are sucessfull on Vista, so that half are blocked (12 on 24). Pick the statistic you prefer.
-------------------------------------------------------------------------------------------------
So i (HotShot) suggest you get a second firewall, I personally use Zone Alarm Free with my Windows Vista Home Premium. Works like a charm and amazingly doesn't seem to lag me. Although make sure you go into the settings and allow all the programs you commonly use like Firefox or IE etc... Zone Alarm Comes out to be the 3rd best in Leak Testing. I will post that later on, but for now, this is what vista users need to know when they are looking for firewalls.

Sunday, June 24, 2007

Vista DRM Precludes Virtualization?

DRM restrictions may have caused Microsoft's Vista virtualization flip-flop.


Eric Lai, Computerworld
Sunday, June 24, 2007 9:00 AM PDT


Conspiracy theorists may link Microsoft Corp.'s abrupt decision late Tuesday not to remove restrictions on consumers virtualizing its Vista operating system to a Department of Justice agreement announced the same day or to a desire to jerk Intel Mac users around.
But the actual reason may be found in three little letters: DRM.


Vista's new digital rights management features enable movies or music files to be password-protected or made accessible only to authorized users for opening, viewing or changing.


Whether most users would call DRM a feature, however, is questionable. A close cousin to DRM technology, known as Windows Rights Management Services (which in turn is part of a larger category of technologies called Enterprise Digital Rights Management, or ERM), can help business users password-protect key documents and files, or assign the ability to open them only to trusted co-workers. But DRM's main purpose seems to be to help the Warner Bros. and Sony Musics of the world keep consumers from sharing movies and music. The entertainment industry claims that almost all blocked sharing is illegal; digital rights watchdogs argue that legitimate consumer uses are also blocked by such technology.


DRM is capable of blocking both overt piracy -- distributing movies via BitTorrent and other peer-to-peer networks -- as well as other common scenarios that most consumers do not consider piracy, such as moving legally acquired music files from their desktop PCs to their notebook computers.


"It's like when you batten down the hatches on a ship in a storm," said Aram Sinnreich, an analyst at Radar Research in Los Angeles. "Vista wants to batten down every software or multimedia bit so that they don't go somewhere the creator doesn't want it to go."
Versions out of control?


The problem is that virtualization, by accident, appears to break most of Vista's DRM and antipiracy schemes.


Virtualization software -- think VMware Inc.'s VMplayer, Microsoft's Virtual PC or Parallels Inc.'s Parallels Desktop -- allow computer users to boot one operating system but run a second one as a "guest" at the same time.


That can allow a user who has booted Windows Vista to load XP-only applications in a guest XP operating system, also known as a virtual machine (VM). Or it can let a user with an Intel Mac boot up the OS X operating system but also run Windows Vista or XP applications at the same time.


Microsoft's original plan was to announce on Tuesday changes to the contracts, known as End User Licensing Agreements (EULA), for its Vista Home Basic and Home Premium editions. Those changes would permit buyers who use those editions to create VMs. The change was purely to the EULA; there is no technical limitation preventing knowledgeable users from virtualizing retail versions of Home Basic or Home Premium.


Microsoft only allows full retail versions of Vista Business or Vista Ultimate (as well as Vista Enterprise for big corporations) to run as virtual guests of a host PC. Vista Business and Ultimate cost $299 and $399, respectively. The simple change in Microsoft's license for the two cheaper editions -- Home Basic Edition and Home Premium Edition cost $199 and $239, respectively -- would have saved customers at least $60 and up to $200.


In addition, Microsoft planned to permit the use of DRM, IRM (Information Rights Management) and Vista's storage encryption technology, BitLocker, in a VM for any version of Vista.


Besides boosting flagging perceptions of Microsoft's overall virtualization strategy, the move would have made Vista virtualization much more attractive to a key and growing segment -- Intel Mac owners who want to run Windows software.


But at the last moment, Microsoft did a 360. Its explanation was terse: "Microsoft has reassessed the Windows virtualization policy and decided that we will maintain the original policy announced last Fall," said a spokesman in an e-mailed statement.
A perfect picture (of cross-purposes)


When a user creates a VM, the virtualization software takes a snapshot of the PC's hardware and then creates an exact copy of how that works in memory, according to DeGroot.


This ability to perfectly simulate the way the original PC ran (albeit more slowly than the original) is why VMs are such a useful tool. But a VM, once created, can be copied hundreds or thousands of times and ported over to radically different PCs without triggering the antipiracy and DRM schemes of most software or multimedia files, including Vista's. Those schemes raise red flags only if they realize they've been moved to another computer, DeGroot said.


Analysts say what probably happened behind the scenes is that Microsoft or one of its media partners decided at the last moment that encouraging consumers to use virtualization would, at least symbolically, be at odds with its attempts to enforce DRM.


"Microsoft doesn't want the music labels, TV networks and movie studios to come back to them and say that you are enabling this ability to move content around," said Mike McGuire, an analyst at Gartner Inc.


Microsoft has more at stake than other high-tech firms, McGuire said, what with its partnerships with NBC, its Xbox gaming platform, its Media Center PCs and even its Zune music player.


"It's a very fine line that Redmond has to walk," McGuire said. "They have to answer to these companies if they want to have any hope of making the PC and their software the de facto usage model for multimedia."


The problem is that even if Microsoft -- and U.S. law -- insist it is still illegal to use virtualization to enable the sharing of software or movies or music, its antipiracy technology is powerless to stop it.


"It's absurd to expect that something demanded by a EULA is followed when technology and common practice permit otherwise," Sinnreich said. "Microsoft is banking on ongoing consumer naivete and goodwill. There will be a backlash against DRM in some not-so-distant future."
Would anyone have bothered?


Will encouraging consumer virtualization result in a major uptick in piracy? Not anytime soon, say analysts.


One of the main obstacles is the massive size of VMs. Because they include the operating system, the simulated hardware, as well as the software and/or multimedia files, VMs can easily run in the tens of gigabytes, making them hard to exchange over the Internet. But DeGroot says that problem can be partly overcome with .zip and compression tools -- some, ironically, even supplied by Microsoft itself.


"It's the kind of idea that is out there among the enthusiast community for file sharing and remixing, but it's not part of the standard arsenal for the average college student," Sinnreich said.


Gartner's McGuire agrees: "Unless virtualization is more convenient and reliable than P2P, then no one is going to go to the trouble."

Saturday, June 23, 2007

Authors Pick Of The Week

Would you like to keep track of all the news, and articles that are going around on the Internet? How about keeping track of the weather in your area? Or simply keeping track of this blog? Well here is my pick of the week.

This Weeks Winning Pick is:
http://www.netvibes.com/

This is a rss/xml tracker or news page as i call it. It can keep track of your email, your local weather, your favorite news websites, this wonderful blog, PC news websites etc...

I picked it because its very simple to edit, and keeps me very organized. All you need to do is create a account, and you don't even need to activate it!

I just ask one thing, that i only suggest you do, add my blog,
http://windowscorp.blogspot.com/feeds/posts/default

Hope you like my pick of the week!

Enjoy,
- HotShot

Microsoft Sues More Hotmail Spammers

Microsoft files suit against a company and individuals accused of sending debt relief and porn spam to Hotmail accounts.


Robert McMillan, IDG News Service
Saturday, June 23, 2007 9:00 AM PDT


Microsoft Corp. has filed two lawsuits over the past weeks, looking to crack down on spam on its Windows Live Hotmail network.


The "John Doe" lawsuits were filed against unknown alleged spammers who had been sending large quantities of spam advertising debt relief and adult Web sites to Hotmail accounts.
Microsoft alleges that a company doing business under the name Consumer Solutions Network sent "misleading, deceptive, and unsolicited commercial e-mails advertising debt relief help to Windows Live Hotmail account holders."


The spam contained subject lines such as "Michelle, accounts over the limit," or "Robert, Payment not received," the suit alleges.


Consumer Solutions Network, which could not be reached for comment on this story, operates several Internet domains including myfinancialsolutions.org, consumersolution.org, and financialsolutionsonline.org, according to Microsoft.


Microsoft has also sued unnamed defendants for sending spam that promoted pornographic Web sites through Hotmail. Microsoft claims that these spammers not only flooded Hotmail accounts with unwanted messages, but also used Hotmail itself to send large volumes of spam. "Many of defendants' illegal e-mail messages were sent using... accounts obtained through false or fraudulent pretenses," Microsoft claims.


Companies like Microsoft, AOL LLC and Earthlink Inc. have launched a large number of these lawsuits in recent years, said Venkat Balasubramani, the principal of Balasubramani Law, and author of the Spam Notes blog. "They serve a deterrent purpose and they also can be a mechanism for investigation. You can issue subpoenas and dig around a little bit to find what's going on," he said.


Microsoft has filed such lawsuits on an almost-monthly basis over the past year, he added.


In April and May of this year it filed similar lawsuits against several alleged stock scammers.


These latest lawsuits were filed in King County Superior Court in Seattle. The Consumer Solutions Network lawsuit was filed on June 13. The suit relating to pornographic spam was filed on Tuesday of this week.

Friday, June 22, 2007

Microsoft Kills Longhorn Reloaded Project

Microsoft has forced developers to close down a project to revive the original Windows client code-named "Longhorn."

Microsoft Corp. has forced developers to close down a project aimed at reviving the original Windows client code-named "Longhorn."

According to a blog posting on the site maintained by developers on the project -- called "Longhorn Reloaded" -- Microsoft sent a "cease and desist" letter to the project leaders asking them to shut it down shortly after the team posted the first release of the project online.

"It deeply saddens me that although Microsoft have known about this project for many months they only issued us with this notice a few days after we started to distribute" the first release, according to a post earlier this month on joejoe.org.Community. "I am just as sorry as you guys are about this, but we got [sic] to think about the community as a whole first."

Longhorn Reloaded Milestone 1 was released May 19 on the project's Web site, but the post informing users the project has shut down said download links and any threads about the project will no longer be active.

Through its public relations firm, Microsoft said that though the company "actively encourages and supports independent developers to take advantage of the features available in our platform to create their own applications and services," the Longhorn Reloaded project violated Windows end-user licensing.

Windows enthusiasts decided to pick up where Microsoft left off with Longhorn's development in October 2006. Microsoft had originally called the client release that became Windows Vista "Longhorn," but switched development plans and names mid project, though the company continued to use the Longhorn name for the next Windows Server release. That release has since been renamed officially to Windows Server 2008.

The Longhorn Reloaded began the project with a build called Windows 6.0.4074, which Microsoft released at its Windows Hardware Engineering Conference in 2004. Microsoft never said it actually abandoned the Longhorn client, and many predicted that when the Longhorn Reloaded project began it likely would run afoul of Microsoft's legal department.