We've moved!

TechKnack.blogspot.com has officially moved to TechKnack.net. You should be redirected in 3-5 seconds. Thank you.
Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

May 27, 2008

Second Look at "Official" XP SP3

Add this post to Del.icio.us. Del.icio.us (0 saved)

Last post I detailed how I installed Windows XP Home SP3 on my long-distended Windows installation, only to find a couple rather major issues. Here's the follow-up.

I successfully removed SP3 (after clearing yet more space - it needs 376MB just to uninstall!). Upon the mandatory reboot, I first attempted to login to my limited user account, only to find that it had the same problem initiating explorer.exe, so I assume that that problem was present before I installed SP3 in the first place.

I logged into my Root account (still SP2, mind you) and found that I could use my themes as I wished. So far, so good.

I then went to the Microsoft Update website, planning to download the update through that. As the "download" progressed, however, I decided it was going too slow and did some searching for alternative means of installation. I found the Network Installation, roughly 316MB. Click the download link, select "run", and wait. When the download was completed, I went through the steps of installing SP3 and rebooted.

At this point, I didn't even worry about my virtually lost Limited User account; best to just copy it to a new account and get rid of it. Logging back into my Root account, I was pleasantly greeted with the Silver Luna theme (I had switched to the default Luna theme and changed colors to silver before installing). I located and downloaded a UXTheme patch for SP3, applied it, rebooted (again!!), logged in, and checked out my theming capabilities. I was greeted with full theming glory.

So, one of the most common Windows Troubleshooting Tips fixed my issues: "If it's messed up, reinstall."

Now that that issue's fixed -- back to linux!!! :)

May 26, 2008

First Look at "Official" XP SP3

Add this post to Del.icio.us. Del.icio.us (0 saved)

A couple days ago, I booted into my Windows XP Home installation (yes, blasphemy, I know) in order to pull some pictures off of a Sony Memory Stick, since Ubuntu doesn't seem to recognize the card when I plug it into my card reader. In the course of performing the Windows Updates that I had long been delinquent on, the MS Update site offered to let me download and install Windows XP SP3. I had some free time so, heck, why not?

Since my switch to nearly-all-linux, I had shrunk my Windows partition down to the minimum to hold all the programs I had installed, the OS itself, and about 1 GB of free space. Seems my 1 GB had been reduced in my sparse Windows use; the SP3 download required roughly 370MB, and the installation another 370MB, and I had to find just a tad more free space. :)

After the install (and the ever-needed reboot), there were a couple major problems with my computer. Most major was the complete destruction of my theme capabilities. I'm quite fond of the infamous UXTheme hack; however, after applying the hack for SP3 (and probably before, but I'll have to check), I could not use any UI themes, not even the default Luna theme. I kept getting an error that the theme couldn't load because the file couldn't load... The visual styles could not be loaded because the file failed to load.  Details:

As tragic as it is that I could not use any window themes, at least I can still use the computer. Well, my Root account, anyway; my limited user account threw an error when I logged in saying that explorer.exe couldn't initialize properly. Clicking the OK button continued the login process, only to login to a completely empty desktop. Explorer failed to load, which in turn kept the desktop, taskbar, etc from loading. I was able to pull up the Task Manager, but attempting to start Explorer.exe from the new task option threw the same error. The aplication failed to initialize properly (0xc0000022). Click on OK to terminate the application.I was able to "work around" this major issue by creating a new limited user account (which logged in perfectly fine), but I ended up running out of space while attempting to copy the Docs & Settings directory from the old account to the new account.

Turns out SP3 is placed in the Add/Remove programs list. I'm going to uninstall SP3, check if any of these problems reoccur under SP2, then try re-installing SP3 and see if it works any better. Maybe I messed something up during the install. Or maybe SP3 isn't ready for the masses yet.

April 16, 2008

Easy Linux-to-Windows File Sharing

Add this post to Del.icio.us. Del.icio.us (0 saved)

Samba has long been the defacto standard for accessing Windows file shares from Linux. However, there is also a Samba daemon (background service) that, if configured correctly, plays the reverse role -- sharing Linux directories to Windows machines. Unfortunately, proper setup requires you to edit the /etc/samba/smb.conf file, which, like most configuration files, can be rather cryptic.

Enter the GUI solution: system-config-samba. That's the package name in the Ubuntu universe repositories, I don't think the program itself has a proper name other than "Samba" (also check out the Fedora project wiki for the app). It's a sparse little app that gives you GUI access to the settings of the smb.conf file. Once you get the behind-the-scenes details set, though, adding shared directories is a snap.

First make sure you have samba installed (package "samba" in Ubuntu repos). Next, install the samba config package - "sudo aptitude install system-config-samba". The installation should put an entry called "Samba" in your Ubuntu menu (for me, using Kubuntu, it's under "Settings"). If you can't find it there, you can start it from a command line by running "system-config-samba &". Before the program starts, it will ask for your administrative password (same as your sudo password, unless you've changed something around).

Once at the main window, You can begin to appreciate how simple SCS makes configuration, using three main buttons that are very self-explanatory, along with a simple list of currently shared directories.

Before you start sharing, you'll want to setup the basic, general details. Open Preferences -> Server Settings. In the Basic tab, set your Workgroup (the default for Windows machines is usually "MSHOME" -- make sure all your computers use the same workgroup name, to avoid issues) and the computer description. In the Security tab, you set the sharing settings. For my home network, which sits behind a router, I use the "Share" authentication mode and set the guest account to my account, to allow open access to my shared directories. Once that's done, click OK. The program may seem to hang for a second or two - this is just the program restarting the Samba daemon for you, and happens everytime you change the settings for Samba or for a share. Next, setup a new share. I have a separate partition that contains all my music ripped from CDs. Within Kubuntu, I mount this partition as read-only, and remount it as read-write only when I need to modify the files (for example, add new rips or coverart). Here I'm sharing it to "everyone", read-only, under the name "music". Check out nixCraft for a quick rundown on Samba permissions.

If everything is right, you should now be able to access the Samba share from a Windows machine on the same network. I haven't tried this method for accessing the share from a Mac, but presumably you can use the same methods you would use for accessing a Windows share.

April 1, 2008

IE8: In Like A Lion, Out Like A Lamb

Add this post to Del.icio.us. Del.icio.us (0 saved)

Here it is, the end of March, and I just couldn't help but notice how little has been said about IE8 lately. When the first beta was publicly released amidst the MIX08 madness, you could almost feel the blogosphere shuddering with the news. The tremors were discernible for what...a week? Maybe two? Then all became silent once more. Is it just that it's Microsoft, and everyone's tired themselves out with the extra efforts put toward M$-bashing that week? Or is it because everyone and their mother (and their dog, to top all) reviewed the thing like no tomorrow, and our eyes have grown weary of the Blue E? (if your eyes are, indeed, weary of the Blue E, don't click that link)

Whatever the reason, I just thought I'd note that the famous March proverb seemed to apply to IE8, with about the same timing. Perhaps we'll hear more about it (both bashing and praise) when it goes stable?

March 4, 2008

IE Team Changes IE8's Default Behavior

Add this post to Del.icio.us. Del.icio.us (0 saved)

Just yesterday, the IE Team announced that they will be changing IE8's default behavior. Instead of the previously decided default of "IE7 Mode", IE8 will default to "IE8 Mode" with the option to switch to IE7 mode with the X-UA-Compatible meta tag. Web developers rejoice!

Additional links:
QuirksBlog: IE team changes its mind on IE8 default behaviour
WebWare: IE8 to be standards compliant: Good for devs and users
IEBlog: Microsoft's Interoperability Principles and IE8

Diggables:
IE team changes its mind on IE8 default behaviour
IE8 to be standards compliant by default
IE8 will render standards-mode pages as best it can

February 25, 2008

Make Word 2007 Save to .doc by Default

Add this post to Del.icio.us. Del.icio.us (0 saved)

While the MS Office 2007 GUI is nice (and maybe even a tad more usable), the (relatively) new docx file format is so proprietary, it's not even funny. Can Office 2003 users open it? Not without the Microsoft-developed "compatibility pack". Can OpenOffice users open it? Not without installing a non-standard file handler for the program (there are instructions for installing this on linux-based systems). Using the format is well and good among 2007 users...but what about when you email that docx writeup (due tonight, no less) to your professor, who uses only OpenOffice? Oops.

The main problem is that the docx format is fundamentally different in composition from the good ol' doc format. The doc format was your standard binary file format, much like image files and executables; essentially, they are text surrounded by Word-readable formatting instructions.

The docx format, on the other hand, is a zip file containing other files that describe the contents, formatting, embedded objects, and everything else the docx file holds. According to Microsoft themselves:

To open a Word 2007 XML file
  1. Create a temporary folder in which to store the file and its parts.
  2. Save a Word 2007 document, containing text, pictures, and other elements, as a .docx file.
  3. Add a .zip extension to the end of the file name.
  4. Double-click the file. It will open in the ZIP application. You can see the parts that comprise the file.
  5. Extract the parts to the folder that you created previously.

Regardless of the differences, though, the mass switching from one format to another caused by the widespread adoption of Office 2007 is nothing less than inconvenient for those users not using the new Office. You can help by setting your copy to save to the compatible doc format by default :D . After starting Word 2007, go to Orb->Word Options. Select the "Save" tab on the left, and choose "Word 97-2003 Document (*.doc)" for the "Save files in this format:" option. Then click the OK button. From now on, anytime you select Orb->Save, Word should offer the old .doc format as the default format to save to. Hail compatibility!

February 10, 2008

An Alternative to IE8's "Opt-in Standards Mode"?

Add this post to Del.icio.us. Del.icio.us (0 saved)

There's been a lot of opinions expressed about the IE team's introduction of the X-UA-Compatible HTTP header (or, in most cases, a meta tag in the html), otherwise known as Opt-in Standards Mode, with IE8. Most of the opinionators seem to be opposed to the "switch", while a few (PPK of QuirksMode and Aaron Gustafson of AListApart amongst them) have already embraced it. But is there a better way?

Ideas

Reading through user comments on PPK's post, I came across some interesting ideas. BARTdG said

...I think they should solve this problem by adding a "Does this site look odd?"-button (to switch IE8 into IE7-mode)...

And Michiel van der Blonk said

I see a different scenario possible. MS ships the new IE8 with full forward compatibility mode (edge) as a default, as all standards aware developers expect it. But, they also deploy a 'crippled' version of IE8 that has all the security features and what not but will render using the IE6 engine.

Tino Zijdel:

If the problem lies mainly with IE-centered intranet apps then why doesn't MS offer a special fabriqued 'Intranet Explorer'?

An alternative?

What if standards-compliant rendering were placed in the hands of the users?

I mean, this is pretty much the case now, what with people having a choice (most of the time) between using IE6, IE7, FireFox, Opera, Safari, Konqueror, and more. Those ignorant of their options will use what they're given, IE7 (or IE8 with the default mode). Why not leave whether or not IE8 renders properly as an option for the user to invoke?

Suppose IE8 ships with two rendering engines (which is how it looks anyway): IE7's current engine, and IE8's new engine. IE8 Standards Mode could be the default engine, which perhaps degrades to IE7 Quirks Mode given a lack of Doctype. Then suppose that there is a button (or menu item, or statusbar icon, or etc) which allows the user to switch to back to IE7 rendering mode (Quirks/Standard, depending on doctype presence). What could the implications of this be?

Possible issues

Breaking the web

If IE8 mode is the default engine, then IE8 will, by default, "break the web". However, most people have noted that the main recipients of this breakage will be company intranets. I've never maintained an intranet before, but surely it wouldn't be too difficult to implement a "switch" of some sort that can easily be used to mass-switch the company's IE8 installations to use IE7 mode.

More crossover

A major concern that might arise is that we developers will have to develop for both IE7 mode and IE8 mode, to cater to all users. So, what exactly are we doing now? Well, those aiming for cross-browser compatibility are still developing with an eye on IE6, as well as IE7, FireFox, etc. And, if the Acid2 announcement is any indication, IE8's Standards Mode shouldn't be too difficult to cater to, if the design works in other majorly-standards-compliant browsers. As Hixie puts it (albeit on a slightly different topic):

Finally, we could just... [continue] to use JS compatibility libraries for the time being, the same way that everyone has been doing for years. Authors would also have to support IE7 anyway, at least for the forseeable future, so it wouldn't be an additional cost.

Usability issues

"Oh, noes, more menu options??? You'll confuse the poor user!" Please. My favorite website looked fine in IE7, and now it won't work in IE8. What's this? A button that makes IE8 work like IE7? Cool! *click* Hey, it works now!
Even better, in the case of "mass-switched company-intranet users": My favorite website worked in IE7. I've been upgraded to IE8 which, since its been switched to use IE7's engine, still displays the site as it always has. I'm sooo happy. :D
And, honestly, if someone sees the button that says "Switch to IE7 mode", and has no clue what that means, are they going to melt down in a puddle of confusion? No. They will ignore it. If they are the initiated type, they might click it to see what it does, or go in search of someone or something that can explain it to them.

A better solution?

I believe this might be better than forcing developers to add a meta tag (or HTTP header) to their pages (or servers), just to get standards compliance. I'll code my site to standards compliance. Other sites will sit "broken" and, if the user wants, they can view those sites with or without standards compliance. Why did they not come up with this before?

Post Notes

Of course, the best thing would be to just ship IE8 with full (as full as it will be) standards-compliant mode, leaving behind the bloat introduced by carrying two or three rendering engines. Make it a user option to have either IE7 or IE8 installed or, if the user so chooses, both installed side-by-side.

If we must have a proprietary HTTP header, consider James's idea of an era-based header, though I would argue that the "current era" should be the default. Pick an era that you are (or were) compatible with, and render era-less sites with standards compliance. And, of course, let the user override the era if they so choose.

Finally, I very much like the idea of modular rendering engines. You can have whichever interface you like, further combined with whichever rendering engine you like. Want to use the customizable interface of FireFox with IE8's Acid2-capable engine? No problem. This could even be enhanced with an option to use specific engines on a per-tab basis (for those browsers with tabs); this would inevitably bloat the program (per-instance, not every time), but it would be invaluable for web developers working on Linux or Mac (Testing the same site in IE6, IE7, FF2, and Opera, all from the FireFox interface?? Cool!). I mean, how long have computer users had operating systems with alternate shell capabilities (for example, Windows and LiteStep, or, more obviously, linux and your choice of Gnome/KDE/XFCE/etc)? Why should browser users not have the same capabilities?
(This idea of modular engines was not originally mine, but I cannot for the life of me figure out where I read it originally. If anyone has a link to a place where the idea is more fully fleshed out, please do share :D )

January 26, 2008

Cleaning a FireFox profile

Add this post to Del.icio.us. Del.icio.us (0 saved)

I'm an avid user of FireFox. I've set my installation up to sync across dual-boot, mainly as part of the Widows-to-Ubuntu crossover process. I can't pinpoint the exact date I started using FireFox, but it's been years...and in those years, I've certainly gathered a fair bit of junk.

Most of that junk is leftover configuration data and files from extensions that I've tried and subsequently gotten rid of. For some reason, the uninstall process of most (if not all) extensions leaves all the about:config preferences. In the case of GreaseMonkey (yes, I do not use GreaseMonkey), it leaves a gm_scripts directory in your profile, containing all the script files you've installed. At the worst, this is simply developer oversight. "Why would they want to uninstall this great extension?? They don't need an uninstall routine!"

At any rate, I've found a short and simple way to clean your FireFox profile. The only things I did differently was 1) leave my bookmarks.html file behind (I use Netvouz :D ) and 2) copy over various tweaks from my old prefs.js to my new prefs.js. A final note: You don't want to copy the entire prefs.js file over; it'll contain all the about:config junk mentioned earlier. Either open both old and new prefs.js files and copy over specific tweaks, or google them up again and re-apply them in the new profile.

Cleaning a FireFox Profile

December 13, 2007

Reclaiming Disk Space: Windows XP

Add this post to Del.icio.us. Del.icio.us (0 saved)

Summary: Intro, Disclaimer, Apps, HowTo, Footnotes

If you have a computer with Windows XP, a hard drive less than 60 Gigabytes, and a tendency to use the system often, you may have wondered at one time or another, "What happened to my disk space?"

Granted, a quick google will give you hundreds of guides to freeing up disk space, but most of them either a) tell you to use the Disk Cleanup Utility, b) promote someone's software, or c) give no usable info. So, allow me to heap another little guide onto the pile.

DISCLAIMER: Unless you KNOW what you're doing, deleting files and folders is never 100% safe. Always search the web and ask those more knowledgeable than yourself if you're in doubt about something. That's what communities and forums are for, and the people there are (more often than not) ready and willing to give advice. Yes, even to computer-illiterate newbies.

Also, most (if not all) of the methods described here will require administrative privileges.

Alright, with that out of the way, prepare to get your hands dirty with the dark recesses of XP's filesystem.

First, an app to install that will be useful: WinDirStat. It's a nice little app that will analyze any drive attached to your computer, and show you, in a graphical format, the layout of your drive(s) in terms of filesize. To install, scroll past the Release Notes to the "Download and Install" portion of the webpage. You can download the installer package, but I prefer the standalone executable (go to the sourceforge page, dropdown the 1.1.2 section which contains all the zip files, and download "windirstat1_1_2-exe-unicode.zip". Extract this to a separate directory, and launch windirstat.exe).

We'll start with something simple: the Disk Cleanup Utility. Yes, there are a million and one guides out there on how to use this thing, but no XP cleanup guide would be complete without it*. We'll go through this quickly: Start > All Programs > Accessories > System Tools > Disk Cleanup. Select your main windows drive (C: in most cases; if in doubt, use the letter that is there by default). Click OK, let it scan the drive, which could take several minutes. When it's done, go through the list and check out what there is to get rid of. What's checked by default should be sufficient, but there may be more that you're comfortable doing. Your choice. When you're done with the list, click "OK" again, then "Yes", and let it do its thing.

Next is an easy one, too. Pull up the "Add/Remove Programs" utility from the Control Panel. Then, go through each item in the list (you may want to uncheck "show updates" in the top right, if you have it, before doing this, for sanity's sake). If you come across anything that you know you never use (that game you installed last year and haven't touched since, for example), remove it. If you're unsure about something or the name sounds weird, check google for it before uninstalling. This list can contain important hardware drivers, and you don't want to delete those. But if you know what it is and you know you don't use it, remove it. This alone can save a decent chunk of space.

When you're done in the realm of apps, open Windows Explorer (or your preferred file manager). Navigate to "C:\Documents and Settings\". This is where the data for each user account is stored. On my computer, with one admin account and one limited user account, this directory contains seven subdirectories: 3 hidden "users" (Default User, LocalService, and NetworkService), an "All Users" directory, an "Owner" directory, and two other directories for my two accounts. We'll only be touching the users' accounts.
One by one, enter each user's home directory (referred to as "C:\Docs\User\"), and go to their Local Settings (C:\Docs\User\Local Settings\). This is a hidden directory, so make sure you can see it. Under local settings, go to the Temp directory, and delete EVERYTHING. This is where programs store files for temporary usage, and, as a general rule, neither windows apps nor the OS they run on are very good at cleaning themselves up. Once done there, head up and over to Temporary Internet Files (another hidden directory). This is the browsers' (plural, for those with more than one) cache and, normally, it's safe to delete everything here. The only reason you would want these files would be to work offline. The same is true of its sibling, the History directory, and C:\Docs\User\Cookies (though you may not be able to delete the index.dat file in the Cookies folder).

Once you've done that for every user, head to each user's Application Data directory (C:\Docs\User\Application Data\). This part is tricky. The directory you're now in is where applications hold their "permanent" data. Unfortunately, this data can be a little too permanent, since it even hangs around after you uninstall the corresponding program -- and it's found under every user's directory, whether the contents be unique or identical. Basically, you can go through this directory and delete any folder that relates to any program you've uninstalled. Programs which download or archive data (especially Google Earth and Google Desktop) seem to take a very large chunk of space in this area. Again, if you're unsure, google it. Once you've finished this directory, do the same for C:\Docs\User\Local Settings\Application Data. Fortunately, this second directory seems to be a less popular data-storage spot.

If, in your forray of deletions, you get an error saying "Cannot delete <foldername>: Access is denied", first make sure you're admin. Then, right-click the offending folder and select Properties. If the "Read-only" box is checked (or semi-checked, as the case may be), uncheck it and try again.

Once you've deleted all you want, make sure to empty all Recycle bins. Each user account has its own Recycle bin. They are all accessible at C:\Recycler (sometimes C:\Recycled). With admin privileges, enter into each subdirectory of C:\Recycler and delete all files (after checking in with the corresponding owners, of course!)

I've found the Application Data directories to be the more space-hungry directories. It depends on what kind of usage the system receives, of course. Altogether, using this method of cleanup, I saved about 2.7GB. That may not be too much in terms of today's hard drives, but it's 2.7 gigabytes I'd rather not have holding useless data ;)

As a last note, also run a defragmentation program once you've cleaned house. This can save a few more megabytes of space, as well as tidy up all your data. One program that I've found to be very good at this is JkDefrag. The downside is it doesn't have much configurability (automatically runs through all attached drives, last I checked), but it definitely compacts the data nicely.

* Unless, of course, that guide leads you to manually deleting everything that the DCU would do automatically.

October 10, 2007

Running .msc files with runas

Add this post to Del.icio.us. Del.icio.us (0 saved)

According to Google Analytics, I've gotten quite a few search hits regarding running .msc files (such as services.msc) under a Windows Limited User account using runas. I mentioned in a previous post that there was no way to do this without using a workaround. I'm sorry. I was wrong.

Apparently the mmc program accepts command line arguments. Typing "mmc services.msc" brings up...the services dialog! I tested it with a few other msc files in the C:\Windows\system32 folder; some of them work if you provide the name of the file only (such as services.msc), but all will work if you use the absolute path to the file (C:\windows\system32\services.msc).

And the best part...this method works with runas! Just be sure you put quotes around the mmc command:

runas /user:{admin} "mmc {path\to\msc_file}"

Enjoy!

October 9, 2007

Virtual Desktops - not just for *nix systems

Add this post to Del.icio.us. Del.icio.us (0 saved)

Wikipedia:
In addition to what is provided by the computer's physical hardware display, virtual desktops provide a "virtual" space, in which the user can place their applications' windows. Each virtual desktop occupies a defined portion of the screen arranged in a matrix or grid. Application windows and icons can be moved between desktops, increasing a user's ability to organize their windowed applications that are currently running by reducing clutter.
According to Wikipedia (the biggest source for popular knowledge), Virtual Desktops were first introduced in 1985 by the Amiga operating system. I've never heard of Amiga, but Linux systems have had "native support" for virtual desktops since the GNOME and KDE environments introduced the idea (date unknown). Boot up almost any Linux Live CD, and you are guaranteed at least two virtual desktops to play around with. Apple recently integrated virtual desktops as "Spaces" in Mac OS X Leopard. Complete with a shiny interface for switching back and forth between spaces. Windows...has yet to catch up. Per usual. On the bright side, however, there are many third-party programs that allow the Windows user to have VDs. Most of these programs are free, many are GPL, and all have at least one problem. You can try out the entire list from Wikipedia until you find one that works for you, but my preference is Compass. Compass is "dead" since 2001, as the author puts it, but its code is available under GPL. This is very fortunate, since I believe it could still use some work. But before I go on, here's the feature list from the webpage:
  • Themeing - 3 themes and a template included
  • Multi-desktop support - Not limited to 1 pager
  • Multi-quadrant support - Have as many virtual desktops as you want
  • Want your pager to be always on-top? on-bottom?
  • Move windows around using the pager window
  • Mark sticky windows
  • Hotkey support
Theming capabilities are always a plus (and the template is a PSD file, compatible with GIMP). I haven't tried the multi-desktop support, but it sounds like a nice feature for those with dual-monitor setups. As many desktops as I want? Nice. The always-on-top-or-bottom feature is nice, but this can cause problems. Move windows from desktop to desktop using the interface - very useful. Sticky windows; good for keeping WinAMP, various Yahoo! widgets, and RKLauncher on every desktop. Hotkey support; what keys do you switch with? Ctrl+Alt+Arrow? Win+Arrow? F? Spacebar? While the app still works under Windows XP (dunno about Vista), it is lacking in a few features that would make it near-perfect:
  • Autohide: the always-on-top feature is nice, but without an autohide feature, it tends to get in the way at times.
  • Any-desktop window moving: you can only move windows from the current desktop to another desktop; inactive desktops are automatically switched to when you click, there is no way to drag windows amongst inactive desktops.
  • It touched my registry! While I don't mind a program storing settings in my registry if I've installed it, an app like this should be getting its settings from a file (which would also make it perfect as a portable app!). If you want more than the default of two virtual desktops, you have to merge a reg file.
In spite of these shortfalls, Compass is probably the best Windows VD manager I've come across. No fancy 3D cube effects, but it works. Better yet, my feature requests shouldn't be too hard to add, given that "the code is straightforward C and Win32". This'll probably be a good summer break project for me ;) So, do you use a VDM under Windows? If so, which one? And what do you want in a VDM that isn't offered by Compass? Leave a comment!

September 17, 2007

Surviving a Windows XP Limited User account

Add this post to Del.icio.us. Del.icio.us (0 saved)

As I mentioned in my last post, it's a good idea to use a "Limited User" account under Windows XP (I haven't experienced Windows Wished'a -- erm, Vista -- so I can't speak for that OS, but chances are it's the same).

But it's so limiting!

You have to login as admin to install software, to install new hardware devices, to setup new internet connections (mostly referring to VPNs, here) -- even to install those bulky Windows Updates!

How do I deal with it?

With much exasperation, to be assured, but windows comes with tools to "make it easier". The main tool I use is "runas". This is a command line tool that takes a variety of options, and lets you run a program as a different user (including admin users). The catches: 1) you almost exclusively have to use it on executable files, and 2) you have to know the other user's password. Which isn't a problem if both user and admin accounts are yours. Also useful, right-clicking an executable file (and a few other file types) offers a "Run as..." option, which is similar but a bit more limited than the runas command line tool.

I use the runas command combined with shortcuts in my quicklaunch menus to launch Windows Explorer, Regedit, and Control Panel under my admin account. This allows me fairly convenient access to these things, though I still have to type my password, which delays access. But it's better than nothing.

To set these shortcuts up, you will need the "Secondary Logon" service to be running (the runas commands rely on this service). The Quicklaunch directory can usually be found at C:\Documents and Settings\{user}\Application Data\Microsoft\Internet Explorer\Quick Launch , where {user} is the name of whichever account you will be using. Alternatively, you can right-click on an empty spot on your quicklaunch toolbar (best is between the last icon and the drop-down arrow that shows the rest of the shortcuts) and click the "Open Folder" option, upon which Explorer will present you with the mentioned directory.

Now, on to exactly which shortcuts I use. In all of the following, {admin} will refer to the name of the admin account you will be logging in under (not your normal user account). When you see (or don't see) the "/env" and "/noprofile" switches for the runas program, they are optional for the most part:

Windows Explorer: Create a new shortcut in your quicklaunch folder and point it to C:\WINDOWS\system32\runas.exe /env /user:{admin} "explorer.exe /e,\"%USERPROFILE%\Desktop\"" This will open a new Explorer window open to the current user's Desktop folder. You can also replace %USERPROFILE%\Desktop with another folder, or, to have My Computer selected, with ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}. The escaped quotes (\") are necessary. For your reference, I've listed some other system folders that you may find convenient to have shortcuts (runas-admin or otherwise) to.

Control Panel: Create a shortcut to C:\WINDOWS\system32\runas.exe /env /user:Root "explorer.exe /e,\"::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\"" Again, you have to omit the /noprofile switch for it to work.

Registry Editor: Create a shortcut to C:\WINDOWS\system32\runas.exe /env /noprofile /user:Root regedit (If you don't understand the following paragraph, you may not even need this shortcut) The problem with using regedit through this method is that HKEY_CURRENT_USER is the admin user. You can still edit other users' accounts by finding their tree under the HKEY_USERS key. If I'm not mistaken (and on this point I very well could be), the trees (under HKEY_USERS) referring to actual users have long strings of numbers separated by dashes, the last number group being 100x (where x is a decimal [possibly hex] number).

Services, Device Manager, Event Viewer, and the like This part gets a little trickier. To pull up the system services, for example, under an admin account, I would normally use Start > Run..., then type "services.msc" and click OK. This works under limited accounts, but you can't start/stop/edit services. And, for some reason, you can't use runas with services.msc; it just won't work. There are two workarounds: 1) find the .msc or whatever file that refers to the administrative tool you want to use under the C:\Windows or C:\Windows\System32 folders, right-click, choose "Run as...", and enter your credentials, or 2) Use the Start > Run... option to run

runas /user:{admin} mmc

then, in the resulting window, File > Add/Remove Snap-in... > Add... and select/add whichever tools you want to work with. Not pretty, not easy, but it's there if you need it.

So, there you go. A few tools (derived from one tool) that I use to tweak my system as a Limited User. Hope you found it helpful, and feel free to ask questions or make suggestions (or boast of whatever tools you use) in the comments!

Also, as promised, some additional system folders:

  • My Computer: ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • Recycle Bin: ::{645FF040-5081-101B-9F08-00AA002F954E}
  • Desktop: ::{00021400-0000-0000-C000-000000000046}
  • Printers: ::{2227A280-3AEA-1069-A2DE-08002B30309D}
  • Dial-up networking: ::{A4D92740-67CD-11CF-96F2-00AA00A11DD9}
  • Fonts: ::{BD84B380-8CA2-1069-AB1D-08000948F534}
  • Internet Explorer: ::{871C5380-42A0-1069-A2EA-08002B30309D}
  • Microsoft Outlook: ::{00020D75-0000-0000-C000-000000000046}
  • Network Neighborhood: ::{208D2C60-3AEA-1069-A2D7-08002B30309D}
  • Inbox: ::{00020D76-0000-0000-C000-000000000046}
  • Subscriptions: ::{F5175861-2688-11d0-9C5E-00AA00A45957}
  • URL History Folder: ::{FF393560-C2A7-11CF-BFF4-444553540000}
  • Briefcase: ::{85BBD920-42A0-1069-A2E4-08002B30309D}
  • Internet Cache Folder: ::{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  • ActiveX Cache Folder: ::{88C6C381-2E85-11D0-94DE-444553540000}
  • Control Panel: ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}
These were taken from the documentation file for KKMenu 2.8, whose author says:
"Please note, that I have taken the list above from the Aqua-Soft discussions (thanks to hydrostereo and fireball) and I have never tested if all of the items do really work. Please e-mail me in case of any inconveniences to: <email removed>."

September 5, 2007

Why use a "Limited User" account on Windows?

Add this post to Del.icio.us. Del.icio.us (0 saved)

(Related google search) By default, any Windows XP user accounts that you create are given administrator privileges. Many people leave it this way (and some just use the built-in administrator account), allowing them to install software, modify settings, and otherwise tweak their system as their whims lead them to. Unfortunately, this also gives administrator privileges to ill-intentioned applications, malicious programs, and viruses. Operating under a Limited User account can limit the damage that an accidentally downloaded virus is able to do. Limited User accounts have limited access to the windows registry, read-only access to select system folders (C:\windows, C:\Program Files, and probably others), and non-use access to several system tools (disk defrag, scandisk, add/remove programs, add hardware, and most tools in the Control Panel). Under such lockdown conditions, viruses and bad programs can't really do much, which is good. If you need to install a program...well, you can't, but your admin account can, and you can access that account's privileges either through the runas command or through switching to your admin account. Or, if you're wanting to run an executable program (whose filename ends with .exe), there's the RunAs context menu option. If you're thinking, "Yikes...so, you basically can't do anything?" then you'd be partially correct. Unless you go through your admin account, you can't install programs, uninstall programs, or do anything short of web-browsing and document-editing. Which may be all you need, depending on your circumstances. If you need regular access to locked-down resources, but still want the added security of a Limited User account, you can do as I have and make two accounts on your machine, one for (limited) everyday use and one for admin use. And check out my post, Surviving a Windows XP Limited User account, on making this situation livable ;) As there are plenty of step-by-step guides on how to setup a new user account, I'll let Microsoft themselves guide you through the process.