Tuesday, 6 September 2016

VMware Workstation - Internal Error when Starting Virtual Machine (VM)

Upon opening VMware Workstation and attempting to power on any virtual machine I occasionally get the error below, stating "Internal Error."



The fix for this in my experience has been to start the VMware Workstation Server service. To view your services press the Windows Key + R (to open the Run prompt) then type services.msc and press Enter

As you can see, even though it is set to "Automatic", for whatever reason it doesn't always start automatically - usually after the computer has been restarted.



Simply right click the service and select "Start". Once the service is started you should be able to power on your VM's from VMware Workstation.

Monday, 5 September 2016

Backing Up Your PC/Computer for Free

With the relatively low cost of computer storage (hard drives) these days, and the ever increasing risk of viruses and malware infections, there's really no excuse for not backing up your PC to an external hard disk drive on a regular basis.

Having a full backup of your computer ensures that all those important files you have on your computer (think photos, songs, documents, spreadsheets etc) are able to be recovered/restored in the event of a serious problem. Such problems could be a virus or malware infection (as previously mentioned), or your computer/laptop being lost, stolen or damaged, or could even be a random hard disk drive failure that can happen from time to time.

One of the best and easiest backup solution products available that is absolutely free for home/personal use is a product called Macrium Reflect. In this blog post I'll be outlining the process for downloading, installing and configuring Macrium Reflect to backup your computer.

Macrium's process for backing up is referred to as "imaging". It essentially takes a snapshot, or "image" of everything on your hard drive and stores it into a large, compressed "image" file.

Before we begin though, you will need an external hard disk drive (USB connected) for your backup to be stored on. These can be bought from any computer or technology store. A 1TB drive would typically be large enough to backup everything on most personal computers, but large drives are available if required.


  1. To begin the installation, open your web browser and go to http://www.macrium.com/reflectfree.aspx and click the "Download" button at the top of the page. Select the option for "Home Use" if prompted.
  2. A file called ReflectDL.exe will now begin to download. Once the download is finished, run/open the file to begin the installer
  3. Ensure the option for Free/Trial software is selected (it should be by default). All other default options can remain. Click the "Download" button to begin the download.


  4. Select "Yes" to proceed with the download. Note that the download is quite large and can take some time to complete (depending on the speed of your internet connection)
  5. The installer will automatically launch once the download is completed. Click the "Next" button to begin
  6. Click "Next" again to proceed past the welcome page and begin the installer
  7. Select "I accept the terms in the license agreement" and select "Next"
  8. Your macrium reflect free license key is automatically generated and displayed here. Click "Next" to continue


  9. Registration is optional. For the purpose of this tutorial we will select "No" then select "Next"


  10. Leave the default installation options then click "Next"


  11. Click "Install" to begin the installation then click "Finish" to complete the installation when prompted


  12. A shortcut to the Reflect application should have been placed on your desktop. Double click the icon to launch Macrium Reflect


  13. From the main Reflect window, ensure you are on the "Create a backup" tab. Select the disks/drives you wish to backup then click the "Image this disk..." option. For this example, we will only be imaging/backing up the C:\ (system drive). If you have multiple disks/drives you can select them from this screen.


  14. Select the destination folder for where the backup image file is to be kept. This should be the external hard drive you have connected to your computer. In this example, my external hard drive has drive letter G:\ assigned to it, and I'll store the backup in a folder called "Win10Backup" on the G:\. Click "Next" to continue


  15. From the next screen you can select a retention or schedule/policy for your backups. You can click the "Add Schedule" button and select the option for "Full". I recommend running a full backup on a weekly basis. Schedule the backup to run on a day/time where the computer is not being utilised (the computer will need to be left switched on for the backup to run). For this example, we'll schedule to run on Monday mornings at 2:00am




  16. Uncheck the options to "Define Retention Rules" and set the option to "Purge the oldest backup set(s) if less than 500GB remaining". Click "Next" to continue


  17. Review your settings and click "Finish" to complete the process
  18. Uncheck the option to "Run this backup now" then click "OK" to save the backup definition file you've just created


  19. You will now be taken to the "Backup Definition Files" tab where you can see the backup definition you have just created. From here you can make amendments/adjustments to the backup file if required


  20. From the "Scheduled Backups" tab you can also review the schedule for your backups and can make amendments if required



    Depending on the size of your hard drive(s) and the amount of data on them, it can take several hours for a backup to complete.

    Once a full backup has completed, you can check for a .mrimg file in the backup location you specified in Step 14 (above). If there is a file in this folder then you have successfully backed up your computer to an image file!



    Stay tuned for my next blog post where I'll run through the process of restoring/recovering files from a backup image file.


Monday, 15 August 2016

Cryptolocker & Ransomware Viruses - Information, Recovery & Prevention

One of the biggest bains of today's IT professionals is a relatively new breed of virus called "Cryptolocker". It is a type of ransomware that essentially takes your files hostage by encrypting them (when they are encrypted, your are unable to view or access them). The virus creator then demands payment for the "key" to decrypt these files.

These viruses are incredibly nasty, and it seems that most antivirus applications cannot stop them, or simply cannot keep up with the increasing number of variants of the virus. Given the money that antivirus companies charge for their applications, I'm not sure why they still seem unable to combat them, and find it frustrating that they don't.

So how do you get infected with a cryptolocker/ransomeware virus? In most cases users are tricked into running an application that contains the malicious code that encrypts your files. The application is normally sent as an attachment, or link/URL pointing to the application that is cleverly disguised as something else.

Some of the emails I've seen are from Australia Post, advising of a missed parcel delivery. From AGL sending you a link to your latest "Electricity Bill", or the Australian Federal Police with a link to a supposed speeding fine. Of course the best defense to these sorts of things is vigilance and common sense, and simply not opening these emails. Scrutinise everything is my best tip. There are normally a few things you can check/test if you're unsure about the legitimacy of an email you've received;

1. Emails sent from large companies like Australia Post, or AGL, will have a "From" address that contains their business name (eg. notifications@australiapost.com.au, or billing @agl.com.au). These cryptolocker emails will not have these full email addresses (see example below)



2. As I mentioned, common sense also plays a big part. Were/are you expecting a parcel/delivery from Australia Post? In Australia, speeding fines aren't issued via email, and they certainly aren't issued by the Australian Federal Police. And is AGL even your electricity provider? If you're not sure, you can always call these companies directly to check. A single phone call could save you alot of time, money and heart ache.

3. The emails will often have spelling or grammar mistakes which is a sure sign they are not legitimate.

If you do get infected with one of these encrytion viruses, in my experience it is unlikely (though not impossible) that you'll be able to get your files back, unless you are able to restore from a backup. Chances are by the time you realise you've been infected, all the files on your computer will be encrypted and no longer accessible.

You can quickly tell because the extension of the encrypted files will change to .encryted or .enc. A popup message will usually appear as well advising you that your files have been encrypted, and will provide a link/instructions on how to decrypt your files (via payment to the virus creator). The virus will scan all the files/folders on your computer, as well as any network/shared drives you have access to and encrypt all files it can find.

Decrypting your files
The following link contains some information/applications you can use to check if your encrypt files are recoverable. As previously stated, there are a large number of "variants" of the cryptolocker virus, some of which are able to be "cracked" using a special utility. You will need a copy of an encrypted file, and the unencrypted version of the same file in order for the process to complete. You can upload a sample and locate recovery tools (if available) from the below website:

https://id-ransomware.malwarehunterteam.com/identify.php

You can also follow this next link which has a full, detailed guide on removing cryptolocker, or other ransomware/malware from your computer if you do get infected. (Note that removing the virus/infection will not unencrypt or recover your files.)

https://malwaretips.com/blogs/malware-removal-guide-for-windows/

Backup Strategies
In my next blog post I will be outlining a free and easy way to implement a backup solution on your home laptop/PC. With the low cost of removable storage (eg. USB hard drives), and the increasing amount of personal photos/files stored on computers, a regular computer backup is a must do for all computer users!

Friday, 28 March 2014

Check/Monitor Website URL with Powershell

Windows Powershell has a built in web request module that you can use to test/check the availability of website URL(s).

The full script to do this is below;

[string] $url = "http://www.google.com"
[net.httpWebRequest] $req = [net.webRequest]::create($url)
$req.method = "HEAD"
[net.httpWebResponse] $res = $req.getresponse()

The first line is self explanatory - simply put in the full URL for the website you wish to check. In this example we will be checking http://www.google.com

[string] $url = "http://www.google.com"

The second line is where we create the actual web request instance in Powershell - under the $req variable

[net.httpWebRequest] $req = [net.webRequest]::create($url)

On the third line, we change the request method to be "HEAD" which means that only header information for the requested URL is retrieved. This speeds up the web request process as it does not pull all the data from the web URL - only the header information. If you leave this line out, the default method is "GET".

$req.method = "HEAD"

On the last line we actually submit the web request, and store the response in the $res variable

[net.httpWebResponse] $res = $req.getresponse()

For a successful web request, the response should look something like this:

IsMutuallyAuthenticated : False
Cookies                 : {}
Headers                 : {Cache-Control, Content-Type, Date, Expires...}
ContentLength           : -1
ContentEncoding         : 
ContentType             : text/html; charset=ISO-8859-1
CharacterSet            : ISO-8859-1
Server                  : gws
LastModified            : 28/03/2014 10:24:19 AM
StatusCode              : OK
StatusDescription       : OK
ProtocolVersion         : 1.1
ResponseUri             : http://www.google.com.au/?gfe_rd=cr&ei=I7M0U5P_BenC8gfRvIHADg
Method                  : HEAD
IsFromCache             : False

Based on this, you could check the statuscode or statusdescription properties of $res to make sure the value matches "OK".

Alternatively, if you enter an invalid URL for a website that doesn't exist, you will get an error, and the value of $res will be $null. The error you get will be something along the lines of;

Exception calling "GetResponse" with "0" argument(s): "The remote server returned an error: (502) Bad Gateway."
At line:4 char:46
+ [net.httpWebResponse] $res = $req.getresponse <<<< ()
    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : DotNetMethodException

Wednesday, 26 March 2014

Get Folder Size (including subfolders) with Powershell

The method for obtaining the size of all items within a folder using Windows Powershell is unfortunately not as straight forward as it probably should be. The method outlined below is very useful for querying multiple folders to determine the size of all items inside, including all subfolders and files.

$dir = "C:\temp"
$totaldirsize = (get-childitem $dir -recurse -force | measure-object -property length -sum)

The first variable sets the directory that we wish to query - in this example it is C:\temp.

Next, we use a get-childitem to query the directory. The -recurse and -force switches mean that all sub directories and files are also included. We then pipe the results to measure-object and calculate the length of each child item (which is actually the size in bytes) and use the -sum switch to add them all up.

If you run the above command, and then look at the $totaldirsize variable, you will see something like below;

PS C:\> $totaldirsize

Count    : 38
Average  : 
Sum      : 51652089
Maximum  : 
Minimum  : 

Property : length

So from this we can see there are 38 items in total in the C:\temp directory, and the sum of all files is 51652089 bytes. To make this more useful, we can easily convert this value to KB, MB or GB

$mbsize = $totaldirsize.sum / 1MB

If we now look at $mbsize, we'll usually have an integer with a large number of decimal places. In this example, the result I got was 49.2592706680298. So as a final step, I'd like to round this number to 2 decimal places

$mbsize2 = "{0:N2}" -f $mbsize

Now if we look at the value of $mbsize2, the result is 49.26.

You can change the 2 in {0:N2} to any other digit to round the number to that many places after the decimal point.

Working with Windows Services in Powershell

We can use the get-wmiobject method in order to retrieve properties of windows services on local or remote servers.

The query below is an example on how to get the properties of the Print Spooler service on a local machine (ie. the same machine that the script is being executed on)

To get the "Service Name" of a windows service, go to services.msc, select a service, open it's properties (right click > Properties) and look at the "Service Name" at the top. 

$serviceprops = get-wmiobject -class win32_service -filter "name='Spooler'"

If we then run $serviceprops we get the following information;

ExitCode  : 0
Name      : Spooler
ProcessId : 1628
StartMode : Auto
State     : Running

Status    : OK

This information could therefore be used to check the respective windows process ID, start mode, state and status of a service

The query below is an example on how to get the properties of the Print Spooler service on a remote machine (server1)

$serviceprops = get-wmiobject -computername "server1" -class win32_service -filter "name='Spooler'"

As you can see, the command is mostly the same, we have simply added the argument "-computername "server1"" to make the get-wmiobject query run on the remote server.

We can then take this one step further and perform an action (aka method) on a service, such as starting or stopping it. To view the available methods for the service, run a get-member on the $serviceprops variable;

$serviceprops | get-member

You will then see a list of available methods (and properties) for the variable.

Two of the most common methods for a service would be to start or stop the service. We simply append the respective methods onto the end of the $serviceprops variable (after it has run the get-wmiobject query above to get the service properties).

To start a service;
$serviceprops.startservice()

To stop a service;
$serviceprops.stopservice()

Friday, 3 May 2013

Adding Multiple Users to 'Accept Messages Only From' - Exchange 2007

Exchange 2007 has a feature that allows restrictions to be placed on a distribution group (I call them "distribution lists", or "DL's") that control who is allowed/permitted to send messages to them.

The Exchange Management Console enables you to search and add individual users to this list, but I found the process can be very slow and tedious, especially if you want to add a large number of users to this list, or want to add users to multiple DL's.

For this reason, I created the below script. Others who may have tried this using a simple "Set-DistributionGroup" command would have found that every time they tried to add a user it replaced any users who were already in the list. This script queries the already existing users and appends/adds the new user onto the already existing list. You will need to provide a list of users either within the script, or by importing a simple .txt file with a list of users you wish to add. For this example, I will use a .txt file.

The .txt file contains a simple list of users with a single name on each line;

firstname.lastname@domain.com
test.user1@domain.com
example.user2@domain.com

And here is the script:

#Name of Distribution Group/List to add user(s) to
$TargetDL = "DL_Test"

#Domain Controller Name - must be used to ensure each user is appended and not replaced. 
$DC = "domaincontrollername"

#Import List of Users to add from .txt file
$UserListFile = "C:\UserList.txt"
$UserList = Get-Content $UserListFile

#Cycle through list of users and add them to 'Accept Messages Only From' list for DL
ForEach ($User in $UserList)
     {
     Set-DistributionGroup "$TargetDL" -AcceptMessagesOnlyFrom ((Get-DistributionGroup -DomainController "$DC" -identity "$TargetDL").AcceptMessagesOnlyFrom + "$User") -DomainController "$DC"
     Write-Host "$User granted permission to send to $TargetDL"
     }


Replace the $TargetDL, $DC, and $UserListFile variables with the relevant information for your Exchange environment