<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Kent Oyer</title>
	
	<link>http://www.kentoyer.com</link>
	<description>Adventures in I.T.</description>
	<lastBuildDate>Sun, 22 Apr 2012 22:28:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/KentOyer" /><feedburner:info uri="kentoyer" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>KentOyer</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Windows 7 firewall service won’t start</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/xFcNAr7adV4/</link>
		<comments>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-wont-start/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 19:39:38 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=150</guid>
		<description><![CDATA[Problem When you attempt to start the Windows 7 firewall service you receive the following error Windows could not start the Windows Firewall on Local Computer. For more information, review the system event log. If this is a non-Microsoft service, &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-wont-start/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<h2>Problem</h2>
<p>When you attempt to start the Windows 7 firewall service you receive the following error</p>
<p style="text-align: center;"><a href="http://www.kentoyer.com/wp-content/firewall-service-access-denied.png"><img class="aligncenter  wp-image-155" title="firewall service access denied" src="http://www.kentoyer.com/wp-content/firewall-service-access-denied-300x124.png" alt="" width="300" height="124" /></a></p>
<blockquote><p>Windows could not start the Windows Firewall on Local Computer. For more information, review the system event log. If this is a non-Microsoft service, contact the service vendor, and refer to service-specific error code 5.</p></blockquote>
<p>If you look in the System Event Log, you will see event 7024 from the Service Control Manager</p>
<blockquote><p>The Windows Firewall service terminated with service-specific error Access is denied..</p></blockquote>
<h2>Cause</h2>
<p>This may be caused because the &#8220;NT Service\MpsSvc&#8221; account does not have adequate permissions on the following registry key</p>
<blockquote><p>HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess</p></blockquote>
<h2>Solution</h2>
<ol>
<li>In Registry Editor, browse to the key HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess</li>
<li>Right click <strong>SharedAccess</strong>, and click <strong>Permissions</strong>.</li>
<li>Click <strong>Add</strong>.</li>
<li>In the &#8220;Enter the object names to select&#8221; field, type &#8220;NT SERVICE\mpssvc&#8221;. Then click <strong>Check</strong> <strong>Names</strong>. The name should change to <span style="text-decoration: underline;">MpsSvc</span></li>
<li>Click OK.</li>
<li>Select Full Control in the Allow column.</li>
<li>Click OK.</li>
</ol>
<h2>Applies To</h2>
<p>Windows 7 (all versions) / Windows Vista (all versions)</p>

<p><a href="http://feedads.g.doubleclick.net/~a/-lo9ImUFBhtigQLxBaMFRmQxvbI/0/da"><img src="http://feedads.g.doubleclick.net/~a/-lo9ImUFBhtigQLxBaMFRmQxvbI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/-lo9ImUFBhtigQLxBaMFRmQxvbI/1/da"><img src="http://feedads.g.doubleclick.net/~a/-lo9ImUFBhtigQLxBaMFRmQxvbI/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/xFcNAr7adV4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-wont-start/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-wont-start/</feedburner:origLink></item>
		<item>
		<title>Windows 7 firewall service is missing</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/f1wBa1dtzW0/</link>
		<comments>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-is-missing/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 18:34:00 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Fixes]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=129</guid>
		<description><![CDATA[Problem You receive a message from the Action Center that the Windows Firewall is turned off. When you attempt to turn it on, you receive a message like this: Windows Firewall can&#8217;t change some of your settings Error code 0&#215;80070424 &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-is-missing/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<h2>Problem</h2>
<p style="text-align: left;">You receive a message from the Action Center that the Windows Firewall is turned off. When you attempt to turn it on, you receive a message like this:</p>
<p style="text-align: center;"><a href="http://www.kentoyer.com/wp-content/firewall-error.png"><img class="wp-image-130 aligncenter" title="firewall error" src="http://www.kentoyer.com/wp-content/firewall-error-300x132.png" alt="" width="300" height="132" /></a></p>
<blockquote><p>Windows Firewall can&#8217;t change some of your settings<br />
Error code 0&#215;80070424</p></blockquote>
<p>If you go into Services, you will find that the Windows Firewall service is missing. Also, the following registry key will be missing as well:</p>
<blockquote><p>HKLM\System\CurrentControlSet\Services\MpsSvc</p></blockquote>
<h2>Solution</h2>
<p>To fix this issue, copy the missing registry key from a working Windows 7 computer. If you don&#8217;t have access to another computer, download this reg file to your desktop and double-click it to import the missing key into your registry.</p>
<p><a href="http://www.kentoyer.com/wp-content/MpsSvc.reg"><img class="wp-image-140 alignnone" title="mpssvc" src="http://www.kentoyer.com/wp-content/mpssvc.png" alt="" width="71" height="72" /></a></p>
<p>Now reboot your computer and the Windows Firewall service should be started.</p>
<p>If the service still won&#8217;t start, you may have permission problems or you may have other missing services such as the <a title="Base Filtering Engine is missing" href="http://kb.eset.com/esetkb/index?page=content&amp;id=SOLN2861&amp;actp=RSS&amp;option=en_EN&amp;locale=en_US" target="_blank">Base Filtering Engine</a></p>
<h2>Applies To</h2>
<p>Windows 7 (all versions)</p>

<p><a href="http://feedads.g.doubleclick.net/~a/kBGZORV7zbCey1TYCbFqW-ld6Ds/0/da"><img src="http://feedads.g.doubleclick.net/~a/kBGZORV7zbCey1TYCbFqW-ld6Ds/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/kBGZORV7zbCey1TYCbFqW-ld6Ds/1/da"><img src="http://feedads.g.doubleclick.net/~a/kBGZORV7zbCey1TYCbFqW-ld6Ds/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/f1wBa1dtzW0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-is-missing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.kentoyer.com/wp-content/MpsSvc.reg" length="6846" type="audio/mpeg" />
		<feedburner:origLink>http://www.kentoyer.com/2012/01/15/windows-7-firewall-service-is-missing/</feedburner:origLink></item>
		<item>
		<title>How to determine who is relaying mail through your Exchange server</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/rur9a4nKSXQ/</link>
		<comments>http://www.kentoyer.com/2011/11/08/determine-which-user-is-relaying-mail-through-exchange/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 15:21:21 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=125</guid>
		<description><![CDATA[Problem If you have relay access control properly configured, only authenticated users should be able to relay mail through your server. If you are still seeing messages being relayed, then it&#8217;s possible a user account has been compromised. This will &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2011/11/08/determine-which-user-is-relaying-mail-through-exchange/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<h1>Problem</h1>
<p>If you have relay access control properly configured, only authenticated users should be able to relay mail through your server. If you are still seeing messages being relayed, then it&#8217;s possible a user account has been compromised. This will allow you to see which users are relaying mail so you know which account has been compromised.</p>
<h1>Solution</h1>
<p>Set Transport Logging to Maximum. This way the SMTP service will log a 1708 Information event which tells you which user account authenticated and which login method they used. You can use the Event Viewer to view these event log entries, filter for event ID 1708 in the Application Log.</p>
<ol>
<li>    Start Exchange System Manager.</li>
<li>    Expand Servers, right-click <em>Your_ Server_Name</em>, and then click <strong>Properties</strong>.</li>
<li>    Click the <strong>Diagnostics Logging</strong> tab, and then click <strong>MSExchangeTransport</strong> under Services.</li>
<li>    Under Categories, click the <strong>Authentication</strong> category.</li>
<li>    Under Logging Level, set the level to <strong>Maximum</strong></li>
</ol>
<p>Now the next time somebody tries to relay mail through your server, an event 1708 will be written to the Application log. The event will contain the username that was used to authenticate.</p>
<h1>Applies To</h1>
<p>Exchange Server 2003</p>

<p><a href="http://feedads.g.doubleclick.net/~a/KaO2gA_srQKjTY9uzYozomzBj84/0/da"><img src="http://feedads.g.doubleclick.net/~a/KaO2gA_srQKjTY9uzYozomzBj84/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/KaO2gA_srQKjTY9uzYozomzBj84/1/da"><img src="http://feedads.g.doubleclick.net/~a/KaO2gA_srQKjTY9uzYozomzBj84/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/rur9a4nKSXQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2011/11/08/determine-which-user-is-relaying-mail-through-exchange/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2011/11/08/determine-which-user-is-relaying-mail-through-exchange/</feedburner:origLink></item>
		<item>
		<title>Microsoft Office encountered an error during setup</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/Iy1zbUfZd60/</link>
		<comments>http://www.kentoyer.com/2011/02/17/microsoft-office-encountered-an-error-during-setup/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 03:47:15 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=121</guid>
		<description><![CDATA[If you are trying to install Microsoft Office 2007 or 2010 on a computer that has had Office installed on it previously, you may encounter the following, un-helpful, error message: Microsoft Office Professional Plus 2010 has encountered an error during &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2011/02/17/microsoft-office-encountered-an-error-during-setup/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>If you are trying to install Microsoft Office 2007 or 2010 on a computer that has had Office installed on it previously, you may encounter the following, un-helpful, error message:</p>
<blockquote><p>Microsoft Office Professional Plus 2010 has encountered an error during setup</p></blockquote>
<p>This can be very frustrating since there is no error code or anything in the message that gives you a clue what the problem is. Usually this indicates that there are fragments of a previous Microsoft Office installation left behind on your hard drive. There are a number of solutions so I&#8217;ll start with the easiest first.</p>
<ol>
<li>Delete the rgstn.lck file in the Microsoft Help folder. The location of this folder depends on your operating system and the rgstn.lck file is normally hidden so follow the instructions in Microsoft Knowledge Base article <a href="http://support.microsoft.com/kb/927153" target="_blank">927153</a>. (NOTE: Some users have reported that you need to delete the entire Microsoft Help folder instead of just the rgstn.lck file)</li>
<li>Make sure you completely uninstall all versions of Office. Even after you uninstall Office using the normal procedure, there may be remnants left behind. Microsoft provides manual removal instructions in KB article <a href="http://support.microsoft.com/kb/928218" target="_blank">928218</a>. However the instructions are quite complicated so I recommend using the &#8220;Fix It&#8221; utility on the same page. This utility can take a long time to run so if it seems to hang on one particular step just be patient and let it finish.</li>
<li>Use a program like <a href="http://www.piriform.com/ccleaner" target="_blank">CCleaner </a>to delete temporary files and invalid registry entries. This is a good housekeeping measure anyway but it&#8217;s especially good after uninstalling something to clean up leftover remnants.</li>
<li>Disable all anti-virus software and/or clean-boot the computer. They always say to disable anti-virus software when installing a new program. Most of the time it doesn&#8217;t matter but there are times when it actually makes a difference. Even better yet is to clean-boot the computer so that nothing is running except the essentials. I&#8217;ll be making an article on that very soon.</li>
</ol>
<p>Following those steps should get you going but if you&#8217;re still having problems, I&#8217;ve heard some people recommend re-registering the Windows Installer and checking permissions on the %TEMP% folder and the C:\Windows\Installer folder to make sure you have full-control. To re-register the Windows Installer run the following commands:</p>
<blockquote><p>msiexec /unregister<br />
msiexec /register</p></blockquote>
<p>I hope that helps!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/DN7KJn1HGIOctgqGvqSjJRUBFdg/0/da"><img src="http://feedads.g.doubleclick.net/~a/DN7KJn1HGIOctgqGvqSjJRUBFdg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/DN7KJn1HGIOctgqGvqSjJRUBFdg/1/da"><img src="http://feedads.g.doubleclick.net/~a/DN7KJn1HGIOctgqGvqSjJRUBFdg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/Iy1zbUfZd60" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2011/02/17/microsoft-office-encountered-an-error-during-setup/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2011/02/17/microsoft-office-encountered-an-error-during-setup/</feedburner:origLink></item>
		<item>
		<title>Windows 7 prompts for password even though password protected sharing is off</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/-Gxq2FKIae0/</link>
		<comments>http://www.kentoyer.com/2011/02/15/cannot-turn-off-password-protected-sharing/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 04:24:00 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=116</guid>
		<description><![CDATA[You may run into this: You are sharing files between two Windows 7 computers on the same network. You go into the Network and Sharing center and turn off password protected sharing. You try to access the shared resource from &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2011/02/15/cannot-turn-off-password-protected-sharing/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>You may run into this:</p>
<ol>
<li>You are sharing files between two Windows 7 computers on the same network.</li>
<li>You go into the Network and Sharing center and turn off password protected sharing.</li>
<li>You try to access the shared resource from another computer and it still prompts you for a username and password.</li>
</ol>
<p>Here&#8217;s what I did to solve it. On the computer that hosts the shared resource:</p>
<ol>
<li>Make sure the Guest account is not disabled</li>
<li>Make sure the Guest account does not have a password. To make sure of this, go into Local Users and Computer and reset the Guest account password. Give it a blank password.</li>
<li>Make sure the Guest account is not denied access from the network. To do this, go into Local Security Policy and drill down to Local Policies -&gt; User Rights Assignment. Look for a policy called &#8220;Deny access to this computer from the network.&#8221; If the Guest account is listed there, delete it.</li>
</ol>

<p><a href="http://feedads.g.doubleclick.net/~a/Fej8MG-hDcAjg4bmDE673_vQmRY/0/da"><img src="http://feedads.g.doubleclick.net/~a/Fej8MG-hDcAjg4bmDE673_vQmRY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Fej8MG-hDcAjg4bmDE673_vQmRY/1/da"><img src="http://feedads.g.doubleclick.net/~a/Fej8MG-hDcAjg4bmDE673_vQmRY/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/-Gxq2FKIae0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2011/02/15/cannot-turn-off-password-protected-sharing/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2011/02/15/cannot-turn-off-password-protected-sharing/</feedburner:origLink></item>
		<item>
		<title>How to configure your Cisco router the easy way</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/qpJL36p55Ig/</link>
		<comments>http://www.kentoyer.com/2011/02/15/how-to-configure-your-cisco-router-the-easy-way/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 03:13:00 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=110</guid>
		<description><![CDATA[Have you ever wished configuring a Cisco router was as easy as a run-of-the mill Linksys or Netgear? Cisco routers are extremely powerful but not-so-easy to configure unless you memorize a bunch of cryptic commands. Sure the ASDM makes it &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2011/02/15/how-to-configure-your-cisco-router-the-easy-way/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Have you ever wished configuring a Cisco router was as easy as a run-of-the mill Linksys or Netgear? Cisco routers are extremely powerful but not-so-easy to configure unless you memorize a bunch of cryptic commands. Sure the ASDM makes it a litter easier but what if you want super-easy? I got tired of copying one config file to another and doing search-and-replace operations so I make this quick-and-dirty, web-based <a href="http://www.kentoyer.com/cisco-config-generator">Cisco Router Config Generator</a>. All you have to do is fill in a few boxes with your network settings and hit &#8220;Generate Config&#8221;. Then upload the resulting config file into your router. It doesn&#8217;t cover all the advanced things you can do with your Cisco router but it covers the most common things like DHCP and Port Forwarding. You can use the config file as is, or customize it to suit your needs.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/kcXwXJJ5s0ryAK0b4EeywcBuLBY/0/da"><img src="http://feedads.g.doubleclick.net/~a/kcXwXJJ5s0ryAK0b4EeywcBuLBY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/kcXwXJJ5s0ryAK0b4EeywcBuLBY/1/da"><img src="http://feedads.g.doubleclick.net/~a/kcXwXJJ5s0ryAK0b4EeywcBuLBY/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/qpJL36p55Ig" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2011/02/15/how-to-configure-your-cisco-router-the-easy-way/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2011/02/15/how-to-configure-your-cisco-router-the-easy-way/</feedburner:origLink></item>
		<item>
		<title>How to use Classic ASP to connect to Access databases on SBS 2008</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/NDyMd_h_8OU/</link>
		<comments>http://www.kentoyer.com/2010/03/16/how-to-use-classic-asp-to-connect-to-access-databases-on-sbs-2008/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 16:21:14 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=85</guid>
		<description><![CDATA[So here&#8217;s the scenario: I recently migrated from Small Business Server 2003 to SBS 2008. It was a fairly smooth transition except for one thing: There was a web application written in classic ASP that connected to an Access database. &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2010/03/16/how-to-use-classic-asp-to-connect-to-access-databases-on-sbs-2008/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>So here&#8217;s the scenario: I recently migrated from Small Business Server 2003 to SBS 2008. It was a fairly smooth transition except for one thing: There was a web application written in classic ASP that connected to an Access database.</p>
<p><strong>Problem #1: No 64-bit JET driver</strong><br />
As you may know, SBS 2008 is required to run as a 64-bit operating system. That means IIS is also 64-bit. Unfortunately, Microsoft does not provide a 64-bit Jet driver for accessing Access databases. ASP worked but as soon as I tried to open a connection object, I got this error:</p>
<blockquote><p>500 &#8211; Internal server error.<br />
There is a problem with the resource you are looking for, and it cannot be displayed.</p></blockquote>
<p>Tracking this error down was a bit tricky. I had to enable Failed Request Tracing. When I reviewed the trace log, I found this:</p>
<blockquote><p>Error 800a0e7a<br />
Provider cannot be found. It may not be properly installed.</p></blockquote>
<p>The provider string I was trying to use was:</p>
<blockquote><p>Provider=Microsoft.Jet.OLEDB.4.0</p></blockquote>
<p><strong>Solution:<br />
</strong>Create a new Application Pool and set it to 32-bit mode</p>
<p>Set the Default Web Site to use the new application pool</p>
<p><strong>Problem #2: Application Pool Crashes</strong><br />
When I tried accessing my site again, I received a different error message</p>
<blockquote><p>503 Service Unavailable</p></blockquote>
<p>I also noticed that the application pool had changed it&#8217;s state to &#8220;Stopped&#8221;. Not good. A quick look in the Windows Event Viewer revealed event 2280:</p>
<blockquote><p>The Module DLL C:\Windows\system32\RpcProxy\RpcProxy.dll failed to load.</p></blockquote>
<p>RpcProxy is a 64-bit DLL required for Exchange to work properly. For some reason, it was trying to load in my 32-bit application pool causing the pool to stop working.</p>
<p><strong>Solution:<br />
</strong>Edit the c:\windows\system32\inetsrv\config\applicationhost.config file. Search for the following line and add preCondition=&#8221;bitness64&#8243;</p>
<blockquote><p>&lt;add name=&#8221;PasswordExpiryModule&#8221; image=&#8221;C:\Windows\system32\RpcProxy\RpcProxy.dll&#8221; preCondition=&#8221;bitness64&#8243; /&gt;</p></blockquote>
<p><strong>Problem #3</strong><br />
Compression module does not load because there is no 32-bit driver. This will cause you to receive the following error:</p>
<blockquote><p>HTTP Error 500.19 &#8211; Internal Server Error<br />
The requested page cannot be accessed because the related configuration data for the page is invalid.</p></blockquote>
<p>If you look in the trace log, you will see something like this:</p>
<blockquote><p>ModuleName StaticCompressionModule<br />
Notification 16<br />
HttpStatus 500<br />
HttpReason Internal Server Error<br />
HttpSubStatus 19<br />
ErrorCode 2147942526<br />
ConfigExceptionInfo<br />
Notification MAP_REQUEST_HANDLER<br />
ErrorCode The specified module could not be found. (0x8007007e)</p></blockquote>
<p><strong>Solution:</strong><br />
The solution is to disable HTTP compression. Unfortunately you can&#8217;t disable compression on a site-by-site basis so you will have to disable it server-wide. Run this command on the server to disable HTTP compression:</p>
<blockquote><p>%windir%\system32\inetsrv\appcmd.exe set config -section:system.webServer/httpCompression /-[name='xpress']</p></blockquote>
<p><strong>Update (1/15/2011):</strong><br />
I discovered today that installing Exchange 2007 Service Pack 3 causes the 32-bit application pool to stop working again. That is because the update adds a new 64-bit only DLL (exppw.dll) to the application pool causing it to crash. The solution is the same as for the RpcProxy DLL we did earlier except you need to add preCondition=&#8221;bitness64&#8243; in two places in the applicationhost.config file . The first place is in the &lt;globalModules&gt; section:</p>
<blockquote><p>&lt;add name=&#8221;exppw&#8221; image=&#8221;C:\Program Files\Microsoft\Exchange Server\ClientAccess\Owa\auth\exppw.dll&#8221; preCondition=&#8221;bitness64&#8243; /&gt;</p></blockquote>
<p>and the second place is in the &lt;modules&gt; section:</p>
<blockquote><p>&lt;add name=&#8221;exppw&#8221; preCondition=&#8221;bitness64&#8243; /&gt;</p></blockquote>
<p><strong>Resources:</strong><br />
ASP &amp; Jet Provider<br />
<a href="http://forums.iis.net/t/1066385.aspx">http://forums.iis.net/t/1066385.aspx</a></p>
<p>500.19 Error When Enabling 32-bit Application Pool<br />
<a href="http://forums.iis.net/t/1149768.aspx">http://forums.iis.net/t/1149768.aspx</a></p>
<p>The Module DLL C:\Windows\system32\RpcProxy\RpcProxy.dll failed to load<br />
<a href="http://forums.iis.net/t/1154189.aspx">http://forums.iis.net/t/1154189.aspx</a></p>
<p>Using Classic ASP with Microsoft Access Databases on IIS 7.0 and IIS 7.5<br />
<a href="http://learn.iis.net/page.aspx/563/using-classic-asp-with-microsoft-access-databases-on-iis-70-and-iis-75">http://learn.iis.net/page.aspx/563/using-classic-asp-with-microsoft-access-databases-on-iis-70-and-iis-75</a></p>
<p>Exchange Server 2007 SP3 kills our 32-bit compiled ASP web application<br />
<a href="http://social.technet.microsoft.com/Forums/en-US/exchangesoftwareupdate/thread/c378f8b5-6ac5-4871-ba70-7eef7d5a1cf4">http://social.technet.microsoft.com/Forums/en-US/exchangesoftwareupdate/thread/c378f8b5-6ac5-4871-ba70-7eef7d5a1cf4</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/feziVmzIYaCBVSkcBQ96JXt67GU/0/da"><img src="http://feedads.g.doubleclick.net/~a/feziVmzIYaCBVSkcBQ96JXt67GU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/feziVmzIYaCBVSkcBQ96JXt67GU/1/da"><img src="http://feedads.g.doubleclick.net/~a/feziVmzIYaCBVSkcBQ96JXt67GU/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/NDyMd_h_8OU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2010/03/16/how-to-use-classic-asp-to-connect-to-access-databases-on-sbs-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2010/03/16/how-to-use-classic-asp-to-connect-to-access-databases-on-sbs-2008/</feedburner:origLink></item>
		<item>
		<title>Dissecting and removing the SHV5 rootkit</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/QcwyMBn0wiE/</link>
		<comments>http://www.kentoyer.com/2009/12/21/removing-the-shv5-rootkit/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 08:07:57 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=94</guid>
		<description><![CDATA[Yesterday I noticed some odd behavior on one of the Linux servers that I maintain. For one thing, every time I would run &#8216;top&#8217; or &#8216;ps&#8217;, I would see the following message Unknown Hz value! (75) Assume 100 I decided &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2009/12/21/removing-the-shv5-rootkit/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Yesterday I noticed some odd behavior on one of the Linux servers that I maintain. For one thing, every time I would run &#8216;top&#8217; or &#8216;ps&#8217;, I would see the following message</p>
<blockquote><p>Unknown Hz value! (75) Assume 100</p></blockquote>
<p>I decided to run rkhunter to check for rootkits. Needless to say, I was disappointed to discover that I had the SHV5 Rootkit on my machine. Let me tell you, it&#8217;s not a good feeling to know you&#8217;ve been hacked. Now I know common wisdom dictates that rootkit-infected machines be formatted and reloaded from scratch but that is not something you do without a lot of planning and preparation. The first thing I wanted to do was get this bad guy off my machine and try to minimize the damage.</p>
<h2>How it works</h2>
<p>I did some quick googling and I discovered <a href="http://www.jigsawboys.com/2008/06/01/lead-story-test/" target="_blank">this page</a> which was very helpful. However, I wanted to add a few more details that might help somebody out in the future. Basically what I discovered is that the rootkit installs an SSH server as a backdoor for the hacker to obtain access to your machine. In my case it was running on port 6522 but this is configurable by the hacker so your mileage my vary.</p>
<p>The hacker does not need to know any passwords to login to your system because the rootkit installs a public key file. The hacker simply needs to have the corresponding private key to authenticate to your server. Unfortunately all of this was invisible to me because the rootkit modifies several core utilities such as &#8216;ls&#8217; and &#8216;netstat&#8217; to hide it&#8217;s presence. The modified versions of these utilities work just like the real ones, except they don&#8217;t display anything that might be incriminating such as certain files and folders, or tell-tale processes.</p>
<h2>Cleaning it up</h2>
<p>The first thing you have to do before you can start cleaning up a rootkit infection is to get your original system files back. Luckily, the rootkit makes this rather easy by setting the immutable bit on the modified files. The purpose is to prevent anyone from deleting or overwriting the hacked files but it also gives us an easy way to tell what&#8217;s been modified. After you run rkhunter, there should be a log file in /var/log called rkhunter.log. Search through this log file to see what files have the immutable bit set. These are the ones we need to replace. I&#8217;ll use /bin/ls in my examples.</p>
<p>First, unset the immutable flag by using this command:</p>
<blockquote><p>chattr -sia /bin/ls</p></blockquote>
<p>Then, you can optionally make a copy of the hacked file for future use. This is helpful to compare the output from the hacked version to the output of the real version to see what&#8217;s different.</p>
<blockquote><p>mv /bin/ls /bin/ls.hacked</p></blockquote>
<p>Next, figure out which RPM your file belongs to by running this:</p>
<blockquote><p>rpm -qif /bin/ls</p></blockquote>
<p>This will tell you the <em>source </em>RPM. To get the <em>binary </em>RPM just replace &#8216;.src.rpm&#8217; with &#8216;.i386.rpm&#8217;. For example, on my machine, the source RPM for /bin/ls is:</p>
<blockquote><p>coreutils-5.97-19.el5.src.rpm</p></blockquote>
<p>So the file I needed to download was:</p>
<blockquote><p>coreutils-5.97-19.el5.i386.rpm</p></blockquote>
<p>You can Google the name of this file or look on popular RPM sites such as rpmfind.net or rpm.pbone.net. Once you are sure you have the <strong>correct </strong>file, install it using the &#8211;force command.</p>
<blockquote><p>rpm -i &#8211;force coreutils-5.97-19.el5.i386.rpm</p></blockquote>
<p>This tells the installer to try to reinstall the package even though it&#8217;s already installed and to replace files as necessary. If you get any errors about files that it can&#8217;t  replace, it&#8217;s probably because those files have the immutable bit set as well. Clear the immutable bit on those files and install the package again until there are no errors.</p>
<p>Repeat this whole process for every file in rkhunter.log that has the immutable bit set. You will probably have to download several different packages.</p>
<p>Now that you have reliable system commands you can begin ripping out the rootkit. Use netstat to see what ports are open and look for anything suspicious.</p>
<blockquote><p>netstat -ln &#8211;programs</p></blockquote>
<p>This is where it&#8217;s handy to have the output from the hacked version of netstat so you can compare. In my case, I found a program called ttyload that was listening on port 6522. I killed the process and deleted the file. After that I confirmed that my server was no longer accessible on that port. I also used the information in rkhunter.log to locate and delete a number of other files and folders as well. Here&#8217;s a list of some of the more interesting ones.</p>
<table border="0">
<tbody>
<tr>
<td>/usr/lib/libsh/hide</td>
<td>a script that removes traces of the hacker&#8217;s activities from the system log files.</td>
</tr>
<tr>
<td>/usr/lib/libsh/.backup</td>
<td>looks like a backup of all the system files that were modifed. DO NOT TRUST THIS.</td>
</tr>
<tr>
<td>/usr/lib/libsh/.sniff/shsniff</td>
<td>a packet sniffer used to capture passwords off the network.</td>
</tr>
<tr>
<td>/lib/libsh.so/sshk</td>
<td>the public key file for SSH authentication.</td>
</tr>
<tr>
<td>/lib/libsh.so/shdcf</td>
<td>a configuration file that determines (among other things) the port to listen on.</td>
</tr>
<tr>
<td>/usr/sbin/ttyload</td>
<td>a script that calls /bin/ttyload and /bin/ttymon. Used at startup.</td>
</tr>
</tbody>
</table>
<p>Make sure you check your /etc/inittab and all the files in /etc/rc.d to see if the rootkit is loading anything at startup. In my case I had to remove the line that calls /usr/sbin/ttyload from /etc/inittab.</p>
<h2>Final thoughts</h2>
<p>Here are some final thoughts on what to do next.</p>
<ol>
<li>Change the root password and the passwords for any other privileged accounts you may have.</li>
<li>Reboot the server and make sure things are still normal after the system comes back up.</li>
<li>Use iptables to block incoming connections on all ports other than the ones you need.</li>
<li>Strongly consider a full format and reload of your system.</li>
<li>Run rkhunter on a regular basis</li>
</ol>

<p><a href="http://feedads.g.doubleclick.net/~a/YVK16RPsPLf3lBtKqCHIi9i6aN0/0/da"><img src="http://feedads.g.doubleclick.net/~a/YVK16RPsPLf3lBtKqCHIi9i6aN0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/YVK16RPsPLf3lBtKqCHIi9i6aN0/1/da"><img src="http://feedads.g.doubleclick.net/~a/YVK16RPsPLf3lBtKqCHIi9i6aN0/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/QcwyMBn0wiE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2009/12/21/removing-the-shv5-rootkit/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2009/12/21/removing-the-shv5-rootkit/</feedburner:origLink></item>
		<item>
		<title>How to backup your MySQL databases to separate files</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/ebTg9sGdpjI/</link>
		<comments>http://www.kentoyer.com/2009/09/01/mysql-backup-script-to-separate-files/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 13:57:43 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=78</guid>
		<description><![CDATA[I wanted to dump all my MySQL databases using the mysqldump utility, but I wanted each database to be in a separate file. I couldn&#8217;t find a solution online, so I wrote my own script. Here it is: #!/bin/sh USERNAME=admin &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2009/09/01/mysql-backup-script-to-separate-files/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>I wanted to dump all my MySQL databases using the mysqldump utility, but I wanted each database to be in a separate file. I couldn&#8217;t find a solution online, so I wrote my own script. Here it is:</p>
<pre>#!/bin/sh
USERNAME=admin
PASSWORD=topsecret
BACKUPDIR=/var/local/mysql-backups

for i in $(mysql -u $USERNAME -p$PASSWORD -e "SHOW DATABASES;" --skip-column-names --batch)
do
   echo "Backing up database $i"
   mysqldump -u $USERNAME -p$PASSWORD --opt $i | gzip &gt; $BACKUPDIR/$i.sql.gz
done</pre>
<p>Of course, you will need to edit the first two lines to reflect your own username and password. When you run this script, it will create a bunch of files in the <code>/var/local/mysql-backups</code> directory, one for each database. The files are compressed to save space.  Of course, you&#8217;ll need to make sure the destination directory exists.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/PMliSkdAs9kdX8fGHvq3yYD7RzE/0/da"><img src="http://feedads.g.doubleclick.net/~a/PMliSkdAs9kdX8fGHvq3yYD7RzE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/PMliSkdAs9kdX8fGHvq3yYD7RzE/1/da"><img src="http://feedads.g.doubleclick.net/~a/PMliSkdAs9kdX8fGHvq3yYD7RzE/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/ebTg9sGdpjI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2009/09/01/mysql-backup-script-to-separate-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2009/09/01/mysql-backup-script-to-separate-files/</feedburner:origLink></item>
		<item>
		<title>Remove Personal Antivirus in 3 easy steps</title>
		<link>http://feedproxy.google.com/~r/KentOyer/~3/xBuKeWC_9c4/</link>
		<comments>http://www.kentoyer.com/2009/08/18/remove-personal-antivirus-in-3-easy-steps/#comments</comments>
		<pubDate>Tue, 18 Aug 2009 02:57:01 +0000</pubDate>
		<dc:creator>Kent</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.kentoyer.com/?p=71</guid>
		<description><![CDATA[What is Personal Antivirus? Personal Antivirus sounds like a wonderful program that might be good to have, right? Actually, it&#8217;s just one of an increasingly common type of malware called a rogue anti-virus or rogue anti-spyware program. It appears to &#8230;<p class="read-more"><a href="http://www.kentoyer.com/2009/08/18/remove-personal-antivirus-in-3-easy-steps/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p><strong>What is Personal Antivirus?</strong></p>
<p>Personal Antivirus sounds like a wonderful program that might be good to have, right? Actually, it&#8217;s just one of an increasingly common type of malware called a rogue anti-virus or rogue anti-spyware program. It <em>appears </em>to be harmless or even beneficial on the surface, but it&#8217;s actual goal is to scare you into thinking you have some nasty virus that can only be removed by purchasing their removal software. It&#8217;s sort of like digital blackmail. Similar &#8220;products&#8221; include XP Antivirus, Antivirus 2008/2009 , Antivirus 360, etc&#8230;</p>
<p><strong>How do I get rid of it?</strong></p>
<p>Unlike most legitimate programs, there is no automatic un-installation method. That&#8217;s because the people behind these scams don&#8217;t want you to remove their software. They usually don&#8217;t show up in the list of programs in the Add/Remove Programs control panel applet. However, in many cases, manual removal is simple. Here are the steps I use. Keep in mind there are many different variants of this program so your mileage may vary.</p>
<p><strong>Step 1: Terminate the application</strong></p>
<p>Open Task Manager and look for a process called &#8220;pav.exe&#8221;. Highlight this process and click End Task. Once the process has been ended, the tray icon and application window should disappear.</p>
<p><strong>Step 2: Prevent the program from starting up</strong></p>
<p>Download a program called <a title="HijackThis Download Link" href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download" target="_blank">HijackThis</a>. After you&#8217;ve installed it, run HijackThis and do a system scan. Look for any reference to the file pav.exe. Usually there will be at least one reference on a line that starts with &#8220;Run&#8221;. Put a check beside any that you find and click &#8220;Fix&#8221;</p>
<p><strong>Step 3: Delete the program files</strong></p>
<p>Delete the Personal Antivirus folder located in C:\Program Files.  You should also delete the shortcut on the desktop and the Personal Antivirus folder in the start menu.</p>
<p>That&#8217;s it. Reboot your computer just to make sure it doesn&#8217;t come back at startup. One optional step is to run a registry cleaner like <a href="http://www.ccleaner.com/" target="_blank">CCleaner</a> after you&#8217;re done. That should remove any leftover registry keys that reference the missing program file folder.</p>
<p><strong>So do I really have a virus?</strong></p>
<p>Just because Personal Antivirus was on your system and it said you have a virus, that does not mean you&#8217;re actually infected. However, I <em>strongly </em>recommend doing a full system scan with a legitimate anti-virus program and an anti-spyware program just to be safe. If you don&#8217;t already have one, here&#8217;s a list of some free alternatives.</p>
<p><span style="text-decoration: underline;">Free Anti-Virus software </span>(install only one at a time)<br />
<a href="http://free.avg.com/" target="_blank">AVG</a><br />
<a href="http://www.avast.com/" target="_blank">Avast</a><br />
<a href="http://www.free-av.com/" target="_blank">Avira AntiVir</a></p>
<p><span style="text-decoration: underline;">Free Anti-Spyware software</span><br />
<a href="http://www.safer-networking.org/en/home/index.html" target="_blank">Spybot Search &amp; Destroy</a><br />
<a href="http://www.lavasoft.com/" target="_blank">AdAware</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/w3Py7hdeKFxNpn0q_yMb0ckAesg/0/da"><img src="http://feedads.g.doubleclick.net/~a/w3Py7hdeKFxNpn0q_yMb0ckAesg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/w3Py7hdeKFxNpn0q_yMb0ckAesg/1/da"><img src="http://feedads.g.doubleclick.net/~a/w3Py7hdeKFxNpn0q_yMb0ckAesg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/KentOyer/~4/xBuKeWC_9c4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.kentoyer.com/2009/08/18/remove-personal-antivirus-in-3-easy-steps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.kentoyer.com/2009/08/18/remove-personal-antivirus-in-3-easy-steps/</feedburner:origLink></item>
	</channel>
</rss>

