I recently revisited the driver installation on a Dell E6400 laptop. There was one stubborn driver that I couldn't get working, the "Broadcom USH" device. Dell's support website didn't list a driver for this so I went out on a wider search across the internet forum. I found a lot of posts talking about installing the Control Vault device drivers. So I grabbed the Dell ControlPoint Security Device Driver and found that it was useless. The drivers were wrapped in an installer (that I didn't want to run, I just wanted the drivers). Then I scrolled a little further down the page and found the Dell ControlVault Driver package (here's the page where I found it). After extracting that exe file I was left with a bunch of MST files and one MSI file. So I extracted the MSI and there they were, the elusive drivers. But it wasn't just a straight forward install.
I tried to install the driver, but it didn't work either. It told me it couldn't find one of the files. At first glance, everything was there. So I ran DPInst against it. It errored on two different drivers. I looked through their INF files and found that they were looking for 2 files that weren't there. A ccidflt.sys and a cvusbdrv.sys were missing. Looking in the folder there was a ccidflt.sys2 and a cvusbdrv.sys1. Close enough, right? I removed the extra number from the ends of the extension and ran DPInst again and it worked!
So there you go, sometimes drivers can be stubborn. But a little persistence pays off in the end.
Problems and the occasional solution for technology issues encountered in a the K-12 education environment.
Thursday, April 10, 2014
Wednesday, April 9, 2014
Chromebook Chargers (HP, Samsung, and Dell)
Again with the Chromebook posts, right? There are tons of reviews out there. But you can only rehash the same specs so many times. In the K-12 market I need to know about the physical properties of the devices too. Let's face it, these things are going to take some abuse. What takes more abuse than the power connector? The charger is going to be plugged up every day, it's got to be tough.
My first experience with a Chromebook was the Samsung Chromebook. No model number, just the Chromebook. That was the first ARM based one that was priced at $249. My thoughts initial thoughts were wow, it's light, it's thin, maybe a little flimsy, but what's with that crazy small charger connector. Really, is this a Nokia phone from 2008? In saying that, I still love that particular model. I was just worried about unleashing a hoard of students on that small connector. The teachers haven't had an issue with it, but I feared the students. I've seen what they were capable of with much more robust connectors.
Then I came across the HP Chromebook 11. Not as thin or light, but not as flimsy either. So how did that charger connector stack up? It's micro-usb. That's great, right? I really thought it was. It's micro-usb! Most of these kids are used to plugging these up with their cell phones. My toddler can plug up a micro-usb connector. Not to mention that micro-usb chargers are everywhere which should have been a huge advantage (but it's not, just Google it for the details, the short version is that cell charger doesn't provide enough juice, Chromebook battery will die while trying use and charge at same time).
All micro usb connectors are not the same. The HP Chromebook 11 appears to have a micro-a usb socket. What is that you ask? It's almost just like the ubiquitous micro-usb connector. In fact, the micro-b usb connector that you're used to works in a micro-a socket. The big difference is that that micro-a connector is a rectangle, it doesn't have the "clipped" corners that make the micro-b connector look kind of like a trapezoid. Here's a link to the USB Wikipedia article, they cover it better than I do and they have pictures, too.
What does the different connector mean to you? It means the socket doesn't have an obvious up side (or downside). I know I'm guilty of blindly trying to plug a cable in, doesn't fit, flip it and try it again. With the more common micro-b connector this isn't a problem. The metal casing on the connector will only fit one way so if it doesn't fit, it just doesn't fit. But the HP Chromebook 11 doesn't have a micro-b socket, it's got a micro-a socket. This means that the metal casing will fit either way. The only thing stopping it from going in upside down is the thin little plastic strip that holds the metal contacts. Do you see the problem with this?
So enough about the Chromebook 11, how about the Chromebook 14? It doesn't have the same problem as the 11. It's got a more standard barrel connector. It seems fairly robust. I haven't spent much time with this one so I don't have a lot more to say about it.
Now let's get to the latest Chromebook that I've tried out. The Dell Chromebook 11. I got it out of the box and was thrilled to see the standard Dell barrel connector. The power adapter is a 65W adapter. It's got rounded corners and doesn't look like the other Dell power bricks that I'm familiar with, but the business end is the same. It even has the light up ring where the cord goes into the back side of the barrel connector. I checked it out, it looked pretty cool. But I didn't plug it up. Right there on my desk was another Dell power adapter from another Dell laptop (not a Chromebook), I picked it up, plugged it in and.... It blew up. Wait, no it didn't. It just worked.
So there we go, the Dell Chromebook 11 has a nice big, fat, rugged power connector. And it's not unique, it's a Dell connector. There's a thriving market for Dell laptop chargers. Try finding an after market HP Chromebook 11 charger (which isn't the same as a HP Chromebook 14). Heck, try to find an OEM adapter for that matter. The HP is always out of stock. Good luck finding a replacement if your dog eats homework, er.... Chromebook charger.
My first experience with a Chromebook was the Samsung Chromebook. No model number, just the Chromebook. That was the first ARM based one that was priced at $249. My thoughts initial thoughts were wow, it's light, it's thin, maybe a little flimsy, but what's with that crazy small charger connector. Really, is this a Nokia phone from 2008? In saying that, I still love that particular model. I was just worried about unleashing a hoard of students on that small connector. The teachers haven't had an issue with it, but I feared the students. I've seen what they were capable of with much more robust connectors.
Then I came across the HP Chromebook 11. Not as thin or light, but not as flimsy either. So how did that charger connector stack up? It's micro-usb. That's great, right? I really thought it was. It's micro-usb! Most of these kids are used to plugging these up with their cell phones. My toddler can plug up a micro-usb connector. Not to mention that micro-usb chargers are everywhere which should have been a huge advantage (but it's not, just Google it for the details, the short version is that cell charger doesn't provide enough juice, Chromebook battery will die while trying use and charge at same time).
All micro usb connectors are not the same. The HP Chromebook 11 appears to have a micro-a usb socket. What is that you ask? It's almost just like the ubiquitous micro-usb connector. In fact, the micro-b usb connector that you're used to works in a micro-a socket. The big difference is that that micro-a connector is a rectangle, it doesn't have the "clipped" corners that make the micro-b connector look kind of like a trapezoid. Here's a link to the USB Wikipedia article, they cover it better than I do and they have pictures, too.
What does the different connector mean to you? It means the socket doesn't have an obvious up side (or downside). I know I'm guilty of blindly trying to plug a cable in, doesn't fit, flip it and try it again. With the more common micro-b connector this isn't a problem. The metal casing on the connector will only fit one way so if it doesn't fit, it just doesn't fit. But the HP Chromebook 11 doesn't have a micro-b socket, it's got a micro-a socket. This means that the metal casing will fit either way. The only thing stopping it from going in upside down is the thin little plastic strip that holds the metal contacts. Do you see the problem with this?
So enough about the Chromebook 11, how about the Chromebook 14? It doesn't have the same problem as the 11. It's got a more standard barrel connector. It seems fairly robust. I haven't spent much time with this one so I don't have a lot more to say about it.
Now let's get to the latest Chromebook that I've tried out. The Dell Chromebook 11. I got it out of the box and was thrilled to see the standard Dell barrel connector. The power adapter is a 65W adapter. It's got rounded corners and doesn't look like the other Dell power bricks that I'm familiar with, but the business end is the same. It even has the light up ring where the cord goes into the back side of the barrel connector. I checked it out, it looked pretty cool. But I didn't plug it up. Right there on my desk was another Dell power adapter from another Dell laptop (not a Chromebook), I picked it up, plugged it in and.... It blew up. Wait, no it didn't. It just worked.
So there we go, the Dell Chromebook 11 has a nice big, fat, rugged power connector. And it's not unique, it's a Dell connector. There's a thriving market for Dell laptop chargers. Try finding an after market HP Chromebook 11 charger (which isn't the same as a HP Chromebook 14). Heck, try to find an OEM adapter for that matter. The HP is always out of stock. Good luck finding a replacement if your dog eats homework, er.... Chromebook charger.
Monday, March 10, 2014
Disable Chrome Frame
Now that Google has ended support for Chrome Frame (see here) the time has come to transition to their new Legacy Browser Extension. I've run into a few systems that I'm unable to remove Chrome Frame from. This wouldn't be an issue except that we have a new site that's IE only, and Chrome Frame is ignoring the policy to render the site with IE. So now they open it in Chrome, the LBS extension kicks them over to IE and then it gets rendered in Chrome Frame. That's extremely helpful, right? Easiest solution is to remove Chrome Frame, right? That would work great if it would uninstall, but the uninstaller fails. So I tried to install a newer version so I that I could maybe get it to uninstall. That didn't work either, the installer fails. So what about a quick and dirty way to disable Google Chrome Frame? You can go into IE and disable it through the Add-On Manager, but I need to disable it on a bunch of machines. How can you do that? Just push the registry key to the machine that says disable the Chrome Frame. What is that registry key? Actually, it's two keys and here they are (just cut and paste this into a .reg file for easy import).
Windows Registry Editor Version 5.00[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}]"Flags"=dword:00000001"Version"="*"
Import those keys to disable it and just delete them to re-enable. Which hopefully you will never have to do once you get Legacy Browser Support up and going.
This is for my old XP machines. I haven't run into this issue on Windows 7 yet, so I haven't bothered with testing it there.
Windows Registry Editor Version 5.00[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}]"Flags"=dword:00000001"Version"="*"
Import those keys to disable it and just delete them to re-enable. Which hopefully you will never have to do once you get Legacy Browser Support up and going.
This is for my old XP machines. I haven't run into this issue on Windows 7 yet, so I haven't bothered with testing it there.
Labels:
chrome frame,
chromeframe,
disable,
lbs,
legacy browser support,
registry
Saturday, March 8, 2014
Asus Chromeboxes are almost here!
It's been a month since I first went on about a new Chromebox from Asus (see here), but they have finally arrived... almost. AnandTech is reporting (here) that the boxes are available for pre-order Newegg, Amazon, and TigerDirect. The one change from the initial press release is that the systems are not going to be fanless. The fans are supposed to be variable speed and not required to run all the time so noise shouldn't be a major issue. However, I do miss the whole "no moving parts" thing. As a plan to use these for a replacement for a thin client I do wonder how the fan will affect it's longevity. I guess I'd rather have the box running cooler, but moving parts are more likely to fail that solid state parts. I just hope they chose to use high quality parts in their fans.
Saturday, February 22, 2014
Following Locked Accounts to Find a Conficker Infection
I recently had several users reporting that they were unable to log in because their accounts had been locked out. This perplexed me, because we have really lax account lockout policies. There's no way one user, much less a bunch of users, could have tried enough wrong passwords to actually lock their accounts all on the same day. Something fishy was going on and it was going to require some investigation.
I started with the Account Lockout Tools from Microsoft. You can find those here, http://www.microsoft.com/en-us/download/details.aspx?id=18465
After you download and install them, you'll have to go find the files, they don't add icons to the Start Menu for you. The default install location for the files is C;\Program Files\Windows Resource Kits\Tools. The one you'll want to run is lockoutstatus.exe.
When you run the lock out status utility you'll provide it with a username and domain of an account that has been locked out. The utility will run against all of your domain controllers and list which one the account was locked from, it will also give you a time too.
Once you know which DC is was locked on we need to go look at the Event Viewer on that server. Check out the security logs. If your server logs are like mine then there are a bunch of events listed. To make things easier filter the log to only show Event ID 4740.
If you've got a machine infected with conficker like I did you'll probably have a lot of these User Account Locked events. Technically, it could be an individual or organization trying to hack your system too. But in my experience and in this environment it's usually some kind of virus doing it.
Most of the events had time stamps really close together. I looked through the logs around the time of the lock event reported from the lockoutstatus tool and found where that user account had been locked. This event and the others were a red flag that something was going on, as this lock event and several of the others were happening in the middle of the night. That wasn't all though, the lockout events were scattered all over the day.
Now, let's use this information to track down our conficker infected machine. Open up one of these events and scroll down in the General tab and look for the Additional Information section at the bottom. What you want to find is the Caller Computer Name, this will be your infected machine.
You might also want to scroll through and look at several of the events to see if they're all coming from the same machine. In my case I actually had 3 old machines that hadn't been patched correctly and were infected.
One of the easiest and fastest ways to verify a conficker infection is to use to the Conficker Eye Chart. Yes it has a ridiculous name, but it's simple, fast, and it works. If you haven't used it before, it just loads a web page that pulls images from the major security vendors. Since conficker blocks access to those domains based on what images load and which ones don't you can tell if you're infected and possibly by which variant.
Once I had confirmed that it was conficker, I ran the Microsoft Malicious Software Removal Tool to remove the infection.
This sounds like a long process but don't get discouraged, in reality it flows pretty quickly.
I started with the Account Lockout Tools from Microsoft. You can find those here, http://www.microsoft.com/en-us/download/details.aspx?id=18465
After you download and install them, you'll have to go find the files, they don't add icons to the Start Menu for you. The default install location for the files is C;\Program Files\Windows Resource Kits\Tools. The one you'll want to run is lockoutstatus.exe.
When you run the lock out status utility you'll provide it with a username and domain of an account that has been locked out. The utility will run against all of your domain controllers and list which one the account was locked from, it will also give you a time too.
Once you know which DC is was locked on we need to go look at the Event Viewer on that server. Check out the security logs. If your server logs are like mine then there are a bunch of events listed. To make things easier filter the log to only show Event ID 4740.
If you've got a machine infected with conficker like I did you'll probably have a lot of these User Account Locked events. Technically, it could be an individual or organization trying to hack your system too. But in my experience and in this environment it's usually some kind of virus doing it.
Most of the events had time stamps really close together. I looked through the logs around the time of the lock event reported from the lockoutstatus tool and found where that user account had been locked. This event and the others were a red flag that something was going on, as this lock event and several of the others were happening in the middle of the night. That wasn't all though, the lockout events were scattered all over the day.
Now, let's use this information to track down our conficker infected machine. Open up one of these events and scroll down in the General tab and look for the Additional Information section at the bottom. What you want to find is the Caller Computer Name, this will be your infected machine.
![]() |
| Event ID 4740, look for the Caller Computer Name |
You might also want to scroll through and look at several of the events to see if they're all coming from the same machine. In my case I actually had 3 old machines that hadn't been patched correctly and were infected.
One of the easiest and fastest ways to verify a conficker infection is to use to the Conficker Eye Chart. Yes it has a ridiculous name, but it's simple, fast, and it works. If you haven't used it before, it just loads a web page that pulls images from the major security vendors. Since conficker blocks access to those domains based on what images load and which ones don't you can tell if you're infected and possibly by which variant.
Once I had confirmed that it was conficker, I ran the Microsoft Malicious Software Removal Tool to remove the infection.
This sounds like a long process but don't get discouraged, in reality it flows pretty quickly.
Labels:
4740,
conficker,
event viewer,
lockout,
malcious software removal tool
Friday, February 14, 2014
A New Chromebox from Dell?
I swear this blog isn't just about Chrome devices, there's just been so much news about them lately and they're such a good fit for education.
It looks like Dell may be preparing to release a Chromebox. They may have gotten to the Chromebook party really late but it looks like they might show up at the Chromebox party pretty close to everyone else. Well, I guess technically Samsung has had a Chromebox out for years, but one person doesn't make a party. They were just really early, because it seems like the Chromebox party is just starting.
I haven't seen any direct press from Dell about a standalone Chromebox, but I've seen Dell mentioned several times as being one of the providers of the Chromebox for Meetings* hardware. In fact, here is Dell's own press release where they mention that they are developing a Dell Chromebox for meetings. Surely if they're developing one for meetings they'll develop one that's not just for meetings.... You know, one that's good for regular day to day use, too.
If you happen to be stuck in a Dell only shop, it looks like you will not be left high and dry when it comes to Chromeboxes.
It looks like the Chromebox vendors are started to really line up. It seems like Samsung has had one forever (they're on their 2nd generation) and now HP, Asus, and Dell are going to be releasing models.
*Just in case you missed the "Chromebox for Meetings" news, I'm not kidding, they really chose to call it Chromebox for Meetings, here's a link to the Google page to prove it:
http://www.google.com/intl/en/chrome/business/solutions/for-meetings.html
It looks like Dell may be preparing to release a Chromebox. They may have gotten to the Chromebook party really late but it looks like they might show up at the Chromebox party pretty close to everyone else. Well, I guess technically Samsung has had a Chromebox out for years, but one person doesn't make a party. They were just really early, because it seems like the Chromebox party is just starting.
I haven't seen any direct press from Dell about a standalone Chromebox, but I've seen Dell mentioned several times as being one of the providers of the Chromebox for Meetings* hardware. In fact, here is Dell's own press release where they mention that they are developing a Dell Chromebox for meetings. Surely if they're developing one for meetings they'll develop one that's not just for meetings.... You know, one that's good for regular day to day use, too.
If you happen to be stuck in a Dell only shop, it looks like you will not be left high and dry when it comes to Chromeboxes.
It looks like the Chromebox vendors are started to really line up. It seems like Samsung has had one forever (they're on their 2nd generation) and now HP, Asus, and Dell are going to be releasing models.
*Just in case you missed the "Chromebox for Meetings" news, I'm not kidding, they really chose to call it Chromebox for Meetings, here's a link to the Google page to prove it:
http://www.google.com/intl/en/chrome/business/solutions/for-meetings.html
Wednesday, February 12, 2014
VDI and Chromebooks
VDI, Virtual Desktop Infrastructure, right? In the K-12 market it hasn't made a whole lot of sense. There are some good use cases for it (customized lab environments anyone?), but the cost of maintaining it hasn't made sense. The dollar cost and the manpower cost, too. Traditionally, school technology departments have been understaffed.
VDI falls into the category of nice to have, but not very feasible to implement. The obvious problem is cost. You want me to deploy $300+ thin clients? Wait, I'm getting fully functional refurbished computers for $300 or $500 (depends on the model). Ok, so just deploy those desktops and then use them as clients. That would work... Except now we're maintaining a bunch of desktops and a bunch of virtual machines. Remember what I said about the manpower cost? We're already under staffed as it is, who's going to keep all of those machines up and running?
That's where the Chromebooks come into play. They can be had for less than $300, which makes them cheaper than thin clients. And those are even portable in a laptop form factor too. How about desktops? That hasn't been as cheap until just recently (see my post here http://practicalschooltech.blogspot.com/2014/02/an-affordable-chromebox-finally.html). Combine that $179 Chromebox with a monitor, keyboard, and mouse and now you've got a full thin client for around $300 too.
You might be wondering now, what's the big deal. Now you've got to maintain all of those Chrome devices and the VDI. Chrome devices don't have that much administrative overhead. They patch themselves, there's no software to install, and a reboot fixes most problem. Still got problems? Swap one Chrome device for another, all the users stuff follows their login so it's seamless to them, and work on the malfunctioning device on your own schedule. The users are happy and the tech staff is happy too.
This sounds good in theory, but how feasible is it, and how well does it work in practice? I agree with the theory and in practice I don't know, because I haven't tried it yet. But the feasible-ness has been a real question wondering around in my mind. Sure, there were remote clients available for the Chrome devices, but no body had a whole package put together to build VDI and use a Chrome device as a client. Was I missing something? Was it just so obvious nobody had done it? Was it not possible? Did it just not work very well?
Since I don't have any VDI infrastructure in place I couldn't really test how well it worked in practice. I've remoted hundreds of machines from my Chromebook, using both VNC and RDP. I haven't had any problems there, but I'm not a typical end user. I know the addresses of the machines that I'm connecting to and I'm so used to minor hiccups my mind just glosses right over them and I don't even notice them anymore. With out actually having all the pieces to try it myself I needed to see someone else doing it, or at least trying it.
That's when I stumbled upon Citrix's VDI-in-a-Box setup. Specifically, their HTML5 Receiver (which ironically, specifically targeted Chrome at first but now they've switched to HTML5). Here's a post from Citrix themselves talking about it, http://blogs.citrix.com/2013/12/05/new-in-vdi-in-a-box-5-4-built-in-html5-receiver/, and check it out. The first use case they mention is "schools", in fact that's the opening word of the post. Exactly what I was looking for, somebody that was trying to put the pieces together. Now I've just got to get my hands on a demo copy of the VDI-in-a-Box so I can try it out and see how it works.
Anybody out there had any experience with this yet?
VDI falls into the category of nice to have, but not very feasible to implement. The obvious problem is cost. You want me to deploy $300+ thin clients? Wait, I'm getting fully functional refurbished computers for $300 or $500 (depends on the model). Ok, so just deploy those desktops and then use them as clients. That would work... Except now we're maintaining a bunch of desktops and a bunch of virtual machines. Remember what I said about the manpower cost? We're already under staffed as it is, who's going to keep all of those machines up and running?
That's where the Chromebooks come into play. They can be had for less than $300, which makes them cheaper than thin clients. And those are even portable in a laptop form factor too. How about desktops? That hasn't been as cheap until just recently (see my post here http://practicalschooltech.blogspot.com/2014/02/an-affordable-chromebox-finally.html). Combine that $179 Chromebox with a monitor, keyboard, and mouse and now you've got a full thin client for around $300 too.
You might be wondering now, what's the big deal. Now you've got to maintain all of those Chrome devices and the VDI. Chrome devices don't have that much administrative overhead. They patch themselves, there's no software to install, and a reboot fixes most problem. Still got problems? Swap one Chrome device for another, all the users stuff follows their login so it's seamless to them, and work on the malfunctioning device on your own schedule. The users are happy and the tech staff is happy too.
This sounds good in theory, but how feasible is it, and how well does it work in practice? I agree with the theory and in practice I don't know, because I haven't tried it yet. But the feasible-ness has been a real question wondering around in my mind. Sure, there were remote clients available for the Chrome devices, but no body had a whole package put together to build VDI and use a Chrome device as a client. Was I missing something? Was it just so obvious nobody had done it? Was it not possible? Did it just not work very well?
Since I don't have any VDI infrastructure in place I couldn't really test how well it worked in practice. I've remoted hundreds of machines from my Chromebook, using both VNC and RDP. I haven't had any problems there, but I'm not a typical end user. I know the addresses of the machines that I'm connecting to and I'm so used to minor hiccups my mind just glosses right over them and I don't even notice them anymore. With out actually having all the pieces to try it myself I needed to see someone else doing it, or at least trying it.
That's when I stumbled upon Citrix's VDI-in-a-Box setup. Specifically, their HTML5 Receiver (which ironically, specifically targeted Chrome at first but now they've switched to HTML5). Here's a post from Citrix themselves talking about it, http://blogs.citrix.com/2013/12/05/new-in-vdi-in-a-box-5-4-built-in-html5-receiver/, and check it out. The first use case they mention is "schools", in fact that's the opening word of the post. Exactly what I was looking for, somebody that was trying to put the pieces together. Now I've just got to get my hands on a demo copy of the VDI-in-a-Box so I can try it out and see how it works.
Anybody out there had any experience with this yet?
Labels:
chromebook,
Chromebox,
chromeos,
citrix,
vdi,
vdi-in-a-box
Subscribe to:
Posts (Atom)
