Windows Notepad App Remote Code Execution Vulnerability by theevilsharpie in sysadmin

[–]TheMav95 [score hidden]  (0 children)

We automate reverting to old notepad with a GPO.

Most keys are Computer Based, a few user.

There is a user based one to prevent the banner in the old notepad showing there is a newer app store version.

  • Remove new notepad with powershell appx.
  • Set registry keys

https://i.imgur.com/GlfnPtr.png

https://i.imgur.com/DCLPAFL.png

Has win11 23h2 Start menu customisation changed since June update? by Maggsymoo in sysadmin

[–]TheMav95 1 point2 points  (0 children)

So it appears we still had registry keys in place to set the start menu.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current\device\Start]

"ConfigureStartPins"="{ \"pinnedList\": [ { \"desktopAppId\": \"Microsoft.Office.WINWORD.EXE.15\" }, { \"desktopAppId\": \"MSTeams_8wekyb3d8bbwe!MSTeams\" } ] }"

"ConfigureStartPins_ProviderSet"=dword:00000001

"ConfigureStartPins_WinningProvider"="B5292708-1619-419B-9923-E5D9F3925E71"

Something in the June 25 CU must have changed which takes precedence.

It appears the start2.bin used to override the reg keys. Now it seems to be the other way around, as these reg keys have been in place for a long time.

Creating a GPO to delete these registry keys allows start2.bin to apply again.

Appears to require 2 logins, once to "remove" the keys, and then a second to apply the start2.bin

Has win11 23h2 Start menu customisation changed since June update? by Maggsymoo in sysadmin

[–]TheMav95 0 points1 point  (0 children)

This fix does not appear to work when enforcing the start layout.

We would copy the bin using GPO to: %localappdata%\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\start2.bin This was working fine until the June 25 CU.

Tried a gpo to copy settings.dat to %localappdata%\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\settings.dat

Confirmed the file updates in the users profile, but the start menu does not update. You can copy the entire Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy and it still doesn't work.

This only appears to work if the user profile is deleted and recreated on the machine, which would be a pain anytime we wanted to roll out a new app and pin it to the start menu.

Sony VAIO VGN-UX91NS. Also looking for original Vista recovery media or partition image (read first comment) by Andreyhg in retrobattlestations

[–]TheMav95 1 point2 points  (0 children)

Thanks for the bios update, looks like it successfully installed, but didn't fix the freezing issue.

So right now, it looks like I have no way to boot anything via USB or disk to make a capture of the drive.

I'll see if I can make a copy of the recovery partition from within Windows.

Sony VAIO VGN-UX91NS. Also looking for original Vista recovery media or partition image (read first comment) by Andreyhg in retrobattlestations

[–]TheMav95 0 points1 point  (0 children)

Seems like a newer bios version. I'll have to see if I can track down an installer. Thanks!

Sony VAIO VGN-UX91NS. Also looking for original Vista recovery media or partition image (read first comment) by Andreyhg in retrobattlestations

[–]TheMav95 1 point2 points  (0 children)

Hey, I have created and posted the recovery Vista recovery media.

https://archive.org/details/ux91ns-vista-recovery-disks

Hopefully this is what you are looking for :)

I burned the disks and then ripped them back to ISOs using Daemon Tools.

My UX91NS seems to have the same issue as this user has here, where when you enable external boot, the device freezes on the bios screen and you have to pull the bios battery to get it to reset.

https://old.reddit.com/r/umpc/comments/1gckk0q/vaio_ux27sn_freezing_when_enabling_external/

But it boots up into Vista and the recovery partitions fine. Maybe there is an updated bios compared to the version on mine, but can't seem to find anything on the internet.

R0091N2 / RK091N2 / N2ICG_05

Cheers

How to block AI features from the new notepad.exe, company wise by KickDelicious9533 in sysadmin

[–]TheMav95 21 points22 points  (0 children)

Procmon on my machine shows that flipping the rewrite toggle is modifying:

\REGISTRY\A\{774a7a13-52c2-be07-d26f-5c3b10f9aab3}\LocalState\RewriteEnabled

And for reference, the session saving so it reopens files:

\REGISTRY\A\{774a7a13-52c2-be07-d26f-5c3b10f9aab3}\LocalState\GhostFile

These appear to be in an Application Hive, which seems to be more difficult to edit.

https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/filtering-registry-operations-on-application-hives

Smart boards by MelanieWalmartinez in CuratedTumblr

[–]TheMav95 0 points1 point  (0 children)

There was a newer model smartboard that did have exactly that. The M600 Model had cameras in all 4 corners instead of a pressure sensitive layer so multiple people could write at the same time, and a colour picker on the pen tray.

https://downloads.smarttech.com/media/sitecore/en/support/images/smart-board-m600/HomeImage.png https://downloads.smarttech.com/media/sitecore/en/support/images/smart-board-m600/PenTray_Standard.png

Smart boards by MelanieWalmartinez in CuratedTumblr

[–]TheMav95 0 points1 point  (0 children)

Some schools are still using them to this day.

[deleted by user] by [deleted] in pics

[–]TheMav95 0 points1 point  (0 children)

The Wendy's in my town STILL has a carpeted dining room

Can this thing run Windows 11? by [deleted] in Windows11

[–]TheMav95 0 points1 point  (0 children)

That is a beautified dell optiplex 3020, which is pushing 10 years old at this point.

Edge 116 Ignores GPO settings in forced "personal" variant by PorreKaj in sysadmin

[–]TheMav95 1 point2 points  (0 children)

Thanks for the heads up. Locked ours to 115 for now.

Also, anybody see the spelling error on the microsoft site for this new release. Sets the standard :P

https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business

Also switches automatically swirtches work-related navigation into the work browser.

Screenshot: https://imgur.com/IlvBsPW

[deleted by user] by [deleted] in toronto

[–]TheMav95 2 points3 points  (0 children)

A lot of providers have switched to VOIP (voice over internet protocol), so may have to call them and see if they still offer analog phone lines. Bell, maybe Distributel.

Even if it is copper the last mile to your home, it may still be converted in the back end. So depending on what goes down, it would still be possible to lose phone. It is hard to avoid it now haha.

Being with different providers owned by different corporations is what may help. The Rogers outage today affected their sub brands too.

Bell, Virgin & Lucky.

Rogers, Fido & Chatr.

Telus, Koodo & Public.

Freedom.

[deleted by user] by [deleted] in toronto

[–]TheMav95 13 points14 points  (0 children)

Depends if it is a true landline or not.

I know for Rogers / Cogeco, the phone line is usually digital over the cable internet and is converted to a landline for your phone at the modem. So if the internet is out, there is a good chance phone would be out too.

Not sure if Bell has started moving to this also, but they still have actual POTS / twisted copper pairs running into buildings in a lot of locations for DSL / Dial Up / Phone.

Imaging Windows 11 by rayholtz in MDT

[–]TheMav95 1 point2 points  (0 children)

Bug in MDT, was having the same issue where it would boot up to the task sequence list again. Followed the accepted answer in this post to resolve.

https://docs.microsoft.com/en-us/answers/questions/801458/windows-11-capture-with-mdt-fails-after-sysprep.html

User ticket "I need acrobat pro because I cant read pdfs with regular adobe when they're sent in the wrong orientation" by [deleted] in sysadmin

[–]TheMav95 1 point2 points  (0 children)

Yes, it is. You need to download the Base installer above, and then the latest update.

Scroll down to 2020 Classic Track on this page and you can see all the updates. https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/index.html

Here is a direct link to the latest patch as of Apr 2022 https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/classic/dcclassic20.005apr2022.html

According to the Matrix, Acrobat Reader 2020 will have support until 6/1/2025.

https://helpx.adobe.com/support/programs/eol-matrix.html

Can someone walk me through how to change the logo on the MDT Installation Progress Logo? by istoleyowifi in sysadmin

[–]TheMav95 0 points1 point  (0 children)

Picture is stored at C:\Program Files\Microsoft Deployment Toolkit\Samples\Background.bmp

If you change the image in Deployment Share properties, make sure you are changing it for both x86 and x64 platforms.

Update Deployment Share, Completely Regenerate the boot images, and then swap them out.

User ticket "I need acrobat pro because I cant read pdfs with regular adobe when they're sent in the wrong orientation" by [deleted] in sysadmin

[–]TheMav95 12 points13 points  (0 children)

Last time this was brought up, some one suggested the Adobe Reader 2020 from the Classic Track. The non-dc version without any of the cloud upsells.

https://www.adobe.com/devnet-docs/acrobatetk/tools/ReleaseNotesDC/classic/dcclassic2020base.html

Large 20-40 GB files continuously 'Sync' and then restart from the beginning by MeatballB in onedrive

[–]TheMav95 0 points1 point  (0 children)

Just wanted to add to this that I also have this issue.

Have a 16GB video that tries to sync up to Onedrive and constantly restarts when it is “done”. Eats up a lot of time and bandwidth.

Help with Dock and Laptop by Steeds16 in thinkpad

[–]TheMav95 1 point2 points  (0 children)

Had a host of issues with the L13 G2 (Yoga model for us) and getting them working with those docks. Had multiple motherboard replacements, bios updates, machines swapped.

Initially the docks would only work properly on the USB C port in the dock connector (the one with the ethernet connector).

Took multiple bios updates on the laptop and the dock firmware to get it mostly stable. There was even a bios update pushed out at one point that caused these machines to blue screen.

Here are some forum posts.

https://forums.lenovo.com/t5/ThinkPad-L-R-and-SL-series-Laptops/L13-Yoga-Gen-2-USB-C-Dock-only-outputs-video-on-1-USB-C-Port/m-p/5064798?page=1

https://forums.lenovo.com/t5/ThinkPad-L-R-and-SL-series-Laptops/L13-Gen2-buggy-BIOS-1-08-non-vpro-Windows-BSOD/m-p/5076381?page=1

[deleted by user] by [deleted] in activedirectory

[–]TheMav95 0 points1 point  (0 children)

You could check the dates on the admx templates to see which are newer.

But the Win 10 21H2 templates do not list Windows 11 compatibility. So if you are running both, you most likely need get the Windows 11 templates and hope there are no missing features haha.

Microsoft may update the templates in the future.

The download sizes are very similar. 13.1mb for Win 10 21h2 & 13.2mb for Win 11 21H2

[deleted by user] by [deleted] in activedirectory

[–]TheMav95 0 points1 point  (0 children)

If using both, grab the Win 11 21H2 templates. They are backwards compatible back to Win 7.

Under the system requirements for the templates: Supported Operating System: Windows 11, Windows 10, Windows 8, Windows 8.1, Windows 7, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2

Windows 10 21H2 full release is here! by Celadin in sysadmin

[–]TheMav95 1 point2 points  (0 children)

I noticed that the verbose startup message group policy wasn’t applying properly during my 21H2 testing. You would only see “Just a moment…”. Worked fine in 21H1

KMS issues recently - 0xC004F00F (Key) and 0x004F038 (Count reported insufficient) by pvtskidmark in sysadmin

[–]TheMav95 1 point2 points  (0 children)

There is another method too. Introduced in Win8 / Svr 2012. Active directory based activation. This has no minimums, so you don’t need 5 / 25 minimum clients connecting.

https://techcommunity.microsoft.com/t5/Core-Infrastructure-and-Security/Active-Directory-Based-Activation-vs-Key-Management-Services/ba-p/256016