Quantcast
Channel: Sysinternals Forums
Viewing all 10386 articles
Browse latest View live

Miscellaneous Utilities : handle.exe misses loaded dlls

$
0
0
Author: timbojones
Subject: handle.exe misses loaded dlls
Posted: 21 March 2014 at 11:47pm

I have found several instances where a process (e.g. robocopy, p4) fails because it can't overwrite a dll file, after handle.exe reports no files in use in the directory.  We have worked around this in most cases by also looking for processes running in that directory, but this workaround is insufficient when the exe loading the dll is running from another directory.

Is there some secret handle.exe argument or another tool that can detect dlls that are locked without having a handle open to them?

I know that tasklist.exe can detect whether a particular module is in use, but I would prefer not to manually enumerate all the modules in a directory.

I want a tool that I can run to determine whether a directory is clear to be removed or replaced, and if not, which processes are preventing it.

PsTools : PsExec Slow with Firewall Enabled

$
0
0
Author: eb52
Subject: PsExec Slow with Firewall Enabled
Posted: 23 March 2014 at 5:59am

I also had this problem when trying to use a Win7 machine to run a program remotely on a WinXP machine. In the WinXP machine Windows Firewall, I opened TCP port 80 for the IP address of the Win7 machine, and this seems to have fixed the problem. I also created an exclusion for psexesvc.exe in my antivirus program, and this sped things up by another couple of seconds.

PsTools : PsExec to launch admin-level task from LU account

$
0
0
Author: AndyA
Subject: PsExec to launch admin-level task from LU account
Posted: 23 March 2014 at 5:31pm

I've recently converted from XP Pro to Windows 7 Pro (Wn7). Under Wn7, I have an admin account, which will be restricted to software installs, and a Standard (Limited) user (LU) account, which will be used the bulk of the time. For now, I've left UAC at default settings.

Under XP, I also used an LU account. I wrote VBS scripts that, for example, used psexec to enable services, run applications and then disable the services.

I'm trying to set up equivalent scripts under Wn7, but have been unsuccessful so I'm appealing here for help.

All of the scripts are being run locally. Remote access is not an issue. The passwords can be present in the scripts in clear text. There are no local security risks.

All of the scripts are written in VBS, with which I'm very familiar.

Ideally, the script should require no user interaction and present no UAC prompts.

As an example, let's say I'd like to have a script start a service.

The VBS would look like something as follows:

Dim Wshso : Set Wshso = WScript.CreateObject("WScript.Shell")

Wshso.Run "psexec.exe -h -u my_username_here -p my_password_here " &_
 WScript.FullName & " " & """" & path_and_VBS_name_here & """"

The script should be launched with admin privileges. It does get launched, but without admin privileges. (The script is unable to start a service.)

I've done lots of reading, but I've obviously missed something.

I read the thread about PsExec on Vista.
I found references to cmdkey.
I tried to use a scheduled task, but it turns out that an LU cannot create a Scheduled Task.
I also looked into alternative utilities.

So far, nothing has worked.

If UAC is left enabled, can I use PsExec to launch a script from an LU account with admin privileges? What's the syntax?

TIA.

regards, AndyA

Troubleshooting : Listview - No Commas =[

$
0
0
Author: xiaoyuantcm
Subject: Listview - No Commas =[
Posted: 24 March 2014 at 6:45am

Nice to see this problem got solved with the just changing of regional settings, I started to doubt with the UI listview control and started to study something on the listview control guide. This thread helps.

Process Explorer : Tree View Greyed Out

$
0
0
Author: xiaoyuantcm
Subject: Tree View Greyed Out
Posted: 24 March 2014 at 6:50am

Does the way to edit the regedit.exe can fix it? I ever considered to shift to some UI treeview control.

Disk2vhd : does vhd2hd work on windows 8.1 pro

$
0
0
Author: carey
Subject: does vhd2hd work on windows 8.1 pro
Posted: 24 March 2014 at 4:58pm

I am currently trying to learn new things and wanted to virtual hard drive on my laptop and see what I can do with it. So, my question can I use it on windows 8.1 pro.

carey


PsTools : PsExec to launch admin-level task from LU account

$
0
0
Author: AndyA
Subject: PsExec to launch admin-level task from LU account
Posted: 24 March 2014 at 8:33pm

I still haven't found a way to launch a program locally as an admin from an LU account with PsExec.

For example, if I try to launch regedit with just the -u and -p parameters, I receive the message that "The requested operation requires elevation," which is expected.

If I add the "-h" parameter, I get the message:

Couldn't install PsExec service:
Access is denied.

FWIW, I found an alternative utility, RunasRob. It does what's needed by installing itself as a service.

Since PsExec also launches as a service, it's not clear why PsExec can't be used to do the same thing.

If anyone can enlighten me on the way to use PsExec to launch an admin-level task locally from an LU account, I'd be grateful. Otherwise, I'll stick with RunasRob.

regards, AndyA

PsTools : PSEXEC works with firewall on, not off

$
0
0
Author: eugenekwalker
Subject: PSEXEC works with firewall on, not off
Posted: 24 March 2014 at 9:23pm

Update.  I believe I am running into the Windows 7 boot time filters which automatically load when the firewall is disabled.  Saw this and am leaning toward this a a possible reason why.  If anyone can debunk this direction, please same me the effort in going forward.

http://blogs.technet.com/b/networking/archive/2009/03/24/stopping-the-windows-authenticating-firewall-service-and-the-boot-time-policy.aspx

Thanks,

Gene

Process Monitor : Promon 3.10 - Bug - Missing events

$
0
0
Author: pvicenti
Subject: Promon 3.10 - Bug - Missing events
Posted: 25 March 2014 at 1:20pm

I've seen this several times. SpyStudio hooks at user level so it cannot loose any operation and the results are equal to what the application sees.
I've seen worse situation when you monitor virtual applications where you've got a sandbox app between the app and the kernel.

Disk2vhd : issues with multiple partitons

$
0
0
Author: bicosteel
Subject: issues with multiple partitons
Posted: 25 March 2014 at 7:30pm

Hello all, I have a Win2008 R2 server that I am running Disk2VHD on and have run into issues. The host will be Hyper-v 2012 Server.
Anyway on the phsyical server the raid is partioned into mulitple drives.Looking in disk management shows
C = 123 GB
D = 100 GB
D = 75.04 GB
 
When I run disk2 with just C: selected I get a working NTFS 123GB C with the OS on it and then 2 raw partitons that are the 100GB and the 75.04GB.
When I run with just D I get the 175GB but it shows as invalid and RAW. Can't do anything with it.  Any help would be great.

BgInfo : Great BGInfo Replacement

$
0
0
Author: WindowsStar
Subject: Great BGInfo Replacement
Posted: 26 March 2014 at 3:34am

Everyone, I have been testing DesktopInfo as a replacement for BGInfo. So far I have it working very well on several test machines. The programmer is very nice and seems to be updating this software regularly. Everyone should give it a try and see if it will do what you want.

http://www.glenn.delahoy.com/software/

Enjoy -WS

Miscellaneous Utilities : VMMap crash 64bit exe with /LARGEADDRESSAWARE:NO

$
0
0
Author: kudryavka
Subject: VMMap crash 64bit exe with /LARGEADDRESSAWARE:NO
Posted: 26 March 2014 at 10:39am

Viewing64-bit process that memory space has truncated to 2GB by /LARGEADDRESSAWARE:NO, VMMap will crash.

Launch new process with /LAA:NO-ed exe file will fail (in Windows 8.1) or crash VMMap (in Windows 7).

Autoruns : Autoruns corrupts Win8 registry ???

$
0
0
Author: Mausebaer
Subject: Autoruns corrupts Win8 registry ???
Posted: 26 March 2014 at 11:27am

...No ideas...? Cry

PsTools : Different delay in PsPing test

$
0
0
Author: ivanls
Subject: Different delay in PsPing test
Posted: 26 March 2014 at 2:22pm

Hi everybody,

I'm working with PsPing tool with the aim of measuring the delay introduced by a network.

When I execute a ping test (ICMP and TCP) the average measured time is about 16 ms. However executing the TCP latency test (packetsize: 32 KBytes) the measured time is about 5.5 ms. 

How could be possible this big difference? Which measure is most reliable?

Thank you.


Edited by ivanls - 8 hours 37 minutes ago at 2:23pm

PsTools : PSEXEC to start teamviewer

$
0
0
Author: davzell13
Subject: PSEXEC to start teamviewer
Posted: 26 March 2014 at 2:34pm

hello, excuse my bad english i'm french.

in my society i can't use teamviewer such as a service.
i want run teamviewer in a distant computer with no user action.

i use psexec to do that with this command: psexec \\server -u domain\admin -p password -i 26 "c:\teamviewer.exe"

it's work fine but only if my session admin is active.

Is it possible to do this with no active session ? maybe with the -s argument ?

when i try => psexec to do that with this command: psexec \\server -u domain\admin -p password -s "c:\teamviewer.exe"

the process apaer 1 second and disapaer.

Thank you in advance.


Miscellaneous Utilities : Coreinfo

$
0
0
Author: Dale 61
Subject: Coreinfo
Posted: 26 March 2014 at 2:48pm

Could some one please tell me how to get Coreinfo to run and stay open ? CMD Window closes way to fast to gather any information .  Thank You.

Disk2vhd : Stops at 99%

$
0
0
Author: ntt
Subject: Stops at 99%
Posted: 26 March 2014 at 3:20pm

I have the same problem. Disk2vhd converted my Samsung 20GB hdd successfully but stops at 100% when I try to convert my 20GB Seagate hdd.
I have tried this with two different computers with windows xp but it always stops with this one Seagate hdd. In other words, is there maybe some problem with the hdd? On the other hand, the (physical) hdd is ok and works normally.

Internals : When is the 7th edition book for Win 8 coming out

$
0
0
Author: pk
Subject: When is the 7th edition book for Win 8 coming out
Posted: 26 March 2014 at 9:55pm

Update from http://www.azius.com:

Windows Internals, 7th edition

After the release of each new major version of Windows, I.T. professionals, developers of all stripes, and OEMs eagerly await the publication of the next edition of the book (or, more recently, set of books) that documents how it all works inside. 

Azius principals Brian Catlin and Jamie Hanrahan have signed with Microsoft Press to write Windows Internals, 7th Edition, Book 1: "User Mode." The 7th edition will cover Windows 8.1 and Server 2012 R2. To be released in Spring of 2014, Book 1 will primarily cover user mode aspects (the internals of application support) and system management mechanisms. New coverage for the 7th edition will include .NET, graphics and the desktop, Windows RT, Windows Store applictions, and server management features, as well as expanded coverage of networking. 

Books 2 and 3 are still in the planning stages, but our current plans are for Book 2 to cover kernel mode components and mechanisms, and Book 3, new for this edition, will describe the architecture and operation of the various Windows device driver models. 

Of course, Windows Internals, 6th Edition, by Mark Russinovich, David Solomon, and Alex Ionescu, will be the starting point for this work. (We contributed to the 6th edition and are credited as such in the introduction.)


Internals : When is the 7th edition book for Win 8 coming out

$
0
0
Author: MagicAndre1981
Subject: When is the 7th edition book for Win 8 coming out
Posted: 27 March 2014 at 4:43pm

thanks for the update :)

PsTools : Update PsShutdown to support Connected Standby

$
0
0
Author: jfelts
Subject: Update PsShutdown to support Connected Standby
Posted: 28 March 2014 at 12:56am

currently if you use "PsShutdown.exe -d" to suspend a platform with connected standby enabled, it will hibernate instead.

Is there plans to support or add support for CS on Win8/8.1?
Viewing all 10386 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>