Quantcast
Channel: Sysinternals Forums
Viewing all 10386 articles
Browse latest View live

Troubleshooting : ntoskrnl.exe hogging the CPU

$
0
0
Author: pinscomputer
Subject: ntoskrnl.exe hogging the CPU
Posted: 26 May 2015 at 2:42pm

BEFORE you start disassembling a laptop... as long as the laptop is not too old, there is software available that might be able to read the RPM of the fan.
 
try hwmonitor...no need to install. just use the portable ZIP version.
 
 

Process Monitor : Procmon 3.11 crashes on my system

$
0
0
Author: FFreestyleRR
Subject: Procmon 3.11 crashes on my system
Posted: 26 May 2015 at 10:12pm

Process Monitor 3.20 is crashing the same way! :(

Process Monitor : no chm file

$
0
0
Author: Dax1792
Subject: no chm file
Posted: 26 May 2015 at 10:35pm

Just seems that someone forgot to add them.
If you down load the whole suite the files are in there.

Process Monitor : no chm file

$
0
0
Author: mikesan
Subject: no chm file
Posted: 26 May 2015 at 11:13pm

Many thanks for the quick reply.
I will try your suggestion.

Process Explorer : How to find what is using my resouces

$
0
0
Author: eddferrell
Subject: How to find what is using my resouces
Posted: 27 May 2015 at 2:11am

Thanks for the response MagicAndre1981,
Sorry for the delay, I appreciate your help.

Just everything is slow. Its plain to see from even the most simple things like re sizing a window, scrolling a folders files, or clicking the Start Button.

You mention that ProcessMonitor will tell me what is calling the "timeout.exe" programs but I just don't know what to look for.

Do you know of a way to sample 10 seconds of so of the activity and then be able to read what is causing the slowdown. Even with no clients connected to the server there seems to be a lot of activity from multiple programs.

Any advice would be welcomed. Thanks for your help.
Edd

Process Explorer : How to find what is using my resouces

Process Explorer : How to find what is using my resouces

$
0
0
Author: MagicAndre1981
Subject: How to find what is using my resouces
Posted: 27 May 2015 at 5:03am

a cmd.exe calls it. Look at the commandline column of the cmd.exe

Troubleshooting : Need help to fix high CPU interrupts.

$
0
0
Author: holian
Subject: Need help to fix high CPU interrupts.
Posted: 27 May 2015 at 7:56am

I reinstall the core windows, and no problem.
So i got an other version of Windows 8.1 Pro, and made a clean install.

With no drivers, just the clean-virgin Windows 8.1 Pro the problem still persist.

But before i run the one-key recovery and restore the factory drivers the problem gone!

I did't made intel driver update as before, maybee that was the problem.


Process Explorer : Error replacing Task Manager: Access is denied.

$
0
0
Author: Briahas
Subject: Error replacing Task Manager: Access is denied.
Posted: 27 May 2015 at 9:26am

Originally posted by allforinternet2 allforinternet2 wrote:

Originally posted by Briahas Briahas wrote:

..
hello!
Did you found the solution of your problem? I have the same situation on both systems: Windows 7 home premium 64bit and Windows 7 home premium 32bit.
Hi. No. I found nothing.
just add it to autorun

Process Explorer : ** Process Explorer Bugs **

$
0
0
Author: mas912
Subject: ** Process Explorer Bugs **
Posted: 27 May 2015 at 11:46am

Process Explorer (latest version) doesn't count .NET processes in status bar.

< style="height: 80px; width: 444px; border-top-color: rgba7, 0, 0, 0; border-left-color: rgba7, 0, 0, 0; border-right-color: rgba7, 0, 0, 0; border-bottom-color: rgba7, 0, 0, 0; border-top-width: 1px; border-left-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-top-style: solid; border-left-style: solid; border-right-style: solid; border-bottom-style: solid; padding-top: 2px; padding-right: 2px; padding-bottom: 2px; padding-left: 2px;">

But it hightlights them in list.

< value="af">Afrikaans< value="sq">Albanian< value="ar">Arabic< value="hy">Armenian< value="az">Azerbaijani< value="eu">Basque< value="be">Belarusian< value="bg">Bulgarian< value="ca">Catalan< value="zh-CN">Chinese (Simplified)< value="zh-TW">Chinese (Traditional)< value="hr">Croatian< value="cs">Czech< value="da">Danish< value="auto" ed="ed">Detect language< value="nl">Dutch< value="en">English< value="et">Estonian< value="tl">Filipino< value="fi">Finnish< value="fr">French< value="gl">Galician< value="ka">Georgian< value="de">German< value="el">Greek< value="ht">Haitian Creole< value="iw">Hebrew< value="hi">Hindi< value="hu">Hungarian< value="is">Icelandic< value="id">Indonesian< value="ga">Irish< value="it">Italian< value="ja">Japanese< value="ko">Korean< value="la">Latin< value="lv">Latvian< value="lt">Lithuanian< value="mk">Macedonian< value="ms">Malay< value="mt">Maltese< value="no">Norwegian< value="fa">Persian< value="pl">Polish< value="pt">Portuguese< value="ro">Romanian< value="ru">Russian< value="sr">Serbian< value="sk">Slovak< value="sl">Slovenian< value="es">Spanish< value="sw">Swahili< value="sv">Swedish< value="th">Thai< value="tr">Turkish< value="uk">Ukrainian< value="ur">Urdu< value="vi">Vietnamese< value="cy">Welsh< value="yi">Yiddish< value="af">Afrikaans< value="sq">Albanian< value="ar">Arabic< value="hy">Armenian< value="az">Azerbaijani< value="eu">Basque< value="be">Belarusian< value="bg">Bulgarian< value="ca">Catalan< value="zh-CN">Chinese (Simplified)< value="zh-TW">Chinese (Traditional)< value="hr">Croatian< value="cs">Czech< value="da">Danish< value="nl">Dutch< value="en">English< value="et">Estonian< value="tl">Filipino< value="fi">Finnish< value="fr">French< value="gl">Galician< value="ka">Georgian< value="de">German< value="el">Greek< value="ht">Haitian Creole< value="iw">Hebrew< value="hi">Hindi< value="hu">Hungarian< value="is">Icelandic< value="id">Indonesian< value="ga">Irish< value="it">Italian< value="ja">Japanese< value="ko">Korean< value="la">Latin< value="lv">Latvian< value="lt">Lithuanian< value="mk">Macedonian< value="ms">Malay< value="mt">Maltese< value="no">Norwegian< value="fa">Persian< value="pl">Polish< value="pt">Portuguese< value="ro">Romanian< value="ru" ed="ed">Russian< value="sr">Serbian< value="sk">Slovak< value="sl">Slovenian< value="es">Spanish< value="sw">Swahili< value="sv">Swedish< value="th">Thai< value="tr">Turkish< value="uk">Ukrainian< value="ur">Urdu< value="vi">Vietnamese< value="cy">Welsh< value="yi">Yiddish
Detect language » Russian

Autoruns : GpExtensions not found in Wow6432Node

$
0
0
Author: crayy8
Subject: GpExtensions not found in Wow6432Node
Posted: 27 May 2015 at 2:57pm

Has anyone else noticed that autoruns does not display autorun entries for GpExtensions found under the Wow6432Node key? I couldn't find any previous discussion about this on the forums. I am wondering if anyone else has the same issue. 

Troubleshooting : Need help to fix high CPU interrupts.

$
0
0
Author: MagicAndre1981
Subject: Need help to fix high CPU interrupts.
Posted: 27 May 2015 at 5:51pm

Where have you downloaded the drivers? From Intel or from the OEM page?

Process Monitor : Procmon 3.11 crashes on my system

$
0
0
Author: MagicAndre1981
Subject: Procmon 3.11 crashes on my system
Posted: 27 May 2015 at 9:03pm

Can you please also post a dump of the crashing version 3.20?

Miscellaneous Utilities : BUG: RamMap version 1.32 creates invalid RMP file

$
0
0
Author: Olegas
Subject: BUG: RamMap version 1.32 creates invalid RMP file
Posted: 27 May 2015 at 10:55pm

BUG: RamMap version 1.32 creates invalid XML RMP file which leads to the file is not accessible or is not a valid XML file error.

The bug presents itself when RAMMAP is executed on a system which accessed a file with alternative stream and alternative stream name contains certain characters. RamMap is able to display special characters correctly, but it doesn’t correctly encode them into resulting RMP XML file.

I noticed this problem while trying to load a production RMP file from Windows 2008 R2. Several files contain alternate stream that begins with 0x5
For example:
<File Key="-8108308282432" Path="C:\windows\system32\tasks\microsoft\windows\pla\new data collector set:|0v1ieca3feahez0jawxjjk5urh"/>

00000000h: 3C 46 69 6C 65 20 4B 65 79 3D 22 2D 38 31 30 38 33 30 38 32 38 32 34 33 32 22 20 50 61 74 68 3D ; <File Key="-8108308282432" Path=
00000020h: 22 43 3A 5C 77 69 6E 64 6F 77 73 5C 73 79 73 74 65 6D 33 32 5C 74 61 73 6B 73 5C 6D 69 63 72 6F ; "C:\windows\system32\tasks\micro
00000040h: 73 6F 66 74 5C 77 69 6E 64 6F 77 73 5C 70 6C 61 5C 6E 65 77 20 64 61 74 61 20 63 6F 6C 6C 65 63 ; soft\windows\pla\new data collec
00000060h: 74 6F 72 20 73 65 74 3A 05 30 76 31 69 65 63 61 33 66 65 61 68 65 7A 30 6A 61 77 78 6A 6A 6B 35 ; tor set:.0v1ieca3feahez0jawxjjk5
00000080h: 75 72 68 22 2F 3E 0D 0A                                                                         ; urh"/>..

It isn’t clear which component creates such alternate stream (TrendMicro, etc), but the problem is reproducible on demand via the steps below:

1. Compile the code snippet below in VS 2005 with Unicode character set
<CODE>
HANDLE hFile, hStream;
DWORD dwRet;
CString csFileName, csAltStreamName;
csFileName = "c:\\temp\\FileWithAltStream.txt";
csAltStreamName = "c:\\temp\\FileWithAltStream.txt:";
csAltStreamName += wchar_t(0x05); //you can change this to other values between 0x01 and 0x31
csAltStreamName += "AltStream";

hFile = CreateFile( csFileName,
GENERIC_WRITE,
FILE_SHARE_WRITE,
NULL,
OPEN_ALWAYS,
0,
NULL );
if( hFile == INVALID_HANDLE_VALUE )
printf( "Cannot open file\n" );
else
WriteFile( hFile, "0123456789", 10, &dwRet, NULL );

hStream = CreateFile( csAltStreamName,
GENERIC_WRITE,
FILE_SHARE_WRITE,
NULL,
OPEN_ALWAYS,
0,
NULL );
if( hStream == INVALID_HANDLE_VALUE )
printf( "Cannot open alternate stream!\n" );
else
WriteFile(hStream, "9876543210", 10, &dwRet, NULL);
</CODE>

2. Execute the newly compiled utility
3. Confirm that the file and the alternate stream were created via the Streams utility

streams.exe -s C:\temp

Streams v1.56 - Enumerate alternate NTFS data streams
Copyright (C) 1999-2007 Mark Russinovich
Sysinternals - www.sysinternals.com

C:\temp\FileWithAltStream.txt:
      :♣AltStream:$DATA 10

4. Launch RamMap, switch to the File Summary tab.
5. Sort by Path and scroll down to C:\temp\. You should see the file and its alternate stream listed

6. Click File |Save to export output in XML
7. Close RamMap
8. Launch new RamMap instance and attempt to open the newly created RMP file

Expected results:
If I understand Windows file naming convention correctly, it allows for 0x1 through 0x31 being included within alternate stream name. RamMap should either replace or correctly encode those while saving output into XML RMP.


Actual results:
RamMap creates incorrectly encoded XML RMP file, which leads to "the file is not accessible or is not a valid XML file" error while loading previously created file.


Thank you,
Olegas

Process Monitor : Procmon 3.11 crashes on my system

$
0
0
Author: FFreestyleRR
Subject: Procmon 3.11 crashes on my system
Posted: 28 May 2015 at 6:04am

Here we go:

http://www77.zippyshare.com/v/Gsy8SlPS/file.html

Also I temporarily disabled UAC and SmartScreen, I tried Clean Boot and also I ran Windows Memory Diagnostics Extended Tests (no errors were found during the tests) with no avail.

Procmon 3.10 is still working as it should.

Thanks!


Regards,
Georgi

PsTools : PsInfo and cyrillic symbols

$
0
0
Author: Ilyich_true
Subject: PsInfo and cyrillic symbols
Posted: 28 May 2015 at 10:34am

still actual for me.

Disk2vhd : Commandline / shadow copy

$
0
0
Author: peter9999
Subject: Commandline / shadow copy
Posted: 28 May 2015 at 1:09pm

Hi! Great tool!

But I have one problem: I use Disk2vhd from batch. In this case it uses alway volume shadow copy as default, which leads in one case for me to a problem. How can I bypass that in a batch command file?

Miscellaneous Utilities : (hashes of) historic versions of sysintnal tools

$
0
0
Author: pc1
Subject: (hashes of) historic versions of sysintnal tools
Posted: 28 May 2015 at 3:36pm

Dear all,

We are deploying Applocker technology, we would like to implement a lockdown that will automatically approve any standard Microsoft signed binary except for the Sysinternal tools.

Unfortunately for us, the Sysinternal tools seem to be using the standard Microsoft code signing certfiicates. Offcourse I can download the most recent version and take the SHA/MD5 hash and ban them based on hash. However, that would leave the opportunity open for someone to circumvent applocker  by using and older version of the sysinternals tools.

Question:
- Is there an archive of older versions of the sysinternals tools?
- Or is there an overview of the MD5/Sha256 hashes?

I am mainly interested in AccessCHK, procdump, pstools (psexec)

Anybody ideas whether such a list of Sha hashes is available?

BgInfo : Support for Powershell for Custom Info

$
0
0
Author: Xanuri
Subject: Support for Powershell for Custom Info
Posted: 28 May 2015 at 4:09pm

Any chance there are plans to update this to support powershell scripts for custom data?

PsTools : RamMap does not work on Windows 8 CP

$
0
0
Author: sergokok
Subject: RamMap does not work on Windows 8 CP
Posted: 28 May 2015 at 4:25pm

Now RAMmap 1.32 doesn't work in Windows 10... i get error: Error refreshing database
Viewing all 10386 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>