Subject: Thread handle access is denied
Posted: 19 July 2017 at 3:26pm
I just noticed, what does that State of "Wait:Executive" mean?
The thread is waiting for the scheduler.
https://msdn.microsoft.com/en-us/library/tkhtkxxy(v=vs.110).aspx?cs-save-lang=1&cs-lang=csharp#code-snippet-1There is a nasty bug in Autoruns v13.71 (which is the latest version at thetime of this writing) that also exists all the way back to v13.01 and likely inversions before v13.01. The problem hasto do with the undesirable modification of the Windows Startup folders hiddenattribute. Now I’ll try to describe theproblem in more detail.
NOTE: Scenario #1 below assumes that you have no other startup programs inthe ‘User’ Startup or ‘All Users’ Startup folders in order to follow each ofthe steps outlined below and to see the same results described below.
Scenario #1
In Window #1, open the ‘User’Startup folder location:
“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”
or
You can instead click on Start: Programs: Startup: right click and select‘Open’
In Window #2, open the ‘All Users’Startup folder location:
“C:\ProgramData\Microsoft\Windows\Start Menu\Programs”
or
You can instead click on Start: Programs: Startup: right click and select‘Open All Users’
In Window #3, open the “C:\Windows\System32” folder.
Now copy (!don’t move!) a program say “C:\Windows\System32\cmd.exe” to the‘User’ Startup folder.
Now copy (!don’t move!) a different program say“C:\Windows\System32\notepad.exe” to the ‘All Users’ Startup folder.
Start Autoruns or click on the Refresh button.
Click on the Logon tab.
In the Options Menu, check ‘Hide Empty Locations’ and check ‘Hide WindowsEntries’ options and uncheck the other options to reduce the number of entriesyou have to sift through.
In Autoruns under the“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs\Startup” section, Uncheckthe box to the left of ‘cmd.exe’
In Autoruns under the “C:\ProgramData\Microsoft\Windows\StartMenu\Programs\Startup” section, Uncheckthe box to the left of ‘notepad.exe’.
Go to Start: Programs: Startup folder and verify the Startup folder displays‘(Empty)’.
In Autoruns Check the box to theleft of ‘cmd.exe’
Go to Start: Programs: Startup folder again and now see that the Startupfolder still shows Empty even though it should show ‘cmd.exe’!!! In addition, if you right click on the Start:Programs: Startup folder, you will no longer see the ‘Open’ and ‘Open AllUsers’ options, but will instead see a completely different list of folder menuoptions.
In Autoruns Check the box to theleft of ‘notepad.exe’.
Go to Start: Programs: Startup folderagain and now see that the Startup folder is COMPLETELY MISSING from the listof folders even though it should be displayed and should show both the ‘cmd.exe’and ‘notepad.exe’ files!!!
Open “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”
Select the ‘Startup’ folder
Right click and select Properties
Uncheck Hidden
Click OK
Select ‘Apply changes to this folder only’
Click OK
Go to Start: Programs: Startup folder again and now see that the Startupmenu reappears and the ‘cmd.exe’ program is properly displayed, but the‘notepad.exe’ program is still missing.
Open “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup”
Select the ‘Startup’ folder
Right click and select Properties
Uncheck Hidden
Click OK
Select ‘Apply changes to this folder only’
Click OK
Go to Start: Programs: Startup folder again and now see that both the‘cmd.exe’ and ‘notepad.exe’ programs are displayed as expected.
You can now go back into Autoruns and uncheck and check the ‘cmd.exe’ and‘notepad.exe’ entries again and go through the same madness a second time!!!
Scenario #2
Now here’s where things really getnasty!
Now copy (!don’t move!) a different program say“C:\Windows\System32\calc.exe” to the ‘User’ Startup folder.
Now copy (!don’t move!) yet another different program say“C:\Windows\System32\mspaint.exe” to the ‘All Users’ Startup folder.
Go to Start: Programs: Startup folder again and now see that all fourprograms namely ‘cmd.exe’, ‘notepad.exe’, ‘calc.exe’, and ‘mspaint.exe’programs are displayed as expected.
Repeat the above steps starting with:
In Autoruns under the“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup”section, Uncheck the box to the leftof ‘cmd.exe’
Repeat the remaining steps after the above step.
Congratulationsyou’ve just made the Startup folder completely disappear from Start: Programswindow!!! And the best part is that youdidn’t even need to Uncheck and Check the ‘calc.exe’ or ‘mspaint.exe’ entriesor any other entries that are still enabled in either of the two Startupfolders! Disabling one entry inside theStartup folder should not change the file attributes of the entire Startupfolder and prevent a user from being able to determine what programs are stillenabled to run at startup and what files are disabled at startup.
I guess one assumption here is that you’re logged on as Administrator. I imagine though that most people that arerunning Autoruns are logged on as Administrator.
Microsoft any way we can get this problem fixed as soon as possible?
![]() Hello Ludespeed, I had the same error. The solution was for me to disable Nvidia Shadowplay (the thing where you can record games [found in the Geforce Experience app]) |
Subject:
[BUG REPORT!] Nastybugs in Autoruns v13.71-v13.01
There are several nasty bugs in Autoruns v13.71 (which isthe latest version at the time of this writing) that also exist all the wayback to v13.01 and likely in versions before v13.01. The problem have to do with the undesirable modificationof the Windows Startup folders hidden attribute and a path problem related todisabled ‘User’ and ‘All Users’ Startup folders entries. Now I’ll try to describe the problems in moredetail.
NOTE: Scenario #1 below assumes that you have no otherstartup programs in the ‘User’ Startup or ‘All Users’ Startup folders in orderto follow each of the steps outlined below and to see the same resultsdescribed below.
Scenario #1
1. In Window #1, openthe ‘User’ Startup folder location:
“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”
or
You can instead click on Start: Programs: Startup: rightclick and select ‘Open’
2. In Window #2, openthe ‘All Users’ Startup folderlocation:
“C:\ProgramData\Microsoft\Windows\Start Menu\Programs”
or
You can instead click on Start: Programs: Startup: rightclick and select ‘Open All Users’
3. In Window #3, openthe “C:\Windows\System32” folder.
4. Now copy (!don’tmove!) a program say “C:\Windows\System32\cmd.exe” to the ‘User’ Startup folder.
5. Now copy (!don’tmove!) a different program say “C:\Windows\System32\notepad.exe” to the ‘AllUsers’ Startup folder.
6. Start Autoruns orclick on the Refresh button.
7. Click on the Logontab.
8. In the OptionsMenu, check ‘Hide Empty Locations’ and check ‘Hide Windows Entries’ options anduncheck the other options to reduce the number of entries you have to siftthrough.
9. In Autoruns underthe “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup”section, Uncheck the box to the leftof ‘cmd.exe’
10. In Autoruns underthe “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup” section, Uncheck the box to the left of‘notepad.exe’.
11. Go to Start:Programs: Startup folder and verify the Startup folder displays ‘(Empty)’.
12. In Autoruns Check the box to the left of ‘cmd.exe’
13. Go to Start:Programs: Startup folder again and now see that the Startup folder still shows (Empty)even though it should show ‘cmd.exe’!!! In addition, if you right click on the Start: Programs: Startup folder,you will no longer see the ‘Open’ and ‘Open All Users’ options, but willinstead see a completely different list of folder menu options.
14. In Autoruns Check the box to the left of‘notepad.exe’.
15. Go to Start: Programs: Startup folder againand now see that the Startup folder is COMPLETELY MISSING from the list offolders even though it should be displayed and should show both the ‘cmd.exe’and ‘notepad.exe’ files!!!
16. Open “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”
Select the ‘Startup’ folder
Right click and select Properties
Uncheck Hidden
Click OK
Select ‘Apply changes to this folder only’
Click OK
17. Go to Start:Programs: Startup folder again and now see that the Startup menu reappears andthe ‘cmd.exe’ program is properly displayed, but the ‘notepad.exe’ program isstill missing.
18. Open “C:\ProgramData\Microsoft\Windows\StartMenu\Programs\Startup”
Select the ‘Startup’ folder
Right click and select Properties
Uncheck Hidden
Click OK
Select ‘Apply changes to this folder only’
Click OK
19. Go to Start: Programs: Startup folder again and now seethat both the ‘cmd.exe’ and ‘notepad.exe’ programs are displayed as expected.
You can now go back into Autoruns and uncheck and check the‘cmd.exe’ and ‘notepad.exe’ entries again and go through the same madness asecond time!!!
Scenario #2
Now here’s wherethings really get nasty!
20. Now copy (!don’tmove!) a different program say “C:\Windows\System32\calc.exe” to the ‘User’Startup folder.
21. Now copy (!don’tmove!) yet another different program say “C:\Windows\System32\mspaint.exe” tothe ‘All Users’ Startup folder.
22. Go to Start:Programs: Startup folder again and now see that all four programs namely‘cmd.exe’, ‘notepad.exe’, ‘calc.exe’, and ‘mspaint.exe’ programs are displayedas expected.
23. Repeat steps 9 – 14 above.
24. Go to Start: Programs: Startup folder againand now see that the Startup folder is completely missing from the Start:Programs window!!! And the best part isthat you didn’t even need to Uncheck and Check the ‘calc.exe’ or ‘mspaint.exe’entries or any other entries that are still enabled in either of the twoStartup folders! Disabling one entryinside the Startup folder should not change the file attributes of the en
Edited by tech_dude - 34 minutes ago at 7:21pm
![]() A kernel memory dump records only the kernel memory. This speeds up the process of recording information in a log when your computer stops unexpectedly. You must have a pagefile large enough to accommodate your kernel memory. For 32-bit systems, kernel memory is usually between150MB and 2GB. Additionally, on Windows 2003 and Windows XP, the page file must be on the boot volume. Otherwise, a memory dump cannot be created. This dump file does not include unallocated memory or any memory that is allocated to User-mode programs. It includes only memory that is allocated to the kernel and hardware abstraction layer (HAL) in Windows 2000 and later, and memory allocated to Kernel-mode drivers and other Kernel-mode programs. For most purposes, this dump file is the most useful. It is significantly smaller than the complete memory dump file, but it omits only those parts of memory that are unlikely to have been involved in the problem. |