Quantcast
Channel: Sysinternals Forums
Viewing all 10386 articles
Browse latest View live

Process Explorer : Thread handle access is denied

$
0
0
Author: cantoris
Subject: Thread handle access is denied
Posted: 19 July 2017 at 3:26pm

I just noticed, what does that State of "Wait:Executive" mean?
Thanks.

Process Monitor : mcafee failure

$
0
0
Author: boopathi
Subject: mcafee failure
Posted: 19 July 2017 at 5:57pm

Hi,
I am getting "the system administrator has set policies to prevent the installation" error during Mcafee VSE installation. Attached the uploads/52333/Setup_Logfile.zip



Please help to find what is causing the installation failure. 

Process Explorer : Thread handle access is denied

Disk2vhd : Disk2vhd on Domain Controller not working in DSRM

$
0
0
Author: LD1
Subject: Disk2vhd on Domain Controller not working in DSRM
Posted: 20 July 2017 at 10:58pm

Hi,

I need to P2V some Server 2008 R2 DCs (I know not good practise, long story, have just inherited this site, can't add an additional virtual DC to the environment as there is a middleware over AD which means you cannot use AD in the normal fashion and this middleware is now unsupported so there is no way to add additional DCs at this time, we are just trying to P2V the servers off failing old hardware and keep things running for a few more months until we rebuild the environment, I am aware of the dangers of USN rollback, etc, ADDS, DFS Replication and DNS services will be disabled during P2V).

I've been testing this in lab environment, I wanted to run Disk2vhd from DSRM (Directory Services Restore Mode) but it won't run with the 'Use volume shadow copy' option ticked, it produces the 'error snapshotting volumes' error (even though the Volume Shadow Copy service is started in DSRM).

So I tried it from Safe Mode instead, here I had to manually disable the ADDS service as this was still running (unlike in DSRM), however in safe mode it produces a Visual C++ Runtime Error, which some people have said you need to enable the Volume Shadow Copy service to fix, however this cannot be enabled in safe mode.

I would like to get it to work in DSRM if anyone knows how, however as long as I am careful with the services, replication, old physical server, etc, should I just do it from a normal boot (as this works fine)?

EDIT: Actually it doesn't work fine during a normal boot, I still get the C++ runtime error, maybe I need windows updates on my test machine.


Edited by LD1 - 53 minutes ago at 11:12pm

PsTools : Psexec argument doesn't work correctly

$
0
0
Author: Watearth
Subject: Psexec argument doesn't work correctly
Posted: 21 July 2017 at 6:54am

Hello,

When I use Psexec -i -c with a KBXXXXXXX.exe and when I want add some argument like /quiet or/and /norestart, I think no argument are used.

Can you check if it is right and someone can fix this problem?

thanks

PsTools : psexec on Windows 10 v1703 Access is denied

$
0
0
Author: mnmatos
Subject: psexec on Windows 10 v1703 Access is denied
Posted: 21 July 2017 at 9:17am

Hi,

I'm facing the exact same behavior. Other pstools such as pslist or psservice are working fine but psexec always return this error even when i'm running it for the local system.

i getting the "Access is denied." message on Windows Server 2003 and Windows Server 2008 R2

Process Monitor : process monitor doesn't start

$
0
0
Author: Diesel
Subject: process monitor doesn't start
Posted: 21 July 2017 at 9:58am

Hi
Procmon.exe doesn't start on my computer.
After start it appears in the Task Manager but I can't see any window from Process Monitor no message nothing.
My system is windows 7 64bit.
Computer acer aspire 5551

Greetings
Diesel

PsTools : psexec on Windows 10 v1703 Access is denied

$
0
0
Author: mnmatos
Subject: psexec on Windows 10 v1703 Access is denied
Posted: 21 July 2017 at 10:42am

I've just found what is happening in my case. the antivirus was blocking it:
7/19/2017 4:11:55 AM Blocked by Access Protection rule <domain>\<user> C:\WINDOWS\system32\psexec.exe \Device\LanmanRedirector\<ip>\ADMIN$\PSEXESVC.exe User-defined Rules:PSEXESVC Action blocked : Create

check if you have the same cause and this should be easy to solve.

PsTools : PsGetSid //* returns a "system error 6118

$
0
0
Author: swinster
Subject: PsGetSid //* returns a "system error 6118
Posted: 21 July 2017 at 5:50pm

Nope, sorry

Internals : Reading Usermode Memory Regions from Kernelside

$
0
0
Author: SAiBOTiERT
Subject: Reading Usermode Memory Regions from Kernelside
Posted: 22 July 2017 at 10:27pm

Hi,

is there a kernel way to readout the memory regions from a userland process? (like virtualqueryex)

Autoruns : [BUG REPORT] Nasty bug in Autoruns v13.71-v13.01

$
0
0
Author: tech_dude
Subject: [BUG REPORT] Nasty bug in Autoruns v13.71-v13.01
Posted: 23 July 2017 at 3:00am

There is a nasty bug in Autoruns v13.71 (which is the latest version at thetime of this writing) that also exists all the way back to v13.01 and likely inversions before v13.01.  The problem hasto do with the undesirable modification of the Windows Startup folders hiddenattribute.  Now I’ll try to describe theproblem in more detail.

NOTE: Scenario #1 below assumes that you have no other startup programs inthe ‘User’ Startup or ‘All Users’ Startup folders in order to follow each ofthe steps outlined below and to see the same results described below. 

 

Scenario #1


In Window #1, open the ‘User’Startup folder location:

“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”

or

You can instead click on Start: Programs: Startup: right click and select‘Open’

 

In Window #2, open the ‘All Users’Startup folder location:

“C:\ProgramData\Microsoft\Windows\Start Menu\Programs”

or

You can instead click on Start: Programs: Startup: right click and select‘Open All Users’

 

In Window #3, open the “C:\Windows\System32” folder.

Now copy (!don’t move!) a program say “C:\Windows\System32\cmd.exe” to the‘User’ Startup folder.

Now copy (!don’t move!) a different program say“C:\Windows\System32\notepad.exe” to the ‘All Users’ Startup folder.

 

Start Autoruns or click on the Refresh button.

Click on the Logon tab.

In the Options Menu, check ‘Hide Empty Locations’ and check ‘Hide WindowsEntries’ options and uncheck the other options to reduce the number of entriesyou have to sift through.

In Autoruns under the“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs\Startup” section, Uncheckthe box to the left of ‘cmd.exe’

In Autoruns under the “C:\ProgramData\Microsoft\Windows\StartMenu\Programs\Startup” section, Uncheckthe box to the left of ‘notepad.exe’.

Go to Start: Programs: Startup folder and verify the Startup folder displays‘(Empty)’.

In Autoruns Check the box to theleft of ‘cmd.exe’

Go to Start: Programs: Startup folder again and now see that the Startupfolder still shows Empty even though it should show ‘cmd.exe’!!!  In addition, if you right click on the Start:Programs: Startup folder, you will no longer see the ‘Open’ and ‘Open AllUsers’ options, but will instead see a completely different list of folder menuoptions.

In Autoruns Check the box to theleft of ‘notepad.exe’.

Go to Start: Programs: Startup folderagain and now see that the Startup folder is COMPLETELY MISSING from the listof folders even though it should be displayed and should show both the ‘cmd.exe’and ‘notepad.exe’ files!!! 

 

Open “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”

Select the ‘Startup’ folder

Right click and select Properties

Uncheck Hidden

Click OK

Select ‘Apply changes to this folder only’

Click OK

 

Go to Start: Programs: Startup folder again and now see that the Startupmenu reappears and the ‘cmd.exe’ program is properly displayed, but the‘notepad.exe’ program is still missing. 

 

Open “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup”

Select the ‘Startup’ folder

Right click and select Properties

Uncheck Hidden

Click OK

Select ‘Apply changes to this folder only’

Click OK

Go to Start: Programs: Startup folder again and now see that both the‘cmd.exe’ and ‘notepad.exe’ programs are displayed as expected. 

You can now go back into Autoruns and uncheck and check the ‘cmd.exe’ and‘notepad.exe’ entries again and go through the same madness a second time!!!

 

Scenario #2

 

Now here’s where things really getnasty!

Now copy (!don’t move!) a different program say“C:\Windows\System32\calc.exe” to the ‘User’ Startup folder. 

Now copy (!don’t move!) yet another different program say“C:\Windows\System32\mspaint.exe” to the ‘All Users’ Startup folder.

Go to Start: Programs: Startup folder again and now see that all fourprograms namely ‘cmd.exe’, ‘notepad.exe’, ‘calc.exe’, and ‘mspaint.exe’programs are displayed as expected. 

Repeat the above steps starting with:

In Autoruns under the“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup”section, Uncheck the box to the leftof ‘cmd.exe’ 

Repeat the remaining steps after the above step.

Congratulationsyou’ve just made the Startup folder completely disappear from Start: Programswindow!!!  And the best part is that youdidn’t even need to Uncheck and Check the ‘calc.exe’ or ‘mspaint.exe’ entriesor any other entries that are still enabled in either of the two Startupfolders!  Disabling one entry inside theStartup folder should not change the file attributes of the entire Startupfolder and prevent a user from being able to determine what programs are stillenabled to run at startup and what files are disabled at startup.

I guess one assumption here is that you’re logged on as Administrator.  I imagine though that most people that arerunning Autoruns are logged on as Administrator.

Microsoft any way we can get this problem fixed as soon as possible?



Edited by tech_dude - 4 hours 59 minutes ago at 5:39am

Miscellaneous Utilities : Zoomit on Windows 10 - 2 sec delay on activation

$
0
0
Author: Johannes3200
Subject: Zoomit on Windows 10 - 2 sec delay on activation
Posted: 23 July 2017 at 12:55pm

Hello Ludespeed,

I had the same error.

The solution was for me to disable Nvidia Shadowplay (the thing where you can record games [found in the Geforce Experience app])

Miscellaneous Utilities : Zoomit on Windows 10 - 2 sec delay on activation

$
0
0
Author: Ludespeed
Subject: Zoomit on Windows 10 - 2 sec delay on activation
Posted: 23 July 2017 at 6:07pm

Originally posted by Johannes3200 Johannes3200 wrote:

Hello Ludespeed,

I had the same error.

The solution was for me to disable Nvidia Shadowplay (the thing where you can record games [found in the Geforce Experience app])

I turned off the share option under settings in Geforce Experience and the lag is gone; thank you so much! :))))

Autoruns : [BUG REPORT] Nasty bugs in Autoruns v13.71-v13.01

$
0
0
Author: tech_dude
Subject: [BUG REPORT] Nasty bugs in Autoruns v13.71-v13.01
Posted: 23 July 2017 at 3:00am

Subject:

[BUG REPORT!] Nastybugs in Autoruns v13.71-v13.01

 

There are several nasty bugs in Autoruns v13.71 (which isthe latest version at the time of this writing) that also exist all the wayback to v13.01 and likely in versions before v13.01.  The problem have to do with the undesirable modificationof the Windows Startup folders hidden attribute and a path problem related todisabled ‘User’ and ‘All Users’ Startup folders entries.  Now I’ll try to describe the problems in moredetail.

 

NOTE: Scenario #1 below assumes that you have no otherstartup programs in the ‘User’ Startup or ‘All Users’ Startup folders in orderto follow each of the steps outlined below and to see the same resultsdescribed below.

 

Scenario #1

 

1.  In Window #1, openthe ‘User’ Startup folder location:

 

“C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”

or

You can instead click on Start: Programs: Startup: rightclick and select ‘Open’

 

2.  In Window #2, openthe ‘All Users’ Startup folderlocation:

 

“C:\ProgramData\Microsoft\Windows\Start Menu\Programs”

or

You can instead click on Start: Programs: Startup: rightclick and select ‘Open All Users’

 

 

3.  In Window #3, openthe “C:\Windows\System32” folder.

 

4.  Now copy (!don’tmove!) a program say “C:\Windows\System32\cmd.exe” to the ‘User’ Startup folder.

 

5.  Now copy (!don’tmove!) a different program say “C:\Windows\System32\notepad.exe” to the ‘AllUsers’ Startup folder.

 

6.  Start Autoruns orclick on the Refresh button.

 

7.  Click on the Logontab.

 

8.  In the OptionsMenu, check ‘Hide Empty Locations’ and check ‘Hide Windows Entries’ options anduncheck the other options to reduce the number of entries you have to siftthrough.

 

9.  In Autoruns underthe “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup”section, Uncheck the box to the leftof ‘cmd.exe’

 

10.  In Autoruns underthe “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup” section, Uncheck the box to the left of‘notepad.exe’.

 

11.  Go to Start:Programs: Startup folder and verify the Startup folder displays ‘(Empty)’.

 

12.  In Autoruns Check the box to the left of ‘cmd.exe’

 

13.  Go to Start:Programs: Startup folder again and now see that the Startup folder still shows (Empty)even though it should show ‘cmd.exe’!!! In addition, if you right click on the Start: Programs: Startup folder,you will no longer see the ‘Open’ and ‘Open All Users’ options, but willinstead see a completely different list of folder menu options.

 

14.  In Autoruns Check the box to the left of‘notepad.exe’.

 

15.  Go to Start: Programs: Startup folder againand now see that the Startup folder is COMPLETELY MISSING from the list offolders even though it should be displayed and should show both the ‘cmd.exe’and ‘notepad.exe’ files!!! 

 

16.  Open “C:\Users\<username>\AppData\Roaming\Microsoft\Windows\StartMenu\Programs”

Select the ‘Startup’ folder

Right click and select Properties

Uncheck Hidden

Click OK

Select ‘Apply changes to this folder only’

Click OK

 

17.  Go to Start:Programs: Startup folder again and now see that the Startup menu reappears andthe ‘cmd.exe’ program is properly displayed, but the ‘notepad.exe’ program isstill missing.

 

18.  Open “C:\ProgramData\Microsoft\Windows\StartMenu\Programs\Startup”

Select the ‘Startup’ folder

Right click and select Properties

Uncheck Hidden

Click OK

Select ‘Apply changes to this folder only’

Click OK

 

19. Go to Start: Programs: Startup folder again and now seethat both the ‘cmd.exe’ and ‘notepad.exe’ programs are displayed as expected.

 

You can now go back into Autoruns and uncheck and check the‘cmd.exe’ and ‘notepad.exe’ entries again and go through the same madness asecond time!!!

 

Scenario #2

 

Now here’s wherethings really get nasty!

 

20.  Now copy (!don’tmove!) a different program say “C:\Windows\System32\calc.exe” to the ‘User’Startup folder.

 

21.  Now copy (!don’tmove!) yet another different program say “C:\Windows\System32\mspaint.exe” tothe ‘All Users’ Startup folder.

 

22.  Go to Start:Programs: Startup folder again and now see that all four programs namely‘cmd.exe’, ‘notepad.exe’, ‘calc.exe’, and ‘mspaint.exe’ programs are displayedas expected.

 

23. Repeat steps 9 – 14 above.

 

24.  Go to Start: Programs: Startup folder againand now see that the Startup folder is completely missing from the Start:Programs window!!!  And the best part isthat you didn’t even need to Uncheck and Check the ‘calc.exe’ or ‘mspaint.exe’entries or any other entries that are still enabled in either of the twoStartup folders!  Disabling one entryinside the Startup folder should not change the file attributes of the en

Edited by tech_dude - 34 minutes ago at 7:21pm

Utilities Suggestions : Best Way to Convert OST to PST

$
0
0
Author: sidhart kumar
Subject: Best Way to Convert OST to PST
Posted: 24 July 2017 at 5:41am

Make utilization of the perfect OST to PST Converter tools which nicely removes all presents errors from OST file and safely repair corrupted, damaged or password protected encrypted OST file in order to convert all the OST file data into PST, EML, MSG, HTML, MHTML, RTF, TXT, DOC, PDF, MBOX and Outlook Profile.This application more smart tool to fix emails of Outlook OST file and restore OST file to PST file with emails properties or mailbox attachments such as-: Contacts, Calendar items, Notes, Scheduled tasks, appointments, journals, drafts etc. (To, Cc, Bcc, Subject, Date & Time etc.).By taking help of this software you can Split large PST File into Small PST File (1 GB to 5 GB).It also support all MS Outlook 2003, 2007, 2010, 2013, 2016.

For download visit on :- Exchange OST to PST

Miscellaneous Utilities : Sysmon 5.2.0.0 - does log Image & ProcessGUID

$
0
0
Author: mpras
Subject: Sysmon 5.2.0.0 - does log Image & ProcessGUID
Posted: 24 July 2017 at 6:44am

Not sure if this a bug with Sysmon version 5.2.0.0 and wondering if anyone else is experiencing the similar issue

Sysmon is not logging Process Name(Image): it simply records as <unbknown processname>
also records Processguid: {00000000-0000-0000-0000-000000000000}
Sample events:

LogName=Microsoft-Windows-Sysmon/Operational
SourceName=Microsoft-Windows-Sysmon
EventCode=3
EventType=4
Type
=Information

ComputerName
=xxxxxxx

User
=NOT
_TRANSLATED

Sid
=S
-1
-5
-18

SidType=0
TaskCategory
=Network
connection detected (rule: NetworkConnect)
OpCode=Info
RecordNumber
=36968544

Keywords
=None

 Message=Network connection detected:
Message=Network connection detected:
UtcTime: 2017-07-24 06:35:54.973
ProcessGuid: {00000000-0000-0000-0000-000000000000}
ProcessId
:
4
Image: <unknown process>
User
:

Protocol: udp
Initiated: true
SourceIsIpv6
:
false
SourceIp: xx.xxx.xxx.xx
SourceHostname
:
xxxxxxxxx
SourcePort: 138
SourcePortName
:
netbios-dgm
DestinationIsIpv6
:
false
DestinationIp: xx.xxx.xxx.xx
DestinationHostname
:

DestinationPort
:
138
DestinationPortName: netbios-dgm

Miscellaneous Utilities : ZoomIt 4.5 on multiple monitors with different DPI

$
0
0
Author: jjdev
Subject: ZoomIt 4.5 on multiple monitors with different DPI
Posted: 24 July 2017 at 2:50pm

Similar problem here.

When my laptop is docked, my primary screen is one of the external 1080p monitors. ZoomIt works well on both of them. It doesn't work on the built-in display - the screen is clipped and zoomed heavily, even when I just enable drawing without any actual zoom.

When undocked, the primary screen is the built-in 4k one and it behaves the same way as when docked - is clipped and zoomed too much as soon as I start drawing.

Process Monitor : Path Column and 8.3 File Format

$
0
0
Author: CMC_GHogge
Subject: Path Column and 8.3 File Format
Posted: 24 July 2017 at 3:08pm


How can I get the path column to display the full file name rather than the 8.3 format?

Troubleshooting : Security and Kernel Dumps

$
0
0
Author: MagicAndre1981
Subject: Security and Kernel Dumps
Posted: 24 July 2017 at 5:43pm

MS explained what is included in the dump:

Quote
A kernel memory dump records only the kernel memory. This speeds up the process of recording information in a log when your computer stops unexpectedly. You must have a pagefile large enough to accommodate your kernel memory. For 32-bit systems, kernel memory is usually between150MB and 2GB. Additionally, on Windows 2003 and Windows XP, the page file must be on the boot volume. Otherwise, a memory dump cannot be created.

This dump file does not include unallocated memory or any memory that is allocated to User-mode programs. It includes only memory that is allocated to the kernel and hardware abstraction layer (HAL) in Windows 2000 and later, and memory allocated to Kernel-mode drivers and other Kernel-mode programs. For most purposes, this dump file is the most useful. It is significantly smaller than the complete memory dump file, but it omits only those parts of memory that are unlikely to have been involved in the problem.




Troubleshooting : xperf showing high DPC in DX12, now what?

$
0
0
Author: MagicAndre1981
Subject: xperf showing high DPC in DX12, now what?
Posted: 24 July 2017 at 5:44pm

share the ETL via Onedrive link and I'll take a lool at it. try if a GPU driver fixes it
Viewing all 10386 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>