Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Monday, 22 May 2017

Troubleshoot "blue screen" or Stop error problems


Try the following methods to troubleshoot Stop error messages:






Review the "bugcheck" code that you find in the event logs. Search for the specific Stop error codes to see whether there are any known issues, resolutions, or workarounds for the problem.


Does the error message indicate any specific driver in regards to the problem? If so, update the driver in question.


Take a detailed look at the event logs on the system. Are you seeing any indication of a service starting or stopping before the crash occurred? Is this service behavior consistent across all instances of the crash? 

If so, you can contact the software vendor for the service to receive updated versions of the software to check whether this resolves the problem.

Try to identify whether you have made any software or hardware change or modification. 

You may want to consider the option to roll back the changes or use the change management to follow standard practices to revert to the last working state. 

Additionally, you may want to contact the software or hardware vendor for more help.

As a best practice, we recommend that you make sure that the BIOS is updated and that hardware and memory tests are performed.

Are you observing behavior that is related to the crashes, and do you believe that you can trigger the crash? Did you reach out to the software vendor for any updated version of the software or drivers that may be triggering the crash?

Make sure that you save the memory dump files for review. These dump files have been validated by using DumpChk and are not corrupted or invalid. You can verify the memory dump by using the Microsoft DumpChk (Crash Dump File Checker) tool. 

For more information, go to the following Knowledge Base article:

315271 How to use Dumpchk.exe to check a Memory Dump file

Make sure that you install the latest Windows updates, cumulative updates, and rollup updates.

Upload the memory dumps that you have verified by using the DmpChk memory dump collector.


This diagnostic tool collects the last five machine mini-dump files from the past 30 days. 

It collects machine memory dump files from a computer and checks for known solutions. 

For more information about Machine Memory Dump Collector, go to the following Knowledge Base article:


2027760 [SDP 3][06bb55c8-3207-406e-a3fc-f538867a399b] Machine Memory Dump Collector - Windows

Friday, 19 May 2017

Ransomware fixes from Microsoft



Wannacry Ransomware fixes from Microsoft. 


Do update ASAP and share with others.


Windows XP SP3  


http://download.windowsupdate.com/d/csa/csa/secu/2017/02/windowsxp-kb4012598-x86-custom-enu_eceb7d5023bbb23c0dc633e46b9c2f14fa6ee9dd.exe  



Windows Vista x86 


http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.0-kb4012598-x86_13e9b3d77ba5599764c296075a796c16a85c745c.msu



Windows Vista x64 


http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.0-kb4012598-x64_6a186ba2b2b98b2144b50f88baf33a5fa53b5d76.msu


Windows 7 x64 


http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu



Windows 7 x86 



http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.1-kb4012212-x86_6bb04d3971bb58ae4bac44219e7169812914df3f.msu



Windows 8 


http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows8-rt-kb4012598-x64_f05841d2e94197c2dca4457f1b895e8f632b7f8e.msu


Windows 8.1 


http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/02/windows8.1-kb4012213-x64_5b24b9ca5a123a844ed793e0f2be974148520349.msu



Windows 10 


http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/03/windows10.0-kb4012606-x64_e805b81ee08c3bb0a8ab2c5ce6be5b35127f8773.msu


Windows 2003 x86 



http://download.windowsupdate.com/c/csa/csa/secu/2017/02/windowsserver2003-kb4012598-x86-custom-enu_f617caf6e7ee6f43abe4b386cb1d26b3318693cf.exe


Windows 2003 x64 


http://download.windowsupdate.com/d/csa/csa/secu/2017/02/windowsserver2003-kb4012598-x64-custom-enu_f24d8723f246145524b9030e4752c96430981211.exe


Windows 2008 


http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.0-kb4012598-x64_6a186ba2b2b98b2144b50f88baf33a5fa53b5d76.msu


Windows 2008R2 



http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu


Windows 2012 



http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/02/windows8-rt-kb4012214-x64_b14951d29cb4fd880948f5204d54721e64c9942b.msu




Windows 2012R2 


http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/02/windows8.1-kb4012213-x64_5b24b9ca5a123a844ed793e0f2be974148520349.msu



Windows 2016 


http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/03/windows10.0-kb4013429-x64_ddc8596f88577ab739cade1d365956a74598e710.msu


Thursday, 6 April 2017

How to create a crash dump in Windows



Overview

Dump files provide a snapshot of a system's memory before a process crashes. On Windows, you can create a crash dump file manually from a running process, where execution will be suspended while the dump is created. The instructions below demonstrate how to do this.

Note that this may result in timeout errors when your process resumes execution. If you would like to enable crash dump files to be created automatically on your system when a process crashes, see this article (How to generate core dump files).




Environment

Operating System: Windows


Instructions

1. Start Windows Task Manager

IF YOU ARE ON WINDOWS x64, start the 64-BIT version of Windows Task Manager: C:Windows\SysWOW64\taskmgr.exe
IF YOU ARE ON WINDOWS x32, start the regular version of Windows Task Manager: C:Windows\System32\taskmgr.exe
You need the 32-bit version of Task Manager to create a 32-bit dump of a 32-bit process. If you use the 64-bit version of Task Manager, you will create a 64-bit dump of a 32-bit process. These are useful for stack traces but much harder to work with.

2. Go to the Windows Task Manager window

3. Click to select the Processes tab

4. Select the process you want to dump.

5. Right-click to open the context menu, then click to select Create Dump File.

Task Manager will create a dump file somewhere like C:\Users\Documents\AppData?\Local\Temp\procname.DMP. Send this file to Aspera Support.

6. NOTE WHAT VERSION OF THE EXECUTABLE you just dumped. Developers need to know the build number to interpret the dump correctly, but this information is not contained in the dump.


Thursday, 16 February 2017

Filter Drivers in Windows


Filter drivers are optional drivers that add value to or modify the behavior of a device. A filter driver can service one or more devices.

Bus Filter Drivers:-


Bus filter drivers typically add value to a bus and are supplied by Microsoft or a system OEM (see the Possible Driver Layers figure). Bus filter drivers are optional. There can be any number of bus filter drivers for a bus.

A bus filter driver could, for example, implement proprietary enhancements to standard bus hardware.

For devices described by an ACPI BIOS, the power manager inserts a Microsoft-supplied ACPI filter (bus filter driver) above the bus driver for each such device. The ACPI filter carries out device power policy and powers on and off devices. The ACPI filter is transparent to other drivers and is not present on non-ACPI machines.




Lower-Level Filter Drivers

Lower-level filter drivers typically modify the behavior of device hardware (see the Possible Driver Layers figure). They are typically supplied by IHVs and are optional. There can be any number of lower-level filter drivers for a device.

A lower-level device filter driver monitors and/or modifies I/O requests to a particular device. Typically, such filters redefine hardware behavior to match expected specifications.
A lower-level class filter driver monitors and/or modifies I/O requests for a class of devices. For example, a lower-level class filter driver for mouse devices could provide acceleration, performing a nonlinear conversion of mouse movement data.

Upper-Level Filter Drivers

Upper-level filter drivers typically provide added-value features for a device (see the Possible Driver Layers figure). Such drivers are usually provided by IHVs and are optional. There can be any number of upper-level filter drivers for a device.

An upper-level device filter driver adds value for a particular device. For example, an upper-level device filter driver for a keyboard could enforce additional security checks.
An upper-level class filter driver adds value for all devices of a particular class.

What Is a File System Filter Driver?


A file system filter driver is an optional driver that adds value to or modifies the behavior of a file system. A file system filter driver is a kernel-mode component that runs as part of the Windows executive.

A file system filter driver can filter I/O operations for one or more file systems or file system volumes. Depending on the nature of the driver, the filter can mean log, observe, modify, or even prevent. Typical applications for file system filter drivers include antivirus utilities, encryption programs, and hierarchical storage management systems

File System Filter Drivers Are Not Device Drivers


A device driver is a software component that controls a particular hardware I/O device. For example, a DVD storage driver controls a DVD drive.
In contrast, a file system filter driver works in conjunction with one or more file systems to manage file I/O operations. These operations include creating, opening, closing, and enumerating files and directories; getting and setting file, directory, and volume information; and reading and writing file data. In addition, file system filter drivers must support file system-specific features such as caching, locking, sparse files, disk quotas, compression, security, recoverability, reparse points and volume mount points.
For more details on the similarities and differences between file system filter drivers and device drivers, see the following:

How File System Filter Drivers Are Similar to Device Drivers


The following subsections describe some of the similarities between file system filter drivers and device drivers in the Microsoft Windows operating system.

Similar Structure:-


Like device drivers, file system filter drivers have DriverEntry, dispatch, and I/O completion routines. They call many of the same kernel-mode routines that device drivers call, and they filter I/O requests for devices (that is, file system volumes) with which they are associated.

Similar Functionality:-


Because file system filter drivers and device drivers are part of the I/O system, they both receive I/O request packets (IRPs) and act on them.
Like device drivers, file system filter drivers can also create their own IRPs and send them to lower-level drivers.
Both kinds of drivers can register for notification (by using callback functions) of various system events.

Other Similarities:-


Like device drivers, file system filter drivers can receive Introduction to I/O Control Codes (IOCTLs). However, file system filter drivers can also receive--and define--file system control codes (FSCTLs).
Like device drivers, file system filter drivers can be configured to be loaded at system startup time or to be loaded later, after the system startup process is complete.

How File System Filter Drivers Are Different from Device Drivers


The following subsections describe some of the differences between file system filter drivers and device drivers.

No Power Management:-


Because file system filter drivers are not device drivers and thus do not control hardware devices directly, they do not receive IRP_MJ_POWER requests. Instead, power IRPs are sent directly to the storage device stack. In rare circumstances, however, file system filter drivers might interfere with power management. For this reason, file system filter drivers should not register dispatch routines for IRP_MJ_POWER in the DriverEntry routine, and they should not call PoXxx routines.

No WDM:-


File system filter drivers cannot be Windows Driver Model (WDM) drivers. The Microsoft Windows Driver Model is only for device drivers. For more information about file system driver development in Windows Me, Windows 98, and Windows 95, see the Windows Me Driver Development Kit (DDK).

No AddDevice or StartIo:-



Because file system filter drivers are not device drivers and thus do not control hardware devices directly, they should not have AddDevice or StartIo routines.

Different Device Objects Created:-


Although file system filter drivers and device drivers both create device objects, they differ in the number and kinds of device objects that they create.
Device drivers create physical and functional device objects to represent devices. The Plug and Play (PnP) Manager builds and maintains a global device tree that contains all device objects that are created by device drivers. The device objects that file system filter drivers create are not contained in this device tree.
File system filter drivers do not create physical or functional device objects. Instead, they create control device objects and filter device objects. The control device object represents the filter driver to the system and to user-mode applications. The filter device object performs the actual work of filtering a specific file system or volume. A file system filter driver normally creates one control device object and one or more filter device objects.

Other Differences:-


Because file system filter drivers are not device drivers, they do not perform direct memory access (DMA).
Unlike device filter drivers, which can attach above or below a target device's function driver, file system filter drivers can attach only above a target file system driver. Thus, in device-driver terms, a file system filter driver can be only an upper filter, never a lower filter.

Installing a File System Filter Driver:-


For Microsoft Windows XP and later operating systems, you should install your file system filter drivers by using an INF file and an installation application. (On Windows 2000 and earlier operating systems, filter drivers were commonly installed by the Service Control Manager.)
In the future, INF-based installation is expected to meet Windows Hardware Certification Kit requirements for file system filter drivers. Note that "INF-based installation" means only that you will need to use an INF file to copy files and to store information in the registry. You will not be required to install your entire product by using only an INF file, and you will not be required to provide a "right-click install" option for your driver.

Initializing a File System Filter Driver:-


The DriverEntry routine for initializing a file system filter driver is very similar to the DriverEntry routine for initializing a device driver. After a driver is loaded, the same component that loaded the driver also initializes the driver by calling the driver's DriverEntry routine. For file system filter drivers, the component that loads the driver is either the I/O Manager (for filters whose start type is SERVICE_BOOT_START) or the Service Control Manager (for other start types).
The DriverEntry routine runs in a system thread context at IRQL = PASSIVE_LEVEL. This routine can be pageable and should be in an INIT segment so that it will be discarded. For more information about how to make your driver code pageable, see the Remarks section of

MmLockPagableCodeSection.

The DriverEntry routine is defined as follows:
NTSTATUS
(*PDRIVER_INITIALIZE) (
    IN PDRIVER_OBJECT DriverObject,
    IN PUNICODE_STRING RegistryPath
    );

This routine has two input parameters. The first, DriverObject, is the driver object that was created when the file system filter driver was loaded. The second, RegistryPath, is a pointer to a counted Unicode string that contains a path to the driver's registry key.
Attaching a Filter to a File System or Volume

A file system filter driver attaches itself to one or more mounted volumes and filters all I/O operations on them. But how does it determine which volumes to attach itself to? The sample filter drivers in the Windows Driver Kit (WDK) illustrate the two most common ways in which this is done:
The end user can specify the volumes to filter by, for example, typing in the drive letters for the volumes. The end user's commands are relayed to the filter driver as a private IRP_MJ_DEVICE_CONTROL request.

The file system filter driver can attach to one or more file system drivers, listen for IRP_MJ_FILE_SYSTEM_CONTROL, IRP_MN_MOUNT_VOLUME requests, and attach to volumes as they are mounted.

Note You should generally assume that the mapping of volumes to drive letters is one-to-many, not one-to-one. This is because of advanced storage features, such as dynamic volumes and volume mount points.

Note You should not assume that IRP_MN_MOUNT_VOLUME requests are always handled synchronously by the file system. For example, a floppy drive may be mounted asynchronously if there is no floppy disk in the drive. Thus your filter driver should be prepared to propagate the PendingReturned flag in its mount completion routine. For more information, see "Checking the PendingReturned Flag."

File system filter drivers can attach to, and filter I/O for, any file system volume. They cannot attach directly to storage devices, such as disk drives or partitions. Also, they cannot attach to individual directories or files.

Wednesday, 25 January 2017

Restarting WMI Services Using Command Line


Restarting WMI Services Using Command Line

Starting Winmgmt Service
The following procedure describes how to start the WMI service.

To start Winmgmt Service
At a command prompt, enter net start winmgmt [/].
For more information about the switches that are available, see winmgmt. You use the built-in Administrator account or an account in the Administrators group running with elevated rights to start the WMI service. For more information, see User Account Control and WMI.

Stopping Winmgmt Service
The following procedure describes how to stop the WMI Service.

To stop Winmgmt Service
At a command prompt, enter net stop winmgmt.

Other services that are dependent on the WMI service also halt, such as SMS Agent Host or Windows Firewall.
Windows 2000: For WMI failures that occur because of improper provider unloading, the REG_SZ registry key value should be set to 1 (one). The default value is 0 (zero).
HKLM\Software\Microsoft\WBEM\
CIMOM\Force Clean Shutdown
winmgmt

Winmgmt is the WMI service within the SVCHOST process running under the LocalSystem account. In all cases, the WMI service automatically starts when the first management application or script requests connection to a WMI namespace. For more information, see Starting and Stopping the WMI Service.

Windows 2000 and Windows NT 4.0: The WMI service runs as a separate service process.
When run from the command prompt, the WMI service has the following switches.

The full error that appears in the Event Viewer is
WinMgmt could not initialize the core parts.This could be due to a badly installed 
version of WinMgmt, WinMgmt repository upgrade failure, 
insufficient disk space or insufficient memory.

To resolve this error and recreate any missing or corrupt registry entries, perform the following steps:
  1. Start a command-line session.
  2. Unregister any WMI service (also known as WinMgmt) performance libraries by typing
    winmgmt /clearadap 
  3. Stop all running copies of the WMI service by typing
    winmgmt /kill 
  4. Unregister the WMI service by typing
    winmgmt /unregserver 
  5. Register the WMI service by typing
    winmgmt /regserver 
  6. Register any WMI service performance libraries by typing
    winmgmt /resyncperf

Thursday, 8 December 2016

Modifying the Windows 7 boot loader with the Boot Configuration Data



Sometimes dual-booting a system is a handy way to test new software, a new operating system, or an application that needs to be run in a specific version of Windows. Other reasons to dual-boot might include replication of a client environment.

Windows handles dual-booting by using boot.ini to display a menu of bootable choices or partitions found on the current system. In Windows Vista and later versions of Windows, the bootloader was moved from boot.ini to a utility called BCDEdit.

Recently, I decided I could make better use of some disk space that I had set aside to create a bootable VHD for Windows Server 2008 R2. There was no data other than the OS installation contained within the file because I had used it only to prepare a blog post about booting from Virtual Hard Disks. To free up the space, I deleted the VHD.

Note: Always make sure to back up any data that you want to keep before deleting or modifying partitions on VHDs. Your changes could make the partition unbootable.
Once I had the VHD removed, I thought Windows would be smart enough to clean up the boot loader, but I was not so lucky. I had Windows 7 set as the primary OS, so I was not without a system.

Started looking around for boot.ini and was directed toward the Boot Configuration Data Editor (BCDEdit) as the utility to use when editing boot loader information in Windows 7 (and in Vista too).

To begin, open the Start menu, select All Programs, and then choose Accessories. Right-click on Command Prompt and select Run As Administrator. Once in the command window, type bcdedit. This will return the current running configuration of your boot loader, showing any and all items that can boot on this system.

In this example, I decided to remove the entry for my Windows 2008 R2 installation, as I wouldn't need it for the time being. To remove an entry, you will need to know the Boot Loader Identifier


Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\test>bcdedit

Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {current}
resumeobject            {a90f9a80-834e-11e5-a27e-88f88aa0953e}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Windows Boot Loader
-------------------
identifier              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 7
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {a90f9a82-834e-11e5-a27e-88f88aa0953e}
recoveryenabled         Yes
graphicsmodedisabled    Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {a90f9a80-834e-11e5-a27e-88f88aa0953e}
nx                      OptIn

C:\Users\test>



Copied the whole list into Notepad and then selected and copied just the ID, braces included.


Removing an entry from the Boot Loader
One simple command got the Windows Server 2008 R2 entry out of the boot loader. At the command prompt, enter the following:


Bcdedit /delete {boot loader identifier}


Press Enter, and the Boot Configuration Data Editor (BCDEdit) will remove the entry for the ID you specified and display a message when finished. When Windows starts, the only choice available in the boot menu should be the current Windows installation.

Warning: Be careful when editing the boot configuration data. If you mistakenly remove the current instance of Windows, you may render your computer unbootable

Monday, 17 October 2016

How to use tailf command in windows



If you use PowerShell then this works:


Get-Content filenamehere -Wait

Posting Stefan's comment from below, so people don't miss it

PowerShell 3 introduces a -Tail parameter to include only the last x lines

Example: -


Get-Content C:\LogFile.txt -Wait



Enjoy Tailing... :)  !!!