Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

Nov 10, 2010

Software Collections for Windows Pocket PC

WavePad V.1.27

A very good program, make sure you know to cut programs and create a ringtone, then this program you can edit the copy for better sound!
Like a program to create ringtones on your computer, this program lets you create effects such as echo to the ringing sound faster, slower, I sound larger, surround sound and cut back .... songs into ringtones go to ..

  • One thing has not come true to create the unique tones on your own ppc ...
  • When creating a logical ring, you can save the file to a memory card with the format mp3, wav ....


alt


Download link:

http://www.4shared.com/file/13565798..._AM_THANH.html


Goldfish

A fun application on your phone, a very nice fish, just like it was swimming kick up your computer, your computer feels like a swimming pool!
You can move the fish fed in the machine ... and when you just want to kick it off 2 times the fish are fish disappear automatically.


alt

Download link:
http://www.4shared.com/file/13565855..._man_hinh.html


Beastmaster v4.2

An application that helps you chase mosquitoes, chasing mice, snakes have to say is .... a lot ... machine was tested with the sounds of different frequencies to help you make it from now ... do not worry about those more harmful insects

alt
Download link:
http://www.4shared.com/file/13565901...an_so_cao.html


FotoFlash

One application that helps you have beautiful paintings are stored in a 2D space applications ... keeps you entertained!
- There are eight paintings you can add on, you can drag the image bigger, move them ....

How to use:
You can copy the picture size 320x240, jpg extension to / Application Data / volatile / FotoFlash, copy 8 img_1.jpg picture naming, img_2.jpg ..... img_8.jpg
Now just kick on and enjoy FotoFlash.exe

alt

Download link:
http://www.4shared.com/file/13565959...FotoFlash.html


LEDEmuPPC

LED effects as a machine to help you more vibrant, beautiful .... this LED, you can create a lot of color to a text run!

How to use:

You kick LEDEmuPPC.exe to run, when run, you can drag the text to run faster or slower, holding on to your LED color changing light kick on .... words to change the text content

alt

Download link:
http://www.4shared.com/file/13570568...LEDEmuPPC.html


EasyHelper_ContactSMSBackup v1.2.3

This is an application to store contacts, messages .... I should not recommend not to notice if something special is that it can save as txt, so you do not need back up again but can help you keep reading ... but the message of the coal-friends, lovers on the phone and on the computer (as can be read directly on the computer) is too good, full of sesame sesame

alt

Download link:
http://www.4shared.com/file/13565924...Backup-123.htm


Software Collections for Windows Pocket PC

WavePad V.1.27

A very good program, make sure you know to cut programs and create a ringtone, then this program you can edit the copy for better sound!
Like a program to create ringtones on your computer, this program lets you create effects such as echo to the ringing sound faster, slower, I sound larger, surround sound and cut back .... songs into ringtones go to ..

  • One thing has not come true to create the unique tones on your own ppc ...
  • When creating a logical ring, you can save the file to a memory card with the format mp3, wav ....


alt


Download link:

http://www.4shared.com/file/13565798..._AM_THANH.html


Goldfish

A fun application on your phone, a very nice fish, just like it was swimming kick up your computer, your computer feels like a swimming pool!
You can move the fish fed in the machine ... and when you just want to kick it off 2 times the fish are fish disappear automatically.


alt

Download link:
http://www.4shared.com/file/13565855..._man_hinh.html


Beastmaster v4.2

An application that helps you chase mosquitoes, chasing mice, snakes have to say is .... a lot ... machine was tested with the sounds of different frequencies to help you make it from now ... do not worry about those more harmful insects

alt
Download link:
http://www.4shared.com/file/13565901...an_so_cao.html


FotoFlash

One application that helps you have beautiful paintings are stored in a 2D space applications ... keeps you entertained!
- There are eight paintings you can add on, you can drag the image bigger, move them ....

How to use:
You can copy the picture size 320x240, jpg extension to / Application Data / volatile / FotoFlash, copy 8 img_1.jpg picture naming, img_2.jpg ..... img_8.jpg
Now just kick on and enjoy FotoFlash.exe

alt

Download link:
http://www.4shared.com/file/13565959...FotoFlash.html


LEDEmuPPC

LED effects as a machine to help you more vibrant, beautiful .... this LED, you can create a lot of color to a text run!

How to use:

You kick LEDEmuPPC.exe to run, when run, you can drag the text to run faster or slower, holding on to your LED color changing light kick on .... words to change the text content

alt

Download link:
http://www.4shared.com/file/13570568...LEDEmuPPC.html


EasyHelper_ContactSMSBackup v1.2.3

This is an application to store contacts, messages .... I should not recommend not to notice if something special is that it can save as txt, so you do not need back up again but can help you keep reading ... but the message of the coal-friends, lovers on the phone and on the computer (as can be read directly on the computer) is too good, full of sesame sesame

alt

Download link:
http://www.4shared.com/file/13565924...Backup-123.htm


Feb 15, 2010

Customize the Start Menu Options in Windows 7

Windows 7 provides excellent control over the Start menu. You can choose which commands appear on the Start menu and how they are arranged. You can add options for Control Panel, Devices And Printers, Network Connections, and other key tools. You can also enable or disable personalized menus on the All Programs menu.

To change the Start menu options, follow these steps:

  • Right-click Start on the taskbar, and then click Properties. The Taskbar And Start Menu Properties dialog box is displayed with the Start Menu tab selected by default.
  • On the Start Menu tab, use the Power Button Action list to select the action to use when the power button is pressed. Options include Switch User, Log Off, Lock, Restart, Sleep, and Shut Down. In a 24x7 environment, or when multiple users log on to the same computer, switching users, logging off, or locking the system may be preferable to shutting down the com¬puter. If you change the default action, you can shut down the computer by clicking Start and then clicking Shutdown.
  • Click Customize. This displays the Customize Start Menu dialog box.
  • Use the options in the dialog box to control the general appearance of the Start menu.
  • Click OK, and then click OK again to close the Taskbar And Start Menu Prop¬erties dialog box.

In the Customize Start Menu dialog box, most of the options control which commands appear on the Start menu and how they are arranged. Some items have the sub-options Display As A Link, Display As A Menu, and Don’t Display This Item. Display As A Link specifies that an item, such as Control Panel, will appear as a sepa¬rate option that opens a window when selected. Display As A Menu specifies that an item will provide access to a submenu that allows you to choose from its related options. Don’t Display This Item removes the item from the Start menu.
Other Customize Start Menu dialog box options you’ll see include the following:

  • Enable Context Menus And Dragging And Dropping When this option is selected, users can right-click to display a shortcut menu and use drag and drop. Typically, you’ll want to enable this option unless there is a specific security reason to disable it.
  • Highlight Newly Installed Programs When this option is selected, menus for recently installed applications are highlighted, as are the menu options.
  • Open Submenus When I Pause On Them With The Mouse Pointer Con¬trols the behavior of menus. When this option is selected, menus open when you point to them. Otherwise, menus open only when you click them.
  • Sort All Programs Menu By Name Controls whether menu items are organized alphabetically or by the order of installation. When this option is selected, menu items are sorted alphabetically. When this option is not selected, menu items are listed in the order of installation.
  • Use Large Icons Controls the size of icons for menu options. To reduce the size of icons used on menus, clear this option. Otherwise, select this option to display standard-size icons on menus.
  • Number Of Recent Programs To Display Controls the number of shortcuts to recently used programs that appear in the most frequently used list on the Start menu. Use the selection menu to assign a value from 0 to 30.The actual number of programs listed in the most frequently used list depends on the screen resolution as well as the number of items in the pinned items list, which appears above the most frequently used list on the Start menu.
  • Number of Recent Items To Display In Jump List Controls how many shortcuts to recently used items appear in jump lists. Jump lists are lists of recent items organized by the program that you use to open them. They can appear on the Start menu and the taskbar. Use the selection menu to assign a value from 0 to 60.

Customize the Start Menu Options in Windows 7

Windows 7 provides excellent control over the Start menu. You can choose which commands appear on the Start menu and how they are arranged. You can add options for Control Panel, Devices And Printers, Network Connections, and other key tools. You can also enable or disable personalized menus on the All Programs menu.

To change the Start menu options, follow these steps:

  • Right-click Start on the taskbar, and then click Properties. The Taskbar And Start Menu Properties dialog box is displayed with the Start Menu tab selected by default.
  • On the Start Menu tab, use the Power Button Action list to select the action to use when the power button is pressed. Options include Switch User, Log Off, Lock, Restart, Sleep, and Shut Down. In a 24x7 environment, or when multiple users log on to the same computer, switching users, logging off, or locking the system may be preferable to shutting down the com¬puter. If you change the default action, you can shut down the computer by clicking Start and then clicking Shutdown.
  • Click Customize. This displays the Customize Start Menu dialog box.
  • Use the options in the dialog box to control the general appearance of the Start menu.
  • Click OK, and then click OK again to close the Taskbar And Start Menu Prop¬erties dialog box.

In the Customize Start Menu dialog box, most of the options control which commands appear on the Start menu and how they are arranged. Some items have the sub-options Display As A Link, Display As A Menu, and Don’t Display This Item. Display As A Link specifies that an item, such as Control Panel, will appear as a sepa¬rate option that opens a window when selected. Display As A Menu specifies that an item will provide access to a submenu that allows you to choose from its related options. Don’t Display This Item removes the item from the Start menu.
Other Customize Start Menu dialog box options you’ll see include the following:

  • Enable Context Menus And Dragging And Dropping When this option is selected, users can right-click to display a shortcut menu and use drag and drop. Typically, you’ll want to enable this option unless there is a specific security reason to disable it.
  • Highlight Newly Installed Programs When this option is selected, menus for recently installed applications are highlighted, as are the menu options.
  • Open Submenus When I Pause On Them With The Mouse Pointer Con¬trols the behavior of menus. When this option is selected, menus open when you point to them. Otherwise, menus open only when you click them.
  • Sort All Programs Menu By Name Controls whether menu items are organized alphabetically or by the order of installation. When this option is selected, menu items are sorted alphabetically. When this option is not selected, menu items are listed in the order of installation.
  • Use Large Icons Controls the size of icons for menu options. To reduce the size of icons used on menus, clear this option. Otherwise, select this option to display standard-size icons on menus.
  • Number Of Recent Programs To Display Controls the number of shortcuts to recently used programs that appear in the most frequently used list on the Start menu. Use the selection menu to assign a value from 0 to 30.The actual number of programs listed in the most frequently used list depends on the screen resolution as well as the number of items in the pinned items list, which appears above the most frequently used list on the Start menu.
  • Number of Recent Items To Display In Jump List Controls how many shortcuts to recently used items appear in jump lists. Jump lists are lists of recent items organized by the program that you use to open them. They can appear on the Start menu and the taskbar. Use the selection menu to assign a value from 0 to 60.

Windows 7 - Use the Registry to Configure Custom Search Providers

Search providers are stored in the registry in either the HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE hives at Software\Microsoft\Internet Explorer\SearchScopes. To automate the process of adding search providers to computers, use a test computer to configure the search engines manually, including specifying the default search engine. Then, create a .reg file based on this registry key and its subkeys and distribute it to your client computers.

To create a .reg file, follow these steps:

  • To start the Registry Editor, click Start, type Regedit, and then press Enter. 
    To configure search engines for individual users, select HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes.
  • To configure search engines for all users on a computer, select HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes.
  • Select Export from the File menu. Save the .reg file.

You can now distribute the .reg file to computers in your organization. To configure the search engines, double-click the .reg file to open the Registry Editor and apply the settings. Unfortunately, this requires administrative credentials. If you need to distribute the updated settings without explicitly providing administrative credentials, have a developer create a Windows Installer package that creates the registry values and distribute the Windows Installer package by using Group Policy software distribution.

Windows 7 - Use the Registry to Configure Custom Search Providers

Search providers are stored in the registry in either the HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE hives at Software\Microsoft\Internet Explorer\SearchScopes. To automate the process of adding search providers to computers, use a test computer to configure the search engines manually, including specifying the default search engine. Then, create a .reg file based on this registry key and its subkeys and distribute it to your client computers.

To create a .reg file, follow these steps:

  • To start the Registry Editor, click Start, type Regedit, and then press Enter. 
    To configure search engines for individual users, select HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes.
  • To configure search engines for all users on a computer, select HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes.
  • Select Export from the File menu. Save the .reg file.

You can now distribute the .reg file to computers in your organization. To configure the search engines, double-click the .reg file to open the Registry Editor and apply the settings. Unfortunately, this requires administrative credentials. If you need to distribute the updated settings without explicitly providing administrative credentials, have a developer create a Windows Installer package that creates the registry values and distribute the Windows Installer package by using Group Policy software distribution.

Windows7 - What’s new in Windows PowerShell 2.0

PowerShell 2.0 is now included in Windows 7 and Windows Server 2008 R2. As of October 2009, PowerShell 2.0 is available to download for Windows XP SP3, Windows 2003 SP2, Windows Vista-SP1, and Windows Server 2008 RTM.

Windows PowerShell 2.0 includes several significant features that extend its use, improve its usability, and allow you to control and manage Windows-based environments more easily and comprehensively. Windows PowerShell 2.0 is backward compatible: Cmdlets, providers, snap-ins, scripts, functions, and profiles that were designed for Windows PowerShell 1.0 work in Windows PowerShell 2.0 without changes.

So with that, let’s check out some of the new features:

Remoting - The PowerShell 2.0 install now includes WinRm 2.0 (Windows Remote Management),  which is our implementation of the WS-Management Protocol. WS-Management allows systems the ability to access and exchange management information across an IT infrastructure. This new ability allows you to run commands on one or more remote computers from a single computer that is also running Windows PowerShell. To configure PowerShell remoting, the following must be accomplished:

1. Start PowerShell as an administrator

2. Use the “Enable-PSRemoting” cmdlet. The “Enable-PSRemoting” cmdlet performs the following operations:

    • Runs the Set-WSManQuickConfig cmdlet, which performs the following tasks:
    • Starts the WinRM service.
    • Sets the startup type on the WinRM service to Automatic.
    • Creates a listener to accept requests on any IP address.
    • Enables a firewall exception for WS-Management communications.
    • Enables all registered Windows PowerShell session configurations to receive instructions from a remote computer.
    • Registers the "Microsoft.PowerShell" session configuration, if it is not already registered.
    • Registers the "Microsoft.PowerShell32" session configuration on 64-bit computers, if it is not already registered.
    • Removes the "Deny Everyone" setting from the security descriptor for all the registered session configurations.
    • Restarts the WinRM service to make the preceding changes effective.

New Cmdlets - PowerShell 2.0 introduces over 100 built-in cmdlets. These cmdlets allow you to do computer-related, event log, and performance counter management tasks, among others. To see a list of new cmdlets that support the remote –computername parameter, type in the following command at a PS > prompt:

Get-Command -CommandType cmdlet | Where-Object { $_.definition -match 'computername' } | Format-Wide -property name –AutoSize

To view a list of all included cmdlets, run the following command at the PS> prompt:

get-commands

Script Debugging - For all you debuggers out there, you can now set breakpoints on lines, columns, variables and commands, and then let you specify the action that occurs when the breakpoint is hit. To get help on Debugging your PowerShell scripts, type in the following command at a PS > prompt:

Help Set-PSDebug

PowerShell GUI - Looking for a PowerShell GUI? Well, now you have it with the PowerShell Integrated Scripting Environment (ISE). This new functionality enables you to run interactive commands and edit and debug scripts in a graphical environment. The main features include color-coded syntax, selective execution, graphical debugging, Unicode support, and context-sensitive help. To launch the PowerShell GUI, run PowerShell_ISE.exe.

Note: you must install the Windows PowerShell Integrated Scripting Environment feature to get the PowerShell GUI.

Background Jobs – PowerShell 2.0 now allows you to run commands or expressions asynchronously and “in the background” without interacting with the console. When you run a background job, the command prompt returns immediately, even if the command is still running. The get-command *-job command will give you a list of job cmdlets that you can use to schedule your jobs.

This is only a small listing of new features included in PowerShell 2.0. To get a complete list, checkout the links below or the about_Windows_PowerShell_2.0 help section included with PowerShell 2.0.

Windows7 - What’s new in Windows PowerShell 2.0

PowerShell 2.0 is now included in Windows 7 and Windows Server 2008 R2. As of October 2009, PowerShell 2.0 is available to download for Windows XP SP3, Windows 2003 SP2, Windows Vista-SP1, and Windows Server 2008 RTM.

Windows PowerShell 2.0 includes several significant features that extend its use, improve its usability, and allow you to control and manage Windows-based environments more easily and comprehensively. Windows PowerShell 2.0 is backward compatible: Cmdlets, providers, snap-ins, scripts, functions, and profiles that were designed for Windows PowerShell 1.0 work in Windows PowerShell 2.0 without changes.

So with that, let’s check out some of the new features:

Remoting - The PowerShell 2.0 install now includes WinRm 2.0 (Windows Remote Management),  which is our implementation of the WS-Management Protocol. WS-Management allows systems the ability to access and exchange management information across an IT infrastructure. This new ability allows you to run commands on one or more remote computers from a single computer that is also running Windows PowerShell. To configure PowerShell remoting, the following must be accomplished:

1. Start PowerShell as an administrator

2. Use the “Enable-PSRemoting” cmdlet. The “Enable-PSRemoting” cmdlet performs the following operations:

    • Runs the Set-WSManQuickConfig cmdlet, which performs the following tasks:
    • Starts the WinRM service.
    • Sets the startup type on the WinRM service to Automatic.
    • Creates a listener to accept requests on any IP address.
    • Enables a firewall exception for WS-Management communications.
    • Enables all registered Windows PowerShell session configurations to receive instructions from a remote computer.
    • Registers the "Microsoft.PowerShell" session configuration, if it is not already registered.
    • Registers the "Microsoft.PowerShell32" session configuration on 64-bit computers, if it is not already registered.
    • Removes the "Deny Everyone" setting from the security descriptor for all the registered session configurations.
    • Restarts the WinRM service to make the preceding changes effective.

New Cmdlets - PowerShell 2.0 introduces over 100 built-in cmdlets. These cmdlets allow you to do computer-related, event log, and performance counter management tasks, among others. To see a list of new cmdlets that support the remote –computername parameter, type in the following command at a PS > prompt:

Get-Command -CommandType cmdlet | Where-Object { $_.definition -match 'computername' } | Format-Wide -property name –AutoSize

To view a list of all included cmdlets, run the following command at the PS> prompt:

get-commands

Script Debugging - For all you debuggers out there, you can now set breakpoints on lines, columns, variables and commands, and then let you specify the action that occurs when the breakpoint is hit. To get help on Debugging your PowerShell scripts, type in the following command at a PS > prompt:

Help Set-PSDebug

PowerShell GUI - Looking for a PowerShell GUI? Well, now you have it with the PowerShell Integrated Scripting Environment (ISE). This new functionality enables you to run interactive commands and edit and debug scripts in a graphical environment. The main features include color-coded syntax, selective execution, graphical debugging, Unicode support, and context-sensitive help. To launch the PowerShell GUI, run PowerShell_ISE.exe.

Note: you must install the Windows PowerShell Integrated Scripting Environment feature to get the PowerShell GUI.

Background Jobs – PowerShell 2.0 now allows you to run commands or expressions asynchronously and “in the background” without interacting with the console. When you run a background job, the command prompt returns immediately, even if the command is still running. The get-command *-job command will give you a list of job cmdlets that you can use to schedule your jobs.

This is only a small listing of new features included in PowerShell 2.0. To get a complete list, checkout the links below or the about_Windows_PowerShell_2.0 help section included with PowerShell 2.0.

Windows 7: Learn Best Practices for Optimizing the Virtual Memory Configuration

In a default installation, Windows creates the page file in the root folder on the same drive that holds the Windows system files. The size of the page file is determined by the amount of RAM in your system. By default, the minimum size on a 32-bit (x86) system is 1.5 times the amount of physical RAM if physical RAM is less than 1 GB, and equal to the amount of physical RAM plus 300 MB if 1 GB or more is installed. The default maximum size is three times the amount of RAM, regardless of how much physical RAM is installed. On a PC with a processor that supports Physical Address Extension (PAE)—which is to say, on any PC that is capable of running Windows 7—the maximum size of the page file is 16 TB. You can see the page file in a Windows Explorer win¬dow if you configure Windows to show hidden and system files; look for Pagefile.sys in the root of your system drive.

To see the current configuration of your system’s virtual memory, open the System dialog box in Control Panel and click the Advanced tab.. Under the Performance heading, click Settings. In the Performance Options dialog box, click the Advanced tab. And under the Virtual Memory heading, click Change.
By default, Windows creates a single page file and manages its size. The Currently Allocated number near the bottom of the dialog box shows how large the file is. If conditions on your system change (say you run an unusually large assortment of memory-intensive applications), Windows might increase or even decrease the size of the page file. All this happens without you know as long as you leave the Automatically Manage Paging File Size for All Drives option selected.
If you don’t want Windows to automatically manage the page file, you have the following options:

  • You can move the page file to a different volume if you have more than one volume.
  • If you have more than one volume, you can establish more than one page file.
  • For any page file, you can choose between System Managed Size and Custom Size.
  • If you choose Custom Size, you can specify an initial size and a maximum size.
  • You can remove a paging file from a volume by selecting the volume and choosing No Paging File. (In fact, you can do this to get rid of all paging files, although doing so is not recommended, even on systems with a lot of RAM.)

Should you get involved in managing the page file? If you have more than one physical disk, moving the page file to a fast drive that doesn’t contain your Windows system files is a good idea. Using multiple page files split over two or more physical disks is an even better idea, because your disk controller can process multiple requests to read or write data concurrently. But don’t make the mistake of creating two or more page files using multiple volumes on a single physical disk. If, for example, you have a single hard disk that contains volumes C, D, and E, splitting the page file over two or more of these volumes, might actually make your computer run more slowly.
If you are short of hard disk space, you might consider setting a smaller initial page file size. Monitor peak usage levels over time; if the peak is well below the current page file size, you can consider reducing the initial size to save disk space. On the other hand, if you’re not short of disk space, there’s nothing to be gained from doing this and you might occasionally overload your custom settings, thereby degrading the performance of your system.
Should you enlarge your page file? Most users won’t need to do this. But you might want to keep an eye on the green line in the Memory chart on the Overview tab of Resource Monitor. If that line is spiking off the top of the graph a great deal of the time during your normal work, you might consider increasing the maximum size of your page file. (Note that you should disregard page file spikes and disk activity in general that takes place while you’re not actually working. This is likely to be the result of search indexing, defragmentation, or other background processes and does not indicate a problem with your actual work performance.

Windows 7: Learn Best Practices for Optimizing the Virtual Memory Configuration

In a default installation, Windows creates the page file in the root folder on the same drive that holds the Windows system files. The size of the page file is determined by the amount of RAM in your system. By default, the minimum size on a 32-bit (x86) system is 1.5 times the amount of physical RAM if physical RAM is less than 1 GB, and equal to the amount of physical RAM plus 300 MB if 1 GB or more is installed. The default maximum size is three times the amount of RAM, regardless of how much physical RAM is installed. On a PC with a processor that supports Physical Address Extension (PAE)—which is to say, on any PC that is capable of running Windows 7—the maximum size of the page file is 16 TB. You can see the page file in a Windows Explorer win¬dow if you configure Windows to show hidden and system files; look for Pagefile.sys in the root of your system drive.

To see the current configuration of your system’s virtual memory, open the System dialog box in Control Panel and click the Advanced tab.. Under the Performance heading, click Settings. In the Performance Options dialog box, click the Advanced tab. And under the Virtual Memory heading, click Change.
By default, Windows creates a single page file and manages its size. The Currently Allocated number near the bottom of the dialog box shows how large the file is. If conditions on your system change (say you run an unusually large assortment of memory-intensive applications), Windows might increase or even decrease the size of the page file. All this happens without you know as long as you leave the Automatically Manage Paging File Size for All Drives option selected.
If you don’t want Windows to automatically manage the page file, you have the following options:

  • You can move the page file to a different volume if you have more than one volume.
  • If you have more than one volume, you can establish more than one page file.
  • For any page file, you can choose between System Managed Size and Custom Size.
  • If you choose Custom Size, you can specify an initial size and a maximum size.
  • You can remove a paging file from a volume by selecting the volume and choosing No Paging File. (In fact, you can do this to get rid of all paging files, although doing so is not recommended, even on systems with a lot of RAM.)

Should you get involved in managing the page file? If you have more than one physical disk, moving the page file to a fast drive that doesn’t contain your Windows system files is a good idea. Using multiple page files split over two or more physical disks is an even better idea, because your disk controller can process multiple requests to read or write data concurrently. But don’t make the mistake of creating two or more page files using multiple volumes on a single physical disk. If, for example, you have a single hard disk that contains volumes C, D, and E, splitting the page file over two or more of these volumes, might actually make your computer run more slowly.
If you are short of hard disk space, you might consider setting a smaller initial page file size. Monitor peak usage levels over time; if the peak is well below the current page file size, you can consider reducing the initial size to save disk space. On the other hand, if you’re not short of disk space, there’s nothing to be gained from doing this and you might occasionally overload your custom settings, thereby degrading the performance of your system.
Should you enlarge your page file? Most users won’t need to do this. But you might want to keep an eye on the green line in the Memory chart on the Overview tab of Resource Monitor. If that line is spiking off the top of the graph a great deal of the time during your normal work, you might consider increasing the maximum size of your page file. (Note that you should disregard page file spikes and disk activity in general that takes place while you’re not actually working. This is likely to be the result of search indexing, defragmentation, or other background processes and does not indicate a problem with your actual work performance.

Windows 7 - Use Windows PowerShell to Monitor System Performance

Windows 7 - Hide Updates that you do not Ever Want to Install

If you choose not to download and install an update, it’s available for you the next time you visit Windows Update…and the next time, and the time after that as well. You might have a good reason for not accepting a particular update—perhaps it makes improvements to a Windows feature you never use—and there’s no reason it should clutter your list of available updates. To remove an item from the list without installing it, you hide it. This is a pretty easy trick, but the option for hiding updates in the list is itself somewhat hidden and often goes overlooked.

In the list of available updates, right-click any update that you don’t want to see again, and choose Hide Update. If you later change your mind—or if you just want to see a list of the updates you’ve chosen to hide—on the main Windows Update page, click Restore Hidden Updates.

Windows 7 - Use Windows PowerShell to Monitor System Performance

A new feature in Windows 7 is the ability to use Windows PowerShell for gathering performance data. Three new Windows PowerShell cmdlets provide functionality as follows:

Get-counter Gets real-time performance counter data from local and remote computers.

Import-counter Exports Performance Counter Sample Set objects as performance counter log (.blg, .csv, .tsv) files.

Export-counter Imports performance counter log files and creates objects that represent each counter sample in the log.
For example, the following Windows PowerShell command gets the current “% Processor Time” combined values for all processors on the local computer every 2 seconds until it has 100 values and displays the captured data:

PS C:\Users\mallen>Get-counter -Counter "\Processor(_Total)\% Processor Time" -SampleInterval 2 -MaxSamples 100

The following command continuously gets the current “% Processor Time” combined values for all processors on the local computer every second (the default sampling interval) and displays the captured data until you press CTRL+C:

PS C:\Users\mallen>Get-counter -Counter "\Processor(_Total)\% Processor Time" –Continuous

You can pipe the output of the Get-counter cmdlet into the Export-counter cmdlet.For example, the following command gets the current “% Processor Time” combined values for all processors on the local computer every 2 seconds until it has 100 values and exports the captured data as a performance counter log file named Data1.blg, which is saved in the current directory (here the root folder of user user1 profile):

PS C:\Users\ user1>Get-counter "\Processor(*)\% Processor Time" -SampleInterval 2 -MaxSamples 100 | Export-counter -Path $home\data1.blg
You can also pipe the output of the Import-counter cmdlet into the Export-counter cmdlet. You might do this, for example, to convert a performance monitor log file from one format to another, such as from .csv to .blg format.

Windows 7 - Use Windows PowerShell to Monitor System Performance

Windows 7 - Hide Updates that you do not Ever Want to Install

If you choose not to download and install an update, it’s available for you the next time you visit Windows Update…and the next time, and the time after that as well. You might have a good reason for not accepting a particular update—perhaps it makes improvements to a Windows feature you never use—and there’s no reason it should clutter your list of available updates. To remove an item from the list without installing it, you hide it. This is a pretty easy trick, but the option for hiding updates in the list is itself somewhat hidden and often goes overlooked.

In the list of available updates, right-click any update that you don’t want to see again, and choose Hide Update. If you later change your mind—or if you just want to see a list of the updates you’ve chosen to hide—on the main Windows Update page, click Restore Hidden Updates.

Windows 7 - Use Windows PowerShell to Monitor System Performance

A new feature in Windows 7 is the ability to use Windows PowerShell for gathering performance data. Three new Windows PowerShell cmdlets provide functionality as follows:

Get-counter Gets real-time performance counter data from local and remote computers.

Import-counter Exports Performance Counter Sample Set objects as performance counter log (.blg, .csv, .tsv) files.

Export-counter Imports performance counter log files and creates objects that represent each counter sample in the log.
For example, the following Windows PowerShell command gets the current “% Processor Time” combined values for all processors on the local computer every 2 seconds until it has 100 values and displays the captured data:

PS C:\Users\mallen>Get-counter -Counter "\Processor(_Total)\% Processor Time" -SampleInterval 2 -MaxSamples 100

The following command continuously gets the current “% Processor Time” combined values for all processors on the local computer every second (the default sampling interval) and displays the captured data until you press CTRL+C:

PS C:\Users\mallen>Get-counter -Counter "\Processor(_Total)\% Processor Time" –Continuous

You can pipe the output of the Get-counter cmdlet into the Export-counter cmdlet.For example, the following command gets the current “% Processor Time” combined values for all processors on the local computer every 2 seconds until it has 100 values and exports the captured data as a performance counter log file named Data1.blg, which is saved in the current directory (here the root folder of user user1 profile):

PS C:\Users\ user1>Get-counter "\Processor(*)\% Processor Time" -SampleInterval 2 -MaxSamples 100 | Export-counter -Path $home\data1.blg
You can also pipe the output of the Import-counter cmdlet into the Export-counter cmdlet. You might do this, for example, to convert a performance monitor log file from one format to another, such as from .csv to .blg format.

Jan 3, 2010

How to get Crash or Hang dump?

I have various methods/tools to collect crash/ hang dump. This article is aimed to consolidate and provide all the related information in a single nutshell.

Target Users : The Reader is familiar with Windows OS (XP & Vista)

Wondering what crash is & how to get crash dump! Here U go!!

A crash in computing is a condition where a program (either an application or part of the operating system) stops performing its expected function and also stops responding to other parts of the system. Often the offending program may simply appear to freeze.

A crash can either be a software fault or system crash. A software fault occurs whenever an exception is left unhandled. Upon software fault the OS stops the application from proceeding further.

System Crash or Blue screens on NT-based Windows systems are usually caused by poorly-written device drivers or malfunctioning hardware. Blue screens can also be caused by physical faults such as faulty memory, power supplies, overheating of computer components, or hardware running beyond its specification limits.

Various Methods for collecting crash dump

Below are the few methods to collect crash information.

  • Using Windbg
  • Using Adplus
  • Using ‘Create Dump option in Vista
  • Using ‘Problem Reports & Solutions’ in Vista
  • Getting dump on BSOD
  • From Keystroke
  • Dump on Heap corruption
Generate crash dump using Windbg as default post-mortem debugger
  • Install Windbg before installing the product.
  • Set Windbg as the default post-mortem debugger
  • Launch command prompt (as admin in Vista)
  • Go to the windbg installed path (C:\Program Files\Debugging Tools for Windows\)
  • Type “windbg.exe –I” and hit ‘Enter’
  • You will see the message “Windbg is set as default post mortem debugger”

Now install the product and continue with your testing. Whenever crash occurs, windbg opens automatically. The below command is used to collect the crash.

.dump /ma <path>\<filename>.dmp

Where, <path> is the path where you want to save the crash dump and <filename> is the name of the file.

Generate crash dump using Windbg after crash occurs (not set any post-mortem debugger)
  • Install Windbg
  • From the crash window, see which process is crashed
  • From the task manager, identify the process Id
  • Make sure you have not closed the crash window
  • Launch windbg from “Start > Programs > Debugging Tools for Windows > WinDbg”
  • Select File > Attach to a Process
  • Select the Process for which you want to collect the crash dump and click OK
  • Type the command .dump /ma <path>\<filename>.dmp in the launched window
Generate Crash/hang dump using Adplus (not set any post-mortem debugger)
  • Install Windbg
  • Identify the process for which you want to generate the dump
  • Make a note of the process id from task manager
  • From command prompt (run as ‘admin’ for Vista), go to C:\Program Files\Debugging Tools for Windows\
  • Type “adplus.vbs” and hit ‘Enter’
  • In the launched dialogs click ‘Ok’
  • In the newly launched command window, you can use any of the below commands
    1. ‘adplus –crash –p <pid>’
    2. ‘adplus –crash –pn <pname>’
    3. ‘adplus –hang –p <pid>’
    4. ‘adplus –hang –pn <pname>’
  • Click ‘Ok’ in the launched dialogs
  • cdb.exe will be running
  • Now perform the test steps you want to do (you want to make a crash/hang)

Once the process crashed the dump will be automatically generated as a dated folder in “C:\Program Files\Debugging Tools for Windows\”

If the cdb.exe doesn’t end, you can use Ctl+C to quit the cdb.exe window and can get the dump

Generate dump using ‘Create Dump’ option in Vista
  • Identify the process for which you want to collect the dump
  • Go to Task Manager > Right click the process > click ‘Create Dump’
  • The dump will be created in %temp% folder
Generate dump using ‘Problem Reports & Solutions’ in Vista

Windows Vista introduced the “Problem Reports and Solutions” control panel application. This dialog will show all detected application errors on the user’s machine. When a crash is encountered, we can leverage this built-in utility to get more information about what went wrong, and how to get more information to help resolve the issue.

When this event is recorded, there are three possible scenarios

  • The crash or hang was recorded and submitted
  • The crash or hang was recorded, but not yet submitted
  • The crash or hang was recorded, but no information was captured.

The first two can provide us with valuable information to troubleshoot the issue. The third can give us a general idea, but no specific information about the exact issue the user reported.

Windows Error Reporting configuration is stored in the following registry key in Vista

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting

User based settings such as Block list are stored at:

HKEY_CURRENT_USER\Software\Microsoft\ Windows\Windows Error Reporting

Problem Reports and Solutions

This dialog is available via Start / Control Panel / Problem Reports and Solutions, or under Start / Control Panel / System and Maintenance / Problem Reports and Solutions (depending on whether the user has “classic view” configured or not). From there, click on “View Problem History”, and look for instances of applications. Double click an entry of interest, and select the “Copy to Clipboard” link, and provide the info. The data will tell us how much information is available, without any other files.

clip_image002

Case 1: WER data Submitted

In this case, the error report has already been submitted. The “Copy to Clipboard” data will include the bucket ID. Usually, in this case, the event files are removed from the local computer, as they have already been submitted. We must look up the crash using the bucket ID provided.

clip_image002[6]

Case 2: WER data Available Locally

In other cases, the report has not yet been sent to WinQual. In this case, we can generally collect the files locally. The files that are available will also be included with the “Copy to clipboard” link at the bottom of the screen is used.

clip_image002[8]

Once the “View Copy” of files link is clicked, an explorer window in the temp directory will be opened. The files present in the temp directory will definitely give more information on crash and hence this can be given to the developer for analysis.

Case 3: WER data not available or Submitted

Unfortunately, in some cases there’s no data available but the exception code, modules names and versions, and offset of the crash. In this case, the best we can do is dig through the data on winqual in an attempt to find it, but it’s not guaranteed the correct crash will be found. The screen shot below is of a managed application.

clip_image002[10]

Blue Screens

In many cases, reports of bug checks (BSODs) will also appear on this screen, allowing this approach to be used when a user experiences a system crash and suspects it may be related to specific software. The approach may be used to collect information about this type of crash as for the application hangs or crashes described above.

clip_image002[12]

Common Issues

In some cases, multiple crashes can appear at the same module & offset. Having a WinQual bucket ID or simply a module offset is sometimes not sufficient to describe the exact crash the user encountered.

Note:

1. When a process is added to the Block list of ‘Problem Reports and Solutions’ you will not get the WER Report for that process.

This can be checked by looking at the Block List at,

Control Panel > Classic View > ‘Problem Reports and Solutions’ > Change Settings > Advanced Settings > Block List

2. Starting with Windows Server 2008 and Windows Vista with Service Pack 1 (SP1), Windows Error Reporting (WER) can be configured so that full user-mode dumps are collected and stored locally after a user-mode application crash.

For more information on this refer http://msdn.microsoft.com/en-us/library/bb787181.aspx

Generate Dump on BSOD

Whenever BSOD occurs the memory dump will be collected automatically at

%SystemRoot%MEMORY.DMP

But the default dump is a small memory dump. In order to get the complete memory dump or kernel memory dump

  • Go to System Properties > Advanced > Startup and Recovery > Settings
  • From Write debugging information, choose the one which you want
  • Click Ok.
  • Proceed with your testing.
Generate Memory Dump using keyboard

Following are the steps to generate the dump using keyboard:

1.    To enable keyboard crash dumping, we need to enable a regkey in regedit. This setting varies w.r.t the keyboard type we use in our machine.

To enable the feature on a computer that uses a PS/2 keyboard, follow these steps:

  • Start Registry Editor.
  • Locate the following registry subkey:
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\i8042prt\Parameters
  • On the Edit menu, click Add Value, and then add the following registry entry:
    • Name: CrashOnCtrlScroll
      Data Type: REG_DWORD
      Value: 1
  • Exit Registry Editor and then restart the computer.

Note: Restart the computer after this regkey setting is must for PS/2 Keyboard.

To enable the feature on a computer that uses a USB keyboard, install the hotfix that is mentioned in the "Windows Server 2003 resolution" subsection of the article at http://support.microsoft.com/kb/244139

To make sure that the feature is enabled on a computer that uses a USB keyboard, follow these steps:

  • Start Registry Editor.
  • Locate the following registry subkey:

           HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\kbdhid\Parameters

  • Make sure that the following registry entry is enabled:

    Name: CrashOnCtrlScroll
    Data Type: REG_DWORD
    Value: 1

  • Exit Registry Editor.
Note: For USB keyboard, Restart is not required. Instead unplug the keyboard and plug it again after this regkey setting.

2.  After setting this regkey, select the appropriate memory dump file option using the below steps:

  • Right-click My Computer and then click Properties.
  • Click the Advanced tab, and then click the Startup and Recovery button.
  • Click Write Debugging Information and then click to select Complete Memory Dump, Kernel Memory Dump, or Small Memory Dump.

3.  When you get the hang, just hold down the CTRL key and pressing the SCROLL LOCK key two times. You must use the CTRL key on the right side of the spacebar.

You can see a Blue screen (as you see during BSOD) wherein it shows the progress of collecting the crash dumps.

Machine will be restarted after this process and you can get the memory dump in "C:\Windows\MEMORY.DMP"

For detailed info, visit this page http://support.microsoft.com/kb/244139

Getting heap information in case of Heap Corruption
  • Enable WinDbg as Post-Mortem debugger using the command  - Windbg -I
  • Enable Full Page Heap Verification for the process (In case of Heap Corruption). Use the below command gflags.exe -p /enable <Image File> /full           
  • When the crash occurs, type the following in the Windows Debugger Command Window   .dump /ma <Dump_Path\File_Name.dmp>
  • As the Page Heap is enabled, we will get complete details of Stack+Heap in the Dump. (Check the Size of the Dump .... It should be approx. 200 MB +).
  • When the dump is created, disable the heap for the particular application. gflags.exe -p /disable <Image File>

Note: Make sure the gflags is enabled before the corresponding process (for which you are trying to generate the dump) starts. In other words, kill the process for which you want to get the heap information, enable gflags for that process, start the process, reproduce the crash and get the dump.

For more information on crash dump you can refer http://msdn.microsoft.com/en-us/library/cc265901.aspx

Set Symbols for Debugging
  • Private symbols files have all information in them for the debugger to resolve data (local variables, structure type information, functions, source file name/line info...).
  • Public symbols files are essentially stripped versions of private symbols that usually just contain the function information so that stack traces work. Sometimes limited type information is included so that debugger extensions can work.
  • Export symbols are the symbols contained inside the binary, so you have these without a .pdb. They contain the public/exported function names.

1) Download the XP/Vista symbols from http://www.microsoft.com/whdc/DevTools/Debugging/symbolpkg.mspx

2) Install the symbols

3) Set the symbol path in windbg via,

Start > Programs > Debugging Tools for Windows > Windbg > File > Symbol File Path

Windbg commands to get the first level info
  • Get Stack Trace using !analyze -v
  • Task Tree using tlist.exe -t
  • Services active in each process using tlist.exe -s
  • Command Line Information using tlist.exe -c
  • Complete Verbose Information using tlist.exe –v
Remote Kernel Debugging

Sometimes if you want to set a breakpoint in the windows kernel and the kernel hit the breakpoint, then the whole system would freeze, because kernel controls (among other stuff) process management, thread switching, etc. In such situations use of two computers to do a remote kernel debugging would be a better option. Below are the steps to perform Remote Kernel debugging using a serial cable or USB cable or Firewire (IEEE 1394).

  • Consider “Machine 1”, which is the computer that you want to debug and ‘Machine 2”, which is the computer running Windbg. First, connect these two computers using Serial cable or USB cable or Firewire
  • Now from Machine 2, start Windbg > File > Kernel Debug & select COM or USB or 1394 according to the connection you have made.
  • Specify the values in the corresponding tab as below and click OK to the Kernel Debugging window
    • COM
      • Baud rate – 115200 (mostly)
      • Port – COM1 or COM2
      • You can check the ‘Pipe’ option if you want to debug a Vmware running in Machine 2
    • USB
      • Specify the target name (any name, but the same should be used in Machine 1)
    • 1394
      • Specify the Channel (a numeric value, but the same should be used in Machine 1)
  • Now windbg in Machine 2 will wait until you configure Machine 1 to go into debug mode
  • From Machine 2, enter into safe mode with networking.
    • XP
      • From command prompt go to C:\Windows\System32 folder
      • Type, bootcfg.exe /debug ON /baud 115200 /PORT COM1 /id 1
      • Use corresponding commands for USB or 1394
    • Vista
      • From command prompt go to C:\Windows\System32 folder
      • Type, bcdedit /dbgsettings DebugType [debugport:Port] [baudrate:Baud]
      • Ex, for serial debugging (using COM1 at 115200bps) it is: bcdedit /dbgsettings serial debugport:1 baudrate:115200
      • After that, enable debugging by using the below command. bcedit /debug on
      • Restart the Machine 1, if everything was configured correctly, you will see Machine 1 stop during boot, and Machine 2's windbg will print a message saying that the connection was established.
  • Now reproduce the crash
  • From Machine 1 , use the below command to get the crash dump. .dump /ma <path\filename>.dmp
References

How to get Crash or Hang dump?

I have various methods/tools to collect crash/ hang dump. This article is aimed to consolidate and provide all the related information in a single nutshell.

Target Users : The Reader is familiar with Windows OS (XP & Vista)

Wondering what crash is & how to get crash dump! Here U go!!

A crash in computing is a condition where a program (either an application or part of the operating system) stops performing its expected function and also stops responding to other parts of the system. Often the offending program may simply appear to freeze.

A crash can either be a software fault or system crash. A software fault occurs whenever an exception is left unhandled. Upon software fault the OS stops the application from proceeding further.

System Crash or Blue screens on NT-based Windows systems are usually caused by poorly-written device drivers or malfunctioning hardware. Blue screens can also be caused by physical faults such as faulty memory, power supplies, overheating of computer components, or hardware running beyond its specification limits.

Various Methods for collecting crash dump

Below are the few methods to collect crash information.

  • Using Windbg
  • Using Adplus
  • Using ‘Create Dump option in Vista
  • Using ‘Problem Reports & Solutions’ in Vista
  • Getting dump on BSOD
  • From Keystroke
  • Dump on Heap corruption
Generate crash dump using Windbg as default post-mortem debugger
  • Install Windbg before installing the product.
  • Set Windbg as the default post-mortem debugger
  • Launch command prompt (as admin in Vista)
  • Go to the windbg installed path (C:\Program Files\Debugging Tools for Windows\)
  • Type “windbg.exe –I” and hit ‘Enter’
  • You will see the message “Windbg is set as default post mortem debugger”

Now install the product and continue with your testing. Whenever crash occurs, windbg opens automatically. The below command is used to collect the crash.

.dump /ma <path>\<filename>.dmp

Where, <path> is the path where you want to save the crash dump and <filename> is the name of the file.

Generate crash dump using Windbg after crash occurs (not set any post-mortem debugger)
  • Install Windbg
  • From the crash window, see which process is crashed
  • From the task manager, identify the process Id
  • Make sure you have not closed the crash window
  • Launch windbg from “Start > Programs > Debugging Tools for Windows > WinDbg”
  • Select File > Attach to a Process
  • Select the Process for which you want to collect the crash dump and click OK
  • Type the command .dump /ma <path>\<filename>.dmp in the launched window
Generate Crash/hang dump using Adplus (not set any post-mortem debugger)
  • Install Windbg
  • Identify the process for which you want to generate the dump
  • Make a note of the process id from task manager
  • From command prompt (run as ‘admin’ for Vista), go to C:\Program Files\Debugging Tools for Windows\
  • Type “adplus.vbs” and hit ‘Enter’
  • In the launched dialogs click ‘Ok’
  • In the newly launched command window, you can use any of the below commands
    1. ‘adplus –crash –p <pid>’
    2. ‘adplus –crash –pn <pname>’
    3. ‘adplus –hang –p <pid>’
    4. ‘adplus –hang –pn <pname>’
  • Click ‘Ok’ in the launched dialogs
  • cdb.exe will be running
  • Now perform the test steps you want to do (you want to make a crash/hang)

Once the process crashed the dump will be automatically generated as a dated folder in “C:\Program Files\Debugging Tools for Windows\”

If the cdb.exe doesn’t end, you can use Ctl+C to quit the cdb.exe window and can get the dump

Generate dump using ‘Create Dump’ option in Vista
  • Identify the process for which you want to collect the dump
  • Go to Task Manager > Right click the process > click ‘Create Dump’
  • The dump will be created in %temp% folder
Generate dump using ‘Problem Reports & Solutions’ in Vista

Windows Vista introduced the “Problem Reports and Solutions” control panel application. This dialog will show all detected application errors on the user’s machine. When a crash is encountered, we can leverage this built-in utility to get more information about what went wrong, and how to get more information to help resolve the issue.

When this event is recorded, there are three possible scenarios

  • The crash or hang was recorded and submitted
  • The crash or hang was recorded, but not yet submitted
  • The crash or hang was recorded, but no information was captured.

The first two can provide us with valuable information to troubleshoot the issue. The third can give us a general idea, but no specific information about the exact issue the user reported.

Windows Error Reporting configuration is stored in the following registry key in Vista

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting

User based settings such as Block list are stored at:

HKEY_CURRENT_USER\Software\Microsoft\ Windows\Windows Error Reporting

Problem Reports and Solutions

This dialog is available via Start / Control Panel / Problem Reports and Solutions, or under Start / Control Panel / System and Maintenance / Problem Reports and Solutions (depending on whether the user has “classic view” configured or not). From there, click on “View Problem History”, and look for instances of applications. Double click an entry of interest, and select the “Copy to Clipboard” link, and provide the info. The data will tell us how much information is available, without any other files.

clip_image002

Case 1: WER data Submitted

In this case, the error report has already been submitted. The “Copy to Clipboard” data will include the bucket ID. Usually, in this case, the event files are removed from the local computer, as they have already been submitted. We must look up the crash using the bucket ID provided.

clip_image002[6]

Case 2: WER data Available Locally

In other cases, the report has not yet been sent to WinQual. In this case, we can generally collect the files locally. The files that are available will also be included with the “Copy to clipboard” link at the bottom of the screen is used.

clip_image002[8]

Once the “View Copy” of files link is clicked, an explorer window in the temp directory will be opened. The files present in the temp directory will definitely give more information on crash and hence this can be given to the developer for analysis.

Case 3: WER data not available or Submitted

Unfortunately, in some cases there’s no data available but the exception code, modules names and versions, and offset of the crash. In this case, the best we can do is dig through the data on winqual in an attempt to find it, but it’s not guaranteed the correct crash will be found. The screen shot below is of a managed application.

clip_image002[10]

Blue Screens

In many cases, reports of bug checks (BSODs) will also appear on this screen, allowing this approach to be used when a user experiences a system crash and suspects it may be related to specific software. The approach may be used to collect information about this type of crash as for the application hangs or crashes described above.

clip_image002[12]

Common Issues

In some cases, multiple crashes can appear at the same module & offset. Having a WinQual bucket ID or simply a module offset is sometimes not sufficient to describe the exact crash the user encountered.

Note:

1. When a process is added to the Block list of ‘Problem Reports and Solutions’ you will not get the WER Report for that process.

This can be checked by looking at the Block List at,

Control Panel > Classic View > ‘Problem Reports and Solutions’ > Change Settings > Advanced Settings > Block List

2. Starting with Windows Server 2008 and Windows Vista with Service Pack 1 (SP1), Windows Error Reporting (WER) can be configured so that full user-mode dumps are collected and stored locally after a user-mode application crash.

For more information on this refer http://msdn.microsoft.com/en-us/library/bb787181.aspx

Generate Dump on BSOD

Whenever BSOD occurs the memory dump will be collected automatically at

%SystemRoot%MEMORY.DMP

But the default dump is a small memory dump. In order to get the complete memory dump or kernel memory dump

  • Go to System Properties > Advanced > Startup and Recovery > Settings
  • From Write debugging information, choose the one which you want
  • Click Ok.
  • Proceed with your testing.
Generate Memory Dump using keyboard

Following are the steps to generate the dump using keyboard:

1.    To enable keyboard crash dumping, we need to enable a regkey in regedit. This setting varies w.r.t the keyboard type we use in our machine.

To enable the feature on a computer that uses a PS/2 keyboard, follow these steps:

  • Start Registry Editor.
  • Locate the following registry subkey:
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\i8042prt\Parameters
  • On the Edit menu, click Add Value, and then add the following registry entry:
    • Name: CrashOnCtrlScroll
      Data Type: REG_DWORD
      Value: 1
  • Exit Registry Editor and then restart the computer.

Note: Restart the computer after this regkey setting is must for PS/2 Keyboard.

To enable the feature on a computer that uses a USB keyboard, install the hotfix that is mentioned in the "Windows Server 2003 resolution" subsection of the article at http://support.microsoft.com/kb/244139

To make sure that the feature is enabled on a computer that uses a USB keyboard, follow these steps:

  • Start Registry Editor.
  • Locate the following registry subkey:

           HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\kbdhid\Parameters

  • Make sure that the following registry entry is enabled:

    Name: CrashOnCtrlScroll
    Data Type: REG_DWORD
    Value: 1

  • Exit Registry Editor.
Note: For USB keyboard, Restart is not required. Instead unplug the keyboard and plug it again after this regkey setting.

2.  After setting this regkey, select the appropriate memory dump file option using the below steps:

  • Right-click My Computer and then click Properties.
  • Click the Advanced tab, and then click the Startup and Recovery button.
  • Click Write Debugging Information and then click to select Complete Memory Dump, Kernel Memory Dump, or Small Memory Dump.

3.  When you get the hang, just hold down the CTRL key and pressing the SCROLL LOCK key two times. You must use the CTRL key on the right side of the spacebar.

You can see a Blue screen (as you see during BSOD) wherein it shows the progress of collecting the crash dumps.

Machine will be restarted after this process and you can get the memory dump in "C:\Windows\MEMORY.DMP"

For detailed info, visit this page http://support.microsoft.com/kb/244139

Getting heap information in case of Heap Corruption
  • Enable WinDbg as Post-Mortem debugger using the command  - Windbg -I
  • Enable Full Page Heap Verification for the process (In case of Heap Corruption). Use the below command gflags.exe -p /enable <Image File> /full           
  • When the crash occurs, type the following in the Windows Debugger Command Window   .dump /ma <Dump_Path\File_Name.dmp>
  • As the Page Heap is enabled, we will get complete details of Stack+Heap in the Dump. (Check the Size of the Dump .... It should be approx. 200 MB +).
  • When the dump is created, disable the heap for the particular application. gflags.exe -p /disable <Image File>

Note: Make sure the gflags is enabled before the corresponding process (for which you are trying to generate the dump) starts. In other words, kill the process for which you want to get the heap information, enable gflags for that process, start the process, reproduce the crash and get the dump.

For more information on crash dump you can refer http://msdn.microsoft.com/en-us/library/cc265901.aspx

Set Symbols for Debugging
  • Private symbols files have all information in them for the debugger to resolve data (local variables, structure type information, functions, source file name/line info...).
  • Public symbols files are essentially stripped versions of private symbols that usually just contain the function information so that stack traces work. Sometimes limited type information is included so that debugger extensions can work.
  • Export symbols are the symbols contained inside the binary, so you have these without a .pdb. They contain the public/exported function names.

1) Download the XP/Vista symbols from http://www.microsoft.com/whdc/DevTools/Debugging/symbolpkg.mspx

2) Install the symbols

3) Set the symbol path in windbg via,

Start > Programs > Debugging Tools for Windows > Windbg > File > Symbol File Path

Windbg commands to get the first level info
  • Get Stack Trace using !analyze -v
  • Task Tree using tlist.exe -t
  • Services active in each process using tlist.exe -s
  • Command Line Information using tlist.exe -c
  • Complete Verbose Information using tlist.exe –v
Remote Kernel Debugging

Sometimes if you want to set a breakpoint in the windows kernel and the kernel hit the breakpoint, then the whole system would freeze, because kernel controls (among other stuff) process management, thread switching, etc. In such situations use of two computers to do a remote kernel debugging would be a better option. Below are the steps to perform Remote Kernel debugging using a serial cable or USB cable or Firewire (IEEE 1394).

  • Consider “Machine 1”, which is the computer that you want to debug and ‘Machine 2”, which is the computer running Windbg. First, connect these two computers using Serial cable or USB cable or Firewire
  • Now from Machine 2, start Windbg > File > Kernel Debug & select COM or USB or 1394 according to the connection you have made.
  • Specify the values in the corresponding tab as below and click OK to the Kernel Debugging window
    • COM
      • Baud rate – 115200 (mostly)
      • Port – COM1 or COM2
      • You can check the ‘Pipe’ option if you want to debug a Vmware running in Machine 2
    • USB
      • Specify the target name (any name, but the same should be used in Machine 1)
    • 1394
      • Specify the Channel (a numeric value, but the same should be used in Machine 1)
  • Now windbg in Machine 2 will wait until you configure Machine 1 to go into debug mode
  • From Machine 2, enter into safe mode with networking.
    • XP
      • From command prompt go to C:\Windows\System32 folder
      • Type, bootcfg.exe /debug ON /baud 115200 /PORT COM1 /id 1
      • Use corresponding commands for USB or 1394
    • Vista
      • From command prompt go to C:\Windows\System32 folder
      • Type, bcdedit /dbgsettings DebugType [debugport:Port] [baudrate:Baud]
      • Ex, for serial debugging (using COM1 at 115200bps) it is: bcdedit /dbgsettings serial debugport:1 baudrate:115200
      • After that, enable debugging by using the below command. bcedit /debug on
      • Restart the Machine 1, if everything was configured correctly, you will see Machine 1 stop during boot, and Machine 2's windbg will print a message saying that the connection was established.
  • Now reproduce the crash
  • From Machine 1 , use the below command to get the crash dump. .dump /ma <path\filename>.dmp
References

Nov 6, 2009

What is Slipstreaming?

What is Slipstreaming?

Slipstreaming dates back to pre-release of Windows 2000 (Windows NT days), Microsoft decided to create a more refined way of integrating service packs or drivers and/or other fixes back into the core Operating System, so that the enterprise customers could always maintain an install of latest version of Windows on new machines.

Slipstreaming is usually done on network shares on corporate enterprise systems. But with the arrival of CD burners being so cheap, it does actually make some sense for the home user or small business user to do the same.

In Pre-Windows 2000 days, i.e. in Windows NT time, this process was a bit complicated in the sense that when users needed to install Windows they had to explicitly download Service Packs after installation of windows, and service pack installs often required users to reinstall components that had previously been installed. This process wasn’t that easy, but with the release of Windows 2000, which fixed it all. From then on Slipstreaming was more or less the same and there are now many software's released to make this process even simpler.

Slipstreaming Windows XP with Service Pack 3

To Slipstream a Service Pack (SP2 or SP3 into a Windows XP or Windows 2000 server),

1. Download the Service Pack 3 (WINDOWSXP-KB936929-sp3-x86-ENU.exe, 316.4 MB), and save it to a directory/folder on your local hard drive (for ex: E:\XP-SP3). For easier remembrance you can rename the downloaded SP3 file to XPsp3.exe.

NOTE: There should be no spaces in the folder naming.

2. Copy the contents of your Windows XP CD to your local hard drive, just create a folder (for ex: E:\XP-CD), and copy all the contents of your Windows XP CD [original version ;-)] in that folder, this might take some time, meanwhile proceed with the next steps.

Get XP SP3 and extract it

1. While that is copying, extract the Windows XP SP3, to do this you need to open a Command Prompt (Start > Run > cmd), and go to the folder where you downloaded SP3 (cd /d E:\XP-SP3).

a. Type the command:

XPsp3.exe -x:e:\XP-SP3

You will then get a pop-up dialog box stating that the files are being extracted.

clip_image002

Once the extraction is done click on OK. You will now be able to see the folder i386, in e:\XP-SP3 folder, which contains the extracted files.

Combine XP with SP3

1. Open a Command Prompt (Start > Run > cmd), and go to the folder where you downloaded SP3 (cd /d E:\XP-SP3).

a. Type the command:

servicepack filename /integrate:drive/path

In my example the command is

WINDOWSXP-KB936929-sp3-x86-ENU /integrate:E:\XP-CD

clip_image004

Once you hit enter you will get an error pop-up.

clip_image006

This happens by the fact that your Windows CD contains updates which cannot be automatically installed when you run the setup. This type of errors occurs when the CD’s are usually from OEM (Original Equipment Manufacturer) suppliers (ex: HP, Dell, IBM or others).

You cannot use this type of CD to create a slipstreamed SP3 install.

For doing this you need to first extract the files from the CD and then integrate the SP3 files to the CD.

clip_image008

Once the process is completed you should get a confirmation that “Windows XP Service Pack 3 has now been

Slipstreamed into your original Windows XP files”.

clip_image010

Create Bootable CD

To create a bootable CD, first extract boot loader image from the original Windows XP CD. To do this explore Windows XP CD and goto “Bootable CD” folder. Copy Microsoft Corporation.img to the drive where you have downloaded the Windows XP files (E:\XP-CD).

From Start > Programs > Nero Burning Rom

From the dialog box select “CD-ROM (Boot)” in New Compilation window. On the boot tab select the “Image File” radio button and select browse to choose the image file, which in our case is “E:\XP-CD\Microsoft Corporation.img” file.

clip_image012

Next goto the “Label” tab and give a name to your Windows XP SP3 CD, such as WINXPSP_EN. Next press New and select the files and folders from the slipstreamed location.

Finally goto Burn tab to select the Read/Write speed of the CD.

clip_image014

Click on Burn, once ready you will have Slipstreamed Windows XP SP3 CD ready to use.

References:

http://www.helpwithwindows.com

http://www.google.com

http://www.wikipedia.com

What is Slipstreaming?

What is Slipstreaming?

Slipstreaming dates back to pre-release of Windows 2000 (Windows NT days), Microsoft decided to create a more refined way of integrating service packs or drivers and/or other fixes back into the core Operating System, so that the enterprise customers could always maintain an install of latest version of Windows on new machines.

Slipstreaming is usually done on network shares on corporate enterprise systems. But with the arrival of CD burners being so cheap, it does actually make some sense for the home user or small business user to do the same.

In Pre-Windows 2000 days, i.e. in Windows NT time, this process was a bit complicated in the sense that when users needed to install Windows they had to explicitly download Service Packs after installation of windows, and service pack installs often required users to reinstall components that had previously been installed. This process wasn’t that easy, but with the release of Windows 2000, which fixed it all. From then on Slipstreaming was more or less the same and there are now many software's released to make this process even simpler.

Slipstreaming Windows XP with Service Pack 3

To Slipstream a Service Pack (SP2 or SP3 into a Windows XP or Windows 2000 server),

1. Download the Service Pack 3 (WINDOWSXP-KB936929-sp3-x86-ENU.exe, 316.4 MB), and save it to a directory/folder on your local hard drive (for ex: E:\XP-SP3). For easier remembrance you can rename the downloaded SP3 file to XPsp3.exe.

NOTE: There should be no spaces in the folder naming.

2. Copy the contents of your Windows XP CD to your local hard drive, just create a folder (for ex: E:\XP-CD), and copy all the contents of your Windows XP CD [original version ;-)] in that folder, this might take some time, meanwhile proceed with the next steps.

Get XP SP3 and extract it

1. While that is copying, extract the Windows XP SP3, to do this you need to open a Command Prompt (Start > Run > cmd), and go to the folder where you downloaded SP3 (cd /d E:\XP-SP3).

a. Type the command:

XPsp3.exe -x:e:\XP-SP3

You will then get a pop-up dialog box stating that the files are being extracted.

clip_image002

Once the extraction is done click on OK. You will now be able to see the folder i386, in e:\XP-SP3 folder, which contains the extracted files.

Combine XP with SP3

1. Open a Command Prompt (Start > Run > cmd), and go to the folder where you downloaded SP3 (cd /d E:\XP-SP3).

a. Type the command:

servicepack filename /integrate:drive/path

In my example the command is

WINDOWSXP-KB936929-sp3-x86-ENU /integrate:E:\XP-CD

clip_image004

Once you hit enter you will get an error pop-up.

clip_image006

This happens by the fact that your Windows CD contains updates which cannot be automatically installed when you run the setup. This type of errors occurs when the CD’s are usually from OEM (Original Equipment Manufacturer) suppliers (ex: HP, Dell, IBM or others).

You cannot use this type of CD to create a slipstreamed SP3 install.

For doing this you need to first extract the files from the CD and then integrate the SP3 files to the CD.

clip_image008

Once the process is completed you should get a confirmation that “Windows XP Service Pack 3 has now been

Slipstreamed into your original Windows XP files”.

clip_image010

Create Bootable CD

To create a bootable CD, first extract boot loader image from the original Windows XP CD. To do this explore Windows XP CD and goto “Bootable CD” folder. Copy Microsoft Corporation.img to the drive where you have downloaded the Windows XP files (E:\XP-CD).

From Start > Programs > Nero Burning Rom

From the dialog box select “CD-ROM (Boot)” in New Compilation window. On the boot tab select the “Image File” radio button and select browse to choose the image file, which in our case is “E:\XP-CD\Microsoft Corporation.img” file.

clip_image012

Next goto the “Label” tab and give a name to your Windows XP SP3 CD, such as WINXPSP_EN. Next press New and select the files and folders from the slipstreamed location.

Finally goto Burn tab to select the Read/Write speed of the CD.

clip_image014

Click on Burn, once ready you will have Slipstreamed Windows XP SP3 CD ready to use.

References:

http://www.helpwithwindows.com

http://www.google.com

http://www.wikipedia.com

Text Widget

Copyright © Vinay's Blog | Powered by Blogger

Design by | Blogger Theme by