SlideShare a Scribd company logo
Sami Laiho
BlackBelt Troubleshooting
Windows 8.1
WHOAMI /ALL (about.me/samilaiho)
•
•
•
•
•

MVP Windows Expert – IT Pro
SpringBoard Technical Expert Panel member
Senior Consultant @ Sovelto
Senior Technical Fellow @ adminize.com
Twitter: @samilaiho
Windows XP Deep Dive in 2001 by me
Projects
• www.wioski.com – Free replacement for
SteadyState
• www.adminize.com – Getting rid of admin rights
and provide onetime admin passwords
• www.getabrandnewpassword.com – Free and
safe password cracker… I mean changer
• idealinfra.blogspot.com – My blog
You get gpedit.msc and we get…
Housekeeping
• I will give away one free course attendance
as promised so leave your business card to
participate  Winner will be notified
afterwards so be sure your card has your
email address
• After the session I will stick around for
questions and to give away a few T-shirts
Agenda
•
•
•
•
•
•
•
•

Baselines and tools for troubleshooting
Error messages
User accounts in troubleshooting
Prelogon diagnostics
Services
Processes and threads
Safemode etc. in Windows 8.1
BSOD in Windows 8.1
BASELINES
Baselines
• I always teach people that the logic in
troubleshooting Windows is that there is no logic
•
•
•
•
•

System vs. Boot partition
System32 vs SysWOW64
bowser vs browser
AFD
Hive
Tools
• You always need at least:

• Sysinternals Tools
• Sysinternals Suite or http://live.sysinternals.com/
• Debugging Tools
• Not so much for debugging but for supporting Sysinternals
Tools
• Message analyzer
• Windows 7/8 can capture traces without it with NETSH TRACE
• Windows 8.1 is the fisrt to support remote network monitoring
ERROR DESCRIPTIONS
Error descriptions
• To be able to troubleshoot you need good
error descriptions especially in Windows 8.1
Error description example
• ”My computer just broke” vs…
Tools for capturing errors
•
•
•
•
•

Net helpmsg & winrm helpmsg
Copy/Paste dialogs
Snipping tool
Windows + Print Screen
PSR
Sami Laiho

DEMO – ERROR DESCRIPTIONS
IN WINDOWS 8.1
USER ACCOUNTS IN
TROUBLESHOOTING
SYSTEM vs Admin
• SYSTEM
• Has more user privileges than Administrator (even
the Built in one)
• Doesn’t need to worry about policies
• Can see stuff Admin can’t
• Can stop processes Admin can’t
• Has a higher integrity level than Administrator
Mandatory Integrity Control
Mandatory Integrity Control to blaim?
• In Windows Vista+ if you don’t have access to
a file and you are sure you should:
• 1. TAKEOWN.exe
• 2. iCacls /SetIntegrityLevel
Running as SYSTEM #1
Running as SYSTEM #2
PSEXEC –SID cmd.exe
Sami Laiho

DEMO – USING THE SYSTEMACCOUNT
PRELOGON DIAGNOSTICS
Basic info on logon?
• Event logs are a good start but to do
BlackBelt troubleshooting you need:
• SYSTEM-account to diagnose what happens
before logon
• Session 0 to diagnose what happens during
logon
Building from the ground up - Prelogon
• What happens before logon
and how to diagnose it
• Slow logons, Startup script
problems, inability to
logon…

• Windows has three
accounts that never log off
• SYSTEM, Local Service and
Network Service
Sami Laiho

DEMO – PRELOGON
DIAGNOSTICS
More info on logon?
• If you need more
info on your logon
don’t forget
Autoruns from
Sysinternals
More info on logon?
• If you need to dig even deeper use Windows
Performance Toolkit
BACKGROUND SERVICES
Background services
• Services not starting/running in Windows 8.1
• Basics: It’s a security issue or something else
• Security
• Security log, Secpol.msc, Process Explorer, Process
Monitor

• Something else
• Process Monitor
Process Monitor example
What a service can or cannot do
• You have to become a Service
• When you start referring to services as He or
She you’re getting the point
Service accounts and user rights
• He/She can use three built in accounts
Service accounts have SIDs
• In Windows 8.1 they have a SID as well
• They become Security Principals
Service accounts have SIDs
Sami Laiho

DEMO – SERVICE PRIVILEGES
PROCESSES AND THREADS
Processes and threads
• In Windows a process can’t really do anything
• Task Manager only shows processes…

• Threads can actually do something
• Search engines probably know the answer to your question
so the real problem with them is noise
• How to get rid of noise?

• Make your searches are more accurate
• Make sure you get results from people who have at least a clue on
what they’re doing
• Learn to diagnose threads instead of processes
Case – Hanged virtual machine
• VM totally stuck…
• Task manager looks like this
Case – Hanged virtual machine
• Task Manager
shows that
SYSTEM is causing
the problem…
Case – Hanged virtual machine
• Process Explorer shows Threads!
Case – Hanged virtual machine
• Removed the virtual floppy
because it was pointing to
a nonexisting file 
Sami Laiho

DEMO – PROCESSES VS
THREADS
SAFEMODE ETC.
How to access boot options in
Windows 8.1
• Shift-Restart or

Same if you want
to goto your
UEFI!
Why is a PC working in Safemode?
• Safemode is configured in the registry
Semi-SafeMode – MSCONFIG &
AUTORUNS
Sami Laiho

DEMO – USING AND MANIPULATING
SAFE MODE
WINDOWS 8.1 BSOD
Changes in BSOD in Windows 8
HKEY_LOCAL_MACHINESystemCurrentControlSet
ControlCrashControl
None
0x0
Complete memory dump 0x1
Kernel memory dump
Small memory dump
Automatic memory
dump

0x2
0x3
0x7
Make sure you are able to crash when
needed!
• http://support.microsoft.com/kb/244139
Basics of BSOD analysis
• Install Debugging tools
• Set the systemwide variable _NT_SYMBOL_PATH
to
SRV*C:symbols*http://msdl.microsoft.com/dow
nload/symbols
• http://support.microsoft.com/kb/311503

• Use WINDBGOpen Crash Dump or DaRT’s
Memory Dump Analyzer
Please evaluate the session
before you leave


Enroll to my free newsletter at:
http://eepurl.com/F-GOj
T-Shirts? Be quick! Remember
business cards!!

More Related Content

Viewers also liked

Evaluation question 4
Evaluation question 4Evaluation question 4
Evaluation question 4Lucyrutter21
 
Evaluation question 4
Evaluation question 4Evaluation question 4
Evaluation question 4Lucyrutter21
 
666.Three BHK Flat For Rent in Prahlad Nagar Extension
666.Three BHK Flat For Rent in Prahlad Nagar Extension666.Three BHK Flat For Rent in Prahlad Nagar Extension
666.Three BHK Flat For Rent in Prahlad Nagar Extension
AAD Realty
 
Madhav trading company
Madhav trading companyMadhav trading company
Madhav trading company
ASHISH KALRA
 
Ie app slides mestres #g
Ie app   slides mestres #gIe app   slides mestres #g
Ie app slides mestres #g
yughoyoshida
 
Wally Mead - Upgrading to system center 2012 r2 configuration manager
Wally Mead - Upgrading to system center 2012 r2 configuration managerWally Mead - Upgrading to system center 2012 r2 configuration manager
Wally Mead - Upgrading to system center 2012 r2 configuration managerNordic Infrastructure Conference
 
Casa
CasaCasa
Casa
fuampablo
 
Roman, britanian roman, peninggalan bangsa roman
Roman, britanian roman, peninggalan bangsa romanRoman, britanian roman, peninggalan bangsa roman
Roman, britanian roman, peninggalan bangsa roman
Apep Wahyudin
 
Props list and schedule
Props list and scheduleProps list and schedule
Props list and schedule
Lucyrutter21
 
Madhav Trading Company
Madhav Trading CompanyMadhav Trading Company
Madhav Trading Company
ASHISH KALRA
 
Question 3
Question 3 Question 3
Question 3
Lucyrutter21
 
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...Nordic Infrastructure Conference
 
Summary of feedback questionnaire results
Summary of feedback questionnaire resultsSummary of feedback questionnaire results
Summary of feedback questionnaire resultsLucyrutter21
 
Forgetters
ForgettersForgetters
Forgetters
Gary V Carter
 
Something for Everyone
Something for EveryoneSomething for Everyone
Something for EveryoneGary V Carter
 
599. Three BHK Flat for Rent in Satellite
599. Three BHK Flat  for Rent in Satellite599. Three BHK Flat  for Rent in Satellite
599. Three BHK Flat for Rent in Satellite
AAD Realty
 
Jan Egil Ring - Get started with windows power shell desired state configuration
Jan Egil Ring - Get started with windows power shell desired state configurationJan Egil Ring - Get started with windows power shell desired state configuration
Jan Egil Ring - Get started with windows power shell desired state configurationNordic Infrastructure Conference
 

Viewers also liked (20)

Evaluation question 4
Evaluation question 4Evaluation question 4
Evaluation question 4
 
Evaluation question 4
Evaluation question 4Evaluation question 4
Evaluation question 4
 
666.Three BHK Flat For Rent in Prahlad Nagar Extension
666.Three BHK Flat For Rent in Prahlad Nagar Extension666.Three BHK Flat For Rent in Prahlad Nagar Extension
666.Three BHK Flat For Rent in Prahlad Nagar Extension
 
Madhav trading company
Madhav trading companyMadhav trading company
Madhav trading company
 
Ie app slides mestres #g
Ie app   slides mestres #gIe app   slides mestres #g
Ie app slides mestres #g
 
Wally Mead - Upgrading to system center 2012 r2 configuration manager
Wally Mead - Upgrading to system center 2012 r2 configuration managerWally Mead - Upgrading to system center 2012 r2 configuration manager
Wally Mead - Upgrading to system center 2012 r2 configuration manager
 
Casa
CasaCasa
Casa
 
Roman, britanian roman, peninggalan bangsa roman
Roman, britanian roman, peninggalan bangsa romanRoman, britanian roman, peninggalan bangsa roman
Roman, britanian roman, peninggalan bangsa roman
 
Props list and schedule
Props list and scheduleProps list and schedule
Props list and schedule
 
Madhav Trading Company
Madhav Trading CompanyMadhav Trading Company
Madhav Trading Company
 
Daemonprocess
DaemonprocessDaemonprocess
Daemonprocess
 
Question 3
Question 3 Question 3
Question 3
 
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...
Kent Agerlund - Via monstra part 4 become the hero of the day, master configm...
 
Summary of feedback questionnaire results
Summary of feedback questionnaire resultsSummary of feedback questionnaire results
Summary of feedback questionnaire results
 
The centimeter
The centimeterThe centimeter
The centimeter
 
The Seven Loves
The Seven LovesThe Seven Loves
The Seven Loves
 
Forgetters
ForgettersForgetters
Forgetters
 
Something for Everyone
Something for EveryoneSomething for Everyone
Something for Everyone
 
599. Three BHK Flat for Rent in Satellite
599. Three BHK Flat  for Rent in Satellite599. Three BHK Flat  for Rent in Satellite
599. Three BHK Flat for Rent in Satellite
 
Jan Egil Ring - Get started with windows power shell desired state configuration
Jan Egil Ring - Get started with windows power shell desired state configurationJan Egil Ring - Get started with windows power shell desired state configuration
Jan Egil Ring - Get started with windows power shell desired state configuration
 

Similar to Sami Laiho - Black belt troubleshooting windows 8.1

In (database) automation we trust
In (database) automation we trustIn (database) automation we trust
In (database) automation we trust
DBmaestro - Database DevOps
 
GR Dev Day Presentation, March 21 2015
GR Dev Day Presentation, March 21 2015GR Dev Day Presentation, March 21 2015
GR Dev Day Presentation, March 21 2015
Tore Franzen
 
Ask a Malware Archaeologist
Ask a Malware ArchaeologistAsk a Malware Archaeologist
Ask a Malware Archaeologist
Michael Gough
 
Hacking Virtual Appliances
Hacking Virtual AppliancesHacking Virtual Appliances
Hacking Virtual Appliances
Jeremy Brown
 
Getting Started with IBM i Security: Securing PC Access
Getting Started with IBM i Security: Securing PC AccessGetting Started with IBM i Security: Securing PC Access
Getting Started with IBM i Security: Securing PC Access
HelpSystems
 
Windows logging workshop - BSides Austin 2014
Windows logging workshop - BSides Austin 2014Windows logging workshop - BSides Austin 2014
Windows logging workshop - BSides Austin 2014
Michael Gough
 
Detecting WMI Exploitation v1.1
Detecting WMI Exploitation v1.1Detecting WMI Exploitation v1.1
Detecting WMI Exploitation v1.1
Michael Gough
 
DBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
DBmaestro's State of the Database Continuous Delivery Survey- Findings RevealedDBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
DBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
DBmaestro - Database DevOps
 
Introduction to operating system, system calls and interrupts
Introduction to operating system, system calls and interruptsIntroduction to operating system, system calls and interrupts
Introduction to operating system, system calls and interrupts
Shivam Mitra
 
AGILE DEVELOPMENT
AGILE DEVELOPMENTAGILE DEVELOPMENT
AGILE DEVELOPMENTwe20
 
Automated testing in javascript
Automated testing in javascriptAutomated testing in javascript
Automated testing in javascript
Michael Yagudaev
 
Functionality, security and performance monitoring of web assets (e.g. Joomla...
Functionality, security and performance monitoring of web assets (e.g. Joomla...Functionality, security and performance monitoring of web assets (e.g. Joomla...
Functionality, security and performance monitoring of web assets (e.g. Joomla...
Sanjay Willie
 
Mwlug2014 - IBM Connections Security and Migration
Mwlug2014 - IBM Connections Security and MigrationMwlug2014 - IBM Connections Security and Migration
Mwlug2014 - IBM Connections Security and Migration
Victor Toal
 
PowerShell - Be A Cool Blue Kid
PowerShell - Be A Cool Blue KidPowerShell - Be A Cool Blue Kid
PowerShell - Be A Cool Blue Kid
Matthew Johnson
 
Webinar: "In database automation we trust"
Webinar: "In database automation we trust"Webinar: "In database automation we trust"
Webinar: "In database automation we trust"
Emerasoft, solutions to collaborate
 
When Security Tools Fail You
When Security Tools Fail YouWhen Security Tools Fail You
When Security Tools Fail You
Michael Gough
 
Six Mistakes of Log Management 2008
Six Mistakes of Log Management 2008Six Mistakes of Log Management 2008
Six Mistakes of Log Management 2008
Anton Chuvakin
 
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...Andriy Krayniy
 
Application Logging Good Bad Ugly ... Beautiful?
Application Logging Good Bad Ugly ... Beautiful?Application Logging Good Bad Ugly ... Beautiful?
Application Logging Good Bad Ugly ... Beautiful?
Anton Chuvakin
 

Similar to Sami Laiho - Black belt troubleshooting windows 8.1 (20)

In (database) automation we trust
In (database) automation we trustIn (database) automation we trust
In (database) automation we trust
 
GR Dev Day Presentation, March 21 2015
GR Dev Day Presentation, March 21 2015GR Dev Day Presentation, March 21 2015
GR Dev Day Presentation, March 21 2015
 
Ask a Malware Archaeologist
Ask a Malware ArchaeologistAsk a Malware Archaeologist
Ask a Malware Archaeologist
 
Hacking Virtual Appliances
Hacking Virtual AppliancesHacking Virtual Appliances
Hacking Virtual Appliances
 
Sami laiho - What's new in windows 8.1
Sami laiho - What's new in windows 8.1Sami laiho - What's new in windows 8.1
Sami laiho - What's new in windows 8.1
 
Getting Started with IBM i Security: Securing PC Access
Getting Started with IBM i Security: Securing PC AccessGetting Started with IBM i Security: Securing PC Access
Getting Started with IBM i Security: Securing PC Access
 
Windows logging workshop - BSides Austin 2014
Windows logging workshop - BSides Austin 2014Windows logging workshop - BSides Austin 2014
Windows logging workshop - BSides Austin 2014
 
Detecting WMI Exploitation v1.1
Detecting WMI Exploitation v1.1Detecting WMI Exploitation v1.1
Detecting WMI Exploitation v1.1
 
DBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
DBmaestro's State of the Database Continuous Delivery Survey- Findings RevealedDBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
DBmaestro's State of the Database Continuous Delivery Survey- Findings Revealed
 
Introduction to operating system, system calls and interrupts
Introduction to operating system, system calls and interruptsIntroduction to operating system, system calls and interrupts
Introduction to operating system, system calls and interrupts
 
AGILE DEVELOPMENT
AGILE DEVELOPMENTAGILE DEVELOPMENT
AGILE DEVELOPMENT
 
Automated testing in javascript
Automated testing in javascriptAutomated testing in javascript
Automated testing in javascript
 
Functionality, security and performance monitoring of web assets (e.g. Joomla...
Functionality, security and performance monitoring of web assets (e.g. Joomla...Functionality, security and performance monitoring of web assets (e.g. Joomla...
Functionality, security and performance monitoring of web assets (e.g. Joomla...
 
Mwlug2014 - IBM Connections Security and Migration
Mwlug2014 - IBM Connections Security and MigrationMwlug2014 - IBM Connections Security and Migration
Mwlug2014 - IBM Connections Security and Migration
 
PowerShell - Be A Cool Blue Kid
PowerShell - Be A Cool Blue KidPowerShell - Be A Cool Blue Kid
PowerShell - Be A Cool Blue Kid
 
Webinar: "In database automation we trust"
Webinar: "In database automation we trust"Webinar: "In database automation we trust"
Webinar: "In database automation we trust"
 
When Security Tools Fail You
When Security Tools Fail YouWhen Security Tools Fail You
When Security Tools Fail You
 
Six Mistakes of Log Management 2008
Six Mistakes of Log Management 2008Six Mistakes of Log Management 2008
Six Mistakes of Log Management 2008
 
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...
Alexey Ostapov: Distributed Video Management and Security Systems: Tips and T...
 
Application Logging Good Bad Ugly ... Beautiful?
Application Logging Good Bad Ugly ... Beautiful?Application Logging Good Bad Ugly ... Beautiful?
Application Logging Good Bad Ugly ... Beautiful?
 

More from Nordic Infrastructure Conference

Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...
Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...
Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...Nordic Infrastructure Conference
 
Andy Malone - Keynote: the cloud one small step for man one giant leap for it
Andy Malone - Keynote: the cloud one small step for man one giant leap for itAndy Malone - Keynote: the cloud one small step for man one giant leap for it
Andy Malone - Keynote: the cloud one small step for man one giant leap for itNordic Infrastructure Conference
 
Wally Mead - Overview of system center 2012 r2 configuration manager
Wally Mead - Overview of system center 2012 r2 configuration managerWally Mead - Overview of system center 2012 r2 configuration manager
Wally Mead - Overview of system center 2012 r2 configuration managerNordic Infrastructure Conference
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Nordic Infrastructure Conference
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Nordic Infrastructure Conference
 
Ståle Hansen - Understand how lync integrates with exchange
Ståle Hansen - Understand how lync integrates with exchangeStåle Hansen - Understand how lync integrates with exchange
Ståle Hansen - Understand how lync integrates with exchangeNordic Infrastructure Conference
 
Scott Schnoll - Exchange server 2013 virtualization best practices
Scott Schnoll - Exchange server 2013 virtualization best practicesScott Schnoll - Exchange server 2013 virtualization best practices
Scott Schnoll - Exchange server 2013 virtualization best practicesNordic Infrastructure Conference
 
Scott Schnoll - Exchange server 2013 high availability and site resilience
Scott Schnoll - Exchange server 2013 high availability and site resilienceScott Schnoll - Exchange server 2013 high availability and site resilience
Scott Schnoll - Exchange server 2013 high availability and site resilienceNordic Infrastructure Conference
 
Ståle Hansen - Understand how video works in lync and how video interoperabil...
Ståle Hansen - Understand how video works in lync and how video interoperabil...Ståle Hansen - Understand how video works in lync and how video interoperabil...
Ståle Hansen - Understand how video works in lync and how video interoperabil...Nordic Infrastructure Conference
 
Robert Waldinger - How to recover active directory if disaster should occur
Robert Waldinger - How to recover active directory if disaster should occurRobert Waldinger - How to recover active directory if disaster should occur
Robert Waldinger - How to recover active directory if disaster should occurNordic Infrastructure Conference
 
Peter De Tender - The roadmap to deploying office365 pro plus
Peter De Tender - The roadmap to deploying office365 pro plusPeter De Tender - The roadmap to deploying office365 pro plus
Peter De Tender - The roadmap to deploying office365 pro plusNordic Infrastructure Conference
 
Kåre Rude Andersen - Be a hero – optimize scom and present your services
Kåre Rude Andersen - Be a hero – optimize scom and present your servicesKåre Rude Andersen - Be a hero – optimize scom and present your services
Kåre Rude Andersen - Be a hero – optimize scom and present your servicesNordic Infrastructure Conference
 

More from Nordic Infrastructure Conference (20)

Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...
Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...
Raymond Comvalius & Sander Berkouwer - Bring your own device essentials with ...
 
Mike Resseler - Using hyper-v replica in your environment
Mike Resseler - Using hyper-v replica in your environmentMike Resseler - Using hyper-v replica in your environment
Mike Resseler - Using hyper-v replica in your environment
 
Mike Resseler - Deduplication in windows server 2012 r2
Mike Resseler - Deduplication in windows server 2012 r2Mike Resseler - Deduplication in windows server 2012 r2
Mike Resseler - Deduplication in windows server 2012 r2
 
Andy Malone - The new office 365 for it pro's
Andy Malone - The new office 365 for it pro'sAndy Malone - The new office 365 for it pro's
Andy Malone - The new office 365 for it pro's
 
Andy Malone - Migrating to office 365
Andy Malone - Migrating to office 365Andy Malone - Migrating to office 365
Andy Malone - Migrating to office 365
 
Andy Malone - Microsoft office 365 security deep dive
Andy Malone - Microsoft office 365 security deep diveAndy Malone - Microsoft office 365 security deep dive
Andy Malone - Microsoft office 365 security deep dive
 
Andy Malone - Keynote: the cloud one small step for man one giant leap for it
Andy Malone - Keynote: the cloud one small step for man one giant leap for itAndy Malone - Keynote: the cloud one small step for man one giant leap for it
Andy Malone - Keynote: the cloud one small step for man one giant leap for it
 
Wally Mead - Overview of system center 2012 r2 configuration manager
Wally Mead - Overview of system center 2012 r2 configuration managerWally Mead - Overview of system center 2012 r2 configuration manager
Wally Mead - Overview of system center 2012 r2 configuration manager
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
 
Travis Wright - PS WF SMA SCSM SP
Travis Wright - PS WF SMA SCSM SPTravis Wright - PS WF SMA SCSM SP
Travis Wright - PS WF SMA SCSM SP
 
Travis Wright - Complete it service management
Travis Wright - Complete it service managementTravis Wright - Complete it service management
Travis Wright - Complete it service management
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
 
Ståle Hansen - Understand how lync integrates with exchange
Ståle Hansen - Understand how lync integrates with exchangeStåle Hansen - Understand how lync integrates with exchange
Ståle Hansen - Understand how lync integrates with exchange
 
Scott Schnoll - Exchange server 2013 virtualization best practices
Scott Schnoll - Exchange server 2013 virtualization best practicesScott Schnoll - Exchange server 2013 virtualization best practices
Scott Schnoll - Exchange server 2013 virtualization best practices
 
Scott Schnoll - Exchange server 2013 high availability and site resilience
Scott Schnoll - Exchange server 2013 high availability and site resilienceScott Schnoll - Exchange server 2013 high availability and site resilience
Scott Schnoll - Exchange server 2013 high availability and site resilience
 
Ståle Hansen - Understand how video works in lync and how video interoperabil...
Ståle Hansen - Understand how video works in lync and how video interoperabil...Ståle Hansen - Understand how video works in lync and how video interoperabil...
Ståle Hansen - Understand how video works in lync and how video interoperabil...
 
Robert Waldinger - How to recover active directory if disaster should occur
Robert Waldinger - How to recover active directory if disaster should occurRobert Waldinger - How to recover active directory if disaster should occur
Robert Waldinger - How to recover active directory if disaster should occur
 
Peter De Tender - The roadmap to deploying office365 pro plus
Peter De Tender - The roadmap to deploying office365 pro plusPeter De Tender - The roadmap to deploying office365 pro plus
Peter De Tender - The roadmap to deploying office365 pro plus
 
Peter De Tender - How to efficiently license office 365
Peter De Tender - How to efficiently license office 365Peter De Tender - How to efficiently license office 365
Peter De Tender - How to efficiently license office 365
 
Kåre Rude Andersen - Be a hero – optimize scom and present your services
Kåre Rude Andersen - Be a hero – optimize scom and present your servicesKåre Rude Andersen - Be a hero – optimize scom and present your services
Kåre Rude Andersen - Be a hero – optimize scom and present your services
 

Recently uploaded

Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Tobias Schneck
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
CatarinaPereira64715
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 

Recently uploaded (20)

Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 

Sami Laiho - Black belt troubleshooting windows 8.1

  • 2. WHOAMI /ALL (about.me/samilaiho) • • • • • MVP Windows Expert – IT Pro SpringBoard Technical Expert Panel member Senior Consultant @ Sovelto Senior Technical Fellow @ adminize.com Twitter: @samilaiho
  • 3. Windows XP Deep Dive in 2001 by me
  • 4. Projects • www.wioski.com – Free replacement for SteadyState • www.adminize.com – Getting rid of admin rights and provide onetime admin passwords • www.getabrandnewpassword.com – Free and safe password cracker… I mean changer • idealinfra.blogspot.com – My blog
  • 5. You get gpedit.msc and we get…
  • 6. Housekeeping • I will give away one free course attendance as promised so leave your business card to participate  Winner will be notified afterwards so be sure your card has your email address • After the session I will stick around for questions and to give away a few T-shirts
  • 7. Agenda • • • • • • • • Baselines and tools for troubleshooting Error messages User accounts in troubleshooting Prelogon diagnostics Services Processes and threads Safemode etc. in Windows 8.1 BSOD in Windows 8.1
  • 9. Baselines • I always teach people that the logic in troubleshooting Windows is that there is no logic • • • • • System vs. Boot partition System32 vs SysWOW64 bowser vs browser AFD Hive
  • 10. Tools • You always need at least: • Sysinternals Tools • Sysinternals Suite or http://live.sysinternals.com/ • Debugging Tools • Not so much for debugging but for supporting Sysinternals Tools • Message analyzer • Windows 7/8 can capture traces without it with NETSH TRACE • Windows 8.1 is the fisrt to support remote network monitoring
  • 12. Error descriptions • To be able to troubleshoot you need good error descriptions especially in Windows 8.1
  • 13. Error description example • ”My computer just broke” vs…
  • 14.
  • 15. Tools for capturing errors • • • • • Net helpmsg & winrm helpmsg Copy/Paste dialogs Snipping tool Windows + Print Screen PSR
  • 16. Sami Laiho DEMO – ERROR DESCRIPTIONS IN WINDOWS 8.1
  • 18. SYSTEM vs Admin • SYSTEM • Has more user privileges than Administrator (even the Built in one) • Doesn’t need to worry about policies • Can see stuff Admin can’t • Can stop processes Admin can’t • Has a higher integrity level than Administrator
  • 20. Mandatory Integrity Control to blaim? • In Windows Vista+ if you don’t have access to a file and you are sure you should: • 1. TAKEOWN.exe • 2. iCacls /SetIntegrityLevel
  • 22. Running as SYSTEM #2 PSEXEC –SID cmd.exe
  • 23. Sami Laiho DEMO – USING THE SYSTEMACCOUNT
  • 25. Basic info on logon? • Event logs are a good start but to do BlackBelt troubleshooting you need: • SYSTEM-account to diagnose what happens before logon • Session 0 to diagnose what happens during logon
  • 26. Building from the ground up - Prelogon • What happens before logon and how to diagnose it • Slow logons, Startup script problems, inability to logon… • Windows has three accounts that never log off • SYSTEM, Local Service and Network Service
  • 27. Sami Laiho DEMO – PRELOGON DIAGNOSTICS
  • 28. More info on logon? • If you need more info on your logon don’t forget Autoruns from Sysinternals
  • 29. More info on logon? • If you need to dig even deeper use Windows Performance Toolkit
  • 30.
  • 32. Background services • Services not starting/running in Windows 8.1 • Basics: It’s a security issue or something else • Security • Security log, Secpol.msc, Process Explorer, Process Monitor • Something else • Process Monitor
  • 34. What a service can or cannot do • You have to become a Service • When you start referring to services as He or She you’re getting the point
  • 35. Service accounts and user rights • He/She can use three built in accounts
  • 36. Service accounts have SIDs • In Windows 8.1 they have a SID as well • They become Security Principals
  • 38. Sami Laiho DEMO – SERVICE PRIVILEGES
  • 40. Processes and threads • In Windows a process can’t really do anything • Task Manager only shows processes… • Threads can actually do something • Search engines probably know the answer to your question so the real problem with them is noise • How to get rid of noise? • Make your searches are more accurate • Make sure you get results from people who have at least a clue on what they’re doing • Learn to diagnose threads instead of processes
  • 41. Case – Hanged virtual machine • VM totally stuck… • Task manager looks like this
  • 42. Case – Hanged virtual machine • Task Manager shows that SYSTEM is causing the problem…
  • 43. Case – Hanged virtual machine • Process Explorer shows Threads!
  • 44. Case – Hanged virtual machine • Removed the virtual floppy because it was pointing to a nonexisting file 
  • 45. Sami Laiho DEMO – PROCESSES VS THREADS
  • 47. How to access boot options in Windows 8.1 • Shift-Restart or Same if you want to goto your UEFI!
  • 48. Why is a PC working in Safemode? • Safemode is configured in the registry
  • 50. Sami Laiho DEMO – USING AND MANIPULATING SAFE MODE
  • 52. Changes in BSOD in Windows 8 HKEY_LOCAL_MACHINESystemCurrentControlSet ControlCrashControl None 0x0 Complete memory dump 0x1 Kernel memory dump Small memory dump Automatic memory dump 0x2 0x3 0x7
  • 53. Make sure you are able to crash when needed! • http://support.microsoft.com/kb/244139
  • 54.
  • 55. Basics of BSOD analysis • Install Debugging tools • Set the systemwide variable _NT_SYMBOL_PATH to SRV*C:symbols*http://msdl.microsoft.com/dow nload/symbols • http://support.microsoft.com/kb/311503 • Use WINDBGOpen Crash Dump or DaRT’s Memory Dump Analyzer
  • 56. Please evaluate the session before you leave  Enroll to my free newsletter at: http://eepurl.com/F-GOj T-Shirts? Be quick! Remember business cards!!