mercredi 31 octobre 2012

Activate God Mode in Windows 8

Many video games have a god mode. Windows 8 also has its own god mode! To activate it, create a new folder and add this:

.{ED7BA470-8E54-465E-825C-99712043E01C}

So you create the folder Params and then add .{ED7BA470-8E54-465E-825C-99712043E01C} So in this example the name of your folder will be ->

Params.{ED7BA470-8E54-465E-825C-99712043E01C}

Enjoy !

lundi 2 avril 2012

Add a driver to a wim image (offline and online)

Offline


2003 environment

1) Open a command prompt.

2) Go to the directory where you can use imagex utility.
cd "c:\Program files\Symantec\Ghost\PETools\x86\"
3) Mount your wim image in a directory you created for this purpose
imagex /mountrw "D:\Program Files\TFTPBOOT\boot\winpe.wim" 1 d:\IMG\mount
4) Add your driver
peimg.exe /inf=D:\IMG\drivers\VISTAX32\E1K6032.INF /image="d:\IMG\mount"
5) Unmount an commit the changes
imagex /unmount /commit D:\IMG\mount

2008 environment

In 2008, you can use DISM (Deployment Image Servicing and Management), and the best is that this tool is integrated with Windows 2008.

1) Open a command prompt.

2) If you have multiple editions in your wim image, get the index of edition to be modified
dism /get-wiminfo /Wimfile:C:\tmp\winpe.wim
3) Mount your wim image in a directory you created for this purpose
dism /Mount-Wim /WimFile:C:\tmp\winpe.wim /Index:1 /MountDir:C:\tmp\mount
4) List out drivers already present in this wim
dism /image:C:\tmp\mount /get-drivers
5) Add your third party driver (in my case it was an Intel 82579LM and 82579V Gigabit Ethernet Driver)
dism /image:C:\tmp\mount /add-driver /driver:C:\tmp\WIN7x32\E1C6232.inf
6) Unmount and commit your image
dism /unmount-Wim  /MountDir:C:\tmp\mount /commit

----------------------

Online

In my case, I had to add a NIC driver to boot in PXE/TFTP mode and make an image of a laptop with GostCast Server.

When I boot on LAN, in Ghost32, I do not have network. So I dynamically loaded the drivers provided by HP with the tool drvload that I have added to my wim image.

I downloaded the drivers, saved on a USB drive and loaded the key into the laptop. Then I loaded the drivers for vista, and it does not works. I finally used drivers for Seven and when I try ipconfig /renew, the laptop get an IP. Then I add this driver to my wim image with dism.

In your winpe environment, type

drvload.exe inf_path

jeudi 29 mars 2012

Centreon Could not find DEFINITIONS :: = BEGIN statement in MIB file!


To recover the traps sent by my SAN MSA2012FC (http://bizsupport1.austin.hp.com/bc/docs/support/SupportManual/c01565941/c01565941.pdf), I tried to add a MIB (found here : http://www.emc.com/microsites/fibrealliance/index.htm) in Centreon.


Here is the error I encountered:


Could not find DEFINITIONS :: = BEGIN statement in MIB file!


After catching a headache I found the solution... 


beginning of the file


FCMGMT-MIB
-
Last edit date: November 10th, 1999
DEFINITIONS :: = BEGIN
   IMPORTS     IpAddress, TimeTicks, experimental         FROM RFC1155-SMI     OBJECT-TYPE         FROM RFC-1212     DisplayString         FROM RFC1213-MIB     TRAP-TYPE         FROM RFC-1215;


--> replaced by


FCMGMT-MIB DEFINITIONS :: = BEGIN   IMPORTS     IpAddress, TimeTicks, experimental         FROM RFC1155-SMI     OBJECT-TYPE         FROM RFC-1212     DisplayString         FROM RFC1213-MIB     TRAP-TYPE         FROM RFC-1215;


and it works ^^'

mercredi 28 mars 2012

How to analyze memory dump after windows crash (Blue Screen of Death)

1) Download and install the Microsoft Debugging Tools : http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx

2) Start > All programs > Debugging Tools for Windows (x86) > WinDbg > File > Symbol File Path
Then paste this line into Symbol path : SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

3) File > Open Crash Dump > Select your crash dump (usually under %systemroot%/minidump)
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [G:\tmp\Mini032911-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp3_gdr.100216-1514
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x80554040
Debug session time: Tue Mar 29 11:42:28.210 2011 (UTC + 2:00)
System Uptime: 4 days 2:09:35.447
Loading Kernel Symbols
...............................................................
..............................................................
Loading User Symbols
Loading unloaded module list
.........................................
Unable to load image ATMFD.DLL, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ATMFD.DLL
*** ERROR: Module load completed but symbols could not be loaded for ATMFD.DLL
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 10000050, {e20937b4, 0, bf83cc83, 1}


Could not read faulting driver name
Probably caused by : ATMFD.DLL ( ATMFD+125e9 )

Followup: MachineOwner
---------

You can obtain the detailed debugging information by enter in the prompt KD> the command !analyze -v

kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: e20937b4, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: bf83cc83, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000001, (reserved)

Debugging Details:
------------------


Could not read faulting driver name

READ_ADDRESS: e20937b4

FAULTING_IP:
win32k!EngUnmapFontFileFD+1c
bf83cc83 8b482c mov ecx,dword ptr [eax+2Ch]

MM_INTERNAL_CODE: 1

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: csrss.exe

LAST_CONTROL_TRANSFER: from bffb25e9 to bf83cc83

STACK_TEXT:
b9144b6c bffb25e9 e2093788 e2093788 00006eb0 win32k!EngUnmapFontFileFD+0x1c
WARNING: Stack unwind information not available. Following frames may be wrong.
b9144ba0 bffafaba 00000000 000004a8 00000001 ATMFD+0x125e9
b9144c00 bffa5ab1 00000001 bf977f53 00000000 ATMFD+0xfaba
b9144c34 bffa2fab 00000001 bf977f53 b9144cf4 ATMFD+0x5ab1
b9144c64 bf8d1267 e3f33968 00000002 00000000 ATMFD+0x2fab
b9144c7c bf8e0428 e3f33968 b9144ca8 bf8e0491 win32k!PDEVOBJ::UnloadFontFile+0x2a
b9144c88 bf8e0491 e26d5008 e103f550 e26d5008 win32k!vCleanupFontFile+0x23
b9144ca8 bf9657f8 b9144cec 00000001 00000000 win32k!PUBLIC_PFTOBJ::bLoadAFont+0x24c
b9144ce4 bf9420a4 00000000 89ec8990 e26d6e58 win32k!PFTOBJ::bUnloadAllButPermanentFonts+0x1c8
b9144cf8 bf93261f 805b0b36 80527852 023b1f48 win32k!GreRemoveAllButPermanentFonts+0x29
b9144d10 bf861ff8 89d31558 00000000 bf861fa2 win32k!EndShutdown+0xe4
b9144d30 bf861fcc 89d31558 00000006 006afeb4 win32k!xxxSetInformationThread+0x17f
b9144d4c 8053d658 0000008c 00000006 006afeb4 win32k!NtUserSetInformationThread+0x31
b9144d4c 7c90e514 0000008c 00000006 006afeb4 nt!KiFastCallEntry+0xf8
006afeb8 00000000 00000000 00000000 00000000 0x7c90e514


STACK_COMMAND: kb

FOLLOWUP_IP:
ATMFD+125e9
bffb25e9 ?? ???

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: ATMFD+125e9

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: ATMFD

IMAGE_NAME: ATMFD.DLL

DEBUG_FLR_IMAGE_TIMESTAMP: 4802a0d3

FAILURE_BUCKET_ID: 0x50_ATMFD+125e9

BUCKET_ID: 0x50_ATMFD+125e9

Followup: MachineOwner
---------

The problem was a font problem

Netbeans - JVM creation failed

You tried to launch your Netbeans IDE and you encountered this error: 

JVM Creation Failed
In my case, under Windows XP x86, I modified this line (in configuration file C:\Program Files\NetBeans 7.0\ etc\netbeans.conf)


->netbeans_default_options="-J-client -J-Xss2m -J-Xms32m -J-XX:PermSize=32m -J-XX:MaxPermSize=384m -J-Dapple.laf.useScreenMenuBar=true -J-Dapple.awt.graphics.UseQuartz=true -J-Dsun.java2d.noddraw=true"

by this one

netbeans_default_options="-J-client -J-Xss2m -J-Xms32m -J-XX:PermSize=32m -J-Xmx256m -J-XX:MaxPermSize=128m -J-Dapple.laf.useScreenMenuBar=true -J-Dapple.awt.graphics.UseQuartz=true -J-Dsun.java2d.noddraw=true"

Same solution works for Netbeans 7.1.1

mardi 27 mars 2012

Powershell - Find a pattern in files (directory recursive)


$findPath="YOURPATH"
$patternToFind="YOURPATTERNTOFIND"
$patternFindInFiles=Dir $findPath -recurse|Select-String $patternToFind |Foreach {$_.path}
$patternFindInFiles|Out-File "found.txt"

jeudi 15 mars 2012

Strict replication consistency should be enabled on all domain controllers in this forest

You run a BPA on your "Active Directory Domain Services" role and you obtain this warning:

Strict replication consistency should be enabled on all domain controllers in this forest
Issue: Strict replication consistency is not enabled on the domain controller SERVERNAME
More information about this best practice and detailed resolution procedures: http://go.microsoft.com/fwlink/?LinkId=142189
(When a domain controller in your Active Directory environment is disconnected from the replication topology for an extended period of time, all objects that are deleted from AD DS on all other domain controllers might remain on the disconnected domain controller. Such objects are called lingering objects. When this domain controller is reconnected to the replication topology, it acts as a source replication partner that has one or more objects that its destination replication partners no longer have. Problems occur when these lingering objects on the source domain controller are updated and these updates are sent by replication to the destination domain controllers. A destination domain controller can respond in one of two ways:

    If the destination domain controller has strict replication consistency enabled, it recognizes that it cannot update the object (because the object does not exist), and it locally halts inbound replication of the directory partition from that source domain controller.

    If the destination domain controller does not have strict replication consistency enabled, it requests the full replica of the updated object, which introduces a lingering object into the directory.
)

What I do:

1) You have to remove lingering objects

/removelingeringobjects <Dest_DSA_LIST> <Source DSA GUID> <NC> [/ADVISORY_MODE]

Dest_DSA_LIST (you can enter the dns name of the server or the distinguished name)

DSA_GUID : To find this one, type :

                      repadmin /showrepl

                     And copy the DSA object GUID value
NC: It's your naming context (example: DC=CONTOSO,DC=COM)

The Advisory_mode logs lingering objects in Event ID 1388 or 1988 (http://technet.microsoft.com/en-us/library/cc780362%28v=ws.10%29.aspx)

2) Enable strict replication consistency

The syntax is : repadmin /regkey DC_LIST {+|-} key

--> I used "repadmin /regkey SERVENAME +strict"