<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>'Cos the world needs one more...</title><link>http://blogs.technet.com/maweeras/default.aspx</link><description /><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>I wrote a KB!</title><link>http://blogs.technet.com/maweeras/archive/2009/11/01/i-wrote-a-kb.aspx</link><pubDate>Sun, 01 Nov 2009 13:26:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3290621</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3290621.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3290621</wfw:commentRss><description>&lt;p&gt;Well….half a KB to be precise :) But I still feel good that I contributed to an official support article in some minute way. Incidentally I wrote the ldp.exe based details in KB 2001769.&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3290621" width="1" height="1"&gt;</description></item><item><title>Lessons learned on CritSit or The importance of updating drivers</title><link>http://blogs.technet.com/maweeras/archive/2009/10/17/lessons-learned-on-critsit-or-the-importance-of-updating-drivers.aspx</link><pubDate>Sat, 17 Oct 2009 19:59:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3287479</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3287479.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3287479</wfw:commentRss><description>&lt;p&gt;As a premier field engineer I have a responsibility to do several on call shifts a year. The week just gone was one such on call shift learned the importance of updating drivers&amp;#160; during it. Allow me to elaborate.&lt;/p&gt;  &lt;p&gt;I got a call around 2AM Wednesday about a customer that needed help recovering the business after accidentally deleting the OU that had all the user accounts in the organisation. I assumed it would be a simple case of performing an authoritative restore and accepted the case. After turning up onsite I learned that authoritative restores had already been performed but when they ran the LDIF file to recover group membership, the destination servers hung. Without running the LDIF file, they had managed to get all the users replicate out successfully. But the DCs geographically spread across the country had inconsistent group membership information.&lt;/p&gt;  &lt;p&gt;As the LDIF file could not be replicated out and as the customer was desperate for resolution, we resorted to rebuilding all the DCs using the source DC backup and performing IFM based promotions. This turned out to be the resolution mechanism while we attempted root cause analysis. A colleague of mine joined me onsite and we recreated the problem in an isolated lab network. Analysis of the memory dump revealed issues with the storage related drivers. Specifically HpCISSs2.sys.&lt;/p&gt;  &lt;p&gt;We then tested the DC (All HP DL360 G5) after updating the following.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Controller Firmware (1.82 as per KB969550)&lt;/li&gt;    &lt;li&gt;Disk Firmware (version HPDA for DH036ABAA5 although customer had DH036ABAA6 disks)&lt;/li&gt;    &lt;li&gt;Controller Drivers (as per KB969550 we installed 6.14.0.32 from a smartstart CD)&lt;/li&gt;    &lt;li&gt;Storport.sys (KB957910 )&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;We could no longer reproduce the issue and a fix was now available. Yay! Customer decided to keep the DCs that were recovered using IFM online and to turn off the remainder and perform metadata and DNS cleanup. They are now planning to rebuild the remainder later after completely rebuilding them using latest HP SmartStart CD and Windows Server 2003 R2 SP2 CDs. Online DCs are to be also gradually updated with updates shown above.&lt;/p&gt;  &lt;p&gt;Lessons learnt were as follows.&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Importance of preventing accidental deletions of key OUs.&lt;/li&gt;    &lt;li&gt;Importance of applying all relevant Windows Server service packs/hotfixes (disable SNP, hotfixes for LVR, ntdsutil etc.)&lt;/li&gt;    &lt;li&gt;Importance of updating hardware firmware/drivers&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;I have tried to keep this post short by skipping information about the long hours and sleep lost, the time it took for trial and error parts of resolution, challenges with 3rd party DNS that had to be circumvented using Windows DNS temporarily during recovery and the pain to customers while they were down for 3 days. But I assure you that failure to learn the lessons highlighted above, will be very painful if this happens to you.&lt;/p&gt;  &lt;p&gt;Regards&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3287479" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/Crash/default.aspx">Crash</category><category domain="http://blogs.technet.com/maweeras/archive/tags/AD/default.aspx">AD</category></item><item><title>Broadcom IPV4 Large Send Offload</title><link>http://blogs.technet.com/maweeras/archive/2009/07/14/broadcom-ipv4-large-send-offload.aspx</link><pubDate>Wed, 15 Jul 2009 00:01:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3264041</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3264041.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3264041</wfw:commentRss><description>&lt;p&gt;I have run into a couple of scenarios where this setting has caused issues and hence decided to blog about it.&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Windows 2008 X64 based domain controllers didn’t replicate with each other. However they were pulling updates inbound from other DCs (that happened to be Windows 2000 Server based) fine. Running commands such as repadmin /bind &amp;lt;W2k8DCname&amp;gt;&amp;#160; and /replsum switches indicated replication failed with access denied. Additionally terminal server sessions –(remote admin mode) were dropped repeatedly within milliseconds of establishing a session. It turned out that the newly built Windows 2008 based DCs had Broadcom cards in them and the driver installer enabled the above setting. Once this was turned off, everything started working perfectly.&lt;/li&gt;    &lt;li&gt;Was at a customer recently that claimed when they made their Windows 2003 X64 DC in a single domain forest a GC, after a while the server was unresponsive to certain RPC traffic. once the server was removed from been a GC and rebooted, it would not cause issues. I didn’t believe them at first but then they demonstrated by configuring the DC to a GC role. Sure enough a few hours later the server was having issues. repadmin /bind &amp;lt;dcname&amp;gt; traffic once captured over netmon showed resets immediately. dir &lt;a href="file://\\dcname\c$"&gt;\\dcname\c$&lt;/a&gt; and other SMB share access access such as SYSVOL and same DC worked. LDAP and GC traffic was perfect. However repadmin based commands like /bind, /replsum did not work. portqry commands to port 135 failed (unfortunately I don’t have error details at the moment). Once the above setting was turned off on the NIC and server was rebooted, no further recurrences were noted.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;So in case you run into issues where “RPC traffic is not responded to properly”, check and disable the above setting if configured on your server NIC. Please post a comment if you run into similar issues resolved by this setting.&lt;/p&gt;  &lt;p&gt;Thanks&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3264041" width="1" height="1"&gt;</description></item><item><title>w2k3_bridges_required</title><link>http://blogs.technet.com/maweeras/archive/2009/06/23/w2k3-bridges-required.aspx</link><pubDate>Tue, 23 Jun 2009 20:30:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257921</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3257921.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3257921</wfw:commentRss><description>&lt;p&gt;repadmin’s w2k3_bridges_required setting is often a misunderstood setting. Even I was confused to its usage. So when elite PFE engineer &lt;a href="http://blogs.technet.com/glennl"&gt;Glenn&lt;/a&gt; explained in an internal DL, I felt it would be good to share with others.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;The +W2K3_BRIDGES_REQUIRED has nothing to do with DFS.&amp;#160; Repeat after me….”+W2K3_BRIDGES_REQUIRED has nothing to do with DFS”&lt;/p&gt;    &lt;p&gt;This setting, when configured on a site, tells the KCC on the ISTG in said site to ignore the BASL setting (on or off) when determining site link transitiveness for the purpose of creating connection objects. Nothing more, nothing less.&lt;/p&gt;    &lt;p&gt;If you want DFS to provide intelligence that can take advantage of site link costing, then you turn on sitecostedreferrals ( see &lt;a title="DFS Tools and Settings" href="http://technet.microsoft.com/en-us/library/cc780950(WS.10).aspx"&gt;DFS Tools and Settings&lt;/a&gt; for details).&amp;#160; If you want that intelligence to extend beyond the adjacent site, then you must have a site link bridge to the transitive sites containing DFS namespace and link servers.&lt;/p&gt;    &lt;p&gt;One way to accomplish this transitiveness is the catchall BASL.&amp;#160; Another completely accurate way is manual site link bridge for each referral path for which you would like the costed referral to be something less than infinity.&amp;#160; That does not necessarily necessitate a full mesh of site link bridges.&lt;/p&gt;    &lt;p&gt;DFS is just a consumer of ISM and its site cost matrix services.&lt;/p&gt;    &lt;p&gt;If there is an adjacent or transitive path from this site to some other site, then that other site will have a cost from this site.&amp;#160; If there is no adjacent or transitive path from this site to some other site, then the cost of the other site is infinity.&lt;/p&gt;    &lt;p&gt;DFS will order referrals for DFS namespace servers and link servers based on that servers site location and its cost away from the callers site.&lt;/p&gt;&lt;/blockquote&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3257921" width="1" height="1"&gt;</description></item><item><title>DCDiag reports “not advertising as time server”</title><link>http://blogs.technet.com/maweeras/archive/2009/05/08/dcdiag-reports-not-advertising-as-time-server.aspx</link><pubDate>Fri, 08 May 2009 18:46:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237733</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3237733.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3237733</wfw:commentRss><description>&lt;p&gt;Just a quick post.&lt;/p&gt;  &lt;p&gt;Was onsite recently and had a DC that was not advertising is a time server. DCDiag confirmed it.&lt;/p&gt;  &lt;p&gt;Checked announceflags and it was set to 10 in hex (0x00000010) instead of 10 in decimal (0x0000000A).&lt;/p&gt;  &lt;p&gt;Changed registry value and use “w32tm /config /update” and all was well. Interestingly it appears to only read last value. So even he (0x0000001A) also works and advertises as time server. Presumably because it reads the last character “A” and thinks&lt;/p&gt;  &lt;p&gt;A = 10 = (0x8) + (0x2) &lt;/p&gt;  &lt;p&gt;and as per &lt;a title="http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx#w2k3tr_times_tools_uhlp" href="http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx#w2k3tr_times_tools_uhlp"&gt;http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx#w2k3tr_times_tools_uhlp&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;h6&gt;AnnounceFlags&lt;/h6&gt;  &lt;h6&gt;Registry path&lt;/h6&gt;  &lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config&lt;/p&gt;  &lt;h6&gt;Version&lt;/h6&gt;  &lt;p&gt;Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008&lt;/p&gt;  &lt;p&gt;This entry controls whether this computer is marked as a reliable time server. A computer is not marked as reliable unless it is also marked as a time server. &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;0x00 Not a time server&lt;/li&gt;    &lt;li&gt;0x01 Always time server&lt;/li&gt;    &lt;li&gt;&lt;font color="#808000"&gt;0x02 Automatic time server&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;0x04 Always reliable time server&lt;/li&gt;    &lt;li&gt;&lt;font color="#808040"&gt;0x08 Automatic reliable time server&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The default value for domain members is 10. The default value for stand-alone clients and servers is 10.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237733" width="1" height="1"&gt;</description></item><item><title>Definition of bad weekend</title><link>http://blogs.technet.com/maweeras/archive/2009/03/30/definition-of-bad-weekend.aspx</link><pubDate>Mon, 30 Mar 2009 13:55:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3219676</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3219676.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3219676</wfw:commentRss><description>&lt;p&gt;A non tech post today.&lt;/p&gt;  &lt;p&gt;1. Get thumb crushed on car door. End up with an agonisingly painful thumb which causes you to visit the Accident and Emergency dept to drain blood under thumbnail by drilling a hole into the thumbnail.&lt;/p&gt;  &lt;p&gt;2. Hours after the thumb was crushed, decide to fill up the car and put 15L of petrol instead of Diesel and then await recovery company to take car away for repair&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3219676" width="1" height="1"&gt;</description></item><item><title>FRS and host files</title><link>http://blogs.technet.com/maweeras/archive/2009/02/24/frs-and-host-files.aspx</link><pubDate>Tue, 24 Feb 2009 15:08:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3206082</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3206082.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3206082</wfw:commentRss><description>&lt;p&gt;Just a quick blog post about something I saw recently. I was at a customer site performing an ADRAP and I ran into one of the customer’s domains where FRS was not converging. Among the troubleshooting steps I tried to verify that DNS had records for the DCs which it did and I verified using nslookup from the ADRAP machine I was using for gathering data from the DCs.&lt;/p&gt;  &lt;p&gt;To cut a long story short the customer had a host file on the DCs of that domain in the following format.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;10.1.1.1 DC1 DC1.Domain.Com&lt;/p&gt;    &lt;p&gt;10.2.3.1 DC2 DC1.Domain.Com&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;As both IP addresses were bound to the same FQDN, FRS on each DC was having issues pulling updates from its partner. However AD replication was working fine. The reason for this is the DCs were using the &amp;lt;GUID&amp;gt;._msdcs.forestFQDN and therefore DNS was resolving the record. &lt;/p&gt;  &lt;p&gt;Note to self, when troubleshooting name resolution always do the test from the host machine directly. &lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M &lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3206082" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/FRS/default.aspx">FRS</category><category domain="http://blogs.technet.com/maweeras/archive/tags/DNS/default.aspx">DNS</category></item><item><title>DCLocator and Closest Site info</title><link>http://blogs.technet.com/maweeras/archive/2009/02/14/dclocator-and-closest-site-info.aspx</link><pubDate>Sat, 14 Feb 2009 23:32:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3202269</guid><dc:creator>maweeras</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3202269.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3202269</wfw:commentRss><description>&lt;p&gt;I’ve been doing some research to prepare for my upcoming first delivery of AD Troubleshooting workshop. The agenda of content includes DCLocator and Netlogon content. Hence this post.&lt;/p&gt;  &lt;p&gt;For the real detail on dsgetdcname and details on the nltest /dsgetdc flags, please see &lt;a href="http://msdn.microsoft.com/en-us/library/ms675983(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/ms675983(VS.85).aspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;I made a lab environment which consisted of a single domain forest and 1 x Vista and 1 x XP client. Here are my observations.&lt;/p&gt;  &lt;p&gt;If the Vista client’s IP address is from a subnet known by AD, a Windows Server 2008 DC will provide the closest site info details as well. It does not do this for XP. Presumably other down-level OS editions are also not given this detail but I didn’t check. &lt;/p&gt;  &lt;p&gt;Here is the LDAP filter one of the UDP based CLDAP ping performed by the Vista client. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Filter: (&amp;amp;(DnsDomain=adatum.com)(Host=ADTMCLIENT1)(DomainGuid={AEF3F962-37E0-D147-8611-D8CA1AAED85E})(NtVer=16:00:00:00))&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;And the response back from the Windows Server 2008 DC is as follows.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Frame: Number = 86, Captured Frame Length = 200, MediaType = ETHERNET &lt;/p&gt;    &lt;p&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-03-FF-0D-FA-00],SourceAddress:[00-03-FF-A5-9B-45]&lt;/p&gt;    &lt;p&gt;+ Ipv4: Src = 10.1.1.2, Dest = 10.1.1.6, Next Protocol = UDP, Packet ID = 3904, Total IP Length = 186&lt;/p&gt;    &lt;p&gt;+ Udp: SrcPort = LDAP(389), DstPort = 58266, Length = 166&lt;/p&gt;    &lt;p&gt;+ Cldap: (CLDAP)Search Result Entry, MessageID: 1, Status: Success&lt;/p&gt;    &lt;p&gt;- NetlogonAttribute: LogonSAMLogonResponseEX (SAM Response to SAM logon request): 23 (0x17)&lt;/p&gt;    &lt;p&gt;- SamLogonResponseEx: ADTMDC1.adatum.com&lt;/p&gt;    &lt;p&gt;Opcode: LogonSAMLogonResponseEX&lt;/p&gt;    &lt;p&gt;Sbz: 0 (0x0)&lt;/p&gt;    &lt;p&gt;+ Flags: 0x000013FD &lt;/p&gt;    &lt;p&gt;DomainGuid: {62F9F3AE-E037-47D1-8611-D8CA1AAED85E}&lt;/p&gt;    &lt;p&gt;DnsForestName: adatum.com&lt;/p&gt;    &lt;p&gt;DnsDomainName: adatum.com&lt;/p&gt;    &lt;p&gt;DnsHostName: ADTMDC1.adatum.com&lt;/p&gt;    &lt;p&gt;NetbiosDomainName: ADATUM&lt;/p&gt;    &lt;p&gt;NetbiosComputerName: ADTMDC1&lt;/p&gt;    &lt;p&gt;UserName: &lt;/p&gt;    &lt;p&gt;DcSiteName: HQ&lt;/p&gt;    &lt;p&gt;ClientSiteName: HQ&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;font color="#800040"&gt;Unknown: Binary Large Object (7 Bytes)&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;+ Version: 0x00000015 NT Version 5 Client&lt;/p&gt;    &lt;p&gt;+ LmNtToken: Windows NT Networking: 0xFFFF&lt;/p&gt;    &lt;p&gt;+ Lm20Token: OS/2 LAN Manager 2.0 (or later) Networking: 0xFFFF&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The italic &lt;em&gt;&lt;font color="#800040"&gt;Unknown: Binary Large Object (7 Bytes)&lt;/font&gt;&lt;/em&gt; has hex details corresponding to the following.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;05 53 69 74 65 32 00 &lt;/p&gt;    &lt;p&gt;.Site2.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Here is the site topology created using the ADTD Visio tool.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/maweeras/WindowsLiveWriter/DCLocatorandClosestSiteinfo_120F3/AD%20Sites_2.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="AD Sites" border="0" alt="AD Sites" src="http://blogs.technet.com/blogfiles/maweeras/WindowsLiveWriter/DCLocatorandClosestSiteinfo_120F3/AD%20Sites_thumb.jpg" width="244" height="242" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Currently Netmon 3.2 with latest parsers decodes as above. Wireshark as of v1.0.5 did not decode this.&lt;/p&gt;  &lt;p&gt;Please note that the above “Unknown: Binary Large Object (7 Bytes)” field is NOT available if the DC cannot see a subnet that the Vista machine belongs to. Netlogon.log on the client shows that the client did not use any try_next_closest_site flags. Yet the DC still presents the information. It can do this as the filter has a NtVer=16:00:00:00 string identifying the Client OS. XP for example would use NtVer=06:00:00:00. Hence a Windows Server 2008 DC will not respond with closest site info to them.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3202269" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/maweeras/archive/tags/Vista/default.aspx">Vista</category></item><item><title>Sysinternals to the rescue</title><link>http://blogs.technet.com/maweeras/archive/2009/01/12/sysinternals-to-the-rescue.aspx</link><pubDate>Mon, 12 Jan 2009 09:48:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3180930</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3180930.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3180930</wfw:commentRss><description>&lt;p&gt;This is a quick post to get me back into the spirit of blogging. Some time back I was onsite performing an &lt;a target="_blank" href="http://www.microsoft.com/uk/services/premiersupport/default.mspx"&gt;ADRAP&lt;/a&gt; to assist the customer with some issues they were having with their AD. Among the many issues we found was one DC reporting the following in its system/DS and FRS event logs.&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;“Registration of the DNS record '_kpasswd._tcp.domain.com. 600 IN SRV 0 100 464 DC1.adatum.com.' failed with the following error: %&lt;em&gt;An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full&lt;/em&gt;.”&lt;/li&gt;    &lt;li&gt;“No Windows NT or Windows 2000 Domain Controller is available for domain adatum. The following error occurred: &lt;em&gt;%Not enough storage is available to process this command&lt;/em&gt;.”&lt;/li&gt;    &lt;li&gt;“The attempt to establish a replication link with parameters.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Partition: CN=Configuration,DC=adatum,DC=com &lt;/p&gt;  &lt;p&gt;Source DSA DN: CN=NTDS Settings,CN=DC3,CN=Servers,CN=Branch1,CN=Sites,CN=Configuration,DC=adatum,DC=com &lt;/p&gt;  &lt;p&gt;Source DSA Address: 5bbb4c2b-47bf-4593-b0dc-460ea4916d49._msdcs.adatum.com &lt;/p&gt;  &lt;p&gt;Inter-site Transport (if any): CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adatum,DC=com &lt;/p&gt;  &lt;p&gt;failed with the following status: &lt;/p&gt;  &lt;p&gt;&lt;em&gt;Not enough storage is available to complete this operation.&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;The record data is the status code.&amp;#160; This operation will be retried.”&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;4.&amp;#160; Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller dc1.adatum.com for FRS replica set configuration information. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;em&gt;Could not bind to a Domain Controller&lt;/em&gt;. Will try again at next polling cycle.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Realising we had a network issue I used “netstat –an” on the DC1 to see the network connections it had established. Output similar to below was &lt;/p&gt;  &lt;p&gt;Proto&amp;#160; Local Address&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Foreign Address&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; State   &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:135&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:445&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:990&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;&amp;lt;snip&amp;gt;    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:1025&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:1026&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:1027&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;&amp;lt;snip&amp;gt;    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4998&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4999&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;TCP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:5000&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:0&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LISTENING    &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;As this was a Windows 2000 Server I did not have the “-o”option of neststat to print out the process ID that was listening on the ports. But you will note that in the above output all ports between 1024-5000 were in use. This is the ephemeral port range. I was pretty certain that the server was infected by now. I wanted to know what the process was so I used &lt;a target="_blank" href="http://technet.microsoft.com/en-us/sysinternals/bb897437.aspx"&gt;TCPView&lt;/a&gt; from Sysinternals. TCPview revaled the process name and a quick search on the &lt;a target="_blank" href="http://www.microsoft.com/security/portal/"&gt;Malware Protection Center&lt;/a&gt; revealed it to be an IRC Bot. Further investigation revealed the DC did not have any anti-virus software and was missing many critical and important security updates. Unfortunately I don’t recall the exact name of the worm.&lt;/p&gt;  &lt;p&gt;This was the first time I’d come across a real production DC that was infected. This particular server had replication issues because it did not have any free ports available for use for replication. AD and FRS replication was affected as a result.&lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3180930" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/AD/default.aspx">AD</category><category domain="http://blogs.technet.com/maweeras/archive/tags/Sysinternals/default.aspx">Sysinternals</category><category domain="http://blogs.technet.com/maweeras/archive/tags/malware/default.aspx">malware</category><category domain="http://blogs.technet.com/maweeras/archive/tags/Virus/default.aspx">Virus</category></item><item><title>The case of the DNS records that didn't resolve</title><link>http://blogs.technet.com/maweeras/archive/2008/10/31/the-case-of-the-dns-records-that-didn-t-resolve.aspx</link><pubDate>Sat, 01 Nov 2008 01:13:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145484</guid><dc:creator>maweeras</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3145484.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3145484</wfw:commentRss><description>&lt;p&gt;I was at a customer today who was in the process of moving their AD from Windows Server 2003 to Windows Server 2008 x64 platform. In the process at some point he changed the DHCP servers to use the new Windows Server 2008 based DC/DNS servers for name resolution. He then said he was having issues with name resolution and said the problem disappeared when he used the Windows Server 2003 based DC/DNS. &lt;/p&gt;  &lt;p&gt;I wasn't sure whether I could believe him :) I did some tests using nslookup and dcdiag and then assumed it was a non existent issue. However, he reproduced the issue. I was absolutely amazed at the time as the same query done on W2K3 worked but it didn't on W2K8. This was for a record that was in an AD integrated zone and so I didn't want to assume a corrupt zone. Netmon traces clearly showed the record as non existent despite visible in dnsmgmt.msc and dnscmd. &lt;/p&gt;  &lt;p&gt;Then I did what I should have done first. I checked the event log :-). In there was an event about &amp;quot;global query block list&amp;quot;. The record that they could not resolve was an important record. I.e. it was the wpad record for proxy settings. In this case the customer had literally typed wpad into the proxy server settings (instead of the proxy server name) along with the relevant port. wpad resolution is typically only required if &amp;quot;Auto detect settings&amp;quot; checkbox is selected to detect the proxy settings. As they were literally using the name &amp;quot;wpad&amp;quot; in the proxy settings dialogs box, they couldn't access the Internet.&lt;/p&gt;  &lt;p&gt;With the mystery solved I proceeded to advise them of the behaviour and point them at Technet resources for more details. The recommendation was to change the proxy settings to use a more meaningful name such as the real proxy server name as they were not reliant on auto proxy settings discovery. Please see &lt;a title="Managing the Global Query Block List" href="http://technet.microsoft.com/en-us/library/cc794902.aspx"&gt;Managing the Global Query Block List&lt;/a&gt; for details.&lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3145484" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/maweeras/archive/tags/DNS/default.aspx">DNS</category></item><item><title>The case of the blocked FRS replication</title><link>http://blogs.technet.com/maweeras/archive/2008/09/14/the-case-of-the-blocked-frs-replication.aspx</link><pubDate>Mon, 15 Sep 2008 01:03:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3123867</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3123867.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3123867</wfw:commentRss><description>&lt;p&gt;So I haven't written anything in quite a while and felt compelled to write something I recently ran into. A customer of mine is in the process of implementing Windows Server 2008 RODC in their branch offices. In order to do that, they are planning to in-place upgrade the W2K3 DCs to W2K8 at the hub sites.&lt;/p&gt;  &lt;p&gt;The customer did an in-place upgrade of their W2K3 DC in their lab and found that while the upgrade worked, the DC didn't appear to be completely functional. Specifically FRS replication appeared to be broken. Event 13508 was logged by the W2K8 DC reporting that it couldn't replicate. Similarly W2K3 DCs reported the W2K8 to be unavailable. The customer even turned the W2K8 firewall off to no avail. I asked for FRSDiag content from the customer and the results I got back were partial. There was no connstat.txt or any other content from ntfrsutl. Instead I had RPC errors scattered through the FRSDiag data.&lt;/p&gt;  &lt;p&gt;The customer in question has a very large global AD implementation and site to site communication is secured with firewalls in place. To ensure AD and FRS replication works through firewalls, the customer has configured static ports for AD and FRS replication. Firewall rules are also configured to ensure these ports are open and the replication traffic between DCs are allowed. &lt;a title="http://support.microsoft.com/kb/224196/" href="http://support.microsoft.com/kb/224196/"&gt;http://support.microsoft.com/kb/224196/&lt;/a&gt; and &lt;a title="http://support.microsoft.com/kb/319553/" href="http://support.microsoft.com/kb/319553/"&gt;http://support.microsoft.com/kb/319553/&lt;/a&gt; have details of how to lock these ports down.&lt;/p&gt;  &lt;p&gt;Analysis of the FRSDiag data showed that FRS was trying to listen on port TCP 49153. This had been enforced through Group Policies. However, it couldn't as the port was in use. In this case, we used &amp;quot;portqry -n &amp;lt;server&amp;gt; -e 135&amp;quot; to query the RPC endpoint mapper. This showed that the Event Log TCPIP was using the port. In W2K8 and Vista we made change to the ephemeral port range to start from 49152 (instead of 1025) and end at 65535 (instead of 5000). So the event log in W2K8 starts early on and grabs this port (49153). In W2K3 it would have grabbed something early in the 1025-5000 range. So the customer didn't see an issue until the upgrade to W2K8.&lt;/p&gt;  &lt;p&gt;Changing FRS to use a dynamic port (by deleting the reg key that enforced a static port) and restarting FRS fixed the issue temporarily. So we knew we had the cause figured out. The problem was the customer did not want to have to go and update firewall rules to allow the in-place upgrade of a W2K3 DC to W2K8 work. So he wanted to know whether we could have the Event Log use another port. From the research I've done, it does not appear to be possible to do this. However, in W2K8 you can move the ephemeral port range to start from another value instead of the default 49152. So I pointed the customer to the fine article at Ned's Askds blog (&lt;a title="http://blogs.technet.com/askds/archive/2007/08/24/dynamic-client-ports-in-windows-server-2008-and-windows-vista-or-how-i-learned-to-stop-worrying-and-love-the-iana.aspx" href="http://blogs.technet.com/askds/archive/2007/08/24/dynamic-client-ports-in-windows-server-2008-and-windows-vista-or-how-i-learned-to-stop-worrying-and-love-the-iana.aspx"&gt;http://blogs.technet.com/askds/archive/2007/08/24/dynamic-client-ports-in-windows-server-2008-and-windows-vista-or-how-i-learned-to-stop-worrying-and-love-the-iana.aspx&lt;/a&gt;) and advised him to move the range to start from 49160 ( which freed 49152-49159 for customer requirements) &lt;strong&gt;and test!&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;FRSDiag is such a great tool. For more good details on its usage, head on to Ned's blog for some quality articles such as &lt;a title="How to get the most from your FRSDiag&amp;#8230;" href="http://blogs.technet.com/askds/archive/2008/05/30/how-to-get-the-most-from-your-frsdiag.aspx"&gt;How to get the most from your FRSDiag&amp;#8230;&lt;/a&gt;and tips.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3123867" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/AD/default.aspx">AD</category><category domain="http://blogs.technet.com/maweeras/archive/tags/FRS/default.aspx">FRS</category><category domain="http://blogs.technet.com/maweeras/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Can't Open XPS Documents on Vista</title><link>http://blogs.technet.com/maweeras/archive/2008/05/25/can-t-open-xps-documents-on-vista.aspx</link><pubDate>Sun, 25 May 2008 14:49:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3060786</guid><dc:creator>maweeras</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3060786.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3060786</wfw:commentRss><description>&lt;p&gt;Just thought I'd post a quick observation I made on my laptop. Some time back I ran into an interesting issue on my laptop where I could create XPS documents using the &amp;quot;XPS Document Writer&amp;quot; printer or even using applications like Office 2007. I could even see a preview of it in Windows Explorer. But I could not open them.&lt;/p&gt;  &lt;p&gt;I accidentally then discovered that if I change my colour scheme to Windows Basic, I can open any XPS files. So I thought I'd post the workaround for others benefit. Incidentally, I am following this up with our engineers here and if I find a fix I will update you all.&lt;/p&gt;  &lt;li&gt;   &lt;p&gt;Go to Control Panel - Personalization&lt;/p&gt; &lt;/li&gt;  &lt;li&gt;   &lt;p&gt;Choose the first Windows Colour and Appearance&lt;/p&gt; &lt;/li&gt;  &lt;li&gt;   &lt;p&gt;Click the &amp;quot;Open Classic Appearance Properties for More Colour Options&amp;quot; at the bottom&lt;/p&gt; &lt;/li&gt;  &lt;li&gt;   &lt;p&gt;Choose Windows Basic as colour scheme.&lt;/p&gt; &lt;/li&gt;  &lt;p&gt;This seems to be a rare issue that does not affect all Vista users. But I hope it helps those that are affected. Incidentally I have a 32-bit Vista Enterprise SP1 laptop (Toshiba M400) with all Windows Updates applied to date.&lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3060786" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/Vista/default.aspx">Vista</category></item><item><title>NTDSUTIL - Group Membership Evaluation</title><link>http://blogs.technet.com/maweeras/archive/2008/05/02/ntdsutil-group-membership-evaluation.aspx</link><pubDate>Fri, 02 May 2008 15:25:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3048645</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3048645.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3048645</wfw:commentRss><description>&lt;p&gt;I just had an issue at a customer where we were troubleshooting an issue where users could not use the SQL Management studio to connect to a SQL server remotely. Local login to SQL server interactively and then launching the client tools worked. The cause was the number of groups the user belonged to. &lt;/p&gt;  &lt;p&gt;To troubleshoot this, we busted out ntdsutil and tried to enumerate the group membership. But to our surprise it only showed 3 groups. Then after changing servers we got 600 plus groups and then again 3 groups. So basically the resultant number of groups were changing all the time.&lt;/p&gt;  &lt;p&gt;It turns out this is a bug in ntdsutil for which a hotfix is now available. If you are using the group membership evaluation feature in ntdsutil, try this version. &lt;a href="http://support.microsoft.com/kb/934185"&gt;http://support.microsoft.com/kb/934185&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3048645" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/AD/default.aspx">AD</category></item><item><title>User initiated crash dump in Vista Laptop</title><link>http://blogs.technet.com/maweeras/archive/2008/03/21/user-initiated-crash-dump-in-vista-laptop.aspx</link><pubDate>Fri, 21 Mar 2008 20:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3017618</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/3017618.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=3017618</wfw:commentRss><description>&lt;P&gt;I have a vista SP1 based Toshiba M400. As we tend to regularly dogfood software builds internally I also assist with self hosting any software builds I am interested in. These builds are not perfect and sometimes they cause laptops to hang, deplete resources etc...&lt;/P&gt;
&lt;P&gt;I've not done much to generate crash dumps and have always had one "helpfully" created for me. I have had the "pleasure" of having to use the instructions in &lt;A title=http://support.microsoft.com/kb/244139 href="http://support.microsoft.com/kb/244139" mce_href="http://support.microsoft.com/kb/244139"&gt;http://support.microsoft.com/kb/244139&lt;/A&gt; article for servers in the past but never used it on a laptop. When I recently had the need to use crashonctrlscroll I was annoyed to discover my laptop had no right Ctrl key. I figured I'd use a USB keyboard but as per &lt;A title=http://support.microsoft.com/kb/944564 href="http://support.microsoft.com/kb/944564" mce_href="http://support.microsoft.com/kb/944564"&gt;http://support.microsoft.com/kb/944564&lt;/A&gt; the feature is not available using USB keyboards. At least not on Windows Server 2008. Not sure if it applies to Vista too but it wouldn't surprise me if it did.&lt;/P&gt;
&lt;P&gt;I unlocked my session from last night only to see the spinning donut (although it wasnt spinning) and the desktop as it last was. No response to keyboard and mouse input. I just tried to use the normal Ctrl +Function+ F12 and was "pleasantly" surprised when it did do the crash dump. Note my M400 needs Fn + F12 for scroll lock. I didn't have a USB keyboard attached although I do have the steps from the 1st KB applied.&lt;/P&gt;
&lt;P&gt;So there you go. You can generate crash dumps on laptops running Vista even without the right Ctrl. &lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;M&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3017618" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/maweeras/archive/tags/Crash/default.aspx">Crash</category></item><item><title>Wevtutil Error</title><link>http://blogs.technet.com/maweeras/archive/2008/01/19/wevtutil-error.aspx</link><pubDate>Sat, 19 Jan 2008 03:29:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2757802</guid><dc:creator>maweeras</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/maweeras/comments/2757802.aspx</comments><wfw:commentRss>http://blogs.technet.com/maweeras/commentrss.aspx?PostID=2757802</wfw:commentRss><description>&lt;p&gt;I just found out today that the command listed to view all audit events for Vista and Windows Server 2008 does not work on installations if using a language other than English USA. The following command will result in an error as follows.&lt;/p&gt;  &lt;p&gt;C:\Windows\system32&amp;gt;wevtutil gp Microsoft-Windows-Security-Auditing /ge &lt;font color="#ff0000"&gt;/gm:true&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;name: Microsoft-Windows-Security-Auditing   &lt;br /&gt;guid: 54849625-5478-4994-a5ba-3e3b0328c30d    &lt;br /&gt;helpLink: &lt;a href="http://go.microsoft.com/fwlink/events.asp?CoName=Microsoft%20Corporati"&gt;http://go.microsoft.com/fwlink/events.asp?CoName=Microsoft%20Corporati&lt;/a&gt;    &lt;br /&gt;on&amp;amp;ProdName=Microsoft%c2%ae%20Windows%c2%ae%20Operating%20System&amp;amp;ProdVer=6.0.600    &lt;br /&gt;0.16386&amp;amp;FileName=adtschema.dll&amp;amp;FileVer=6.0.6000.16386    &lt;br /&gt;resourceFileName: %SystemRoot%\system32\adtschema.dll    &lt;br /&gt;parameterFileName: %SystemRoot%\system32\msobjs.dll    &lt;br /&gt;messageFileName: %SystemRoot%\system32\adtschema.dll    &lt;br /&gt;message:    &lt;br /&gt;channels:    &lt;br /&gt;&amp;#160; channel:    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; name: Security    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; id: 10    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; flags: 1    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; message:    &lt;br /&gt;levels:    &lt;br /&gt;&amp;#160; level:    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; name: win:Informational    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; value: 4    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; message:    &lt;br /&gt;opcodes:    &lt;br /&gt;&amp;#160; opcode:    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; name: win:Info    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; value: 0    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; task: 0    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; opcode: 0    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; message:    &lt;br /&gt;tasks:    &lt;br /&gt;&amp;#160; task:    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; name: SE_ADT_SYSTEM_SECURITYSTATECHANGE    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; value: 12288    &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; eventGUID: 00000000-0000-0000-0000-000000000000    &lt;br /&gt;&lt;font color="#ff0000"&gt;Failed to get message property. the message resource is present but the message     &lt;br /&gt;is not found in the string/message table&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;The Windows Events Development team is aware and will address this in the near future.&lt;/p&gt;  &lt;p&gt;HTH&lt;/p&gt;  &lt;p&gt;M&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2757802" width="1" height="1"&gt;</description></item></channel></rss>