Steve's online kb-notes

Somewhat cryptic notes, but perhaps they may help.  As always, use at your own risk!

Stop C2 - BAD_POOL_CALLER

Same problem in safe mode or trying to logon using the CD then the Repair mode.

See http://support.microsoft.com/kb/307545/en-us

typically - reinstall

Working offline

Microsoft server (corporate) workstation goes "offline", this registry tweak may resolve the problem:

On workstation, add the following DWORD:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache

  • FormatDatabase

  • Change the value to1

  • Restart workstation

Can't log in

Attempt to log on immediately logs off again... logon immediately logs off

copy userinit.exe as wsaupdater.exe

Regedit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

Change C:\WINDOWS\System32\wsaupdater.exe -to- C:\WINDOWS\System32\userinit.exe

else

Reinstall Windows

(stupid) Vista unidentified network

as found in other articles, none seem to work...

(rock and a hard place)  First install all service packs and updates.

Uninstall NIC then reboot

and/or

ipconfig /flushdns

and/or

  • Click Start , click All Programs, and then click Accessories.
  • Right-click Command Prompt, and then click Run as Administrator. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
  • At the command prompt, type
    netsh interface tcp set global autotuninglevel=disabled
  • Restart the computer.

else

Reinstall Windows

Forgotten passwords

This is a problem with Windows XP and later versions and even more so with certain applications such as accounting software.  Microsoft offers this policy article about lost passwords, but it does very little to help under most circumstances...  kw: forgot password, XP password

XP Pro not Home

  • Boot to the Safe Mode and logon to the Administrative account. 
    Note: If that also has password, you may need a third party application (see below), but it might work booting to the Windows CD and entering the Repair mode prompt...
  • Once logged on to the Admin account, you may be able to simply remove the password from the Control Panel's > Users settings
  • Otherwise try:  Open a command windows (Start > Run > "cmd")
  • At the command prompt, type net user ¿
    • That will list the user names on the computer...
  • Next type net user "username" * ¿
    • i.e., the (desired) user's name shown in the list and then literally type that name within quotes followed by the asterisk...
  • That prompts you for the new password.  Type whatever password you desire ¿  then confirm that new password.
  • Reboot the computer

There are password cracking applications available for Windows and various applications, but you will likely have to pay for anything that really works...  Search for lost XP password, lost applicationname password, etc...

Privacy Center pc.exe shell
AV.Exe and AVE.Exe likely require factory restore...

any USB device crashes to BOD:  usb crash

Start in Safe, rename c:\windows\system32\drivers\usbport.sys to .old
Copy same from $NTServicePackUninstall$ to c:\windows\system32\drivers

"This operation has been cancelled due to restrictions in effect on this computer."

Remove Google Chrome (re-load if desired)

http://www.slipstick.com/problems/link_restrict.htm

Applications will not open instead prompt you to choose a program to open with:

HKEY_CLASSES_ROOT
exefile
Shell
open
command
default
The value should read exactly and only 
"%1" %*  



or merge this file which contains:

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"

[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"TileInfo"="prop:FileDescription;Company;FileVersion"
"InfoTip"="prop:FileDescription;Company;FileVersion;Create;Size"

[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"

[HKEY_CLASSES_ROOT\exefile\shell]

[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\runas]

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shellex]

[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser]
@="{09A63660-16F9-11d0-B1DF-004F56001CA7}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
@="{86F19A00-42A0-1069-A2E9-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"

BSoD after Feb 9 updates

the root cause is an infection of %System32\drivers\atapi.sys, and that replacing this file with a clean version will get the system booting normally

Vista network: A dependency service failed to start.  DHCP client access denied

did not work: delete winsock and winsock2 from registry, reinstall TCP protocol from windows\inf
neither worked: netsh winsock reset and netsh int ip reset
did not work: permissions on HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp.

CD/DVD drive missing?

Delete upper and lower filters from HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\
{4D36E965-E325-11CE-BFC1-08002BE10318}

http://support.microsoft.com/kb/314060   /  Microsoft fix/article.

Vista hangs (could occur with other OSs)

Even after a fresh install, Vista hangs just before the welcome screen or initial install screen asking for name, time, etc.

In the BIOS, turn off Flash Cache and change the drive type to ATA rather than AHCI

Clear IE Content Advisor password

Click on Start and choose Run.
Type in RegEdit and select OK.
Tunnel to H_KEY_LOCAL_MACHINE/Software/Microsoft/Windows/Current Version/Policies/Ratings
Delete "Key"
Exit and reboot
Go to the Internet Options > Content tab and click on Disable.

Enter a password like 1