09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 16<br />

Error Messages<br />

In this chapter, I’ll demonstrate troubleshooting techniques using the Sysinternals<br />

utilities when the primary symptom is an error message. In this chapter, Procmon is the<br />

troubleshooting tool of choice in all but the first two cases:<br />

■ The Case of the Locked Folder highlights a common use case for Procexp.<br />

■ The Case of the Failed AV Update demonstrates Autoruns’ Analyze Offline System<br />

feature to repair an unbootable computer.<br />

■ The Case of the Failed Lotus Notes Backups is interesting to me and will be useful to<br />

many readers because it shows what a search for a missing DLL looks like in Procmon.<br />

■ The Case of the Failed Play-To and The Case of the Crashing Proksi Utility<br />

highlight different ways in which “Access Denied errors can manifest.<br />

■ The Case of the Installation Failure turned out to be caused by ill-advised security<br />

guidance.<br />

■ The Case of the Missing Folder Association demonstrates comparing a Procmon<br />

trace from a problematic system to one from a working system.<br />

■ The Case of the Temporary Registry Profiles is especially interesting because it<br />

affected a large number of users and made use of one of Procmon’s lesser-known<br />

features: boot logging.<br />

The Case of the Locked Folder<br />

While writing up “The Case of the IExplore-Pegged CPU” (in Chapter 17, “Hangs and<br />

Sluggish Performance”), I decided to rename the folder containing the files. However, I ran<br />

into an unexpected error (shown in Figure 16-1) because another program had an open<br />

handle to the folder or to something in it. After making sure I didn’t have any files open or<br />

command prompts in that folder, I clicked Try Again, but the folder remained in use and<br />

could not be renamed.<br />

www.it-ebooks.info<br />

383

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!