free780 Posted June 21, 2018 Posted June 21, 2018 Anyone tried clearing the per user firewall rules created by modern applications? I've seen this in server 2016 RDS where many users have logged on. The RDS hosts do not have impero installed. Granted the build is on par with LTSC 1607.
TechMonkey Posted June 27, 2018 Posted June 27, 2018 To throw a spanner in the works, we are getting this and don't have Impero. May be a standard MS issue.
smurfomatic Posted June 27, 2018 Posted June 27, 2018 To throw a spanner in the works, we are getting this and don't have Impero. May be a standard MS issue. Same here, just with the brand new batch of Windows 10 machines we bought earlier this year, no one else seems to be affected.
Oaktech Posted June 27, 2018 Posted June 27, 2018 It seems to be worse on certain builds of w10. I am not seeing it at all (so far) on any of our 1709 or 1803 machines. It seems much worse on 1703 build 15063.1088 and virtually non existent on 1703 build 15063.1155. Adding the DLLHOST exclusion to Impero has helped a lot though.
DCUK6 Posted June 27, 2018 Author Posted June 27, 2018 (edited) So far, added all exclusions to impero, and made sure they were applying has we had a issue where they wernt at first. AV on diagnostic mode for a few days, apart from the 1000's of messages saying Impero was allowed there is only the touchpad and crcss service being blocked acces now, blocked access to AV program files. GPO has been cleaned removing any unnecessary policies. Scripts have all been altered to check for files before applying and to exit. Roaming profiles all removed. Printers no longer auto deployed. Curruntly upgrading AV to latest version. We are a bit low on student machines, hopefully i get 28 shiny new laptops ordered tomorrow with good specs so will see if these suffer. Will be creating a new image with the latest build on them. Edited June 27, 2018 by DCUK6
TechMonkey Posted June 27, 2018 Posted June 27, 2018 It seems to be worse on certain builds of w10. I am not seeing it at all (so far) on any of our 1709 or 1803 machines. It seems much worse on 1703 build 15063.1088 and virtually non existent on 1703 build 15063.1155. Adding the DLLHOST exclusion to Impero has helped a lot though. I don't think we have seen it before, just starting to get it on 1803. Nice for it to be consistent!
Arthur Posted August 8, 2018 Posted August 8, 2018 (edited) [b][u]Application[/u][/b]:[b][u]Description[/u][/b]: fontdrvhost.exe Windows Font Driver Management dwm.exe Desktop Window Manager [color="#FF0000"][b]constant.exe[/b][/color] User Account Control werfault.exe Windows Error Reporting dllhost.exe COM Surrogate Just in case anyone comes across @Mic_Impero's post above via search. The UAC line contains a typo. constant.exe should be consent.exe I had constant.exe in my Injection Exclusions list. Changing it to consent.exe improved login times on our older Core 2 Duo Windows 10 PCs by over a minute! Edited August 8, 2018 by Arthur 2
Mic_Impero Posted August 8, 2018 Posted August 8, 2018 Thank you Arthur, i'll ensure we update the source of that information. Mic
gshaw Posted August 10, 2018 Posted August 10, 2018 I've just logged a case for this exact same issue, will try the exclusions list on Monday unless support say differently. It hasn't shown up on any of the individual machines I've been working with in my office but logging in a batch of 15 in a classroom today was almost 50% stuck on the black background. On the latest 7.0.65 Impero Client too.
gshaw Posted August 16, 2018 Posted August 16, 2018 @Arthur is this completely resolved for you or still getting instances of the black screen? We've tried a whole list of things with support including running the latest early-release 7.1.29 client, still seeing the black screen on about 50% of machines on a first login when using the Impero Console to log them in all at once. Back to the testing tomorrow to try and isolate it further
elsiegee40 Posted August 16, 2018 Posted August 16, 2018 Just in case anyone comes across @Mic_Impero's post above via search. The UAC line contains a typo. constant.exe should be consent.exe I had constant.exe in my Injection Exclusions list. Changing it to consent.exe improved login times on our older Core 2 Duo Windows 10 PCs by over a minute! I have edited the post and those quoting it (apart from this one ) 2
Arthur Posted August 17, 2018 Posted August 17, 2018 is this completely resolved for you or still getting instances of the black screen? I haven't seen any black screens so far, just really long login times.
gshaw Posted August 17, 2018 Posted August 17, 2018 What sort of times are you talking about? @alfatec anywhere from 30 seconds to 2 minutes
Rob_D Posted August 17, 2018 Posted August 17, 2018 We've been getting the black screen issue on some of our windows 10 computers. When it happens we find an error for "Windows.CloudStore.dll, version: 10.0.16299.98" in the event log. Although not much closer to working out why it's happening.
gshaw Posted August 17, 2018 Posted August 17, 2018 (edited) @alfatec first login, I clear the profiles with DelProf2 to run further tests as subsequent logins seem to be OK @Rob_D interesting, I see a Windows Tile Repository error on some machines but that may be a red herring, perhaps 1709 doesn't like a 1703 StartMenuLayout file despite it working fine in terms of applying the layout as expected Have also noticed if I log in a room of machines (via Impero console) with the same account I'll get the black screen issues, however if I log in a bunch of (different) accounts it's fine. For the concurrent logins the black screen issue seems to be related to Folder Redirection as accounts without redirection configured don't experience the issue. Edited August 17, 2018 by gshaw
hugginsn Posted August 22, 2018 Posted August 22, 2018 Hi all, We've been having the same problem. It became noticeable after upgrading Windows 10 to 1803, but that's not to see we didn't have this issue with 1709!! We also use Impero, currently version is 7.1.29 - we still had the problem with 6.3.7.4. What we had observed was that the user would sit there with a black screen and the mouse pointer, which would be moveable. We loaded task manager and tried the old trick of running explorer.exe (not sure how that works in a Win10 environment). We then scrolled down the list of processes to see if anything obvious was running a high processor count or ram usage...nothing. We then noticed the Shell Information Host. Ended the task, it automatically started again and within seconds the task bar, start menu and desktop all sprang into life. I went onto the Impero server and added sihost.exe to the injections list. Everything has been working fine since. I hope that someone finds the information useful. 1
Oaktech Posted August 22, 2018 Posted August 22, 2018 Correcting constant to consent and adding sihost to exclusions seems to have brought the login time on a wired client down to a consistent 20-30 seconds from anywhere between a minute and 5 minutes. Thanks everyone...
gshaw Posted August 23, 2018 Posted August 23, 2018 Hoping sihost does the trick, we're already on the latest 7.1.32 so hoping this all does the trick. @Mic_Impero should we also exempt our AV from Injection? I've noticed Sophos service errors on a few machines which I've never seen before and wonder if they don't like being tampered with
Mic_Impero Posted August 24, 2018 Posted August 24, 2018 @gshaw Please follow the link below for our anti-virus exclusions advice. Thanks Mic https://bit.ly/ImperoEdProAntiVirusExc
gshaw Posted August 24, 2018 Posted August 24, 2018 @gshaw Please follow the link below for our anti-virus exclusions advice. Thanks Mic https://bit.ly/ImperoEdProAntiVirusExc @Mic_Impero already done this but my query is in the other direction - is Impero trying to inject *into* the AV process?
Mic_Impero Posted August 24, 2018 Posted August 24, 2018 Apologies, misunderstood. Yes it will do, I can't see any reason for it to do so though, so my advice would be to include the names in the injection exclusion list in the Impero server application. You may need a reboot at the client end for that to take place. Mic
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now