Jump to content

Koldov

Members
  • Posts

    5,084
  • Joined

  • Last visited

Everything posted by Koldov

  1. Try this: w32tm /config /manualpeerlist:uk.pool.ntp.org,0x8 /syncfromflags:manual /reliable:yes /update You might also have to stop and restart the time service. net stop w32time net start w32time Then: w32tm.exe /resync /rediscover /nowait I think it's going to be a little more complicated due to having a GPO undoing any manual set-up. I've never actually looked up 'best practise' but have certainly read many times not to sync time with the host, as far as I'm aware the PDC gets its time from NTP and all other 'on-domain' computers (whether they are VM or not) get their time from the PDC and nowhere else, as if they were getting their time from CMOS or host they could be different. There are a couple of posts on here about it: http://www.edugeek.net/forums/windows-server-2019/228381-ntp-gpo-workstations-not-listening.html http://www.edugeek.net/forums/windows-server-2012/223638-time-out-dc.html http://www.edugeek.net/forums/windows-server-2019/217637-windows-time-out-hour.html ~A bit more complicated but might turn out to be time related... http://www.edugeek.net/forums/windows-server-2016/220462-dc-issues.html And more here: https://community.spiceworks.com/topic/1682342-time-sync-best-practices-hyper-v EDIT: In w32tm /query /configuration the PDC should show 'Type: NTP (Local)' as above and every other 'on-domain' computer should show Type: 'NT5DS (Local)'. EDIT2: Then in w32tm /query /peers the PDC should show the NTP server and all other 'on-domain' computers should show the PDC.
  2. What does the Host CMOS time say (is that only visible on a reboot - I'm guessing so)...? Could the VM Host and its CMOS clock be different...? I can't understand why you are asking the Host OS to get the time from an NTP source (which sets the time for the Host OS) and then the VM to get the time from the Host's CMOS and it's blowing my mind a little... Anyway, our PDC (VM) has the following lines in w32tm /query /configuration: Type: NTP (Local) NtpServer: uk.pool.ntp.org,0x8 (Local) Also all domain clients show: Type: NT5DS (Local) Are your Hosts on the Domain? If not I understand why they are getting an external NTP source for their time (ours are and so still get the time from the PDC VM)? I had a bit of trouble a while ago (changed PDC and so time server) and had to manually set on a couple of clients: w32tm /config /syncfromflags:domhier /update net stop w32time net start w32time But the PDC always gets its time from an NTP source: w32tm /config /manualpeerlist:"uk.pool.ntp.org,0x8" /syncfromflags:manual /update I don't use a GPO as there is only one PDC I just did it manually.
  3. Could be wrong but I thought best practise was that as the PDC is the only one that is an authoritative time server for the domain, it should therefore be the only one pulling from an NTP source and obviously everything else gets the time from it. Definitely do not rely on HOST/CMOS and in fact make sure it is disabled between the HOST > VM settings (we use Hyper-V).
  4. The thing is those 50+ year old NQTs have probably had other jobs (which may have included computer use and possibly MS Office related although not necessarily). Not only that, but they will have gained a different (better?) work ethic, by having a job outside of a school. The teachers that have a greater grasp on things in general and a better view on work (in my experience) have been teachers who joined the profession later on in life, as if you think about it those others that are 'career' teachers have actually never 'left' school and I think that does have an effect on their 'job mentality'.... School > Uni > School I have always said (as is borne out by one or two teachers here insistence on complaining that their old Flash based resources no longer work) that a certain type of teacher is solely concerned with sticking to what they know and what works for them (I do have some sympathy with them if I'm honest as my Server 2012 R2 instances show). With most of their mindset (and working life) focussed on purely the job at hand... If you think that 08:30 - 15:30 of every working day will be taken up purely managing 30 little darlings and the evenings with marking/planning etc. Most of their time taken up with the actual T&L for the pupils and not expanding their own knowledgebase by learning new software or new products. 20-30 year olds have probably lived most of their life on an 'always on' iPad or some make of smartphone (possibly the cause of many 'why is this computer so slow', 'why can't I download X,Y or Z app' and 'why does it have to do updates all the time' complaints)...? I remember that a certain young NQT once told me that this was her first job and in all her training had never once been shown how to actually use an interactive whiteboard...
  5. Bit of a strange one and probably quite a rare scenario but... As well as a cloud back-up, we run a rotating USB set of disks for offline backups (basically important stuff like SIMS database and SLT drives to the cloud and staff data to USB). It is running via WSB on 2012R2 and I found a way to disable the USB on a scheduled tasks (the scheduled task calls 'Devcon.exe' and the argument is enable or disable *VID_XXXX*. , worked fine for a couple of years... but now this seems to have stopped working and I'm at a loss to find out why. The scheduled task runs, so no answers there and nothing shows in Event Viewer as an error... It also seems to be running as when I eject and swap the disks it doesn't appear (so I know it has been disabled) then it must enable the device (via scheduled task) at the correct time because the back-up does run... It just fails to disable the disk afterwards (therefore making susceptible to virus/malware encryption). Maybe the disk is going to 'sleep' or the USB settings (eject/safe remove/disk caching) are wrong somehow, but I don't think I've changed any setting for that recently. Also if anyone has a reliable (easy & free) way to accomplish the same thing, I'm listening.
  6. What a minefield finding a decent supplier with a website that doesn't seem hurriedly knocked up in Front Page... and is a generic site for loads of different suppliers (who are actually all the same supplier)... pretending to be in the UK. I've looked at original HP which are over £70! There are 2 types... https://partsurfer.hp.com/partsurfer?searchtext=919701-850 4-cell, 41-Whr, 2.8-Ah Li-ion battery part # 919701-851 and https://partsurfer.hp.com/partsurfer?searchtext=919700-850 3-cell, 31-Whr, 2.8-Ah Li-ion battery part # 919700-850 Basically just 3 & 4 cell versions, but you can't order what was the cheaper 3 cell anymore and other suppliers seem to have the numbers mixed up so you have to read the description very carefully... Anyway, my Business Manager isn't happy with that and has found some for about £20... he is saying they are all made in the same place (China), with the same materials, to the same specification... but the last couple he ordered (from a dodgy website while I was on holiday) never showed up and now he can't get an answer from them... I can't be bothered to Google exploding laptop batteries and show him, so I'd rather see if I can get a reasonable price from a reputable supplier and meet him halfway... Any proven suppliers with quality products?
  7. After my recent thread about a couple of laptops not installing the Summer update and deleting from SOLUS, then unistalling and reinstalling the agent... I now appear to have one of them listed twice! Both in: Environment > Targets > Clients and Environment > Agents > Targets I guess there was some sort of overlap whilst removing it from SOLUS and then with the uninstall/reinstall of the agent, but is it safe to delete one of them... if so which one (as they're identical) and does this mean there is an issue in the SOLUS database (as it normally won't let you put in a Target twice).
  8. Quick bump on this as having set the appropriate GPO (and verified in REG) I can still open IE11! Will the GPO only take affect if you have Edge installed (as I see that it is listed as a prerequisite) that can't be right can it...? https://docs.microsoft.com/en-us/deployedge/edge-ie-disable-ie11 You can't disable IE11 via GPO unless you have another MS browser installed...?
  9. Just a quick bump to this thread as it has happened again... not only that but it did it on a 'Preview' and not even a proper update (not what I want on prod servers.)! After a bit if research and reading between the lines, it appears that if you ever do a manual 'search' for updates, it will find them and install them and you can't stop it... From this post: https://community.spiceworks.com/topic/2281814-server-2019-dc-preview-updates-how-to-block#entry-8932658
  10. Thanks, that did the trick and I do now seem to remember doing something similar a few years ago.... Would be nice to have the code though as it appears it can be set to open the toner door when 'low' and then set back to 'empty' once it's changed. Have to see if I can catch the service engineer next time for a 'tech to tech' chat...
  11. Well, seems like the old removing the computer from SOLUS and manually uninstalling the Agent (then reinstalling from scratch in SOLUS) did the trick and got things moving... So, not Sophos at least!
  12. Yes we have Sophos.... and I had seen a couple of threads that pointed that way... It's just that it is only these 2 laptops having issues with SOLUS/SIMS out of the whole fleet (that all have Sophos installed) and all the others have been pretty seamless. Of course it doesn't mean it isn't that, just a bit random so it's hard to point the finger just yet and I know it will be a pain to get hold of the laptops to uninstall Sophos and test. EDIT: The SOLUS console also shows 'Copying Files' OK and 'Installation Complete' messages for the agent on 'Reinstall Agent', it just will then not communicate.
  13. **PM ONLY PLEASE** I have researched and found that the 10871087 or 5000 codes don't seem to work! Can anyone tell me any other default Engineer/Service code for the KYOCERA TASKALFA 5052ci to get to the U000 menu please....? We have a FULL waste toner warning and it will now not print, but the Black toner which is supposed to replace it still has 5% and will not release the toner door until it is empty...
  14. Did you get anywhere with this @superatticman ? I have two agents that stopped reporting into SOLUS on 25/04/2022 and I haven't pushed out any updates since then so I didn't notice. Now after the two laptops have tried to load the Summer update and failed, I tried to reinstall the agent and that stays as 'Install Active' and 'Get Target Version' and 'Check Status' fail with the following error:
  15. I did read previously that it was due for the Autumn release and so 'forgot' about it, but unfortunately haven't kept up with any changes! After a bit of research I can see now it has been advertised that the change would be in the Summer update... I can find an 'offline' (.exe) installer, but how to get .NET Framework 4.7.2 deployed out over the network...?
  16. Maybe this should go in the 'Annoying Things' thread.... grabbed as soon as I walked through the door.... First issue of the new school year at 08:30... Here we go! SIMS won't open on a few teacher laptops due to .NET Framework 4.7.2 not being installed. Although it was fine before we did the Summer update. I have a few laptops that have never been upgraded from the original install and new .NET versions aren't something I usually bother with unless a specific program requires it to run.
  17. Are these 'older' physical servers or VMs..? If physical, have you found any driver issues (raid controllers etc)? Also for the OP, is this what dedupe does, the file you may see in a users folder is a placeholder for the actual file. I think there would be other folders that need to be moved or it might just not work if the new Server doesn't have any way to know where he original file is. I don't use dedupe so not sure how it actually works, but found this: http://www.edugeek.net/forums/windows-server-2012/206816-why-dedup-folder-so-big.html Which talks about dedupe folders, chunkstore etc. It also has some other useful links to other info.
  18. Not entirely sure as I don't have access to that particular machine at the moment, seems it is a known issue though. EDIT: Just checked and there are still quite a few URLMON.DLL files on an affected machine. After some more research it appears that whilst Chrome was installed and made the default, in the registry this key still exists... [ATTACH=CONFIG]66207[/ATTACH] But there is a sub-key to this (shell\open\command) and when IE11 is uninstalled it removes that key completely and whatever was in that line disappears (maybe reinstalling Chrome would fix it)! As you can see this is a machine where Chrome was installed (and made default) and then IE11 was uninstalled... there is no reg key for the 'shell\open\command'. [ATTACH=CONFIG]66208[/ATTACH] Pointed out here (changes to the reg key are lost when IE11 is uninstalled as it removes the sub-key completely): https://www.tenforums.com/browsers-email/131138-removed-ie-now-i-cannot-open-hyperlinks-outlook-2010-a.html#post2008939 I'm a bit confused as to the relevance of HKEY_CLASSES_ROOT\htmlfile and HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\shell\open\command... as further up from that one post describes ROOT and then posts a picture of HKLM.... It probably requires a little more research... but I changed the HKLM reg key to point to Chrome and the Hyperlinks from Office now work, however on checking the reg key the 'Chrome' part has now disappeared, but Hyperlinks from Office still work... [ATTACH=CONFIG]66206[/ATTACH] ...maybe suggesting that whilst the key needs to be there, if nothing is entered it honours the OS default browser choice....?
  19. Glad I could be of service....
  20. So, fixed the boot loop and back onto this issue! Turns out it is also Word, Excel, Powerpoint... so basically all Office programs. It has been resolved by reinstalling IE11... Change default browser back to Chrome... Hyperlinks now open in Chrome... WTF M$?! All that work I did removing it from every machine in the building... yeah that!
  21. Turns out that seemed to be the issue (I completely uninstalled Wireshark), I've always been vary wary of installing 3rd party software on my servers (and now I'll be even more so). Safe mode didn't stop the boot loop unfortunately (but it did kill any chance of using RDP), luckily I live quite close so went in and did it. It was just NTLM in general I was looking at, as a setting I had to deny it (and which I'd had set for ages) obviously wasn't applying with our old 2012R2 DCs, now we've moved to 2019 it seems to have kicked in and killed scan to folder.
  22. Just a random thought.... Looking through the MEMORY.DMP it notes NDIS.SYS and a lot of Google results suggest NIC drivers need updating... but it has been solid for so long and any number of reboots before this happened... Then I saw a thread somewhere about NDIS.SYS causing BSOD and the answer was about the following: Replace: WinPcap to npcap Then it hit me, the only change I made to the server yesterday was updating Wireshark (which is probably not a good idea on a prod server but I was trying to deal with another error about NTLM being blocked stopping 'scan to folder')..... That also had references to WinPcap and npcap during the install! Here's an old GitHub thread with references: https://github.com/nmap/npcap/issues/565 Specifically: "Bluescreen (ndis.sys) on Windows 8.1 with npcap 1,60" "Hi, have the same issue. Fails in ndisCreateStringStreamEntry." "I have the same issue. Npcap 1.60 and Windows Server 2012 R2. I will send you a minidump. Oddly, this problem only started approximately 1 day after initial installation. Without Driver Verifier: The machine will bluescreen within a few minutes after rebooting with a SYSTEM_THREAD_EXCEPTION_NOT_HANDLED error with a reference to ndis.sys. With Driver Verifier: The machine will bluescreen within a few seconds after rebooting with a SYSTEM_THREAD_EXCEPTION_NOT_HANDLED error with no reference to any driver. I can confirm that "Raw 802.11 Packet Capture Support" seems to be the problem, as everything seems to work fine after I reinstalled without that option."
  23. Well, a bit bleary eyed this morning... I tried changing it to boot into safe mode with networking, but it didn't stop the boot loop, it did however stop me getting in via RDP... Then I tried to: Seize all FMSO roles to a different VM DC (luckily I went with 2 on different hosts) Clean-up Metadata Then remembering... Administrator isn't a member of Schema Admins (failed on last role seize) Create Time Server on new PDC Clean up of DNS might have to wait to see what I can salvage as it was a pain to change so if I can isolate the old VM PDC from the network I will demote and promote... I seem to have been able to remotely shutdown the host (so might save a bit of disk wear, until Monday morning when I can go in and assess the damage and start the real work... Luckily I got the MEMORY.DMP file first, I didn't have the time to get it from the server directly before the reboot but managed to get it to another server (as that was much quicker) and then copied it from there. I didn't have the store on my work laptop to get 'WinDbg Preview' so that was another issue to overcome trying to find in GitHub what file and what code to use (seems like it is fairly easy now though with no script or files to extract anymore), just a simple command.... genius whoever found that out! Worked for LTSC 2019, not entirely sure how much it enabled (Xbox crud, etc.) but it did the job. https://www.reddit.com/r/Windows10LTSC/comments/s88jre/guide_activateinstall_windows_store_without_an/ If anyone can make sense of the MEMORY.DMP file it is as follows: Microsoft (R) Windows Debugger Version 10.0.25136.1001 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\Users\Administrator\Desktop\MEMORY.DMP] Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available. ************* Path validation summary ************** Response Time (ms) Location Deferred srv* Symbol search path is: srv* Executable search path is: Windows 8.1 Kernel Version 9600 MP (16 procs) Free x64 Product: Server, suite: TerminalServer SingleUserTS Edition build lab: 9600.20475.amd64fre.winblue_ltsb_escrow.220622-1747 Machine Name: Kernel base = 0xfffff802`1de11000 PsLoadedModuleList = 0xfffff802`1e0d4650 Debug session time: Sat Aug 6 13:09:36.319 2022 (UTC + 1:00) System Uptime: 0 days 0:06:02.053 Loading Kernel Symbols ............................................................... ................................................................ ........................... Loading User Symbols Loading unloaded module list .... For analysis of this file, run !analyze -v nt!KeBugCheckEx: fffff802`1df504c0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffd000`21f222c0=000000000000007e 7: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e) This is a very common BugCheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffff800904c458f, The address that the exception occurred at Arg3: ffffd00021f23288, Exception Record Address Arg4: ffffd00021f22aa0, Context Record Address Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : AV.Dereference Value: NullPtr Key : AV.Fault Value: Read Key : Analysis.CPU.mSec Value: 3952 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 3961 Key : Analysis.Init.CPU.mSec Value: 3405 Key : Analysis.Init.Elapsed.mSec Value: 10096 Key : Analysis.Memory.CommitPeak.Mb Value: 88 Key : Bugcheck.Code.DumpHeader Value: 0x7e Key : Bugcheck.Code.KiBugCheckData Value: 0x7e Key : Bugcheck.Code.Register Value: 0x7e Key : WER.OS.Branch Value: winblue_ltsb_escrow Key : WER.OS.Timestamp Value: 2022-06-22T17:47:00Z Key : WER.OS.Version Value: 8.1.9600.20475 FILE_IN_CAB: MEMORY.DMP BUGCHECK_CODE: 7e BUGCHECK_P1: ffffffffc0000005 BUGCHECK_P2: fffff800904c458f BUGCHECK_P3: ffffd00021f23288 BUGCHECK_P4: ffffd00021f22aa0 EXCEPTION_RECORD: ffffd00021f23288 -- (.exr 0xffffd00021f23288) ExceptionAddress: fffff800904c458f (NDIS!ndisCreateStringStreamEntry+0x000000000000002f) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: 0000000000000000 Attempt to read from address 0000000000000000 CONTEXT: ffffd00021f22aa0 -- (.cxr 0xffffd00021f22aa0) rax=ffffd00021f23790 rbx=0000000000000015 rcx=ffffd00021f23540 rdx=ffffe00121e66ad8 rsi=ffffd00021f23680 rdi=ffffd00021f23540 rip=fffff800904c458f rsp=ffffd00021f234c0 rbp=0000000000000000 r8=ffffd00021f23680 r9=0000000000000000 r10=0000000000000000 r11=ffffd00021f23790 r12=fffff800904b1950 r13=ffffe0011e17c040 r14=ffffe00121e66990 r15=0000000000000000 iopl=0 nv up ei ng nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286 NDIS!ndisCreateStringStreamEntry+0x2f: fffff800`904c458f 66413929 cmp word ptr [r9],bp ds:002b:00000000`00000000=???? Resetting default scope PROCESS_NAME: System READ_ADDRESS: 0000000000000000 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s. EXCEPTION_CODE_STR: c0000005 EXCEPTION_PARAMETER1: 0000000000000000 EXCEPTION_PARAMETER2: 0000000000000000 EXCEPTION_STR: 0xc0000005 STACK_TEXT: ffffd000`21f234c0 fffff800`904c46a1 : 00000000`00000015 00000000`00000002 ffffe001`21e66ad8 ffffe001`2a1eea98 : NDIS!ndisCreateStringStreamEntry+0x2f ffffd000`21f234f0 fffff800`9043faa8 : ffffe001`21e66900 ffffd000`21f239d0 fffff800`904b2e00 ffffd000`21f239d0 : NDIS!ndisSqmLogDriverVersion+0xb9 ffffd000`21f238d0 fffff802`1de6a15f : fffff800`9043f958 fffff800`904b2ea8 00000000`00000000 fffff802`1e0ad4c0 : NDIS!ndisSqmTimerWorkerRoutine+0x150 ffffd000`21f23b50 fffff802`1dee27aa : ffffc000`000a0000 ffffd000`20fc0180 00000000`00000080 ffffe001`1d3968c0 : nt!ExpWorkerThread+0x69f ffffd000`21f23c00 fffff802`1df57f66 : ffffd000`20fc0180 ffffe001`1e17c040 ffffd000`20fd0680 00000000`00000000 : nt!PspSystemThreadStartup+0x18a ffffd000`21f23c60 00000000`00000000 : ffffd000`21f24000 ffffd000`21f1e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16 SYMBOL_NAME: NDIS!ndisCreateStringStreamEntry+2f MODULE_NAME: NDIS IMAGE_NAME: NDIS.SYS STACK_COMMAND: .cxr 0xffffd00021f22aa0 ; kb BUCKET_ID_FUNC_OFFSET: 2f FAILURE_BUCKET_ID: AV_NDIS!ndisCreateStringStreamEntry OS_VERSION: 8.1.9600.20475 BUILDLAB_STR: winblue_ltsb_escrow OSPLATFORM_TYPE: x64 OSNAME: Windows 8.1 FAILURE_ID_HASH: {a6009a6f-0469-bc4c-27f7-a8fa2f293092} Followup: MachineOwner ---------
  24. Strange... I had somehow got it into my head a while ago that it was MS 'security' best practise and 'recommended' thing to disable NTLM... I think there is a regular waring that comes up in my server event log saying so. Now I have completely trashed my server by poking it with a big stick trying to get it to do something I didn't even need to!
  25. Also this is going to hurt even more considering it is the SIMS server...
×
×
  • Create New...