<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Przemysław Łukawski&#039;s blog &#187; Windows Server 2008 and 2008 R2</title>
	<atom:link href="http://p-lider.lideve.eu/wordpress/?cat=5&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://p-lider.lideve.eu/wordpress</link>
	<description>Solutions for IT technical problems admins and developers may face with.</description>
	<lastBuildDate>Tue, 23 Sep 2014 18:29:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.2.22</generator>
	<item>
		<title>Windows registry autorun locations</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=159</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=159#comments</comments>
		<pubDate>Sun, 17 Nov 2013 12:14:46 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows 8]]></category>
		<category><![CDATA[Windows Explorer]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.lideve.eu/wordpress/?p=159</guid>
		<description><![CDATA[Many times people ask me to check their computers for malware or for the reason it is working slow. The first thing I do is to check all programs that automatically start with windows. Normally I remember 4 or 5 locations in registry where to look for such programs and almost all the time I [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Many times people ask me to check their computers for malware or for the reason it is working slow. The first thing I do is to check all programs that automatically start with windows. Normally I remember 4 or 5 locations in registry where to look for such programs and almost all the time I must search the internet for another ones. That made me to write this post, which will allow me to always have the full (or almost full) list about the registry locations for auto startup purpose in one place.</p>
<p>In the below table I described all of the registry locations I know which programs are using to start automatically with Windows:</p>
<style>
.descrcell {
	border: 1px solid #000000; 
	padding-top: 0cm; padding-bottom: 0.1cm; padding-left: 0.1cm; padding-right: 0.1cm;
}
.tablecell {
	border: 1px solid #000000;
	padding-top: 0cm;
	padding-bottom: 0.1cm;
	padding-left: 0.1cm;
	padding-right: 0cm;
}
</style>
<div style="overflow: auto; height:500px;">
<table width="707" cellspacing="0" cellpadding="4">
<colgroup>
<col width="15" />
<col width="360" />
<col width="200" /></colgroup>
<tbody>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><b>No.</b></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><b>Registry Location (<span style="color: #0047ff;">blue </span>ones are present in 64bit OS only)</b></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><b>Description</b></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">1</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">2</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when any user logs in. After execution<br />
the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">3</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunServices\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed as services when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">4</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed as services when any user logs in.<br />
After execution the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">5</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when current user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">6</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when current user logs in. After<br />
execution the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">7</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Used only by<br />
setup. A progress bar is being displayed.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">8</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 5 but<br />
applies to LOCAL SYSTEM user only.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">9</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKU\.Default\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 6 but<br />
applies to LOCAL SYSTEM user only.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">10</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows<br />
NT\CurrentVersion\Winlogon\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">Shell”<br />
and „Userinit” values contain file names separated<br />
with comma which are executed when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">11</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows<br />
NT\CurrentVersion\Winlogon\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">Shell”<br />
and „Userinit” values contain file names separated<br />
with comma which are executed when current user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">12</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Active<br />
Setup\Installed Components\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Active<br />
Setup\Installed Components\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All subkeys<br />
are evaluated for execution when any user logs in. The “StubPath”<br />
value under each subkey describes the program being run.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">13</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Control<br />
Panel\Desktop</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">SCRNSAVE.EXE”<br />
value is executed when screen saver is being displayed for current<br />
user.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">14</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\CurrentControlSet\Control\Session<br />
Manager\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">The<br />
„BootExecute” value is being executed at boot time.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">15</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\Control\WOW\cmdline</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Value is<br />
executed when 16 bit application is being run for all users.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">16</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\Control\WOW\wowcmdline</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Value is<br />
executed when 16 bit DOS application is being run for all users.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">17</span></p>
</td>
<td sclass="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Values<br />
contains GUID for COM library which is being run after explorer<br />
finished loading.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">18</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows<br />
NT\CurrentVersion\Windows\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">The „run”<br />
and „load” values are executed when current user logs<br />
in. </span></p>
<p lang="en-US">
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">19</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows<br />
NT\CurrentVersion\Windows\AppInit_DLLs</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Windows<br />
NT\CurrentVersion\Windows\AppInit_DLLs</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">AppInit_DLLs<br />
value contains dll file names separated with comma which are being<br />
loaded into every process being run in the system.</span></p>
<p lang="en-US"><span style=""><strong>IMPORTANT</strong>:<br />
Very dangerous entry used by many malware programs.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">20</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 5.<br />
Normally values are named here as numbers starting from „1”.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">21</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 1.<br />
Normally values are named here as numbers starting from „1”.</span></p>
</td>
</tr>
</tbody>
</table>
</div>
<p>Some information in the above table has been taken from this forum: <a href="https://forums.hak5.org/index.php?/topic/12112-registry-autostart-locations/">Registry AutoStart Locations</a></p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=159</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Restoring Selfimage&#8217;s partition image to a greater partition</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=115</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=115#comments</comments>
		<pubDate>Sun, 19 Dec 2010 12:26:06 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.rootnode.net/wordpress/?p=115</guid>
		<description><![CDATA[Sometimes you must restore you partition images made by programs like SelfImage to a greater partitions &#8211; for example after buying new greater hard drive and setting the partitions&#8217; sizes to greater values as they were in original drive. The problem with such operation is that after restoring for example 20GB partition image to a partition which has [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Sometimes you must restore you partition images made by programs like SelfImage to a greater partitions &#8211; for example after buying new greater hard drive and setting the partitions&#8217; sizes to greater values as they were in original drive.</p>
<p>The problem with such operation is that after restoring for example 20GB partition image to a partition which has 40GB, you will see, that the file system says that there is only 20GB of total partition&#8217;s space. This is caused due to old partition size information saved inside internal filesystem&#8217;s structures, which was made during the format of the partition on the original drive. Fortunately, the DISKPART utility built in Windows XP and newer systems can fix that problem. To do that follow the following steps after you restore the image to the new, reater partition:</p>
<ol>
<li>Launch the <em>diskpart</em> command line utility.</li>
<li>Execute &#8220;select volume &lt;number&gt;&#8221; command, where &#8220;&lt;number&gt;&#8221; is a number of the volume containing the restored partition image (the list of all volumes and their numbers can be retrieved by executing &#8220;list volume&#8221; command).</li>
<li>Execute &#8220;extend filesystem&#8221; command.</li>
<li>And this is all &#8211; now exit the diskpart utility by executing &#8220;exit&#8221; command and the system will correctly see the real partition size.</li>
</ol>
<p>Thanks to this tip you can use programs like SelfImage not only for making backups but also for moving entire partitions (including system partitions) to other hard drives even, when they size do not match.</p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=115</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>HYPER-V and wrong time measurement in virtual servers</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=109</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=109#comments</comments>
		<pubDate>Fri, 03 Dec 2010 14:42:12 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[HYPER-V]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.rootnode.net/wordpress/?p=109</guid>
		<description><![CDATA[If you have a virtual server which has more than 1 virtual processor and is hosted by HYPER-V technology then you can face problems during time measurement. As the result you can see that login to such server can take quite long time and you can see strange errors in EventViewer saying something like “Windows cannot [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>If you have a virtual server which has more than 1 virtual processor and is hosted by HYPER-V technology then you can face problems during time measurement. As the result you can see that login to such server can take quite long time and you can see strange errors in EventViewer saying something like “Windows cannot obtain the domain controller name for your computer network” etc.</p>
<p>The solution to such problems is quite easy – you only have to add <strong><em>/usepmtimer</em></strong> switch to your server’s <em>boot.ini</em> file and restart the virtual server. This will cause a different approach during time measurement and will fix mentioned problems.</p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=109</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VPN connection and internal DNS names</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=106</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=106#comments</comments>
		<pubDate>Fri, 03 Dec 2010 14:31:57 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.rootnode.net/wordpress/?p=106</guid>
		<description><![CDATA[Sometimes after you connect to your VPN network by means of any VPN client (CiscoVPN, OpenVPN, etc.) you are not able to access network resources using their names, however you can access them using IP addresses. This is caused by the DnsCache service, which sometimes may cache wrong IP addresses for your internal network names. [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Sometimes after you connect to your VPN network by means of any VPN client (CiscoVPN, OpenVPN, etc.) you are not able to access network resources using their names, however you can access them using IP addresses. This is caused by the DnsCache service, which sometimes may cache wrong IP addresses for your internal network names.</p>
<p>To fix this irritating behavior clearing the dnscache will not always work. The best way to cope with this problem is to stop DnsCache service – after doing that every time you try access any network resource by its name, the DNS name query will be passed directly to your DNS servers omitting your local cache.</p>
<p>EDIT:</p>
<p>After some time I noticed one more problem with DNS especially when using VPNs established using RRAS. Simply the names were not being resolved by DNS servers provided by RRAS but they were trying to be resolved by DNS servers outside of VPN. This prevented accessing VPN network resources using names. The problem can be fixed by following the following steps:</p>
<ol>
<li>Go to Network Connections in Control Panel.</li>
<li>Go to Menu: Advanced -&gt; Advanced Settings -&gt; Adapters &amp; Bindings</li>
<li>Move DialUp connections to the top of the list.</li>
<li>Save changes by clisking OK button.</li>
<li>In Windows XP &amp; 2k also follow the instructions described under the following link: <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;311218">http://support.microsoft.com/default.aspx?scid=kb;en-us;311218</a></li>
<li>Reboot your computer.</li>
</ol>
<p>After performing the above operations you should not have any DNS issues when using VPNs on your computer.</p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=106</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing OS using DRAC cards having damaged DVD with OS physically inserted into server&#8217;s DVD-ROM.</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=102</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=102#comments</comments>
		<pubDate>Sun, 07 Nov 2010 13:54:26 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>

		<guid isPermaLink="false">http://p-lider.rootnode.net/wordpress/?p=102</guid>
		<description><![CDATA[If your server is equipped with DRAC card and you have also a DVD with an operating system inserted into server&#8217;s DVD-ROM, installing the OS remotely is quite an easy operation. However, problems occur when the inserted DVD is damaged and makes the OS installer to stop &#8211; without physical presence in the server room, you [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>If your server is equipped with DRAC card and you have also a DVD with an operating system inserted into server&#8217;s DVD-ROM, installing the OS remotely is quite an easy operation. However, problems occur when the inserted DVD is damaged and makes the OS installer to stop &#8211; without physical presence in the server room, you will have to install the OS using Virtually mounted DVD through network. There would be no problem with that if the Windows Installer would be ignorring the inserted physical DVD &#8211; unfortunately it does not ignore it.</p>
<p>So even when you request the server to boot from Virtual media, during the installation the Windows Installer will be using the physically inserted DVD as a source. To avoid that sick behavior you have to disable any optical drives in server&#8217;s BIOS setup for the time of installation.  After disabling them, Windows Installer will look for source files only on virtual media and not on physical DVD allowing you to successfully install the OS.</p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=102</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
