Home
%3CLINGO-SUB%20id%3D%22lingo-sub-723866%22%20slang%3D%22en-US%22%3EThe%20Case%20of%20the%20Slow%20Logons%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-723866%22%20slang%3D%22en-US%22%3E%0A%20%26lt%3Bmeta%20http-equiv%3D%22Content-Type%22%20content%3D%22text%2Fhtml%3B%20charset%3DUTF-8%22%20%2F%26gt%3B%3CSTRONG%3E%20First%20published%20on%20TechNet%20on%20Jan%2012%2C%202010%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%3CP%3E%3CEM%3E%20Update%3A%26nbsp%3B%20The%20Active%20Directory%20team%20has%20released%20useful%20guides%20for%20troubleshooting%20slow%20logon%20issues%3A%20%3C%2FEM%3E%3C%2FP%3E%0A%20%20%3CUL%3E%0A%20%20%20%3CLI%3E%3CA%20href%3D%22http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10130.root-causes-for-slow-boots-and-logons.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20%3CEM%3E%20http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10130.root-causes-for-slow-boots-and-logons.aspx%20%3C%2FEM%3E%20%3C%2FA%3E%3C%2FLI%3E%0A%20%20%20%3CLI%3E%3CA%20href%3D%22http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10128.tools-for-troubleshooting-slow-boots-and-slow-logons.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20%3CEM%3E%20http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10128.tools-for-troubleshooting-slow-boots-and-slow-logons.aspx%20%3C%2FEM%3E%20%3C%2FA%3E%3C%2FLI%3E%0A%20%20%20%3CLI%3E%3CA%20href%3D%22http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10123.troubleshooting-slow-operating-system-boot-times-and-slow-user-logons.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20%3CEM%3E%20http%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F10123.troubleshooting-slow-operating-system-boot-times-and-slow-user-logons.aspx%20%3C%2FEM%3E%20%3C%2FA%3E%3C%2FLI%3E%0A%20%20%3C%2FUL%3E%0A%20%20%3CP%3EEmails%20containing%20troubleshooting%20cases%20keep%20arriving%20in%20my%20inbox.%20I%E2%80%99ve%20received%20many%20cases%20that%20start%20with%20a%20seemingly%20unsolvable%20problem%20and%20end%20a%20few%20steps%20later%20with%20a%20solution%20or%20-%20often%20just%20as%20useful%20-%20a%20workaround.%20I%E2%80%99ve%20amassed%20several%20hundred%20such%20cases%20that%20I%E2%80%99ve%20captured%20in%20over%20400%20PowerPoint%20slides%2C%20giving%20me%20great%20material%20from%20which%20to%20draw%20for%20my%20blog%20and%20the%20%3CEM%3E%20Case%20of%20the%20Unexplained%20%3C%2FEM%3E%20%3CEM%3E%20talk%20series%20%3C%2FEM%3E%20%3CEM%3E%20%3C%2FEM%3E%20I%E2%80%99ve%20delivered%20at%20a%20number%20of%20major%20industry%20conferences%3C%2FP%3E%0A%20%20%3CP%3EI%E2%80%99m%20always%20looking%20for%20fresh%20cases%2C%20use%20of%20obscure%20tool%20features%2C%20and%20unique%20troubleshooting%20techniques%2C%20so%20please%20keep%20them%20coming.%20This%20time%2C%20I%E2%80%99m%20sharing%20a%20fascinating%20case%20that%20highlights%20two%20useful%20techniques%3A%20comparing%20Sysinternals%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Fsysinternals%2Fbb896645.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20Process%20Monitor%20%3C%2FA%3E%20logs%20from%20working%20and%20problematic%20systems%2C%20and%20using%20Sysinternals%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Fsysinternals%2Fbb897553.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20PsExec%20%3C%2FA%3E%20to%20capture%20activity%20during%20a%20logon.%3C%2FP%3E%0A%20%20%3CP%3EThe%20case%20begins%20when%20a%20systems%20administrator%20at%20a%20large%20company%20got%20multiple%20end-user%20complaints%20that%20logon%20was%20taking%20over%20three%20minutes.%20The%20users%20didn%E2%80%99t%20encounter%20any%20problems%20once%20logged%20on%2C%20but%20the%20delays%20were%20understandably%20frustrating.%20Many%20other%20users%20running%20with%20the%20same%20software%20configuration%20weren%E2%80%99t%20experiencing%20issues%2C%20however.%20Looking%20for%20commonalities%2C%20the%20administrator%20queried%20the%20network%20configuration%20database%20and%2C%20sure%20enough%2C%20saw%20that%20all%20the%20systems%20with%20complaints%20were%20Dell%20Precision%20670%20workstations.%20He%20thought%20he%20had%20a%20major%20clue%20until%20he%20looked%20he%20saw%20that%20the%20systems%20running%20without%20issue%20included%20seemingly%20identical%20670%20workstations.%3C%2FP%3E%0A%20%20%3CP%3ELooking%20for%20clues%20more%20directly%2C%20his%20next%20step%20was%20to%20try%20to%20analyze%20the%20logon%20process%20of%20the%20delayed%20systems.%20He%20used%20PsExec%20to%20run%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Fsysinternals%2Fbb896653.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20Process%20Explorer%20%3C%2FA%3E%20in%20the%20Local%20System%20account%20so%20that%20it%20would%20survive%20a%20logoff%20and%20be%20active%20at%20the%20next%20logon.%20Because%20the%20systems%20were%20running%20Windows%20XP%2C%20the%20command-line%20he%20used%20was%20the%20following%20(see%20the%20end%20of%20the%20post%20for%20how%20to%20do%20this%20on%20Windows%20Vista%20and%20higher)%3A%3C%2FP%3E%0A%20%20%3CBLOCKQUOTE%3E%0A%20%20%20%3CP%3E%3CFONT%20face%3D%22cour%22%3E%20psexec%20%E2%80%93sid%20c%3A%5Csysint%5Cprocexp.exe%20%3C%2FFONT%3E%3C%2FP%3E%0A%20%20%3C%2FBLOCKQUOTE%3E%0A%20%20%3CP%3EThe%20%E2%80%9C-s%E2%80%9D%20directs%20PsExec%20to%20launch%20the%20process%20in%20the%20Local%20System%20account%2C%20%E2%80%9C%E2%80%93i%E2%80%9D%20to%20connect%20the%20process%20with%20the%20interactive%20desktop%20so%20that%20its%20windows%20are%20visible%2C%20and%20%E2%80%9C-d%E2%80%9D%20to%20return%20immediately%20instead%20of%20waiting%20for%20the%20process%20to%20terminate.%20Note%20that%20if%20you%20have%20Fast%20User%20Switching%20enabled%20and%20you%20are%20not%20logged%20into%20session%200%2C%20do%20not%20log%20out%2C%20but%20instead%20switch%20users%2C%20login%20to%20the%20problematic%20account%2C%20and%20then%20switch%20back%20to%20the%20session%20from%20which%20you%20started%20PsExec.%3C%2FP%3E%0A%20%20%3CP%3EAt%20the%20subsequent%20logon%2C%20he%20noticed%20that%20Lisa_client_7.0.0.0.exe%2C%20the%20company%E2%80%99s%20own%20system%20inventory%20line-of-business%20(LoB)%20application%2C%20consumed%20CPU%20for%20a%20short%20time%2C%20went%20idle%20for%20three%20minutes%2C%20then%20exited%2C%20after%20which%20the%20logon%20process%20would%20continue%20as%20normal%3A%3C%2FP%3E%0A%20%20%3CP%3E%3CIMG%20alt%3D%22image%22%20border%3D%220%22%20height%3D%2271%22%20original-url%3D%22http%3A%2F%2Fblogs.technet.com%2Fblogfiles%2Fmarkrussinovich%2FWindowsLiveWriter%2FTheCaseoftheLogonScriptHangs_CCDE%2Fimage_thumb.png%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F121187i7B5DB4CE1BABDBDE%22%20style%3D%22border-right-width%3A%200px%3B%20display%3A%20inline%3B%20border-top-width%3A%200px%3B%20border-bottom-width%3A%200px%3B%20border-left-width%3A%200px%22%20title%3D%22image%22%20width%3D%22554%22%20%2F%3E%3C%2FP%3E%0A%20%20%3CP%3E%3CA%20href%3D%22http%3A%2F%2Fwww.solsem.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3EDavid%20Solomon%20%3C%2FA%3E%20coined%20a%20phrase%20back%20before%20Process%20Monitor%20replaced%20Filemon%20and%20Regmon%20that%20still%20applies%20when%20updated%3A%20%E2%80%9CWhen%20in%20doubt%2C%20run%20Process%20Monitor!%E2%80%9D%20(I%20follow%20this%20advice%20religiously%2C%20even%20having%20my%20daughter%20run%20Process%20Monitor%20when%20she%20comes%20to%20me%20with%20a%20homework%20question).%20This%20case%20is%20a%20great%20example%20of%20that%20philosophy%20put%20into%20practice%20because%20it%20seems%20unlikely%20on%20the%20surface%20that%20Process%20Monitor%20would%20reveal%20the%20cause%20for%20a%20process%20hang%2C%20but%20the%20administrator%20turned%20to%20the%20tool%20nonetheless.%3C%2FP%3E%0A%20%20%3CP%3EAfter%20launching%20Process%20Monitor%20with%20PsExec%20and%20capturing%20a%20logon%20trace%2C%20he%20scrolled%20to%20the%20beginning%20of%20the%20captured%20data%20and%20started%20his%20analysis.%20Because%20of%20what%20he%20saw%20in%20Process%20Explorer%2C%20the%20Lisa_client%20process%20was%20the%20obvious%20suspect%2C%20so%20he%20right-clicked%20on%20its%20process%20name%20in%20one%20of%20the%20trace%20lines%20and%20selected%20the%20%3CEM%3E%20Include%20%3C%2FEM%3E%20quick-filter%20menu%20item%20to%20remove%20from%20the%20display%20entries%20related%20to%20activity%20from%20other%20processes%3A%3C%2FP%3E%0A%20%20%3CP%3E%3CIMG%20alt%3D%22image%22%20border%3D%220%22%20height%3D%22219%22%20original-url%3D%22http%3A%2F%2Fblogs.technet.com%2Fblogfiles%2Fmarkrussinovich%2FWindowsLiveWriter%2FTheCaseoftheLogonScriptHangs_CCDE%2Fimage_thumb_2.png%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F121188i5E0D82F9D2D589BB%22%20style%3D%22border-right-width%3A%200px%3B%20display%3A%20inline%3B%20border-top-width%3A%200px%3B%20border-bottom-width%3A%200px%3B%20border-left-width%3A%200px%22%20title%3D%22image%22%20width%3D%22249%22%20%2F%3E%3C%2FP%3E%0A%20%20%3CP%3EWhen%20troubleshooting%20a%20hang%20with%20Process%20Monitor%2C%20you%20should%20first%20see%20if%20there%20are%20any%20gaps%20in%20operation%20time%20stamps%20that%20match%20the%20hang%20duration.%20You%20can%20look%20for%20lengthy%20operations%20by%20adding%20the%20%3CEM%3E%20Duration%20%3C%2FEM%3E%20column%20to%20the%20display%20and%20then%20making%20sure%20to%20filter%20out%20operations%20that%20commonly%20don%E2%80%99t%20immediately%20complete%2C%20like%20directory%20change%20notifications.%20That%20can%20be%20useful%20when%20you%20don%E2%80%99t%20see%20a%20significant%20time%20gap%20between%20operations%20because%20the%20process%20has%20multiple%20threads%2C%20some%20of%20which%20continue%20to%20operate%20while%20the%20one%20causing%20the%20hang%20is%20dormant.%3C%2FP%3E%0A%20%20%3CP%3ETo%20his%20pleasant%20surprise%2C%20he%20soon%20found%20an%20event%20that%20not%20only%20preceded%20a%20gap%20of%20exactly%20three%20minutes%2C%20but%20that%20had%20an%20unusual%20result%20code%2C%20IO%20DEVICE%20ERROR%3A%3C%2FP%3E%0A%20%20%3CP%3E%3CIMG%20alt%3D%22image%22%20border%3D%220%22%20height%3D%2269%22%20original-url%3D%22http%3A%2F%2Fblogs.technet.com%2Fblogfiles%2Fmarkrussinovich%2FWindowsLiveWriter%2FTheCaseoftheLogonScriptHangs_CCDE%2Fimage_thumb_3.png%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F121189i50F5ECEA30C99E68%22%20style%3D%22border-right-width%3A%200px%3B%20display%3A%20inline%3B%20border-top-width%3A%200px%3B%20border-bottom-width%3A%200px%3B%20border-left-width%3A%200px%22%20title%3D%22image%22%20width%3D%22554%22%20%2F%3E%3C%2FP%3E%0A%20%20%3CP%3EIt%20appeared%20that%20the%20Lisa_client%20process%20performed%20a%20SCSI%20pass-through%20command%20to%20the%20disk%20hosting%20the%20C%3A%20volume%20that%20timed-out%20after%20three%20minutes%20with%20a%20hardware%20error.%20Wondering%20what%20the%20result%20of%20the%20command%20was%20on%20one%20of%20the%20670%E2%80%99s%20that%20logged%20on%20promptly%2C%20he%20captured%20a%20trace%20from%20one%20and%20saw%20that%20the%20corresponding%20operation%20took%20less%20than%20a%20millisecond%20and%20was%20successful%3A%3C%2FP%3E%0A%20%20%3CP%3E%3CIMG%20alt%3D%22image%22%20border%3D%220%22%20height%3D%2266%22%20original-url%3D%22http%3A%2F%2Fblogs.technet.com%2Fblogfiles%2Fmarkrussinovich%2FWindowsLiveWriter%2FTheCaseoftheLogonScriptHangs_CCDE%2Fimage_thumb_6.png%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F121190iB5795B5951144D51%22%20style%3D%22border-right-width%3A%200px%3B%20display%3A%20inline%3B%20border-top-width%3A%200px%3B%20border-bottom-width%3A%200px%3B%20border-left-width%3A%200px%22%20title%3D%22image%22%20width%3D%22554%22%20%2F%3E%3C%2FP%3E%0A%20%20%3CP%3EThe%20evidence%20clearly%20pointed%20at%20a%20hardware%20issue%20with%20the%20disks%20installed%20on%20a%20subset%20of%20the%20670%E2%80%99s%2C%20so%20he%20gathered%20disk%20type%20data%20from%20all%20the%20670%E2%80%99s%2C%20correlated%20them%20with%20the%20reports%20of%20slow%20logons%2C%20and%20found%20that%20all%20of%20the%20slow%20systems%20had%20Seagate%20disks%20and%20the%20others%20had%20Fujitsu%20disks.%3C%2FP%3E%0A%20%20%3CP%3EHis%20company%20was%20obviously%20not%20going%20to%20replace%20disks%20just%20to%20avoid%20an%20issue%20being%20caused%20by%20its%20own%20LoB%20application%2C%20so%20he%20had%20to%20figure%20out%20a%20workaround.%20He%20notified%20the%20Lisa_client%20development%20team%20of%20the%20issue%2C%20who%20reported%20that%20they%20could%20remove%20the%20command%20without%20loss%20of%20functionality%2C%20but%20that%20it%20would%20take%20at%20least%20several%20days%20for%20the%20update%20to%20go%20through%20their%20internal%20release%20process.%20Having%20a%20few%20days%20where%20system%20information%20wouldn%E2%80%99t%20be%20collected%20for%20a%20subset%20of%20systems%20was%20less%20important%20than%20end-user%20productivity%2C%20so%20in%20the%20meantime%20he%20wrote%20a%20WMI%20logon%20script%20to%20query%20the%20system%20disk%20and%20launch%20Lisa_client%20only%20if%20it%20wasn%E2%80%99t%20a%20Seagate%20model.%3C%2FP%3E%0A%20%20%3CP%3EWithout%20Process%20Monitor%E2%80%99s%20help%20he%20would%20have%20probably%20determined%20that%20the%20disks%20were%20the%20key%20hardware%20difference%2C%20but%20it%E2%80%99s%20not%20clear%20he%20would%20have%20discovered%20the%20root%20cause%20and%20been%20able%20to%20work%20around%20it%20rather%20than%20resort%20to%20replacing%20disks.%20This%20is%20yet%20another%20case%20solved%20with%20the%20help%20of%20Process%20Monitor%20and%20insightful%20detective%20work.%3C%2FP%3E%0A%20%20%3CP%3EIn%20closing%2C%20I%20mentioned%20that%20I%20would%20provide%20steps%20for%20configuring%20an%20application%20to%20survive%20logoff%20and%20logon%20on%20Windows%20Vista%2C%20Windows%20Server%202008%20and%20higher.%20The%20PsExec%20command%20I%20supplied%20for%20Windows%20XP%20won%E2%80%99t%20work%20on%20newer%20operating%20systems%20because%20Windows%20Vista%20introduced%20%3CA%20href%3D%22http%3A%2F%2Fwww.microsoft.com%2Fwhdc%2Fsystem%2Fsysinternals%2FSession0Changes.mspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20Session%200%20Isolation%20%3C%2FA%3E%20%2C%20requiring%20a%20couple%20of%20extra%20commands%20to%20make%20the%20launched%20application%20accessible%20after%20a%20logon.%20First%2C%20start%20the%20utility%20in%20session%200%20with%20this%20PsExec%20command%20in%20an%20elevated%20command%20prompt%3A%3C%2FP%3E%0A%20%20%3CBLOCKQUOTE%3E%0A%20%20%20%3CP%3E%3CFONT%20face%3D%22cour%22%3E%20psexec%20%E2%80%93sd%20%E2%80%93i%200%20c%3A%5Csysint%5Cprocmon.exe%20%3C%2FFONT%3E%3C%2FP%3E%0A%20%20%3C%2FBLOCKQUOTE%3E%0A%20%20%3CP%3EYou%E2%80%99ll%20see%20a%20window%20titled%20%E2%80%9CInteractive%20services%20dialog%20detection%E2%80%9D%20flash%20in%20the%20taskbar%2C%20indicating%20that%20a%20process%20is%20running%20with%20a%20window%20on%20the%20hidden%20session%200%20desktop.%20Click%20on%20the%20taskbar%20window%20to%20restore%20the%20notification%20dialog%20and%20then%20on%20the%20Show%20Me%20the%20Message%20button%20to%20switch%20to%20that%20desktop%3A%3C%2FP%3E%0A%20%20%3CP%3E%3CIMG%20alt%3D%22image%22%20border%3D%220%22%20height%3D%22201%22%20original-url%3D%22http%3A%2F%2Fblogs.technet.com%2Fblogfiles%2Fmarkrussinovich%2FWindowsLiveWriter%2FTheCaseoftheLogonScriptHangs_CCDE%2Fimage_thumb_7.png%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F121191iCCEDABBC5CD8B844%22%20style%3D%22border-right-width%3A%200px%3B%20display%3A%20inline%3B%20border-top-width%3A%200px%3B%20border-bottom-width%3A%200px%3B%20border-left-width%3A%200px%22%20title%3D%22image%22%20width%3D%22404%22%20%2F%3E%3C%2FP%3E%0A%20%20%3CP%3EThe%20utility%20you%20launched%20will%20be%20visible%20there%20and%20you%20can%20configure%20it%20with%20desired%20settings%20(it%E2%80%99s%20running%20in%20the%20Local%20System%20account%20so%20won%E2%80%99t%20have%20your%20own%20account%E2%80%99s%20defaults).%20When%20done%2C%20click%20on%20the%20Return%20button%20to%20get%20back%20to%20the%20main%20desktop.%20You%20can%20now%20logoff%20and%20log%20back%20on%20to%20reproduce%20the%20problem%20you%E2%80%99re%20investigating.%20After%20logging%20on%20again%2C%20execute%20the%20following%20commands%20in%20an%20elevated%20command%20prompt%20to%20cause%20the%20doorway%20to%20the%20session%200%20desktop%20to%20reappear%3A%3C%2FP%3E%0A%20%20%3CBLOCKQUOTE%3E%0A%20%20%20%3CP%3E%3CFONT%20face%3D%22cour%22%3Enet%20stop%20ui0detect%20%3CBR%20%2F%3E%20%3C%2FFONT%3E%20%3CFONT%20face%3D%22cour%22%3E%20net%20start%20ui0detect%3C%2FFONT%3E%3C%2FP%3E%0A%20%20%3C%2FBLOCKQUOTE%3E%0A%20%20%3CP%3EGo%20back%20to%20the%20session%200%20desktop%20to%20look%20at%20the%20captured%20information%20and%20close%20the%20tool.%3C%2FP%3E%0A%20%20%3CP%3EOne%20last%20thing%20I%20want%20to%20leave%20you%20with%20is%20a%20reminder%20that%20I%E2%80%99ve%20documented%20many%20other%20troubleshooting%20cases%20in%20this%20blog%20and%20you%20can%20find%20them%20in%20the%20blog%20index%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Fsysinternals%2Fbb963890.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20here%20%3C%2FA%3E%20.%20You%20can%20also%20watch%20recordings%20of%20my%20%3CEM%3E%20Case%20of%20the%20Unexplained%20%3C%2FEM%3E%20sessions%20from%20TechEd%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Fsysinternals%2Fbb963887.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3E%20here%20%3C%2FA%3E%20and%20be%20sure%20to%20come%20to%20%3CA%20href%3D%22http%3A%2F%2Fnorthamerica.msteched.com%2F%3FCR_CC%3D100280253%26amp%3BWT.srch%3D1%26amp%3BCR_SCC%3D100280253%26amp%3BWT.srch%3D1%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%20TechEd%20US%20this%20June%20in%20New%20Orleans%20%3C%2FA%3E%20%2C%20where%20I%E2%80%99ll%20be%20delivering%20it%20again%20with%20all%20new%20cases.%3C%2FP%3E%0A%20%0A%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-723866%22%20slang%3D%22en-US%22%3EFirst%20published%20on%20TechNet%20on%20Jan%2012%2C%202010%20Update%3A%26nbsp%3B%20The%20Active%20Directory%20team%20has%20released%20useful%20guides%20for%20troubleshooting%20slow%20logon%20issues%3A%20http%3A%2F%2Fsocial.%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-723866%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMark%20Russinovich%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft
First published on TechNet on Jan 12, 2010

Update:  The Active Directory team has released useful guides for troubleshooting slow logon issues:

Emails containing troubleshooting cases keep arriving in my inbox. I’ve received many cases that start with a seemingly unsolvable problem and end a few steps later with a solution or - often just as useful - a workaround. I’ve amassed several hundred such cases that I’ve captured in over 400 PowerPoint slides, giving me great material from which to draw for my blog and the Case of the Unexplained talk series I’ve delivered at a number of major industry conferences

I’m always looking for fresh cases, use of obscure tool features, and unique troubleshooting techniques, so please keep them coming. This time, I’m sharing a fascinating case that highlights two useful techniques: comparing Sysinternals Process Monitor logs from working and problematic systems, and using Sysinternals PsExec to capture activity during a logon.

The case begins when a systems administrator at a large company got multiple end-user complaints that logon was taking over three minutes. The users didn’t encounter any problems once logged on, but the delays were understandably frustrating. Many other users running with the same software configuration weren’t experiencing issues, however. Looking for commonalities, the administrator queried the network configuration database and, sure enough, saw that all the systems with complaints were Dell Precision 670 workstations. He thought he had a major clue until he looked he saw that the systems running without issue included seemingly identical 670 workstations.

Looking for clues more directly, his next step was to try to analyze the logon process of the delayed systems. He used PsExec to run Process Explorer in the Local System account so that it would survive a logoff and be active at the next logon. Because the systems were running Windows XP, the command-line he used was the following (see the end of the post for how to do this on Windows Vista and higher):

psexec –sid c:\sysint\procexp.exe

The “-s” directs PsExec to launch the process in the Local System account, “–i” to connect the process with the interactive desktop so that its windows are visible, and “-d” to return immediately instead of waiting for the process to terminate. Note that if you have Fast User Switching enabled and you are not logged into session 0, do not log out, but instead switch users, login to the problematic account, and then switch back to the session from which you started PsExec.

At the subsequent logon, he noticed that Lisa_client_7.0.0.0.exe, the company’s own system inventory line-of-business (LoB) application, consumed CPU for a short time, went idle for three minutes, then exited, after which the logon process would continue as normal:

image

David Solomon coined a phrase back before Process Monitor replaced Filemon and Regmon that still applies when updated: “When in doubt, run Process Monitor!” (I follow this advice religiously, even having my daughter run Process Monitor when she comes to me with a homework question). This case is a great example of that philosophy put into practice because it seems unlikely on the surface that Process Monitor would reveal the cause for a process hang, but the administrator turned to the tool nonetheless.

After launching Process Monitor with PsExec and capturing a logon trace, he scrolled to the beginning of the captured data and started his analysis. Because of what he saw in Process Explorer, the Lisa_client process was the obvious suspect, so he right-clicked on its process name in one of the trace lines and selected the Include quick-filter menu item to remove from the display entries related to activity from other processes:

image

When troubleshooting a hang with Process Monitor, you should first see if there are any gaps in operation time stamps that match the hang duration. You can look for lengthy operations by adding the Duration column to the display and then making sure to filter out operations that commonly don’t immediately complete, like directory change notifications. That can be useful when you don’t see a significant time gap between operations because the process has multiple threads, some of which continue to operate while the one causing the hang is dormant.

To his pleasant surprise, he soon found an event that not only preceded a gap of exactly three minutes, but that had an unusual result code, IO DEVICE ERROR:

image

It appeared that the Lisa_client process performed a SCSI pass-through command to the disk hosting the C: volume that timed-out after three minutes with a hardware error. Wondering what the result of the command was on one of the 670’s that logged on promptly, he captured a trace from one and saw that the corresponding operation took less than a millisecond and was successful:

image

The evidence clearly pointed at a hardware issue with the disks installed on a subset of the 670’s, so he gathered disk type data from all the 670’s, correlated them with the reports of slow logons, and found that all of the slow systems had Seagate disks and the others had Fujitsu disks.

His company was obviously not going to replace disks just to avoid an issue being caused by its own LoB application, so he had to figure out a workaround. He notified the Lisa_client development team of the issue, who reported that they could remove the command without loss of functionality, but that it would take at least several days for the update to go through their internal release process. Having a few days where system information wouldn’t be collected for a subset of systems was less important than end-user productivity, so in the meantime he wrote a WMI logon script to query the system disk and launch Lisa_client only if it wasn’t a Seagate model.

Without Process Monitor’s help he would have probably determined that the disks were the key hardware difference, but it’s not clear he would have discovered the root cause and been able to work around it rather than resort to replacing disks. This is yet another case solved with the help of Process Monitor and insightful detective work.

In closing, I mentioned that I would provide steps for configuring an application to survive logoff and logon on Windows Vista, Windows Server 2008 and higher. The PsExec command I supplied for Windows XP won’t work on newer operating systems because Windows Vista introduced Session 0 Isolation , requiring a couple of extra commands to make the launched application accessible after a logon. First, start the utility in session 0 with this PsExec command in an elevated command prompt:

psexec –sd –i 0 c:\sysint\procmon.exe

You’ll see a window titled “Interactive services dialog detection” flash in the taskbar, indicating that a process is running with a window on the hidden session 0 desktop. Click on the taskbar window to restore the notification dialog and then on the Show Me the Message button to switch to that desktop:

image

The utility you launched will be visible there and you can configure it with desired settings (it’s running in the Local System account so won’t have your own account’s defaults). When done, click on the Return button to get back to the main desktop. You can now logoff and log back on to reproduce the problem you’re investigating. After logging on again, execute the following commands in an elevated command prompt to cause the doorway to the session 0 desktop to reappear:

net stop ui0detect
net start ui0detect

Go back to the session 0 desktop to look at the captured information and close the tool.

One last thing I want to leave you with is a reminder that I’ve documented many other troubleshooting cases in this blog and you can find them in the blog index here . You can also watch recordings of my Case of the Unexplained sessions from TechEd here and be sure to come to TechEd US this June in New Orleans , where I’ll be delivering it again with all new cases.