Tag Archives: featured

New Antimalware Exe Causes Regular Win11 APPCRASH

In watching a new Windows OS, I tend to check in on Reliability Monitor regularly to look for errors. After my intense efforts to get my Windows 11 PCs upgraded to Defender’s latest Antimalware engine recently, I have to laugh. My Lenovo ThinkPad X380 Yoga in the Beta Channel has thrown 14 critical events since its July 29 upgrade. Half of those events originated from the Antimalware Service Executable, version 4.18.2107.4. Hence my assertion: New Antimalware Exe Causes Regular Win11 APPCRASH.

I have to chuckle, because getting to this version also fixed a documented problem with Windows 11. It did prevent the “Automatic sample submisssion” from resetting to off after each reboot. But apparently, something else in that executable is itself problematic. Such gotchas are pretty normal for Insider Preview code. I imagine MS is working hard to fix it, too.

New Antimalware Exe Causes Regular Win11 APPCRASH: What of It?

Looking at all 14 “Critical Events” in Relimon since July 29, 3 come from Lenovo Firmware Update checks (fwdetectcmd1911.exe). All the rest — including the 7 from the antimalware engine — come from Windows internal components and elements. To me this is just the normal working out of a new OS release as it morphs from Insider Preview to nearly production-ready status. In other words, it simply shows that the development process is proceeding as it usually does.

Over time, the frequency of such errors will drop off. As Insider Preview users report specific items, MS dev teams will investigate. They’ll invariably fix those in need of fixing (as I expect will happen with this MsMpEng.exe issue). When only a few random or minor issues remain unsolved, the developers will start moving more aggressively to create production target builds for Windows 11. That’s usually when it would show up as a Release Preview channel item, and would signal that production release is immanent.

This time around, we already know MS will move heaven and earth to get Windows 11 ready by late October. That’s as far as they can push things, and still have PCs or devices with Windows 11 pre-installed ready for the holiday shopping season. Stay tuned, and we’ll see how it all unfolds.

Facebooklinkedin
Facebooklinkedin

Dev Channel Downgrade Raises Flightsigning Mystery

OK, then. Yesterday I posted here about the conditions under which Insiders can downgrade from Dev Channel to Beta or Release Preview channels. Today, there are reports that Insider Preview stuff may go missing in SettingsUpdateWindows Insider Program if you follow that advice. At the same time MS Insider Team member Eddie Leonard has posted a fix for same at Answers.Microsoft.com. As you’ll see in his step-by-step fix advice below, the Dev Channel downgrade raises Flightsigning mystery because it’s key to that fix. Here are those details, quoted verbatim (I changed the text color to red on the key term to make it stand out):

 

1. Click on Start
2. In the search box, type cmd
3. In the lower right of the search results, under Command Prompt, click Run as Administrator
4. On the UAC prompt, click OK
5. At the elevated command prompt, type: bcdedit /set flightsigning on
6. Press Enter
7. At the elevated command prompt, type: bcdedit /set {bootmgr} flightsigning on
8. Press Enter
9. Reboot the device

How do you know if you’ve got this problem? You’ll see a screen that looks like the one from the lead-in graphic (also cribbed from Eddie’s Answers Fix info). Notice that only the “Stop getting preview builds” choice appears, when you should also see choices for “Choose your Insider settings” and “Windows Insider account.” The preceding fix explains how to get those items back, and restore Windows Insider Program capabilities along the way.

Researching Dev Channel Downgrade Raises Flightsigning Mystery

Of course that raises more questions — namely:
“What is flightsigning?”
“Why must it be turned on (twice)?”
I have no answers for these questions just yet, but I’m digging in. There’s a 2014 TechNet article “What is flightsigning?” It raises the question and provides the glimmer of an answer from bcdedit tool help “Allows flight-signed code signing certificates.” It also says “These are certificates used during the Windows development process and chain to an internal root.” Documentation simply says:

“…this command will enable the system to trust Windows Insider Preview builds that are signed with certificates that are not trusted by default:”

I’m guessing that downgrading from Dev Channel may somehow alter these certificate checks. Further, I believe Beta and Release Preview channels must have them turned on by default. Switching from Dev to lower channels requires them to get turned back on and enabled in the boot manager before Insider Program info can show up.

But details are sparse and documentation terse and limited. The BCDEdit command-line options at MS Docs mentions flightsigning only in passing (see “Changing entry options”). Even the GitHub info from MS Docs doesn’t say much about flightsigning. There’s also a tantalizing post at OSR.com about “New test signing options.” But not a lot of hard or explanatory info.

I’ll keep digging. But if anybody has other sources or info, please comment or use the website’s Contact form to send me an email. All input gratefully received.

 

Facebooklinkedin
Facebooklinkedin

Downgrading Dev Channel Is Now Sometimes Possible

Here’s an interesting tidbit from the July 29 version of Microsoft Docs “Deeper look at flighting.” And of course, as the lead sentence reads “Flighting is the process of running Windows Insider Preview Builds on your device.” In an amendment to prior policy, downgrading Dev Channel is now sometimes possible for test PCs or VMs. Let me explain…

What Downgrading Dev Channel Is Now Sometimes Possible Means

The key to switching without requiring a clean re-install (the prior policy in all cases) is that the Dev Channel must have the same or lower Build number than the target channel. That means switching from Dev Channel to another channel requires users “to find your current build number and compare it to the current build number in the channel you wish to switch to.” Build numbers appear in the output from winver.exe, and in Start → Settings → System → About.

I quote the step-by-step process verbatim from the previously linked flighting document:

  1. Open Settings > Windows Update > Windows Insider Program.
  2. Select Choose your Insider settings.
  3. Select the desired channel, either Beta Channel (Recommended), or Release Preview Channel.
  4. The next time you receive an update, it will be for your new channel.

This will make the process of downgrading channels simpler. It also provides an “exit strategy” for Dev Channel PCs. Prior policy insisted that the only escape from Dev Channel could be a clean re-install of some other Windows version. The other channels have always offered the option to drop back to production/RTM versions when they become available. This extends that out to Dev Channel, but requires two steps to get there: first drop back to Beta or Insider Preview, then drop back to production/RTM. Good stuff!

Why Am I Telling You This … Now?

As you look at the WinVer output from Dev Channel (left) and Beta Channel (right) in the lead graphic, right now the Build numbers are the same. That means that you can downgrade Dev Channel PCs as I write this story. Given that MS hasn’t released a Dev Channel build in a while this can’t last forever. If you want to try it out, act fast — or wait for the next synch-up. Your call…

Facebooklinkedin
Facebooklinkedin

Pondering Windows 11 Hardware Requirements

The Windows user community is abuzz with reactions and concerns about what it takes, PC-wise, to upgrade to Windows 11. This has many people — myself included — pondering Windows 11 hardware requirements.  For the record, Microsoft Docs states those things clearly on the Windows 11 requirements page. (Indeed, the bulleted list below is cut’n’pasted from that source) :

    • Processor: 1 gigahertz (GHz) or faster with two or more cores on a compatible 64-bit processor or system on a chip (SoC).
    • RAM: 4 gigabytes (GB) or greater.
    • Storage: 64 GB* or greater available storage is required to install Windows 11.
      • Additional storage space might be required to download updates and enable specific features.
    • Graphics card: Compatible with DirectX 12 or later, with a WDDM 2.0 driver.
    • System firmware: UEFI, Secure Boot capable.
    • TPM: Trusted Platform Module (TPM) version 2.0.
    • Display: High definition (720p) display, 9″ or greater monitor, 8 bits per color channel.
    • Internet connection: Internet connectivity is necessary to perform updates, and to download and use some features.
      • Windows 11 Home edition requires an Internet connection and a Microsoft Account to complete device setup on first use.

Pondering Windows 11 Hardware Requirements Leads to Upgrade Plans

Of the 10 systems currently on the premises here at Chez Tittel, only 3 of them fail to meet the afore-stated stipulations. Those 3 systems are:

1. My production desktop PC, whose i7-6700 misses the CPU cut-off by one Intel generation. It also lacks TPM 2.0.
2. My son’s desktop PC, whose i7-4770K (built in 2014) is pretty long in the tooth. It’s overdue for an upgrade anyway. It too, lacks TPM 2.0 support.
3. My 2014 Surface Pro 3 sports another 4th-gen Intel processor, an i7-4650U. No TPM 2.0 here, either.

I will upgrade both desktops (systems #1 and #2 above). The parts for #2 arrived this weekend and I’ll be upgrading that system sometime this week. It’s going to be a Ryzen 5800X. Its B550 mobo offers TPM 2.0 emulation as part of a broad range of capabilities. I plan to upgrade my production desktop next month, or the month after, to be ready for an October Windows 11 production release date.

Keeping an Eye on Windows 10

Usually when a new OS version comes out, I abandon the previous one completely and move wholesale to the new version. I won’t be able to do that with the Surface Pro 3 (#3 above) so I’ll keep it running Windows 10 as long as it can.

EOL for Windows 10 is October 2025, so that’s going to be a while yet. In fact, if all goes to plan I may be retiring that year myself assuming my son also manages to graduate from college in 4 years. (Alas, that’s not always a safe assumption: both of my step-kids took 5 or more years to earn their bachelor’s degrees, and my sister’s 2 are on the same course. I’m resigned to the notion that it may take him 5 years to finish a bachelor’s, because that’s become such a norm.)

Why I’m Basically OK with MS Requirements

I’m not as bent out of shape by Microsoft’s requirements cut-offs as many people seem to be. I understand one must draw the line somewhere, and that hardware-level security has made dramatic strides in the past half-decade. I’m assuming that’s why MS drew the line at 8th generation Intel (Coffee Lake) CPUs and AMD and ARM processors of similar vintage.

These cut-offs take us back to 2017, nearly 5 years back from the upcoming Windows 11 release date (more or less expected for October). Because TPM (via emulation) is part and parcel of all such systems, by and large, it’s not really an additional hurdle unless users bought older motherboards for newer processors in the 2017-2018 timeframe.

For some fascinating viewpoints and issues on this topic, check out the ElevenForum thread “Update on Windows 11 minimum requirements.” As I write about this conversation, it already boasts numerous items (including my own at #212). There are sure to be many, many more before all is said and done. That said, it’s worth a read-through. Lots of good opinions and ideas, pro and con, and good reflection of the state of the user community.

 

Facebooklinkedin
Facebooklinkedin

Slow Charger Warning Means Underpowered Thunderbolt Dock

Here’s one I haven’t run into before. I wanted to use multiple USB-C ports on my Lenovo X390 Yoga yesterday. Alas, it has but one. So I plugged it into a Lenovo Thunderbolt 3 Gen2 dock the company sent me. Even though it was for another computer I expected all itches properly scratched. Instead I learned that a slow charger warning means underpowered Thunderbolt dock at work. In fact, by the next morning, the battery was exhausted and the laptop inert, amidst a massive PC-to-iTunes music conversion.

Given Slow Charger Warning Means Underpowered Thunderbolt Dock, Then What?

Find a workaround, obviously. Luckily the X390 sports two USB 3 ports. I used one for the drive dock where the music files resided, and the other for the iPhone 12’s Lightning-to-USB cable. I ended up not using USB-C at all (except for power from the dock and then the brick later on).

In fact, the Lenovo Dock claims to support “up to 65W power charging.”  And indeed, the X390 needs 65W of power delivery. But obviously, something wasn’t right. In fact, Reliability monitor showed an APPCRASH from PowerMgr.exe at 7:12 this morning. I guess that’s when the battery finally died. When I saw the error message after this morning’s walk I switched back to the regular power brick and the music transfer continued without further hitches or delays.

The moral of this story appears to be: if notifications ever tell you there’s a “slow charger” at work, you’d best use a different power supply if you want to keep your laptop running indefinitely. Lesson learned for me, for sure!

Note Added August 2: Reader Concurs

I got a comment from a LinkedIn member on this post that cites to issues with some docks and power bricks. Apparently these devices struggle to service peripherals and keep the battery charged at the same time. Interesting!

Facebooklinkedin
Facebooklinkedin

MS Makes LTSC Sole Windows Server Release Channel

When you think about it, here’s a sensible move. Windows Server is the kind of platform that organizations want to stand up, get right, and leave alone. There’s little need for personalization, and it doesn’t need desktop tweaks. In fact, Server is really a background thing. It  holds up the “you ask, I answer” side of client/server. architecture. Then, too, MS put containers and microservices under the Azure umbrella. That’s why, I think, that MS makes LTSC sole Windows Server Release channel.

Why MS Makes LTSC Sole Windows Server Release Channel

A July 26 Microsoft Docs item spells things out. It’s entitled Windows Server release information. This quote explains things (emphasis mine):

The Semi-Annual Channel in previous versions of Windows Server focused on containers and microservices, and that innovation will continue with Azure Stack HCI. With the Long-Term Servicing Channel, a new major version of Windows Server is released every 2-3 years. Users are entitled to 5 years of mainstream support and 5 years of extended support. This channel provides systems with a long servicing option and functional stability, and can be installed with Server Core or Server with Desktop Experience installation options. The Long-Term Servicing Channel will continue to receive security and non-security updates, but it will not receive the new features and functionality.

Organizations can migrate if and when compelling new features emerge. It’s arguable this change makes a virtue of necessity. Why say that? Most organizations upgrade servers no more often than once every 2-3 years (or longer) anyway.

On balance, I think this is a good move. For developers, it means building, testing and maintaining fewer releases . That is good news for everybody. Developers can build more cool new stuff. Admins face less busy work. This means shorter, simpler scheduled updates. And because updates often happen over long weekends, it means more holiday time with family and friends. That’s a real win-win!

Facebooklinkedin
Facebooklinkedin

21H2 Preview Experiences After Two Weeks

I’ve got one lone test machine running the “other path” for older Windows hardware — namely the 21H2 Feature Update released on 7/16/2021. Here, I recite my 21H2 Preview Experiences after two weeks. While I’ve not encountered any show-stoppers, the Reliability Monitor report that appears above says it all. As is not untypical for new release forks, this one’s got some minor gotchas.

Summarizing 21H2 Preview Experiences After Two Weeks

I’ll start with a list of all errors reported in the foregoing Reliability Monitor screencap.

Date Source Summary
16-Jul Windows Hardware error
17-Jul Windows Update Medic Service Stopped working
Search application Stopped working and was closed
Search application Stopped working
18-Jul Windows Desktop Gadgets Stopped working
21-Jul PWA Identity Proxy Host Stopped responding and was closed
Windows Desktop Gadgets Stopped working

Upon examination, the error sources mostly originate from Windows itself. Only Windows Desktop Gadgets (which occurs twice) is a third-party app. The rest of the stuff is OS components, hardware, or built-in Windows apps.

IMHO, this kind of behavior is typical for a new release fork. It indicates a shakeout from current preview status on the way to something more stable. It’s only July and the release probably won’t happen until October, so there’s still plenty of time to get things right. If what I’m seeing right now is any indication, what needs fixing is mostly minor stuff.

I would say this augurs well for those who plan to upgrade to 21H2 on production PCs. If your PCs won’t meet Windows 11 upgrade requirements, they should be able to run Windows 10 until EOL in October 2025 without too much fuss or bother. Good stuff!

Facebooklinkedin
Facebooklinkedin

Vexing Windows 11 Antimalware Platform Update Issues

Right now, I have two PC dedicated to Windows 11 testing and learning. Just recently, I discovered some vexing Windows 11 Antimalware platform update issues. The short version is: one of my PCs is up-to-date. It’s no longer subject to Automatic Sample Submission reset to off following each restart. Alas, the other remains stubbornly stuck on an earlier Antimalware platform release. None of the update options available work, so I can’t get no relief. Let me explain…

Fighting Vexing Windows 11 Antimalware Platform Update Issues

First, let me be clear. This is a known and documented Windows 11 issue. It’s been around since the initial release hit. Indeed, a fix exists: when the Antimalware Platform version gets to 4.18.2107.4 or higher, the problem disappears. For the record that problem is depicted in this story’s lead-in graphic. After every reboot, the Automatic Sample Submission feature for virus uploads in Defender is turned off. The feature is easy to turn back on, until the next reboot. OCD OS maintainer that I am, the workaround isn’t enough for me. I want it fixed, for good, now.

Here’s the vexing part. WU hasn’t yet deigned to update the antimalware engine behind the scenes. Ditto for the Protection updates option in Windows Security. There’s a registry hack documented on a related ElevenForum thread. There’s even a manual Defender update download that’s supposed to take the Antimalware engine release to 1.2.2107.02. It comes in a file named defender-update-kit-x64.zip. Alas, inspection of said update file shows the Antimalware engine to be 4.18.2015.5. It’s too old to fix the issue, in other words. Thus, no relief just yet, shy of a permanent registry hack.

The Perils of Perfectionism

Yes, I could hack the registry to turn this off. But I’d have to unhack it again when the fix finally shows up on the X380 Yoga that’s affected. I’m going to have to wait for WU to get around to providing me the latest antimalware engine on its own, or find a newer manual update. Alas, that’s the way things go sometimes, here in Windows-World. Oddly, I find myself hoping for a new Windows 11 build, in hopes the latest antimalware engine will be part of its contents. Stay tuned: I’ll let you know how all this shakes out.

Note Added August 4: Update Came!

Thanks to long-time and active TenForums and ElevenForum user @Cliff S, I learned this morning that Antimalware Client Version 4.18.2107.4 arrived via WU. Checking my own previously stuck test machine, I saw it too, had gotten this update. And now, my PC no longer reverts to Automatic Sample Submission=Off after each reboot. Fixed!

I’ve also determined this version is available through the Microsoft Update Catalog. Search for KB4052623, and grab the correct version, if WU doesn’t come through for you.

 

 

Facebooklinkedin
Facebooklinkedin

Next LTSC Is 21H2 Based: Windows 11 Follows Later

In a July 15 Windows Experience Blog post, MS VP John Cable writes that in “the second half of 2021” the next version of the Windows LTSC will hit. Here’s a quote: “…we will also launch the next version of the Windows 10 Long-Term Servicing Channel (LTSC) based on version 21H2 at the same time.” A recent “Ask Me Anything” (AMA) session said a “next LTSC” after that would use Windows 11. Hence my assertion: the next LTSC is 21H2 based, Windows 11 follows later.

Next LTSC is 21H2 based Windows 11 Follows Later. How long?

Good question. Take a look at a list of LTSC Windows 10 releases. I include my guess for the upcoming one:

1. Windows 10 Enterprise LTSC 2015 1507   07/29/2015
2. Windows 10 Enterprise LTSC 2016 1607   08/02/2016
3. Windows 10 Enterprise LTSC 2019  1809   11/13/2018
4. Windows 10 Enterprise LTSC 2021  21H1   11/??/2021

The gaps vary. It starts with just over a year (1 → 2). The next is over 2 years (2 → 3). That latest goes up to around 3 years (3 → 4). Recent history argues it will likely hit in two or three years. A lot depends on features that Windows 11 offers and Windows 10 does not. Equally important: how much they matter for deployments likely to use the long-lived LTSC code base.

Why Use a Windows LTSC Release?

In its LTSC explainer in Microsoft Docs, MS works hard to distinguish LTSC from other release channels and to identify typical usage scenarios (italic text is quoted verbatim):

 Important

The Long-Term Servicing Channel is not intended for deployment on most or all the PCs in an organization. The LTSC edition of Windows 10 provides customers with access to a deployment option for their special-purpose devices and environments. These devices typically perform a single important task and don’t need feature updates as frequently as other devices in the organization. These devices are also typically not heavily dependent on support from external apps and tools. Since the feature set for LTSC does not change for the lifetime of the release, over time there might be some external tools that do not continue to provide legacy support. See LTSC: What is it, and when it should be used.

The latter document calls out a “key requirement … that functionality and features don’t change over time.” These include medical systems like those used in MRI and CAT scan devices, industrial process controllers, and air traffic control systems. All such systems are costly, complex, and relatively isolated from public networks.

My gut feel is a long wait doesn’t matter that much for LTSC deployments. Because they’re so specialized and focused. engineers will build around whatever’s available when they put LTSC to work. When it gets used, the Windows OS isn’t really important: the function and capabilities of the overall system in which LTSC is embedded is what really matters.

Facebooklinkedin
Facebooklinkedin

Beta Channel Update Has Uncertain Timing

I always have troubles with patience. That goes double when I know a PC will run Windows 11, but hasn’t gotten the upgrade offer just yet. I’m talking about my second Lenovo ThinkPad X380 Yoga unit. It had been on the Release Preview Channel. But two days ago, I bumped it up to the Beta Channel in hopes of getting the Windows 11 upgrade. Because this Beta Channel update has uncertain timing, I’m not sure when this PC will get the offer. Here’s the irony: I have a second, nearly identical X380 unit (they differ only in the SSD installed) that’s been running Windows 11 since Day 1 on the Dev Channel.

Does Trickle-out Mean Beta Channel Update Has Uncertain Timing?

As you can see in this story’s lead graphic, Beta Channel PCs should be getting “these Windows 11 builds…” So far, this particular X380 Yoga is hanging back on Windows 10, Build 19043.1149. I’m eager to get the machine onto the new OS, but I want to see how long this is going to take to happen.

My track record on such things is far from stellar. I’ve forcibly upgraded many machines to new Windows 10 versions when upgrade offers were slow to appear. That raises the question: Can I wait long enough for WU to do its thing? Or will I succumb to the fatal allure of instant upgrade and do it manually?

I do want to understand how things will work in the Beta Channel. But I’m having trouble waiting on the system to catch up with me. Let me try another reboot and see if that will help … goes off to make that happen … Nothing doing.

Stay tuned. I’ll be back (soon, I hope) to tell you that WU has come through, or to confess that my patience wore out and I used an ISO to perform an in-place upgrade to Windows 11. One way or the other, I’ll get there, I promise!

Facebooklinkedin
Facebooklinkedin