The Microsoft Windows Malicious Software Removal Tool

If you’ve ever looked over the regular updates that get delivered the second Tuesday of every month (so-called “Patch Tuesday”) to your Vista machine, you can’t help but have noticed the regular appearance of something called the Windows Malicious Software Removal Tool. As I write this blog on 8/05/2008, it’s only the first Tuesday of the month, so the latest version is dated 7/8/2008, as documented in KB article 890830 (there’s also a download).

Continue reading The Microsoft Windows Malicious Software Removal Tool

Facebooklinkedin
Facebooklinkedin

Stealthy, Interesting “Patch Tuesday” Item

The second Tuesday of every month is also known as “Patch Tuesday,” because that’s the day when Microsoft normally releases its security updates, along with other patches and fixes for its various Windows operating systems, applications, and so forth. Yesterday was the second Tuesday in September, and Windows Update proffered 10 items, most of which are described in the Security Bulletin for that month.Here, I’m going to focus in on one non-security update entitled “Update for Windows Vista (KB955302)“.

Continue reading Stealthy, Interesting “Patch Tuesday” Item

Facebooklinkedin
Facebooklinkedin

Shaking Down Windows Vista Proves Too Interesting

In the past two weeks, I’ve built a new Windows Vista system and upgraded the CPU on my primary production machine. In each case, I’ve seen problems pop up afterward that caused the Windows Reliability Monitor to report errors and related problems on those machines, and have watched their reliability scores plummet accordingly.

Continue reading Shaking Down Windows Vista Proves Too Interesting

Facebooklinkedin
Facebooklinkedin

Quick ‘n’ Dandy Windows Process Lookup

I’ve used lots of online sources to look up Windows processes and DLLs by name in the past, but one that keeps coming up on Google over the years is Uniblue’s site at www.processlibrary.com. Now, that company has created a free, fabulous, and small (2 MB) process lookup tool. It integrates right into Windows Task Manager and links any entry that shows up in the Processes tab view to its corresponding Process Library coverage.

Continue reading Quick ‘n’ Dandy Windows Process Lookup

Facebooklinkedin
Facebooklinkedin

Mystery Solved — 103 Devices, 5 Volumes

This looked just plain weird to me. When I checked Reliability Monitor and the installation of the generic volume shadow copy devices I couldn’t make out a pattern even though it was there to be found. I even posted queries about this to vistaforums.com, techsupportforum.com, and to Microsoft Tech Support, but it took a Facebook email to one of the demiurges in the Windows pantheon–namely, Mark Russinovich–to get to the bottom of the matter (more on this to follow at the end of this story).

Continue reading Mystery Solved — 103 Devices, 5 Volumes

Facebooklinkedin
Facebooklinkedin

More on the latest BSOD

In digging further into my BSOD from Thursday, August 7, using the Windows Debugger I observed that the ultimate cause was a module named pctsSvc.exe (see attached screenshot below). A quick process lookup informs me that this is part of PC Tools Spyware Doctor runtime environment. Additional research on Windows crashes related to this module indicates that a remove/reinstall maneuver often addresses the problem (see this PC Tools forum thread for more info).

Continue reading More on the latest BSOD

Facebooklinkedin
Facebooklinkedin

Lesson Learned: More on Post-Uninstall Clean-up

Last week, my blog “Should Software Makers Clean Up After Themselves?” expressed my consternation that responsible software vendors could create uninstall utilities that don’t completely clean up after themselves. I reported that one well-known program that I just uninstalled left 462 registry entries and 151 files behind. I was wrong: it also installed the Viewpoint Media Player, which runs as viewpointservice.exe, and not only left it running on my machine, it also continued to load up and run at boot time, even with no consuming processes to serve.

Continue reading Lesson Learned: More on Post-Uninstall Clean-up

Facebooklinkedin
Facebooklinkedin

Interesting Event Viewer Error Message

In keeping with my ongoing Vista troubleshooting exercise, I’ve gotten into the habit of dropping in on my Event Viewer every couple of days to see what kinds of errors and warnings are popping up. By keeping tabs on this information, and researching stuff I haven’t seen before or don’t understand, I keep learning more and more interesting stuff about Vista. This morning, I found a new error from the Volume Shadow Copy Service (which shows up in the Windows Application log as a source named VSS). Because VSS is important to maintaining Vista operating and file system integrity, I started digging more deeply into this right away.

Continue reading Interesting Event Viewer Error Message

Facebooklinkedin
Facebooklinkedin

Author, Editor, Expert Witness