Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Saturday, 17 August 2024

Windows Memory compression (More RAM at the expanse of CPU)

In its 10525 build, Windows 10 introduced a feature known as Memory Compression also included in Windows 11. This feature aims to optimize the utilization of your system’s physical memory and reduce the need for disk-based pagefile IO operations.

Memory Compression works by compressing infrequently accessed pages and retaining them in a new compression store within the physical RAM. This process allows your PC’s RAM to store more data than its original capacity, which can enhance your system's performance.

For instance, if your PC has 8 GB of RAM available, and there’s 9 GB of data to be stored on it, Memory Compression will attempt to compress the extra data so it fits within the 8 GB capacity of your RAM. Without Memory Compression, your PC would store the extra data in a file on your hard drive storage, which can slow down your PC as it takes more time to read data from a file on the hard drive than from RAM.

While Memory Compression can improve performance, it does use more CPU resources. If you notice a lot of compressed memory and think it’s slowing down your PC, there are a couple of solutions. One solution is to install more physical memory (RAM). This will allow your system to store more data in RAM without needing to compress it, reducing the CPU usage associated with Memory Compression.

If installing more RAM is not feasible, you can disable Memory Compression. Here’s how:

  1. Open the Command Prompt as an administrator.
  2. Type the following command and press Enter: `Disable-MMAgent -mc`
  3. Restart your computer.

In conclusion, Memory Compression is a feature designed to optimize your system's performance by making efficient use of your RAM. It's a tool that can be beneficial, but like all tools, it's important to understand how it works and when to use it.

Saturday, 8 July 2023

Using previous files in Windows to restore a file

Have you ever accidentally deleted a file or made changes to it that you regret? Fortunately, Windows has a built-in feature that allows you to restore previous versions of files. This feature is called "Previous Versions" and can be a lifesaver in situations where you need to recover lost data. In this guide, we will walk you through the steps to restore a file using previous versions in Windows.

Step 1: Accessing Previous Versions

The first step to restoring a file using previous versions is to access the feature. To do this, follow these steps:

1. Navigate to the folder that contained the file you want to restore.

2. Right-click on the file and select "Properties" from the context menu.

3. In the Properties window, click on the "Previous Versions" tab.

If you see the message "No previous versions available," it means that Windows does not have any previous versions of the file that you can restore.

Step 2: Selecting a Previous Version to Restore

Once you have accessed the Previous Versions tab, you will see a list of all the available previous versions of the file. Each version will have a timestamp indicating when it was created or last modified. Follow these steps to select a previous version to restore:

1. Select the version you want to restore from the list.

2. Click on the "Restore" button.

3. In the confirmation window, click on "Restore" again to confirm that you want to restore the selected version.

Step 3: Restoring the File

After you have confirmed that you want to restore the selected version, Windows will restore the file to its previous state. Depending on the size of the file, this process may take a few seconds or several minutes. Once the process is complete, you should see the restored file in the folder where it was originally located.

Wednesday, 14 June 2023

Modern Standby (S0) Connected Standby and Disconnected standby

In the ever-evolving world of technology, power management plays a crucial role in enhancing user experiences and maximizing device efficiency. One notable power model that has gained significant attention is Modern Standby. Originally based on the Windows 8.1 Connected Standby power model, Modern Standby offers a seamless user experience with its instant-on/instant-off capabilities, akin to those found in smartphones. This blog post dives into the features and benefits of Modern Standby and highlights the two operational modes: Connected Standby and Disconnected Standby.

The Power of Modern Standby

Modern Standby, an advanced power management model, provides users with an unparalleled experience of instant responsiveness and efficient power consumption. Unlike its predecessor, the Windows 8.1 Connected Standby power model, Modern Standby expands the scope of low-power idle functionality to market segments that were previously limited to the Traditional Sleep (S3) power model. By allowing the system to remain connected to the network while in a low-power mode, known as the S0 low power idle model, Modern Standby ensures real-time delivery of emails, messaging, and cloud-synced data.

Connected Standby: Always Connected for Continuous Updates

Connected Standby, the default mode of Modern Standby, offers users uninterrupted connectivity and real-time updates. With Connected Standby, the device maintains network connectivity and keeps Wi-Fi enabled, ensuring the seamless delivery of emails, messages, and other cloud-synced data. This mode allows users to experience an instant-on functionality, similar to that of a smartphone, where the device quickly resumes from a low-power state, ready for immediate interaction.

Disconnected Standby: Optimizing Battery Life

Modern Standby also introduces Disconnected Standby, an optional mode specifically designed to maximize battery life. In Disconnected Standby mode, the device continues to provide the instant-on experience, but with power-saving optimizations. By disabling Wi-Fi, Bluetooth, and other network connectivity features, Disconnected Standby conserves battery power without compromising the device's responsiveness when needed. This mode is particularly useful when users are on the move or in situations where power outlets are not readily available.

Switching Between Standby Options


To switch between Connected Standby and Disconnected Standby modes, specific commands can be executed in Windows. The following commands need to be run:

Disconnected Standby enabled:

Battery mode:

powercfg /setdcvalueindex scheme_current sub_none F15576E8-98B7-4186-B944-EAFA664402D9 0

Mains mode:

powercfg /setacvalueindex scheme_current sub_none F15576E8-98B7-4186-B944-EAFA664402D9 0

Connected Standby (Default) enabled:

Battery mode:

powercfg /setdcvalueindex scheme_current sub_none F15576E8-98B7-4186-B944-EAFA664402D9 1

Mains mode:

powercfg /setacvalueindex scheme_current sub_none F15576E8-98B7-4186-B944-EAFA664402D9 1

Verifying the Configuration

To confirm the applied standby mode, you can run the following command:

powercfg /a

Important Consideration

One important factor to note is that if you have set the mains mode to Connected Standby and the battery mode to Disconnected Standby, shutting down the device while it is connected to mains power will not switch it to Disconnected Standby mode. To ensure the correct standby profile is activated, it is necessary to switch to battery mode before powering off the device, simply put unplug if form the mains before you turn it off.

Monday, 5 June 2023

Windows Power mode vs Power Plans


Windows, as an operating system, has undergone significant changes over the years. One notable evolution has been in the way it manages power, particularly for mobile devices such as laptops and tablets. As chip and device developers strive to maximize battery life, the old power management strategies need to be reviewed.

The Old Rule: High Performance as the Default

In the past, the prevailing wisdom was to set power plans to "high performance" for optimal performance. Any other option was seen as asking for trouble. As, Windows often struggled with waking up sleeping cores and even failed to do so at 100% utilization, causing frustration for users, particularly in server environments.

This approach is still recommended for servers and high-performance workstations but now is not suitable for battery-powered user mobile devices.

Considering Device Age

Device age also plays a role in power management decisions. Over time, devices naturally become slower, and users may need an extra performance boost before replacing them. In such cases, temporarily switching to the high-performance mode can provide a much-needed performance boost at the cost of battery run time, buying time to plan and prepare for a new device, but it should be done near the end of the devices life not at the start.

The Rise of Mobile Devices and Battery Life Concerns

With the rise of mobile devices and the increasing demand for longer battery life, the old rule of sticking to high-performance power plans no longer holds true in all cases. Mobile devices, such as laptops and tablets, now have better power management then they did years ago and newer built-in features that come enabled via the "Balanced" power plan or the customized plan some device manufacturers install for specific usage. Adjusting the power mode has become the better option for performance while still allowing the operating system to access power saving functions in the device drivers.

Configuring Power Modes in Windows

In Windows 10, changing the power mode is as simple as clicking on the battery icon located in the lower right corner of the screen. Windows 11 has reorganized this feature under the "Settings" menu and "Power & battery" options. These changes make it easier for users to switch between power modes and tailor their device's performance to their needs.

The evolution of power management in Windows reflects the changing needs of users, particularly in the mobile device landscape. While high-performance power plan were once the default choice, battery life concerns have prompted a revaluation of these strategies. Mobile devices now benefit from the balanced power plan or customized plans that strike a balance between performance and battery life. Windows 10 and Windows 11 offer straightforward options to configure power modes, making it easier for users to optimize their device's performance. Understanding the relationship between power management, device age, and performance is crucial for getting the most out of mobile devices in an increasingly mobile-centric world.


Tuesday, 16 May 2023

Moving applications between monitors

Windows provides essential shortcuts to swiftly move applications between monitors, streamlining your workflow. Here are the key shortcuts:

  • Move to the left monitor: Windows key + Shift + Left arrow

  • Move to the right monitor: Windows key + Shift + Right arrow

  • Move to the upper monitor: Windows key + Shift + Up arrow

  • Move to the lower monitor: Windows key + Shift + Down arrow

Wednesday, 29 March 2023

Browser Notification Scams: How to Remove Them from Microsoft Edge and Chrome


Have you ever encountered a browser notification that warns you of a virus or malware on your computer? If so, you may have fallen victim to a browser notification scam. These scams use social engineering tactics to trick you into clicking on a link or downloading a file that will infect your computer with malware.

Here are some tips on how to remove the notification setting for the site from Microsoft Edge and Chrome:

Microsoft Edge:

  1. Open Microsoft Edge and click on the three dots in the upper-right corner of the screen.
  2. Select "Settings" from the drop-down menu..
  3. Click on " Cookies and Site permissions" section.
  4. Click on "All sites" to see a list of sites that have custom permissions.
  5. Find the site that is sending the fake virus warning and click on the three dots next to it.
  6. Select "Remove" to remove the site from the list of allowed sites.

Chrome:

  1. Open Chrome and click on the three dots in the upper-right corner of the screen.
  2. Select "Settings" from the drop-down menu.
  3. Click on "Privacy and security" in the left-hand menu.
  4. Click on "Site settings" under the "Permissions" section.
  5. Click on "Notifications" to see a list of sites that are allowed to send notifications.
  6. Find the site that is sending the fake virus warning and click on the three dots next to it.
  7. Select "Remove" to remove the site from the list of allowed sites.

By removing the notification setting for the site, you will no longer receive fake virus warnings or other scam notifications from that site.

Remember to always be cautious when clicking on links or downloading files from unknown sources. If you suspect that your computer has been infected with malware, run a full system scan using your antivirus software. 

Wednesday, 22 March 2023

Quick Guide: Windows Quick Assist


When it comes to technical difficulties, remote assistance can be a lifesaver. Windows Quick Assist is one such feature that allows a user to remotely access another Windows computer to resolve issues. Here's a quick guide on how to use Windows Quick Assist.

To use Quick Assist, both the user who needs assistance and the person who will provide it must sign in to Quick Assist. To launch Quick Assist, open the Start menu, enter "Quick Assist," then select it from the results. Alternatively, press the Windows key and Ctrl and Q simultaneously.

If you use the key presses and do not have Quick Assist installed it will pop up and as if you want to get from the store.

https://www.microsoft.com/store/productId/9P7BP5VNWKX5

Once you have Quick Assist open, enter the six-digit code provided by the other person in the "Code from assistant" box, then click "Submit." If you're the one providing assistance, you can share your screen by selecting "Allow."

Windows Quick Assist is an easy-to-use feature that can be a lifesaver when you're dealing with technical issues. Whether you're providing assistance or receiving it, Quick Assist can help you resolve problems quickly and efficiently.

Use Quick Assist to help users - Windows Client Management | Microsoft Learn

Tuesday, 28 February 2023

Windows UAC and Local admin rights


User Account Control (UAC) is a security feature in Windows that helps prevent unauthorized changes to your computer. It was introduced in Windows Vista and has been an important security mechanism in all versions of Windows since then. UAC works by prompting the user for permission before allowing any action that requires administrative privileges.

UAC is an important security mechanism in Windows that helps protect your computer from unauthorized changes and malware. Turning off UAC is not recommended and can make your computer vulnerable to attacks. It is always better to keep UAC enabled and take extra precautions to protect your system from potential threats

But when it comes to local admin rights even with UAC enabled you should still split these local rights to another account.  A users everyday account should have little to no extra permissions then want is needed for the everyday work they do.

But they are times when having these rights are a positive as it gives users flexibility and faster response to install software and updates without the need of IT support, this brings more user autonomy and lowers the involvement of IT support.

Given a user a local admin account just for admin tasks while also maintaining a normal account is the best of both words when it comes to user autonomy and security.

Thursday, 16 February 2023

PowerShell - See the last reason why a Windows shutdown / rebooted

 Get-EventLog -logname system | Where-Object {$_.EventID -eq 1074 -or $_EventID -eq 6008} | Select -first 1

Wednesday, 1 June 2022

Find which Windows program is accessing a external device like a web cam

  1. You need the devices "Physical Object" name, you get this by doing to "Device Manager" and double clicking on the device and switching to the details tab.

    From there you can use the drop down box and select "Physical Object", right click on the value and select copy.

  2. You will need Process Explorer for this part.  you can get it from the following location:

    Process Explorer - Windows Sysinternals | Microsoft Docs

  3. Run Process Explorer as administrator and then go to Find and select "Find Handle or DLL"

  4. Paste in the "Physical Object" name from step 1 and press search.

    You will need to give it a few minutes as it can be slow.
Once its listed the process you can see if its being accessed by programs you where expecting of it something else is going on.

Friday, 22 April 2022

Reset Windows Network

Open cmd as admin and run the following commands

netsh winsock reset

netsh int ip reset

The top one resets the winsock while the botton one resets  TCP/IP settings.

Not had to run theses a few years but sometimes it comes in hand to reset a systems network when things start running slow over the network.

Running both commands will reset the TCP settings meaning static ip address and DNS will be lost

Friday, 8 April 2022

Sophos Cloud AV fails update on ML Engine

If you seeing this error "Failed to install sme64: general error" when trying to update.

It can be due to a recent change by Sophos in there SSL signing on the DLL.

RESOLVED Advisory: Sophos Central Windows devices - Sophos ML Engine installation failure

The root SSL is now from these guys

https://trusted-root-g4.chain-demos.digicert.com

If you are getting an SSL error on this website you will need to install the root SSL in to your OS and then try again to install the update and it should work.


Thursday, 7 April 2022

ODBC Deployment via GPO

 Deploying ODBC by GPO can be handy when you have a number of systems you need to keep updated.  The first thing is am going to make a few assumptions on this like

  1. You already have the driver installed into the system via another method and this is just setting up the connector its self.
  2. You know your away around Group Policy Management and import reg keys
You can do this the standard way via the following GPO location

User Configuration > Preferences > Control Panel Settings > Data Sources

But this can have some limitations in what can be done and you can also do it via importing the REG keys from within the GPO.  For this you will need to do the following:

  1. Set up the ODBC settings manual within ODBC, make a note if its a System Data or User Data as this changes the key location.
  2. Once this is done open reg edit and drill down in to the location of the connector you just made.

    User Data Sources
    Located here "HKEY_CURRENT_USER\SOFTWARE\ODBC\ODBC.INI"

    System Data Sources
    Located here "HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBC.INI"
  3. Once you located the key right click on it and select export and save it to a file.
  4. You know just need to open the GPO editor and set up the group policy and use the registry import wizard.

    But depending on  if its a system / user data source will change the location of if you do it under Computer or User

    Preferences > Windows Settings > Registry
  5.  you can then import the reg keys from the above locations, but if you are doing it on a different system then take the reg file you made and import it locally and then in to the GPO.  remember to delete them locally afterwards form the registry
Side note
It also need to export the key from the following location

Software\ODBC\ODBC.INI\ODBC Data Sources

It will make an entry with the same name and a value with which driver you used,  this is needed otherwise it will not show in the ODBC panel

Thursday, 18 February 2021

Windows Administrative shares

 By default Windows automatically makes the following shares

ADMIN$
IPC$
NETLOGON
SYSVOL
PRINT$
FAX$
DRIVELETTER$

These are administrative shares and are they to help with the remote admin / function of a server.  Normally only admins can access these.  But sometimes if you are trying to meet a security compliancy you will need to disable these on workstations and some server.

You can do this by changing the following reg key 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\AutoShareServer

To 0 (Zero) and if its not there you will need to make a REG_DWORD and set it to 0 (Zero)

Remove administrative shares - Windows Server | Microsoft Docs

Ideally I would leave them be; as they do come in handy and the client / server should have firewalls configured to limit risk.

Saturday, 30 January 2021

Windows Sysprep for Virtual Machine

  1.  run command prompt as Administrator
  2. cd C:\Windows\System32\Sysprep
  3. run "sysprep.exe /oobe /generalize /shutdown /mode:vm"

Thursday, 28 January 2021

Resetting Windows 10 password without a local admin account

Sometimes due to company policy local admin accounts are not allowed and if a device is removed from the domain in the wrong order you can paint your self in a corner.

Best hope is to reset and enable the Administrator account or if someone made a local admin but then forget the password with:

Download | Hiren's BootCD PE

If you don't need access to the data then Downloading Windows 10 and reinstall may also be a better option

Monday, 7 December 2020

RDP File settings from a RDS Broker registry

If you have lost the RPD file for one of you collections in your Remote Desktop Broker,  the quick fix is to log in the brokers website and download the RDP file.

But if you do not have access to that collection you can also pull it from Registry and save it in the black text file called <SOMETHING>.rdp

You are looking for Key called ' RDPFileContents'  and it will be located in a subfolder in the following location

HKEY_LOCAL_MACHINE > SOFTWARE >Microsoft > Windows NT > CurrentVersion >Terminal Server > CentralPublishedResources >PublishedFarms

 They are some more subfolders to drill down in to but it depends on what you have called your collections.

Thursday, 3 December 2020

UAC Group Policy Settings

Where possible you should keep this as default,  some Windows applications can start acting odd if the UAC is turned down to far.

UAC Group Policy Settings and Registry Key Settings | Microsoft Docs