Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

[SDP 3][9b9d2b88-02f1-4a27-807d-0bb44178cdab] Networking Diagnostic for Windows


View products that this article applies to.

Summary

The Networking Diagnostic collects data for troubleshooting networking issues in Windows.

↑ Back to the top


More Information

The Networking Diagnostic collects static configuration data for networking components. This is the main diagnostic for gathering general information for troubleshooting networking issues. 

Information collected

802.1X Client
DescriptionFile name
802.1X Client netsh information from netsh.exe
{ComputerName}_8021xClient_netsh.TXT
HKLM\SOFTWARE\Microsoft\EAPOL
HKLM\SOFTWARE\Policies\Microsoft\Windows\WiredL2
HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless
HKLM\SYSTEM\CurrentControlSet\Services\dot3svc
HKLM\SYSTEM\CurrentControlSet\Services\EapHost
HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc
HKLM\SYSTEM\CurrentControlSet\Services\WZCSVC
{ComputerName}_8021xClient_reg_.TXT
Microsoft-Windows-EapHost/Operational
Microsoft-Windows-Wired-AutoConfig/Operational
Microsoft-Windows-WLAN-AutoConfig/Operational
{ComputerName}__evt_*.*

Best Practices Analyzer
DescriptionFile name
Best Practices Analyzer (BPA) Report
{ComputerName}_*BPA*.htm

BITS Client
DescriptionFile name
Current jobs information from BitsAdmin command: cmd.exe /c bitsadmin /list /allusers /verbose
{ComputerName}_BitsClient_bitsadmin-list-allusers-verbose.TXT
HKLM\SOFTWARE\Policies\Microsoft\Windows\BITS
HKLM\System\CurrentControlSet\Services\BITS
{ComputerName}_BitsClient_reg_.TXT
Microsoft-Windows-Bits-Client/Operational
{ComputerName}__evt_*.*

BITS Server
DescriptionFile name
HKLM\System\CurrentControlSet\Services\BITSCompactServer
{ComputerName}_BitsServer_reg_.TXT
Microsoft-Windows-Bits-CompactServer/Operational
{ComputerName}__evt_*.*

BranchCache
DescriptionFile name
BranchCache information from netsh output
{ComputerName}_BranchCache_netsh_output.TXT
HKLM\SOFTWARE\Policies\Microsoft\PeerDist
HKLM\SYSTEM\CurrentControlSet\services\PeerDistKM
HKLM\SYSTEM\CurrentControlSet\services\PeerDistSvc
{ComputerName}_BranchCache_reg_output.TXT
Microsoft-Windows-BranchCache/Operational
Microsoft-Windows-BranchCacheSMB/Operational
{ComputerName}__evt_*.*

Bridge
DescriptionFile name
Bridge information from netsh output
{ComputerName}_Bridge.TXT

Certificates information
DescriptionFile name
Certutil command to show certificates in the machine store: certutil -silent -store my
{ComputerName}_Certificates-machinestore.TXT
Certutil command to show certificates in the user store: certutil -silent -user -store my
{ComputerName}_Certificates-userstore.TXT
HKLM\SYSTEM\CurrentControlSet\services\CertPropSvc
HKLM\SYSTEM\CurrentControlSet\services\crypt32
HKLM\SYSTEM\CurrentControlSet\services\CryptSvc
HKLM\SYSTEM\CurrentControlSet\services\SCardSvr
HKLM\SYSTEM\CurrentControlSet\services\SCPolicySvc
{ComputerName}_Certificates_reg_.TXT
Microsoft-Windows-CAPI2/Operational
{ComputerName}__evt_*.*

CscClient
DescriptionFile name
HKCU\SOFTWARE\Policies\Microsoft\Windows\Netcache
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache
HKLM\SOFTWARE\Policies\Microsoft\NetCache
HKLM\SYSTEM\CurrentControlSet\services\CSC
HKLM\SYSTEM\CurrentControlSet\services\CscService
{ComputerName}_CscClient_reg_output.TXT
Microsoft-Windows-OfflineFiles/Analytic
Microsoft-Windows-OfflineFiles/Debug
Microsoft-Windows-OfflineFiles/Operational
Microsoft-Windows-OfflineFiles/SyncLog
{ComputerName}__evt_*.*

DFS Client
DescriptionFile name
DFS Client Information from dfsutil output
{ComputerName}_DfsClient_info.TXT
HKLM\Software\Policies\Microsoft\System\DFSClient
HKLM\SYSTEM\CurrentControlSet\services\DfsC
HKLM\SYSTEM\CurrentControlSet\services\MUP
{ComputerName}_DfsClient_reg_output.TXT

DHCP Client
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\Dhcp
{ComputerName}_DhcpClient_reg_.TXT
Microsoft-Windows-Dhcp-Client/Operational
Microsoft-Windows-DhcpNap/Operational
Microsoft-Windows-Dhcpv6-Client/Operational
{ComputerName}__evt_*.*

DHCP Server
DescriptionFile name
DHCP Server Netsh Dump
{ComputerName}_DhcpServer_netsh_dump.TXT
DHCP Server Netsh Output
{ComputerName}_DhcpServer_netsh_info.TXT
HKLM\SYSTEM\CurrentControlSet\Services\DHCPServer
{ComputerName}_DhcpServer_reg_.TXT
Microsoft-Windows-Dhcp-Server/Admin
Microsoft-Windows-Dhcp-Server/Operational
{ComputerName}__evt_*.*

DirectAccess Client
DescriptionFile name
Collects multiple registry key contents related to the DirectAccess client.
{ComputerName}_DirectAccessClient_reg_.TXT
DNS Client netsh show state (for DirectAccess): netsh dnsclient show state
{ComputerName}_DirectAccessClient_netsh_dnsclient-show-state.TXT
W8/WS2012 powershell output for the DirectAccess client.
{ComputerName}_DirectAccessClient_info_pscmdlets.TXT

DirectAccess Server
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\DirectAccess
HKLM\SOFTWARE\Policies\Microsoft\Windows\RemoteAccess
HKLM\System\CurrentControlSet\Services\RaMgmtSvc
HKLM\System\CurrentControlSet\Services\RemoteAccess
{ComputerName}_DirectAccessServer_reg_.TXT
Microsoft-Windows-RemoteAccess-MgmtClient/Operational
Microsoft-Windows-RemoteAccess-RemoteAccessServer/Admin
Microsoft-Windows-RemoteAccess-RemoteAccessServer/Operational
{ComputerName}__evt_*.*
W8/WS2012 powershell output for the DirectAccess Server
{ComputerName}_DirectAccessServer_info_pscmdlets.TXT

DNS Client
DescriptionFile name
Copies the Hosts file if it exists.
{ComputerName}_DnsClient_HostsFile.TXT
DNS Client - Hosts file from windir\system32\drivers\etc\HOSTS
{ComputerName}_DnsClient_HostsFile.TXT
DNS Client netsh show state (for DirectAccess): netsh dnsclient show state
{ComputerName}_DnsClient_netsh_dnsclient-show-state.TXT
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient
HKLM\SYSTEM\CurrentControlSet\services\Dnscache
{ComputerName}_DnsClient_reg_.TXT
IP configuration from command: Ipconfig /displaydns
{ComputerName}_DnsClient_ipconfig-displaydns.TXT
Microsoft-Windows-DNS-Client/Operational
{ComputerName}__evt_*.*
W8/WS2012 powershell output for the DNS Client.
{ComputerName}_DnsClient_info_pscmdlets.TXT

DNS server
DescriptionFile name
DNS server
{ComputerName}__evt_*.*
DnsCmd /enumzones
{ComputerName}_DnsServer_DnsCmd-enumzones.TXT
DnsCmd /info
{ComputerName}_DnsServer_DnsCmd-info.TXT
DnsCmd /statistics
{ComputerName}_DnsServer_DnsCmd-statistics.TXT
DnsCmd /statistics
{ComputerName}_DnsServer_DnsCmd-EnumDirectoryPartitions.TXT
HKLM\SYSTEM\CurrentControlSet\services\DNS
{ComputerName}_DnsServer_reg_.TXT

File version information (Chksym)
DescriptionFile name
File version information from %ProgramFiles%\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*
{ComputerName}_sym_MS_iscsi.*
File version information from %windir%\cluster\*.*
{ComputerName}_sym_ProgramFiles_sys.*
File version information from %windir%\cluster\*.*
{ComputerName}_sym_Cluster.*
File version information from %windir%\system32\*.dll
{ComputerName}_sym_System32_dll.*
File version information from %windir%\system32\*.exe
{ComputerName}_sym_System32_exe.*
File version information from %windir%\system32\*.sys
{ComputerName}_sym_System32_sys.*
File version information from %windir%\system32\drivers folder
{ComputerName}_sym_Drivers.*
File version information from %windir%\system32\Spool\*.*
{ComputerName}_sym_PrintSpooler.*
File version information from %windir%\syswow64 folder and subfolders
{ComputerName}_sym_SysWOW64_sys.*
File version information from %windir%\syswow64\drivers folder
{ComputerName}_sym_SysWOW64_sys.*
File version information from {Program Files (x86)}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFilesx86_sys.*
File version information from {Program Files}\*.sys folder and subfolders
{ComputerName}_sym_ProgramFiles_sys.*
File version information from drivers that are currently running on the computer
{ComputerName}_sym_RunningDrivers.*
File version information from processes that are currently running on the computer
{ComputerName}_sym_Process.*

Firewall
DescriptionFile name
[W8/WS2012] Get-NetFirewallProfile
[W8/WS2012] Get-NetFirewallRule
[W8/WS2012] Get-NetIPsecMainModeSA
[W8/WS2012] Get-NetIPsecQuickModeSA
[W8/WS2012] Show-NetFirewallRule
[W8/WS2012] Show-NetIPsecRule -PolicyStore ActiveStore
{ComputerName}_Firewall_info_pscmdlets.TXT
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall
HKLM\SYSTEM\CurrentControlSet\Services\BFE
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
{ComputerName}_Firewall_reg_.TXT
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose
{ComputerName}__evt_*.*
netsh advfirewall consec show rule all any dynamic verbose
netsh advfirewall consec show rule all any static verbose
{ComputerName}_Firewall_netsh_advfirewall-consec-rules.TXT
netsh advfirewall export
{ComputerName}_Firewall_netsh_advfirewall-export.wfw
netsh advfirewall firewall show rule name=all
{ComputerName}_Firewall_netsh_advfw-firewall-rules.TXT
netsh advfirewall monitor show consec verbose
{ComputerName}_Firewall_netsh_advfirewall-consec-rules-active.TXT
netsh advfirewall monitor show firewall verbose
{ComputerName}_Firewall_netsh.TXT
netsh advfirewall show allprofiles
netsh advfirewall show allprofiles state
netsh advfirewall show currentprofile
netsh advfirewall show domainprofile
netsh advfirewall show global
netsh advfirewall show privateprofile
netsh advfirewall show publicprofile
netsh advfirewall show store
{ComputerName}_Firewall_netsh_advfirewall.TXT
netsh wfp show boottimepolicy file=
{ComputerName}_Firewall_netsh_wfp-show-boottimepolicy.XML
netsh wfp show filters file=
{ComputerName}_Firewall_netsh_wfp-show-filters.XML
netsh wfp show netevents file=
{ComputerName}_Firewall_netsh_wfp-show-netevents.XML
netsh wfp show options optionsfor=keywords
{ComputerName}_Firewall_netsh_wfp-show-options-optionsforkeywords
netsh wfp show options optionsfor=netevents
{ComputerName}_Firewall_netsh_wfp-show-options-optionsfornetevents
netsh wfp show security netevents
{ComputerName}_Firewall_netsh_wfp-show-security-netevents.TXT
netsh wfp show state file=
{ComputerName}_Firewall_netsh_wfp-show-state
netsh wfp show sysports file=
{ComputerName}_Firewall_netsh_wfp-show-sysports.XML

Fltmc
DescriptionFile name
Filter management tool output
{ComputerName}_Fltmc.TXT

FolderRedirection
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\System\Fdeploy
{ComputerName}_FolderRedirection_reg_output.TXT
Microsoft-Windows-Folder Redirection/Operational
{ComputerName}__evt_*.*

General information
DescriptionFile name
Basic information about processes such as memory usage and handle count, and information about kernel memory utilization, such as Paged Pool and Non-Paged Pool memory
{ComputerName}_ProcessesPerfInfo.htm
Basic system information, including machine name, service pack, computer model, processor name, and processor speed
resultreport.xml

List of installed updates and hotfixes
{ComputerName}_Hotfixes.*
List of user SIDs, group memberships, and permissions through Whoami /all output
{ComputerName}_Whoami.txt
Resultant Set of Policy (RSoP) generated by Gpresult.exe utility
{ComputerName}_GPResult.*
Scheduled Tasks information (csv and txt) generated by Schtasks.exe utility
{ComputerName}_schtasks.*
Sysinternals Autoruns utility output
{ComputerName}_Autoruns.*
System information - MSInfo32 tool output
{ComputerName}_msinfo32.nfo
{ComputerName}_msinfo32.txt

General performance information
DescriptionFile name
Information about process and threads that are using Pstat.exe tool
{ComputerName}_PStat.txt

Group Policy client
DescriptionFile name
Microsoft-Windows-GroupPolicy/Operational
{ComputerName}__evt_*.*

HTTP
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\Services\HTTP
{ComputerName}_HTTP_reg_.TXT
HTTP information from netsh output
{ComputerName}_HTTP_netsh_output.TXT

Hyper-V role
DescriptionFile name
Hyper-V Configuration and Virtual Machine Information
{ComputerName}_HyperV-Info.HTM
Hyper-V Networking Advanced Information
{ComputerName}_Hyper-V-NetworkingInfo.txt

Internet Explorer
DescriptionFile name
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings
{ComputerName}_InternetExplorer_reg_output.TXT

IPsec
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
HKLM\SYSTEM\CurrentControlSet\Services\IPsec
HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent
{ComputerName}_IPsec_reg_.TXT
IPsec information from command: netsh dynamic show all
{ComputerName}_IPsec_netsh_dynamic.TXT
IPsec information from command: netsh ipsec static exportpolicy
{ComputerName}_IPsec_netsh_LocalPolicyExport.ipsec
IPsec information from command: netsh static show all
{ComputerName}_IPsec_netsh_static.TXT
W8/WS2012 powershell output for the IPsec.
{ComputerName}_IPsec_info_pscmdlets.TXT

IPv6Check
DescriptionFile name
Networking adapt configuration from WMI
{ComputerName}_Networking.TXT

IPv6To4Check
DescriptionFile name
IP configuration data from ipconfig command
{ComputerName}_Networking.TXT

Kerberos tickets and TGT
DescriptionFile name
Kerberos information from Klist.exe output
{ComputerName}_Kerberos_klist.txt

Memory dump information and files
DescriptionFile name
Information about machine memory dump files, user memory dump files, and memory dump configuration
{ComputerName}_DumpReport.*
Machine Full or Kernel memory dump files (Memory.dmp)
{ComputerName}_dmp_memory.zip
Mini memory dump files from {Windows}\Minidump folder
User dumps generated by Windows Error Reporting
{ComputerName}_dmp_*.zip

NAP Client
DescriptionFile name
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Security Center
HKLM\SOFTWARE\Policies\Microsoft\NetworkAccessProtection
HKLM\System\CurrentControlSet\Services\napagent
{ComputerName}_NapClient_reg_.TXT
Microsoft-Windows-NetworkAccessProtection/Operational
Microsoft-Windows-NetworkAccessProtection/WHC
{ComputerName}__evt_*.*
NAP Client information from netsh output
{ComputerName}_NapClient_netsh_output.TXT

NAP Server
DescriptionFile name
HKLM\SOFTWARE\Microsoft\NapServer
{ComputerName}_NapServer_reg_.TXT
Microsoft-Windows-MSSHAV-SHV/Operational
{ComputerName}__evt_*.*

Network adapters
DescriptionFile name
W8/WS2012 powershell output for network adapter information
{ComputerName}_NetworkAdapters_info_pscmdlets.TXT

Network connections
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\Netman
{ComputerName}_NetworkConnections_reg_.TXT
W8/WS2012 powershell output for network connections
{ComputerName}_NetworkConnections_info_pscmdlets.TXT

Network LBFO
DescriptionFile name
W8/WS2012 powershell output for Network LBFO
{ComputerName}_NetworkLBFO.TXT

Network List
DescriptionFile name
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList
HKLM\SYSTEM\CurrentControlSet\services\netprofm
{ComputerName}_NetworkList_reg_.TXT
Microsoft-Windows-NetworkProfile/Operational
{ComputerName}__evt_*.*

Network Location Awareness
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc
{ComputerName}_NetworkLocationAwareness_reg_.TXT
Microsoft-Windows-NlaSvc/Operational
{ComputerName}__evt_*.*

Network Store Interface
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\nsi
HKLM\SYSTEM\CurrentControlSet\services\nsiproxy
{ComputerName}_NetworkStoreInterface_reg_.TXT

NLB
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\WLBS
{ComputerName}_NLB_reg_.TXT
NLB display information from nlb.exe output
{ComputerName}_NLB_nlb-display.txt
NLB query information from nlb.exe output
{ComputerName}_NLB_nlb-query.txt
W8/WS2012 powershell output for NLB
{ComputerName}_NLB_info_pscmdlets.TXT

NPS
DescriptionFile name
If W2003, HKLM\SYSTEM\CurrentControlSet\services\IAS
{ComputerName}_IAS_reg_.TXT
If WS2008 and later, HKLM\SYSTEM\CurrentControlSet\services\IAS
{ComputerName}_NPS_reg_.TXT
If WS2008 and later, Netsh output for IAS (W2003 and later)
{ComputerName}_IAS_netsh_output.TXT
If WS2008 and later, Netsh output for NPS
{ComputerName}_NPS_netsh_output.TXT

P2P
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\p2pimsvc
HKLM\SYSTEM\CurrentControlSet\services\p2psvc
{ComputerName}_P2P_reg_output.TXT
P2P information from netsh p2p output
{ComputerName}_P2P_netsh_output.TXT

Proxy Configuration
DescriptionFile name
Copies PAC files from Internet Explorer locations
Network Isolation Policy registry information
Proxy Configuration: Firewall Client Proxy Configuration (ISA/TMG)
Proxy Configuration: IE System
Proxy Configuration: IE User
Proxy Configuration: WinHTTP

RAS
DescriptionFile name
HKLM\System\CurrentControlSet\services\RasMan
{ComputerName}_RAS_reg_.TXT
RAS information from netsh ras output
{ComputerName}_RAS_netsh_ras-output.TXT
RAS Tracing Logs located at windir\tracing\*.*
{ComputerName}_RasTracingLog_*.*

Remote Desktop Gateway component
DescriptionFile name
HKCU\Software\Policies\Microsoft\Windows NT\Terminal Services
HKLM\SYSTEM\CurrentControlSet\services\TSGateway
{ComputerName}_RDG_reg_.TXT

Remote File Systems Client component
DescriptionFile name
Remote File System Client binary versions
{ComputerName}_RemoteFileSystemClient_BinaryVersions.TXT

Remote File Systems Server component
DescriptionFile name
Remote File System Server binary versions
{ComputerName}_RemoteFileSystemServer_BinaryVersions.TXT

RPC
DescriptionFile name
HKLM\Software\Microsoft\Rpc
HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper
HKLM\SYSTEM\CurrentControlSet\Services\RpcLocator
HKLM\SYSTEM\CurrentControlSet\Services\RpcSs
{ComputerName}_RPC_reg_output.TXT
RPC information from netsh rpc output
{ComputerName}_RPC_netsh_output.TXT

Server manager and server roles information
DescriptionFile name
List of roles and features installed on Server media (Windows Server 2008 R2 and later)
resultreport.xml


SMB Client
DescriptionFile name
HKCU\Network
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider
HKLM\SYSTEM\CurrentControlSet\Control\SMB
HKLM\SYSTEM\CurrentControlSet\services\LanManWorkstation
HKLM\SYSTEM\CurrentControlSet\services\lmhosts
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb10
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb20
HKLM\SYSTEM\CurrentControlSet\services\MUP
HKLM\SYSTEM\CurrentControlSet\services\NetBIOS
HKLM\SYSTEM\CurrentControlSet\services\NetBT
HKLM\SYSTEM\CurrentControlSet\services\Rdbss
{ComputerName}_SmbClient_reg_output.TXT
SMB Client Information from Net.exe
{ComputerName}_SmbClient_info.TXT

SMB Server
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\LanManServer
HKLM\SYSTEM\CurrentControlSet\services\SRV
HKLM\SYSTEM\CurrentControlSet\services\SRV2
HKLM\SYSTEM\CurrentControlSet\services\SRVNET
{ComputerName}_SmbServer_reg_output.TXT
SMB Server Information from tools such as Net.exe
{ComputerName}_SmbServer_info.txt

SNMP
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\Control\SNMP
HKLM\SYSTEM\CurrentControlSet\services\SNMP
HKLM\SYSTEM\CurrentControlSet\services\SNMPTRAP
{ComputerName}_SNMP_reg_output.TXT

System Performance Monitor
DescriptionFile name
Performance Monitor Log
{ComputerName}_*.blg
Performance Monitor Report
{ComputerName}_report.html

TCPIP
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\TCPIP
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc
HKLM\SYSTEM\CurrentControlSet\services\TCPIP
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6
HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg
{ComputerName}_TCPIP_reg_output.TXT
Microsoft-Windows-Iphlpsvc/Operational
{ComputerName}__evt_*.*
TCP OFFLOAD information from netstat output
{ComputerName}_TCPIP_OFFLOAD.TXT
TCPIP Information from commands like: hostname, ipconfig, route, netstat etc.
{ComputerName}_TCPIP_info.TXT
TCPIP information from netsh output
{ComputerName}_TCPIP_netsh_info.TXT
TCPIP Services File located at: windir\system32\drivers\etc\services
{ComputerName}_TCPIP_ServicesFile.TXT
W8/WS2012 powershell output for TCPIP
{ComputerName}_TCPIP_info_pscmdlets_net.TXT

WebClient
DescriptionFile name
HKCU\Network
HKCU\Software\Microsoft\Office\14.0\Common\Internet
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider
HKLM\System\CurrentControlSet\Services\MRxDAV
HKLM\SYSTEM\CurrentControlSet\services\WebClient
{ComputerName}_WebClient_reg_output.TXT
WebClient proxy settings from command: netsh winhttp show proxy
{ComputerName}_WebClient_netsh_winhttp-proxy-settings.txt
WebClient proxy settings from proxycfg.exe output
{ComputerName}_WebClient_proxycfg.txt

WinHTTP
DescriptionFile name
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKLM\System\CurrentControlSet\Services\WinHttpAutoProxySvc
{ComputerName}_WinHTTP_reg_output.TXT
WinHTTP proxy settings from command: netsh winhttp show proxy
{ComputerName}_WinHTTP_netsh_proxy-settings.txt
WinHTTP proxy settings from proxycfg.exe output
{ComputerName}_WinHTTP_proxycfg.txt

WINS Client
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\WINS
{ComputerName}_WinsClient_reg_output.TXT
WINS Client - Lmhosts file located at: windir\system32\drivers\etc\LMHOSTS
{ComputerName}_WinsClient_LmhostsFile.TXT
WINS Client information from nbtstat output
{ComputerName}_WinsClient_nbtstat-output.TXT

WINS Server
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\WINS
{ComputerName}_WinsServer_reg_output.TXT
WINS Server information from netsh output
{ComputerName}_WinsServer_netsh_output.TXT

WinSock
DescriptionFile name
Microsoft-Windows-Winsock-AFD/Operational
Microsoft-Windows-Winsock-WS2HELP/Operational
{ComputerName}__evt_*.*
HKLM\SYSTEM\CurrentControlSet\services\AFD
HKLM\SYSTEM\CurrentControlSet\services\WinSock
HKLM\SYSTEM\CurrentControlSet\services\WinSock2
Registry Information for WinSock and AFD:
{ComputerName}_WinSock_reg_.TXT
Winsock information from netsh winsock output
{ComputerName}_WinSock_netsh.TXT


In addition to collecting the information that is described earlier, this package can perform the following diagnostic tasks:  
  • Check for Symantec Endpoint Protection MR1/MR2
  • Check for Evaluation Media
  • Check whether Page Heap is enabled to one or more processes
  • Check whether driver verifier has been enabled for at least one driver
  • Check for ephemeral port usage
  • Check for ephemeral port usage
  • Check DNS zones for top level CNAME records
  • Windows Firewall start mode check
  • Check whether Windows Firewall is running
  • IPv6 check
  • IPv6 6To4 interface check
  • Check whether there's more than 32 GB of physical memory and whether the operating system is Windows 2008 R2 Standard Edition
  • Check whether PMTU has been disabled on the computer
  • Check for unexpected TcpIp registry settings (KB 967224)
  • Check for excessive number of 6to4 adapters (which may decrease startup and logon performance)
  • Check whether Tunnel.sys driver is missing a Windows Server 2008 R2 Server Core installation option
  • Check for problem related to Microsoft DHCP Relay Agent that may cause slow startup (KB2459530)
  • Check HTTP Redirection on TSGateway
  • Check whether the SMB2 Client driver has been disabled
  • Check whether the SMB2 Server driver has been disabled
  • Check whether Opportunistic Locking has been disabled
  • Check whether InfoCacheLevel setting is configured to enable caching for all files and folders
  • Check whether McAfee HIPS 7.0 is installed
  • Check for Best Practices Analyzer errors and warnings
  • Check for memory dump-related issues
  • Check whether one or more processes are using a large number of handles
  • Check for kernel memory performance-related problems
  • Check whether the system is currently running under low system PTEs
  • Check whether the system is currently running under low virtual memory
  • Check for System Performance warnings
  • Check whether there are any virtual machines that have high CPU utilization
  • Check whether dynamic memory is enabled to one or more virtual machines
  • Check whether dynamic memory is enabled on one or more virtual machines with old Integration Services
  • Check for version mismatches of Integration Services
  • Check whether one or more virtual machines have virtual hard drives located on a disk with Advanced Format drives (512e disks)
  • Check for event log messages
  • Check the virtualization environment

References

For more information about the Microsoft Automated Troubleshooting Services and about the Support Diagnostics Platform, see the following Microsoft Knowledge Base article:  

2598970 Information about Microsoft Automated Troubleshooting Services and Support Diagnostic Platform

↑ Back to the top


Keywords: kb

↑ Back to the top

Article Info
Article ID : 2562677
Revision : 1
Created on : 1/7/2017
Published on : 6/14/2013
Exists online : False
Views : 843