Event ID: 10009-Microsoft Windows DistributedCOM
You all ever seen this error from System Logs?
The description for Event ID 10009 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component
on the local computer.
If the event originated on another computer, the display information had to be saved with the event.
The following information was included with the event:
COMPUTERNAMEHERE
Thanks Torsten.
From my research it looks like SCCM is trying to locate some machines that are no longer on the network but yet DNS is reporting it.
So I have asked DNS Guys to flush or refresh the DNS.
We often bring these dead\redundant records back from AD via the AD discovery methods ... it is a good idea to get the AD guys to do some house-cleaning or at least set the permissions on dead objects so that the Site serve performing the discovery does not
have read access on the object.
Similar Messages
-
Hi there... I am getting the above mentioned error with the
Description: dows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
Full message is -
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 5/15/2012 1:18:44 PM
Event ID: 10016
Task Category: None
Level: Error
Keywords: Classic
User: NT AUTHORITY\IUSR
Computer: Server.domain.com
Description:
The description for Event ID 10016 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on
the local computer.
If the event originated on another computer, the display information had to be saved with the event.
The following information was included with the event:
application-specific
Local
Activation
{2D527A8C-A4B6-4E74-A63F-E867360D401C}
{B13EFBAE-7504-4938-9ED7-8E8B53E51221}
NT AUTHORITY
IUSR
S-1-5-17
LocalHost (Using LRPC)
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="49152">10016</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2012-05-15T19:18:44.000000000Z" />
<EventRecordID>43121</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>Server.Domain.com</Computer>
<Security UserID="S-1-5-17" />
</System>
<EventData>
<Data Name="param1">application-specific</Data>
<Data Name="param2">Local</Data>
<Data Name="param3">Activation</Data>
<Data Name="param4">{2D527A8C-A4B6-4E74-A63F-E867360D401C}</Data>
<Data Name="param5">{B13EFBAE-7504-4938-9ED7-8E8B53E51221}</Data>
<Data Name="param6">NT AUTHORITY</Data>
<Data Name="param7">IUSR</Data>
<Data Name="param8">S-1-5-17</Data>
<Data Name="param9">LocalHost (Using LRPC)</Data>
</EventData>
</Event>
Please let me know any solutions to fix....
Steps, I did try from one of the blogs -
Open Component Services. Got oStart --> Control Panel --> Administrative Tools --> Components Services. Expand the Component Services branch then expand Computers, My Computer and DCOM Config. Right-click on "sms agent host" (my case) and click
Properties. Click on the Security tab and under “Launch and Activation Permissions” select "edit" and add user Local Service (Local lunch). Click OK, close the Component Services window.
In the Launch Permission dialog box, make sure that the Everyone group has Remote Launch and Remote Activation permissions.
In the Launch Permission dialog box, make sure that the SMS Reporting Users local group has following permissions:
Local Launch / Remote Launch / Local Activation / Remote Activation
Also added Remote Launch / Remote Activation permission for Network Service (for the SMS_Reporting_Point)
Added Admin Group to the "ConfigMgr Remote Control Users"
VTIn addition, In the security policy the ‘Local Service’ need to be configured for the following Policies
- Generate security audits
- Create global objects
- Replace a process level token
- Adjust memory quotas for a process
- Impersonate a client after authentication
- Log on as a service
- Bypass traverse checking
Hope this helps.
Regards,
Yan Li
hi,
i m having similiar error but with another APPID
i did what u said in 1st part but i couldnt get what u mean in additional settings ? i couldnt do that.
Error details :
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 7/2/2013 4:03:20 PM
Event ID: 10016
Task Category: None
Level: Error
Keywords: Classic
User: LOCAL SERVICE
Computer: THINK
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{7160A13D-73DA-4CEA-95B9-37356478588A}
and APPID
{7160A13D-73DA-4CEA-95B9-37356478588A}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="0">10016</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2013-02-07T14:03:20.356793400Z" />
<EventRecordID>1465</EventRecordID>
<Correlation />
<Execution ProcessID="868" ThreadID="2832" />
<Channel>System</Channel>
<Computer>THINK</Computer>
<Security UserID="S-1-5-19" />
</System>
<EventData>
<Data Name="param1">machine-default</Data>
<Data Name="param2">Local</Data>
<Data Name="param3">Activation</Data>
<Data Name="param4">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
<Data Name="param5">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
<Data Name="param6">NT AUTHORITY</Data>
<Data Name="param7">LOCAL SERVICE</Data>
<Data Name="param8">S-1-5-19</Data>
<Data Name="param9">LocalHost (Using LRPC)</Data>
<Data Name="param10">Unavailable</Data>
<Data Name="param11">Unavailable</Data>
</EventData>
</Event> -
Last night, some of our systems installed updates released on 11/13/2014.
KB3021674
KB2901983
KB3023266
KB3014029
KB3022777
KB3020388
KB890830
Today, all of the servers running Windows Server 2008 R2 started logging the following error in the Security log over and over:
Log Name: Security
Source: Microsoft-Windows-Eventlog
Date: 1/15/2015 11:12:39 AM
Event ID: 1108
Task Category: Event processing
Level: Error
Keywords: Audit Success
User: N/A
Description:
The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.
Servers running Windows Server 2008 that also installed the updates are not experiencing the problem. It looks like one of the updates may have introduced this problem with Server 2008 R2....Did you for sure confirm that:
https://technet.microsoft.com/library/security/MS15-001
is the cause?
I did. I had a VM that was not experiencing the problem. I took a snapshot and tested the patches one by one. Installing only KB3023266 immediately caused the issue to occur (after reboot). A similar process was used to confirm that
installing KB2675611 resolved the problem.
Note that I found the installation of KB2675611 is usually quick, but it took several hours hours to install on some of our systems. We had installed this patch a few months ago on a couple of servers and it was always quick to install. But,
it seems like installing it on a symptomatic system can cause it to take a long time. -
DistributedCOM Event ID 10010 on Windows 2008 R2
Hi,
I'm getting following error on one of my Virtual Windows 2008 R2 server and have tried lots of solutions but still this event logging on my server.
The GUID mentioned in the event is related to Virtual Disk Service and I have verified all security permission related setting in component services as well as in Windows Registry but no luck yet.
Please help to resolve this issue.
Following are the event details:
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 19/04/2013 9:02:54 PM
Event ID: 10010
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: ExchangeSVR.Gen3Com.local
Description:
The server {7D1933CB-86F6-4A98-8628-01BE94C9A575} did not register with DCOM within the required timeout.
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="49152">10010</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-04-19T11:02:54.000000000Z" />
<EventRecordID>133132</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>ExchangeSVR.Gen3Com.local</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">{7D1933CB-86F6-4A98-8628-01BE94C9A575}</Data>
</EventData>
</Event>
Thanks,Hi Thakur,
I believe, this thread may help to fix DCOM issue.
http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/8c292062-64f2-4c1a-8c50-13ababb67738/
Regards, Ravikumar P -
Hello,
I upgraded my machine to Win7 x64 Pro about 3 weeks ago. My HW is an Asus mobo, Intel Q9450 w/8GB RAM. The boot drives are two Raptors configured as RAID01. All the drivers are the latest available from Intel, Asus and 3rd party vendors. My WEI is 5.9, limited by the disk transfer rates, otherwise 7.1 and 7.2 on the other indexes.
I've been receiving these errors at boot;
Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
Source: Microsoft-Windows-Kernel-EventTracing
Date: 11/10/2009 7:51:03 AM
Event ID: 4
Task Category: Logging
Level: Warning
Keywords: Session
User: SYSTEM
Computer: herbt-PC
Description:
The maximum file size for session "ReadyBoot" has been reached. As a result, events might be lost (not logged) to file "C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl". The maximum files size is currently set to 20971520 bytes.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
<EventID>4</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>1</Task>
<Opcode>10</Opcode>
<Keywords>0x8000000000000010</Keywords>
<TimeCreated SystemTime="2009-11-10T12:51:03.393985600Z" />
<EventRecordID>28</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="164" />
<Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
<Computer>herbt-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="SessionName">ReadyBoot</Data>
<Data Name="FileName">C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl</Data>
<Data Name="ErrorCode">3221225864</Data>
<Data Name="LoggingMode">0</Data>
<Data Name="MaxFileSize">20971520</Data>
</EventData>
</Event>
The image for PID 4 is listed as System.
My searches have turned up similar events listed but no solutions.
Any help would be appreciated.
Cheers!Session "Circular Kernel Context Logger" failed to start with the following error: 0xC0000035
As suggested above I assume this is a microsoft issue? It has been discussed here and other forums for quite some time. I never have seen a fix? I wish when we received errors of this nature microsoft would tell us what they were. How is this related to superfetch? What is superfetch? Why would superfetch have changed?
BY THE WAY.... Superfetch is on(started) is on automatic and logs on as local system. So this is not the cause of my issue. Also what is readyboot? Does the average computer really know what these programs/services or unique microsoft words/terms are?
System
Provider
[ Name]
Microsoft-Windows-Kernel-EventTracing
[ Guid]
{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}
EventID
2
Version
0
Level
2
Task
2
Opcode
12
Keywords
0x8000000000000010
TimeCreated
[ SystemTime]
2010-04-11T14:35:49.829600000Z
EventRecordID
25
Correlation
Execution
[ ProcessID]
4
[ ThreadID]
48
Channel
Microsoft-Windows-Kernel-EventTracing/Admin
Computer
Daddy-PC
Security
[ UserID]
S-1-5-18
EventData
SessionName
Circular Kernel Context Logger
FileName
ErrorCode
3221225525
LoggingMode
268436608
Windows7, Windows, Win7 -
Events 5719, NETLOGON, Event 1129, Microsoft-Windows-GroupPolicy
I have been seeing these events lately on our Windows 7 PCs. We have 2 domain controllers, Server 2012 and 2003. I think most of these events started after I added the 2012 DC. We were running just the one 2003 DC. I moved DHCP from
the 2003 to the 2012. Both servers are AD integrated DNS servers and a third server is a DNS secondary server.
I tried the hotfix from here...
http://support.microsoft.com/kb/2459530
on one PC as a test. It appears to have solved the 1129 event but I still get the 5719 NETLOGON event. I also tried updating the Gigabit NIC drivers on this system but it didn't help. What should I try next?
Hi,
According to the following article,
this behavior can occur when your server is connected to a switch that has the spanning tree "portfast" setting disabled.
To work around this behavior, enable the spanning tree "portfast" setting on the switch.
A “Netlogon event ID 5719” event message is logged when you start a Windows based computer
http://support.microsoft.com/kb/247922
Hope this helps. -
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 11/10/2010 4:31:37 PM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (2)
User: SYSTEM
Computer: Felix-PC
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2010-10-11T06:31:37.175213500Z" />
<EventRecordID>96455</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Felix-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">244</Data>
<Data Name="BugcheckParameter1">0x3</Data>
<Data Name="BugcheckParameter2">0xfffffa8002d20b30</Data>
<Data Name="BugcheckParameter3">0xfffffa8002d20e10</Data>
<Data Name="BugcheckParameter4">0xfffff80002fcd5d0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event><Data Name="BugcheckCode">244</Data>
244 (dez) = F4 (hex)
Bug Check 0xF4: CRITICAL_OBJECT_TERMINATION -
This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated.
Cause
Several processes and threads are necessary for the operation of the system. When they are terminated for any reason, the system can no longer function.
Please copy the dmp files from the folder C:\Windows\Minidump first to your desktop, zip all dmp into 1 zip file and upload the zip file to your Skydrive [1] and post a link here, so that I can look at the dumps with the debugger and to to see the cause of
the crash.
André
[1]
http://social.technet.microsoft.com/Forums/en-US/w7itproui/thread/4fc10639-02db-4665-993a-08d865088d65
"A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/ -
Hi,
Does anyone know why some of the events in ETL (created using WPRUI) generated through Microsoft-Windows-GroupPolicy provider have '%%<EventID>' instead of the event description? Is there a way
to fix it?
I wonder if the standard 'First Level Triage' profile doesn't have some necessary option configured to have these collected and the log should be collected using command line?
Thanks,
Ivan
Ivan SeriavinHi,
Does anyone know why some of the events in ETL (created using WPRUI) generated through Microsoft-Windows-GroupPolicy provider have '%%<EventID>' instead of the event description? Is there a way
to fix it?
I wonder if the standard 'First Level Triage' profile doesn't have some necessary option configured to have these collected and the log should be collected using command line?
Thanks,
Ivan
Ivan Seriavin -
Event ID 1 Error Microsoft-Windows-UAC Microsoft-Windows-UAC/Operational
This error pops upon every restart of Windows Server 2012.
Event ID 1 Error Microsoft-Windows-UAC Microsoft-Windows-UAC/Operational
The process failed to handle ERROR_ELEVATION_REQUIRED during the creation of a child process.
Event Viewer traces user to S-1-5-18 SYSTEM, Execution ProcessID in Task Manager corresponds to SVCHOST.EXE.
SYSTEM is the owner of SVCHOST.EXE, even having granted SYSTEM permission Full Control does not fix the error.
Any help will be appreciated.@Dharmesh, thanks for your advice.
The specific SVCHOST process causing the error runs these services :
- Application Experience
- Application Information
- Certificate Propagation
- Group Policy Client
- IKE and AuthIP IPsec Keying Modules
- IP Helper
- Multimedia Class Scheduler
- Remote Access Connection Manager
- Remote Desktop Configuration
- Routing and Remote Access
- Server
- Shell Hardware Detection
- System Event Notification Service
- Task Scheduler
- Themes
- User Profile Service
- Windows Management Instructmentation
- Windows Update
I doubted if any of those would actually need the ElevateCreateProcess fix.
However, I gave it a try, applying the compatibility fixes at Server 2003 and Vista SP2 levels; yet the error was not corrected.
So, combing through those services seemed unavoidable. Eventually, the culprit was identified.
For the benefits of people encountering the same issue, this may help save some clueless efforts.
Somehow, Windows Server setup a RaMgmtUIRestartTask in Task Scheduler, to run ramgmtui.exe as Administrators at log on of any user; but, not granting it the necessary permission. It is supposed to start the Remote Access Management console, failing which
it logs the Event ID 1 Error, and gives little hint on the whereabouts of the cause.
To stop the error, one would simply locate the scheduled task, then have it disabled, or check the option to grant it the highest privilege. -
Microsoft-Windows-Folder Redirection Error 502. CSC database locked by another user
Dear all,
We are finalizing our Windows 7 migration where we migrated 500+ clients. In our enterprise concept we implemented RUP (Roaming User Profiles) and Redirected Folders for all
users. The Redirected Folders have been by enabled by a single GPO which redirects all folders from
AppData to
Searches \\servername.domain.name\documents$\%username%.
Problem:
The RUP and Redirected folders solution works fine until a new user wants to logon. This new user has been migrated to RUP and Redirected on another system and
he just wants to work on another workplace or gets a temporary pc. What happens is that redirected folders do not work. The user gets a message that the folder is not reachable and desktop is empty.
Troubleshooting:
Soon I found out that something was being locked. If we used a user account which had working Redirect Folders than this
worked for that user. An event of 10 was logged in OfflineFiles area of EventViewer to reconnect the path which was configured in the GPO.
This is example screenshot. It says "Error on Open Folder. \\server.domain.name\documents$\%username%\Desktop refers to a location that is unavailable. It could be on a hard disk
on this computer, or a on a network. Check to make sure that the disk is properly inserted, or that you are connected to the Internet or your network, and then try again. If it still cannot be located, the information might have been moved to a different location."
These symptoms happen randomly and not on all workstations. The pain here is when it happens on a portable computer. For desktop we disabled the "Disable Offline Files' in "Manage
Offline Files" control panel and then reboot. After the reboot the folders are directed
and it works without these errors... On portable computer we can't use this work around as they need to work offline.
If I connect to the share without the FQDN like \\servername\documents$\%username%\Desktop than this works fine and user can access all folders. When I try the FQDN path which is
configured in the GPO to redirect user to like \\servername.domain.name\documents$\%username%\Desktop than it fails with this message. I personally think because the C:\Windows\CSC database is locked by the previous user who has been logged on this system.
An example of the event generated in the Applications Event viewer part (I removed some username and server path):
Log Name: Application
Source: Microsoft-Windows-Folder Redirection
Date: 1-2-2011 17:40:11
Event ID: 502
Task Category: None
Level: Error
Keywords:
User: domain\ivan
Computer: computer.domain.name
Description:
Failed to apply policy and redirect folder "Videos" to "\\servername.domain.name\documents$\ivan\Documents\My Videos".
Redirection options=0x1001.
The following error occurred: "Can not create folder "\\\servername.domain.name\documents$\ivan\Documents\My Videos"".
Error details: "Access is denied.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Folder Redirection" Guid="{7D7B0C39-93F6-4100-BD96-4DDA859652C5}" />
<EventID>502</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2011-02-01T16:40:11.486983400Z" />
<EventRecordID>2754</EventRecordID>
<Correlation ActivityID="{3211E6FB-2801-456D-BE6E-66AAE150A4DC}" />
<Execution ProcessID="968" ThreadID="5856" />
<Channel>Application</Channel>
<Computer>computer.domain.name</Computer>
<Security UserID="S-1-5-21-3705223304-2632712944-1292073641-26755" />
</System>
<EventData Name="EVENT_FDEPLOY_FailedToApplyPolicy">
<Data Name="FromFolder">Videos</Data>
<Data Name="ToFolder">\\servername.domain.name\documents$\ivan\Documents\My Videos</Data>
<Data Name="Options">0x1001</Data>
<Data Name="Error">Can not create folder "\\servername.domain.name\documents$\ivan\Documents\My Videos"</Data>
<Data Name="ErrorDetails">Access is denied.
</Data>
</EventData>
</Event>
Something like this I see in the Application Eventviewer:
Environment:
Windows 7 Enterprise client with patches until 1-Nov-2010
Windows Server 2008 R2 for the Documents$ share
Windows Server 2003 R2 as the domain controller
I have tried all different option even to rebuild the CSC database but this also was not helping. I hope we are not dealing with a bug.
Any help is much appreciated.
Best regards, Ivan Versluis http://www.networknet.nlIvan and SteveDIG - Thanks for taking the time to post detailed information about what you have found. I have found the same things over the past few months and have been working with Microsoft to resolve this. Like Ivan, I have been told by
MS that this is a design problem in Windows 7, but they did admit it is a bug and did not charge me for the case. That was the good news. The bad news was that the problem is so 'deep' in Windows 7 that it will not be fixed until Windows 8 and
the CSC engineering team in Redmond has rejected several requests to fix this issue in Windows 7 from several customers. I personally feel we should have hauled our TAM in over this, but that wasn't my call so we haven't attempted to get an attitude
change from MS.
<RANT> I find this completely outrageous. Windows is supposed to be a multi-user operating system suitable for deployment to mobile workforces spread around the world and often using slow VPN links. Offline folders, folder redirection,
slow link detection, etc. are all great on paper and as I did the design work for the W7 solution I've just built I sold these advantages heavily. I now have serious egg on my face and am not happy. Like others here I missed this in testing as
multiple users are a fringe for us, but still important, I unfortunately didn't think to specifically test for multiple users, though I tested the features thoroughly and was happy with the results when used on single user machines.</RANT>
As identified above, this issue manifests when more than one user uses a machine and their Offline folders (all redirected folders are configured this way by default) are in an offline state when the first user logs off. The second user cannot access
this 'offline' share so folder redirection fails. We get burnt as we have latency=0 configured for slow link detection with Offline folders so users always work offline. This is partly because of WAN optimisers in the network that lie to Windows
so the online/offline transition doesn't work on slow links (not MS's fault), and partly because it made sense for other reasons.
The workaround Microsoft and I came up with for our environment was to use individual file shares for each user. We had been using a common file share with each user folder under that file share. Changing to an individual share for each users
means the share is not locked by the previous user.
Examples
This would cause a problem if John then Emma logged on to the same machine. Folder redirection would fail for Emma:
\\FileServer1\Users$\john
\\FileServer1\Users$\emma
So would this if DFS was used
\\my.domain\users\john (points to \\FileServer1\Users$\John)
\\my.domain\users\emma (points to \\FileServer1\Users$\Emma)
This would fix the problem:
\\FileServer1\John$
\\FileServer1\Emma$
Unfortunately we then figured we could move these shares behind DFS like so:
\\my.domain\homes\john (points to \\FileServer1\John$)
\\my.domain\homes\emma (points to \\FileServer1\emma$)
This was wrong. The problem returned. I assume the share that is being locked is now the DFS root and not the user share.
The operations team here is very reluctant to go with direct access to the file servers and not use DFS as that will create issues for them in the future when they need to make file server changes. I sympathise with them but can't see an alternative
at the moment as we are deploying W7 and can't stop. If I'd picked this up earlier a third party product might have been the solution (MS actually suggested this when I opened my case).
I hope the information about individual shares above is helpful to someone. Otherwise I don't really have more to add but I needed the rant :-)
<RANT>BTW. Has anyone tested changing a user’s home directory path once it is cached? Try it. Test a scenario where you move the user from one file server to another. You will not enjoy the results. I'll say no more
than this as it is off topic, but it shows the lack of investment in the CSC feature in Windows. Very disappointing</RANT> -
Hello!
I've a big problem with this MP. When the zone monitoring is enabled (by default) the MonitoringHost.exe takes up all the CPU. I've put the zones in Maintenance mode.
I've got this problem only with a new Windows 2012 R2 server. Other Windows Servers (2003 R2, 2008 & 2008 R2) with DNS Server Role they don't have this problem.
Any ideas?
Thank you!
The configuration is:
SCOM 2012 R2
Microsoft Windows Server DNS Monitoring v7.1.10100.0 Management Pack
DNS Management Pack Action Account has been configured
"Act as proxy..." is enabled
The monitored server config:
Windows Server 2012 R2 (standalone)
DNS Server Role installed
DNS Management Pack Action Account is a member of the "Administrators" group
The only events I've are the following but I'm not sure if they're related (because of the ...DNSSEC...):
Log Name: Operations Manager
Source: Health Service Modules
Date: 8/11/2013 11:16:21
Event ID: 11903
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: NS2...
Description:
The Microsoft Operations Manager Expression Filter Module could not convert the received value to the requested type.
Property Expression: Property[@Name='QueriesResponded']
Property Value: Property[@Name='QueriesResponded']
Conversion Type: DataItemElementTypeInteger(5)
Original Error: 0x80FF005A
One or more workflows were affected by this.
Workflow name: Microsoft.Windows.Server.DNS.2012R2.Monitor.DNSSEC.NameResolutionQueries
Instance name: <zone-name> on NS2...
Instance ID: {4BCB4738-1287-2E6F-E0AA-1FF8D66DDB0B}
Management group: <grp-name>
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Health Service Modules" />
<EventID Qualifiers="49152">11903</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-11-08T09:16:21.000000000Z" />
<EventRecordID>9602</EventRecordID>
<Channel>Operations Manager</Channel>
<Computer>NS2...</Computer>
<Security />
</System>
<EventData>
<Data><grp-name></Data>
<Data>Microsoft.Windows.Server.DNS.2012R2.Monitor.DNSSEC.NameResolutionQueries</Data>
<Data><zone name> on NS2...</Data>
<Data>{4BCB4738-1287-2E6F-E0AA-1FF8D66DDB0B}</Data>
<Data>Property[@Name='QueriesResponded']</Data>
<Data>Property[@Name='QueriesResponded']</Data>
<Data>DataItemElementTypeInteger(5)</Data>
<Data>0x80FF005A</Data>
</EventData>
</Event>Glad to see you found the solution and thanks for your sharing.
Niki Han
TechNet Community Support -
== Issue
==
I have another kind of problem with Firefox
== Description
==
In migrating from an XP PC to a new Win 7 PC, I downloaded Firefox to the new PC and it worked fine - got my Gmail contacts, calendar, etc. Later I used Micros Soft's Windows Easy Transfer to move data, profiles, etc to the new PC. Then could log onto Gmail but it would not show Contacts or Calendar. I then uninstalled Firefox and reinstalled it - nohelp, then I did a system to Restore to before I did the Windows Easy Transfer - no help, then I manually moved my Firefox Profile from the XP machine - no help. BTW at least one other website does not display correctly: http://www.hollandamerica.com/main/Main.action. NOTE - through all this Internet Explorer has shown these sites correctly.
== This happened
==
Every time Firefox opened
== Used Microsoft Windows Easy Transfer
==
== Troubleshooting information
==
Troubleshooting Information
This page contains technical information that might be useful when you're
trying to solve a problem. If you are looking for answers to common questions
about Firefox, check out our support web site.
Copy all to clipboard
Application Basics
Name
Firefox
Version
3.6.3
Profile Directory
Open Containing Folder
Installed Plugins
about:plugins
Build Configuration
about:buildconfig
Extensions
Name
Version
Enabled
ID
Flashblock 1.5.13 true {3d7eb24f-2740-49df-8937-200b1cc08f8a}
Google Notebook 1.0.0.22 false [email protected]
Microsoft .NET Framework Assistant 1.2.1 true {20a82645-c095-46ed-80e3-08825760534b}
PDF Download 3.0.0.1 false {37E4D8EA-8BDA-4831-8EA1-89053939A250}
Java Console 6.0.20 true
McAfee SiteAdvisor 3.0 true
Modified Preferences
Name
Value
accessibility.typeaheadfind.flashBar 0
browser.history_expire_days 20
browser.history_expire_days.mirror 20
browser.places.importBookmarksHTML false
browser.places.importDefaults false
browser.places.leftPaneFolderId -1
browser.places.migratePostDataAnnotations false
browser.places.smartBookmarksVersion 2
browser.places.updateRecentTagsUri false
browser.startup.homepage https://mail.google.com/mail/?shva=1#contacts
browser.startup.homepage_override.mstone rv:1.9.2.3
browser.tabs.loadInBackground false
dom.disable_window_move_resize true
dom.event.contextmenu.enabled false
extensions.lastAppVersion 3.6.3
general.useragent.extra.microsoftdotnet ( .NET CLR 3.5.30729)
network.cookie.lifetimePolicy 1
network.cookie.prefsMigrated true
network.image.imageBehavior 0
places.last_vacuum 1273287748
print.print_printer HP Photosmart C7100 series
print.printer_HP_OfficeJet_Pro_1170Cse.print_bgcolor false
print.printer_HP_OfficeJet_Pro_1170Cse.print_bgimages false
print.printer_HP_OfficeJet_Pro_1170Cse.print_command
print.printer_HP_OfficeJet_Pro_1170Cse.print_downloadfonts false
print.printer_HP_OfficeJet_Pro_1170Cse.print_evenpages true
print.printer_HP_OfficeJet_Pro_1170Cse.print_footercenter
print.printer_HP_OfficeJet_Pro_1170Cse.print_footerleft &PT
print.printer_HP_OfficeJet_Pro_1170Cse.print_footerright &D
print.printer_HP_OfficeJet_Pro_1170Cse.print_headercenter
print.printer_HP_OfficeJet_Pro_1170Cse.print_headerleft &T
print.printer_HP_OfficeJet_Pro_1170Cse.print_headerright &U
print.printer_HP_OfficeJet_Pro_1170Cse.print_in_color true
print.printer_HP_OfficeJet_Pro_1170Cse.print_margin_bottom 0.3
print.printer_HP_OfficeJet_Pro_1170Cse.print_margin_left 0.5
print.printer_HP_OfficeJet_Pro_1170Cse.print_margin_right 0.3
print.printer_HP_OfficeJet_Pro_1170Cse.print_margin_top 0.3
print.printer_HP_OfficeJet_Pro_1170Cse.print_oddpages true
print.printer_HP_OfficeJet_Pro_1170Cse.print_orientation 0
print.printer_HP_OfficeJet_Pro_1170Cse.print_pagedelay 500
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_data 1
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_height 11.00
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_size 1634485807
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_size_type 0
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_size_unit 0
print.printer_HP_OfficeJet_Pro_1170Cse.print_paper_width 8.50
print.printer_HP_OfficeJet_Pro_1170Cse.print_printer HP OfficeJet Pro 1170Cse
print.printer_HP_OfficeJet_Pro_1170Cse.print_reversed false
print.printer_HP_OfficeJet_Pro_1170Cse.print_scaling 1.00
print.printer_HP_OfficeJet_Pro_1170Cse.print_shrink_to_fit true
print.printer_HP_OfficeJet_Pro_1170Cse.print_to_file false
print.printer_HP_Photosmart_C7100_series.print_bgcolor false
print.printer_HP_Photosmart_C7100_series.print_bgimages false
print.printer_HP_Photosmart_C7100_series.print_command
print.printer_HP_Photosmart_C7100_series.print_downloadfonts false
print.printer_HP_Photosmart_C7100_series.print_edge_bottom 0
print.printer_HP_Photosmart_C7100_series.print_edge_left 0
print.printer_HP_Photosmart_C7100_series.print_edge_right 0
print.printer_HP_Photosmart_C7100_series.print_edge_top 0
print.printer_HP_Photosmart_C7100_series.print_evenpages true
print.printer_HP_Photosmart_C7100_series.print_footercenter
print.printer_HP_Photosmart_C7100_series.print_footerleft &PT
print.printer_HP_Photosmart_C7100_series.print_footerright &D
print.printer_HP_Photosmart_C7100_series.print_headercenter
print.printer_HP_Photosmart_C7100_series.print_headerleft &T
print.printer_HP_Photosmart_C7100_series.print_headerright &U
print.printer_HP_Photosmart_C7100_series.print_in_color true
print.printer_HP_Photosmart_C7100_series.print_margin_bottom 0.300000011920929
print.printer_HP_Photosmart_C7100_series.print_margin_left 0.5
print.printer_HP_Photosmart_C7100_series.print_margin_right 0.300000011920929
print.printer_HP_Photosmart_C7100_series.print_margin_top 0.300000011920929
print.printer_HP_Photosmart_C7100_series.print_oddpages true
print.printer_HP_Photosmart_C7100_series.print_orientation 0
print.printer_HP_Photosmart_C7100_series.print_pagedelay 500
print.printer_HP_Photosmart_C7100_series.print_paper_data 1
print.printer_HP_Photosmart_C7100_series.print_paper_height 11.00
print.printer_HP_Photosmart_C7100_series.print_paper_size 1634485807
print.printer_HP_Photosmart_C7100_series.print_paper_size_type 0
print.printer_HP_Photosmart_C7100_series.print_paper_size_unit 0
print.printer_HP_Photosmart_C7100_series.print_paper_width 8.50
print.printer_HP_Photosmart_C7100_series.print_reversed false
print.printer_HP_Photosmart_C7100_series.print_scaling 0.80
print.printer_HP_Photosmart_C7100_series.print_shrink_to_fit false
print.printer_HP_Photosmart_C7100_series.print_to_file false
print.printer_HP_Photosmart_C7100_series.print_unwriteable_margin_bottom 0
print.printer_HP_Photosmart_C7100_series.print_unwriteable_margin_left 0
print.printer_HP_Photosmart_C7100_series.print_unwriteable_margin_right 0
print.printer_HP_Photosmart_C7100_series.print_unwriteable_margin_top 0
print.printer_hp_psc_1200_series.print_bgcolor false
print.printer_hp_psc_1200_series.print_bgimages false
print.printer_hp_psc_1200_series.print_command
print.printer_hp_psc_1200_series.print_downloadfonts false
print.printer_hp_psc_1200_series.print_evenpages true
print.printer_hp_psc_1200_series.print_footercenter
print.printer_hp_psc_1200_series.print_footerleft &PT
print.printer_hp_psc_1200_series.print_footerright &D
print.printer_hp_psc_1200_series.print_headercenter
print.printer_hp_psc_1200_series.print_headerleft &T
print.printer_hp_psc_1200_series.print_headerright &U
print.printer_hp_psc_1200_series.print_in_color true
print.printer_hp_psc_1200_series.print_margin_bottom 0.3
print.printer_hp_psc_1200_series.print_margin_left 0.5
print.printer_hp_psc_1200_series.print_margin_right 0.3
print.printer_hp_psc_1200_series.print_margin_top 0.3
print.printer_hp_psc_1200_series.print_oddpages true
print.printer_hp_psc_1200_series.print_orientation 0
print.printer_hp_psc_1200_series.print_pagedelay 500
print.printer_hp_psc_1200_series.print_paper_data 1
print.printer_hp_psc_1200_series.print_paper_height 11.00
print.printer_hp_psc_1200_series.print_paper_size 1634485807
print.printer_hp_psc_1200_series.print_paper_size_type 0
print.printer_hp_psc_1200_series.print_paper_size_unit 0
print.printer_hp_psc_1200_series.print_paper_width 8.50
print.printer_hp_psc_1200_series.print_reversed false
print.printer_hp_psc_1200_series.print_scaling 1.00
print.printer_hp_psc_1200_series.print_shrink_to_fit true
print.printer_hp_psc_1200_series.print_to_file false
privacy.clearOnShutdown.cookies false
privacy.clearOnShutdown.downloads false
privacy.clearOnShutdown.formdata false
privacy.clearOnShutdown.history false
privacy.clearOnShutdown.passwords true
privacy.cpd.cookies false
privacy.cpd.downloads false
privacy.cpd.formdata false
privacy.cpd.history false
privacy.item.downloads false
privacy.item.formdata false
privacy.item.history false
privacy.item.passwords true
privacy.sanitize.migrateFx3Prefs true
privacy.sanitize.promptOnSanitize false
privacy.sanitize.sanitizeOnShutdown true
security.warn_viewing_mixed false
== Firefox version
==
3.6.3
== Operating system
==
Windows 7
== User Agent
==
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 ( .NET CLR 3.5.30729)
== Plugins installed
==
*-Default Plug-in
*NPRuntime Script Plug-in Library for Java(TM) Deploy
*Shockwave Flash 10.0 r45
*McAfee Virtual Technician plugin for Mozilla (Gecko Version: 1.8b1)
*3.0.50106.0
*NPWLPG
*Next Generation Java Plug-in 1.6.0_20 for Mozilla browsers
*Adobe PDF Plug-In For Firefox and NetscapeOops - for some reason, this problem now seems to have gone away. May have had something to do with Flash. I'll keep my fingers crossed.
-
Microsoft Windows - Intrastat Has Stopped Working error message...
Hi Experts,
When running the Intrastat Declaration Report the following error window box pops up:
Microsoft Windows
Intrastat For Business One Has Stopped Working
Windows can check online for a solution to the problem
-> Check on line for a solution and close the program
-> Close the program
Problem Signature:
Problem Event Name: BEX
Application Name: BN_Intrastat.exe
Application Version: 8.80.229.0
Application Timestamp: 4db5952d
Fault Module Name: MSVCR80.dll
Fault Module Version: 8.0.50727.4053
Fault Module Timestamp: 4a594c79
Exception Offset: 0000eb46
Exception Code: c000000d
Please can you help me with this one please?
It's SAP 8.8
Many thanks in advance for any help!
CarolineHi Caroline,
Your question belongs to 3rd arty add-on forum. I will move it there after few days.
To give you a tip: try restart everything to see if problem could be gone away. If not, you have to do a clean reinstall for the add-on.
Thanks,
Gordon -
Microsoft Windows Kernal Power
I have a computer that has bluescreened twice without anything happening. Both times it is reported that no one is using the laptop. It's just sitting there not doing anything. I looked at the Event Viewer and there are Kernal-Power events, and then Kernal-Processor-Power
events. The most recent gave me these details:
- System
- Provider
[ Name] Microsoft-Windows-Kernel-Power
[ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4}
EventID 41
Version 2
Level 1
Task 63
Opcode 0
Keywords 0x8000000000000002
- TimeCreated
[ SystemTime] 2015-04-09T19:18:11.102008100Z
EventRecordID 29574
Correlation
- Execution
[ ProcessID] 4
[ ThreadID] 8
Channel System
Computer LIZ2-PC
- Security
[ UserID] S-1-5-18
- EventData
BugcheckCode 0
BugcheckParameter1 0x0
BugcheckParameter2 0x0
BugcheckParameter3 0x0
BugcheckParameter4 0x0
SleepInProgress false
PowerButtonTimestamp 0
I'm trying to assess why these blue screens are occurring so I can do some preventative work on it. Be it replacing the computer or the RAM, this issue is slowing productivity and I need to rectify it before it halts productivity.We do need the actual log files (called a DMP files) as they contain the only record
of the sequence of events leading up to the crash, what drivers were loaded, and what was responsible.
Please follow our instructions for finding and uploading the files we need to help you fix your computer. They can be found here
As this thread has been quiet for a while, we assume that the issue has been resolved. At this time, we will mark it as ‘Answered’ as the previous
steps should be helpful for many similar scenarios.
If the issue still persists and you want to return to this question, please reply this post directly so we will be notified to follow it up. You
can also choose to unmark the answer as you wish.
In addition, we’d love to hear your feedback about the solution. By sharing your experience you can help other community members facing similar
problems.
Thanks!
Arnav Sharma | http://arnavsharma.net/ Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
the thread. -
Can anyone tell me what the possible values are for the CurrentState value of a package under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages
For Example:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2900986~31bf3856ad364e35~amd64~~6.1.1.1
"CurrentState"=dword:00000070
I believe that this equates to "Installed", but I am looking for somewhere that documents this.
I located http://technet.microsoft.com/en-us/library/cc756248%28v=ws.10%29.aspx and the related events pages show values like 0, 4, 5, 6, 7. Not x00000070 (112) etc
Thanks In Advance
JimHi Jim,
Thank you for your post.
From your description, I see that you want to know if there is a related official article which introduces the value of CurrentState (dword:00000070) under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages.
Please let me know if I have misunderstood anything.
Based on my research, I'm sorry that it appears that there is not a corresponding official document which can meet your requirement. However, according to my knowledge, 99% of the time the value will be 00000070 for CurrentState.
Currently, I'd like to confirm that if there is any real problem occurs due to the registry value? If so, then we may find another way to help with you.
Please feel free to let me know if you have any questions. Thank you for your time and understanding.
Best Regards,
Sophis Sun
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Maybe you are looking for
-
Unable to capture stdout, stderr from python.
I am trying to read the stdout and stderr of a python program. When I invoke anything else apart from python my class works fine. The python program takes ca 1 sec to start. It then prints one line of text, then it prints a promt and waits for input
-
Install Oracle 8.0.5 on Slackware 3.5,
Install Oracle 8.0.5 Trial on Slackware 3.5, I set all environ and logon as oracle to run /home/oracle/install/orainst/orainst, it give error that ./.orainst.cm: file not exist, but the file do exist, and the permission is rwx, why? thanks for help.
-
Profit center derivation in cross company transactions
Hi I have following business scenario: we have 2 company codes A and B A company is there in X and Y locations B company is there in D and E locations Now we mapped locations are Profit Centers. Now we are transferring vendor balance from company
-
How to relink to all VI's at once?
I changed the terminals of a subVI that is used many times in my code. Do I really have to relink to all of them manually? Or is there a "relink all" option somewhere? Certified LabVIEW Developer (CLD)
-
Hi, I have to build my own connection pool. Any resources and help will be appreciated. cheers, vjoy