Event IDs 136 and 137 0x80000000000000 in System Log on Windows 2008 R2 Server, Exchange 2010 in Cluster
Hi,
I'm having an issue with one of my exchange 2010 Servers. We had a power outage and upon recovery, I cannot start Services Net.Pipe Listener Adapter and Net.Tcp Listener Adapter (And thus cannot Start IIS and provide Exchange Client Services.) This is a
physical server (Not VMWare or Hyper-V)
The System event log has lots of Event 136's and 137s on Ntfs with the keyword - 0x80000000000000 - The General Messages are: The default transaction resource manager on volume C: encountered an error while starting and its metadata was
reset. The data contains the error code.
and
The default transaction resource manager on volume OS encountered a non-retryable error and could not start. The data contains the error code.
XML Output as follows:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Ntfs" />
<EventID Qualifiers="32772">136</EventID>
<Level>3</Level>
<Task>2</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated
SystemTime="2014-11-17T18:10:37.788942300Z" />
<EventRecordID>315532</EventRecordID>
<Channel>System</Channel>
<Computer>server.domain.com</Computer>
<Security />
</System>
- <EventData>
<Data />
<Data>C:</Data>
<Binary>1C00040002003000020000008800048000000000060019C000000000000000000000000000000000060019C0</Binary>
</EventData>
</Event>
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Ntfs" />
<EventID Qualifiers="49156">137</EventID>
<Level>2</Level>
<Task>2</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated
SystemTime="2014-11-17T18:10:37.788942300Z" />
<EventRecordID>315531</EventRecordID>
<Channel>System</Channel>
<Computer>server.domain.com</Computer>
<Security />
</System>
- <EventData>
<Data />
<Data>OS</Data>
<Binary>1C0004000200300002000000890004C000000000020100C000000000000000000000000000000000020100C0</Binary>
</EventData>
</Event>
When I attempt to start the services - I get the following errors:
The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error:
Transaction support within the specified resource manager is not started or was shut down due to an error.
The Net.Pipe Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error:
Transaction support within the specified resource manager is not started or was shut down due to an error.
I have tried the "fsutil resource setautoreset true" fix without success.
Any ideas or direction would be much appreciated. Restoring this server will be extremely difficult.
Thanks!
We can close this question.
From an elevated prompt, I ran 'fsutil resource setautoreset true' and attempted to remove the files with .blf and regtrans-ms file extensions from C:\Windows\System32\config\TxR. but these files were locked by system processes. (They are also
tagged with the hidden file attrib so you may not see them at first)
So, I booted the system with a Windows 2008 R2 Install Disk, selected repair OS and selected the command prompt. I then performed a chkdsk /f c: and selected "Y" to unmount the drive. It made some repairs.
With the system booted from the install disk, and chkdsk executed, the locks were freed and I was able to delete the files from C:\Windows\System32\config\TxR.
Once the system rebooted, the services came back fine and everything was back to normal.
Similar Messages
-
Errors for excel - excel service unavailable. Event Viewer has error event ids - 5239 and 5231.
We restart the excel service app and it solves. Looking for permanent solution.
Regards,
KunalTo resolved the issue do a simple restart.
Restart the server
Before restarting, verify that this problem occurs often. It may be an intermittent problem that is automatically corrected and does not require you to restart the server.
If the problem occurs often, restart the server running Excel Services Application.
If the problem continues to occur often, and restarting the server did not correct the problem, confirm that the hardware of the server is functioning correctly, or reinstall Excel Services Application and re-add the server to the server farm.
Here's the article with the explanation: Error communicating with Excel Services
Application - Events 5231 5239 5240
Please 'propose as answer' if it helped you, also 'vote helpful' if you like this reply. -
Windows 2008 R2 Server not showing update history and not detecting new updates
Hi Sirs,
We have a Windows 2008 R2 server which is showing an empty windows update history, and is not detecting new updates from the WSUS server. It says that the windows is up to date, no error when trying to detect new updates, but I doubt it because when I checked
the installed updates menu, it shows that that the most recent update date installed was last 2013, it just stop detecting and installing updates. I've already tried the ff workarounds but to no avail:
1. restart wuauserv and bits service
2. rename/delete the software distribution folder
3. reinstalled the update agent/restarted the server
4. deleted the susclientid on the registry
Thanks in advanced for your help.
here's the windowsupdate.log:
2014-07-22 00:57:06:728 928 a34 AU #############
2014-07-22 00:57:06:728 928 a34 AU Successfully wrote event for AU health state:0
2014-07-22 00:57:06:728 928 a34 AU Featured notifications is disabled.
2014-07-22 00:57:06:728 928 a34 AU AU setting next detection timeout to 2014-07-21 20:50:56
2014-07-22 00:57:06:728 928 a34 AU Successfully wrote event for AU health state:0
2014-07-22 00:57:06:728 928 a34 AU Successfully wrote event for AU health state:0
2014-07-22 00:57:11:727 928 abc Report REPORT EVENT: {AF0753F1-F6F9-4583-87B0-A0B0AEA0C6A7} 2014-07-22 00:57:06:728+0800 1
147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows
Update Client successfully detected 0 updates.
2014-07-22 00:57:11:727 928 abc Report REPORT EVENT: {188957AA-577F-4DC5-9CDB-2D8CFEE96670} 2014-07-22 00:57:06:728+0800 1
156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting
client status.
2014-07-22 00:57:11:727 928 abc Report CWERReporter finishing event handling. (00000000)
2014-07-22 01:11:10:931 928 abc Report Uploading 2 events using cached cookie, reporting URL = http://mtp-wsus2/ReportingWebService/ReportingWebService.asmx
2014-07-22 01:11:10:947 928 abc Report Reporter successfully uploaded 2 events.
2014-07-22 04:50:56:736 928 1130 AU #############
2014-07-22 04:50:56:736 928 1130 AU ## START ## AU: Search for updates
2014-07-22 04:50:56:736 928 1130 AU #########
2014-07-22 04:50:56:736 928 1130 AU <<## SUBMITTED ## AU: Search for updates [CallId = {F40B494F-91F1-4FFB-B7A5-46CEA397AA52}]
2014-07-22 04:50:56:736 928 d08 Agent *************
2014-07-22 04:50:56:736 928 d08 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 04:50:56:736 928 d08 Agent *********
2014-07-22 04:50:56:736 928 d08 Agent * Online = Yes; Ignore download priority = No
2014-07-22 04:50:56:736 928 d08 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation'
or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-07-22 04:50:56:736 928 d08 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-07-22 04:50:56:736 928 d08 Agent * Search Scope = {Machine}
2014-07-22 04:50:57:017 928 d08 Setup Checking for agent SelfUpdate
2014-07-22 04:50:57:017 928 d08 Setup Client version: Core: 7.6.7600.256 Aux: 7.6.7600.256
2014-07-22 04:50:57:017 928 d08 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 04:50:57:017 928 d08 Misc Microsoft signed: Yes
2014-07-22 04:50:59:611 928 d08 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 04:50:59:611 928 d08 Misc Microsoft signed: Yes
2014-07-22 04:50:59:611 928 d08 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 04:50:59:611 928 d08 Misc Microsoft signed: Yes
2014-07-22 04:50:59:626 928 d08 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 04:50:59:626 928 d08 Misc Microsoft signed: Yes
2014-07-22 04:50:59:626 928 d08 Setup Determining whether a new setup handler needs to be downloaded
2014-07-22 04:50:59:626 928 d08 Setup SelfUpdate handler is not found. It will be downloaded
2014-07-22 04:50:59:626 928 d08 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 04:51:01:095 928 d08 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 04:51:01:095 928 d08 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 04:51:01:110 928 d08 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 04:51:01:110 928 d08 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 04:51:01:142 928 d08 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 04:51:01:142 928 d08 Setup SelfUpdate check completed. SelfUpdate is NOT required.
2014-07-22 04:51:01:860 928 d08 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-07-22 04:51:01:860 928 d08 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 04:51:01:891 928 d08 PT WARNING: Cached cookie has expired or new PID is available
2014-07-22 04:51:01:891 928 d08 PT Initializing simple targeting cookie, clientId = 487b95fe-31a4-44f7-9989-bd77766ce5fa, target group = , DNS name = itg-soatrainsvr.mbtc.mgc.local
2014-07-22 04:51:01:891 928 d08 PT Server URL = http://mtp-wsus2/SimpleAuthWebService/SimpleAuth.asmx
2014-07-22 04:51:04:485 928 d08 PT +++++++++++ PT: Synchronizing extended update info +++++++++++
2014-07-22 04:51:04:485 928 d08 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 04:51:04:875 928 d08 Agent * Found 0 updates and 68 categories in search; evaluated appl. rules of 503 out of 777 deployed entities
2014-07-22 04:51:04:875 928 d08 Agent *********
2014-07-22 04:51:04:875 928 d08 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 04:51:04:875 928 d08 Agent *************
2014-07-22 04:51:04:875 928 1278 AU >>## RESUMED ## AU: Search for updates [CallId = {F40B494F-91F1-4FFB-B7A5-46CEA397AA52}]
2014-07-22 04:51:04:875 928 1278 AU # 0 updates detected
2014-07-22 04:51:04:875 928 1278 AU #########
2014-07-22 04:51:04:875 928 1278 AU ## END ## AU: Search for updates [CallId = {F40B494F-91F1-4FFB-B7A5-46CEA397AA52}]
2014-07-22 04:51:04:875 928 1278 AU #############
2014-07-22 04:51:04:875 928 1278 AU Successfully wrote event for AU health state:0
2014-07-22 04:51:04:875 928 1278 AU Featured notifications is disabled.
2014-07-22 04:51:04:875 928 1278 AU AU setting next detection timeout to 2014-07-22 00:38:28
2014-07-22 04:51:04:875 928 1278 AU Successfully wrote event for AU health state:0
2014-07-22 04:51:04:875 928 1278 AU Successfully wrote event for AU health state:0
2014-07-22 04:51:09:874 928 d08 Report REPORT EVENT: {FE398C01-75A1-4AD8-8C43-0894FCFCE13F} 2014-07-22 04:51:04:875+0800 1
147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows
Update Client successfully detected 0 updates.
2014-07-22 04:51:09:874 928 d08 Report REPORT EVENT: {CDA386AD-6392-4C34-859E-35307BCB5EA0} 2014-07-22 04:51:04:875+0800 1
156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting
client status.
2014-07-22 04:51:09:874 928 d08 Report CWERReporter finishing event handling. (00000000)
2014-07-22 05:05:09:109 928 d08 Report Uploading 2 events using cached cookie, reporting URL = http://mtp-wsus2/ReportingWebService/ReportingWebService.asmx
2014-07-22 05:05:09:109 928 d08 Report Reporter successfully uploaded 2 events.
2014-07-22 08:38:28:883 928 1130 AU #############
2014-07-22 08:38:28:883 928 1130 AU ## START ## AU: Search for updates
2014-07-22 08:38:28:883 928 1130 AU #########
2014-07-22 08:38:28:883 928 1130 AU <<## SUBMITTED ## AU: Search for updates [CallId = {9A097F9F-88DD-4037-A4DD-48B9CC891327}]
2014-07-22 08:38:28:883 928 53c Agent *************
2014-07-22 08:38:28:883 928 53c Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 08:38:28:883 928 53c Agent *********
2014-07-22 08:38:28:883 928 53c Agent * Online = Yes; Ignore download priority = No
2014-07-22 08:38:28:883 928 53c Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation'
or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-07-22 08:38:28:883 928 53c Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-07-22 08:38:28:883 928 53c Agent * Search Scope = {Machine}
2014-07-22 08:38:29:195 928 53c Setup Checking for agent SelfUpdate
2014-07-22 08:38:29:195 928 53c Setup Client version: Core: 7.6.7600.256 Aux: 7.6.7600.256
2014-07-22 08:38:29:195 928 53c Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 08:38:29:195 928 53c Misc Microsoft signed: Yes
2014-07-22 08:38:31:804 928 53c Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 08:38:31:804 928 53c Misc Microsoft signed: Yes
2014-07-22 08:38:31:804 928 53c Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 08:38:31:820 928 53c Misc Microsoft signed: Yes
2014-07-22 08:38:31:820 928 53c Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 08:38:31:820 928 53c Misc Microsoft signed: Yes
2014-07-22 08:38:31:835 928 53c Setup Determining whether a new setup handler needs to be downloaded
2014-07-22 08:38:31:835 928 53c Setup SelfUpdate handler is not found. It will be downloaded
2014-07-22 08:38:31:835 928 53c Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 08:38:33:241 928 53c Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 08:38:33:241 928 53c Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 08:38:33:272 928 53c Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 08:38:33:272 928 53c Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 08:38:33:288 928 53c Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 08:38:33:288 928 53c Setup SelfUpdate check completed. SelfUpdate is NOT required.
2014-07-22 08:38:33:991 928 53c PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-07-22 08:38:33:991 928 53c PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 08:38:34:038 928 53c PT WARNING: Cached cookie has expired or new PID is available
2014-07-22 08:38:34:038 928 53c PT Initializing simple targeting cookie, clientId = 487b95fe-31a4-44f7-9989-bd77766ce5fa, target group = , DNS name = itg-soatrainsvr.mbtc.mgc.local
2014-07-22 08:38:34:038 928 53c PT Server URL = http://mtp-wsus2/SimpleAuthWebService/SimpleAuth.asmx
2014-07-22 08:38:36:616 928 53c PT +++++++++++ PT: Synchronizing extended update info +++++++++++
2014-07-22 08:38:36:616 928 53c PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 08:38:37:022 928 53c Agent * Found 0 updates and 68 categories in search; evaluated appl. rules of 503 out of 777 deployed entities
2014-07-22 08:38:37:022 928 53c Agent *********
2014-07-22 08:38:37:022 928 53c Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 08:38:37:022 928 53c Agent *************
2014-07-22 08:38:37:022 928 aa8 AU >>## RESUMED ## AU: Search for updates [CallId = {9A097F9F-88DD-4037-A4DD-48B9CC891327}]
2014-07-22 08:38:37:022 928 aa8 AU # 0 updates detected
2014-07-22 08:38:37:022 928 aa8 AU #########
2014-07-22 08:38:37:022 928 aa8 AU ## END ## AU: Search for updates [CallId = {9A097F9F-88DD-4037-A4DD-48B9CC891327}]
2014-07-22 08:38:37:022 928 aa8 AU #############
2014-07-22 08:38:37:022 928 aa8 AU Successfully wrote event for AU health state:0
2014-07-22 08:38:37:022 928 aa8 AU Featured notifications is disabled.
2014-07-22 08:38:37:022 928 aa8 AU AU setting next detection timeout to 2014-07-22 04:15:53
2014-07-22 08:38:37:022 928 aa8 AU Successfully wrote event for AU health state:0
2014-07-22 08:38:37:022 928 aa8 AU Successfully wrote event for AU health state:0
2014-07-22 08:38:42:021 928 53c Report REPORT EVENT: {45B5AD35-C612-4C43-8FE0-DFC63B114FC9} 2014-07-22 08:38:37:022+0800 1
147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows
Update Client successfully detected 0 updates.
2014-07-22 08:38:42:021 928 53c Report REPORT EVENT: {BA606714-0153-41BA-ADC8-78520F678D97} 2014-07-22 08:38:37:022+0800 1
156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting
client status.
2014-07-22 08:38:42:021 928 53c Report CWERReporter finishing event handling. (00000000)
2014-07-22 08:52:41:224 928 53c Report Uploading 2 events using cached cookie, reporting URL = http://mtp-wsus2/ReportingWebService/ReportingWebService.asmx
2014-07-22 08:52:41:240 928 53c Report Reporter successfully uploaded 2 events.
2014-07-22 12:15:53:027 928 1130 AU #############
2014-07-22 12:15:53:027 928 1130 AU ## START ## AU: Search for updates
2014-07-22 12:15:53:027 928 1130 AU #########
2014-07-22 12:15:53:027 928 1130 AU <<## SUBMITTED ## AU: Search for updates [CallId = {9BDC1D71-5139-49D4-88F0-E2B639CE8846}]
2014-07-22 12:15:53:043 928 a58 Agent *************
2014-07-22 12:15:53:043 928 a58 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 12:15:53:043 928 a58 Agent *********
2014-07-22 12:15:53:043 928 a58 Agent * Online = Yes; Ignore download priority = No
2014-07-22 12:15:53:043 928 a58 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation'
or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-07-22 12:15:53:043 928 a58 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-07-22 12:15:53:043 928 a58 Agent * Search Scope = {Machine}
2014-07-22 12:15:53:308 928 a58 Setup Checking for agent SelfUpdate
2014-07-22 12:15:53:308 928 a58 Setup Client version: Core: 7.6.7600.256 Aux: 7.6.7600.256
2014-07-22 12:15:53:308 928 a58 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 12:15:53:324 928 a58 Misc Microsoft signed: Yes
2014-07-22 12:15:55:901 928 a58 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 12:15:55:901 928 a58 Misc Microsoft signed: Yes
2014-07-22 12:15:55:901 928 a58 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 12:15:55:917 928 a58 Misc Microsoft signed: Yes
2014-07-22 12:15:55:917 928 a58 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 12:15:55:917 928 a58 Misc Microsoft signed: Yes
2014-07-22 12:15:55:933 928 a58 Setup Determining whether a new setup handler needs to be downloaded
2014-07-22 12:15:55:933 928 a58 Setup SelfUpdate handler is not found. It will be downloaded
2014-07-22 12:15:55:933 928 a58 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 12:15:57:167 928 a58 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 12:15:57:167 928 a58 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 12:15:57:167 928 a58 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 12:15:57:167 928 a58 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 12:15:57:198 928 a58 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 12:15:57:198 928 a58 Setup SelfUpdate check completed. SelfUpdate is NOT required.
2014-07-22 12:15:57:917 928 a58 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-07-22 12:15:57:917 928 a58 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 12:15:57:963 928 a58 PT WARNING: Cached cookie has expired or new PID is available
2014-07-22 12:15:57:963 928 a58 PT Initializing simple targeting cookie, clientId = 487b95fe-31a4-44f7-9989-bd77766ce5fa, target group = , DNS name = itg-soatrainsvr.mbtc.mgc.local
2014-07-22 12:15:57:963 928 a58 PT Server URL = http://mtp-wsus2/SimpleAuthWebService/SimpleAuth.asmx
2014-07-22 12:16:00:572 928 a58 PT +++++++++++ PT: Synchronizing extended update info +++++++++++
2014-07-22 12:16:00:572 928 a58 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 12:16:00:932 928 a58 Agent * Found 0 updates and 68 categories in search; evaluated appl. rules of 503 out of 777 deployed entities
2014-07-22 12:16:00:932 928 a58 Agent *********
2014-07-22 12:16:00:932 928 a58 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 12:16:00:932 928 a58 Agent *************
2014-07-22 12:16:00:932 928 1120 AU >>## RESUMED ## AU: Search for updates [CallId = {9BDC1D71-5139-49D4-88F0-E2B639CE8846}]
2014-07-22 12:16:00:932 928 1120 AU # 0 updates detected
2014-07-22 12:16:00:932 928 1120 AU #########
2014-07-22 12:16:00:932 928 1120 AU ## END ## AU: Search for updates [CallId = {9BDC1D71-5139-49D4-88F0-E2B639CE8846}]
2014-07-22 12:16:00:932 928 1120 AU #############
2014-07-22 12:16:00:932 928 1120 AU Successfully wrote event for AU health state:0
2014-07-22 12:16:00:932 928 1120 AU Featured notifications is disabled.
2014-07-22 12:16:00:932 928 1120 AU AU setting next detection timeout to 2014-07-22 08:15:22
2014-07-22 12:16:00:932 928 1120 AU Successfully wrote event for AU health state:0
2014-07-22 12:16:00:932 928 1120 AU Successfully wrote event for AU health state:0
2014-07-22 12:16:05:931 928 a58 Report REPORT EVENT: {25E75367-1205-4F59-A812-02DA28BB3234} 2014-07-22 12:16:00:932+0800 1
147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows
Update Client successfully detected 0 updates.
2014-07-22 12:16:05:931 928 a58 Report REPORT EVENT: {FE1434F8-C6AF-4F87-B3DF-6E4D6C4B05FB} 2014-07-22 12:16:00:932+0800 1
156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting
client status.
2014-07-22 12:16:05:931 928 a58 Report CWERReporter finishing event handling. (00000000)
2014-07-22 12:30:05:116 928 a58 Report Uploading 2 events using cached cookie, reporting URL = http://mtp-wsus2/ReportingWebService/ReportingWebService.asmx
2014-07-22 12:30:05:131 928 a58 Report Reporter successfully uploaded 2 events.
2014-07-22 14:05:29:584 928 10a0 AU Triggering AU detection through DetectNow API
2014-07-22 14:05:29:584 928 10a0 AU Triggering Online detection (interactive)
2014-07-22 14:05:29:584 928 1130 AU #############
2014-07-22 14:05:29:584 928 1130 AU ## START ## AU: Search for updates
2014-07-22 14:05:29:584 928 1130 AU #########
2014-07-22 14:05:29:584 928 1130 AU <<## SUBMITTED ## AU: Search for updates [CallId = {CC67CC44-7DFB-49DE-AA83-8D6A7995ABFA}]
2014-07-22 14:05:29:584 928 8e0 Agent *************
2014-07-22 14:05:29:584 928 8e0 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 14:05:29:584 928 8e0 Agent *********
2014-07-22 14:05:29:584 928 8e0 Agent * Online = Yes; Ignore download priority = No
2014-07-22 14:05:29:584 928 8e0 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation'
or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-07-22 14:05:29:584 928 8e0 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-07-22 14:05:29:584 928 8e0 Agent * Search Scope = {Machine}
2014-07-22 14:05:29:584 928 8e0 Setup Checking for agent SelfUpdate
2014-07-22 14:05:29:584 928 8e0 Setup Client version: Core: 7.6.7600.256 Aux: 7.6.7600.256
2014-07-22 14:05:29:584 928 8e0 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 14:05:29:600 928 8e0 Misc Microsoft signed: Yes
2014-07-22 14:05:29:616 928 8e0 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
2014-07-22 14:05:29:631 928 8e0 Misc Microsoft signed: Yes
2014-07-22 14:05:29:631 928 8e0 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 14:05:29:631 928 8e0 Misc Microsoft signed: Yes
2014-07-22 14:05:29:647 928 8e0 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
2014-07-22 14:05:29:662 928 8e0 Misc Microsoft signed: Yes
2014-07-22 14:05:29:662 928 8e0 Setup Determining whether a new setup handler needs to be downloaded
2014-07-22 14:05:29:662 928 8e0 Setup SelfUpdate handler is not found. It will be downloaded
2014-07-22 14:05:29:662 928 8e0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 14:05:29:662 928 8e0 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 14:05:29:662 928 8e0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 14:05:29:694 928 8e0 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 14:05:29:694 928 8e0 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256"
2014-07-22 14:05:29:709 928 8e0 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.6.7600.256" is already installed.
2014-07-22 14:05:29:725 928 8e0 Setup SelfUpdate check completed. SelfUpdate is NOT required.
2014-07-22 14:05:30:037 928 8e0 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-07-22 14:05:30:037 928 8e0 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 14:05:30:053 928 8e0 PT WARNING: Cached cookie has expired or new PID is available
2014-07-22 14:05:30:053 928 8e0 PT Initializing simple targeting cookie, clientId = 487b95fe-31a4-44f7-9989-bd77766ce5fa, target group = , DNS name = itg-soatrainsvr.mbtc.mgc.local
2014-07-22 14:05:30:053 928 8e0 PT Server URL = http://mtp-wsus2/SimpleAuthWebService/SimpleAuth.asmx
2014-07-22 14:05:35:630 928 8e0 PT +++++++++++ PT: Synchronizing extended update info +++++++++++
2014-07-22 14:05:35:630 928 8e0 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://mtp-wsus2/ClientWebService/client.asmx
2014-07-22 14:05:36:411 928 8e0 Agent * Found 0 updates and 68 categories in search; evaluated appl. rules of 503 out of 777 deployed entities
2014-07-22 14:05:36:411 928 8e0 Agent *********
2014-07-22 14:05:36:411 928 8e0 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-07-22 14:05:36:411 928 8e0 Agent *************
2014-07-22 14:05:36:411 928 1360 AU >>## RESUMED ## AU: Search for updates [CallId = {CC67CC44-7DFB-49DE-AA83-8D6A7995ABFA}]
2014-07-22 14:05:36:411 928 1360 AU # 0 updates detected
2014-07-22 14:05:36:411 928 1360 AU #########
2014-07-22 14:05:36:411 928 1360 AU ## END ## AU: Search for updates [CallId = {CC67CC44-7DFB-49DE-AA83-8D6A7995ABFA}]
2014-07-22 14:05:36:411 928 1360 AU #############
2014-07-22 14:05:36:411 928 1360 AU Successfully wrote event for AU health state:0
2014-07-22 14:05:36:411 928 1360 AU Featured notifications is disabled.
2014-07-22 14:05:36:411 928 1360 AU AU setting next detection timeout to 2014-07-22 10:01:01
2014-07-22 14:05:36:411 928 1360 AU Successfully wrote event for AU health state:0
2014-07-22 14:05:36:411 928 1360 AU Successfully wrote event for AU health state:0
2014-07-22 14:05:41:410 928 8e0 Report REPORT EVENT: {6A2B180E-A95F-42F7-B775-5750DFFD6ECD} 2014-07-22 14:05:36:411+0800 1
147 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software Synchronization Windows
Update Client successfully detected 0 updates.
2014-07-22 14:05:41:410 928 8e0 Report REPORT EVENT: {83041427-693D-4A42-AED0-E8E7BFB8E7E3} 2014-07-22 14:05:36:411+0800 1
156 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Pre-Deployment Check Reporting
client status.
2014-07-22 14:05:41:410 928 8e0 Report CWERReporter finishing event handling. (00000000)No Service Pack 1 installed. Does this mean that no updates will be detected if SP1 is not installed? thanks
That's exactly what that means!
Updates have not been available for Windows Server 2008 R2 *RTM* systems since April, 2013.
http://support.microsoft.com/lifecycle/?p1=14134
Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
SolarWinds Head Geek
Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
http://www.solarwinds.com/gotmicrosoft
The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds. -
Tracking oracle database activities in security/system logs of windows server
Can database activity like create or drop tables and packages be tracked in the security/system logs of windows 2003 server for the oracle database 10.2.0.4?
Can purging of oracle log, n case the file has become big or even tempered be tracked in the security/system logs of windows 2003 server for the oracle database 10.2.0.4?
dhomyaHi Dhomya,
I am not familiar with Oracle database, though you may try to enable file system auditing:
Audit object access
https://technet.microsoft.com/en-us/library/cc776774(v=ws.10).aspx
Apply or modify auditing policy settings for an object using Group Policy
https://technet.microsoft.com/en-us/library/cc757864(v=ws.10).aspx
Best Regards,
Amy
Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] -
System.Windows.Forms.SaveFileDialog not working under Windows 2008 R2 Server
I am using Windows Server 2008 R2 (64-bit) that is been virtualized with Hyper-V and it is being used as a "Remote Desktop Server".
I am trying to use this PowerShell code that will open a "Save-File-Dialog" box to select the PDF file and send it to my "batch" file for scanning. This code works great on my Windows Vista machine and my Windows 7 32-bit machine
but I cannot get it to work on the "Windows 2008 R2 Server (64-bit)". It will not come up with any window at all and it will not produce any errors at all, so I can't exactly google for this issue. I am using PowerShell 2.0 from 2009.
Any ideas? I tried it from an Admin account and a regular domain users and neither worked at all, no errors, no window, no nothing.
*** Update ***
I took Out-Null out and I received this...
GAC Version Location
True v2.0.50727 C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
I then checked the path and the DLL file was in there and it had read and execute permissions for Domain users and Administrators and the window still won't pop up...
Here is the entire code in question.....
# Uses the dot net assembly to give the users a Save-File-Dialog box so they can decide where to put the pdf file
Function Get-SaveFile($initialDirectory){
[System.Reflection.Assembly]::LoadWithPartialName("System.windows.forms") | Out-Null
$SaveFileDialog = New-Object System.Windows.Forms.SaveFileDialog
$SaveFileDialog.initialDirectory = $initialDirectory
$SaveFileDialog.filter = "PDF files (*.pdf)| *.pdf"
$SaveFileDialog.ShowDialog() | Out-Null
$SaveFileDialog.filename
# open dialog box to select the .nessuss file.
$OutputFile = Get-SaveFile
# User selected where they want to put the scanned.pdf file and it will automatically set it to .pdf for them
start-process Scan $OutputFileI ran the code you have in your function on a Windows 2008 Standard server, and it seems to be hanging on the line
$SaveFileDialog.ShowDialog()
| Out-Null
It just sits there and nothing happens, but if I run it on my Windows 7 machines, it runs without any issues. So it seems like the dialog opened, but behind the scenes, and is waiting on the user, but since it doesn't open, the user can't do anything.
If you find that my post has answered your question, please mark it as the answer. If you find my post to be helpful in anyway, please click vote as helpful.
Don't Retire Technet -
Automate the database and forms / reports services to start on windows 2008 server R2 startup
Dear memebers,
I want to automate the database and forms / reports services to start on windows 2008 server R2 startup. whats the possibilities and which method is the best?
Regards:Hi,
type services.msc at run
then check for Oracle Services--> Right Click-->Properties-->Startup type-->start automatic
HTH -
Two Asa Two Isp and Windows 2008 R2 Server
Hello Everybody ,
If you can support my issue , I do appreciate a lot.
First of all thanks a lot for your interest ..
Here is my issue :
I have two Isp Connection ( 1 metro Eth Connection and 1 Ghdsl Connection )
1) Asa 5505 (Version 8.0(5)) is for the 1.st Isp Connection
Windows 2008 R2 server is up and running as Web Server on this ASA 5505 config.
As:
(static (inside,outside) mywebsrv.mycompany.com 192.168.5.5 netmask 255.255.255.255
And Ipconfig of W2008Srv is 192.168.5.5 255.255.255.0 192.168.5.1 (Gateway ASA 5505)
2) Asa 5510 (Version 8.0(5)) is for the 2.nd Isp Connection
Windows 2003 R2 server is up and running as Ftp Server on this ASA 5510 config.
As:
(static (inside,outside) myftpsrv.mycompany.com 192.168.50.10 netmask 255.255.255.255
And Ipconfig of W2003Srv is 192.168.50.10 255.255.255.0 192.168.50.1 (Gateway ASA 5510)
Here is my question :
I need to move my Ftp server (due to old hardware + old server issues )
into the Windows 2008 R2 Server ( HP DL Server with 4 Nic).
If I conect my Asa 5510 to the second nic of Windows 2008 R2 Server.
and give an ip address as 192.168.50.10 255.255.255.0
what should be the gateway Ip address : ?
Before I go ahead and implement :
a) What do I need to do on the Windows 2008 R2 Server
as persistent route adds with different metrics
b) Any config adds or changes on Asa 5505 and ASA 5510 regarding static routes with
different metric and so on ...
Many thanks in advance for your support .If you do that, the second interface will work as a failsafe for the first NIC.
As far as i know, you won't be able to route traffic based on the type of traffic nor do load-balancing between the interfaces.
I guess the best approach will be to get a newer server and use it as a replacement for the one running 2003 R2. -
When I try to print using Windows 2008 print server I have to use the generic print drivers supplied. If I use the OEM driver the printer locks up. I have tried a HP 4 plus and a Canon Copier.
A number of vendor drivers written for OS X cannot be used when connecting via SMB to a printer that is shared by Windows. This is due to limitations of the driver.
In some cases, if you were to enable the LPD Print Service in Windows, you can connect to the share using the same syntax as SMB but on the Mac you would use the LPD as the protocol.
If you can reply with the brand and model of printer you have then we may be able to provide more information. -
OS X Leopard and Windows 2008 file server mount_smbfs
Hello
I am unable to use the command mount_smbfs to mount a share on a Windows 2008 file server in OS X 10.5.8 Leopard.
Here is what I am trying to do:
I have a Mac Mini running OS X 10.5.8 that is joined to a Windows 2003 Active Directory domain. I also have a stand alone Windows file server running Windows Server 2008.
I want to mount a share on the Windows 2008 file Server using the command line and not Finder. I do have a reason for wanting to do this which I wont bore you with.
On the Mac Mini, I log in with an Domain account that has permission to access the file shares on the Windows 2008 file server. In Terminal I do the following:
cd /Users/username
mkdir mountpoint
mount_smbfs //windows2008server/fileshare /Users/username/mountpoint
This command should mount the share "fileshare" hosted on server "windows2008server" in the folder "mountpoint" on the Mac Mini.
Here is the problem:
When I execute this command, I get:
Password: so I put in my password
then I get:
mount_smbfs: mount error: /Users/username/mountpoint: Broken pipe
Analysis of the problem:
I tried exactly the same commands to mount a share on a Windows 2003 file server. I am not asked for my password and the share mounts perfectly. I also tried the same command in OS X 10.6 to mount a share on a Windows 2008 file server, again, I was not asked for my password and the share mounted perfectly.
So the problem is only mounting Windows 2008 file shares using mount_smbfs in OS X 10.5.8. I am not sure quite what is going wrong here, as the Mac is joined to the domain, it is granted a Kerberos ticket so should not be asking for my password. Is this a known bug in OS X 10.5? Is there a fix/workaround for it?
Many thanks
Richard.Not sure what user the mount command defaults to. You may want to specify your user name in the mount command (you can also specify the password). Try using this:
mount_smbfs //username@windows2008server/fileshare /User/username/mountpoint
Of course substituting the Windows 2008 account name you are mounting with for the username.
Cheers,
Dave -
Hi
A newly installed Exchange 2013 Server (Mailbox and Client Access roles) shows every 5 minutes the event id's 16025 and 205 in the eventlog.
Both events are shown twice at the same time. First 205 then 16025 and again 205 and 16025.
Level: Error
Id 205 - Source: MSExchange Common
Id 16025 - Source: MSExchangeFrontEndTransport
Both have exactly the same description:
No DNS servers could be retrieved from network adapter 0957d69c-9b06-4b72-aa6b-ac825435b485. Check if the computer is connected to a network and Get-NetworkConnectionInfo returns any results
Get-NetworkConnectionInfo shows the following results:
RunspaceId : e854435f-ffbe-4ccb-81d9-7e729284e26a
Name : Microsoft Hyper-V Network Adapter
DnsServers : {10.10.32.34, 10.10.32.42}
IPAddresses : {10.10.32.45, 10.10.32.44, fe80::9cb9:ad68:c7cc:2052}
AdapterGuid : 0957d69c-9b06-4b72-aa6b-ac825435b485
MacAddress : 00:1D:D8:B7:1E:2A
Identity : 0957d69c-9b06-4b72-aa6b-ac825435b485
IsValid : True
ObjectState : Unchanged
Mailflow is working, I would like to get rid of these error events.
Any suggestions?
Regards
PeterHi,
According to your description, I understand that Exchange server experience an circulating error(Event ID 205, 16025), however mail flow works fine.
If I misunderstand your concern, please do not hesitate to let me know.
Basic on Event ID, I find an Microsoft article with a deep analysis. For your reference:
http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Exchange&ProdVer=8.0&EvtID=205&EvtSrc=MSExchange+Common&LCID=1033
http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Exchange&ProdVer=8.0&EvtID=16025&EvtSrc=MSExchangeTransport&LCID=1033
For your question, please try below steps for troubleshooting:
Step1:
1. Go to the Registry HKLM\System\Currentcontrolset\services\Tcpip\Adapters.
2. The GUID we have in 16025 would be seen missing from here.
3. If the GUID is present DO NOT DELETE it from the registry.
Step2:
1. Login EAC and switch to Servers.
2. Select a mailbox server to edit, double check the internal and external DNS configuration in DNS lookups.
3. Restart Microsoft Exchange Transport service.
Thanks
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Allen Wang
TechNet Community Support -
Windows 2008 R2 SP1 Exchange DAG event 1196 and 1579 Bad DNS Key
Hi,
I'm running an Exchange 2010 SP1 DAG on Windows 2008 R2 SP1. We are using an INFOBLOX appliance for DNS resolution.
DNS resolution is working and SRV records are created.
On one of the two clusternodes I get warning 1579 and error 1196 every 15 minutes. After looking around on the internet and technet, I found kb 977158 stating the problem and resolution. However this hotfix is not applicabel on Windows
2008 R2 SP1 .
How can I resolve these annoying events?
Event 1196 failoverClustering:
Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason:
DNS bad key.
Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server.
Event 1579 Failover Clustering
Cluster network name resource 'Cluster Name' failed to update the DNS record for name 'DAG.domain.local' over adapter 'NIC1-LAN'. The error code was 'DNS bad key. (9017)'. Ensure that a DNS server is accessible from this cluster node and contact your DNS
server administrator to verify the cluster identity can update the DNS record 'DAG.domain.local'.
FrederikCause:
The cluster name resource which has been added to the DNS prior to setup active passive cluster ( or any type) need to be updated by the Physical nodes on behalf of the resource record itself. When the active node owns the resources it want to update the
A record in the DNS database and DNS record which was created won’t allow any authenticated user to update the DNS record with the same owner
Solution:
Delete the existing A record for the cluster name and re-create it and make sure select the box says “Allow any authenticated user to update DNS record with the same owner name “Don’t worry about breaking anything , this has “ZERO”
impact to cluster simply delete the A record and re-create as it is suggested here.
http://amradmin.wordpress.com/2011/01/27/event-id-1196-1119-dns-operation-refused-cluster-servers/
Thanks,
Amr Tantawi |MCITP |EMA -
Windows 2008 member server, repeating event 4625 in the security log
Hello,
I'm having an issue with a member server on our 2008 domain, security log is filling up with event 4625, here are the details:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 4/23/2014 2:04:42 PM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: my.member.server
Description:
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name:
Account Domain:
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc000006a
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: -
Source Network Address: 10.0.0.115
Source Port: 51366
Detailed Authentication Information:
Logon Process: Kerberos
Authentication Package: Kerberos
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon request fails. It is generated on the computer where access was attempted.
The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).
The Process Information fields indicate which account and process on the system requested the logon.
The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>4625</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12544</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2014-04-23T18:04:42.197Z" />
<EventRecordID>99893119</EventRecordID>
<Correlation />
<Execution ProcessID="744" ThreadID="844" />
<Channel>Security</Channel>
<Computer>KLINEWEB.kline.local</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-0-0</Data>
<Data Name="SubjectUserName">-</Data>
<Data Name="SubjectDomainName">-</Data>
<Data Name="SubjectLogonId">0x0</Data>
<Data Name="TargetUserSid">S-1-0-0</Data>
<Data Name="TargetUserName">
</Data>
<Data Name="TargetDomainName">
</Data>
<Data Name="Status">0xc000006d</Data>
<Data Name="FailureReason">%%2313</Data>
<Data Name="SubStatus">0xc000006a</Data>
<Data Name="LogonType">3</Data>
<Data Name="LogonProcessName">Kerberos</Data>
<Data Name="AuthenticationPackageName">Kerberos</Data>
<Data Name="WorkstationName">-</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">-</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0x0</Data>
<Data Name="ProcessName">-</Data>
<Data Name="IpAddress">10.0.0.115</Data>
<Data Name="IpPort">51366</Data>
</EventData>
</Event>
The IP address that appears in source network address all belong to VPN clients. And it looks like its only happening with 4-5 IPs, all of which are VPN clients. These clients shouldn't be connecting to anything on this server, which is why its puzzling.
Our DC is Windows 2008 and the VPN server is another member server on the domain. I suspect the issue is at the client PCs since there are many other VPN clients connected that don't generate the event ID.
Can anyone tell what the issue might be?
Thanks.Hi Rayminette,
There are multiple login sources that could possibly be generating the errors:
FTP logins - check your FTP log to see if login failures are showing up at the same time.
Logins via Basic Authentication over http or https (simple, but possibly dangerous, way to password-protect a web site).
ASP scripts.
This logon type 8 indicates a network logon like logon type 3 but where the password was sent over the network in the clear text. Windows server doesn’t allow connection to shared file or printers with clear text authentication. The only situation
I’m aware of are logons from within an ASP script using the ADVAPI or when a user logs on to IIS using IIS’s basic authentication mode. In both cases the logon process in the event’s description will list advapi. Basic authentication is only dangerous
if it isn’t wrapped inside an SSL session (i.e. https). As far as logons generated by an ASP, script remember that embedding passwords in source code is a bad practice for maintenance purposes as well as the risk that someone malicious will view the source
code and thereby gain the password.
Reference from:
What is the source of thousands of 4625 Logon Failure errors with Logon Type 8 (NetworkCleartext)?
I hope this helps. -
Dear Team
i need solution from Microsoft for the issue;
My infrastructure
- Windows Server 2008 R2 (Role - AD and Terminal Service)- Updated
- Client Machine running with windows 7 pro (Updated)
- Client Using RDP Client to connect Windows 2008 Terminal Session
- All are working fine, but Redirect Printing is not working (Through Windows 7 Pro) ... (HP Laser Jet 1020 plus - attached in Client PC)
- it is working fine from Windows XP
- i was done All terminal setting in both end, also try RDP Login with Administrator User, but issue is not resolve;
What Microsoft can say about the issue;
Thanks & Regards,
VIMAL PRAJAPATI | 09824111686Have you checked the Print Service log in event viewer?
Here's How.
I have the Microsoft XPS driver on my clients, so I use that fact to my advantage below.
Click Start Button/Administrative Tools/Remote Desktop Services/Remote Desktop Services Manager on the RDSH server
Click the Sessions tab. PC’s are listed Under Client Name by their computer name. Take Note of the corresponding
ID. We will use this to locate the Printer information in the Event Log.
In the Event Log open Application and Services Logs/Microsoft/Windows/Print Service/Admin/ and Find the Event ID 823 entry that has the corresponding ID from the sessions tab you previously noted.
This Event Log Entry is created at Logon and you can only get the session ID when they are logged in.
This tells you what client printer was mapped for the client. The name that appears is the name of the Printer that was set on the client when the printer was installed.
See if you see any errors here.
If you see Event Id 823 with the following message “The default printer was changed to Microsoft XPS Document Writer,winspool,Ne00:. See the event user data for context information.” Twice in a row with no other messages in between, and the first occurs
at the time the user logged in, then their printer was not properly redirected.
You see the Microsoft XPS driver mapped for each session prior to Easy Print redirecting the client machine’s Default Printer.
Since your printer is the HP 1020 I would bet the driver on the client does not work with Easyprint. I would try the the HP Universal Print Driver or the driver for a printer that is very close, like the HP 1018.
Thanks,
Jeremy -
Hi Guys,
I'm experiencing a problem with CoCreateInstance, where it returns error 0x8007007e.
The code is something like this:
HRESULT hRes = S_OK;
CComPtr<IMyInterface> spObj;
if(FAILED(CoInitialize(NULL))) { /* quit */ }while(FAILED(hRes = spObj.CoCreateInstance(CLDIS_MyClass, NULL, CLSCTX_LOCAL_SERVER)))
// LogFailure(hRes);
Sleep(10);
The problems occurs only on a single machine having Windows 2008 Enterprise SP2 installed (it works fine on other machines / OS versions). It happens only during the system startup (this is a Windows Service) and only for the first call of the CoCreateInstance.
The second call always succeeds.
The problem does not occurr when starting the service manually from Services.
I did some investigation using Process Monitor and found that the HKCR\CLSID\[CLSID of MyClass]\LocalServer32!LocalServer32 registry value is accessed before the failure. The registry value exists - it is added by the Windows Installer during
installation.
If I remove the registry value then the CoCreateInstance always succeeds.
I've been trying to lookup for some documentation on HKCR\CLSID\...\LocalServer32!LocalServer32 but haven't found anything useful other than it's a "Windows Installer Entrypoint". I assume that the Windows Installer does some integrity checks when
calling CoCreateInstance for such class and this fails for some reason but currently I fail to find the reason.
Can anyone help finding out what's the root cause of the 0x8007007e error here, please? Any help or tip is much appreciated.
Many thanks!
Marcin.Hi Marcin,
This forum is mainly for talk about the product use related issue and not the best place to talk about the develop issue, for the develop issue we can post in MSDN forum for
the further help and your issue may need capture a dump then for the further analysis it is not an efficient way to work in this community since we may need more resources which is not appropriate to handle in the community. I‘d like to suggest that you submit
a service request to MS Professional tech support service so that a dedicated Support Professional can further assist with this request.
MSDN forum
https://social.msdn.microsoft.com/Forums/en-US/home
Please visit the below link to see the various paid support options that are available to better meet your needs.
http://support.microsoft.com/default.aspx?id=fh;en-us;offerprophone
Thanks for your understanding and support.
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected] -
Install and uninstall of Oracle 11g R2 on Windows 2008 Server
Hi,
I installed Oracle 11g R2 and set up a database on Windows 2008 Server following the steps in the Installation Guide and it was successful. After uninstalling the product and doing a re-install, the step to configure the Net Configuration Assistant fails with the following msg.
Failed to allocate port(s) in the specified range(s) for the following process(es): JMS
[5540-5559], RMI [5520-5539], Database Control [5500-5519], EM Agent [3938] | [1830-1849]
Also, when I ran "netca.bat" and tried to reconfigure the Listener, it indicated the default port 1521 is being used. I ran "netstat -an" and do not see the port listed.
Questions:
What is the best way to check if something was leftover from my previous install of Oracle that is using the default ports?
What do I need to do to ensure a re-install is successful?
Uninstalling Oracle -
1. Log in as the Administrator.
2. Stop all Oracle Services.
3. From a cmd window, run C:\app\oracle\product\11.2.0\dbhome_1\deinstall\deinstall.bat.
4. Delete the C:\app\oracle directory.
5. Remove the following registry entries as per http://download.oracle.com/docs/cd/E11882_01/relnotes.112/e16777/toc.htm:
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle Services for MTS
HKLM\System\CurrentControlSet\Services\EventLog\Application\OracleDBConsole<SID>
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle.<SID>
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle.VSSWriter.<SID>
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Oracle11Johan, after I uninstalled Oracle, I checked to ensure there were no remaining Oracle services remaining.
Srini, below are the steps I followed to uninstall Oracle. In step 3, I just ran deinstall.bat without any parameters and provided required information as prompted. Note, I uninstalled using the Administrator user and not the "oracle" account that I used to install Oracle.
Uninstalling Oracle -
1. Log in as the Administrator.
2. Stop all Oracle Services.
3. From a cmd window, run C:\app\oracle\product\11.2.0\dbhome_1\deinstall\deinstall.bat.
4. Delete the C:\app\oracle directory.
5. Remove the following registry entries as per http://download.oracle.com/docs/cd/E11882_01/relnotes.112/e16777/toc.htm:
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle Services for MTS
HKLM\System\CurrentControlSet\Services\EventLog\Application\OracleDBConsole<SID>
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle.<SID>
HKLM\System\CurrentControlSet\Services\EventLog\Application\Oracle.VSSWriter.<SID>
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Oracle11
Maybe you are looking for
-
Foreign Exchange on Report Painter Report
I've been asked to create a Balance Sheet and P&L that have the G/L Accounts down the right hand side while across the top each column is a new company code. I am working on building this report in Report Painter. In each column I have no problem
-
I am running mac osx 10.7.2 on a macbook pro. I'm trying to export a pdf file with a password in preview v5.5.1. However, when I click on the check box next to the "encrypt" option, it just changed the grey color to a deeper grey and didn't ask me
-
A region with different language
I want to use a region Dominican republic with different language not in spanish. but in english??? how do i put it back
-
How can I define this FormBean in struts?
I'm a new struts learner. I want to display a shopping cart to user, but the product items is dynamicly generated. Is it needed to define a formBean? If I use struts tags,......some ideas please. Thanks
-
How to have horizotal and vertical scrollbar similtaneously in form
Hi, I my prj I have a main normal content canvas and in top of content canvas there is stacked canvas which fetches the data from datablock.By seting the scrollbar properly in datablock its possible to set horizontal or vertical scrollbar.However I n