Windows Firewall Service Crashes on Windows Server 2012

Hello Team,
I am facing issues with Windows Firewall Service in new Windows 2012 R2 deployments. when i try to start the Firewall service it wont start and it throws an error message to check the system event logs for information
The Windows Firewall service terminated with the following service-specific error: 
The data is invalid.
I deployed this OS on a VM running with latest VM tools and HW version which is running on ESXi 5.1 U1
2 GB RAM, 1 vCPU
OS deployed through ISO downloaded from MS portal and License activated through KMS system, performed a couple of reboots as well.
any advise on this issue? i am sure some of you might have also faced the same issue

1. VMware support forum and knowledge base may give you more specific advice.
2. Windows services may be dependent on another service(s). Analyze these dependences. Do it after you understand implications of VMware firewall function.
3. More detailed info from Event log is needed for analysis (Event ID, etc)
4. Hope you have connectivity configured correctly.
5. For firewall in VMware read the following article(s):
http://pubs.vmware.com/vsphere-51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-52188148-C579-4F6A-8335-CFBCE0DD2167.html&__utma=207178772.2027713003.1393320147.1393320147.1393320147.1&__utmb=207178772.0.10.1393320147&__utmc=207178772&__utmx=-&__utmz=207178772.1393320147.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=(not%20provided)&__utmv=-&__utmk=174193441
Regards
Milos

Similar Messages

  • Windows Search Service Crashes on Windows Server 2012 R2

    Hi, 
    I'm running Windows Search service on a Windows Server 2012 R2 (24GB RAM, 8-core proc). The index catalog has a little over 2 million items (files and folders indexed). 
    Every once in a while this service crashes, and either remains in limbo or automatically recovers and restarts the index from zero. I'm trying to find out information about what may be causing the crashes and about how to prevent them. Unfortunately, I don't
    seem to be able to find much about the Windows Search service on Windows Server 2012 R2. So anyone who may have input on this, please chip in.
    Additional info:
    - As mentioned above, the server OS is Windows Server 2012 R2. This is a physical server with 24GB RAM, 8-core proc and over 2TB of storage. 
    - This server acts as a DC and as a File Server. In addition to this and Windows Search service, there are no other major services running here
    - Symantec Endpoing protection is installed and running on this server, but I've made sure to exclude the Window Search database from SEP
    Here are some of the errors that are generated when the issue happens:
    The error below may show up in the event logs. If it shows up more than once, the indexing service has likely crashed and won't recover. 
    Log Name: System 
    Source: Service Control Manager 
    Date: 1/23/2015 3:32:15 PM 
    Event ID: 7011 
    Task Category: None 
    Level: Error 
    Keywords: Classic 
    User: N/A 
    Computer: myserver.mydomain.local 
    Description: 
    A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service. 
    I attempted to stop the indexing service, but it didn't stop. I noticed though that the indexing GUI started responding as soon as the
    the service stop command failed. The indexing service seems to have picked up where it was (~300K items) and continued indexing. 
    Logs sequence: 
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:01 PM 
    Event ID: 102 
    Task Category: General 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local 
    Description: 
    SearchIndexer (18232) Windows: The database engine (6.03.9600.0000) is starting a new instance (0).
    ====
     Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:01 PM 
    Event ID: 300 
    Task Category: Logging/Recovery 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local  
    Description: 
    SearchIndexer (18232) Windows: The database engine is initiating recovery steps. 
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:01 PM 
    Event ID: 301 
    Task Category: Logging/Recovery 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local 
    Description: 
    SearchIndexer (18232) Windows: The database engine has begun replaying logfile X:\IndexingService\Search\Data\Applications\Windows\edb0053D.log. 
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:01 PM 
    Event ID: 301 
    Task Category: Logging/Recovery 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local 
    Description: 
    SearchIndexer (18232) Windows: The database engine has begun replaying logfile X:\IndexingService\Search\Data\Applications\Windows\edb0053E.log. 
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:02 PM 
    Event ID: 301 
    Task Category: Logging/Recovery 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local
    Description: 
    SearchIndexer (18232) Windows: The database engine has begun replaying logfile X:\IndexingService\Search\Data\Applications\Windows\edb.log. 
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:02 PM 
    Event ID: 302 
    Task Category: Logging/Recovery 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local
    Description: 
    SearchIndexer (18232) Windows: The database engine has successfully completed recovery steps. 
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:02 PM 
    Event ID: 105 
    Task Category: General 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local 
    Description: 
    SearchIndexer (18232) Windows: The database engine started a new instance (0). (Time=1 seconds) 
    Internal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.032, [5] 1.046, [6] 0.094, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.
    ====
    Log Name: Application 
    Source: ESENT 
    Date: 1/23/2015 3:57:02 PM 
    Event ID: 326 
    Task Category: General 
    Level: Information 
    Keywords: Classic 
    User: N/A 
    Computer:
    myserver.mydomain.local 
    Description: 
    SearchIndexer (18232) Windows: The database engine attached a database (1, X:\IndexingService\Search\Data\Applications\Windows\Windows.edb).
    (Time=0 seconds) 
    Internal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11]
    0.000, [12] 0.000. 
    Saved Cache: 1 0 

    Hi,
    Thanks for your post.
    To resolve this problem, use the Registry Editor to change the default timeout value for all services.
    http://social.technet.microsoft.com/wiki/contents/articles/13765.event-id-7011-service-timeout.aspx
    Please note before making changes to the registry, you should back up any valued data.
    Regards.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • [Solved] Windows Firewall rule that allows Windows Update

    Can anyone kindly give me a Windows Firewall rule that allows Windows Update? Assume I'm running MMC's "Windows Firewall with Advanced Security" snap-in as Administrator. Note that a "solution" that takes down the outbound firewall is
    not acceptable.
    Thank You.
    ===== Solution =====
    Suppose that, as the default, you've set the outbound firewall to block (see
    To close the outbound firewall, below). In order for Windows Update to check whether an update is available and then to download the update files, you first need an outbound firewall
    allow-rule that allows the Windows Update service to pass through the outbound firewall.
    Prerequisite: Knowledge of the Microsoft Management Console (MMC) and its "Windows Firewall with Advanced Security" plug-in.
    What you will do: You will use the "Windows Firewall with Advanced Security" MMC plug-in to create an outbound firewall rule that
    allows '%SystemRoot%\System32\svchost.exe' (the generic service driver) to pass through the outbound firewall on behalf of 'wuauserv' (the name of the specific service that performs the update).
    Warning: If you don't know what I'm writing about, get help.
    Name: Allow Windows Update (...or any name you prefer - it doesn't matter)
    Group:
    Profile: Public
    Enabled: Yes
    Action: Allow
    Program: %SystemRoot%\System32\svchost.exe
    Local Address: Any
    Remote Address: Any
    Protocol: Any
    Local Port: Any
    Remote Port: Any
    Allowed Computers: Any
    Status: OK
    Service: wuauserv
    Rule Source: Local Setting
    Interface Type: All interface types
    Excepted Computers: None
    Description:
    To open the outbound firewall:
    More accurate wording would be
    Outbound connections are allowed unless explicitly blocked by a rule.
    If you look at the standard rules you will find no block-rules. That means that nothing is blocked, everything is allowed, and the outbound firewall is wide open.
    To close the outbound firewall:
    More accurate wording would be
    Outbound connections are blocked unless explicitly allowed by a rule.
    If you look at the standard rules you will find only allow-rules that have been crafted to allow the vital Windows connections to pass through the outbound firewall. To an informed observer it's obvious that the firewall engineers crafted these
    allow-rules so that users who closed the outbound firewall wouldn't have to write them. But the firewall engineers left out Windows Update.

    Hi mark,
    Thanks for sharing, it will help other users who have similar issue.
    Regards

  • Why will a stand alone executalbe with an installer work on windows 2000 and crashes on windows xp professional?

    When I run the setup.exe file on a Windows 2000 system it installs properly, but the same file run on a XP Professional system I get an error stating Fatal Error: Installation ended prematurely because of an error.
    See here for more information on the specific installer I'm trying to use.
    In fact I get this error for any stand alone executable I try to install on any XP machines. I am using LV 7.1. Is there a way to manually install eve
    rything?
    Thanks

    Sure you can Install a lv application manually. just copy the exe-file,
    support files in a folder. For the runtimeengine just copy the file
    lvrte.dll in the folder of your application or in the windows system folder.
    Hope that helps, Niko
    BB Herman wrote:
    > Why will a stand alone executalbe with an installer work on windows
    > 2000 and crashes on windows xp professional?
    >
    > When I run the setup.exe file on a Windows 2000 system it installs
    > properly, but the same file run on a XP Professional system I get an
    > error stating Fatal Error: Installation ended prematurely because of
    > an error.
    >
    > See
    > HREF="http://exchange.ni.com/servlet/ProcessRequest?RHIVEID=101&RPAGEID=135&HOID=50650000000800000...
    for more information on the specific installer I'm trying to
    > use.
    >
    > In fact I get this error for any stand alone executable I try to
    > install on any XP machines. I am using LV 7.1. Is there a way to
    > manually install everything?
    >
    > Thanks

  • Windows Update stuck on downloading on Server 2012

    Hi,
    Using VMWare Workstation 9, I created new virtual machine where I installed Windows Server 2012 Standard edition from MDSN disk en_windows_server_2012_x64_dvd_915478.iso  In the Server 2012 virtual machine, when I go to check for updates it says
    there are important updates available so I click on Install Updates.  It then just gets stuck on downloading updates for hours and nothing ever happens.  Stuck at 0 KB total, 0% complete.  I am able to access web pages using Internet Explorer
    with no problem so the machine does appear to have connectivity to the Internet.  If I go to help, click on "What can I do if I'm having problems installing updates?" and click on "Tab or click to open the Windows Update troubleshooter"
    it says "Windows Online Troubleshooting Service is not enabled for this version of Windows."  Any suggestions or ideas?
    Thanks,
    Greg

    I had a similar problem with a guest Windows 2012 R2 running on a Hyper-V host. I went to the network adapter in device manager in the guest and I disabled the "Large Send Offload Version 2 (IPv4)" option. Why? Well, this was also an issue previously when
    guesting Windows 2008 where the symptom was an error 80072ee2 when retrieving updates. See this post
    http://blog.ronnypot.nl/?p=310 for details. Anyway, I tried this and it worked for me. Hung before the change, worked after.

  • Cannot revert to Windows 8 after installing Hyper-V Server 2012 R2

    I own a laptop with a pre-installed Windows 8. I've installed Hyper-V Server 2012 R2 on top of it by mistake, and now I would like to get rid of it and revert it back to Windows 8. I've tried doing so by a backup USB, though it doesn't seem to work. Is there
    anyway to do this without having to use a disc? I haven't received one when I bought it.
    Thanks for any help in advance.

    Found something for specific computer. Find similat info for your computer:
    Acer Recovery Instructions:
    1) Power on the machine
    2) At the ACER BIOS screen, press and hold the 'Alt' key and the 'F10' key simultaneously to start Acer eRecovery.
    3) Once eRecovery utility is displayed, click 'Restore to Factory Default Settings'.
    4) Click 'OK' to continue
    5) The recovery process restore a fully functional factory image of Windows.
    6) After eRecovery has completed, press 'OK' to reboot the computer.
    Acer Recovery Media Purchase Program:
    https://secure.tx.acer.com/RCDB/Main.aspx?brand=acer
    This site is used for purchasing recovery media for your Acer product. 
    To get started, please enter the serial number or SNID located on your Acer product and click "Next"
    System Information
    Get your system information:
    http://secure3.tx.acer.com/FindSystem/FindSystem.aspx?title=Information%20About%20Your%20System
    Acer Main Support page:
    http://www.acersupport.com/
    Regards
    Milos

  • Can't Windows 7 access an RD on Server 2012 that uses SHA512/2048-bit certificates

    I have a Server 2012 R2 Remote Desktop that works fine if configured with the self-signed certs (SHA1/2048-bit), but not with certs from our internal CA.
    With the self-signed certs, our remote clients can connect but of course get security warnings due to the untrusted certificates.  The clients do trust our root CA, so we should be able to eliminate those by using certs from our internal CA instead.
    However, when I do configure the Server 2012 R2 RD to use certs generated on our internal CA (SHA512/2048-bit) clients (Windows 7) cannot open RDP sessions.  They get errors and on server event log contain:
    (Source: Schannel; Event ID: 36874)  [sic] An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    (Source: Schannel; Event ID: 36888)  A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205.
    The strange thing is that if I connect from client on Server 2008 R2, it can open RDP session!!!
    Thanks.

    Hi,
    Indicates by the event, it seems that the Cipher Suites use by the client are disabled on the server.
    Please check if any Cipher Suites of TLS 1.2 are disabled on the server.
    Cipher Suites in Schannel
    http://msdn.microsoft.com/en-us/library/windows/desktop/aa374757(v=vs.85).aspx
    How to restrict the use of certain cryptographic algorithms and protocols in Schannel.dll
    http://support.microsoft.com/kb/245030
    Hope this helps.
    Jeremy Wu
    TechNet Community Support

  • Not able to start the service 'Windows SharePoint Services Adminisration' in the server hosting SharePoint 2007 farm

    While upgrading my SharePoint 2007 farm to June 2013 CU , I saw the service ‘Windows SharePoint Services Adminisration’ was not starting. This is throwing error on every attempt of service start.

    While further investigation with Microsoft, the below approach was suggested :
    Back up the registry before you modify it. Then, you can restore the registry if a problem occurs.
     Click Start, click Run, type regedit in the Open box, and then click OK.
    Locate and then select the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
    Right-click Control, point to New, and then click DWORD Value.
    In the New Value box, type ServicesPipeTimeout, and then press Enter.
    Right-click ServicesPipeTimeout, and then click Modify.
    Click Decimal, type the number of milliseconds that you want to wait until the service times out, and then click OK.  In my case put it as 60000
    (60 secs)
    Exit Registry Editor and then restart the computer.
    The above steps resolved my issue and the service was successfully started.

  • Question : Service Accounts for SQL Server 2012

    Hello,
    I am planning to create AD accounts for SQL Server 2012 services that will be installed on Windows 2012 server.
    I was reading the following
    Configure Windows Service Accounts and Permissions
    and
    Windows Privileges and Rights
    Is there a recommendation / document that would list that assocation of SQL Server Services with Actvie Directory service accounts / privileges required for installation and starting the services.
    Isn't it recommended to create separate account for every service and they should not be local accounts ?
    Hope to hear soon as to what industry standards are being followed for production systems ?
    Thank you very much in advance.
    Regards
    Nikunj

    From MSDN:
    Each service in SQL Server represents a process or a set of processes to manage authentication of SQL Server operations with Windows. Each service can be configured to use its own service account. This facility is exposed
    at installation. SQL Server provides a special tool, SQL Server Configuration Manager, to manage the services configuration.
    When choosing service accounts, consider the principle of least privilege. The service account should have exactly the privileges that it needs to do its job and no more privileges. You also need to consider account isolation; the service accounts should
    not only be different from one another, they should not be used by any other service on the same server. Do not grant additional permissions to the SQL Server service account or the service groups.
    From Glen Berry's Blog:
    You should request that a dedicated domain user account be created for use by the SQL Server service. This should just be a regular, domain account with no special rights on the domain. You do not need or want this account to be a local admin on the machine
    where SQL Server will be installed. The SQL Server setup program will grant the necessary rights on the machine to that account during installation.
    You will also want a separate, dedicated domain user account for the SQL Server Agent service. If you are going to be installing and using other SQL Server related services such as SQL Server Integration Services (SSIS), SQL Server Reporting Services (SSRS),
    or SQL Server Analysis Services (SSAS), you will want dedicated domain accounts for each service. The reason you want separate accounts for each service is because they require different rights on the local machine, and having separate accounts is both more
    secure and more resilient, since a problem with one account won’t affect all of the SQL Server Services.
    Depending on your organization, getting these domain accounts created could take anywhere from minutes to weeks to complete, so make sure to allow time for this. For each one of these accounts, you will need their logon credentials for the SQL Server setup
    program. You are going to want to make sure that the accounts don’t have a temporary password that must be changed during the next login. If they are set up that way, make sure to change them to use a strong password, and record this information in a secure
    location.
    Please Mark This As Answer if it solved your issue
    Please Mark This As Helpful if it helps to solve your issue
    Thanks,
    Shashikant

  • Install Virtual Guest Services option not updating Server 2012 Guests

    Hi,
    I'm using VMM 2012 SP1 Update Rollup 3 and Hyper-V 2012.
    I have installed KB2908415 hotfix onto our Hyper-V clusters to resolve stability issues with CSVs.  Installing this hotfix causes an update in Integration Tools to version 6.2.9200.20873.
    If I shut down my virtual machine and use the manual option of "Install Virtual Guest Services" it completes successfully but the Integration Tools aren't upgraded on the virtual machine.  This only happens with Server 2012 guest machines
    (Windows 7 and Server 2008 R2 guest machines are updated successfully.  I have tried refreshing the virtual machine in VMM so the Integration Tools version is displayed.
    VMM mounts the iso from c:\windows\system32 onto the virtual machine but the install doesn't seem to start.
    Has anyone managed to get this working?
    Thanks,
    Emma

    I attempted to create a new VM and was met with the same error but I'm able to create a VM using Hyper-V manager.

  • Itunes will not install..windows INSTALLER service not available.windows 7

    I am trying to find a fix for this...just bought a new computer with windows 7, all updates have been performed. Itunes will not install...it just stops and says "windows installer service not available" Can't find a stand alone downloadable version of installer 5.0 which is what comes with 7 from the research I have done. I have the newest version of itunes saved on desktop, tried running it from desktop, tried running as admin, tried several other ideas that I found on here and Microsoft..but nothing is working. Any advice?
    Message was edited by: ehindahl

    Same error message "This version is for a 32 bit computer, yours is a 64 bit!"
    Doublechecking ... by any chance did you migrate a 32-bit version of the iTunes, Apple Mobile Device Support and Bonjour programs to the 64-bit machine from a 32-bit machine using the PC Mover utility?
    (Your symptoms are consistent with that ... the installer service throws the message when trying to uninstall the 32-bit itunes and related 32-bit componentry prior to installing the new 64-bit versions.)

  • Strange errors regarding RPC and WMI after migrating Hyper-V from Windows Server 2008 R2 to Windows Server 2012 cluster...

    Hi all;
    Suppose I have created a two-node Hyper-V cluster with a fibre channel shared storage in Windows Server 2012. Everything work fine except some issues. One of the is that when I want to configure the cluster to add a VM as its cluster resource, the following
    error message appears:
    An error occurred while determining the state of this clustered role in the cluster. The remote procedure call failed with error 800706BE.
    Any ideas?
    Thanks
    Please VOTE as HELPFUL if the post helps you and remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

    Thanks for your reply…
    I have tested many possible solutions without any success. The actions that I have done so far are mentioned in the following and the results of them have been said, too.
    When I restart the servers, everything are good but after some times when I reopen Failover Cluster Manager on one of the servers, the snap-in related to my cluster name does not load. Please look at the following figure:
    And when I want to connect to my cluster name, the following error message appears:
    Note: The above problem appears randomly regarding to servers. In the other hand, after the restart, one of the servers acts as the above statement.
    The following error message is the result of the DTCPing utility:
    ++++++++++++hosts     
    ++++++++++++
    06-11, 10:02:15.346-->Error(0x424) at clutil.cpp @256
    06-11, 10:02:15.346-->-->OpenCluster
    06-11, 10:02:15.356-->-->1060(The specified service does not exist as an installed service.)
    ++++++++++++++++++++++++++++++++++++++++++++++
         DTCping 1.9 Report for ADMINISTRATOR1 
    ++++++++++++++++++++++++++++++++++++++++++++++
    RPC server is ready
    ++++++++++++Validating Remote Computer Name++++++++++++
    06-11, 10:02:20.428-->Start DTC connection test
    Name Resolution:
    SRV04-->172.16.140.11-->SRV04
    06-11, 10:02:32.448-->Start RPC test (ADMINISTRATOR1-->SRV04)
    Problem:fail to invoke remote RPC method
    Error(0x6D9) at dtcping.cpp @303
    -->RPC pinging exception
    -->1753(There are no more endpoints available from the endpoint mapper.)
    RPC test failed
    And
    06-11, 10:26:10.837-->Error(0x424) at clutil.cpp @256
    06-11, 10:26:10.837-->-->OpenCluster
    06-11, 10:26:10.837-->-->1060(The specified service does not exist as an installed service.)
    ++++++++++++++++++++++++++++++++++++++++++++++
         DTCping 1.9 Report for ADMINISTRATOR1 
    ++++++++++++++++++++++++++++++++++++++++++++++
    RPC server is ready
    ++++++++++++Validating Remote Computer Name++++++++++++
    06-11, 10:26:14.947-->Start DTC connection test
    Name Resolution:
    SRV04-->172.16.140.11-->SRV04
    06-11, 10:26:26.967-->Start RPC test (ADMINISTRATOR1-->SRV04)
    Problem:fail to invoke remote RPC method
    Error(0x6D9) at dtcping.cpp @303
    -->RPC pinging exception
    -->1753(There are no more endpoints available from the endpoint mapper.)
    RPC test failed
    And
    ++++++++++++hosts     
    ++++++++++++
    06-11, 10:47:51.510-->Error(0x424) at clutil.cpp @256
    06-11, 10:47:51.510-->-->OpenCluster
    06-11, 10:47:51.510-->-->1060(The specified service does not exist as an installed service.)
    ++++++++++++++++++++++++++++++++++++++++++++++
         DTCping 1.9 Report for ADMINISTRATOR1 
    ++++++++++++++++++++++++++++++++++++++++++++++
    RPC server is ready
    ++++++++++++Validating Remote Computer Name++++++++++++
    06-11, 10:47:55.020-->Start DTC connection test
    Name Resolution:
    SRV03-->172.16.140.10-->SRV03
    06-11, 10:48:06.830-->Start RPC test (ADMINISTRATOR1-->SRV03)
    Problem:fail to invoke remote RPC method
    Error(0x6D9) at dtcping.cpp @303
    -->RPC pinging exception
    -->1753(There are no more endpoints available from the endpoint mapper.)
    RPC test failed
    The following output is the result of running PortQuery on port 135 on both servers:
    =============================================
     Starting portqry.exe -n srv03 -e 135 -p TCP ...
    Querying target system called:
     srv03
    Attempting to resolve name to IP address...
    Name resolved to 172.16.140.10
    querying...
    TCP port 135 (epmap service): LISTENING
    Using ephemeral source port
    Querying Endpoint Mapper Database...
    Server's response:
    UUID: d95afe70-a6d5-4259-822e-2c84da1ddb0d
    ncacn_ip_tcp:srv03[49152]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv03[49285]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv03[49285]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv03[49285]
    UUID: 367abb81-9844-35f1-ad32-98f038001003
    ncacn_ip_tcp:srv03[49159]
    UUID: b97db8b2-4c63-11cf-bff6-08002be23f2f Microsoft Cluster Server API
    ncacn_ip_tcp:srv03[49156]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_np:srv03[\\pipe\\lsass]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_ip_tcp:srv03[49155]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_np:srv03[\\pipe\\lsass]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_ip_tcp:srv03[49155]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_np:srv03[\\pipe\\lsass]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_ip_tcp:srv03[49155]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_ip_tcp:srv03[49157]
    UUID: 7f1343fe-50a9-4927-a778-0c5859517bac DfsDs service
    ncacn_np:srv03[\\PIPE\\wkssvc]
    UUID: 3473dd4d-2e88-4006-9cba-22570909dd10 WinHttp Auto-Proxy Service
    ncacn_np:srv03[\\PIPE\\W32TIME_ALT]
    UUID: 1ff70682-0a51-30e8-076d-740be8cee98b
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 378e52b0-c0a9-11cf-822d-00aa0051e40f
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 86d35949-83c9-4044-b424-db363231fd0c
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 86d35949-83c9-4044-b424-db363231fd0c
    ncacn_ip_tcp:srv03[49154]
    UUID: 3a9ef155-691d-4449-8d05-09ad57031823
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 3a9ef155-691d-4449-8d05-09ad57031823
    ncacn_ip_tcp:srv03[49154]
    UUID: a398e520-d59a-4bdd-aa7a-3c1e0303a511 IKE/Authip API
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: a398e520-d59a-4bdd-aa7a-3c1e0303a511 IKE/Authip API
    ncacn_ip_tcp:srv03[49154]
    UUID: 552d076a-cb29-4e44-8b6a-d15e59e2c0af IP Transition Configuration endpoint
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 552d076a-cb29-4e44-8b6a-d15e59e2c0af IP Transition Configuration endpoint
    ncacn_ip_tcp:srv03[49154]
    UUID: 2e6035b2-e8f1-41a7-a044-656b439c4c34 Proxy Manager provider server endpoint
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 2e6035b2-e8f1-41a7-a044-656b439c4c34 Proxy Manager provider server endpoint
    ncacn_ip_tcp:srv03[49154]
    UUID: c36be077-e14b-4fe9-8abc-e856ef4f048b Proxy Manager client server endpoint
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: c36be077-e14b-4fe9-8abc-e856ef4f048b Proxy Manager client server endpoint
    ncacn_ip_tcp:srv03[49154]
    UUID: c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 Adh APIs
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 Adh APIs
    ncacn_ip_tcp:srv03[49154]
    UUID: 98716d03-89ac-44c7-bb8c-285824e51c4a XactSrv service
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 98716d03-89ac-44c7-bb8c-285824e51c4a XactSrv service
    ncacn_ip_tcp:srv03[49154]
    UUID: 1a0d010f-1c33-432c-b0f5-8cf4e8053099 IdSegSrv service
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 1a0d010f-1c33-432c-b0f5-8cf4e8053099 IdSegSrv service
    ncacn_ip_tcp:srv03[49154]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_ip_tcp:srv03[49154]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_np:srv03[\\PIPE\\srvsvc]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_np:srv03[\\PIPE\\atsvc]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_ip_tcp:srv03[49154]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_np:srv03[\\PIPE\\srvsvc]
    UUID: f6beaff7-1e19-4fbb-9f8f-b89e2018337c Event log TCPIP
    ncacn_np:srv03[\\pipe\\eventlog]
    UUID: f6beaff7-1e19-4fbb-9f8f-b89e2018337c Event log TCPIP
    ncacn_ip_tcp:srv03[49153]
    UUID: 30adc50c-5cbc-46ce-9a0e-91914789e23c NRP server endpoint
    ncacn_np:srv03[\\pipe\\eventlog]
    UUID: 30adc50c-5cbc-46ce-9a0e-91914789e23c NRP server endpoint
    ncacn_ip_tcp:srv03[49153]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 DHCP Client LRPC Endpoint
    ncacn_np:srv03[\\pipe\\eventlog]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 DHCP Client LRPC Endpoint
    ncacn_ip_tcp:srv03[49153]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 DHCPv6 Client LRPC Endpoint
    ncacn_np:srv03[\\pipe\\eventlog]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 DHCPv6 Client LRPC Endpoint
    ncacn_ip_tcp:srv03[49153]
    UUID: 76f226c3-ec14-4325-8a99-6a46348418af
    ncacn_np:srv03[\\PIPE\\InitShutdown]
    UUID: d95afe70-a6d5-4259-822e-2c84da1ddb0d
    ncacn_np:srv03[\\PIPE\\InitShutdown]
    Total endpoints found: 51
    ==== End of RPC Endpoint Mapper query response ====
    portqry.exe -n srv03 -e 135 -p TCP exits with return code 0x00000000.
    And
    =============================================
     Starting portqry.exe -n srv04 -e 135 -p TCP ...
    Querying target system called:
     srv04
    Attempting to resolve name to IP address...
    Name resolved to 172.16.140.11
    querying...
    TCP port 135 (epmap service): LISTENING
    Using ephemeral source port
    Querying Endpoint Mapper Database...
    Server's response:
    UUID: d95afe70-a6d5-4259-822e-2c84da1ddb0d
    ncacn_ip_tcp:srv04[1025]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv04[1143]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv04[1143]
    UUID: 906b0ce0-c70b-1067-b317-00dd010662da
    ncacn_ip_tcp:srv04[1143]
    UUID: 367abb81-9844-35f1-ad32-98f038001003
    ncacn_ip_tcp:srv04[1065]
    UUID: b97db8b2-4c63-11cf-bff6-08002be23f2f Microsoft Cluster Server API
    ncacn_ip_tcp:srv04[1057]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_np:srv04[\\pipe\\lsass]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_ip_tcp:srv04[1028]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_np:srv04[\\pipe\\lsass]
    UUID: 0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7 RemoteAccessCheck
    ncacn_ip_tcp:srv04[1028]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_np:srv04[\\pipe\\lsass]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_ip_tcp:srv04[1028]
    UUID: 12345778-1234-abcd-ef00-0123456789ac
    ncacn_ip_tcp:srv04[1084]
    UUID: 7f1343fe-50a9-4927-a778-0c5859517bac DfsDs service
    ncacn_np:srv04[\\PIPE\\wkssvc]
    UUID: 1ff70682-0a51-30e8-076d-740be8cee98b
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 378e52b0-c0a9-11cf-822d-00aa0051e40f
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 86d35949-83c9-4044-b424-db363231fd0c
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 86d35949-83c9-4044-b424-db363231fd0c
    ncacn_ip_tcp:srv04[1027]
    UUID: 3a9ef155-691d-4449-8d05-09ad57031823
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 3a9ef155-691d-4449-8d05-09ad57031823
    ncacn_ip_tcp:srv04[1027]
    UUID: a398e520-d59a-4bdd-aa7a-3c1e0303a511 IKE/Authip API
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: a398e520-d59a-4bdd-aa7a-3c1e0303a511 IKE/Authip API
    ncacn_ip_tcp:srv04[1027]
    UUID: 552d076a-cb29-4e44-8b6a-d15e59e2c0af IP Transition Configuration endpoint
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 552d076a-cb29-4e44-8b6a-d15e59e2c0af IP Transition Configuration endpoint
    ncacn_ip_tcp:srv04[1027]
    UUID: 2e6035b2-e8f1-41a7-a044-656b439c4c34 Proxy Manager provider server endpoint
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 2e6035b2-e8f1-41a7-a044-656b439c4c34 Proxy Manager provider server endpoint
    ncacn_ip_tcp:srv04[1027]
    UUID: c36be077-e14b-4fe9-8abc-e856ef4f048b Proxy Manager client server endpoint
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: c36be077-e14b-4fe9-8abc-e856ef4f048b Proxy Manager client server endpoint
    ncacn_ip_tcp:srv04[1027]
    UUID: c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 Adh APIs
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 Adh APIs
    ncacn_ip_tcp:srv04[1027]
    UUID: 98716d03-89ac-44c7-bb8c-285824e51c4a XactSrv service
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 98716d03-89ac-44c7-bb8c-285824e51c4a XactSrv service
    ncacn_ip_tcp:srv04[1027]
    UUID: 1a0d010f-1c33-432c-b0f5-8cf4e8053099 IdSegSrv service
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 1a0d010f-1c33-432c-b0f5-8cf4e8053099 IdSegSrv service
    ncacn_ip_tcp:srv04[1027]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_ip_tcp:srv04[1027]
    UUID: c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 Impl friendly name
    ncacn_np:srv04[\\PIPE\\srvsvc]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_np:srv04[\\PIPE\\atsvc]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_ip_tcp:srv04[1027]
    UUID: 30b044a5-a225-43f0-b3a4-e060df91f9c1
    ncacn_np:srv04[\\PIPE\\srvsvc]
    UUID: f6beaff7-1e19-4fbb-9f8f-b89e2018337c Event log TCPIP
    ncacn_np:srv04[\\pipe\\eventlog]
    UUID: f6beaff7-1e19-4fbb-9f8f-b89e2018337c Event log TCPIP
    ncacn_ip_tcp:srv04[1026]
    UUID: 30adc50c-5cbc-46ce-9a0e-91914789e23c NRP server endpoint
    ncacn_np:srv04[\\pipe\\eventlog]
    UUID: 30adc50c-5cbc-46ce-9a0e-91914789e23c NRP server endpoint
    ncacn_ip_tcp:srv04[1026]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 DHCP Client LRPC Endpoint
    ncacn_np:srv04[\\pipe\\eventlog]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 DHCP Client LRPC Endpoint
    ncacn_ip_tcp:srv04[1026]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 DHCPv6 Client LRPC Endpoint
    ncacn_np:srv04[\\pipe\\eventlog]
    UUID: 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 DHCPv6 Client LRPC Endpoint
    ncacn_ip_tcp:srv04[1026]
    UUID: 76f226c3-ec14-4325-8a99-6a46348418af
    ncacn_np:srv04[\\PIPE\\InitShutdown]
    UUID: d95afe70-a6d5-4259-822e-2c84da1ddb0d
    ncacn_np:srv04[\\PIPE\\InitShutdown]
    Total endpoints found: 50
    ==== End of RPC Endpoint Mapper query response ====
    portqry.exe -n srv04 -e 135 -p TCP exits with return code 0x00000000.
    I have read the KB197814 and did the steps in it, restarted both servers, but the problem did not resolved.
    I have check both servers for RPC Service status and in both servers it has started.
    The both servers are alive and can ping each other by their IP address and name.
    The firewall of both servers is off and I stopped the Windows Firewall service COMPLETELY.
    Any services and applications that are depending on RPC have problems. For example when I want o remotely manages the services on these servers by using Services.msc console, the following error message appears:
    Error 1726: The remote procedure call failed.
    Please VOTE as HELPFUL if the post helps you and remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

  • Windows Firewall damaged by 'Windows 7 antivirus 2012'

    I run Windows 7. I think 64bit, not sure.
    I have been getting hit with a lot of rogue antiviruses and up till now have been fighting them off, but last night I was hit by a new rendition of "Windows 7 Antivirus 2012".
    I got a window saying explorer.exe wanted to make changes to my computer, I would tell it no and each time it would return. In between the constantly returning window I managed to open the task manager, find the process, and end the process. I then found
    the file and destroyed it with killbox.
    Everything seems to be back in working order now, except for the firewall. Every page in the control panel for windows firewall gives me an Administrator button that says use reccomended settings', when I click it it says it can't do that and gives
    me error 0x800705b4, which I understand to be an authentication error.
    The last time I had this I tried to reset my firewall with an admistrator command prompt, it would tell me it could not load wshelper.dll, so I did some stuff I cannot remember to reset my winsock and was then able to reset my firewall and all was good again.
    This time when I go into command.com and type 'netsh advfirewall reset' instead of the DLL message, I get 'An error occoured while attempting to contact the  Windows Firewall service. Make sure the service is running and try your request again'.
    In my attempts to fix this myself I have been to the device manager. I had it 'show hidden devices' and located my Windows Firewall Authorization driver. I found it had been stopped, and so I started it again. It currently says it is started, but nothing
    has changed functionally.
    I have been into Services as an Administrator; Windows Firewall is not there. I was also told to look for Windows Event Controller and Base Filtering Engine and they are not there either.
    I have done an administrator command promtp with sfc /scannow and the first time it said it had made changes and the second time it said everythign was alright but nothing functionally has changed.
    I have been told to enter the following command prompts and gotten - the following results
    netsh advfirewall reset - error stated above
    net start mpsdrv - The requested service has already been started
    net start bfe - The service name is invalid
    net start mpssvc - the service name is invalid
    regsvr32 firewallapi.dll - Popup window stating DllRegisterServer in firewallapi.dll succeeded
    no functional change after that.
    I have also been told to try:
    sc config wuauserv start= auto - [SC] ChangeServiceConfig SUCCESS
    sc config bits start= auto - [SC] ChangeServiceConfig SUCCESS
    sc config DcomLaunch start= auto - Access is denied.
    net stop wuauserv - The Windows Update service was stopped successfully.
    net start wuauserv - The Windows Update service was started successfully.
    net stop bits - The Backround Intelligent Transfer Service was stopped successfully.
    net start bits - The Backround Intelligent Transfer Service was started successfully.
    net start dcomlaunch - The requested service has already been started.
    I have also tried a system restore, but whatever is screwing with my firewall is also screwing with that an it will not complete successfully.
    A Windows XP thread steered me toward a file called, I believe, netfw.inf in my windir folder, related to the firewall. This does not seem to be on my Windows 7 machine and I have been unable to find the Windows 7 equivalent.
    So, it appears my firewall is gone, or just pretending to be. I fixxed it last time by making some correction to my winsock but I cannot seem to find the process I used for that. Additionally, Microsoft Security Essentials has dissapeared from my system
    tray, though otherwise seems to be working fine.
    I am confident that this can be fixxed without a wipe and reinstall. Please help.

    Hi
    Make sure that PC is clean(free from zero access rootkit before trying this fixes)
    This firewall issue is commonly found on vista and windows 7 (64 BIT OS)
    It is recommended to contact malware removal forums to remove it first and try the fix
    Run the services repair tool by ESET
    http://kb.eset.com/library/ESET/KB%20Team%20Only/Malware/ServicesRepair.exe
    Restart the PC.Firewall and critical missing services should work.
    Manual Fix
    Download both the registry files
    Windows firewall - 
    Firewall
    Base filtering engine - 
    BFE
    Launch them,You should get a UAC prompt now
    Click YES  & Restart your PC
    Now,Press Windows+ R key and type
    regedit and click ok
    go to
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE
    Right click on it-permissions
    Click on ADD and type
    Everyone and click ok
    Now Click on Everyone
    Below you have permission for users
    Select full control and click ok
    Now,open RUN and type
    services.msc and click ok
    start base filtering engine service and then windows firewall service
    If you still have this error
    Windows could not start Windows Firewall on local Computer. See event log, if non-windows services contact vendor. Error code 5.
    Download and launch this key,click YES
    Shared access
    give full control permission to this key similar to previous one
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess
    Right click on it -permissions
    Click on Add and type
    Everyone and select Full control
    You should able to start firewall now
    You may also be missing security center windows defender ,BITS and windows update services
    Download
    Security center  -wscsvc
    Windows defender - windefend
    BITS    -  BITS
    Windows update  - 
    wuauserv
    Launch them and click YES when you get a UAC prompt
    Good luck

  • Windows 7 (Ent) Sp1 on server 2012 R2 HyperV, RFX USB redirection not working

    Hello, 
    I currently have  windows server 2012 R2 with HyperV installed. I have built two virtual machines. A windows 8.1 and Windows 7 sp1. Both are enterprise editions  
    For RemoteFX the hypervisor is using a Zotec GTX 760 GPU. It recognizes it and uses it to apply remoteFX adapter on my Windows 7 Sp1 VM. 
    As you are aware I do not need to use a GPU to enable RFX on my Windows 8.1 it can do this without the need of a GPU.    
    Using an RDP client( v8.1)  I can connect to my Windows 8.1 VM with a USB headset,memory Key or a printer and they all enumerate on the Virtual machine. The driver for each device installs 
    and I can use the device without any issues. 
    However this issue lies with the Windows 7 SP1 VM. I can connect to it via RDP( Same client)  but I cannot redirect any devices to it. I have installed the latest integration services available on the VM. I have ran all updates available.
    Because I have ran all updates the rdp version on the VM is running v8.1.
    Previous to installing the updates USBr still was not working
    I have enabled the following group polices under remote desktop services on the Windows 7 SP1 VM : 
    RDP 8.0 -- Enabled
    Configure RFX -- Enabled
    Is there a known issue with USB redirection not working on a Windows 7sp1 virtual machine hosted on server 2012 Hypervisor ??
    Many Thanks 
    Brian 

    Hi,
    According to the log above, I found that we run the script on both Server6 and Server7. Errors as below:
    Server6: Conversion is not supported in restricted language mode or a Data section.
    Server7: Couldn't figure out valid servers from the specified destination scope. Check your parameters and try again.
    Since we can only run the RollAlternateserviceAccountPassword.ps1 Script on CAS server, the script not works well if Server6 is MBX server.
    For Server7, based on the error message, it seems you still have no right to run the script/cmdlet.
    Please add your account to Organization Management Role group(ADUC->domain.com->Microsoft Exchange Security Groups) to test if possible.
    By the way, from Technet:
    You need to be assigned permissions before you can perform this procedure. To see what permissions you need, see the "Client Access Security" entry in the Client Access Permissions topic.
    Client Access Permissions
    http://technet.microsoft.com/en-us/library/dd638131.aspx
    Feel free to contact me if there is any problem.
    Thanks
    Mavis
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Mavis Huang
    TechNet Community Support

  • Will Disabling IPv6 harm a Windows 8 or Server 2012 R2?

    I have a script that was written for Windows 7 and server 2008. I would like to know if it was harm a Windows 8 or any build of Server 2012 box. If so, could you please list what it would harm.
    It was create to help with speed issues for an older network based program.
    Thanks in advance.
    netsh interface tcp set global autotuning=disabled
    ocsetup MSRDC-Infrastructure /uninstall
    @Echo off 
    @ECHO Windows Registry Editor Version 5.00 > %TEMP%\DisableIPv6.reg
    @ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters] >> %TEMP%\DisableIPv6.reg
    @ECHO "DisabledComponents"=dword:ffffffff >> %TEMP%\DisableIPv6.reg 
    @ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] >> %TEMP%\DisableIPv6.reg
    @ECHO "Smb2"=dword:00000000 >> %TEMP%\DisableIPv6.reg 
    REGEDIT /S %TEMP%\DisableIPv6.reg
    ipconfig /flushdns
    sc config CscService start= disabled
    sc config lanmanworkstation depend= bowser/mrxsmb10/nsi
    sc config mrxsmb20 start= disabled

    Hi:
    I don't think anyone can say for sure if it would cause any harm to any build of Windows 8 or Server 2012Rx.  No one would have tested disabling IPV6 on all the possible combinations.  The conventional wisdom is to NOT disable IPV6, but given special
    circumstances I suppose it might be done:
    http://blogs.technet.com/b/sbs/archive/2008/10/24/issues-after-disabling-ipv6-on-your-nic-on-sbs-2008.aspx
    While written for Server 2008 and SBS 2008, you might want to check the above link for ideas.  About half way down it discusses some considerations.
    Are you still running some older program that might benefit from this?  If so, have you actually tested it without disabling IPV6 on say one server and one station.  It would be easy enough to test then reverse the changes if there was no perceived
    benefit.
    Larry Struckmeyer[MVP] If your question is answered please mark the response as the answer so that others can benefit.

Maybe you are looking for