PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Noms de domaine > ms.public.winnt.domain > RPC service unavailiable
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
ms.public.winnt.domain Usnet Forum about Windows NT.

RPC service unavailiable

Réponse
 
LinkBack Outils de la discussion
Vieux 06/11/2007, 19h23   #1
The_Amply
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut RPC service unavailiable

Hi,
We have multiple issues with Windows NT4 servers ... since july we have
about 10-15 servers that stop working ... can't log on locally ,
application running on these servers are still responding (oracle, IIS ) ,
can't acces any share on the server, unable to shutdown properly ... when
connecting to a share you get the error unable to connect, RPC service is not
availiable ... we dont have any message in the event viewers (only when we
get the DR watson errors but not all the time)
We have still have about 100 Windows nt 4 server only those 10-15 have the
issues ... they are not the same subnet and they are located anywhere in
the country .. the server are running Norton Symentec v.10 and Mcafee Virus
Scan 5.2.0.0 .. they are updated correctly ...
Here is what we done for now :
Deactivate anti-virus software , (no change)
verify for any virus that attacks RPC service (found nothing)
Verify if there was attack on RPC port ( found nothing)
Un-install SMS agent (no change)
deactivated automatic inventory update ((no change)
verify the disk space (space is good on all servers)
verify the backups done on all these servers (found nothing)
All the server are old Compaq machines .. we discover that the Power
Management Software from compaq could cause these problems but in not install
on any server ...
All the servers have service pack 6 a installed .. and they all have the
same version of the rpcss.exe file v. 4.0.1381.7263
All servers got the latest and last patches done by microsoft for Windows
NT4 ...
I notice that some servers got DR watson .. here the detail of one of then
some of them .. they dont always coinside we the problem but i got this on
several of them see below ...

Any is very appreciated Thank you ...

Application exception occurred:
App: exe\lsass.dbg (pid=57)
When: 10/7/2007 @ 21:14:6.265
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: GBWEB01
User Name: <unknown user name>
Number of Processors: 1
Processor Type: x86 Family 6 Model 8 Stepping 3
Windows Version: 4.0
Current Build: 1381
Service Pack: 6
Current Type: Uniprocessor Free
Registered Organization: PMG
Registered Owner: GBWEB01
*----> Task List <----*
0 Idle.exe
2 System.exe
32 SMSS.exe
36 CSRSS.exe
42 WINLOGON.exe
52 SERVICES.exe
57 LSASS.exe
82 SPOOLSS.exe
95 rpcss.exe
102 msdtc.exe
122 Ntagent.exe
126 CPQRCMC.exe
132 DefWatch.exe
135 DkService.exe
139 Control.exe
141 DNTUS26.exe
145 em60.exe
150 LogWatNT.exe
154 NetIQccm.exe
176 TCSERVER.exe
185 PSTORES.exe
191 SRVANY.exe
195 SavRoam.exe
197 QAWS.exe
203 mstask.exe
215 SNMP.exe
223 Rtvscan.exe
228 SYSDOWN.exe
232 SRVANY.exe
236 WinMgmt.exe
246 inetinfo.exe
250 ASDSCSVC.exe
254 cpqnimgt.exe
187 LicCheck.exe
265 cqmgserv.exe
274 cqmgstor.exe
405 cqmghost.exe
443 cpqwmgmt.exe
308 mtx.exe
520 mtx.exe
446 mtx.exe
517 NetIQmc.exe
263 NQPERF~1.exe
320 GENEventLog.exe
454 DWRCS.exe
507 DRWTSN32.exe
0 _Total.exe
(018e0000 - 018e6000) exe\lsass.dbg
(77f60000 - 77fbf000) dll\ntdll.dbg
(77f00000 - 77f5e000) dll\kernel32.dbg
(76520000 - 76549000) dll\lsasrv.dbg
(78000000 - 78044000)
(77e10000 - 77e67000) dll\rpcrt4.dbg
(77dc0000 - 77dff000) dll\advapi32.dbg
(77e70000 - 77ec2000) dll\user32.dbg
(7c000000 - 7c035000) dll\gdi32.dbg
(74f50000 - 74f7e000) dll\samsrv.dbg
(75c20000 - 75c2c000) dll\msprivs.dbg
(73680000 - 736b2000) dll\netlogon.dbg
(4ca00000 - 4ca41000) dll\netapi32.dbg
(77840000 - 77849000) dll\NetRap.dbg
(777e0000 - 777ed000) dll\samlib.dbg
(776d0000 - 776d8000) dll\wsock32.dbg
(776b0000 - 776c4000) dll\ws2_32.dbg
(776a0000 - 776a7000) dll\ws2.dbg
(52100000 - 52128000) dll\wldap32.dbg
(75b80000 - 75b8f000) dll\msv1_0.dbg
(77e00000 - 77e06000) dll\rpclts1.dbg
(77bf0000 - 77bf7000) dll\rpcltc1.dbg
(76e70000 - 76e82000) dll\secur128.dbg
(71710000 - 71724000) dll\msapsspc.dbg
(779d0000 - 779d0000)
(780a0000 - 780b2000)
(77400000 - 7741e000) dll\sch128c.dbg
(5e380000 - 5e3a5000) dll\msoss.dbg
(5cf00000 - 5cf75000) dll\crypt32.dbg
(01620000 - 01630000) dll\msasn1.dbg
(716e0000 - 716ff000) dll\msnsspc.dbg
(01630000 - 01640000)
(77980000 - 779a4000) dll\dnsapi.dbg
(77660000 - 7766f000) dll\msafd.dbg
(77690000 - 77699000) dll\wshtcpip.dbg
(77be0000 - 77be5000) dll\secur32.dbg
(77720000 - 77731000) dll\mpr.dbg
(01bf0000 - 01bf7000) dll\iissuba.dbg
State Dump for Thread Id 0x3c
eax=00144e80 ebx=77e58000 ecx=00000000 edx=00000000 esi=009ef790 edi=00138dd0
eip=77f67b1b esp=009ef684 ebp=009ef6c4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: ZwFsControlFile
77f67b10 b83b000000 mov eax,0x3b
77f67b15 8d542404 lea edx,[esp+0x4]
ss:019ee08b=????????
77f67b19 cd2e int 2e
77f67b1b c22800 ret 0x28
77f67b1e 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
009ef6c4 77e20e1e 00138dd0 001af008 000003fc 009ef79c ntdll!ZwFsControlFile
009ef6ec 77e3080d 001af008 000003fc 009ef79c 009ef790
rpcrt4!I_RpcTransServerUnprotectThread
009ef7cc 77e1f92b 009efa48 00000000 00000000 009ef830
rpcrt4!I_RpcLaunchDatagramReceiveThread
009ef840 77e2058b 009efa48 00000000 009efb10 009ef994
rpcrt4!I_RpcTransServerNewConnection
009efb10 77dcab93 77dec248 77dec3fa 009efb2c 0198ca18
rpcrt4!I_RpcTransServerReallocBuffer
009efb9c 7652e466 0013f1e0 00000010 00000003 00000230
advapi32!ElfReportEventA
009efd80 7652e243 008e0000 0012fea4 009efeb8 00000000
lsasrv!LsarEnumerateTrustedDomains
009efd98 7652dd75 008e0000 00000000 7652b8df 009efdb8
lsasrv!LsarEnumerateTrustedDomains
009effb8 77f04ef0 00000000 0012fea4 0012fd68 00000000
lsasrv!LsarEnumerateTrustedDomains
009effec 00000000 7652b854 00000000 00000000 000000b0 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
*----> Raw Stack Dump <----*
009ef684 49 10 bf 77 24 01 00 00 - 00 00 00 00 00 00 00 00 I..w$...........
009ef694 00 00 00 00 bc f6 9e 00 - 17 c0 11 00 08 f0 1a 00 ................
009ef6a4 fc 03 00 00 10 70 14 00 - 00 04 00 00 00 00 00 00 .....p..........
009ef6b4 90 8c 13 00 00 80 e5 77 - 00 00 00 00 24 00 00 00 .......w....$...
009ef6c4 ec f6 9e 00 1e 0e e2 77 - d0 8d 13 00 08 f0 1a 00 .......w........
009ef6d4 fc 03 00 00 9c f7 9e 00 - 90 f7 9e 00 00 00 00 00 ................
009ef6e4 e4 03 00 00 08 f0 1a 00 - cc f7 9e 00 0d 08 e3 77 ...............w
009ef6f4 08 f0 1a 00 fc 03 00 00 - 9c f7 9e 00 90 f7 9e 00 ................
009ef704 20 f8 9e 00 74 fa 9e 00 - 90 8c 13 00 00 f6 53 76 ...t.........Sv
009ef714 3a c5 de 77 20 f0 1a 00 - 94 f9 9e 00 58 c5 de 77 :..w .......X..w
009ef724 58 f7 9e 00 79 37 e1 77 - 94 f9 9e 00 e0 f3 1a 00 X...y7.w........
009ef734 00 f6 53 76 54 c5 de 77 - e4 f3 1a 00 7c fd 9e 00 ..SvT..w....|...
009ef744 4c c5 de 77 3d 00 00 00 - 00 00 00 00 08 fd 9e 00 L..w=...........
009ef754 dc f3 1a 00 78 f7 9e 00 - c1 29 e1 77 94 f9 9e 00 ....x....).w....
009ef764 74 fd 9e 00 4c c5 de 77 - 74 fd 9e 00 cd f9 9e 00 t...L..wt.......
009ef774 00 c5 de 77 98 f7 9e 00 - c8 24 e1 77 94 f9 9e 00 ...w.....$.w....
009ef784 74 fd 9e 00 48 c5 de 77 - 01 00 00 00 00 04 00 00 t...H..w........
009ef794 00 00 00 00 b8 8d 13 00 - 10 70 14 00 94 f9 9e 00 .........p......
009ef7a4 04 8d 13 00 54 fa 9e 00 - 50 fa 9e 00 01 00 00 00 ....T...P.......
009ef7b4 30 16 00 00 d2 c5 de 77 - e4 03 00 00 18 00 00 00 0......w........
State Dump for Thread Id 0x3e
eax=00bffdac ebx=00000000 ecx=00000101 edx=00000000 esi=77f9e4c0 edi=00000000
eip=77f6839b esp=00bfff98 ebp=00bfffb8 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: NtWaitForSingleObject
77f68390 b8c5000000 mov eax,0xc5
77f68395 8d542404 lea edx,[esp+0x4]
ss:01bfe99f=????????
77f68399 cd2e int 2e
77f6839b c20c00 ret 0xc
77f6839e 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00bfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000
ntdll!NtWaitForSingleObject
00bfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x3f
eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014
edi=00cfff00eip=77f68067 esp=00cffee0 ebp=00cfffb8 iopl=0 nv up ei ng
nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:01cfe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00cfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000
ntdll!ZwReplyWaitReceivePort
00cfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x40
eax=00dff520 ebx=00000000 ecx=00153c30 edx=00000000 esi=00000014 edi=00dfff00
eip=77f68067 esp=00dffee0 ebp=00dfffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:01dfe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00dfffb8 77f04ef0 00000001 00000000 00000000 00000001
ntdll!ZwReplyWaitReceivePort
00dfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x41
eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00efff00
eip=77f68067 esp=00effee0 ebp=00efffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:01efe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00efffb8 77f04ef0 00000002 00000000 00000000 00000002
ntdll!ZwReplyWaitReceivePort
00efffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x42
eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00ffff00
eip=77f68067 esp=00fffee0 ebp=00ffffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:01ffe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00ffffb8 77f04ef0 00000003 00000000 00000000 00000003
ntdll!ZwReplyWaitReceivePort
00ffffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x43
eax=010ff63c ebx=00000000 ecx=010ff638 edx=00000000 esi=00000014 edi=010fff00
eip=77f68067 esp=010ffee0 ebp=010fffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:020fe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
010fffb8 77f04ef0 00000004 00000000 00000000 00000004
ntdll!ZwReplyWaitReceivePort
010fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x44
eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=011fff00
eip=77f68067 esp=011ffee0 ebp=011fffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:021fe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
011fffb8 77f04ef0 00000005 00000000 00000000 00000005
ntdll!ZwReplyWaitReceivePort
011fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x45
eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=012fff00
eip=77f68067 esp=012ffee0 ebp=012fffb8 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: ZwReplyWaitReceivePort
77f6805c b890000000 mov eax,0x90
77f68061 8d542404 lea edx,[esp+0x4]
ss:022fe8e7=????????
77f68065 cd2e int 2e
77f68067 c21000 ret 0x10
77f6806a 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
012fffb8 77f04ef0 00000006 00000000 00000000 00000006
ntdll!ZwReplyWaitReceivePort
012fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x46
eax=0013b601 ebx=013fff64 ecx=00000000 edx=00000000 esi=000000dc edi=00000000
eip=77f67fc7 esp=013ffe84 ebp=013ffeec iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: ZwReadFile
77f67fbc b886000000 mov eax,0x86
77f67fc1 8d542404 lea edx,[esp+0x4]
ss:023fe88b=????????
77f67fc5 cd2e int 2e
77f67fc7 c22400 ret 0x24
77f67fca 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
013ffeec 77dd8a35 000000dc 001384b8 0000021a 013fff1c ntdll!ZwReadFile
013fff20 77dd8481 000000dc 001384b8 0000021a 013fff64
advapi32!RegisterServiceCtrlHandlerA
013fff84 77dd829e 000000dc 001384b8 0000021a 0012ffb0
advapi32!StartServiceCtrlDispatcherW
013fffa8 76528f3e 76544268 77f3b968 00000000 77f04ef0
advapi32!StartServiceCtrlDispatcherA
013fffec 00000000 00000000 00000000 00000000 00000000 lsasrv!LsapInitLsa
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x4c
eax=0000afc8 ebx=015ffc94 ecx=0000000d edx=00000000 esi=7ffdf000 edi=00000001
eip=77f6838b esp=015ffc70 ebp=015ffcc4 iopl=0 nv up ei pl nz ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000213
function: NtWaitForMultipleObjects
77f68380 b8c4000000 mov eax,0xc4
77f68385 8d542404 lea edx,[esp+0x4]
ss:025fe677=????????
77f68389 cd2e int 2e
77f6838b c21400 ret 0x14
77f6838e 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
015ffcc4 77f1cf3e 00000002 015ffec8 00000000 0000afc8
ntdll!NtWaitForMultipleObjects
015ffce0 7368957b 00000002 015ffec8 00000000 0000afc8
kernel32!WaitForMultipleObjects
015fff58 73689fb1 001384b8 73680000 00144d58 76541830
netlogon!I_NetNotifyRole
015fff74 7652cb77 00000001 00144d60 001384b8 00144d58 netlogon!NlNetlogonMain
015fffa8 77dd8c15 00000001 00144d60 001383d0 77f04ef0
lsasrv!LsaIOpenPolicyTrusted
015fffec 00000000 00000000 00000000 00000000 00000000
advapi32!RegisterServiceCtrlHandlerA
00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
State Dump for Thread Id 0x22a
eax=00000000 ebx=00137b48 ecx=00000501 edx=00000000 esi=00137b38 edi=00000006
eip=77f6838b esp=2740feec ebp=2740ff2c iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206
function: NtWaitForMultipleObjects
77f68380 b8c4000000 mov eax,0xc4
77f68385 8d542404 lea edx,[esp+0x4]
ss:2840e8f3=????????
77f68389 cd2e int 2e
77f6838b c21400 ret 0x14
77f6838e 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
2740ff2c 77e20fb4 00137b38 2740ff58 2740ff88 2740ff84
ntdll!NtWaitForMultipleObjects
2740ff60 77e1da4a 2740ff8c 2740ff88 2740ff84 0015c0b8
rpcrt4!I_RpcTransServerUnprotectThread
2740ff90 77e1f49b 77e17bd9 00137a58 2740ffec ffffffff rpcrt4!RpcTestCancel
00003a98 00000000 00000000 00000000 00000000 00000000
rpcrt4!I_RpcTransServerNewConnection
State Dump for Thread Id 0x246
eax=2750fcdc ebx=00191fd0 ecx=00000030 edx=00000000 esi=00000010 edi=00173924
eip=76534730 esp=2750fc48 ebp=2750fc8c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: LsarLookupNames
76534713 85c0 test eax,eax
76534715 7c30 jl LsarLookupNames+0x1795 (76534747)
76534717 8b45ec mov eax,[ebp-0x14]
ss:2850e692=????????
7653471a 8b4de0 mov ecx,[ebp-0x20]
ss:2850e692=????????
7653471d c1e104 shl ecx,0x4
76534720 8b54300c mov edx,[eax+esi+0xc]
ds:00ffea17=19638800
76534724 0355c8 add edx,[ebp-0x38]
ss:2850e692=????????
76534727 8b4518 mov eax,[ebp+0x18]
ss:2850e692=????????
7653472a 8b5804 mov ebx,[eax+0x4]
ds:2850e6e2=????????
7653472d 8b4524 mov eax,[ebp+0x24]
ss:2850e692=????????
FAULT ->76534730 89540b0c mov [ebx+ecx+0xc],edx
ds:00ffea37=19642800
76534734 ff08 dec dword ptr [eax]
ds:2750fcdc=00000003
76534736 83c704 add edi,0x4
76534739 83c610 add esi,0x10
7653473c 8b45d4 mov eax,[ebp-0x2c]
ss:2850e692=????????
7653473f ff45cc inc dword ptr [ebp-0x34]
ss:2850e692=????????
76534742 3945cc cmp [ebp-0x34],eax
ss:2850e692=????????
76534745 7287 jb LsarLookupNames+0x171c (765346ce)
76534747 33f6 xor esi,esi
76534749 3975f8 cmp [ebp-0x8],esi
ss:2850e692=????????
7653474c 0f8c7bfeffff jl LsarLookupNames+0x161b (765345cd)
76534752 3975d8 cmp [ebp-0x28],esi
ss:2850e692=????????
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
2750fc8c 76532a3a 00000003 001ba2e8 2750fcc8 001a1ff0 lsasrv!LsarLookupNames
2750fcfc 76539ea3 00164378 001ba2dc 2750fde4 001ba354 lsasrv!LsarLookupSids
2750fe20 77e11423 2750fef0 001380a8 2750fef0 00000000 lsasrv!<nosymbols>
2750fe5c 77e111dc 76539d84 2750fef0 2750ff34 00000000
rpcrt4!NdrClientInitializeNew
2750feb0 77e114f9 2750fef0 00000000 2750ff34 00176074 rpcrt4!I_RpcGetBuffer
2750fed0 77e1e035 2750fef0 00000000 2750ff34 00176074
rpcrt4!NdrClientInitializeNew
2750ff40 77e1ff21 001ba2b0 000000b4 2750ff90 00137a80 rpcrt4!RpcTestCancel
001ba2b0 00000010 000000b4 00000003 0000009c 000f0000
rpcrt4!I_RpcTransServerNewConnection
thank you for your ...
  Réponse avec citation
Vieux 29/01/2008, 23h41   #2
Patrick
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut RE: RPC service unavailiable

I am a rookie,so bear with me.Basically,the same problems,came up on my Net
Vista ,Windows 2000 same stepping stuff.My error report said error 1202,from
Microsoft.It was a security conflict from a clash between Norton,who I
thought I had taken everything off,and my ISP security system.Mine BSOD'd,2
months later.,for improper registration.Any ,will be appreciated.Thanks.
--
zadude


"The_Amply" wrote:

> Hi,
> We have multiple issues with Windows NT4 servers ... since july we have
> about 10-15 servers that stop working ... can't log on locally ,
> application running on these servers are still responding (oracle, IIS ) ,
> can't acces any share on the server, unable to shutdown properly ... when
> connecting to a share you get the error unable to connect, RPC service is not
> availiable ... we dont have any message in the event viewers (only when we
> get the DR watson errors but not all the time)
> We have still have about 100 Windows nt 4 server only those 10-15 have the
> issues ... they are not the same subnet and they are located anywhere in
> the country .. the server are running Norton Symentec v.10 and Mcafee Virus
> Scan 5.2.0.0 .. they are updated correctly ...
> Here is what we done for now :
> Deactivate anti-virus software , (no change)
> verify for any virus that attacks RPC service (found nothing)
> Verify if there was attack on RPC port ( found nothing)
> Un-install SMS agent (no change)
> deactivated automatic inventory update ((no change)
> verify the disk space (space is good on all servers)
> verify the backups done on all these servers (found nothing)
> All the server are old Compaq machines .. we discover that the Power
> Management Software from compaq could cause these problems but in not install
> on any server ...
> All the servers have service pack 6 a installed .. and they all have the
> same version of the rpcss.exe file v. 4.0.1381.7263
> All servers got the latest and last patches done by microsoft for Windows
> NT4 ...
> I notice that some servers got DR watson .. here the detail of one of then
> some of them .. they dont always coinside we the problem but i got this on
> several of them see below ...
>
> Any is very appreciated Thank you ...
>
> Application exception occurred:
> App: exe\lsass.dbg (pid=57)
> When: 10/7/2007 @ 21:14:6.265
> Exception number: c0000005 (access violation)
> *----> System Information <----*
> Computer Name: GBWEB01
> User Name: <unknown user name>
> Number of Processors: 1
> Processor Type: x86 Family 6 Model 8 Stepping 3
> Windows Version: 4.0
> Current Build: 1381
> Service Pack: 6
> Current Type: Uniprocessor Free
> Registered Organization: PMG
> Registered Owner: GBWEB01
> *----> Task List <----*
> 0 Idle.exe
> 2 System.exe
> 32 SMSS.exe
> 36 CSRSS.exe
> 42 WINLOGON.exe
> 52 SERVICES.exe
> 57 LSASS.exe
> 82 SPOOLSS.exe
> 95 rpcss.exe
> 102 msdtc.exe
> 122 Ntagent.exe
> 126 CPQRCMC.exe
> 132 DefWatch.exe
> 135 DkService.exe
> 139 Control.exe
> 141 DNTUS26.exe
> 145 em60.exe
> 150 LogWatNT.exe
> 154 NetIQccm.exe
> 176 TCSERVER.exe
> 185 PSTORES.exe
> 191 SRVANY.exe
> 195 SavRoam.exe
> 197 QAWS.exe
> 203 mstask.exe
> 215 SNMP.exe
> 223 Rtvscan.exe
> 228 SYSDOWN.exe
> 232 SRVANY.exe
> 236 WinMgmt.exe
> 246 inetinfo.exe
> 250 ASDSCSVC.exe
> 254 cpqnimgt.exe
> 187 LicCheck.exe
> 265 cqmgserv.exe
> 274 cqmgstor.exe
> 405 cqmghost.exe
> 443 cpqwmgmt.exe
> 308 mtx.exe
> 520 mtx.exe
> 446 mtx.exe
> 517 NetIQmc.exe
> 263 NQPERF~1.exe
> 320 GENEventLog.exe
> 454 DWRCS.exe
> 507 DRWTSN32.exe
> 0 _Total.exe
> (018e0000 - 018e6000) exe\lsass.dbg
> (77f60000 - 77fbf000) dll\ntdll.dbg
> (77f00000 - 77f5e000) dll\kernel32.dbg
> (76520000 - 76549000) dll\lsasrv.dbg
> (78000000 - 78044000)
> (77e10000 - 77e67000) dll\rpcrt4.dbg
> (77dc0000 - 77dff000) dll\advapi32.dbg
> (77e70000 - 77ec2000) dll\user32.dbg
> (7c000000 - 7c035000) dll\gdi32.dbg
> (74f50000 - 74f7e000) dll\samsrv.dbg
> (75c20000 - 75c2c000) dll\msprivs.dbg
> (73680000 - 736b2000) dll\netlogon.dbg
> (4ca00000 - 4ca41000) dll\netapi32.dbg
> (77840000 - 77849000) dll\NetRap.dbg
> (777e0000 - 777ed000) dll\samlib.dbg
> (776d0000 - 776d8000) dll\wsock32.dbg
> (776b0000 - 776c4000) dll\ws2_32.dbg
> (776a0000 - 776a7000) dll\ws2.dbg
> (52100000 - 52128000) dll\wldap32.dbg
> (75b80000 - 75b8f000) dll\msv1_0.dbg
> (77e00000 - 77e06000) dll\rpclts1.dbg
> (77bf0000 - 77bf7000) dll\rpcltc1.dbg
> (76e70000 - 76e82000) dll\secur128.dbg
> (71710000 - 71724000) dll\msapsspc.dbg
> (779d0000 - 779d0000)
> (780a0000 - 780b2000)
> (77400000 - 7741e000) dll\sch128c.dbg
> (5e380000 - 5e3a5000) dll\msoss.dbg
> (5cf00000 - 5cf75000) dll\crypt32.dbg
> (01620000 - 01630000) dll\msasn1.dbg
> (716e0000 - 716ff000) dll\msnsspc.dbg
> (01630000 - 01640000)
> (77980000 - 779a4000) dll\dnsapi.dbg
> (77660000 - 7766f000) dll\msafd.dbg
> (77690000 - 77699000) dll\wshtcpip.dbg
> (77be0000 - 77be5000) dll\secur32.dbg
> (77720000 - 77731000) dll\mpr.dbg
> (01bf0000 - 01bf7000) dll\iissuba.dbg
> State Dump for Thread Id 0x3c
> eax=00144e80 ebx=77e58000 ecx=00000000 edx=00000000 esi=009ef790 edi=00138dd0
> eip=77f67b1b esp=009ef684 ebp=009ef6c4 iopl=0 nv up ei pl zr na po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
> function: ZwFsControlFile
> 77f67b10 b83b000000 mov eax,0x3b
> 77f67b15 8d542404 lea edx,[esp+0x4]
> ss:019ee08b=????????
> 77f67b19 cd2e int 2e
> 77f67b1b c22800 ret 0x28
> 77f67b1e 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 009ef6c4 77e20e1e 00138dd0 001af008 000003fc 009ef79c ntdll!ZwFsControlFile
> 009ef6ec 77e3080d 001af008 000003fc 009ef79c 009ef790
> rpcrt4!I_RpcTransServerUnprotectThread
> 009ef7cc 77e1f92b 009efa48 00000000 00000000 009ef830
> rpcrt4!I_RpcLaunchDatagramReceiveThread
> 009ef840 77e2058b 009efa48 00000000 009efb10 009ef994
> rpcrt4!I_RpcTransServerNewConnection
> 009efb10 77dcab93 77dec248 77dec3fa 009efb2c 0198ca18
> rpcrt4!I_RpcTransServerReallocBuffer
> 009efb9c 7652e466 0013f1e0 00000010 00000003 00000230
> advapi32!ElfReportEventA
> 009efd80 7652e243 008e0000 0012fea4 009efeb8 00000000
> lsasrv!LsarEnumerateTrustedDomains
> 009efd98 7652dd75 008e0000 00000000 7652b8df 009efdb8
> lsasrv!LsarEnumerateTrustedDomains
> 009effb8 77f04ef0 00000000 0012fea4 0012fd68 00000000
> lsasrv!LsarEnumerateTrustedDomains
> 009effec 00000000 7652b854 00000000 00000000 000000b0 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> *----> Raw Stack Dump <----*
> 009ef684 49 10 bf 77 24 01 00 00 - 00 00 00 00 00 00 00 00 I..w$...........
> 009ef694 00 00 00 00 bc f6 9e 00 - 17 c0 11 00 08 f0 1a 00 ................
> 009ef6a4 fc 03 00 00 10 70 14 00 - 00 04 00 00 00 00 00 00 .....p..........
> 009ef6b4 90 8c 13 00 00 80 e5 77 - 00 00 00 00 24 00 00 00 .......w....$...
> 009ef6c4 ec f6 9e 00 1e 0e e2 77 - d0 8d 13 00 08 f0 1a 00 .......w........
> 009ef6d4 fc 03 00 00 9c f7 9e 00 - 90 f7 9e 00 00 00 00 00 ................
> 009ef6e4 e4 03 00 00 08 f0 1a 00 - cc f7 9e 00 0d 08 e3 77 ...............w
> 009ef6f4 08 f0 1a 00 fc 03 00 00 - 9c f7 9e 00 90 f7 9e 00 ................
> 009ef704 20 f8 9e 00 74 fa 9e 00 - 90 8c 13 00 00 f6 53 76 ...t.........Sv
> 009ef714 3a c5 de 77 20 f0 1a 00 - 94 f9 9e 00 58 c5 de 77 :..w .......X..w
> 009ef724 58 f7 9e 00 79 37 e1 77 - 94 f9 9e 00 e0 f3 1a 00 X...y7.w........
> 009ef734 00 f6 53 76 54 c5 de 77 - e4 f3 1a 00 7c fd 9e 00 ..SvT..w....|...
> 009ef744 4c c5 de 77 3d 00 00 00 - 00 00 00 00 08 fd 9e 00 L..w=...........
> 009ef754 dc f3 1a 00 78 f7 9e 00 - c1 29 e1 77 94 f9 9e 00 ....x....).w....
> 009ef764 74 fd 9e 00 4c c5 de 77 - 74 fd 9e 00 cd f9 9e 00 t...L..wt.......
> 009ef774 00 c5 de 77 98 f7 9e 00 - c8 24 e1 77 94 f9 9e 00 ...w.....$.w....
> 009ef784 74 fd 9e 00 48 c5 de 77 - 01 00 00 00 00 04 00 00 t...H..w........
> 009ef794 00 00 00 00 b8 8d 13 00 - 10 70 14 00 94 f9 9e 00 .........p......
> 009ef7a4 04 8d 13 00 54 fa 9e 00 - 50 fa 9e 00 01 00 00 00 ....T...P.......
> 009ef7b4 30 16 00 00 d2 c5 de 77 - e4 03 00 00 18 00 00 00 0......w........
> State Dump for Thread Id 0x3e
> eax=00bffdac ebx=00000000 ecx=00000101 edx=00000000 esi=77f9e4c0 edi=00000000
> eip=77f6839b esp=00bfff98 ebp=00bfffb8 iopl=0 nv up ei pl zr na po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
> function: NtWaitForSingleObject
> 77f68390 b8c5000000 mov eax,0xc5
> 77f68395 8d542404 lea edx,[esp+0x4]
> ss:01bfe99f=????????
> 77f68399 cd2e int 2e
> 77f6839b c20c00 ret 0xc
> 77f6839e 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 00bfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000
> ntdll!NtWaitForSingleObject
> 00bfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x3f
> eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014
> edi=00cfff00eip=77f68067 esp=00cffee0 ebp=00cfffb8 iopl=0 nv up ei ng
> nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:01cfe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10
> 77f6806a 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 00cfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000
> ntdll!ZwReplyWaitReceivePort
> 00cfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x40
> eax=00dff520 ebx=00000000 ecx=00153c30 edx=00000000 esi=00000014 edi=00dfff00
> eip=77f68067 esp=00dffee0 ebp=00dfffb8 iopl=0 nv up ei ng nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:01dfe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10
> 77f6806a 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 00dfffb8 77f04ef0 00000001 00000000 00000000 00000001
> ntdll!ZwReplyWaitReceivePort
> 00dfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x41
> eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00efff00
> eip=77f68067 esp=00effee0 ebp=00efffb8 iopl=0 nv up ei ng nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:01efe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10
> 77f6806a 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 00efffb8 77f04ef0 00000002 00000000 00000000 00000002
> ntdll!ZwReplyWaitReceivePort
> 00efffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x42
> eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00ffff00
> eip=77f68067 esp=00fffee0 ebp=00ffffb8 iopl=0 nv up ei ng nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:01ffe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10
> 77f6806a 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 00ffffb8 77f04ef0 00000003 00000000 00000000 00000003
> ntdll!ZwReplyWaitReceivePort
> 00ffffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x43
> eax=010ff63c ebx=00000000 ecx=010ff638 edx=00000000 esi=00000014 edi=010fff00
> eip=77f68067 esp=010ffee0 ebp=010fffb8 iopl=0 nv up ei ng nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:020fe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10
> 77f6806a 8bc0 mov eax,eax
> *----> Stack Back Trace <----*
> FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
> 010fffb8 77f04ef0 00000004 00000000 00000000 00000004
> ntdll!ZwReplyWaitReceivePort
> 010fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
> 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols>
> State Dump for Thread Id 0x44
> eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=011fff00
> eip=77f68067 esp=011ffee0 ebp=011fffb8 iopl=0 nv up ei ng nz ac po nc
> cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296
> function: ZwReplyWaitReceivePort
> 77f6805c b890000000 mov eax,0x90
> 77f68061 8d542404 lea edx,[esp+0x4]
> ss:021fe8e7=????????
> 77f68065 cd2e int 2e
> 77f68067 c21000 ret 0x10

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 07h00.


Édité par : vBulletin® version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,26914 seconds with 10 queries