|
|
|
|
||||||
| ms.public.winnt.domain Usnet Forum about Windows NT. |
![]() |
|
|
LinkBack | Outils de la discussion |
|
|
#1 |
|
Messages: n/a
Hébergeur: |
Hi,
We have multiple issues with Windows NT4 servers ... since july we have about 10-15 servers that stop working ... can't log on locally , application running on these servers are still responding (oracle, IIS ) , can't acces any share on the server, unable to shutdown properly ... when connecting to a share you get the error unable to connect, RPC service is not availiable ... we dont have any message in the event viewers (only when we get the DR watson errors but not all the time) We have still have about 100 Windows nt 4 server only those 10-15 have the issues ... they are not the same subnet and they are located anywhere in the country .. the server are running Norton Symentec v.10 and Mcafee Virus Scan 5.2.0.0 .. they are updated correctly ... Here is what we done for now : Deactivate anti-virus software , (no change) verify for any virus that attacks RPC service (found nothing) Verify if there was attack on RPC port ( found nothing) Un-install SMS agent (no change) deactivated automatic inventory update ((no change) verify the disk space (space is good on all servers) verify the backups done on all these servers (found nothing) All the server are old Compaq machines .. we discover that the Power Management Software from compaq could cause these problems but in not install on any server ... All the servers have service pack 6 a installed .. and they all have the same version of the rpcss.exe file v. 4.0.1381.7263 All servers got the latest and last patches done by microsoft for Windows NT4 ... I notice that some servers got DR watson .. here the detail of one of then some of them .. they dont always coinside we the problem but i got this on several of them see below ... Any is very appreciated Thank you ... Application exception occurred: App: exe\lsass.dbg (pid=57) When: 10/7/2007 @ 21:14:6.265 Exception number: c0000005 (access violation) *----> System Information <----* Computer Name: GBWEB01 User Name: <unknown user name> Number of Processors: 1 Processor Type: x86 Family 6 Model 8 Stepping 3 Windows Version: 4.0 Current Build: 1381 Service Pack: 6 Current Type: Uniprocessor Free Registered Organization: PMG Registered Owner: GBWEB01 *----> Task List <----* 0 Idle.exe 2 System.exe 32 SMSS.exe 36 CSRSS.exe 42 WINLOGON.exe 52 SERVICES.exe 57 LSASS.exe 82 SPOOLSS.exe 95 rpcss.exe 102 msdtc.exe 122 Ntagent.exe 126 CPQRCMC.exe 132 DefWatch.exe 135 DkService.exe 139 Control.exe 141 DNTUS26.exe 145 em60.exe 150 LogWatNT.exe 154 NetIQccm.exe 176 TCSERVER.exe 185 PSTORES.exe 191 SRVANY.exe 195 SavRoam.exe 197 QAWS.exe 203 mstask.exe 215 SNMP.exe 223 Rtvscan.exe 228 SYSDOWN.exe 232 SRVANY.exe 236 WinMgmt.exe 246 inetinfo.exe 250 ASDSCSVC.exe 254 cpqnimgt.exe 187 LicCheck.exe 265 cqmgserv.exe 274 cqmgstor.exe 405 cqmghost.exe 443 cpqwmgmt.exe 308 mtx.exe 520 mtx.exe 446 mtx.exe 517 NetIQmc.exe 263 NQPERF~1.exe 320 GENEventLog.exe 454 DWRCS.exe 507 DRWTSN32.exe 0 _Total.exe (018e0000 - 018e6000) exe\lsass.dbg (77f60000 - 77fbf000) dll\ntdll.dbg (77f00000 - 77f5e000) dll\kernel32.dbg (76520000 - 76549000) dll\lsasrv.dbg (78000000 - 78044000) (77e10000 - 77e67000) dll\rpcrt4.dbg (77dc0000 - 77dff000) dll\advapi32.dbg (77e70000 - 77ec2000) dll\user32.dbg (7c000000 - 7c035000) dll\gdi32.dbg (74f50000 - 74f7e000) dll\samsrv.dbg (75c20000 - 75c2c000) dll\msprivs.dbg (73680000 - 736b2000) dll\netlogon.dbg (4ca00000 - 4ca41000) dll\netapi32.dbg (77840000 - 77849000) dll\NetRap.dbg (777e0000 - 777ed000) dll\samlib.dbg (776d0000 - 776d8000) dll\wsock32.dbg (776b0000 - 776c4000) dll\ws2_32.dbg (776a0000 - 776a7000) dll\ws2.dbg (52100000 - 52128000) dll\wldap32.dbg (75b80000 - 75b8f000) dll\msv1_0.dbg (77e00000 - 77e06000) dll\rpclts1.dbg (77bf0000 - 77bf7000) dll\rpcltc1.dbg (76e70000 - 76e82000) dll\secur128.dbg (71710000 - 71724000) dll\msapsspc.dbg (779d0000 - 779d0000) (780a0000 - 780b2000) (77400000 - 7741e000) dll\sch128c.dbg (5e380000 - 5e3a5000) dll\msoss.dbg (5cf00000 - 5cf75000) dll\crypt32.dbg (01620000 - 01630000) dll\msasn1.dbg (716e0000 - 716ff000) dll\msnsspc.dbg (01630000 - 01640000) (77980000 - 779a4000) dll\dnsapi.dbg (77660000 - 7766f000) dll\msafd.dbg (77690000 - 77699000) dll\wshtcpip.dbg (77be0000 - 77be5000) dll\secur32.dbg (77720000 - 77731000) dll\mpr.dbg (01bf0000 - 01bf7000) dll\iissuba.dbg State Dump for Thread Id 0x3c eax=00144e80 ebx=77e58000 ecx=00000000 edx=00000000 esi=009ef790 edi=00138dd0 eip=77f67b1b esp=009ef684 ebp=009ef6c4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 function: ZwFsControlFile 77f67b10 b83b000000 mov eax,0x3b 77f67b15 8d542404 lea edx,[esp+0x4] ss:019ee08b=???????? 77f67b19 cd2e int 2e 77f67b1b c22800 ret 0x28 77f67b1e 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 009ef6c4 77e20e1e 00138dd0 001af008 000003fc 009ef79c ntdll!ZwFsControlFile 009ef6ec 77e3080d 001af008 000003fc 009ef79c 009ef790 rpcrt4!I_RpcTransServerUnprotectThread 009ef7cc 77e1f92b 009efa48 00000000 00000000 009ef830 rpcrt4!I_RpcLaunchDatagramReceiveThread 009ef840 77e2058b 009efa48 00000000 009efb10 009ef994 rpcrt4!I_RpcTransServerNewConnection 009efb10 77dcab93 77dec248 77dec3fa 009efb2c 0198ca18 rpcrt4!I_RpcTransServerReallocBuffer 009efb9c 7652e466 0013f1e0 00000010 00000003 00000230 advapi32!ElfReportEventA 009efd80 7652e243 008e0000 0012fea4 009efeb8 00000000 lsasrv!LsarEnumerateTrustedDomains 009efd98 7652dd75 008e0000 00000000 7652b8df 009efdb8 lsasrv!LsarEnumerateTrustedDomains 009effb8 77f04ef0 00000000 0012fea4 0012fd68 00000000 lsasrv!LsarEnumerateTrustedDomains 009effec 00000000 7652b854 00000000 00000000 000000b0 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> *----> Raw Stack Dump <----* 009ef684 49 10 bf 77 24 01 00 00 - 00 00 00 00 00 00 00 00 I..w$........... 009ef694 00 00 00 00 bc f6 9e 00 - 17 c0 11 00 08 f0 1a 00 ................ 009ef6a4 fc 03 00 00 10 70 14 00 - 00 04 00 00 00 00 00 00 .....p.......... 009ef6b4 90 8c 13 00 00 80 e5 77 - 00 00 00 00 24 00 00 00 .......w....$... 009ef6c4 ec f6 9e 00 1e 0e e2 77 - d0 8d 13 00 08 f0 1a 00 .......w........ 009ef6d4 fc 03 00 00 9c f7 9e 00 - 90 f7 9e 00 00 00 00 00 ................ 009ef6e4 e4 03 00 00 08 f0 1a 00 - cc f7 9e 00 0d 08 e3 77 ...............w 009ef6f4 08 f0 1a 00 fc 03 00 00 - 9c f7 9e 00 90 f7 9e 00 ................ 009ef704 20 f8 9e 00 74 fa 9e 00 - 90 8c 13 00 00 f6 53 76 ...t.........Sv 009ef714 3a c5 de 77 20 f0 1a 00 - 94 f9 9e 00 58 c5 de 77 :..w .......X..w 009ef724 58 f7 9e 00 79 37 e1 77 - 94 f9 9e 00 e0 f3 1a 00 X...y7.w........ 009ef734 00 f6 53 76 54 c5 de 77 - e4 f3 1a 00 7c fd 9e 00 ..SvT..w....|... 009ef744 4c c5 de 77 3d 00 00 00 - 00 00 00 00 08 fd 9e 00 L..w=........... 009ef754 dc f3 1a 00 78 f7 9e 00 - c1 29 e1 77 94 f9 9e 00 ....x....).w.... 009ef764 74 fd 9e 00 4c c5 de 77 - 74 fd 9e 00 cd f9 9e 00 t...L..wt....... 009ef774 00 c5 de 77 98 f7 9e 00 - c8 24 e1 77 94 f9 9e 00 ...w.....$.w.... 009ef784 74 fd 9e 00 48 c5 de 77 - 01 00 00 00 00 04 00 00 t...H..w........ 009ef794 00 00 00 00 b8 8d 13 00 - 10 70 14 00 94 f9 9e 00 .........p...... 009ef7a4 04 8d 13 00 54 fa 9e 00 - 50 fa 9e 00 01 00 00 00 ....T...P....... 009ef7b4 30 16 00 00 d2 c5 de 77 - e4 03 00 00 18 00 00 00 0......w........ State Dump for Thread Id 0x3e eax=00bffdac ebx=00000000 ecx=00000101 edx=00000000 esi=77f9e4c0 edi=00000000 eip=77f6839b esp=00bfff98 ebp=00bfffb8 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 function: NtWaitForSingleObject 77f68390 b8c5000000 mov eax,0xc5 77f68395 8d542404 lea edx,[esp+0x4] ss:01bfe99f=???????? 77f68399 cd2e int 2e 77f6839b c20c00 ret 0xc 77f6839e 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 00bfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000 ntdll!NtWaitForSingleObject 00bfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x3f eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00cfff00eip=77f68067 esp=00cffee0 ebp=00cfffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:01cfe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 00cfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000 ntdll!ZwReplyWaitReceivePort 00cfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x40 eax=00dff520 ebx=00000000 ecx=00153c30 edx=00000000 esi=00000014 edi=00dfff00 eip=77f68067 esp=00dffee0 ebp=00dfffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:01dfe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 00dfffb8 77f04ef0 00000001 00000000 00000000 00000001 ntdll!ZwReplyWaitReceivePort 00dfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x41 eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00efff00 eip=77f68067 esp=00effee0 ebp=00efffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:01efe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 00efffb8 77f04ef0 00000002 00000000 00000000 00000002 ntdll!ZwReplyWaitReceivePort 00efffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x42 eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00ffff00 eip=77f68067 esp=00fffee0 ebp=00ffffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:01ffe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 00ffffb8 77f04ef0 00000003 00000000 00000000 00000003 ntdll!ZwReplyWaitReceivePort 00ffffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x43 eax=010ff63c ebx=00000000 ecx=010ff638 edx=00000000 esi=00000014 edi=010fff00 eip=77f68067 esp=010ffee0 ebp=010fffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:020fe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 010fffb8 77f04ef0 00000004 00000000 00000000 00000004 ntdll!ZwReplyWaitReceivePort 010fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x44 eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=011fff00 eip=77f68067 esp=011ffee0 ebp=011fffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:021fe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 011fffb8 77f04ef0 00000005 00000000 00000000 00000005 ntdll!ZwReplyWaitReceivePort 011fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x45 eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=012fff00 eip=77f68067 esp=012ffee0 ebp=012fffb8 iopl=0 nv up ei ng nz ac po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296 function: ZwReplyWaitReceivePort 77f6805c b890000000 mov eax,0x90 77f68061 8d542404 lea edx,[esp+0x4] ss:022fe8e7=???????? 77f68065 cd2e int 2e 77f68067 c21000 ret 0x10 77f6806a 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 012fffb8 77f04ef0 00000006 00000000 00000000 00000006 ntdll!ZwReplyWaitReceivePort 012fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x46 eax=0013b601 ebx=013fff64 ecx=00000000 edx=00000000 esi=000000dc edi=00000000 eip=77f67fc7 esp=013ffe84 ebp=013ffeec iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 function: ZwReadFile 77f67fbc b886000000 mov eax,0x86 77f67fc1 8d542404 lea edx,[esp+0x4] ss:023fe88b=???????? 77f67fc5 cd2e int 2e 77f67fc7 c22400 ret 0x24 77f67fca 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 013ffeec 77dd8a35 000000dc 001384b8 0000021a 013fff1c ntdll!ZwReadFile 013fff20 77dd8481 000000dc 001384b8 0000021a 013fff64 advapi32!RegisterServiceCtrlHandlerA 013fff84 77dd829e 000000dc 001384b8 0000021a 0012ffb0 advapi32!StartServiceCtrlDispatcherW 013fffa8 76528f3e 76544268 77f3b968 00000000 77f04ef0 advapi32!StartServiceCtrlDispatcherA 013fffec 00000000 00000000 00000000 00000000 00000000 lsasrv!LsapInitLsa 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x4c eax=0000afc8 ebx=015ffc94 ecx=0000000d edx=00000000 esi=7ffdf000 edi=00000001 eip=77f6838b esp=015ffc70 ebp=015ffcc4 iopl=0 nv up ei pl nz ac pe cy cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000213 function: NtWaitForMultipleObjects 77f68380 b8c4000000 mov eax,0xc4 77f68385 8d542404 lea edx,[esp+0x4] ss:025fe677=???????? 77f68389 cd2e int 2e 77f6838b c21400 ret 0x14 77f6838e 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 015ffcc4 77f1cf3e 00000002 015ffec8 00000000 0000afc8 ntdll!NtWaitForMultipleObjects 015ffce0 7368957b 00000002 015ffec8 00000000 0000afc8 kernel32!WaitForMultipleObjects 015fff58 73689fb1 001384b8 73680000 00144d58 76541830 netlogon!I_NetNotifyRole 015fff74 7652cb77 00000001 00144d60 001384b8 00144d58 netlogon!NlNetlogonMain 015fffa8 77dd8c15 00000001 00144d60 001383d0 77f04ef0 lsasrv!LsaIOpenPolicyTrusted 015fffec 00000000 00000000 00000000 00000000 00000000 advapi32!RegisterServiceCtrlHandlerA 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> State Dump for Thread Id 0x22a eax=00000000 ebx=00137b48 ecx=00000501 edx=00000000 esi=00137b38 edi=00000006 eip=77f6838b esp=2740feec ebp=2740ff2c iopl=0 nv up ei pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206 function: NtWaitForMultipleObjects 77f68380 b8c4000000 mov eax,0xc4 77f68385 8d542404 lea edx,[esp+0x4] ss:2840e8f3=???????? 77f68389 cd2e int 2e 77f6838b c21400 ret 0x14 77f6838e 8bc0 mov eax,eax *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 2740ff2c 77e20fb4 00137b38 2740ff58 2740ff88 2740ff84 ntdll!NtWaitForMultipleObjects 2740ff60 77e1da4a 2740ff8c 2740ff88 2740ff84 0015c0b8 rpcrt4!I_RpcTransServerUnprotectThread 2740ff90 77e1f49b 77e17bd9 00137a58 2740ffec ffffffff rpcrt4!RpcTestCancel 00003a98 00000000 00000000 00000000 00000000 00000000 rpcrt4!I_RpcTransServerNewConnection State Dump for Thread Id 0x246 eax=2750fcdc ebx=00191fd0 ecx=00000030 edx=00000000 esi=00000010 edi=00173924 eip=76534730 esp=2750fc48 ebp=2750fc8c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 function: LsarLookupNames 76534713 85c0 test eax,eax 76534715 7c30 jl LsarLookupNames+0x1795 (76534747) 76534717 8b45ec mov eax,[ebp-0x14] ss:2850e692=???????? 7653471a 8b4de0 mov ecx,[ebp-0x20] ss:2850e692=???????? 7653471d c1e104 shl ecx,0x4 76534720 8b54300c mov edx,[eax+esi+0xc] ds:00ffea17=19638800 76534724 0355c8 add edx,[ebp-0x38] ss:2850e692=???????? 76534727 8b4518 mov eax,[ebp+0x18] ss:2850e692=???????? 7653472a 8b5804 mov ebx,[eax+0x4] ds:2850e6e2=???????? 7653472d 8b4524 mov eax,[ebp+0x24] ss:2850e692=???????? FAULT ->76534730 89540b0c mov [ebx+ecx+0xc],edx ds:00ffea37=19642800 76534734 ff08 dec dword ptr [eax] ds:2750fcdc=00000003 76534736 83c704 add edi,0x4 76534739 83c610 add esi,0x10 7653473c 8b45d4 mov eax,[ebp-0x2c] ss:2850e692=???????? 7653473f ff45cc inc dword ptr [ebp-0x34] ss:2850e692=???????? 76534742 3945cc cmp [ebp-0x34],eax ss:2850e692=???????? 76534745 7287 jb LsarLookupNames+0x171c (765346ce) 76534747 33f6 xor esi,esi 76534749 3975f8 cmp [ebp-0x8],esi ss:2850e692=???????? 7653474c 0f8c7bfeffff jl LsarLookupNames+0x161b (765345cd) 76534752 3975d8 cmp [ebp-0x28],esi ss:2850e692=???????? *----> Stack Back Trace <----* FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name 2750fc8c 76532a3a 00000003 001ba2e8 2750fcc8 001a1ff0 lsasrv!LsarLookupNames 2750fcfc 76539ea3 00164378 001ba2dc 2750fde4 001ba354 lsasrv!LsarLookupSids 2750fe20 77e11423 2750fef0 001380a8 2750fef0 00000000 lsasrv!<nosymbols> 2750fe5c 77e111dc 76539d84 2750fef0 2750ff34 00000000 rpcrt4!NdrClientInitializeNew 2750feb0 77e114f9 2750fef0 00000000 2750ff34 00176074 rpcrt4!I_RpcGetBuffer 2750fed0 77e1e035 2750fef0 00000000 2750ff34 00176074 rpcrt4!NdrClientInitializeNew 2750ff40 77e1ff21 001ba2b0 000000b4 2750ff90 00137a80 rpcrt4!RpcTestCancel 001ba2b0 00000010 000000b4 00000003 0000009c 000f0000 rpcrt4!I_RpcTransServerNewConnection thank you for your ... |
|
|
|
#2 |
|
Messages: n/a
Hébergeur: |
I am a rookie,so bear with me.Basically,the same problems,came up on my Net
Vista ,Windows 2000 same stepping stuff.My error report said error 1202,from Microsoft.It was a security conflict from a clash between Norton,who I thought I had taken everything off,and my ISP security system.Mine BSOD'd,2 months later.,for improper registration.Any ,will be appreciated.Thanks. -- zadude "The_Amply" wrote: > Hi, > We have multiple issues with Windows NT4 servers ... since july we have > about 10-15 servers that stop working ... can't log on locally , > application running on these servers are still responding (oracle, IIS ) , > can't acces any share on the server, unable to shutdown properly ... when > connecting to a share you get the error unable to connect, RPC service is not > availiable ... we dont have any message in the event viewers (only when we > get the DR watson errors but not all the time) > We have still have about 100 Windows nt 4 server only those 10-15 have the > issues ... they are not the same subnet and they are located anywhere in > the country .. the server are running Norton Symentec v.10 and Mcafee Virus > Scan 5.2.0.0 .. they are updated correctly ... > Here is what we done for now : > Deactivate anti-virus software , (no change) > verify for any virus that attacks RPC service (found nothing) > Verify if there was attack on RPC port ( found nothing) > Un-install SMS agent (no change) > deactivated automatic inventory update ((no change) > verify the disk space (space is good on all servers) > verify the backups done on all these servers (found nothing) > All the server are old Compaq machines .. we discover that the Power > Management Software from compaq could cause these problems but in not install > on any server ... > All the servers have service pack 6 a installed .. and they all have the > same version of the rpcss.exe file v. 4.0.1381.7263 > All servers got the latest and last patches done by microsoft for Windows > NT4 ... > I notice that some servers got DR watson .. here the detail of one of then > some of them .. they dont always coinside we the problem but i got this on > several of them see below ... > > Any is very appreciated Thank you ... > > Application exception occurred: > App: exe\lsass.dbg (pid=57) > When: 10/7/2007 @ 21:14:6.265 > Exception number: c0000005 (access violation) > *----> System Information <----* > Computer Name: GBWEB01 > User Name: <unknown user name> > Number of Processors: 1 > Processor Type: x86 Family 6 Model 8 Stepping 3 > Windows Version: 4.0 > Current Build: 1381 > Service Pack: 6 > Current Type: Uniprocessor Free > Registered Organization: PMG > Registered Owner: GBWEB01 > *----> Task List <----* > 0 Idle.exe > 2 System.exe > 32 SMSS.exe > 36 CSRSS.exe > 42 WINLOGON.exe > 52 SERVICES.exe > 57 LSASS.exe > 82 SPOOLSS.exe > 95 rpcss.exe > 102 msdtc.exe > 122 Ntagent.exe > 126 CPQRCMC.exe > 132 DefWatch.exe > 135 DkService.exe > 139 Control.exe > 141 DNTUS26.exe > 145 em60.exe > 150 LogWatNT.exe > 154 NetIQccm.exe > 176 TCSERVER.exe > 185 PSTORES.exe > 191 SRVANY.exe > 195 SavRoam.exe > 197 QAWS.exe > 203 mstask.exe > 215 SNMP.exe > 223 Rtvscan.exe > 228 SYSDOWN.exe > 232 SRVANY.exe > 236 WinMgmt.exe > 246 inetinfo.exe > 250 ASDSCSVC.exe > 254 cpqnimgt.exe > 187 LicCheck.exe > 265 cqmgserv.exe > 274 cqmgstor.exe > 405 cqmghost.exe > 443 cpqwmgmt.exe > 308 mtx.exe > 520 mtx.exe > 446 mtx.exe > 517 NetIQmc.exe > 263 NQPERF~1.exe > 320 GENEventLog.exe > 454 DWRCS.exe > 507 DRWTSN32.exe > 0 _Total.exe > (018e0000 - 018e6000) exe\lsass.dbg > (77f60000 - 77fbf000) dll\ntdll.dbg > (77f00000 - 77f5e000) dll\kernel32.dbg > (76520000 - 76549000) dll\lsasrv.dbg > (78000000 - 78044000) > (77e10000 - 77e67000) dll\rpcrt4.dbg > (77dc0000 - 77dff000) dll\advapi32.dbg > (77e70000 - 77ec2000) dll\user32.dbg > (7c000000 - 7c035000) dll\gdi32.dbg > (74f50000 - 74f7e000) dll\samsrv.dbg > (75c20000 - 75c2c000) dll\msprivs.dbg > (73680000 - 736b2000) dll\netlogon.dbg > (4ca00000 - 4ca41000) dll\netapi32.dbg > (77840000 - 77849000) dll\NetRap.dbg > (777e0000 - 777ed000) dll\samlib.dbg > (776d0000 - 776d8000) dll\wsock32.dbg > (776b0000 - 776c4000) dll\ws2_32.dbg > (776a0000 - 776a7000) dll\ws2.dbg > (52100000 - 52128000) dll\wldap32.dbg > (75b80000 - 75b8f000) dll\msv1_0.dbg > (77e00000 - 77e06000) dll\rpclts1.dbg > (77bf0000 - 77bf7000) dll\rpcltc1.dbg > (76e70000 - 76e82000) dll\secur128.dbg > (71710000 - 71724000) dll\msapsspc.dbg > (779d0000 - 779d0000) > (780a0000 - 780b2000) > (77400000 - 7741e000) dll\sch128c.dbg > (5e380000 - 5e3a5000) dll\msoss.dbg > (5cf00000 - 5cf75000) dll\crypt32.dbg > (01620000 - 01630000) dll\msasn1.dbg > (716e0000 - 716ff000) dll\msnsspc.dbg > (01630000 - 01640000) > (77980000 - 779a4000) dll\dnsapi.dbg > (77660000 - 7766f000) dll\msafd.dbg > (77690000 - 77699000) dll\wshtcpip.dbg > (77be0000 - 77be5000) dll\secur32.dbg > (77720000 - 77731000) dll\mpr.dbg > (01bf0000 - 01bf7000) dll\iissuba.dbg > State Dump for Thread Id 0x3c > eax=00144e80 ebx=77e58000 ecx=00000000 edx=00000000 esi=009ef790 edi=00138dd0 > eip=77f67b1b esp=009ef684 ebp=009ef6c4 iopl=0 nv up ei pl zr na po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 > function: ZwFsControlFile > 77f67b10 b83b000000 mov eax,0x3b > 77f67b15 8d542404 lea edx,[esp+0x4] > ss:019ee08b=???????? > 77f67b19 cd2e int 2e > 77f67b1b c22800 ret 0x28 > 77f67b1e 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 009ef6c4 77e20e1e 00138dd0 001af008 000003fc 009ef79c ntdll!ZwFsControlFile > 009ef6ec 77e3080d 001af008 000003fc 009ef79c 009ef790 > rpcrt4!I_RpcTransServerUnprotectThread > 009ef7cc 77e1f92b 009efa48 00000000 00000000 009ef830 > rpcrt4!I_RpcLaunchDatagramReceiveThread > 009ef840 77e2058b 009efa48 00000000 009efb10 009ef994 > rpcrt4!I_RpcTransServerNewConnection > 009efb10 77dcab93 77dec248 77dec3fa 009efb2c 0198ca18 > rpcrt4!I_RpcTransServerReallocBuffer > 009efb9c 7652e466 0013f1e0 00000010 00000003 00000230 > advapi32!ElfReportEventA > 009efd80 7652e243 008e0000 0012fea4 009efeb8 00000000 > lsasrv!LsarEnumerateTrustedDomains > 009efd98 7652dd75 008e0000 00000000 7652b8df 009efdb8 > lsasrv!LsarEnumerateTrustedDomains > 009effb8 77f04ef0 00000000 0012fea4 0012fd68 00000000 > lsasrv!LsarEnumerateTrustedDomains > 009effec 00000000 7652b854 00000000 00000000 000000b0 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > *----> Raw Stack Dump <----* > 009ef684 49 10 bf 77 24 01 00 00 - 00 00 00 00 00 00 00 00 I..w$........... > 009ef694 00 00 00 00 bc f6 9e 00 - 17 c0 11 00 08 f0 1a 00 ................ > 009ef6a4 fc 03 00 00 10 70 14 00 - 00 04 00 00 00 00 00 00 .....p.......... > 009ef6b4 90 8c 13 00 00 80 e5 77 - 00 00 00 00 24 00 00 00 .......w....$... > 009ef6c4 ec f6 9e 00 1e 0e e2 77 - d0 8d 13 00 08 f0 1a 00 .......w........ > 009ef6d4 fc 03 00 00 9c f7 9e 00 - 90 f7 9e 00 00 00 00 00 ................ > 009ef6e4 e4 03 00 00 08 f0 1a 00 - cc f7 9e 00 0d 08 e3 77 ...............w > 009ef6f4 08 f0 1a 00 fc 03 00 00 - 9c f7 9e 00 90 f7 9e 00 ................ > 009ef704 20 f8 9e 00 74 fa 9e 00 - 90 8c 13 00 00 f6 53 76 ...t.........Sv > 009ef714 3a c5 de 77 20 f0 1a 00 - 94 f9 9e 00 58 c5 de 77 :..w .......X..w > 009ef724 58 f7 9e 00 79 37 e1 77 - 94 f9 9e 00 e0 f3 1a 00 X...y7.w........ > 009ef734 00 f6 53 76 54 c5 de 77 - e4 f3 1a 00 7c fd 9e 00 ..SvT..w....|... > 009ef744 4c c5 de 77 3d 00 00 00 - 00 00 00 00 08 fd 9e 00 L..w=........... > 009ef754 dc f3 1a 00 78 f7 9e 00 - c1 29 e1 77 94 f9 9e 00 ....x....).w.... > 009ef764 74 fd 9e 00 4c c5 de 77 - 74 fd 9e 00 cd f9 9e 00 t...L..wt....... > 009ef774 00 c5 de 77 98 f7 9e 00 - c8 24 e1 77 94 f9 9e 00 ...w.....$.w.... > 009ef784 74 fd 9e 00 48 c5 de 77 - 01 00 00 00 00 04 00 00 t...H..w........ > 009ef794 00 00 00 00 b8 8d 13 00 - 10 70 14 00 94 f9 9e 00 .........p...... > 009ef7a4 04 8d 13 00 54 fa 9e 00 - 50 fa 9e 00 01 00 00 00 ....T...P....... > 009ef7b4 30 16 00 00 d2 c5 de 77 - e4 03 00 00 18 00 00 00 0......w........ > State Dump for Thread Id 0x3e > eax=00bffdac ebx=00000000 ecx=00000101 edx=00000000 esi=77f9e4c0 edi=00000000 > eip=77f6839b esp=00bfff98 ebp=00bfffb8 iopl=0 nv up ei pl zr na po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246 > function: NtWaitForSingleObject > 77f68390 b8c5000000 mov eax,0xc5 > 77f68395 8d542404 lea edx,[esp+0x4] > ss:01bfe99f=???????? > 77f68399 cd2e int 2e > 77f6839b c20c00 ret 0xc > 77f6839e 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 00bfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000 > ntdll!NtWaitForSingleObject > 00bfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x3f > eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 > edi=00cfff00eip=77f68067 esp=00cffee0 ebp=00cfffb8 iopl=0 nv up ei ng > nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:01cfe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 > 77f6806a 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 00cfffb8 77f04ef0 00000000 77f92f94 77f9e4c0 00000000 > ntdll!ZwReplyWaitReceivePort > 00cfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x40 > eax=00dff520 ebx=00000000 ecx=00153c30 edx=00000000 esi=00000014 edi=00dfff00 > eip=77f68067 esp=00dffee0 ebp=00dfffb8 iopl=0 nv up ei ng nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:01dfe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 > 77f6806a 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 00dfffb8 77f04ef0 00000001 00000000 00000000 00000001 > ntdll!ZwReplyWaitReceivePort > 00dfffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x41 > eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00efff00 > eip=77f68067 esp=00effee0 ebp=00efffb8 iopl=0 nv up ei ng nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:01efe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 > 77f6806a 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 00efffb8 77f04ef0 00000002 00000000 00000000 00000002 > ntdll!ZwReplyWaitReceivePort > 00efffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x42 > eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=00ffff00 > eip=77f68067 esp=00fffee0 ebp=00ffffb8 iopl=0 nv up ei ng nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:01ffe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 > 77f6806a 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 00ffffb8 77f04ef0 00000003 00000000 00000000 00000003 > ntdll!ZwReplyWaitReceivePort > 00ffffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x43 > eax=010ff63c ebx=00000000 ecx=010ff638 edx=00000000 esi=00000014 edi=010fff00 > eip=77f68067 esp=010ffee0 ebp=010fffb8 iopl=0 nv up ei ng nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:020fe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 > 77f6806a 8bc0 mov eax,eax > *----> Stack Back Trace <----* > FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name > 010fffb8 77f04ef0 00000004 00000000 00000000 00000004 > ntdll!ZwReplyWaitReceivePort > 010fffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW > 00000000 00000000 00000000 00000000 00000000 00000000 lsass!<nosymbols> > State Dump for Thread Id 0x44 > eax=00181fec ebx=00000000 ecx=00000002 edx=00000000 esi=00000014 edi=011fff00 > eip=77f68067 esp=011ffee0 ebp=011fffb8 iopl=0 nv up ei ng nz ac po nc > cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000296 > function: ZwReplyWaitReceivePort > 77f6805c b890000000 mov eax,0x90 > 77f68061 8d542404 lea edx,[esp+0x4] > ss:021fe8e7=???????? > 77f68065 cd2e int 2e > 77f68067 c21000 ret 0x10 |
|
![]() |
| Outils de la discussion | |
|
|