Quantcast
Channel: Windows Server General Forum forum
Viewing all 24879 articles
Browse latest View live

Poolmon Tag LS$S for SMB reads 16GB in the bytes column, possible memory leak, total RAM 24GB.

$
0
0

High memory Usage on Windows 2008 R2 Sp1 DC problem. - Physical machine, Not a VM.

Problem started approx 4 months ago. Seeing High memory Usage on Windows 2008 R2 Sp1 DC. Paged Pool memory seems very high at approx 16GB. The top tag LS$S reads 16GB in the bytes column and the Tag relates to srv.sys and srv2.sys drivers. We installed KB4056897 in April and KB4103718 Addresses an issue that may cause a memory leak on SMB servers after installing KB4056897.  But our servers do not match the exact conditions detailed in KB4103718.   

From Poolmon we see Tag: LS$S Allocs at 1000,016,900  bytes and Frees at 829,796,212 bytes and Diff at 170,220,677 bytes we also see LSASS.exe Memory(Private) at over 8GB in Task Mgr.

Other DC's also have very high memory usage and Paged Pool memory usage is increasing daily. We reboot the servers to prevent them from running out of resources, it could take a few months for them to deplete their resources.

Are their any known issues that you are aware of regarding SMB and paged pool memory that has arisen recently?

Regards,

Derek



NDES SCEP IIS appcrash win server 2012r2

$
0
0

Hi

I have setup NDES role on a WS2012R2 following documentation below
https://docs.microsoft.com/en-us/intune/certificates-scep-configure
https://ronnydejong.com/2017/05/02/part-2-deploying-microsoft-intune-connector-in-an-enterprise-world-troubleshooting/IIS

Profile has been created in Intune with rootCA cert and published to win10 client, when client tries to enroll I get error in eventlog and on ndes server. On serverside in IIS-logs it seems there are IIS appcrashes whenever client tries to enroll.
I have reinstalled NDES together with IIS, checked request handling and registry entries without success.
Does anyone have any hints or knows where I should troubleshoot.

Client (win10):
SCEP Certificate enrollment for AzureAD\testuser via https://ndes.domain.com/certsrv/mscep/mscep.dll/pkiclient.exe failed:

SubmitDone
GetCACert: OK
HTTP/1.1 200 OK
Date: Sun, 25 Feb 2018 22:14:59 GMT
Content-Length: 4987
Content-Type: application/x-x509-ca-ra-cert
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET

Method: GET(11109ms)
Stage: SubmitDone
The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)



NDES Server:
Appcrash:
Faulting application name: w3wp.exe, version: 8.5.9600.16384, time stamp: 0x5215df96
Faulting module name: ntdll.dll, version: 6.3.9600.18895, time stamp: 0x5a4b1b67
Exception code: 0xc0000374


WAS (5010) A process serving application pool 'SCEP' failed to respond to a ping. The process id was '4100'.

WAS (5011) A process serving application pool 'SCEP' suffered a fatal communication error with the Windows Process Activation Service. The process id was '3940'. The data field contains the error number.


How to repair corrupted DHCP database which is giving Event ID 1010

$
0
0

How to repair corrupted DHCP database which is giving Event ID 1010

Database has been currupted long back 14July 2012 even dont have working backup copy

Kindly anybody let me know how repair DHCP Database.

Mohan

Trust Relationship between Server and DC Fails

$
0
0

I wasn't sure which forum to post this in, if there is a better one, please let me know!

I am having problems establishing a trust relationship between a server and a DC.

Here are the things I have tried(that I can rememeber):

  • Unjoining and rejoining the Domain
  • Running: netdom reset 'computername' /domain:abc /userO:xxx /passwordO:*
  • Running Test-ComputerSecureChannel -Repair -Verbose
  • Resetting the password of the computer from the DC
  • After all of these, Test-ComputerSecureChannel still returns false

Many of the error messages I get revolve around 'Access is Denied'. However, all of these commands are run from elevated PowerShell, as a domain administrator, with the netdom command run on both the local machine and the DC. The local machine is running Server 2012 and the DC is Server 2016. Any thoughts would be appreciated.

Windows 2012 R2 Migration of FRS to DFSR some errors when use diagnostic report

$
0
0

Experts,

When I try to do migration after SetGlobalState 1 I see this error:

 "Local path of replicated folder SYSVOL Share does not match the newly configured local path. "

I am following this guide:

https://blogs.technet.microsoft.com/filecab/2014/06/25/streamlined-migration-of-frs-to-dfsr-sysvol/#quick

Is that error message something I should worry about? I have reverted the migration to state 0.


ME


ME

How many CAL needed for hosting an online system? (windows server 2016)

$
0
0

Hi, i plan to buy HPE ProLiant DL360 Gen10 Silver 4110 (2.1GHz/8-core) for hosting my HR ESS system in Windows server 2016 standard, more than 100 employees will use this HR system to apply leave, view payslip. They will access it through intranet using their own computer, we also plan to let them access this system using internet once we get our own fixed IP (maybe one or two years later).

May i know what type of CAL and how many of CAL that i need to purchase? Around 6 persons will have direct access to server, others are more than 100 employees who will use the HR system hosting at the server. Is it hosting at VM will save the cost of CAL? If it does, how many CAL i need for hosting at VM?


Patch for CVE-2018-8115 - Windows Host Compute Service Shim (hcsshim) Remote Code Execution Vulnerability

$
0
0
I am unable to find the details of the patch that was released for CVE-2018-8115. Can someone please provide the link?

Computer Warning

$
0
0
I was on my computer when a huge Warning came on saying that hackers or viruses were on my computer and spreading to others.  I could not turn it off no matter how I tried.  There was an 888 phone number but when I called it, it didn't sound legit.  What action should I take now? I don't want to lose my info.

Pagefile.sys situation (can delete or not?)

$
0
0

I have some inquiry for the pagefile.sys. I'm currently maintaining Window Server 2008 VM, and we have for about 3 separate disk, C,D, and E. Before this, the RAM will consume the C drive if the RAM is not enough, and it will consume for about 32 gb. When Im rebooting the VM, I already reconfigured the virtual memory, pagefile.sys in disk d, and e for about 32 gb. and I want to make the pagefile.sys in C to none.

After rebooting, I realised that the C drive still have the old 32gb pagefile.sys before this eventhough I make it to none on the configuration. So, can I just delete the file because I already configured the pagefile.sys in another drive(D,E)? My assumption is that, after reconfiguration, if the RAM use is high, it will go to D, or E rather than to use C.



Error code lookup

$
0
0

Hello

I have been using Windows Error Lookup Tool v3.0.7 (http://www.gunnerinc.com/welt.htm) for the last few years to identify codes in event logs etc. However, I increasingly find that codes I need to lookup are not contained within the program's database.

Searching for these on the Internet is hit and miss at best. A question about a code often results in questions being asked about the system, and troubleshooting steps without actually defining the code - we still do not know what the code means.

I have used the Microsoft Exchange Server Error Code Look-up utility, but it's a faff having to open a command prompt each time I wish to use it and the supported OS is 2003. Does anyone know if there is a similar lookup tool with a GUI that maintains an up-to-date list of public error codes, please?

Thanks.

Windows Server 2016 Event 1000, Application Error Faulting application name: mmc.exe

$
0
0
Faulting application name: mmc.exe, version: 10.0.14393.2097, time stamp: 0x5a820e5d
Faulting module name: GPOAdmin.dll, version: 10.0.14393.2068, time stamp: 0x5a7e7062
Exception code: 0xc0000005
Fault offset: 0x00000000000be1d6
Faulting process id: 0x3a8
Faulting application start time: 0x01d428f2d03e703a
Faulting application path: C:\Windows\system32\mmc.exe
Faulting module path: C:\Windows\System32\GPOAdmin.dll
Report Id: a87fb79e-672e-4311-b356-b574aa4c2245
Faulting package full name:
Faulting package-relative application ID:

TrustedInstaller using a lot of memory.

$
0
0

Hello.

I'm using Windows Server 2008 R2 and a process with the name "TrustedInstaller.exe" using a lot of memory:

How can I solve it?

Thank you.

MDT support in Windows Server 2008 R2?

$
0
0

Hi All,

I want to use the MDT (Microsoft Deployment Toolkit) on a Windows Server 2008 R2 instance to image many laptops with Windows 10.

Will my Server version support imaging Windows 10?

Thanks

Davo

Changelog for Windows Server 2012R2, Windows Server 2016 and Windows Server 2019

$
0
0

Hi

To know side-by-side changes in Windows 10 Builds, I found some links that explain changelog in Windows 10 Builds also I found some links that explain which features have been deprecated in next Build of Windows 10.

Like this, I would like to know and searching for changelog and deprecated features of Windows Server 2012R2, Windows Server 2016 and upcoming Windows Server 2019.

Unfortunately, I couldn’t find more informative links yet. Please look for it.

With Regards
InTech

AD DFS Replication - Event ID 4010, 4606 & 2010 after backup process

$
0
0

Hi All,

We've recently migrated from Server 2003 DCs to Server 2012 R2 DCs and our AD is now running at Windows Server 2012 R2 Forest and Domain functional levels respectively, happy days. Yesterday we migrated from FRS to DFSR SYSVOL replication, the migration process went smoothly but I've noticed event ID 4010, 4606 & 2010 on the DCs. Our backups start at 19:00 and I've noticed that prior to these alarming Event IDs there are events warning that the DC is stopping communications with replication partners due to a backup process, could the events be linked? My initial response to these events was one of alarm but after running repadmin commands, dcdiag and using the trusted create a file in SYSVOL folder structure and see if it's replicated test it appears that replication is indeed working correctly.  

Event ID 4010, DFSR
"The DFS Replication service detected that the replicated folder at local path E:\ADDS\SYSVOL_DFSR has been removed from configuration.

Event ID 4606, DFSR
"The DFS Replication service is not replicating the SYSVOL replicated folder. If the domain controller was demoted and the DFS Replication service has been replicating SYSVOL, this event is expected and no user action is required.

Event ID 2010, DFSR
"The DFS Replication service has detected that all replicated folders on volume E: have been disabled or deleted.

All of our Server 2012 R2 DCs are VMs hosted on ESXi 5.5. We have NetApp shared storage and the backups are being taken using the NetApp Virtual Storage Console (VSC) vCenter server plugin.

Is this something that can be ignored? Has anyone else spotted these event IDs? Any advice would be appreciated.

Thanks in advance.

Andrew


what is this or who is this S-1-5-21-1960408961-1604221776-682003330-1003

$
0
0
his is in my user group what is it

Windows Server 2016 folder redirection No errors but Windows 7 client is still pointed to itself for My Music.

$
0
0

Have GPO that directs My Music, My Pictures and My Video to follow Document folder redirection.

Looking at user shell folders, I see that path is to the server for documents and to the client for My Music, My Pictures and My Video. There are no folder redirection errors but is a warning that the folder redirection is delayed.

When Windows Explorer is opened then get the following disconnect.

Documents

  My Documents

       My Music (pointed to server)

       My Pictures (pointed to server)

       My Videos (pointed to server)

Music (pointed to client)

Pictures (pointed to client)

Videos (pointed to client)

How do I fix this?

      


How to upgrade the wuaueng.dll for Windows server 2012 R2

$
0
0

Hi, 

  Some of the windows server 2012 R2 servers not getting update from the WSUS and its wualleng.all version shows 7.9.9600 18756 , How to upgrade this old version to latest version ( 7.9.9600 18970) .

Kindly clarify the below error also 

018-08-1611:18:19:4388602294AU  # Will interact with non-admins (Non-admins are elevated (User preference))
2018-08-1611:18:19:4398602294MiscWARNING:     IsSessionRemote: WinStationQueryInformationW(WTSIsRemoteSession) failed for session 3, GetLastError=2250
2018-08-1611:18:19:4508602294AUWARNING: Failed to get Wu Exemption info from NLM, assuming not exempt, error = 0x80240037
2018-08-1611:18:19:4518602294AUWARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-08-1611:18:19:4538602294AUAU finished delayed initialization
2018-08-1611:18:19:4548602294AUCurrently AUX is enabled - so not show any WU Upgrade notifications.
2018-08-1611:18:19:4558602294AUWARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-08-1611:18:19:4588602294AUWARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-08-1611:18:19:461860181cDnldMgrAsking handlers to reconcile their sandboxes
2018-08-1611:28:19:4648602278AUEarliest future timer found: 
2018-08-1611:28:19:4648602278AU    Timer: CF1ABEC6-7887-4964-BB93-B2E21B31CEC1, Expires 2018-08-16 13:53:11, not idle-only, not network-only
2018-08-1611:28:20:4648602294AU###########  AU: Uninitializing Automatic Updates  ###########
2018-08-1611:28:20:4808602294WuTaskUninit WU Task Manager
2018-08-1611:28:20:5218602294AUEarliest future timer found: 
2018-08-1611:28:20:5218602294AU    Timer: CF1ABEC6-7887-4964-BB93-B2E21B31CEC1, Expires 2018-08-16 13:53:11, not idle-only, not network-only
2018-08-1611:28:20:5438602294AUEarliest future timer found: 
2018-08-1611:28:20:5438602294AU    Timer: CF1ABEC6-7887-4964-BB93-B

Regards,

V.P.Neelakandan

error code 0x0000232B RCODE_NAME_ERROR

$
0
0

Hi all, I was create AD and join to domain one server after accidently deleted the AD server and cerate new one and now I try to add the same server again to AD and have this problem .

error code 0x0000232B RCODE_NAME_ERROR

Computers authenticate to DC on another subnet causing wrong GPO

$
0
0

Hi all,

I'm facing a weird problem. I have a DC on subnet 1.0 with some GPO applied according to sites. Sometimes I have computers that get GPO from a DC on a other subnet (2.0) despite their DHCP is right configured.

After a reboot all come back in order, but I can't find why they don't contact their proper DC first.

When the problem appear, nslookup return to the wrong DC, and DHCP is ok. Sites & Services is right configured.

DC on 1.0 is W2K8, DC on 2.0 is W2K16.

Thanks

Viewing all 24879 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>