Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Server becomes completely unresponsive

Status
Not open for further replies.

reynolwi

IS-IT--Management
Sep 7, 2006
452
US
My AD server here at the main site has started acting extremely weird. Somebody figured they could install Sharepoint Services on the server so Im thinking sharepoint screwed something up because with sharepoint you would lose all communication with the server and we couldnt login locally. I removed sharepoint and rebooted a few times and its still doing it and its giving me these error messages...

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 7/17/2008
Time: 9:50:45 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER-1
Description:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.

For more information, see Help and Support Center at

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1054
Date: 7/17/2008
Time: 10:00:45 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER-1
Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.

For more information, see Help and Support Center at

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1053
Date: 7/17/2008
Time: 10:15:47 AM
User: NT AUTHORITY\SYSTEM
Computer: SERVER-1
Description:
Windows cannot determine the user or computer name. (The RPC server is unavailable. ). Group Policy processing aborted.

For more information, see Help and Support Center at


Event Type: Warning
Event Source: SRMSVC
Event Category: None
Event ID: 12317
Date: 7/17/2008
Time: 10:20:06 AM
User: N/A
Computer: SERVER-1
Description:
File Server Resource Manager failed to enumerate share paths or DFS paths. Mappings from local file paths to share and DFS paths may be incomplete or temporarily unavailable. FSRM will retry the operation at a later time.

Error-specific details:
Error: NetShareEnum, 0x8007046a, Not enough server storage is available to process this command.

Error: (0x8007054b) The specified domain either does not exist or could not be contacted.


For more information, see Help and Support Center at Data:
0000: 50 4d 43 41 43 48 45 43 PMCACHEC
0008: 35 34 33 00 00 00 00 00 543.....
0010: 50 4d 43 41 43 48 45 43 PMCACHEC
0018: 35 31 36 00 00 00 00 00 516.....



Event Type: Error
Event Source: MSSQL$SOPHOS
Event Category: (8)
Event ID: 19011
Date: 7/18/2008
Time: 7:29:48 AM
User: N/A
Computer: SERVER-1
Description:
The description for Event ID ( 19011 ) in Source ( MSSQL$SOPHOS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: FillAddress(MSAFD Tcpip [TCP/IPv6]) : Error 0.



Event Type: Error
Event Source: LoadPerf
Event Category: None
Event ID: 3012
Date: 7/18/2008
Time: 7:31:23 AM
User: N/A
Computer: SERVER-1
Description:
The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. BaseIndex value from Performance registry is the first DWORD in Data section, LastCounter value is the second DWORD in Data section, and LastHelp value is the third DWORD in Data section.

For more information, see Help and Support Center at Data:
0000: 37 07 00 00 00 00 00 00 7.......
0008: 00 00 00 00 09 03 00 00 ........



Event Type: Error
Event Source: LoadPerf
Event Category: None
Event ID: 3011
Date: 7/18/2008
Time: 7:31:23 AM
User: N/A
Computer: SERVER-1
Description:
Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The Error code is the first DWORD in Data section.

For more information, see Help and Support Center at Data:
0000: f2 03 00 00 6e 05 00 00 ò...n...



Reading all the error messages in all the logs its like it completely loses communication with itself as well because DFS, DNS, FRS, DHCP, Directory Service all start failing because it cant find itself.

Wm. Reynolds
Premise Communications
Texas Public Safety Solutions


- - - - - - - - - - - - -

Network Error:
Hit any user to continue
 
For some reason these got left out. I took a few from each service log...

Event Type: Error
Event Source: Application Popup
Event Category: None
Event ID: 333
Date: 7/17/2008
Time: 5:37:06 PM
User: N/A
Computer: SERVER-1
Description:
An I/O operation initiated by the Registry failed unrecoverably. The Registry could not read in, or write out, or flush, one of the files that contain the system's image of the Registry.

For more information, see Help and Support Center at Data:
0000: 00 00 00 00 01 00 6c 00 ......l.
0008: 00 00 00 00 4d 01 00 c0 ....M..À
0010: 00 00 00 00 4d 01 00 c0 ....M..À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........



Event Type: Error
Event Source: Srv
Event Category: None
Event ID: 2019
Date: 7/17/2008
Time: 5:37:20 PM
User: N/A
Computer: SERVER-1
Description:
The server was unable to allocate from the system nonpaged pool because the pool was empty.

For more information, see Help and Support Center at Data:
0000: 00 00 04 00 01 00 54 00 ......T.
0008: 00 00 00 00 e3 07 00 c0 ....ã..À
0010: 00 00 00 00 9a 00 00 c0 ....?..À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 42 00 00 00 B...



Event Type: Warning
Event Source: W32Time
Event Category: None
Event ID: 22
Date: 7/17/2008
Time: 5:27:46 PM
User: N/A
Computer: TXCS-W1
Description:
The time provider NtpServer encountered an error while digitally signing the NTP response. NtpServer cannot provide secure (signed) time to the client and will ignore the request. The error was: Not enough server storage is available to process this command. (0x8007046A)

For more information, see Help and Support Center at


Event Type: Warning
Event Source: Srv
Event Category: None
Event ID: 2012
Date: 7/17/2008
Time: 4:31:55 PM
User: N/A
Computer: TXCS-W1
Description:
While transmitting or receiving data, the server encountered a network error. Occassional errors are expected, but large amounts of these indicate a possible error in your network configuration. The error status code is contained within the returned data (formatted as Words) and may point you towards the problem.

For more information, see Help and Support Center at Data:
0000: 00 00 04 00 01 00 54 00 ......T.
0008: 00 00 00 00 dc 07 00 80 ....Ü..?
0010: 00 00 00 00 10 00 00 c0 .......À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 7a 09 00 00 z...



Event Type: Error
Event Source: DNS
Event Category: None
Event ID: 4015
Date: 7/17/2008
Time: 10:10:07 AM
User: N/A
Computer: TXCS-W1
Description:
The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.

For more information, see Help and Support Center at Data:
0000: 52 00 00 00 R...



Event Type: Error
Event Source: DNS
Event Category: None
Event ID: 4004
Date: 7/17/2008
Time: 10:10:07 AM
User: N/A
Computer: TXCS-W1
Description:
The DNS server was unable to complete directory service enumeration of zone .. This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is "". The event data contains the error.

For more information, see Help and Support Center at Data:
0000: 2a 23 00 00 *#..



Event Type: Error
Event Source: DNS
Event Category: None
Event ID: 4000
Date: 7/17/2008
Time: 10:16:07 AM
User: N/A
Computer: TXCS-W1
Description:
The DNS server was unable to open Active Directory. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.



These are just a few from each... I have checked microsoft and googled items but im not getting a right answer.

Wm. Reynolds
Premise Communications
Texas Public Safety Solutions


- - - - - - - - - - - - -

Network Error:
Hit any user to continue
 
Are you seeing high processor utilization on your DC?

I have had a few issues over the years where appliations will query AD on non-indexed attributes. In one instance, it was an anti-spam app, and another it was a programmer.

Looking back at the errors you have reported, I would tend to agree with Techy. If you have a secondary DC, it will be faster to transfer all the FSMO roles and GC function, then demote and rebuild the problem box.

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
IS DNS functioning OK? I've seen some of those errors occur when you have a domain controller that only specifies itself as the DNS Server. There's a problem I've seen a few times where DNS is not loaded by the time AD tries to load and therefore AD fails as it's highly dependent on DNS. I just saw some of those troubleshooting a replication problem with a remote DC last night and I temporarily fixed it by setting the DNS settings to two other DNS servers and rebooting until I can get the firewall situation straightened out.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top