Question

Server reboots every hour or few minutes

Asked by: MH-Administrator

My Server 2003 is rebooting sometimes at 2 hours or other times every few minutes.
Error:
"The security package NTLM generated an exception.  The exception information is the data."

I get a prompt that "the server is rebooting in 58 seconds". If I "shutdown -a", it prevents the shutdown, but then OWA won't work and I cannot restart IIS. Absolutely no idea what it could be.
I ran Malwarebytes and it only found "hijack.displaysettings" which I've found to be harmless.

I found this: http://support.microsoft.com/kb/838656, but I would of course have to pay MS for the time.

Any thoughts?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-08-26 at 11:25:59ID24684161
Tags

Windows Server 2003

Topic

Windows 2003 Server

Participating Experts
5
Points
500
Comments
65

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. OWA Access and NTLM
    I have recently installed OWA on a Proxy server. I got the OWA working allowing Basic Authentication and Allowing Anonymous Access. Then I tried adding the NTLM support. After struggling with this for some time, I decided to remove the NTLM Authentication; however, it is ...
  2. OWA/IIS Loses Settings on Server Reboot
    Guys, Overview of system: Exchange Server: Windows 2000 Server SP4 Exchange 2000 SP3 IIS Our Outlook Web Access works great most of the time, however every time I need to complete a server reboot (when I say server I mean the server running IIS for OWA) it seems to lose it...
  3. OWA fine after server reboot, 2 hours later doesn't wor…
    I have an NT 4.0 server that i just inherited. It has Exchange 5.5 and OWA on it. Peridoically the OWA times out. If I reboot the server, everything works fine for about 2 to 2.5 hours. After that, OWA times out again untilt he next reboot. Can't stop and start IIS either...
  4. NTLM and IIS
    I have a w2003 box with IIS that is running many websites. I have disable anonymous access to one of the sites and added users to the box. I want the users to always get the NTLM login which will then take them to the login for the web itself. It seems if I clear all cache an...
  5. Server Reboots every Hour for no reason - Unexpected S…
    My setup: Domain of 10 Microsoft servers in a datacentre behind an ISA 2006 Firewall. Servers are a mixture of web servers running iis6 and 2 database servers running SQL 2005. All servers receive latest SUS updates and are protected by F-PROT antivirus as well as a weekly CL...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: ZENOBIAPosted on 2009-08-26 at 11:49:30ID: 25190908

Hm, may can you please check for MSBLAST.EXE worm aka Blaster.A, LoveSan or Msblast.A exploits ?
This will affect workstation and server in that kind what you describes.

You´ll find the removal tool here:

http://www.symantec.com/security_response/writeup.jsp?docid=2003-081119-5051-99

 

by: MH-AdministratorPosted on 2009-08-26 at 14:10:57ID: 25192294

I have Kaspersky on it and it found nothing. Results from the symantec scan; "W32.blaster.worm has not been found on your computer"

 

by: ChiefITPosted on 2009-08-26 at 23:58:55ID: 25195227

What are you using IIS for, WSUS services??

 

by: MH-AdministratorPosted on 2009-08-28 at 08:11:23ID: 25208487

IIS is for OWA
Here is the error that precedes the system reboot:
8/28/2009      8:43:44 AM      Application Error      Error      -100      1000      N/A      MH-MSX      Faulting application lsass.exe, version 5.2.3790.1830, faulting module msv1_0.dll, version 5.2.3790.4530, fault address 0x0000000000016df1.

Googled it and it was largely useless

 

by: MH-AdministratorPosted on 2009-08-28 at 08:13:06ID: 25208504

I removed Kaspersky and stopped RDP-ing to the server and it didn't errantly reboot until this morning. so I can rule out Kaspersky and RDP.

 

by: MH-AdministratorPosted on 2009-08-28 at 09:59:18ID: 25209563

I'm testing a hypothesis, though it's a long shot. I have APC software installed on the server and it would shut it down in case of little battery remaining on the UPS. It runs on Java. I've uninstalled the APC software and Java. It hasn't rebooted yet, but it's only been about an hour.

I hate computers. I'm gonna go be a hobo.

 

by: ChiefITPosted on 2009-08-28 at 18:18:20ID: 25212639

Well, let's break down the error into something more tangible:

LSASS stands for Local Security Authority Subsystem Service> We also know this pertains to IIS  (Internet Information Service).

So, you are having problems with authentication on IIS. Is it the subsystem's routine?? HMM

http://support.microsoft.com/kb/893712

http://support.microsoft.com/kb/838656

 

by: MH-AdministratorPosted on 2009-08-31 at 13:18:40ID: 25226070

I checked kb-893712and neither switch is enabled. kb-838656 may be accurate.
I must say however that my system has not rebooted since I removed java. I've been advised to spend money only as a last resort.

I'll get back in a few days with an update.

 

by: MH-AdministratorPosted on 2009-09-02 at 13:39:07ID: 25245441

Well, the java uninstall didn't fix it. I'm going to follow the advice of kb 838656, and hope it's the cure.

 

by: RohkPosted on 2009-09-05 at 12:01:21ID: 25267336

Having the same problem. Windows Server 2003 Enterprise with SP2, Exchange 2003 Enterprise SP2. Installed KB968389 on 8/25/09 (along with several others), which updated msv1_0.dll (indicated as the faulting module in the event log errors). This fault started occuring last night, 9/4/09.

My question is: can patch KB968389 be removed safely?

 

by: MH-AdministratorPosted on 2009-09-07 at 20:17:42ID: 25278417

@Rohk - Post in a new question. I've actually paid for my account. You cannot hijack this thread.

 

by: MH-AdministratorPosted on 2009-09-07 at 20:35:28ID: 25278460

OK, so I tried to install that patch, but it won't install. I think it is the x86 version and my OS is x64. I'm going to try to re-install SP2. Any other suggestions?

 

by: ChiefITPosted on 2009-09-08 at 01:36:01ID: 25279742

SFC /scannow should varify versions of OS files. I think I would go to the command prompt and type:

SFC /scannow

Have your install disc handy. It may ask for it.

 

by: RohkPosted on 2009-09-08 at 13:22:53ID: 25285802

Okaaaay. Let me put my comment another way: have you installed patch KB968389? If yes, when did you install it? Did your rebooting problem start before, or after (and how long after) you installed that patch? Have you tried uninstalling that patch? What were the results?

The error message in your event log (as posted by you, above) indicates msv1_0.dll is the "faulting module." This DLL is replaced by the recently released patch KB968389, and may be related to the problem you are having.

Good luck.

 

by: MH-AdministratorPosted on 2009-09-08 at 13:33:14ID: 25285873

@Rohk - ahh, ok. Since you put it that way, I have not installed that patch. I will look into it.

I'm still trying to find the OS disk to do a SFC.

Mondays are always so freaking busy and I am the everyman IT here at this company.

 

by: RohkPosted on 2009-09-08 at 13:44:56ID: 25285983

Please double-check to make sure you don't have that patch installed. Look in Add Remove Programs, with "Show Updates" checked.

Just to be clear: my suggestion was that KB968389 might actually be the *cause* of your problem. If you don't have it installed, then my suggestion is wrong.

I know how you feel. :-)  Good luck!

 

by: MH-AdministratorPosted on 2009-09-09 at 07:03:53ID: 25291385

I found and uninstalled kb968389 and rebooted. Original error still occurring.

I ran the SFC scan, but it didn't find anything. The dialog box disappeared without any queries or errors which leads me to believe that everything was nominal.

 

by: ChiefITPosted on 2009-09-12 at 13:23:57ID: 25317766

What service pack are you on??

If on SP1, then install SP2.

The version of LSSAS you are using is SP1. SP1 has many problems that were mostly corrected with SP2.

 

by: MH-AdministratorPosted on 2009-09-14 at 06:17:27ID: 25325034

I'm on SP2

 

by: sullimdPosted on 2009-09-14 at 13:23:16ID: 25328968

Not trying to hijack, but my Exchange server is doing the same thing - Exchange 2007, x64, SP2, started rebooting on 9/4 just like yours.  We have to find an answer to this.

 

by: MH-AdministratorPosted on 2009-09-14 at 13:36:07ID: 25329074

"The version of LSSAS you are using is SP1"

Should I re-run SP2 install?

 

by: ChiefITPosted on 2009-09-14 at 18:56:17ID: 25330888

I think I would.

 

by: MH-AdministratorPosted on 2009-09-15 at 06:19:02ID: 25334530

I've re-installed SP2. Let's see if it reboots autonomously today.

 

by: sullimdPosted on 2009-09-16 at 06:49:59ID: 25345521

I wanted to provide an update of some things I've been investigating with this issue.  Again, not trying to hijack but provide further info for others to troubleshoot.

My server rebooted last night at 2:33am and again this morning at 8:33am.  Both times in the security logs is a failed logon/logoff attempt by a user that was recently terminated from our company.  Her account still exsists in AD but has been disabled now for a couple of weeks.  These security log events happen exactly 1 second before the NTLM exception happens.  The NTLM exception causes lsass.exe to crash which cause the reboot.  The failed logon attempt is coming from 208.54.83.83, which is a Tmobile IP.  She had a Tmobile Android phone that was hooked up to Exchange, that I'm guessing she hasn't removed the Exchange profile from her phone yet, so its still trying to check email.

Im wondering if with the latest Windows update changes to the msv1_0.dll file, various phones trying to use OWA's address is somehow exploiting a bug that causes the NTLM package to fail while trying to authenticate?

That may be a long shot, but could others having this issue check the security logs at the same time at the first error message is generated and see if you have failed logon attempts by a user's phone, a disabled user, etc....

 

by: MH-AdministratorPosted on 2009-09-16 at 06:56:45ID: 25345593

SP2 fix failed. Still rebooting.

I'm going to examine my logs for your findings above. Have you tried removing the user?

 

by: sullimdPosted on 2009-09-16 at 06:58:11ID: 25345607

Not yet.  That would be my next step.

 

by: ChiefITPosted on 2009-09-16 at 07:57:29ID: 25346297

Well, let's prevent the server from rebooting so we can get a blue screen of death>

Right click "my computer" icon>>select "properties">>go to the "advanced" tab>>Under the startup and recovery section, choose the "settings" button. Then, deselect auto sartup upon error.

Once you reboot. It should provide you with a blue screen. Please writed down the 0x... code and application that is problematic.

 

by: sullimdPosted on 2009-09-16 at 08:01:38ID: 25346344

As far as I can tell, the server reboots cleanly.  That is, it does not 'blue screen' and just reboot itself.  The winlogon.exe process actually shuts it down cleanly.

 

by: MH-AdministratorPosted on 2009-09-16 at 08:11:02ID: 25346437

I agree. Every time it reboots, there is a countdown and no BSOD.

 

by: ChiefITPosted on 2009-09-16 at 08:55:47ID: 25347017

The reboot, will make it appear to be a clean reboot if the computer is selected to auto restart upon error.

This is why we might unselect that option to see the BSOD.

 

by: MH-AdministratorPosted on 2009-09-16 at 09:04:22ID: 25347122

I've disabled reboot upon BSOD

 

by: ChiefITPosted on 2009-09-16 at 09:52:55ID: 25347640

Let us know what happens upon the next reboot.

Write down the application and 0x... error code.

 

by: MH-AdministratorPosted on 2009-09-16 at 10:11:25ID: 25347791

Second auto-reboot following the "restart after error". No BSOD. Rebooted just fine tho.

 

by: ChiefITPosted on 2009-09-16 at 12:30:21ID: 25349179

OK, had to revert to research:

EventID.NET:
http://www.eventid.net/display.asp?eventid=5000&eventno=1313&source=LsaSrv&phase=1

"Ray Fernandez (Last update 7/27/2005):
I just installed Windows 2003 Enterprise Server running Exchange 2003 and IIS 6 for OWA, and it was giving me this error. After calling Microsoft, they said the reason for that was the frequent Bot attacks to IIS 6, and pointed me to install MS04-011 and MS04-007. They also suggested MS05-019 if it applied to my system. They said these patches are not been pushed as Windows updates because of some issues and they must be downloaded and installed manually. After installing those patches and rebooting the system, the event disappeared."

This posting was submitted in 2005. So, we should make sure the patches apply to your system.  Links to the patches are at the bottom of the EventID.Net web page.

 

by: sullimdPosted on 2009-09-16 at 12:39:27ID: 25349263

I have seen several articles like this too, dated from 2004-2006.  It seems like these issues should be patched by now though?  Also it doesn't seem like a coincidence that there are three of us who just started having this issue around the same couple of days.  Not discounting the research, just trying to apply normal troubleshooting logic/variables into the mix.

 

by: sullimdPosted on 2009-09-16 at 13:43:57ID: 25349917

Just auto-rebooted again.  Events are time stampted at the same time.  Disabled user tries to logon, NTLM throws an exception:

From the security log:
-----------------------------------

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      531
Date:            9/16/2009
Time:            3:29:19 PM
User:            NT AUTHORITY\SYSTEM
Computer:      DAXBHMEX01
Description:
Logon Failure:
      Reason:            Account currently disabled
      User Name:      lwilliams
      Domain:            DCC001
      Logon Type:      8
      Logon Process:      Advapi  
      Authentication Package:      Negotiate
      Workstation Name:      DAXBHMEX01
      Caller User Name:      DAXBHMEX01$
      Caller Domain:      DCC001
      Caller Logon ID:      (0x0,0x3E7)
      Caller Process ID:      4384
      Transited Services:      -
      Source Network Address:      208.54.83.63
      Source Port:      57618

From the System log:
-----------------------

Event Type:      Error
Event Source:      LsaSrv
Event Category:      Security Package Manager
Event ID:      5000
Date:            9/16/2009
Time:            3:29:19 PM
User:            N/A
Computer:      DAXBHMEX01
Description:
The security package NTLM generated an exception.  The exception information is the data.




 

by: MH-AdministratorPosted on 2009-09-16 at 14:01:10ID: 25350095

I'm on the phone with MS right now. Unlike others, I promise to post the resolution so future users find a corrective action.

 

by: ChiefITPosted on 2009-09-16 at 14:09:23ID: 25350190

A while back, I use to see clients that were trying to authenticate with a Kerberos Authentication server, using LMHash authentication. From that, we saw clients with the inability to logon.

So, we prevented the clients from authenticating using LMhash. Here is the posting:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_2003_Active_Directory/Q_23132123.html

Now, from what I am seeing, you have clients that are trying to authenticate using NTLMhash. I wonder if new updates are not permitting 2003 server to be compatible with NTLMhash authentication through IIS6??

This thread explains how to authenticate using NTLM and kerberos at the same time using IIS6.
http://support.microsoft.com/kb/215383

DANGER: NTLM hash is a very easy hack and clients should not be authenticating in NTLM if at all possible, (especially using a web based api).

I am thinking the same group policy for preventing LMhash would not only secure your network, but might prevent the server from trying to cough up a NTLM authentication. To find out how to prevent LMhash authentication see the Experts Exchange link. If nothing else, this helps secure your network a bit better.

 

by: ChiefITPosted on 2009-09-16 at 14:11:30ID: 25350213

Also perform this on one test machine:

Backup prior to testing.

Playing with LSASS registry keys can cause BSOD's. So be very precise.

The test machine I would try out would be.
DAXBHMEX01

Furthermore, LM and NTLM viruses may try to infultrate your server. I would check that machine out for Malware.

 

by: RohkPosted on 2009-09-18 at 11:40:12ID: 25368685

@sullimd - we had four reboots yesterday, and the first seemed to follow directly after a failed Android phone logon (not a disabled account, however, just a bad password). However, the subsequent reboots did not show any Android logon just prior to the reboot, so unfortunately that doesn't appear to be the cause (at least for us). Also, the subsequent reboots did not appear to directly follow any sort of failed logon. I'm curious to know if this pattern (failed Android logon followed by lsass failure and reboot) is still holding true for you?

@ChiefIT - the auto-reboot after failure of lsass is by design, and is not typically accompanied by a BSOD (replying to one of your earlier messages).

@MH-Administrator - was Microsoft able to help you?

 

by: sullimdPosted on 2009-09-18 at 11:48:58ID: 25368771

My pattern was holding true every time.  Failed login from this one users phone - then the next log at the same timestamp to the second (as seen above) was the NTLM package throwing the exception.  

I ended up blocking 208.54.0.0/16 yesterday at my firewall to prevent any Tmobile phone from accessing OWA.  I also emailed the user at a personal email address HR had on file to tell her to delete her Exchange account.  Haven't heard back from her, but all day yesterday while her phone was blocked we did NOT have a reboot.  No reboots today either.  

The fact that both of us had failed Android logins is too much of a coincidence to be ignored.  Not that the Android is the problem, but in some way it seems like its exploiting some type of Windows bug that may be undiscovered at this point.

I'm interested to see what MS said too.

 

by: RohkPosted on 2009-09-18 at 12:10:02ID: 25368975

@sullimd - we just had another reboot, directly preceded by a failed Android phone logon (same user as yesterday). I'm going to go back for a closer look at the logs from the other three reboots yesterday...

 

by: sullimdPosted on 2009-09-18 at 12:26:24ID: 25369153

You can try to block the IP range on the failed security log attempt, but just know that it will block all phones on Tmobile from accessing Exchange.  It is somewhat of a drastic move depending on how many phones rely on email, but it can help in troubleshooting to see if thats the issue.

 

by: MH-AdministratorPosted on 2009-09-18 at 12:30:48ID: 25369200

I've examined my logs and there is no correlation between user logins and server reboots. Of four reboots, various users successfully authenticated seconds before lsass crashed. Some of these users don't have smartphones. I have very few failed authentications.

I'm on my third escalation with MS support. So far, they've had me try to install KB868356 (http://support.microsoft.com/kb/838656). It wouldn't install on my machine, but I thought I'd add it JIC it resolves your issue.

 

by: MH-AdministratorPosted on 2009-09-18 at 12:32:25ID: 25369215

I transposed the KB. It's KB 838656; http://support.microsoft.com/kb/838656

 

by: sullimdPosted on 2009-09-18 at 12:35:10ID: 25369245

I saw that fix several days ago, but the fix is for x64 SP1 and I'm running SP2.  It would not install for me.

 

by: ChiefITPosted on 2009-09-18 at 12:43:46ID: 25369327

This phone and these remote stations that are authenticating through NTLMhash might be upgraded to a kerberos authentication scheme.

Phones, these days, are mini handheld computers with their own OS. So, I am thinking the OS version of the phone can be upgraded to support Kerberos and get off the NTLM authentication you are seeing.

Microsoft updates to service pack 2, disables the server's ability to be backwards compatible with LMhash Authentication as a security update. This may render clients unable to authenticate with the server because the client is on the WRONG authentication protocol. This is why things might work for a while, then a few computers fail to logon after a windows update. By default, MS computers, including the server are suppose to use kerberos. But NTLM was used to be backwards compatible with Legacy machines. This is why most of your articles pertaining to NTLM authentication are dated way back.

I did find an article that effects the servers running EXCHANGE and SHAREPOINT. It disables kerberose on the Exhcange server. This effects the front and backend servers. The inability to negotiate Kerberos from the clients, I COULD see causing the server to reboot repetetively.

Guys:

Tell me what you are looking at:

Are these a couple clients that are trying to authenticate via NTLM?

Or is the Server stuck trying to provide authentication via NTLM over IIS6?

If it is the clients, we may need to get in touch with these clients phones and machines to make sure they authenticate via Kerberos. For a phone, that may require a OS update.


If this is the server, It looks like there are things to check that pertain to the way OWA clients interact with your authentication over IIS.

http://www.microsoft.com/exchange/2007/support/e2k3owa.mspx

 

by: sullimdPosted on 2009-09-18 at 13:15:38ID: 25369599

Here are the two logs that happens before/at the time of the crash.

DAXBHMEX01 is my Exchange server - I do not have a front/back.  All services are on the same box.  WINDROID is the Google Android phone.  208.54.x.x is Tmobile's IP range.  Looks like the phone is trying NTLM.

---------

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      537
Date:            9/16/2009
Time:            7:29:16 AM
User:            NT AUTHORITY\SYSTEM
Computer:      DAXBHMEX01
Description:
Logon Failure:
       Reason:            An error occurred during logon
       User Name:      LWILLIAMS
       Domain:            DCC001
       Logon Type:      3
       Logon Process:      NtLmSsp
       Authentication Package:      NTLM
       Workstation Name:      WINDROID
       Status code:      0xC0000225
       Substatus code:      0x0
       Caller User Name:      -
       Caller Domain:      -
       Caller Logon ID:      -
       Caller Process ID:      -
       Transited Services:      -
       Source Network Address:      208.54.83.79
       Source Port:      6908
---------

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      531
Date:            9/16/2009
Time:            7:29:15 AM
User:            NT AUTHORITY\SYSTEM
Computer:      DAXBHMEX01
Description:
Logon Failure:
       Reason:            Account currently disabled
       User Name:      lwilliams
       Domain:            DCC001
       Logon Type:      8
       Logon Process:      Advapi  
       Authentication Package:      Negotiate
       Workstation Name:      DAXBHMEX01
       Caller User Name:      DAXBHMEX01$
       Caller Domain:      DCC001
       Caller Logon ID:      (0x0,0x3E7)
       Caller Process ID:      4056
       Transited Services:      -
       Source Network Address:      208.54.83.63
       Source Port:      33957


 

by: RohkPosted on 2009-09-18 at 13:19:54ID: 25369640

@MH-Administrator: please report the version of msv1_0.dll in your \Windows\System32 directory (right-click, properties, version tab). I'd like to confirm that the uninstall of KB968389 successfully backed out that DLL. Thanks.

 

by: MH-AdministratorPosted on 2009-09-18 at 14:34:55ID: 25370177

I found 968389 installed again. I thought I removed it but I guess I was wrong. It's gone now and the ver is 5.2.3790.3959.

No errors yet. We'll see whats what.

 

by: MH-AdministratorPosted on 2009-09-18 at 14:37:17ID: 25370197

I went into WSUS and declined the update. Would that be enough to keep it from installing?

 

by: sullimdPosted on 2009-09-18 at 14:41:25ID: 25370231

Should be.  If you have any GPO's controlling it make sure those apply to the server in question.

 

by: RohkPosted on 2009-09-18 at 15:20:43ID: 25370468

Ah, okay. So I think my original suspicion may be correct then. I have uninstalled the bundle of patches that I installed on 8/25, one at a time. I built a dependency matrix and uninstalled them in the following order:

KB956744
KB973540
KB971032 (reboot)
KB960859
KB971557
KB973869
KB973507 (reboot)
KB973354
KB968389 (reboot)

You should build your own matrix if there is any question of what order your own installed patches should be uninstalled in.

I'll reinstall all of these patches except KB968389 and we'll see what happens. My reboots have not been daily, so I'll report back in a week if there are no reboots (or sooner if there are).

 

by: RohkPosted on 2009-09-18 at 16:49:05ID: 25370816

Update: I asked my Android user to try connecting again with a bad password. Logon errors logged, but no reboot. So far, so good...

 

by: MH-AdministratorPosted on 2009-09-21 at 09:18:44ID: 25384534

Still no reboot yet. Mine were at eight a day or none for several days. I'll check back in a few days to see if everything remains stable.

 

by: ChiefITPosted on 2009-09-21 at 11:33:32ID: 25385974

Howdy All::

Looks like we have a fourth person with this LSASS problem. Anyone willing to make sure this person is having the same problem and work with him on fixing it????

John

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q__24748877.html

 

by: RohkPosted on 2009-09-25 at 10:44:18ID: 25425291

I've gone a week without a reboot, so I think we solved this.

 

by: keith_alabasterPosted on 2009-09-25 at 10:59:06ID: 25425462

Lets stop here please. Whilst sharing information, symptoms, resolution attempts across a number of systems/outfits is great, it also makes troubleshooting and diagnosis a nightmare by changing too many parameters within the question set.

MH - You stated you had been on the phone to Microsoft - are you in a position to advise on Microsoft's advice regarding the issue you have given to them?

In your initial post you stated 'my server' - is this the only server you have in your workgroup or domain? Do you have any others? Are they also experiencing the same issue?
What services is this server running? Is it just file and print? Other? DC?
What role is the server playing within your company/organisation?
What applications are installed? SQL? MSDE? Anything?

Thanks
Keith


 

by: keith_alabasterPosted on 2009-09-25 at 10:59:33ID: 25425464

Lets stop here please. Whilst sharing information, symptoms, resolution attempts across a number of systems/outfits is great, it also makes troubleshooting and diagnosis a nightmare by changing too many parameters within the question set.

MH - You stated you had been on the phone to Microsoft - are you in a position to advise on Microsoft's advice regarding the issue you have given to them?

In your initial post you stated 'my server' - is this the only server you have in your workgroup or domain? Do you have any others? Are they also experiencing the same issue?
What services is this server running? Is it just file and print? Other? DC?
What role is the server playing within your company/organisation?
What applications are installed? SQL? MSDE? Anything?

Thanks
Keith


 

by: RohkPosted on 2009-09-25 at 22:26:28ID: 25428847

@keith: If you're a Microsoft engineer, you have the problem you describe: what exactly is the trigger, what exact configurations are affected, etc. For our purposes, however, we've found the culprit: Microsoft released a patch which is causing our various systems to "spontaneously" (from our point of view) reboot. There have been at least three other threads on this issue started in the past couple of weeks just on Experts Exchange alone... and who knows how many on other message boards.

Let's look at the commonalities (all of which have already been spelled out upthread): Microsoft Windows Server 2003, running various versions of Exchange (2003 and 2007) with OWA enabled. We all installed patch KB968389 shortly before the reboots started. The error messages in the logs point to a DLL which was updated by that patch (msv1_0.dll). When we uninstalled that patch, the reboots went away. As far as I'm concerned, we're done.

Now, if you're Microsoft, you've got a headache to deal with, but that's not our responsibility - it's theirs. I'm looking forward to an updated patch that doesn't cause my Exchange server to reboot, and I won't reinstall KB968389 on that server until they've proven it will be stable.

 

by: keith_alabasterPosted on 2009-09-26 at 01:36:12ID: 25429217

Rohk - I am no longer Microsoft.

MH-Administrator, in addition to my questions above, can you confirm that since the removal of the patch on the 18th, you have still not had any issues?

I am not aware of any 'replacement' patch being issued currently but the issue is documented on a number of forums with PSS recommending the removal if this form of issue is seen, as mentioned by previous commentors. Here is just one of them.

http://messagexchange.blogspot.com/2009/09/kb968389-lsass-reboots.html

 

by: RohkPosted on 2009-09-26 at 07:31:24ID: 25429917

@ keith: I wasn't trying to say that you were with Microsoft. I was simply suggesting that Microsoft has more work to do on this issue. Also, thanks for confirming my solution.

 

by: MH-AdministratorPosted on 2009-09-30 at 06:28:09ID: 25458574

Sorry, been on vacation.

------------------------------------
Answers @ keith_alabaster:
In your initial post you stated 'my server' - is this the only server you have in your workgroup or domain?
-This is the only Exchange server

Do you have any others? Are they also experiencing the same issue?
-I have five other servers. They do not have this issue

What services is this server running? Is it just file and print? Other? DC?
Email and OWA only

What role is the server playing within your company/organisation?
-Exchange 2007

What applications are installed? SQL? MSDE? Anything?
-Only Exchange 2007 - nothing else

Also, while speaking with MS support, they advised to remove the 968389 patch. I did so on 18SEPT09 and have had no reboots since. This is now resolved.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...