Solved

Svchost Error Popups

Posted on 2007-04-04
13
3,623 Views
Last Modified: 2008-01-09
Application popup: svchost.exe - Application Error : The exception unknown software exception (0xc0000409) occurred in the application at location 0x5b86a3c0.

I have been struggling for days trying to find the root cause of these popups occuring on my Windows XP Professional server's system console.  I will pay 1000 points to anyone who advises on how to identify the offending source.

Through Windows Task Manager, Services and Event Viewer,  I have about 10 different DLLs that launch under svchost and I can;t trace them individually.
0
Comment
Question by:dettore
  • 7
  • 3
  • 2
13 Comments
 
LVL 22

Expert Comment

by:orangutang
ID: 18855578
I think it's either related to Windows Update or some DLL. I'm not really sure how to find out but try:
Download Process Explorer (http://download.sysinternals.com/Files/ProcessExplorer.zip). When svchost.exe crashes, open Process Explorer, double-click every "svchost.exe" item you see, click the "Threads" tab, and tell us all of the DLLs mentioned in the list.
0
 

Author Comment

by:dettore
ID: 18855817
Here are the svchost dumps via ProcessExplorer

First svchost group
DcomLaunch      rpcss.dll
TermService      termsrv.dll

Second svchost group
Dnscache      dnsrslvr.dll  I suspect this may be the trouble
When I get the popup on ythe system console and click OK or Cancel, people say they get lose access to the shared file volume they are accessing on this server.

Third svchost group
LmHosts            lmhsvc.dll
Remote Registry      regsvc.dll
SSDPSRV            ssdpsrv.dll
WebClient            webclnt.dll

Fourth svchost group
Stisvc            wiaservc.dll

Fifth svchost group
EventSystem                           es.dll
Helpsvc            pchsvc.dll  in PCHealth\HelpCtr\Binaries
Lanmanserver      srvsvc.dll
Nla            mswsock.dll
RasMan            rasmans.dll
Schedule            schedsvc.dll
SENS            sens.dll
TapiSrv            tapisrv.dll
Winmgnt            WMIsvc.dll
0
 

Author Comment

by:dettore
ID: 18855881
I also see in the Event Viewer that the Event ID 26 is sending info to Microsoft that states Filename is ntdll.dll.  Does this focus in on the problem DLL?
0
 
LVL 22

Accepted Solution

by:
orangutang earned 250 total points
ID: 18855916
Actually, I don't think using Process Explorer will help in this situation. Anyway, look here:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/Q_22027680.html
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 18855927
Can you show us a hijackthis log please? log might show something.

http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

You can either upload the log to any hosting sites,
or go to the below link and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.

OR: paste to this site::
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:

0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 18856012
Yes, I've seen some cases where svchost error was caused by windows auto-update software.
Try turning off auto-updates and reboot, you can then do manual updates and again turn back on auto-updates.

http://www.experts-exchange.com/Virus_and_Spyware/Anti-Virus/Desktop_Anti-Virus/Q_22457701.html
0
 

Author Comment

by:dettore
ID: 18856052
Logfile of HijackThis v1.99.1
Scan saved at 11:55:12 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\srv\scan\dream\radmin.exe
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\LocalServer.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\sokkit\Apache2\bin\apache.exe
C:\sokkit\Apache2\bin\apache.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\ctfmon.exe
c:\sokkit\mysql\bin\mysqld.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\logonui.exe
C:\Program Files\2BrightSparks\SyncBackSE\SyncBackSE.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AcroTray.exe
C:\Program Files\Quick 'n Easy FTP Service\ftpservice.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\PC Doctor Toolbox\A.  PC Doctor Tool Bin\Spyware Tools\HijackThis.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINDOWS\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Protected and restricted by PC Doctor for SES Inc. Last Exam 2/28/07
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - Startup: SyncBackSE.lnk = C:\Program Files\2BrightSparks\SyncBackSE\SyncBackSE.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
O16 - DPF: {156BF4B7-AE3A-4365-BD88-95A75AF8F09D} -
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} -
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4980/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
O17 - HKLM\System\CS1\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
O17 - HKLM\System\CS2\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
O18 - Protocol: offline-8876480 - {1A1AFFFE-9017-428E-A89C-852DBE045AAF} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Quick 'n Easy FTP Service - Pablo Software Solutions - C:\Program Files\Quick 'n Easy FTP Service\ftpservice.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\srv\scan\dream\radmin.exe" /service (file missing)
O23 - Service: AlertManagrServer (Serv-U) - Cat Soft - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\LocalServer.exe
O23 - Service: Sokkit - Unknown owner - C:\sokkit\Apache2\bin\apache.exe" -k runservice (file missing)

0
 

Author Comment

by:dettore
ID: 18856073
The Windows Automatic Update is already disabled so I can rule this out as the cause of continuous (average 15-20 per day) Application Popups
0
 

Author Comment

by:dettore
ID: 18888162
I have tried further isolation and have this info.  Perhaps this leads to netapi32 problems.

When I get a popup error, the title is "Generic Host Process for Win32 Services" and the error signature is Event Type: BEX P1: svchost.exe P2: 5.1.2600.2180 P3: 41107ed6 P4: netapi32.dll P5: 5.1.2600.2180 P6: 411096ac P7: 0000a3c0 P8: c0000409 P9: 00000000
0
 

Author Comment

by:dettore
ID: 18888175
Here is my latest hijack log.  Note the system has been reduced significantly.

Logfile of HijackThis v1.97.7
Scan saved at 1:55:48 AM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Quick 'n Easy FTP Service\ftpservice.exe
C:\WINDOWS\srv\scan\dream\radmin.exe
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\LocalServer.exe
C:\sokkit\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\dell printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\sokkit\Apache2\bin\apache.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
c:\sokkit\mysql\bin\mysqld.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\CleanCenter\CleanCenter.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\PC Doctor Toolbox\A.  PC Doctor Tool Bin\Spyware Tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = "http://runonce.msn.com/?v
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Protected and restricted by PC Doctor for SES Inc. Last Exam 4/7/07
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
O17 - HKLM\System\CS1\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
O17 - HKLM\System\CS2\Services\Tcpip\..\{8C56F7FB-925F-4505-AB17-0C1F8928C357}: NameServer = 216.74.11.130,68.4.16.30,65.107.43.210
0
 
LVL 47

Assisted Solution

by:rpggamergirl
rpggamergirl earned 250 total points
ID: 18888586
The second log is of older version, that could be why there's not many entries showing.

You can fix these entries in Hijackthis, but first you need to turn off Tea Timer and any other registry monitoring programs you have because they interfer when Hijackthis fixes entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Also fix these if you didn't set these restrictions yourself.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone  
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone  
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone  
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone  
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {156BF4B7-AE3A-4365-BD88-95A75AF8F09D} -  
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} -  
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -  
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -  
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} -  
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -  
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\srv\scan\dream\radmin.exe" /service (file missing)

Do you have a Remote Access Service?
C:\WINDOWS\srv <-- do you know what this folder is? looks suspicious to me. If you don't know this folder, then have it check with jotti online scan  --> http://virusscan.jotti.org/


Also try running this scanner:
http://www.superantispyware.com/
0
 

Author Comment

by:dettore
ID: 18912578
I have narrowed down that if I disable the Server process, the popups stop.  But I also lose some functionality, notice that when I go into examine Sahred Folder, Open Sessions, Open Files, they all display unable to because the Serve is not running.  I am remote from the office so I do not know if local users will lose network server access until I test on Monday.  So here;s your question:

Service Name: lanmanserver
C:\WINDOWS\system32\svchost.exe -k netsvcs
Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

What causes this Server service to fail like this?

How can I identify what files this requires and possibly copy from another server?  How to reinstall this service

0

Join & Write a Comment

When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now