Jump to content
Compatible Support Forums
Sign in to follow this  
overworked

Event 49 Ftdisk error configuring page file for crash dump

Recommended Posts

The Evil Empire doesn't like me!

 

Recently, I have completed slipstreaming SP4 and all the SP5 hotfixes into a W2K distribution. In testing this it has become apparent that something isn't quite right. I get an event 49 ftdisk error configuring the page file for crash dump on all the test machines.

 

Searching the docs for this error leads to 2 situations/solutions which do not apply.

1) This error can occur when you increase the RAM in a machine without increasing the page file accordingly. Then if the machine crashes, the page file is too small for the memory dump.

2) An error that was supposedly fixed with SP4 and included version 5.0.2195.5505 of Ntkrnlmp.exe, Ntkrnlpa.exe, Ntkrpamp.exe and Ntoskrnl.exe. I'm at version 5.0.2195.6902.

 

I have compared the version and MD5 of ftdisk.sys being deployed and running on machines that don't exhibit this error. They are the same. I have examined the registry of well behaved machines vs. those of the test machines. I'm at a complete loss. Aside from pulling out the SysInternals tools and looking at what files are involved prior to the error being generated, I just don't know what else to do. If anyone has encountered this problem and has a solution I sure would like to hear about it. Wading through Filemon and Regmon logs just isn't my forte.

 

Regards,

-Overworked-

 

Share this post


Link to post

Well, I tried to delete the pagefile.sys by going into performance options and selecting a file size of 0 bytes. This appeared to remove the pagefile. Then when I rebooted W2K created a new small page file for me. The same error persists. I've compared the registry settings for ftdisk.sys on well behaved systems and errant systems from the new deployment. I am fairly certain MS has created a file mismatch for me with KB835732 (MS04-011).

 

25-Feb-2004 23:55 5.0.2195.6902 1,699,904 Ntkrnlmp.exe

25-Feb-2004 23:55 5.0.2195.6902 1,699,264 Ntkrnlpa.exe

25-Feb-2004 23:55 5.0.2195.6902 1,720,064 Ntkrpamp.exe

11-Mar-2004 02:37 5.0.2195.6902 1,726,032 Ntoskrnl.exe

 

These are the files that I think may be related to the problem. I found a MS bulletin that said these files were replaced in SP4 to cure the same error....although the file versions were earlier. To avoid finding old files delivered in my deployment, I usually have to take apart the cab files, update them and put them back together in the deployment. Thus, these files would not only be included in the I386 directory but also the SP4 cab file. I have seen older versions of files pulled out of cabs too many times (even with the appropriate security cats in place). Also, I noticed that ftdisk.sys was not replaced in the KB835732 patch. I guess my next step will be to put together a deployment excluding this patch and apply the patch at the end of the deployment as you would with a previously installed OS. If the test system without this patch does not have the error and by applying this patch the error shows up, we'll know that this patch is responsible. Also, I'll take a snapshot of the registry before and after, in the event that the error doesn't appear, I'll look for differences in the registry that may cause the problem.....If I had to do his for all the MS patches, I'd QUIT!

 

I'll let you know what I find....although it may be a few days (this is my part-time job).

 

-overworked-

 

Share this post


Link to post

Well, here we go again....

 

I tried deploying W2K SP4 as a slipstreamed deployment (this has worked fine before) and patching the OS using the MS Qchain utility. The results are the same as if I had slipstreamed all the hotfixes in the initial deployment....

 

****************************************************************

Event Type: Error

 

Event Source: Ftdisk

 

Event Category: None

 

Event ID: 49

 

Date: 9/9/2004

 

Time: 1:47:44 PM

 

User: N/A

 

Computer: COMPUTER

 

Description:

 

Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.

 

Data:

 

0000: 00 00 00 00 01 00 56 00 ......V.

 

0008: 00 00 00 00 31 00 04 c0 ....1..À

 

0010: 03 00 00 00 00 00 00 00 ........

 

0018: 00 00 00 00 00 00 00 00 ........

 

0020: 00 00 00 00 00 00 00 00 ........

*************************************************************

 

I have searched your online documentation. The page file is of sufficient size for the physical memory in the computer. KB319931 indicates this error was fixed in SP4 with the following files:

 

 

 

01-Apr-2002 16:07 5.0.2195.5505 1,687,296 Ntkrnlmp.exe

01-Apr-2002 16:08 5.0.2195.5505 1,686,912 Ntkrnlpa.exe

01-Apr-2002 16:08 5.0.2195.5505 1,707,584 Ntkrpamp.exe

01-Apr-2002 16:07 5.0.2195.5505 1,665,024 Ntoskrnl.exe

 

These files were replaced with a more recent version by hotfix KB835732.

 

This is the log of the hotfix installation:

 

***************************************************************

[KB835732.log]

***

 

2004/9/9 13:49:23.927

***

 

Exe = UPDATE.EXE, Version = 5.4.1.0

***

 

================== Update.exe started at 9/ 9/2004 at 13:49:23 ==================

***

 

Service Pack started with following command line: /passive /norestart /n

***

 

---- Old Information In The Registry ------

***

 

 

Source:c:\973ee628f2a8b52ee64f511636837ff2

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\6d3a162f9b5a04bb99f97b5f4ffd

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\3928fe31ffe634249bea

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\ac4165566af797da3366d09025

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\1a635ad07e9efaa80f119c

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000002_.tmp

Version: 5.0.2195.6656

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000003_.tmp

Version: 5.0.2195.6692

***

 

 

Destination:

Version:

***

 

 

Source:c:\bebde20982628e4db4c5e4eb290b6b

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\b04ac7d7846fea53a9

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\94ee866ab40915189e08c2c4a5

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\186a5f5ec8762f89ee

Version:

***

 

 

Destination:

Version:

***

 

 

 

 

---- New Information In The Registry ------

***

 

 

Source:c:\973ee628f2a8b52ee64f511636837ff2

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\6d3a162f9b5a04bb99f97b5f4ffd

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\3928fe31ffe634249bea

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\ac4165566af797da3366d09025

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\1a635ad07e9efaa80f119c

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000002_.tmp

Version: 5.0.2195.6656

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000003_.tmp

Version: 5.0.2195.6692

***

 

 

Destination:

Version:

***

 

 

Source:c:\bebde20982628e4db4c5e4eb290b6b

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\b04ac7d7846fea53a9

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\94ee866ab40915189e08c2c4a5

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\186a5f5ec8762f89ee

Version:

***

 

 

Destination:

Version:

***

 

SetAltOsLoaderPath: No section uses DirId 65701; done.

***

 

IncludeDirectoryIdFromInfSection: No DirId found for: DontRemoveOnUninst.DirId

***

 

FetchSourceURL: SetupOpenInfFile Failed to open file: c:\a65364d63c17a6149a16eea49204ef\update\update.url

***

 

DoInstallation: FetchSourceURL for c:\a65364d63c17a6149a16eea49204ef\update\update.inf Failed

***

 

CreateUninstall = 0,Directory = C:\WINNT\$NtUninstallKB835732$

***

 

LoadFileQueues: SetupGetSourceFileLocation for halacpi.dll failed: 0xe0000102

***

 

BuildCabinetManifest:SetupOpenInfFile failed with error INVALID_HANDLE_VALUE

***

 

AnalyzePhaseZero used 0 ticks

 

***

 

AnalyzePhaseOne: used 10775 ticks

 

***

 

AnalyzeComponents: Hotpatch analysis disabled; skipping.

***

 

AnalyzeComponents: Hotpatching is disabled.

***

 

AnalyzePhaseTwo used 10 ticks

 

***

 

AnalyzePhaseThree used 0 ticks

 

***

 

AnalyzePhaseFive used 0 ticks

 

***

 

AnalyzePhaseSix used 0 ticks

 

***

 

AnalyzeComponents used 10785 ticks

 

***

 

 

Downloading 0 files

 

 

***

 

bPatchMode = FALSE

 

***

 

Inventory complete: ReturnStatus=0, 10855 ticks

 

***

 

Num Ticks for invent : 10865

 

***

 

Allocation size of drive C: is 4096 bytes, free space = 12403466240 bytes

 

***

 

Drive C: free 11828MB req: 57MB w/uninstall 0MB

 

***

 

Num Ticks for download : 0

 

***

 

CabinetBuild complete

 

***

 

Num Ticks for Cabinet build : 0

 

***

 

Starting process: C:\WINNT\system32\secedit.exe /configure /cfg C:\WINNT\inf\hfsecper.inf /db C:\WINNT\security\templates\hfsecper.sdb /log C:\WINNT\security\logs\hfsecper.log

***

 

Return Code = 1

***

 

Registering Uninstall Program for -> KB835732, KB835732 , 0x0

***

 

LoadFileQueues: SetupGetSourceFileLocation for halacpi.dll failed: 0xe0000102

***

 

Copied file: C:\WINNT\system32\spmsg.dll

***

 

SfcTurnOff: System is not Win2k < SP2; Not turning off SFC.

***

 

SfcTurnOff: SFC was not turned off; using MakeSfcFileException.

***

 

AtomicReplaceFile: Calling HpReplaceSystemModule( C:\WINNT\system32\ADVAPI32.DLL, HFXC6.tmp, _1762269569_.tmp, FALSE ).

***

 

AtomicReplaceFile: HpReplaceSystemModule failed; status=0xc0000003, location=684.

***

 

DoNoDelayReplace: Atomic replace support not implemented; disabling.

***

 

Copied file: C:\WINNT\system32\ADVAPI32.DLL

***

 

Copied file: C:\WINNT\system32\LSASS.EXE

***

 

Copied file: C:\WINNT\system32\msasn1.dll

***

 

Copied file: C:\WINNT\system32\MSV1_0.DLL

***

 

Copied file: C:\WINNT\system32\samlib.dll

***

 

Copied file: C:\WINNT\system32\SAMSRV.DLL

***

 

Copied file: C:\WINNT\system32\DRIVERS\ksecdd.sys

***

 

Copied file: C:\WINNT\system32\DRIVERS\mountmgr.sys

***

 

Copied file: C:\WINNT\system32\KERNEL32.DLL

***

 

Copied file: C:\WINNT\system32\NTDLL.DLL

***

 

Copied file: C:\WINNT\system32\NTKRNLPA.EXE

***

 

Copied file: C:\WINNT\system32\NTOSKRNL.EXE

***

 

Copied file: C:\WINNT\system32\WIN32K.SYS

***

 

Copied file: C:\WINNT\system32\WINSRV.DLL

***

 

Copied file: C:\WINNT\system32\LSASRV.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETD4.tmp

***

 

Copied file: C:\WINNT\system32\SCHANNEL.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETD5.tmp

***

 

Copied file: C:\WINNT\system32\DllCache\LSASRV.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\SCHANNEL.DLL

***

 

Copied file: C:\WINNT\system32\BASESRV.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETD8.tmp

***

 

Copied file: C:\WINNT\system32\browser.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETD9.tmp

***

 

Copied file: C:\WINNT\system32\CMD.EXE

***

 

Copied file (delayed): C:\WINNT\system32\SETDA.tmp

***

 

Copied file: C:\WINNT\system32\CRYPT32.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETDB.tmp

***

 

Copied file: C:\WINNT\system32\CRYPTNET.DLL

***

 

Copied file: C:\WINNT\system32\cryptsvc.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETDD.tmp

***

 

Copied file: C:\WINNT\system32\dnsapi.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETDE.tmp

***

 

Copied file: C:\WINNT\system32\dnsrslvr.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETDF.tmp

***

 

Copied file: C:\WINNT\system32\EVENTLOG.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETE0.tmp

***

 

Copied file: C:\WINNT\system32\GDI32.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETE1.tmp

***

 

Copied file: C:\WINNT\system32\h323.tsp

***

 

Copied file: C:\WINNT\system32\ipnathlp.dll

***

 

Copied file: C:\WINNT\system32\kerberos.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETE4.tmp

***

 

Copied file: C:\WINNT\system32\mf3216.dll

***

 

Copied file: C:\WINNT\system32\mpr.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETE6.tmp

***

 

Copied file: C:\WINNT\system32\MSGINA.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETE7.tmp

***

 

Copied file: C:\WINNT\system32\NETAPI32.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETE8.tmp

***

 

Copied file: C:\WINNT\system32\NETLOGON.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETE9.tmp

***

 

Copied file: C:\WINNT\system32\ntdsa.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETEA.tmp

***

 

Copied file: C:\WINNT\system32\PSBASE.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETEB.tmp

***

 

Copied file: C:\WINNT\system32\scecli.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETEC.tmp

***

 

Copied file: C:\WINNT\system32\scesrv.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETED.tmp

***

 

Copied file: C:\WINNT\system32\sfcfiles.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETEE.tmp

***

 

Copied file: C:\WINNT\system32\umandlg.dll

***

 

Copied file: C:\WINNT\system32\USER32.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETF0.tmp

***

 

Copied file: C:\WINNT\system32\USERENV.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETF1.tmp

***

 

Copied file: C:\WINNT\system32\w32time.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETF2.tmp

***

 

Copied file: C:\WINNT\system32\w32tm.exe

***

 

Copied file (delayed): C:\WINNT\system32\SETF3.tmp

***

 

Copied file: C:\WINNT\system32\WINLOGON.EXE

***

 

Copied file (delayed): C:\WINNT\system32\SETF4.tmp

***

 

Copied file: C:\WINNT\system32\WINTRUST.DLL

***

 

Copied file (delayed): C:\WINNT\system32\SETF5.tmp

***

 

Copied file: C:\Program Files\NetMeeting\callcont.dll

***

 

Copied file: C:\Program Files\NetMeeting\mst120.dll

***

 

Copied file: C:\Program Files\NetMeeting\nmcom.dll

***

 

Copied file: C:\WINNT\system32\sp3res.dll

***

 

Copied file: C:\WINNT\system32\winhttp.dll

***

 

Copied file (delayed): C:\WINNT\system32\SETFA.tmp

***

 

Copied file: C:\WINNT\INF\hfsecper.inf

***

 

Copied file: C:\WINNT\INF\hfsecupd.inf

***

 

Copied file: C:\WINNT\Driver Cache\i386\kernel32.dll

***

 

Copied file: C:\WINNT\Driver Cache\i386\ntdll.dll

***

 

Copied file: C:\WINNT\Driver Cache\i386\ntkrnlmp.exe

***

 

Copied file: C:\WINNT\Driver Cache\i386\ntkrnlpa.exe

***

 

Copied file: C:\WINNT\Driver Cache\i386\ntkrpamp.exe

***

 

Copied file: C:\WINNT\Driver Cache\i386\ntoskrnl.exe

***

 

Copied file: C:\WINNT\Driver Cache\i386\win32k.sys

***

 

Copied file: C:\WINNT\Driver Cache\i386\winsrv.dll

***

 

Copied file: C:\WINNT\system32\DllCache\sp3res.dll

***

 

Copied file: C:\WINNT\system32\DllCache\winhttp.dll

***

 

Copied file: C:\WINNT\system32\DllCache\advapi32.dll

***

 

Copied file: C:\WINNT\system32\DllCache\BASESRV.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\browser.dll

***

 

Copied file: C:\WINNT\system32\DllCache\callcont.dll

***

 

Copied file: C:\WINNT\system32\DllCache\CMD.EXE

***

 

Copied file: C:\WINNT\system32\DllCache\CRYPT32.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\cryptnet.dll

***

 

Copied file: C:\WINNT\system32\DllCache\cryptsvc.dll

***

 

Copied file: C:\WINNT\system32\DllCache\dnsapi.dll

***

 

Copied file: C:\WINNT\system32\DllCache\dnsrslvr.dll

***

 

Copied file: C:\WINNT\system32\DllCache\EVENTLOG.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\GDI32.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\h323.tsp

***

 

Copied file: C:\WINNT\system32\DllCache\ipnathlp.dll

***

 

Copied file: C:\WINNT\system32\DllCache\kdcsvc.dll

***

 

Copied file: C:\WINNT\system32\DllCache\kerberos.dll

***

 

Copied file: C:\WINNT\system32\DllCache\kernel32.dll

***

 

Copied file: C:\WINNT\system32\DllCache\ksecdd.sys

***

 

Copied file: C:\WINNT\system32\DllCache\lsass.exe

***

 

Copied file: C:\WINNT\system32\DllCache\mf3216.dll

***

 

Copied file: C:\WINNT\system32\DllCache\mountmgr.sys

***

 

Copied file: C:\WINNT\system32\DllCache\mpr.dll

***

 

Copied file: C:\WINNT\system32\DllCache\msasn1.dll

***

 

Copied file: C:\WINNT\system32\DllCache\MSGINA.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\mst120.dll

***

 

Copied file: C:\WINNT\system32\DllCache\msv1_0.dll

***

 

Copied file: C:\WINNT\system32\DllCache\NETAPI32.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\NETLOGON.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\nmcom.dll

***

 

Copied file: C:\WINNT\system32\DllCache\ntdll.dll

***

 

Copied file: C:\WINNT\system32\DllCache\ntdsa.dll

***

 

Copied file: C:\WINNT\system32\DllCache\NTKRNLMP.EXE

***

 

Copied file: C:\WINNT\system32\DllCache\ntkrnlmp.exe

***

 

Copied file: C:\WINNT\system32\DllCache\ntkrnlpa.exe

***

 

Copied file: C:\WINNT\system32\DllCache\NTKRPAMP.EXE

***

 

Copied file: C:\WINNT\system32\DllCache\ntkrpamp.exe

***

 

Copied file: C:\WINNT\system32\DllCache\ntoskrnl.exe

***

 

Copied file: C:\WINNT\system32\DllCache\PSBASE.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\samlib.dll

***

 

Copied file: C:\WINNT\system32\DllCache\samsrv.dll

***

 

Copied file: C:\WINNT\system32\DllCache\scecli.dll

***

 

Copied file: C:\WINNT\system32\DllCache\scesrv.dll

***

 

Copied file: C:\WINNT\system32\DllCache\sfcfiles.dll

***

 

Copied file: C:\WINNT\system32\DllCache\umandlg.dll

***

 

Copied file: C:\WINNT\system32\DllCache\USER32.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\USERENV.DLL

***

 

Copied file: C:\WINNT\system32\DllCache\w32time.dll

***

 

Copied file: C:\WINNT\system32\DllCache\w32tm.exe

***

 

Copied file: C:\WINNT\system32\DllCache\win32k.sys

***

 

Copied file: C:\WINNT\system32\DllCache\WINLOGON.EXE

***

 

Copied file: C:\WINNT\system32\DllCache\winsrv.dll

***

 

Copied file: C:\WINNT\system32\DllCache\wintrust.dll

***

 

Num Ticks for Copying files : 39537

 

***

 

Num Ticks for Reg update and deleting 0 size files : 20

 

***

 

Starting process: C:\WINNT\system32\secedit.exe /configure /cfg C:\WINNT\inf\hfsecupd.inf /db C:\WINNT\security\templates\hfsecupd.sdb /log C:\WINNT\security\logs\hfsecupd.log

***

 

Return Code = 0

***

 

UpdateSpUpdSvcInf: Source [ProcessesToRunAfterReboot] section is empty; nothing to do.

***

 

---- Old Information In The Registry ------

***

 

 

Source:c:\973ee628f2a8b52ee64f511636837ff2

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\6d3a162f9b5a04bb99f97b5f4ffd

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\3928fe31ffe634249bea

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\ac4165566af797da3366d09025

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\1a635ad07e9efaa80f119c

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000002_.tmp

Version: 5.0.2195.6656

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000003_.tmp

Version: 5.0.2195.6692

***

 

 

Destination:

Version:

***

 

 

Source:c:\bebde20982628e4db4c5e4eb290b6b

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\b04ac7d7846fea53a9

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\94ee866ab40915189e08c2c4a5

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\186a5f5ec8762f89ee

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000004_.tmp

Version: 5.0.2195.6710

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000005_.tmp

Version: 5.0.2195.6695

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000006_.tmp

Version: 5.0.2195.6666

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000007_.tmp

Version: 5.0.2195.6680

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000008_.tmp

Version: 5.0.2195.6666

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000009_.tmp

Version: 5.0.2195.6697

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000012_.tmp

Version: 5.0.2195.6688

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000013_.tmp

Version: 5.0.2195.6685

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000016_.tmp

Version: 5.0.2195.6708

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000017_.tmp

Version: 5.0.2195.6699

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\SETD4.tmp

Version: 5.0.2195.6902

***

 

 

Destination:C:\WINNT\system32\LSASRV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETD5.tmp

Version: 5.1.2195.6899

***

 

 

Destination:C:\WINNT\system32\SCHANNEL.DLL

Version: 5.0.1.0

***

 

 

Source:C:\WINNT\system32\SETD8.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\BASESRV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETD9.tmp

Version: 5.0.2195.6866

***

 

 

Destination:C:\WINNT\system32\browser.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDA.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\CMD.EXE

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDB.tmp

Version: 5.131.2195.6824

***

 

 

Destination:C:\WINNT\system32\CRYPT32.DLL

Version: 5.0.131.0

***

 

 

Source:C:\WINNT\system32\SETDD.tmp

Version: 5.0.2195.6868

***

 

 

Destination:C:\WINNT\system32\cryptsvc.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDE.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\dnsapi.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDF.tmp

Version: 5.0.2195.6876

***

 

 

Destination:C:\WINNT\system32\dnsrslvr.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE0.tmp

Version: 5.0.2195.6883

***

 

 

Destination:C:\WINNT\system32\EVENTLOG.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE1.tmp

Version: 5.0.2195.6898

***

 

 

Destination:C:\WINNT\system32\GDI32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE4.tmp

Version: 5.0.2195.6903

***

 

 

Destination:C:\WINNT\system32\kerberos.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE6.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\mpr.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE7.tmp

Version: 5.0.2195.6895

***

 

 

Destination:C:\WINNT\system32\MSGINA.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE8.tmp

Version: 5.0.2195.6897

***

 

 

Destination:C:\WINNT\system32\NETAPI32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE9.tmp

Version: 5.0.2195.6891

***

 

 

Destination:C:\WINNT\system32\NETLOGON.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEA.tmp

Version: 5.0.2195.6896

***

 

 

Destination:C:\WINNT\system32\ntdsa.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEB.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\PSBASE.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEC.tmp

Version: 5.0.2195.6893

***

 

 

Destination:C:\WINNT\system32\scecli.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETED.tmp

Version: 5.0.2195.6903

***

 

 

Destination:C:\WINNT\system32\scesrv.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEE.tmp

Version: 5.0.2195.6894

***

 

 

Destination:C:\WINNT\system32\sfcfiles.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF0.tmp

Version: 5.0.2195.6897

***

 

 

Destination:C:\WINNT\system32\USER32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF1.tmp

Version: 5.0.2195.6794

***

 

 

Destination:C:\WINNT\system32\USERENV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF2.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\w32time.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF3.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\w32tm.exe

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF4.tmp

Version: 5.0.2195.6898

***

 

 

Destination:C:\WINNT\system32\WINLOGON.EXE

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF5.tmp

Version: 5.131.2195.6824

***

 

 

Destination:C:\WINNT\system32\WINTRUST.DLL

Version: 5.0.131.0

***

 

 

Source:C:\WINNT\system32\SETFA.tmp

Version: 5.1.2600.1327

***

 

 

Destination:C:\WINNT\system32\winhttp.dll

Version: 5.0.1.0

***

 

 

 

 

---- New Information In The Registry ------

***

 

 

Source:c:\973ee628f2a8b52ee64f511636837ff2

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\6d3a162f9b5a04bb99f97b5f4ffd

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\3928fe31ffe634249bea

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\ac4165566af797da3366d09025

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\1a635ad07e9efaa80f119c

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000002_.tmp

Version: 5.0.2195.6656

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000003_.tmp

Version: 5.0.2195.6692

***

 

 

Destination:

Version:

***

 

 

Source:c:\bebde20982628e4db4c5e4eb290b6b

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\b04ac7d7846fea53a9

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\94ee866ab40915189e08c2c4a5

Version:

***

 

 

Destination:

Version:

***

 

 

Source:c:\186a5f5ec8762f89ee

Version:

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000004_.tmp

Version: 5.0.2195.6710

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000005_.tmp

Version: 5.0.2195.6695

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000006_.tmp

Version: 5.0.2195.6666

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000007_.tmp

Version: 5.0.2195.6680

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000008_.tmp

Version: 5.0.2195.6666

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000009_.tmp

Version: 5.0.2195.6697

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000012_.tmp

Version: 5.0.2195.6688

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000013_.tmp

Version: 5.0.2195.6685

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000016_.tmp

Version: 5.0.2195.6708

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\_000017_.tmp

Version: 5.0.2195.6699

***

 

 

Destination:

Version:

***

 

 

Source:C:\WINNT\system32\SETD4.tmp

Version: 5.0.2195.6902

***

 

 

Destination:C:\WINNT\system32\LSASRV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETD5.tmp

Version: 5.1.2195.6899

***

 

 

Destination:C:\WINNT\system32\SCHANNEL.DLL

Version: 5.0.1.0

***

 

 

Source:C:\WINNT\system32\SETD8.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\BASESRV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETD9.tmp

Version: 5.0.2195.6866

***

 

 

Destination:C:\WINNT\system32\browser.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDA.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\CMD.EXE

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDB.tmp

Version: 5.131.2195.6824

***

 

 

Destination:C:\WINNT\system32\CRYPT32.DLL

Version: 5.0.131.0

***

 

 

Source:C:\WINNT\system32\SETDD.tmp

Version: 5.0.2195.6868

***

 

 

Destination:C:\WINNT\system32\cryptsvc.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDE.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\dnsapi.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETDF.tmp

Version: 5.0.2195.6876

***

 

 

Destination:C:\WINNT\system32\dnsrslvr.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE0.tmp

Version: 5.0.2195.6883

***

 

 

Destination:C:\WINNT\system32\EVENTLOG.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE1.tmp

Version: 5.0.2195.6898

***

 

 

Destination:C:\WINNT\system32\GDI32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE4.tmp

Version: 5.0.2195.6903

***

 

 

Destination:C:\WINNT\system32\kerberos.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE6.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\mpr.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE7.tmp

Version: 5.0.2195.6895

***

 

 

Destination:C:\WINNT\system32\MSGINA.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE8.tmp

Version: 5.0.2195.6897

***

 

 

Destination:C:\WINNT\system32\NETAPI32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETE9.tmp

Version: 5.0.2195.6891

***

 

 

Destination:C:\WINNT\system32\NETLOGON.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEA.tmp

Version: 5.0.2195.6896

***

 

 

Destination:C:\WINNT\system32\ntdsa.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEB.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\PSBASE.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEC.tmp

Version: 5.0.2195.6893

***

 

 

Destination:C:\WINNT\system32\scecli.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETED.tmp

Version: 5.0.2195.6903

***

 

 

Destination:C:\WINNT\system32\scesrv.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETEE.tmp

Version: 5.0.2195.6894

***

 

 

Destination:C:\WINNT\system32\sfcfiles.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF0.tmp

Version: 5.0.2195.6897

***

 

 

Destination:C:\WINNT\system32\USER32.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF1.tmp

Version: 5.0.2195.6794

***

 

 

Destination:C:\WINNT\system32\USERENV.DLL

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF2.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\w32time.dll

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF3.tmp

Version: 5.0.2195.6824

***

 

 

Destination:C:\WINNT\system32\w32tm.exe

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF4.tmp

Version: 5.0.2195.6898

***

 

 

Destination:C:\WINNT\system32\WINLOGON.EXE

Version: 5.0.0.0

***

 

 

Source:C:\WINNT\system32\SETF5.tmp

Version: 5.131.2195.6824

***

 

 

Destination:C:\WINNT\system32\WINTRUST.DLL

Version: 5.0.131.0

***

 

 

Source:C:\WINNT\system32\SETFA.tmp

Version: 5.1.2600.1327

***

 

 

Destination:C:\WINNT\system32\winhttp.dll

Version: 5.0.1.0

***

 

IsRebootRequired: At least one file operation was delayed; reboot is required.

If none are listed below, check above for delayed deletes.

***

 

IsRebootRequired: c:\winnt\system32\wintrust.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\winlogon.exe was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\winhttp.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\w32tm.exe was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\w32time.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\userenv.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\user32.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\winsrv.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\win32k.sys was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\ntdll.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\kernel32.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\sfcfiles.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\schannel.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\scesrv.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\scecli.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\samsrv.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\samsrv.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\samlib.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\samlib.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\psbase.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\ntoskrnl.exe was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\ntkrnlpa.exe was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\ntdsa.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\netlogon.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\netapi32.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\msv1_0.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\msv1_0.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\msgina.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\msasn1.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\msasn1.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\mpr.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\drivers\mountmgr.sys was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\mountmgr.sys was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\lsass.exe was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\lsass.exe was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\lsasrv.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\drivers\ksecdd.sys was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\ksecdd.sys was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\kerberos.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\gdi32.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\eventlog.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dnsrslvr.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dnsapi.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\cryptsvc.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\crypt32.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\cmd.exe was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\browser.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\basesrv.dll was delayed; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\advapi32.dll was no-delay replaced; reboot is required.

***

 

IsRebootRequired: c:\winnt\system32\dllcache\advapi32.dll was no-delay replaced; reboot is required.

***

 

DoInstallation: IsRebootRequired returned TRUE.

***

 

VerifySize: Unable to verify size: Source = NULL: c:\winnt\oem1.cat

 

***

 

RebootNecessary = 1,WizardInput = 0 , DontReboot = 1, ForceRestart = 0

***

 

***************************************************************

 

This is the manifest of the applied hotfixes:

 

KB823559.exe

KB819696.exe

KB824105.exe

KB823182.exe

KB826232.exe

KB828035.exe

KB825119.exe

KB828749.exe

KB830352.EXE

KB835732.EXE

KB828741.EXE

KB837001.EXE

KB839643.EXE

KB842526.EXE

KB841872.EXE

KB841873.EXE

dtcsetup.exe

KB840315.EXE

KB839645.EXE

 

*****************************************************************

This list does not include the Qchain utility. Also, it reflects the dtcsetup which was extracted from one of the patches so I could use command line switches with it.

 

All advice is appreciated.

 

-overworked-

 

Share this post


Link to post

Maybe the Evil Empire isn't so evil after all....

 

This morning I started a support case with them. They were kind enough to pick-up the tab on this support issue. I'll let you know how we end up resolving this issue.

 

Stay tuned....more to come ;-)

 

-overworked-

 

Share this post


Link to post

Event ID 49 Is Logged After Adding Random Access Memory

http://support.microsoft.com/?kbid=226448

 

Event ID 49 After You Start Your Computer

http://support.microsoft.com/default.asp...;NoWebContent=1

 

Event ID 49 Entry Is Added to the System Event Log When You Use the 3GB Switch in Windows 2000

http://support.microsoft.com/default.aspx?kbid=319931

 

Quote:
As per Microsoft: "A Memory.dmp file is created when a kernel mode STOP error occurs on a computer that has the "crash dump" feature enabled. If the page file is unable to accommodate a Memory.dmp file, debugging the problem is not possible. The page file is configured for crash dump when your computer starts, and the behavior described earlier in this article is logged when the physical memory on the computer is greater than the size of the Pagefile.sys file.".

 

Q319931 refers to all W2K servers: This problem is caused by a bug in the Memory Manager when it tries to allocate a contiguous run of free memory" and provides a fix.

 

I just wanted to add some quicks links and quotes that I saw in my travels to help resolve your issue.

 

Ping us back with the answer smile

Share this post


Link to post

Originally posted by ds3circuit:

Quote:
Event ID 49 Is Logged After Adding Random Access Memory

http://support.microsoft.com/?kbid=226448

 

Event ID 49 After You Start Your Computer

http://support.microsoft.com/default.asp...;NoWebContent=1

 

Event ID 49 Entry Is Added to the System Event Log When You Use the 3GB Switch in Windows 2000

http://support.microsoft.com/default.aspx?kbid=319931

 

Quote:
As per Microsoft: "A Memory.dmp file is created when a kernel mode STOP error occurs on a computer that has the "crash dump" feature enabled. If the page file is unable to accommodate a Memory.dmp file, debugging the problem is not possible. The page file is configured for crash dump when your computer starts, and the behavior described earlier in this article is logged when the physical memory on the computer is greater than the size of the Pagefile.sys file.".

 

Q319931 refers to all W2K servers: This problem is caused by a bug in the Memory Manager when it tries to allocate a contiguous run of free memory" and provides a fix.

 

I just wanted to add some quicks links and quotes that I saw in my travels to help resolve your issue.

 

Ping us back with the answer smile

 

Q3139931 says that this problem was corrected in SP4. I have long since installed SP4, but have the error message in my event viewer for every system start for several weeks now. I have (repeatedly) deleted the pagefile and recreated it with various sizes. I now have a 512MB pagefile for 256MB memory, and have disabled crash dump completely. Nonetheless, this error message is still appearing. The system also refuses to shutdown, but produces no error message in normal mode (just blank background screen for W2k). In safe mode, shutdown often produces blue screen with error message 0x9f DRIVER_POWER_STATE_FAILURE. All of this was working fine a few weeks ago.

 

What else can I do?

 

Tearing my hair out,

rsbrux

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×