Primary Domain Controller having "Run DLL" issue!

Answered Primary Domain Controller having "Run DLL" issue!

  • Monday, April 23, 2012 3:06 PM
     
     

    Hi all,

    I have windows server 2008 R2 Enterprise-64 Bit domain controller. when logging in that server i can see "N" number of pop ups it says "Run DLL" error. my domain controller having any issue?please suggest how can i avoid those mentioned pop-ups. what was the problem?



    DCDIAG Result:

    Directory Server Diagnosis


    Performing initial setup:

       Trying to find home server...

       Home Server = mascrp1xvdp2

       * Identified AD Forest.
       Done gathering initial info.


    Doing initial required tests

       
       Testing server: MASCRP1\MASCRP1XVDP2

          Starting test: Connectivity

             ......................... MASCRP1XVDP2 passed test Connectivity



    Doing primary tests

       
       Testing server: MASCRP1\MASCRP1XVDP2

          Starting test: Advertising

             ......................... MASCRP1XVDP2 passed test Advertising

          Starting test: FrsEvent

             ......................... MASCRP1XVDP2 passed test FrsEvent

          Starting test: DFSREvent

             There are warning or error events within the last 24 hours after the

             SYSVOL has been shared.  Failing SYSVOL replication problems may cause

             Group Policy problems.
             ......................... MASCRP1XVDP2 failed test DFSREvent

          Starting test: SysVolCheck

             ......................... MASCRP1XVDP2 passed test SysVolCheck

          Starting test: KccEvent

             An error event occurred.  EventID: 0x000001BF

                Time Generated: 04/23/2012   20:17:51

                Event String:

                NTDS (556) NTDSA: A bad page link (error -327) has been detected in a B-Tree (ObjectId: 166, PgnoRoot: 563) of database C:\Windows\NTDS\ntds.dit (2045 => 6402, 10290).

             An error event occurred.  EventID: 0xC00007D8

                Time Generated: 04/23/2012   20:17:51

                Event String:

                Internal error: The security descriptor propagation task encountered an error while processing the following object. The propagation of security descriptors may not be possible until the problem is corrected.


             An error event occurred.  EventID: 0xC00004EE

                Time Generated: 04/23/2012   20:17:51

                Event String:

                The security descriptor propagation task could not process a propagation event starting from the following container.


             ......................... MASCRP1XVDP2 failed test KccEvent

          Starting test: KnowsOfRoleHolders

             ......................... MASCRP1XVDP2 passed test KnowsOfRoleHolders

          Starting test: MachineAccount

             ......................... MASCRP1XVDP2 passed test MachineAccount

          Starting test: NCSecDesc

             ......................... MASCRP1XVDP2 passed test NCSecDesc

          Starting test: NetLogons

             ......................... MASCRP1XVDP2 passed test NetLogons

          Starting test: ObjectsReplicated

             ......................... MASCRP1XVDP2 passed test ObjectsReplicated

          Starting test: Replications

             ......................... MASCRP1XVDP2 passed test Replications

          Starting test: RidManager

             ......................... MASCRP1XVDP2 passed test RidManager

          Starting test: Services

             ......................... MASCRP1XVDP2 passed test Services

          Starting test: SystemLog

             An error event occurred.  EventID: 0x0000165B

                Time Generated: 04/23/2012   20:20:39

                Event String:

                The session setup from computer 'MEDALLCORP' failed because the security database does not contain a trust account 'MEDALLCORP$' referenced by the specified computer.  


             An error event occurred.  EventID: 0x40000004

                Time Generated: 04/23/2012   20:26:11

                Event String:

                The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server comp-med-0248$. The target name used was cifs/COMP-MED-118.medallcorp.in. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (MEDALLCORP.IN) is different from the client domain (MEDALLCORP.IN), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

             An error event occurred.  EventID: 0x40000004

                Time Generated: 04/23/2012   20:26:12

                Event String:

                The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server comp-med-0248$. The target name used was host/COMP-MED-118.medallcorp.in. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (MEDALLCORP.IN) is different from the client domain (MEDALLCORP.IN), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

             An error event occurred.  EventID: 0x40000004

                Time Generated: 04/23/2012   20:26:23

                Event String:

                The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server COMP-MED-0252$. The target name used was cifs/COMP-MED-128.medallcorp.in. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (MEDALLCORP.IN) is different from the client domain (MEDALLCORP.IN), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

             An error event occurred.  EventID: 0x000016AD

                Time Generated: 04/23/2012   20:26:28

                Event String:

                The session setup from the computer MEDALLCORP failed to authenticate. The following error occurred:


             ......................... MASCRP1XVDP2 failed test SystemLog

          Starting test: VerifyReferences

             ......................... MASCRP1XVDP2 passed test VerifyReferences

       
       
       Running partition tests on : ForestDnsZones

          Starting test: CheckSDRefDom

             ......................... ForestDnsZones passed test CheckSDRefDom

          Starting test: CrossRefValidation

             ......................... ForestDnsZones passed test

             CrossRefValidation

       
       Running partition tests on : DomainDnsZones

          Starting test: CheckSDRefDom

             ......................... DomainDnsZones passed test CheckSDRefDom

          Starting test: CrossRefValidation

             ......................... DomainDnsZones passed test

             CrossRefValidation

       
       Running partition tests on : Schema

          Starting test: CheckSDRefDom

             ......................... Schema passed test CheckSDRefDom

          Starting test: CrossRefValidation

             ......................... Schema passed test CrossRefValidation

       
       Running partition tests on : Configuration

          Starting test: CheckSDRefDom

             ......................... Configuration passed test CheckSDRefDom

          Starting test: CrossRefValidation

             ......................... Configuration passed test CrossRefValidation

       
       Running partition tests on : medallcorp

          Starting test: CheckSDRefDom

             ......................... medallcorp passed test CheckSDRefDom

          Starting test: CrossRefValidation

             ......................... medallcorp passed test CrossRefValidation

       
       Running enterprise tests on : medallcorp.in

          Starting test: LocatorCheck

             ......................... medallcorp.in passed test LocatorCheck

          Starting test: Intersite

             ......................... medallcorp.in passed test Intersite

    REPLICATION SUMMARY:

    Replication Summary Start Time: 2012-04-23 20:28:15



    Beginning data collection for replication summary, this may take awhile:

      .....





    Source DSA          largest delta    fails/total %%   error

     MASCRP1XVDP1              59m:00s    0 /   5    0  

     MASCRP1XVDP2              58m:54s    0 /   5    0  





    Destination DSA     largest delta    fails/total %%   error

     MASCRP1XVDP1              58m:54s    0 /   5    0  

     MASCRP1XVDP2              59m:00s    0 /   5    0 

    ====================================================================================================



    Repadmin: running command /showrepl against full DC localhost

    MASCRP1\MASCRP1XVDP2

    DSA Options: IS_GC

    Site Options: (none)

    DSA object GUID: c936e558-2d0b-4484-9fe2-12352f8d0d82

    DSA invocationID: a84a6545-0796-44bd-935f-e6e055acf797



    ==== INBOUND NEIGHBORS ======================================



    DC=medallcorp,DC=in

        MASCRP1\MASCRP1XVDP1 via RPC

            DSA object GUID: 92fb2ad9-cd0c-404b-81e1-4200f518a585

            Last attempt @ 2012-04-23 20:28:43 was successful.



    CN=Configuration,DC=medallcorp,DC=in

        MASCRP1\MASCRP1XVDP1 via RPC

            DSA object GUID: 92fb2ad9-cd0c-404b-81e1-4200f518a585

            Last attempt @ 2012-04-23 19:29:15 was successful.



    CN=Schema,CN=Configuration,DC=medallcorp,DC=in

        MASCRP1\MASCRP1XVDP1 via RPC

            DSA object GUID: 92fb2ad9-cd0c-404b-81e1-4200f518a585

            Last attempt @ 2012-04-23 19:29:15 was successful.



    DC=DomainDnsZones,DC=medallcorp,DC=in

        MASCRP1\MASCRP1XVDP1 via RPC

            DSA object GUID: 92fb2ad9-cd0c-404b-81e1-4200f518a585

            Last attempt @ 2012-04-23 20:27:07 was successful.



    DC=ForestDnsZones,DC=medallcorp,DC=in

        MASCRP1\MASCRP1XVDP1 via RPC

            DSA object GUID: 92fb2ad9-cd0c-404b-81e1-4200f518a585

            Last attempt @ 2012-04-23 19:29:15 was successful.







    Dhakshinamoorthy Balasubramanian

All Replies

  • Monday, April 23, 2012 3:35 PM
     
     

    Hello,

    It seems that your NTDS database is corrupted.

    Please boot using DSRM mode and then refer to section "How to recover the Database" in this article: http://support.microsoft.com/kb/816120

    For the DLL issue, you can run sfc /scannow.

    If this does not help and you have another DC / DNS / GC server, you can simply proceed like that:

    • Re-install the OS of this DC
    • Perform a metadata cleanup: http://technet.microsoft.com/en-us/library/cc736378%28v=ws.10%29.aspx
    • Resize FSMO roles on the left DC if the old DC was an FSMO holder: http://support.microsoft.com/kb/255504
    • Promote again the re-installed DC and make it a DNS and GC server

    Another option is to restore your DC using a non-authoritative restore.


    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.   

    Microsoft Student Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator: Security
    Microsoft Certified Systems Engineer: Security
    Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows 7, Configuring
    Microsoft Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
    Microsoft Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

  • Monday, April 23, 2012 5:17 PM
     
     

    Hi,

    what is the name of .dll file and also run msconfig , go to startup tab and see what all programs are running in the startup. Also run sfc /scannow as suggested above

  • Monday, April 23, 2012 6:05 PM
     
     

    Hello,

    is that the only DC in the domain, then i would think about doing a restore from the DC?

    Please see here about semantic database check: http://support.microsoft.com/kb/258062

    If not save all required data and remove the problem DC from the domain, either with dcpromo or dcpromo /forceremoval and then run metadata cleanup and remove it also from, AD sites and services, DNS zones and zone properties, name server tab.

    http://msmvps.com/blogs/mweber/archive/2010/05/16/active-directory-metadata-cleanup.aspx

    Btw: Please upload the next time large content as text file to Windows sky drive and just add the link here, keeps the thread better readable.


    Best regards

    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://msmvps.com/blogs/mweber/

    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.


  • Tuesday, April 24, 2012 6:12 AM
    Moderator
     
     

    Hi,

    According to the screen capture you provided, we know the issue is:

    There was a problem starting tbrjlq.ij
    The specified module could not be found.

    After search we can’t find any information about “tbrjlq.ij”, I think this is not a MS build-in component.

    As posted above, run msconfig then check startup list, disable all startup items and check the result. Then give us feedback for further troubleshooting.

    For more information please refer to following MS articles:

    How to use the System File Checker tool to troubleshoot missing or corrupted system files
    http://support.microsoft.com/kb/929833
    Managing Active Directory Backup and Restore
    http://technet.microsoft.com/en-us/library/cc778772(v=ws.10).aspx


    Lawrence

    TechNet Community Support

  • Tuesday, April 24, 2012 12:12 PM
     
     

    Hi,

    I ran sfc /scannow. here i attached the system file checker result. but, still RunDll error persists. what i need to do?

    I have two domain controllers named as MASCRP1XVDP1,MASCRP1XVDP2

    MASCRP1XVDP2=Primary Domain controller

    MASCRP1XVDP1=Additional Domain controller

    Please find the below attachments:

    DCDIAG Reports


    Dhakshinamoorthy Balasubramanian





  • Wednesday, April 25, 2012 2:47 AM
    Moderator
     
     Answered

    Hi,

    As my posting above, I don’t think “tbrjlq.ij” file is a MS build-in component. We can’t find any related information from MS website or even search form Google.

    Run msconfig command and disable all startup items at Startup tab, restart DC and check the result.

    Select “Hide all Microsoft services” checkbox to check third party services status at Services tab, disable them and restart DC and check the result.

    Start your DC in safe mode to check whether you still receive the error.

    For more information please refer to following MS articles:

    Using the Safe Mode Boot Options
    http://technet.microsoft.com/en-us/library/bb124193(v=EXCHG.65).aspx
     


    Lawrence

    TechNet Community Support

  • Wednesday, May 02, 2012 2:02 AM
    Moderator
     
     

    Hi,

    I would like to confirm what is the current situation? Have you resolved the problem?

    If there is anything that we can do for you, please do not hesitate to let us know, and we will be happy to help.



    Lawrence

    TechNet Community Support


  • Saturday, May 05, 2012 5:58 AM
     
     Answered

    Thanks very much Lawrence.

    My PDC AD database ntds.dit was corrupted. now i transfered all fsmo roles to ADC and introduced new Additional DC.

    Thanks once more for asking..


    Dhakshinamoorthy Balasubramanian