By using this site, you agree to our updated Privacy Policy and our Terms of Use. Manage your Cookies Settings.
440,130 Members | 2,141 Online
Bytes IT Community
+ Ask a Question
Need help? Post your question and get tips & solutions from a community of 440,130 IT Pros & Developers. It's quick & easy.

NTbackup fails after running fine for 1 years

P: n/a
I have found lots of people talking about this issue, but no one seems to
have a solution. I could really use some help here. Has anyone seen this or
have any ideas?

I have been running the same backup for 2 years and I came in one morning
and it just decided it would not work anymore.

Histroy:

* Windows 2003 Server
* Role - DC
* I checked the media to make sure I can read it.
* I made sure the backup was failing by checking the data on the restore
and it is not current
* Backup reports are blank
* I deleted the my local profile and the profile used for backup
* I deleted the backups and recreated them
* I varified the account is not locked out and the password is correct.
* I did open the task manager and place a /um at the end of the command
line to make the media unmanaged.
* Nothing has changed on this server
* No new tapes have been introduced
* Anti-Virus reports everything is clean
* No new software have been installed

Events:

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1524
Date: 7/31/2008
Time: 11:00:33 PM
User: Domain\Account
Computer: DC
Description:
Windows cannot unload your classes registry file - it is still in use by
other applications or services. The file will be unloaded when it is no
longer in use.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Userenv
Event Category: None
Event ID: 1516
Date: 7/31/2008
Time: 11:01:04 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
Windows unloaded user S-1-5-21-1203075926-436352153-549210805-2132_Classes
registry when it received a notification that no other applications or
services were using the profile.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Successful Logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x40003F)
Logon Type: 4
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: DC
Logon GUID: {****1f30-fc37-bc46-19c4-d9745d3561**}
Caller User Name: DC$
Caller Domain: Domain
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 1024
Transited Services: -
Source Network Address: -
Source Port: -
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Special privileges assigned to new logon:
User Name:
Domain:
Logon ID: (0x0,0x40003F)
Privileges: SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Special privileges assigned to new logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x4003A3)
Privileges: SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Successful Network Logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x4003A3)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {****030b-c1ec-d8ec-c322-f45a0e16a5**}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.168.20.35
Source Port: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 592
Date: 7/31/2008
Time: 11:00:00 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
A new process has been created:
New Process ID: 3548
Image File Name: C:\WINDOWS\system32\ntbackup.exe
Creator Process ID: 1024
User Name: DC$
Domain: Domain
Logon ID: (0x0,0x3E7)
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 600
Date: 7/31/2008
Time: 11:00:00 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
A process was assigned a primary token.
Assigning Process Information:
Process ID: 1024
Image File Name: C:\WINDOWS\system32\svchost.exe
Primary User Name: DC$
Primary Domain: Domain
Primary Logon ID: (0x0,0x3E7)
New Process Information:
Process ID: 3548
Image File Name: C:\WINDOWS\system32\ntbackup.exe
Target User Name: Account
Target Domain: Domain
Target Logon ID: (0x0,0x40003F)
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 7/31/2008
Time: 11:00:01 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
The Removable Storage service was successfully sent a start control.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 7/31/2008
Time: 11:00:01 PM
User: N/A
Computer: DC
Description:
The Removable Storage service entered the running state.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Removable Storage Service
Event Category: None
Event ID: 98
Date: 7/31/2008
Time: 11:01:04 PM
User: N/A
Computer: DC
Description:
RSM was stopped.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 7/31/2008
Time: 11:01:04 PM
User: N/A
Computer: DC
Description:
The Removable Storage service entered the stopped state.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Aug 2 '08 #1
Share this Question
Share on Google+
1 Reply


P: n/a
Try a more suitable newsgroup. This newsgroup is for Microsoft ".NET"
programming questions.
"Syntax 37707" <Sy*********@discussions.microsoft.comwrote in message
news:FB**********************************@microsof t.com...
>I have found lots of people talking about this issue, but no one seems to
have a solution. I could really use some help here. Has anyone seen this
or
have any ideas?

I have been running the same backup for 2 years and I came in one morning
and it just decided it would not work anymore.

Histroy:

* Windows 2003 Server
* Role - DC
* I checked the media to make sure I can read it.
* I made sure the backup was failing by checking the data on the restore
and it is not current
* Backup reports are blank
* I deleted the my local profile and the profile used for backup
* I deleted the backups and recreated them
* I varified the account is not locked out and the password is correct.
* I did open the task manager and place a /um at the end of the command
line to make the media unmanaged.
* Nothing has changed on this server
* No new tapes have been introduced
* Anti-Virus reports everything is clean
* No new software have been installed

Events:

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1524
Date: 7/31/2008
Time: 11:00:33 PM
User: Domain\Account
Computer: DC
Description:
Windows cannot unload your classes registry file - it is still in use by
other applications or services. The file will be unloaded when it is no
longer in use.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Userenv
Event Category: None
Event ID: 1516
Date: 7/31/2008
Time: 11:01:04 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
Windows unloaded user S-1-5-21-1203075926-436352153-549210805-2132_Classes
registry when it received a notification that no other applications or
services were using the profile.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Successful Logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x40003F)
Logon Type: 4
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: DC
Logon GUID: {****1f30-fc37-bc46-19c4-d9745d3561**}
Caller User Name: DC$
Caller Domain: Domain
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 1024
Transited Services: -
Source Network Address: -
Source Port: -
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Special privileges assigned to new logon:
User Name:
Domain:
Logon ID: (0x0,0x40003F)
Privileges: SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 576
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Special privileges assigned to new logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x4003A3)
Privileges: SeSecurityPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeLoadDriverPrivilege
SeImpersonatePrivilege
SeEnableDelegationPrivilege

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 7/31/2008
Time: 11:00:00 PM
User: Domain\Account
Computer: DC
Description:
Successful Network Logon:
User Name: Account
Domain: Domain
Logon ID: (0x0,0x4003A3)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Logon GUID: {****030b-c1ec-d8ec-c322-f45a0e16a5**}
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.168.20.35
Source Port: 0
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 592
Date: 7/31/2008
Time: 11:00:00 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
A new process has been created:
New Process ID: 3548
Image File Name: C:\WINDOWS\system32\ntbackup.exe
Creator Process ID: 1024
User Name: DC$
Domain: Domain
Logon ID: (0x0,0x3E7)
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 600
Date: 7/31/2008
Time: 11:00:00 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
A process was assigned a primary token.
Assigning Process Information:
Process ID: 1024
Image File Name: C:\WINDOWS\system32\svchost.exe
Primary User Name: DC$
Primary Domain: Domain
Primary Logon ID: (0x0,0x3E7)
New Process Information:
Process ID: 3548
Image File Name: C:\WINDOWS\system32\ntbackup.exe
Target User Name: Account
Target Domain: Domain
Target Logon ID: (0x0,0x40003F)
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 7/31/2008
Time: 11:00:01 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
The Removable Storage service was successfully sent a start control.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 7/31/2008
Time: 11:00:01 PM
User: N/A
Computer: DC
Description:
The Removable Storage service entered the running state.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Removable Storage Service
Event Category: None
Event ID: 98
Date: 7/31/2008
Time: 11:01:04 PM
User: N/A
Computer: DC
Description:
RSM was stopped.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 7/31/2008
Time: 11:01:04 PM
User: N/A
Computer: DC
Description:
The Removable Storage service entered the stopped state.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Aug 2 '08 #2

This discussion thread is closed

Replies have been disabled for this discussion.