only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

  • Thread starter Thread starter Christine
  • Start date Start date
C

Christine

Guest
only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

I have 3 servers (DC, Exchange,
App Server) all running Windows2k3 Standard. I have about 50 systems
running WinXP SP2. Just last week I went to install the client for an
application when the client executable file came up with the generic
executable icon (the blue/white one) and when I tried to run the
application it popped back the error, "only part of a
ReadProcessMemory or WriteProcessMemory request was completed".

Troubleshooting done so far:
1. tested on various machines- approximately 10. Through network
mapped drives the error occurs
2. tested via remote desktop to each server and error occurs
3. tested on the actual server itself (each of them) and the error
occurs)
4. Shut down and restarted each server (naturally in the appropriate
order)
5. Shut down and restarted each switch and the router
6. No errors in network connectivity and no excessive traffic on the
network
7. No event viewer output from attempting to run these applications,
it seems there is no dump to the event viewer to give me some kind of
idea.
8. If I copy the file directly to a local machine it is broken still
(outputs same error locally) but if I copy a working .exe to the
server it works properly
9. Problem executables are all executables- examples are: Client for
accounting application (sage mas 200), CRM Software client install
(sage saleslogix), Time clock software (gneil), fonts (exe unpacker
to
the font directory), and adobe reader. It doesn't discriminate.
10. Aug 17th backup contains good files. Aug 24th backup doesn't
therefore I have pinpointed a time period when the files went 'sour'
11. Event viewer has only one error between that time period: DNSApi
Error ID 11158 which appears to have no bearing.


The MSKB has offered me nothing,
Google has offered me nothing, and usenet has now delivered nothing.
I
cannot fathom that this situation calls for reinstalling THREE
servers and applications/items on ALL three servers in order to fix
the problem. I have no clue now and beg the community for
help. The main thing that scares me is some applications have been
affected by the problem- I've been able to fix it by restoring the
executables from backup but what about a windows dependent executable?
I am afraid to reboot my servers if they need it.


FWIW: Doing searches on this regarding CDROMS and optical drives
showed that putting the controller mode to PIO fixed the issue. I
have
scsi drives (RAID5 config) here and don't think that's truly an
option.

I appreciate any replies in advance. I'm just at a loss here. I never
have the easy problems- just crazy ones like this.

Sincerely,


Christine
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Christine,
What does your no.8 mean?
What AV do you have?
What versions of W2K3?
Anthony,
http://www.airdesk.com



"Christine" <christine.giglio@gmail.com> wrote in message
news:1190218150.469247.243240@22g2000hsm.googlegroups.com...
>I have 3 servers (DC, Exchange,
> App Server) all running Windows2k3 Standard. I have about 50 systems
> running WinXP SP2. Just last week I went to install the client for an
> application when the client executable file came up with the generic
> executable icon (the blue/white one) and when I tried to run the
> application it popped back the error, "only part of a
> ReadProcessMemory or WriteProcessMemory request was completed".
>
> Troubleshooting done so far:
> 1. tested on various machines- approximately 10. Through network
> mapped drives the error occurs
> 2. tested via remote desktop to each server and error occurs
> 3. tested on the actual server itself (each of them) and the error
> occurs)
> 4. Shut down and restarted each server (naturally in the appropriate
> order)
> 5. Shut down and restarted each switch and the router
> 6. No errors in network connectivity and no excessive traffic on the
> network
> 7. No event viewer output from attempting to run these applications,
> it seems there is no dump to the event viewer to give me some kind of
> idea.
> 8. If I copy the file directly to a local machine it is broken still
> (outputs same error locally) but if I copy a working .exe to the
> server it works properly
> 9. Problem executables are all executables- examples are: Client for
> accounting application (sage mas 200), CRM Software client install
> (sage saleslogix), Time clock software (gneil), fonts (exe unpacker
> to
> the font directory), and adobe reader. It doesn't discriminate.
> 10. Aug 17th backup contains good files. Aug 24th backup doesn't
> therefore I have pinpointed a time period when the files went 'sour'
> 11. Event viewer has only one error between that time period: DNSApi
> Error ID 11158 which appears to have no bearing.
>
>
> The MSKB has offered me nothing,
> Google has offered me nothing, and usenet has now delivered nothing.
> I
> cannot fathom that this situation calls for reinstalling THREE
> servers and applications/items on ALL three servers in order to fix
> the problem. I have no clue now and beg the community for
> help. The main thing that scares me is some applications have been
> affected by the problem- I've been able to fix it by restoring the
> executables from backup but what about a windows dependent executable?
> I am afraid to reboot my servers if they need it.
>
>
> FWIW: Doing searches on this regarding CDROMS and optical drives
> showed that putting the controller mode to PIO fixed the issue. I
> have
> scsi drives (RAID5 config) here and don't think that's truly an
> option.
>
> I appreciate any replies in advance. I'm just at a loss here. I never
> have the easy problems- just crazy ones like this.
>
> Sincerely,
>
>
> Christine
>
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Hey Anthony,

> What does your no.8 mean?


The executables that are not functioning properly (ie give the error
message described above) if I copy them to my local machine (the
client WinXP machine) they will still give the error. However if I
copy a working executable from a local machine to the server it will
function and run normally. It seems that this problem isn't growing as
the days go by, it just happened one day.

> What AV do you have?


Symantec Enterprise 10.1 I believe it is .1

> What versions of W2K3?


I mentioned Standard.

Thanks!

Christine
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Christine,
I have no idea what you mean by "copy a working executable from a local
machine to the server"
Standard isn't a version. Are they W2K3 SP1, SP2, R2?
This is why I asked.

"Christine" <christine.giglio@gmail.com> wrote in message
news:1190232628.490019.278430@57g2000hsv.googlegroups.com...
> Hey Anthony,
>
>> What does your no.8 mean?

>
> The executables that are not functioning properly (ie give the error
> message described above) if I copy them to my local machine (the
> client WinXP machine) they will still give the error. However if I
> copy a working executable from a local machine to the server it will
> function and run normally. It seems that this problem isn't growing as
> the days go by, it just happened one day.
>
>> What AV do you have?

>
> Symantec Enterprise 10.1 I believe it is .1
>
>> What versions of W2K3?

>
> I mentioned Standard.
>
> Thanks!
>
> Christine
>
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

There is Win2k3 Server Standard and Win2k3 Server Enterprise. I have
Standard (obviously cause I stated that). I misunderstood what you
meant but they are the latest releases, all patched up and everything.
These servers were just implemented in March 2007 and get their weekly
dose of updates. :) I hope this helps. As for number 8 here's how it
goes.

On all my servers some executables give out the error message "only
part of a ReadProcessMemory or WriteProcessMemory request was
completed error on 3 servers."

I thought maybe it was an 'over the network' issue so I copied an
executable that errored like this to my local machine over the mapped
network drive. It would still give the same error on my local machine.

So I thought, well I will copy a good executable I have from my local
machine up to the server and see if after a bit of time the executable
turns to where it gives the error message but it doesn't, when you
copy a good working executable from my local machine to the server
over a mapped network drive it works fine.

I hope that explains it a bit better!! Thanks so much for taking the
time to read this!
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

If you look closely at the properties of the one that works and the one that
does not, do you see a difference?
Anthony
http://www.airdesk.com





"Christine" <christine.giglio@gmail.com> wrote in message
news:1190251420.959305.196270@y42g2000hsy.googlegroups.com...
> There is Win2k3 Server Standard and Win2k3 Server Enterprise. I have
> Standard (obviously cause I stated that). I misunderstood what you
> meant but they are the latest releases, all patched up and everything.
> These servers were just implemented in March 2007 and get their weekly
> dose of updates. :) I hope this helps. As for number 8 here's how it
> goes.
>
> On all my servers some executables give out the error message "only
> part of a ReadProcessMemory or WriteProcessMemory request was
> completed error on 3 servers."
>
> I thought maybe it was an 'over the network' issue so I copied an
> executable that errored like this to my local machine over the mapped
> network drive. It would still give the same error on my local machine.
>
> So I thought, well I will copy a good executable I have from my local
> machine up to the server and see if after a bit of time the executable
> turns to where it gives the error message but it doesn't, when you
> copy a good working executable from my local machine to the server
> over a mapped network drive it works fine.
>
> I hope that explains it a bit better!! Thanks so much for taking the
> time to read this!
>
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Anthony,

I only checked permissions and there wasn't any changes. Maybe you
could enlighten me as to what I may be looking for?

Christine
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

You say you have two copies of the exe, one that works and one that doesn't.
We are looking to see if they are identical copies of the file (in which
case something in the environment is causing the execution to fail) or
different (in which case something changed the file). If you right click the
files you should see all the properties and can compare them in detail.
Anthony,
http://www.airdesk.com




"Christine" <christine.giglio@gmail.com> wrote in message
news:1190298593.650851.106220@r29g2000hsg.googlegroups.com...
> Anthony,
>
> I only checked permissions and there wasn't any changes. Maybe you
> could enlighten me as to what I may be looking for?
>
> Christine
>
>
 
Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

Re: only part of a ReadProcessMemory or WriteProcessMemory request was completed error on 3 servers.

So, I ran a check on the good files and the bad files. Basically it
seems these files were modified on Aug 24th at 8:05am. Secondly all
files that are bad are actually 41kb bigger than the good files. Even
though my virus scans are coming up clean, I'm curious if it was some
kinda of virus. I happened to be on vacation that week but I do know
that one of our workstations on the network broke down on that day. I
am not sure of the time. The person who took over my position while I
was on vacation swears it was some kind of virus but she got outside
technical support to pick up the machine and they claim that the
system's motherboard is completely fried as it wouldn't post when they
got a hold of it. The drive I know is good because I recovered outlook
cache files from it. I haven't seen a virus do that kind of damage
since Chernobyl (or aka CIH) so I am stumped but still feel something
hit those files that wasn't cool!

So, I am still stuck but I have an exact time of the problem occuring
and the hint that each file is 41kb bigger now that it is bad.
I have the infected machine here, but my boss considers it 'low
priority' so I have to wait before a post mortem dissection on
it...but I plan that. Any insight is appreciated!

Thanks!

Christine


On Sep 20, 9:51 am, "Anthony" <anthony.s...@spammedout.com> wrote:
> You say you have two copies of the exe, one that works and one that doesn't.
> We are looking to see if they are identical copies of the file (in which
> case something in the environment is causing the execution to fail) or
> different (in which case something changed the file). If you right click the
> files you should see all the properties and can compare them in detail.
> Anthony,http://www.airdesk.com
 
Back
Top