cancel
Showing results for 
Search instead for 
Did you mean: 
Community Guide

Re: Update on Winlogin 4005 & Terminal Servers - November 22, 2016

We previously had an RDS server with the 4005 error, which we moved to Silent Audit mode as a result of the problem.  After installing 9.0.17.32, I moved the system back to our normal server policy.  So far no issues.

 

I have since updated all client RDS servers with this version and am monitoring further.


We are SysAdmins.
We walk in the wiring closets no others will enter.
We stand on the bridge, and no malware may pass.
We engage in tech support, we do not retreat.
We live for the LAN. We die for the LAN.

Highlighted
Product Manager

Re: Update on Winlogin 4005 & Terminal Servers - 13th September 2017

Hello,

 

Working closely with our customers, Webroot has identified an issue that manifests itself in the form of existing Terminal Server sessions becoming un-responsive with users no longer being able to log in. The affected Terminal Servers have required restarting in order for normal service to be resumed. For customers who have experienced this, an update to WSA is available now and Webroot support will provide assistance as required. The fix will also be rolled into the next general release of WSA which is forecast to be automatically deployed in October. Forthcoming product bulletins will advise of the exact date.

 

Before applying the agent build we have created to address this issue, please ensure that you have applied the below Microsoft patches. These patches were designed specifically to address 4005 errors/RDS connection issues.

 

http://support.microsoft.com/kb/3172614

http://support.microsoft.com/kb/3179574

http://support.microsoft.com/kb/3197875

http://support.microsoft.com/kb/3197874

 

Before installing the following agent build please ensure that you have removed the agent currently installed and ensure that C:\Program Data\WRData has been removed (if not please delete this folder:

http://download.webroot.com/9.0.17.32/WRSASME.EXE

Please ensure that you reboot the server after applying the above update. If you experience any further issues, please update your support ticket and the escalation team will get back to you promptly.

 

Thank you for your patience whilst we have investigated and developed the update. It is deeply appreciated by us all at Webroot.

 

Regards

 

Webroot Global Escalation Team”

New Voice

Re: Update on Winlogin 4005 & Terminal Servers - November 22, 2016

Jonathon,

Thanks for the Policy suggestion.   I have created the policy and applied it to the single server causing me these problems.   I find it kind of unsettling that I have to disable so much of the product just to keep the client's server running.   Seems kind of counter-intuitive - "Please pay for this product, but don't use its security features or your server will crash!"

I have a single 2008 r2 RDS server that has been having these issues for some time - the Event ID 4005 and inability for users to log in.   (WR Agent 9.0.18.34)  Server seems to be completely unresponsive when it happens.  I have to power cycle it to get it back up again.

I found a document somewhere a while ago suggesting an override for C:\Windows\system32\winlogon.exe - is this advised, or was it an uninformed suggestion?   (No idea where I saw it...)

I find it amazing that this has been going on for so long without a resolution.    There's a document in this thread somewhere listing patches that are supposed to fix it, but they all seem to be for Server 2012 and r2 - not for 2008.

I am reluctant to do so, but am considering just removing WBSA from this server so I can stop getting urgent SOS calls from the client.    Understand that it is very difficult to recommend a product to my clients that has had an unresolved issue like this for so long.

 

Product Manager

Re: Update on Winlogin 4005 & Terminal Servers - November 22, 2016

winlogon.exe -  I'd avoid doing that. 

 

You're entirely right in saying that this has been going on for a long time.  No matter what we've tried in house, we can't reproduce this.  Some customers have Terminal Servers that rarely, if ever, see this issue.  It's been a pain in arse for everyone concerned, but particulary our customers. 

 

But there's some good news.  We've been given a full crash dump from a server that was experiencing a 4005 event and that's undergoing analysis at the moment.  I'm expecting that will give us direction as to what the underlying root cause is and then we'll be able to do something about it.  Given the past history, it's going to take a number of releases for us to flush out the solution. 

 

Jonathan

 

 

 

 

 

New Member

Re: Update on Winlogin 4005 & Terminal Servers - November 22, 2016

Hi is this stil happening? I have a terminal server that has been plagued with this issue for 6 months or more and we use webroot. I never thought to check that it might be webroot.

Retired Webrooter
Retired Webrooter

Re: Update on Winlogin 4005 & Terminal Servers - November 22, 2016

@seantheitguy, please reach out to our Support Team to look into this further for you.

 

Business Technical Support: Call 1-866-254-8400 M-F 7:00 AM – 6:00 PM MT
Open a Support Ticket