Solved

High System Process Utilization on Windows 2000 Server

Posted on 2004-04-22
15
1,755 Views
Last Modified: 2007-12-19
I have a Windows 2000 Server with all Service Packs and critical updates installed. My System (NOT System Idle Process) is consistently around 90-99% CPU utilization. I have done the following, unsuccessfuly, to resolve the issue

1. I have Symantec Anti-Virus Server. I have verified virus definitions, done a full system scan. No virus on the system. I have also disabled real-time scan for troubleshooting purposes

2. I have disconnected the server from the network.

3. Restarted server in safe mode

4. Run Ad-Aware and Spybot. Removed all detected spywares

5. Stopped all services that are not a part of the default windows services

No matter what I try to do, the System process is always consistently high. This causes me to restart the server every couple of days. HELP!
0
Comment
Question by:manivivek
  • 5
  • 2
  • 2
  • +4
15 Comments
 
LVL 7

Expert Comment

by:spareticus
Comment Utility
run process explorer from sysinternals.com and see if you can see where the handles for this process are going, or what other threads may be running under it

have you tried safe mode to see if the utilization goes down?
0
 

Author Comment

by:manivivek
Comment Utility
I did start the server in safe mode. The system process remains at high CPU utilization.
0
 

Author Comment

by:manivivek
Comment Utility
Process explorer from sysinternals shows

1. Interrupts CPU (approx) 17
2. DPC CPU (approx) 42
3. System CPU (approx) 38

0
 
LVL 7

Expert Comment

by:spareticus
Comment Utility
have you updated any drivers lately?
this could very well be a driver problem
is this a new build, or an existing server that recently started acting this way?
0
 

Author Comment

by:manivivek
Comment Utility
Spareticus, This is an existing server that has started acting up. I thought starting the server in safe mode would isolate a driver issue?
0
 
LVL 1

Expert Comment

by:dltsd
Comment Utility
What hardware is this server?

Have you recently added the latest MS04-011 Patch to this system?
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 82

Expert Comment

by:oBdA
Comment Utility
"all Service Packs and critical updates installed" is probably be the cause. There seem to be some issues concerning the KB 835732 Hotfix.
On W2k in certain configurations, it's high CPU usage of the system process, on Server 2k3, it disables IE's encryption, and it seems to mess up some NT4 installations as well.
Here's a description about how to best remove it:
http://groups.google.de/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=%23IOM%23EzIEHA.3476%40TK2MSFTNGP11.phx.gbl
or another possibility:
http://groups.google.de/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=1d1d201c42315%2448f9c3b0%24a501280a%40phx.gbl&rnum=2

If it doesn't work, google groups for "835732" and "CPU usage" or "835732" and "realtime".
Here are the important parts of the articles above, just in case:

====8<----[MICROSOFT IS LOOKING at the KB 835732 issue now]----
To unistall it, I did the following
(1) Boot into Safe mode.
(2) Run TaskManager - and noticed that the SYSTEM process
was using 99% of the CPU time.
(3) From TaskManager set the Priority of the EXPLORER
process to REALTIME, so that I can get to the control
panel.
(4) Run ADD/REMOVE PROGRAM from control panel.
(5) Go back to TaskManager and set the Priority of
MSHTA.exe to REALTIME, so that the ADD/REMOVE PROGRAM can
get some CPU time.
(6) Select and Remove "Windows 2000 Hotfix  - KB835732".
(7) Go back to TaskManager and set the Priority
of "SPUNIST.exe" to REALTIME, for the uninstall program to
run.
(8) Wait a few minutes, and the uninstall program will
eventually ask you to click FINISH to reboot the machine.
It took a long time for the system to shutdown and I just
unplugged the power.
(9) The machine should become normal after reboot.
====8<----[MICROSOFT IS LOOKING at the KB 835732 issue now]----

====8<----[HELP...ME TOO! my machine is doing the exact same thing...]----
I found this solution below,  and it worked great.
Boot into SAFE MODE (no networking or no command prompt).
Go to: Control Panel --> Add / Remove Programs
UNINSTALL Windows Hotfix KB 835732
Reboot...

There's some additional tricks to this that you can use:

1) Instead of using add\remove programs,  run CMD and type
in:
%systemroot%\$Ntuninstallkb835732$\spuninst\spuninst.exe

or
2) if you can get to the desktop,  go to task manager.  
Give the explorer process Realtime priority.  Then go to
the command prompt and follow step #1.  Once you start up
the spuninst.exe program,  go into task manager and give
it Realtime priority as well.
====8<----[HELP...ME TOO! my machine is doing the exact same thing...]----
0
 
LVL 9

Expert Comment

by:MSGeek
Comment Utility
While I believe SpyBot is a great product, if you come to the point where your running it on a DC, it is time for a rebuild.  I avoid surfing the web at all costs on servers with the exception of neccessary visits to vendor sites.  I just love it when I launch IE on a server to find one of my fellow engineers has been checking their Yahoo mail on the server.. MSGeek
0
 

Author Comment

by:manivivek
Comment Utility
Uninstalling KB 835732 did not resolve the issue.
0
 
LVL 3

Expert Comment

by:mohsyn
Comment Utility
what service components are running and not running?
0
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
0
 

Author Comment

by:manivivek
Comment Utility
Problem turned out to be hardware related. Specifically, the serial cable from the UPS to the server.

Thanks for all your time and input
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
Comment Utility
PAQed, with points refunded (500)

Computer101
E-E Admin
0

Featured Post

Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

Join & Write a Comment

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This video discusses moving either the default database or any database to a new volume.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now