?
Solved

Services shut off with no warning, stops file sharing

Posted on 2008-11-03
14
Medium Priority
?
3,255 Views
Last Modified: 2011-10-19
the following services periodically shut down on their own, i can't see anything in the event logs as to why.

these services once down, stop any file sharing going on.

Application Management
Computer Browser
Remote Access Connection Manager
Network Connections
Network Location Awareness (NLA)

Ive attached a list of services & setup. will attach event logs shortly.


services.xls
0
Comment
Question by:funnymanmike
  • 9
  • 4
14 Comments
 
LVL 5

Author Comment

by:funnymanmike
ID: 22869420
event logs
eventlogs.zip
0
 
LVL 39

Expert Comment

by:ChiefIT
ID: 22872872
Are the workstation and Server services also shutting down? If not, it sounds like you have a browser conflict. I am currently rebuilding my main desktop for the administrtor, so I couldn't open up the zip file due to lack of a zip utility.

I'll bet you have event 8030 and 8021 that say something like, "xxxcomputer thinks it is the domain master browser. The browser service has been stopped and an election has been forced."

0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22873430
yeah workstation and server have also been known to shut down.

this server has a odd recent history (i was away)
the previous tech removed it from the domain forgot the password so we sent it into a password recovery shop.
once we got the password put it back on a domain, now its just a stand alone server. so i don't know if its creating a weird conflict.

i'll check for the events tomorow and update.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 39

Expert Comment

by:ChiefIT
ID: 22875314
So, many things may apply:

You may have this server tombstoned in AD, depending on how long it was in the "password recovery" shop. So, you may have AD metadata.

You may have AD Sites and Services told to replicate to this server, even though it is not just a "member server". So, there is probably FRS metadata.

You might also have DNS metadata of SRV records for this server being an AD server.


0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22876689
So what do you recommend doing?
0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22880548
this has also happened to another server (2) recently.

at the start of it, i thought it was just a problem with RPC an unable to RDP to the server (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_23875203.html)

0
 
LVL 3

Accepted Solution

by:
kg69 earned 400 total points
ID: 22880602
For staters follow this: http://windowsitpro.com/article/articleid/80294/jsi-tip-7751-winmgmt-could-not-initialize-the-core-parts.html

Your getting that error several times in your application log.

All the services that are crashing except Computer Browser can be ignored. BUT, the fact that svchost.exe -k netsvcs is crashing is a bigger concern.

Also your getting an:
EventID 3095
This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.

To resolve this if it is in the domain:
change the local admin password, drop the computer from the domain, delete the computer in AD Users & Computers, DNS, and WINS if using wins. If you have more then one DC wait for replication, then rejoin the server to the domain.

Also looks like you may have an issue with your Dell RAID controller:
cercsr6
The description for Event ID ( 9 ) in Source ( cercsr6 ) cannot be found.
OR, this could be malware acting as the cercsr6.sys file if in windows, windows\system32

For this its possible you have an infection of sometype. I would run an antivirus scan using another vendor like www.trendmicro.com HouseCall (under Personal) or AVG or a trial of Mcaffe.

This event makes me think you have more of a RAID/disk issue then anything else:
Event ID 55
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:

In this case I'd make sure you have a good backup of the system, and if the system is under warranty call in a hardware tech to check out the controller. If not, rebuild on new hardware if possible, if not try to replace the controller (be sure to use the configuration from the drives when the controller detects them).

0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22880932
Thanks kg69:

I ran a virus scan on it today, looks clean

i will follow the procedure tonight as well as run the checkdsk hopefuly that fixes those problems.

do you feel that once i run (http://windowsitpro.com/article/articleid/80294/jsi-tip-7751-winmgmt-could-not-initialize-the-core-parts.html) the system will act normally?
0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22883100
- run http://windowsitpro.com/article/articleid/80294/jsi-tip-7751-winmgmt-could-not-initialize-the-core-parts.html

Commands i ran

C:\>winmgmt /clearadap
C:\>winmgmt /kill
C:\>winmgmt /unregserver
C:\>winmgmt /regserver
C:\>winmgmt /resyncperf
Generated following event errors

Event Type:      Error
Event Source:      WinMgmt
Event Category:      None
Event ID:      28
Date:            11/4/2008
Time:            11:06:18 PM
User:            N/A
Computer:      CBIZ_QB
Description:
WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Warning
Event Source:      WinMgmt
Event Category:      None
Event ID:      43
Date:            11/4/2008
Time:            11:06:18 PM
User:            N/A
Computer:      CBIZ_QB
Description:
WMI ADAP failed to connect to namespace \\.\root\cimv2 with the following error: 0x80041002

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Warning
Event Source:      WinMgmt
Event Category:      None
Event ID:      60
Date:            11/4/2008
Time:            11:06:18 PM
User:            N/A
Computer:      CBIZ_QB
Description:
WMI ADAP was unable to process the performance libraries: 0x80041001

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
- run chkdsk
Volume fragmentation
    Total fragmentation                        = 6 %
    File fragmentation                         = 12 %
    Free space fragmentation                   = 0 %
Not Recommended to defrag
0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22883327
applied 234474_ENU_i386 HF, this was from http://support.microsoft.com/kb/910666

services appear to be up on start up

received the following errors

Event Type:      Error
Event Source:      Userenv
Event Category:      None
Event ID:      1090
Date:            11/5/2008
Time:            12:26:16 AM
User:            NT AUTHORITY\SYSTEM
Computer:      CBIZ_QB
Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Error
Event Source:      Userenv
Event Category:      None
Event ID:      1090
Date:            11/5/2008
Time:            12:25:17 AM
User:            NT AUTHORITY\SYSTEM
Computer:      CBIZ_QB
Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Event Type:      Error
Event Source:      WinMgmt
Event Category:      None
Event ID:      28
Date:            11/5/2008
Time:            12:25:17 AM
User:            N/A
Computer:      CBIZ_QB
Description:
WinMgmt could not initialize the core parts.  This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

i will monitor this server for the next day, hopefully this resolved the problem
0
 
LVL 39

Assisted Solution

by:ChiefIT
ChiefIT earned 600 total points
ID: 22883662
I think you should look for metadata of an improperly demoted domain controller:

FRS, DNS and AD metadata is what you should look for.

This article explains the four stages of a deleted SID. It also has some information on how to look for certain metadata.
http://support.microsoft.com/kb/248047

This page is used to remove all that metadata of a domain controller:
http://www.petri.co.il/delete_failed_dcs_from_ad.htm
0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22886210
but this was never a domain controller, it was just a server part of a domain.
0
 
LVL 39

Assisted Solution

by:ChiefIT
ChiefIT earned 600 total points
ID: 22898257
It could be bad data in the WMI file of your machine. You can rebuild the WMI files by:
1 Stop the Windows Management Instrumentation service (WMI service). (Do not disable it)
2 Go to the %SystemRoot%\System32\Wbem\Repository folder.
3. Delete all of the files in that file folder
4 Restart the computer. Restarting will start the WMI service and rebuild the WMI files.
0
 
LVL 5

Author Comment

by:funnymanmike
ID: 22898741
Thanks ChiefIT

scheduled for after production tonight
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Stellar Phoenix SQL Database Repair software easily fixes the suspect mode issue of SQL Server database. It is a simple process to bring the database from suspect mode to normal mode. Check out the video and fix the SQL database suspect mode problem.

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question