Unexplained reboots - Win2003 SP2 - The process winlogon.exe has initiated the restart of computer

Unexplained reboots - Win2003 SP2 - The process winlogon.exe has initiated the restart of computer.
System starts to shutdown by itself and by giving countdown to reboot. It happens a few times a day. It also fails to reboot.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Darren SharplesSystems SpecialistCommented:
maybe a corrupt profile or virus, not to sure. you can issue a shutdown -a to prevent it when you see it while you diagnose
akeramatAuthor Commented:
Thanks Sharpting.
I will try this while I need to know how to rrouble shoot this problem.
Look in the Event Viewer, under the source User32 and see if it gives any hints as to what initiated the shutdown... Might get lucky.....


reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /s winlog.reg
notepad winlog.reg

Post the results here please..... It might be an infection thats loaded under the Winlogon process causing the problem.....
Newly released Acronis True Image 2019

In announcing the release of the 15th Anniversary Edition of Acronis True Image 2019, the company revealed that its artificial intelligence-based anti-ransomware technology – stopped more than 200,000 ransomware attacks on 150,000 customers last year.

Darren SharplesSystems SpecialistCommented:
1. hit control alt delete and click the processes tab, have a look for any suspicous virusy looking files that are running.

2. search for that file and delete all instances of it.

3. run a virus scan http://housecall.trendmicro.com/uk/ and install spybot and run that.

if your not sure what suspicous virusy files look like then just skip straight to step 3.
B HCommented:
is this 'small business server' with another domain controller on the network?  if so, the sbs server knows, and will shutdown/reboot itself every day or so - but it does a good job about logging it in the "...reason for the shutdown was: " section of the event logs.

what happens in your event logs just before the shutdown is logged?
akeramatAuthor Commented:
Thanks all for all the tips and suggestions.
This was a PC connected to Network. Somehow the profile was corrupted.
We restored to an earlier date and disjoined the PC from domain and rejoined it to the domain,
and it worked. Everything seemingly is fine. We can calose this issue.
"Everything seemingly is fine"

System Restore doesnt remove the viral files that are responsible for these types of threats, just be aware.....

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
akeramatAuthor Commented:
Thanks, i will be aware.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows XP

From novice to tech pro — start learning today.