Solved

Trapping why Windows Server reboots randomly

Posted on 2014-01-29
7
1,963 Views
Last Modified: 2014-02-12
Hello Experts,   I have a server that continues to reboot randomly.  I wiped out the OS and reinstalled all of the software.  It is a RDS (terminal service) server.

Is there a way to trap what is causing it to reboot?

I suspect a driver is causing the issue as the hardware checks out via manufacturer diagnostics.
0
Comment
Question by:tucktech
7 Comments
 
LVL 13

Assisted Solution

by:Andy M
Andy M earned 125 total points
ID: 39817870
First port of call would be check the event logs - it should give you an idea of what was happening around the time of the reboot and what initiated it (if it was  proper reboot).

If it's a bluescreen event you should have a memory dump which can be checked for information on what may have caused it as well. (If it's a driver this should point towards it).

Another option would be to setup some performance monitors - see if anything shows up around the time of the reboots.

If none of these show anything it could indicate a power issue - faulty PSU/plug/someone switching it off?
0
 

Assisted Solution

by:tucktech
tucktech earned 0 total points
ID: 39817935
The only thing I see in the event logs for application and system are events after the system started up stating the shutdown was unexpected.

Where can I find the dump logs?

Also, with the hardware checks it did check the PSU and it appears to be ok.
0
 
LVL 10

Accepted Solution

by:
tmoore1962 earned 175 total points
ID: 39818633
First run a memory / hard drive test on the server since you have reloaded it.  Make sure you run the memory test several passes if reboots are random.  Even if memory test successfully completes several passes, I'd at least reseat memory (use a pencil eraser to clean the memory contacts - remember static control - especially if svr in area where temp/humid varies.  I'd also check the voltages either using Bios or CPUid hardware monitor.  You can also blow out fans / heat sinks if they look like they need it when you reseat mem.
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 8

Assisted Solution

by:Ratnesh Mishra
Ratnesh Mishra earned 100 total points
ID: 39819592
Look for " Event id : 1074 Source : USER32 " in System log . This will give you the process name with reason. Also which account is used for it. Apart from this if you start audit log ,that will also help you a lot.
0
 

Author Comment

by:tucktech
ID: 39820527
tmoore1962, I have run hardware diagnostics, but you are correct, I have had bad memory play funny tricks unless extensive diagnostics are run to validate there is nothing wrong.  I will run memory diagnostics.

 Ratnesh Mishra, below are some logs, the interesting thing is that I don't have a 1074 fot the time around the unexpected restart.  Also, how do I setup audit log?

Log Name:      System
Source:        USER32
Date:          1/29/2014 12:11:44 AM
Event ID:      1074
Task Category: None
Level:         Information
Keywords:      Classic
User:          SYSTEM
Computer:      CC5.cc.ad
Description:
The process msiexec.exe has initiated the restart of computer CC5 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x80030002
 Shutdown Type: restart
 Comment: The Windows Installer initiated a system restart to complete or continue the configuration of ''.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="USER32" />
    <EventID Qualifiers="32768">1074</EventID>
    <Level>4</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-29T06:11:44.000000000Z" />
    <EventRecordID>9068</EventRecordID>
    <Channel>System</Channel>
    <Computer>CC5.cc.ad</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data>msiexec.exe</Data>
    <Data>CC5</Data>
    <Data>No title for this reason could be found</Data>
    <Data>0x80030002</Data>
    <Data>restart</Data>
    <Data>The Windows Installer initiated a system restart to complete or continue the configuration of ''.</Data>
    <Data>NT AUTHORITY\SYSTEM</Data>
    <Binary>02000380000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        USER32
Date:          1/29/2014 12:00:09 AM
Event ID:      1074
Task Category: None
Level:         Information
Keywords:      Classic
User:          CC\administrator
Computer:      CC5.cc.ad
Description:
The process C:\Windows\System32\shutdown.exe (CC5) has initiated the restart of computer CC5 on behalf of user CC\Administrator for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: restart
 Comment:
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="USER32" />
    <EventID Qualifiers="32768">1074</EventID>
    <Level>4</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-29T06:00:09.000000000Z" />
    <EventRecordID>8814</EventRecordID>
    <Channel>System</Channel>
    <Computer>CC5.cc.ad</Computer>
    <Security UserID="S-1-5-21-3111841159-2826495398-1470007349-500" />
  </System>
  <EventData>
    <Data>C:\Windows\System32\shutdown.exe (CC5)</Data>
    <Data>CC5</Data>
    <Data>No title for this reason could be found</Data>
    <Data>0x800000ff</Data>
    <Data>restart</Data>
    <Data>
    </Data>
    <Data>CC\Administrator</Data>
    <Binary>FF000080000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        USER32
Date:          1/28/2014 11:42:20 PM
Event ID:      1074
Task Category: None
Level:         Information
Keywords:      Classic
User:          SYSTEM
Computer:      CC5.cc.ad
Description:
The process msiexec.exe has initiated the restart of computer CC5 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x80030002
 Shutdown Type: restart
 Comment: The Windows Installer initiated a system restart to complete or continue the configuration of 'NComputing vSpace Server for Windows'.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="USER32" />
    <EventID Qualifiers="32768">1074</EventID>
    <Level>4</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-29T05:42:20.000000000Z" />
    <EventRecordID>8566</EventRecordID>
    <Channel>System</Channel>
    <Computer>CC5.cc.ad</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data>msiexec.exe</Data>
    <Data>CC5</Data>
    <Data>No title for this reason could be found</Data>
    <Data>0x80030002</Data>
    <Data>restart</Data>
    <Data>The Windows Installer initiated a system restart to complete or continue the configuration of 'NComputing vSpace Server for Windows'.</Data>
    <Data>NT AUTHORITY\SYSTEM</Data>
    <Binary>02000380000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>



Log Name:      System
Source:        EventLog
Date:          1/29/2014 7:45:48 AM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      CC5.cc.ad
Description:
The previous system shutdown at 7:41:30 AM on ¿1/¿29/¿2014 was unexpected.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-29T13:45:48.000000000Z" />
    <EventRecordID>9429</EventRecordID>
    <Channel>System</Channel>
    <Computer>CC5.cc.ad</Computer>
    <Security />
  </System>
  <EventData>
    <Data>7:41:30 AM</Data>
    <Data>¿1/¿29/¿2014</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>26800</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>DE07010003001D00070029001E009902DE07010003001D000D0029001E0099023C0000003C000000000000000000000000000000000000000100000000000000</Binary>
  </EventData>
</Event>
0
 

Author Comment

by:tucktech
ID: 39842705
this was my own comment back, not required for providing points to self.
0
 

Author Closing Comment

by:tucktech
ID: 39852808
The event logs never pointed to a specific issue.  A good memory check pointed out a hardware issue, memory.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now