Solved

Unexpected Restarts

Posted on 2014-02-08
8
3,086 Views
1 Endorsement
Last Modified: 2014-11-10
Hi Guys,

I was hoping someone could shed some light on a problem I have been experiencing for the last 10 days.

My WIN 7 x64 PC keeps restarting itself every night at 12:13:14 AM for no apparent reason. I have no scheduled tasks that could be triggering this. It appears to be a fairly graceful restart.

I have completed multiple malware/anti virus scans (Kaspersky, FSecure) to name a few. Downloaded some rootkits which yielded nothing, created a new Admin profile and disabled the old one, yet still it is restarting itself.

Any ideas would be greatly appreciated!

Information below,

Thanks guys & gals!


Event Viewer Reads:

GENERAL TAB:
The process C:Windowssystem32shutdown.exe (**PCNAME**) has initiated the restart of computer **PCNAME** on behalf of user NT AUTHORITYNETWORK SERVICE for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: restart
 Comment:

DETAILS TAB:

- System

  - Provider

   [ Name]  USER32
 
  - EventID 1074

   [ Qualifiers]  32768
 
   Level 4
 
   Task 0
 
   Keywords 0x80000000000000
 
  - TimeCreated

   [ SystemTime]  2014-02-08T13:13:14.000000000Z
 
   EventRecordID 424139
 
   Channel System
 
   Computer **PCNAME**
 
  - Security

   [ UserID]  S-1-5-20
 

- EventData

   C:\Windows\system32\shutdown.exe **PCNAME**)
   **PCNAME**
   No title for this reason could be found
   0x800000ff
   restart
   
   NT AUTHORITY\NETWORK SERVICE
   FF000080000000000000000000000000000000000000000000000000000000000000000000000000


--------------------------------------------------------------------------------

Binary data:


In Words

0000: 800000FF 00000000 00000000 00000000
0008: 00000000 00000000 00000000 00000000
0010: 00000000 00000000  


In Bytes

0000: FF 00 00 80 00 00 00 00   ÿ..¿....
0008: 00 00 00 00 00 00 00 00   ........
0010: 00 00 00 00 00 00 00 00   ........
0018: 00 00 00 00 00 00 00 00   ........
0020: 00 00 00 00 00 00 00 00   ........
1
Comment
Question by:chudmarek
8 Comments
 
LVL 91

Expert Comment

by:nobus
Comment Utility
it can be you had a BSOD; so check for minidumps in windows\minidumps, and post the latest dmp here
look also in event viewer for other causes
0
 

Author Comment

by:chudmarek
Comment Utility
Hi nobus,

Thank you for your response.


The last MiniDump appears to be 13/9/2012....so not much to go off there.

I've checked the event viewer a few times for things that could be happening around that time, but have yet to come up with anything significant.

It's just bizarre that it is the same time every night, right on cue

Thanks.
0
 
LVL 91

Accepted Solution

by:
nobus earned 250 total points
Comment Utility
it looks like there is something scheduled for that time, do you have any tasks running?
0
 

Author Comment

by:chudmarek
Comment Utility
No, there is nothing
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 
LVL 91

Expert Comment

by:nobus
Comment Utility
if you connect a 2nd pc to that AC line, does it restart also?
0
 
LVL 18

Assisted Solution

by:web_tracker
web_tracker earned 250 total points
Comment Utility
I would thinks of updates that are scheduled to install at that time. Maybe a group policy thing on the server is installed so that updates are installed and the computer is rebooted at that time. For example this pc may be part of the managed group... where all computers listed in this group automatically have updates installed at a specific time and the computer would automatically be restarted to apply these new updates.
0
 

Expert Comment

by:LukeHarrison
Comment Utility
I'm having this exact same problem. I have no tasks set that would restart the machine, and no update schedule for that time. We did, however, have a Conficker and FTP.bat infection, but both of these have been cleaned and removed.

All the other symptoms are the same, same restart time, same message, everything.

Can anybody help?
0
 
LVL 91

Expert Comment

by:nobus
Comment Utility
LukeHarrison
if you want help, post your own question - don't piggy-back on another!
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

by Nathan Brom/Bromy2004 Introduction There are numerous websites out there for any different type of program you can imagine.  Of those, you'll need to decide which ones are legitimate and aren't trying to steal your money or infect your comput…
Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now