Strange svchost crash


i running windows 2008 r2 sp1 64-bit server. , encountering weird error, namely every 1-2 hours svchost crashes following error:

"faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1

faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
exception code: 0xc0000005
fault offset: 0x000000000004e4b4
faulting process id: 0x398
faulting application start time: 0x01cd0089bb8a8f90
faulting application path: c:\windows\system32\svchost.exe
faulting module path: c:\windows\system32\ntdll.dll
report id: 0fe60889-6cf5-11e1-8ee5-001e67257e05"

this crash coensides system account log in (possibly scheduled task, although have not found tasks scheduled run @ these times):

an account logged on.


"subject:
security id: system
account name: "servername"$
account domain: ktmk
logon id: 0x3e7


logon type: 5


new logon:
security id: system
account name: system
account domain: nt authority
logon id: 0x3e7
logon guid: {00000000-0000-0000-0000-000000000000}


process information:
process id: 0x214
process name: c:\windows\system32\services.exe


network information:
workstation name:
source network address: -
source port: -


detailed authentication information:
logon process: advapi  
authentication package: negotiate
transited services: -
package name (ntlm only): -
key length: 0"

after svchost crash following services crash:

application experience service
bits
certificate propagation service
group police client
ike , authip ipsec keying modules service
ip helper service
multimedia class scheduler service
user profile service service
task scheduler service
system event notification service service
remote desktop configuration service
themes service
windows management instrumentation service
windows update service

and after wmi reports error id 10:

"event filter query "select * __instancemodificationevent within 60 targetinstance isa "win32_processor" , targetinstance.loadpercentage > 99" not reactivated in namespace "//./root/cimv2" because of error 0x80041003. events cannot delivered through filter until problem corrected."

the strange thing 1 system of 2 same (hardware , software wise) , 1 of these running perfectly, other getting errors.

i appreciate advice.


hello,


it’s hard determine service causing problem. mrx suggested, apply update , check result. suggest update anti-virus , perform full disk scan. run sfc tool , install latest system update readiness tool. start server in clean boot to bypass third-party software , services. if still no luck, consider in-place upgrade. in-place upgrade reinstall system while keep programs , data intact.


thanks
zhang



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN