For the last three days, I’ve been troubleshooting a problem with my primary server, which provides a variety of services on our network and we rely on it a lot. Monday morning, I came to work to see that the screen was frozen on a blank gray background. The server didn’t respond to anything; the only way to get it back working was to force it off with the power button.
After rebooting, I scanned the event logs and found several errors. Throughout the day the server would work for a couple of hours and then quit. After doing some research I removed a couple of applications, and reinstalled the NIC drivers (the latter by recommendation and guidance of Dell). However, after removing the unnecessary applications and reinstalling these drivers, I still was unable to solve the problem.
In reading the logs again, my research led me to a few incorrect settings in DNS. So, of course, I went to the DNS manager and scanned through every setting and found a couple of discrepancies. After making these corrections and rebooting the server, I gained an average of 12 hours of stable use.
The problem has not gone away yet and I’m expecting later this afternoon having to reboot again. The one error that seems to come up frequently is the following:
Event ID: 1000, Source: Application Error, Date: 1/7/2009, Time: 6:24:13 AM
Faulting application svchost.exe, version 5.2.3790.3959, faulting module ntdll.dll, version 5.2.3790.3959, fault address 0x0000000000011f8d.
or this error
Event ID: 1004, Source: Application Error, Date: 1/6/2009, Time: 3:39:36 PM
Reporting queued error: faulting application svchost.exe, version 5.2.3790.3959, faulting module ntdll.dll, version 5.2.3790.3959, fault address 0x000000000003aee2.
Another error that I see often is the following:
Event ID: 1001, Source: Application Error, Date: 1/7/2009, Time: 7:41:27 AM
Fault bucket 00307075.