locked
F-Secure and Unexpected Shutdown RRS feed

  • Question

  • Any one else experience this?

    On 6/1/09 my server shut itself off sometime early in the morning (about 8 minutes after 4:00AM).  When I turned it back on and checked the log it showed the last shutdown as unexpected.  This morning 7/1/09 the same thing occured.  I noticed that F-Secure for WHS is setup to start a monthly scan at 4:00AM on the first of every month.  The scheduled task log shows the task starting and only running for about 4 minutes.  Then the server unexpectedly shut down.

    I have disabled the monthly file scan as it is probably not necessary since I am using real time protection.

    Any ideas?
    Thursday, July 2, 2009 3:01 AM

All replies

  • Any one else experience this?

    On 6/1/09 my server shut itself off sometime early in the morning (about 8 minutes after 4:00AM).  When I turned it back on and checked the log it showed the last shutdown as unexpected.  This morning 7/1/09 the same thing occured.  I noticed that F-Secure for WHS is setup to start a monthly scan at 4:00AM on the first of every month.  The scheduled task log shows the task starting and only running for about 4 minutes.  Then the server unexpectedly shut down.

    I have disabled the monthly file scan as it is probably not necessary since I am using real time protection.

    Any ideas?

    Is there a MEMORY.DMP file in C:\Windows?  The system is probably bugchecking during the scan.

    If you have a Memory dump, we can analyze it and tell you if that is what is happening. The best way to get that to us is to file a bug on Connect and then we will provide you with an upload location (Connect won't allow large attachments).


    Thanks!

    Lara Jones [MSFT] | Program Manager
    Community Support and Beta | Windows Home Server Team
    Windows Home Server Team Blog
    Connect Windows Home Server
    Windows Home Server
    Thursday, July 2, 2009 3:08 AM
    Moderator

  • Is there a MEMORY.DMP file in C:\Windows?  The system is probably bugchecking during the scan.

    If you have a Memory dump, we can analyze it and tell you if that is what is happening. The best way to get that to us is to file a bug on Connect and then we will provide you with an upload location (Connect won't allow large attachments).


    Thanks!

    Lara Jones [MSFT] | Program Manager
    Community Support and Beta | Windows Home Server Team
    Windows Home Server Team Blog
    Connect Windows Home Server
    Windows Home Server


    Lara - There is a memory dump file in C:\Windows, but it is from April 12 2009 and I am not sure what happened on that day.  It seems the last two events which seem to be related to the virus scan did not produce a MEMORY.DMP

    Is there anything else I can provide to help investigate?

    Here are the two warnings that have occured each time:

    The plug and play manager error also occured on 4/1/09 and 2/1/09 but without being followed by an unexpected shutdown.  Funny I wonder if LEGACY_FSBL is an F-Secure driver of some sort?

    Event Type: Error
    Event Source: EventLog
    Event Category: None
    Event ID: 6008
    Date:  6/1/2009
    Time:  6:41:32 AM
    User:  N/A
    Computer: SERVER
    Description:
    The previous system shutdown at 4:41:56 AM on 6/1/2009 was unexpected.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: d9 07 06 00 01 00 01 00   Ù.......
    0008: 04 00 29 00 38 00 f9 01   ..).8.ù.
    0010: d9 07 06 00 01 00 01 00   Ù.......
    0018: 0b 00 29 00 38 00 f9 01   ..).8.ù.

    Event Type: Error
    Event Source: PlugPlayManager
    Event Category: None
    Event ID: 11
    Date:  6/1/2009
    Time:  4:18:24 AM
    User:  N/A
    Computer: SERVER
    Description:
    The device Root\LEGACY_FSBL\0000 disappeared from the system without first being prepared for removal.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: 00 00 00 00               ....   


    Event Type: Error
    Event Source: EventLog
    Event Category: None
    Event ID: 6008
    Date:  7/1/2009
    Time:  12:01:14 PM
    User:  N/A
    Computer: SERVER
    Description:
    The previous system shutdown at 4:08:24 AM on 7/1/2009 was unexpected.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: d9 07 07 00 03 00 01 00   Ù.......
    0008: 04 00 08 00 18 00 9f 02   ......Ÿ.
    0010: d9 07 07 00 03 00 01 00   Ù.......
    0018: 0b 00 08 00 18 00 9f 02   ......Ÿ.

     Event Type: Error
    Event Source: PlugPlayManager
    Event Category: None
    Event ID: 11
    Date:  7/1/2009
    Time:  4:02:40 AM
    User:  N/A
    Computer: SERVER
    Description:
    The device Root\LEGACY_FSBL\0000 disappeared from the system without first being prepared for removal.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: 00 00 00 00               ....   


    Thanks

    Thursday, July 2, 2009 6:10 AM