About a month ago, our domain controller started rebooting spontaneously. A popup box similar to what one would see on a computer infected with Sasser or Blaster pops up with the following message: "The system process c:windowssystem32services.exe terminated unexpectedly with status code 128. The system will now shut down and restart."
This happens at least once a week, sometimes twice a week. I have a small script running that intercepts the shutdown command before it can bounce my server. Other times, services.exe will crash, but NOT take down my server; it only kills services or apps that are running (SQL Server, Trend Micro OfficeScan, Apache Web Server, basically anything running in the systray). Backup Exec will run, but it shows the status of its services as "unknown." From that point on, clients can still log in and get access to server resources, and I can still use Active Directory, but I cannot run ANY Administrative Tools, nor can I bring up the Event Viewer. I am also unable to log in at the console or through RDP if I'm not already running a session. When I *am* able, the desktop can take up to ten minutes to load.
When I try to get to the Event Log or the Services applet via the management console on my client PC, I get the following error: "The RPC Server is unavailable." The only thing that fixes this is an abrupt power down/power up of the server. There is never anything in the event logs that indicates there was a problem. This latter problem also occurs once or twice a week. It's as if the server wanted to shut down, but couldn't. Restarting services.exe does not help.
Here is what I've already tried:
--Steps in Microsoft KB 318447. No nonexistent shares were indicated.
--Ran a full virus/malware scan using Trend Micro OfficeScan AND Trend Micro House Call. Nothing found.
--Ran fixblaster.exe and fixsasser.exe, just to be sure. Neither program was found.
--Ran Spybot S&D twice. Nothing found.
--Ran Hijackthis. Logfile follows:
Any help would be greatly appreciated. I'm stumped.