I've installing and used Windows Server 2008 since early in the beta,
installed it on many physical computers as well as in virtual machines and
this is the first time I've encountered this problem, or anything like it
I had two Server 2008 servers on which the Event Log service is always in
the "Starting" status and I got message boxes popping up saying that the
Windows Module Installer has stopped working. Because the Event Log service
is not running, I could not view the Event Logs.
Although I could logon locally, essentially no roles or features were
DNS service didn't start - this is Active Directory integrated - server
is a domain controller
could not connect to the computer over the network (shares, printers,
Remote Desktop Connection, Computer Management all failed)
I found a few references on the Internet about this situation, but none
provided a solution.
The first server is Windows Server 2008 Enterprise 64 bit with Hyper-V
installed. It has Active Directory Domain Services role and WSUS installed
in the Parent VM (not recommended I know, but this is a small, test
installation). This has been working fine ever since the RTM version of
Server 2008 was installed, a day or so after Server 2008 was initially
released. This server gets shutdown overnight.
When the problem happened, I tried various ways to fix the problem but none
worked. Since the Windows Server Backup wouldn't work, I could not restore
the server from a recent backup. However, eventually, by booting from the
Windows Server 2008 DVD, I was able to restore this server from the backup
and it again working OK (this was the only Domain Controller in this
The second server was a new clean install of Windows Server 2008 Standard 32
bit. The intent was to make this a second domain controller, transfer the
FSMO roles to it, run adprep for Windows Server 2008 R2, then upgrade it to
Windows Server 2008 R2. However, after installing all the available
updates, promoting it to be a domain controller and restarting, the Event
Log service failed to start. Perhaps coincidentally, after the next restart
of the first server, it got the same problem - Event Log service remained in
the Starting state; so now I had two, none functional domain controllers and
panic started. That's when, after trying various suggested methods to fix
this problem I restored the first domain controller from backup - this
backup was from a few days ago before the second domain controller was
Next, I started all over again on the second server:
Clean install of Windows Server 2008 Standard 32 bit (RTM) w/o Hyper-V
installed Service Pack 2
Event Log service stuck in Starting status and pop up messages that Windows
Module Installer has stopped working.
Here's the corrective actions I've taken so far - without success:
1. changed the permissions for the Event Log account for the folder
c:\windows\system32\winevt to Full Control; restart
When I logon (local Administrator account) I get a message box that says
"Windows must be reinstalled. An unauthorized change was made to Windows.
Windows must be re-installed to activate. Insert the Windows installation
DVD or CD into your computer to begin the reinstallations process."
2. start over - boot from DVD, select to format the installation partition,
install Windows Server 2008 32 bit Standard (Full Installation) w/o Hyper-v
a. activated successfully
c. changed computer name
e. install Service Pack 2
f. restarted several times - problem did not resurface
g. in AD Users and Computers, create an OU and use GPMC to Block
Inheritance; create a new computer account for this server in this OU so no
GPOs get applied to this computer
h. join computer to domain; restart several times - system OK
i. remove the block inheritance setting so computer will get the GPOs
applied to the domain level (no other GPOs in the OU path at this point);
restart several times - no problem
j. move the computer account to the OU containing other servers - several
more GPOs are applied to this OU, including one that uses Restricted Groups
to populate the local groups (e.g. Administrators, Remote Desktop Users,
Power Users, Users), and one that configures WSUS.
k. restart; Windows Update Software 7.1.6001.65 was automatically
installed . Control Panel Programs and Features, Installed Updates does not
allow the update (955430) to be uninstalled.
The Event Log service is stuck in the Starting state - the problem is back!
l. install the HotFix from KB 952664- get the message "The update does not
apply to your system".
Anyone have any idea how to correct this problem?
It is perfectly useless to know the right answer to the wrong question.