SBS 2003 sp2
We have have 4 backups that run nightly, one system state to usb, one for the c drive to usb, one for the d drive to usb and one usb to tape. About once a week one of them will fail, not always the same one, and not always the same time, but always event ID 4354 source eventsystem and ID 12302 source VSS. I've pasted the event ID's below, the backup log and some information I've see common to this problem like vssadmin list writers. we've been working on this problem for a while now and would appreciate any assistance.
Per http://support.microsoft.com/kb/940032 we've re-registered the listed dll files.
Per http://support.microsoft.com/kb/907574 I've checked HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Catalogs and all sub keys have locations.
Event ID info
----------------------
Event Type: Warning
Event Source: EventSystem
Event Category: (52)
Event ID: 4354
Date: 5/8/2009
Time: 9:05:48 PM
User: N/A
Computer: MAHMAIN
Description:
The COM+ Event System failed to fire the RequestWriterInfo method on subscription {09F06CA7-662B-4BD1-B4AB-BB40A1B52BD2}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 8002801D.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: VSS
Event Category: None
Event ID: 12302
Date: 5/8/2009
Time: 9:05:50 PM
User: N/A
Computer: MAHMAIN
Description:
Volume Shadow Copy Service error: An internal inconsistency was detected in trying to contact shadow copy service writers. Please check to see that the Event Service and Volume Shadow Copy Service are operating properly.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2d 20 43 6f 64 65 3a 20 - Code:
0008: 42 55 45 43 58 4d 4c 43 BUECXMLC
0010: 30 30 30 30 37 32 38 33 00007283
0018: 2d 20 43 61 6c 6c 3a 20 - Call:
0020: 42 55 45 43 58 4d 4c 43 BUECXMLC
0028: 30 30 30 30 37 32 31 39 00007219
0030: 2d 20 50 49 44 3a 20 20 - PID:
0038: 30 30 30 30 33 30 31 32 00003012
0040: 2d 20 54 49 44 3a 20 20 - TID:
0048: 30 30 30 31 33 37 32 38 00013728
0050: 2d 20 43 4d 44 3a 20 20 - CMD:
0058: 43 3a 5c 57 49 4e 44 4f C:\WINDO
0060: 57 53 5c 73 79 73 74 65 WS\syste
0068: 6d 33 32 5c 6e 74 62 61 m32\ntba
0070: 63 6b 75 70 2e 65 78 65 ckup.exe
0078: 20 62 61 63 6b 75 70 20 backup
0080: 22 40 43 3a 5c 44 6f 63 "@C:\Doc
0088: 75 6d 65 6e 74 73 20 61 uments a
0090: 6e 64 20 53 65 74 74 69 nd Setti
0098: 6e 67 73 5c 6e 78 73 74 ngs\nxst
00a0: 65 63 68 5c 4c 6f 63 61 ech\Loca
00a8: 6c 20 53 65 74 74 69 6e l Settin
00b0: 67 73 5c 41 70 70 6c 69 gs\Appli
00b8: 63 61 74 69 6f 6e 20 44 cation D
00c0: 61 74 61 5c 4d 69 63 72 ata\Micr
00c8: 6f 73 6f 66 74 5c 57 69 osoft\Wi
00d0: 6e 64 6f 77 73 20 4e 54 ndows NT
00d8: 5c 4e 54 42 61 63 6b 75 \NTBacku
00e0: 70 5c 64 61 74 61 5c 4d p\data\M
00e8: 41 48 4d 61 69 6e 4e 69 AHMainNi
00f0: 67 68 74 6c 79 53 79 73 ghtlySys
00f8: 74 65 6d 53 74 61 74 65 temState
0100: 2e 62 6b 73 22 20 2f 61 .bks" /a
0108: 20 2f 64 20 22 4d 41 48 /d "MAH
0110: 4d 61 69 6e 4e 69 67 68 MainNigh
0118: 74 6c 79 53 79 73 74 65 tlySyste
0120: 6d 53 74 61 74 65 20 46 mState F
0128: 72 69 2d 30 35 2d 30 38 ri-05-08
0130: 2d 32 30 30 39 2d 30 39 -2009-09
0138: 2d 30 35 22 20 2f 76 3a -05" /v:
0140: 6e 6f 20 2f 72 3a 6e 6f no /r:no
0148: 20 2f 72 73 3a 6e 6f 20 /rs:no
0150: 2f 68 63 3a 6f 66 66 20 /hc:off
0158: 2f 6d 20 6e 6f 72 6d 61 /m norma
0160: 6c 20 2f 6a 20 22 4d 41 l /j "MA
0168: 48 4d 61 69 6e 4e 69 67 HMainNig
0170: 68 74 6c 79 53 79 73 74 htlySyst
0178: 65 6d 53 74 61 74 65 22 emState"
0180: 20 2f 6c 3a 73 20 2f 66 /l:s /f
0188: 20 22 46 3a 5c 62 61 63 "F:\bac
0190: 6b 75 70 5c 4d 41 48 4d kup\MAHM
0198: 61 69 6e 4e 69 67 68 74 ainNight
01a0: 6c 79 53 79 73 74 65 6d lySystem
01a8: 53 74 61 74 65 2e 62 6b State.bk
01b0: 66 22 20 20 20 20 20 20 f"
01b8: 2d 20 55 73 65 72 3a 20 - User:
01c0: 4d 41 48 5c 6e 78 73 74 MAH\nxst
01c8: 65 63 68 20 20 20 20 20 ech
01d0: 2d 20 53 69 64 3a 20 20 - Sid:
01d8: 53 2d 31 2d 35 2d 32 31 S-1-5-21
01e0: 2d 32 36 31 35 39 38 35 -2615985
01e8: 35 33 39 2d 31 31 33 34 539-1134
01f0: 36 30 36 32 34 34 2d 31 606244-1
01f8: 33 32 38 31 34 38 34 35 32814845
0200: 38 2d 31 31 33 36 20 20 8-1136
Event Type: Error
Event Source: NTBackup
Event Category: None
Event ID: 8019
Date: 5/8/2009
Time: 9:10:47 PM
User: N/A
Computer: MAHMAIN
Description:
End Operation: Warnings or errors were encountered.
Consult the backup report for more details.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
ntbackup log
----------------------
Backup Status
Operation: Backup
Active backup destination: File
Media name: "MAHMainNightlySystemState.bkf created 5/8/2009 at 9:05 PM"
Volume shadow copy creation: Attempt 1.
Timeout before function completed
Error returned while creating the volume shadow copy:0xffffffff.
Error returned while creating the volume shadow copy:ffffffff
Aborting Backup.
----------------------
The operation did not successfully complete.
----------------------
vss list writers and providers
----------------------
C:\>vssadmin list writers
vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001 Microsoft Corp.
Writer name: 'System Writer'
Writer Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Instance Id: {13a88806-24d8-44d8-b34d-4abac63dccef}
State: [5] Waiting for completion
Last error: No error
Writer name: 'MSDEWriter'
Writer Id: {f8544ac1-0611-4fa5-b04b-f7ee00b03277}
Writer Instance Id: {10665000-25b4-483b-b494-f81f5f66c118}
State: [1] Stable
Last error: No error
Writer name: 'Removable Storage Manager'
Writer Id: {5d3c3e01-0297-445b-aa81-a48d7151e235}
Writer Instance Id: {29f0f445-1d4a-4739-97be-3e464a65bd1d}
State: [1] Stable
Last error: No error
Writer name: 'Registry Writer'
Writer Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
Writer Instance Id: {5183990d-b8ce-44a6-8d35-06607b5b8da2}
State: [1] Stable
Last error: No error
Writer name: 'Event Log Writer'
Writer Id: {eee8c692-67ed-4250-8d86-390603070d00}
Writer Instance Id: {fd4c78a0-6cd0-4fe4-b6e8-0dc6a32ff889}
State: [1] Stable
Last error: No error
Writer name: 'COM+ REGDB Writer'
Writer Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
Writer Instance Id: {9b85e8ad-45a3-4af6-b61e-822df2ac0f4b}
State: [1] Stable
Last error: No error
Writer name: 'FRS Writer'
Writer Id: {d76f5a28-3092-4589-ba48-2958fb88ce29}
Writer Instance Id: {efb53afd-1204-4799-b1c9-8535700e96a8}
State: [5] Waiting for completion
Last error: No error
Writer name: 'WMI Writer'
Writer Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
Writer Instance Id: {7702f1a9-fe8e-48f3-a0f5-8b16f27feeff}
State: [5] Waiting for completion
Last error: No error
Writer name: 'IIS Metabase Writer'
Writer Id: {59b1f0cf-90ef-465f-9609-6ca8b2938366}
Writer Instance Id: {befcb464-e768-4517-8148-43d68e7a8b8f}
State: [5] Waiting for completion
Last error: No error
Writer name: 'WINS Jet Writer'
Writer Id: {f08c1483-8407-4a26-8c26-6c267a629741}
Writer Instance Id: {6cdae8f5-afc1-46a6-97af-37b6f7dd4775}
State: [5] Waiting for completion
Last error: No error
Writer name: 'NTDS'
Writer Id: {b2014c9e-8711-4c5c-a5a9-3cf384484757}
Writer Instance Id: {03113b19-a80a-4f23-8def-840b40c86098}
State: [1] Stable
Last error: No error
Writer name: 'Dhcp Jet Writer'
Writer Id: {be9ac81e-3619-421f-920f-4c6fea9e93ad}
Writer Instance Id: {ed938b85-66d7-4e15-a86c-ed559ae9b93b}
State: [5] Waiting for completion
Last error: No error
C:\>vssadmin list providers
vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001 Microsoft Corp.
Provider name: 'Microsoft Software Shadow Copy provider 1.0'
Provider type: System
Provider Id: {b5946137-7b9f-4925-af80-51abd60b20d5}
Version: 1.0.0.7