Article ID: 2132080 - Last Review: May 26, 2010 - Revision: 2.0

[SDP 2][C3A235A7-80DC-437B-ADC7-15C57161CD26] Exchange Server 2003 Troubleshooter for Windows Server 2003

System TipThis article applies to a different operating system than the one you are using. Article content that may not be relevant to you is disabled.
Expand all | Collapse all

SUMMARY

The Exchange Server 2003 Troubleshooter for Windows 2003 was designed to collect a comprehensive set of information for troubleshooting Exchange Server 2003 issues.

MORE INFORMATION

This article describes information that may be collected from a machine when running Exchange Server 2003 Troubleshooter for Windows Server 2003. Output file names are generally prefixed {prefix} with the name of the item for which output was generated (<computer name> <cluster name> <storage group name> <database name>, for example), exceptions are noted below:

Information Collected

Exchange Server and Organization Baseline
Collapse this tableExpand this table
DescriptionFile Name
Exchange Best Practices Analyzer Health Check including Organization, Administrative Groups and local Exchange Server in run-scope via exbpacmd.exe utility{prefix}_ExBPA.xml
Log from Exchange Best Practices Analyzer Health Check{prefix}_ExBPA.xml.log
Exchange organization, configuration and permissions information via exchdump.exe utility{prefix}_ExchDump_<date>_<time>
.HTM and .XML
Exchange Server Setup Progress Log from %SystemDrive%{prefix}_Exchange Server Setup Progress.log
Exchange Server Deployment Tools logs from %SystemDrive%\ExDepl~1\*.*{prefix}_<ExDeploy Log Name>
Information store function call logging file{prefix}_store.fcl
File version information from Exchange\*.exe, *.dll{prefix}_sym_Exchange_EXE_DLL.*
HKLM\SOFTWARE\Microsoft\Exchange{prefix}_reg_Exchange.TXT
HKLM\System\CurrentControlSet\Services:
  MSExchangeActiveSyncNotify
  MSExchangeADDXA
  MSExchangeAL
  MSExchangeDSAccess
  MSExchangeES
  MSExchangeFBPublish
  MSExchangeIS
  MSExchangeMGMT
  MSExchangeMTA
  MSExchangeMU
  MSExchangeOMA
  MSExchangeSA
  MSExchangeSenderID
  MSExchangeTransport
  MSExchangeUCF
  MSExchangeWEB
{prefix}_reg_Exchange.TXT
HKLM\Software\Microsoft\MosTrace\CurrentVersion\DebugAsyncTrace{prefix}_reg_Exchange.TXT
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\STORE.EXE{prefix}_reg_Exchange.TXT

Event Logs
Collapse this tableExpand this table
DescriptionFile Name
Event Log – Application – text, csv and evt formats{prefix}_evt_Application.*
Event Log – System – text, csv, and evt formats{prefix}_evt_System.*
Event Logs – PowerShell – text, csv and evt formats{prefix}_evt_*PowerShell*.*

File Version Information
Collapse this tableExpand this table
DescriptionFile Name
File version information from %windir%\cluster\*.*{prefix}_sym_Cluster.*
File version information from %windir%\system32\inetsrv\*.exe, *.dll{prefix}_sym_InetSrv_EXE_DLL.*
File version information from %windir%\system32\drivers\*.*{prefix}_sym_Drivers.*
File version information from {Program Files}\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*{prefix}_sym_MS_Iscsi.*
File version information from all drivers currently running on machine{prefix}_sym_RunningDrivers.*
File version information from all processes currently running on machine{prefix}_sym_Process.*

Registry Keys and Values
Collapse this tableExpand this table
DescriptionFile Name
HKLM\Software\Microsoft\Windows NT\CurrentVersion

HKLM\Software\Microsoft\Windows\CurrentVersion
{prefix}_reg_CurrentVersion.TXT
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{prefix}_reg_Uninstall.TXT
HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions{prefix}_reg_ProductOptions.TXT
HKLM\System\MountedDevices{prefix}_reg_MountedDevices.*
HKLM\System\CurrentControlSet\Control\CrashControl
HKLM\System\CurrentControlSet\Control\Session Manager
HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management
HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\Software\Microsoft\Windows\Windows Error Reporting
HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting
{prefix}_reg_Recovery.TXT
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\ Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Runonce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Load
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
{prefix}_reg_Startup.TXT
HKLM\SYSTEM\CurrentControlSet\Control\Print{prefix}_reg_Print.hiv
HKCU\Software\Policies
HKLM\Software\Policies
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
{prefix}_reg_Policies.txt
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
{prefix}_reg_TimeZone.txt
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server Web Access
HKLM\SYSTEM\CurrentControlSet\Services\TermService
HKLM\SYSTEM\CurrentControlSet\Services\TermDD
{prefix}_reg_TermServices.txt
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer
HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb
HKLM\SYSTEM\CurrentControlSet\Services\SMB
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb10
HKLM\SYSTEM\CurrentControlSet\Services\MRxSmb20
{prefix}_reg_SMB.txt
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters{prefix}_reg_TCPIPParameters
HKLM\SYSTEM\CurrentControlSet\Services\VSS{prefix}_reg_VSS.TXT
HKLM\SYSTEM\CurrentControlSet\Services\iScsiPrt
HKLM\SOFTWARE\Microsoft\iSCSI Target
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\iSCSI
{prefix}_reg_iSCSI.TXT
HKLM\System\CurrentControlSet\Control\MPDev
HKLM\System\CurrentControlSet\Control\iSCSIPrt
HKLM\System\CurrentControlSet\Services\MSiSCSI
HKLM\System\CurrentControlSet\Services\MSDsm
HKLM\System\CurrentControlSet\Services\MPIO
HKLM\System\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}
HKLM\System\CurrentControlSet\Services\Tcpip
{prefix}_reg_Storage.TXT

Networking Information
Collapse this tableExpand this table
DescriptionFile Name
Output from the netdiag.exe utility{prefix}_netdiag.txt
DNS client information from ipconfig displaydns{prefix}_DnsClient-DnsCache.TXT
DNS server information from dnscmd /info{prefix}_DnsServer-DnsCmd.TXT
Firewall information from netsh firewall(prefix}_Firewall-Netsh-Fw.TXT
Ipsec information from netsh ipsec{prefix}_Ipsec-Netsh.TXT
Network configuration information from netsh dump{prefix}_Netsh-Dump.TXT
Basic IP networking configuration information, such as Tcp/ip registry key, ipconfig, netstat, nbtstat and netsh output{prefix}_TcpIp-Info.txt
TCPIP offload and configuration information, such as Tcp/ip parameters registry key, netstat, and netsh output{prefix}_TCPIP-Info-OFFLOAD.TXT
Netsh information for IPv4{prefix}_TCPIP-Netsh-IPv4.TXT
Netsh information for IPv6{prefix}_TCPIP-Netsh-IPv6.TXT
Netsh information for TCP global and chimney{prefix}_TCPIP-Netsh-TCP.TXT

Active Directory and Policy Information
Collapse this tableExpand this table
DescriptionFile Name
Resultant Set of Policy (RSoP) information via gpresult.exe{prefix}_GPResult.*
Security templates currently cached on the system{prefix}_AppliedSecTempl.txt
Report of user rights and privileges on the local machine{prefix}_USERRIGHTS.TXT
FSMO role owner information via netdom{prefix}_netdomfsmo.txt
Output from DCDiag.exe diagnostic utility{prefix}_dcdiag.txt
Output from RepAdmin.exe diagnostic utility{prefix}_repadmin.txt
Output from Group Policy Consistency Checker (GPOTool.exe) {prefix}_gpotool.txt

Collapse this tableExpand this table
DescriptionFile Name
Cluster Configuration information{prefix}_CLUSTER_MPS_INFORMATION.TXT
File version information from %windir%\cluster\*.*{prefix}_sym_Cluster.* or {prefix}_CLUSTER_DIR.TXT
Cluster resource properties{prefix}_CLUSTER_RES_PROPERTIES_ALL.TXT
List of cluster resources{prefix}_CLUSTER_RESOURCES.TXT
Files from %windir%\cluster\*chkdsk*{prefix}_*chkdsk*
Copy of cluster configuration log file ClCfgSrv.log{prefix}_ClCfgSrv.log
Copy of cluster.log file{prefix}_Cluster.log
Copy of the file %windir%\cluster\ClusPrepCfg.xml used to customize Validation{prefix}_CLusPrepCfg.xml
HKLM\System\CurrentControlSet\Services\clusdisk{prefix}_Clusdisk.txt
HKLM\System\CurrentControlSet\Services\clussvc{prefix}_ClussvcRegistry.txt
HKEY_LOCAL_MACHINE\Cluster in .txt and .hiv formats{prefix}_ClusterRegistry.*

Hotfixes and Updates
Collapse this tableExpand this table
DescriptionFile Name
Installed updates and hotfixes{prefix}_Hotfixes .HTM and .TXT
WindowsUpdate.log file located in windows folder{prefix}_WindowsUpdate.log

Storage / Disk Information
Collapse this tableExpand this table
DescriptionFile Name
iSCSI related information generated by iscsicli.exe utility{prefix}_ISCSI*.txt
Fibre Channel Information via FCInfo.exe utility{prefix}_FCInfo.txt
Volume Shadow Copy Service (VSS) information{prefix}_VSSAdmin.txt

Other
Collapse this tableExpand this table
DescriptionFile Name
System information output via msinfo32.exe{prefix}_msinfo.*
Copy of metabase.xml{prefix}_metabase.xml
Process and threads information via pstat.exe{prefix}_PSTAT.txt
Operating system Boot options file (Boot.ini){prefix}_BOOT.INI
Output from Driver Verifier Manager (verifier.exe) utility{prefix}_Verifier.txt
Report of all tasks scheduled on the local computer{prefix}_schtasks.*

Additional Information

In additional to the files collected and listed above, this troubleshooter can detect one or more of the following situations:
  • Machine is running under a hardware virtualization environment
  • Presence of machine memory dumps in the past 30 days
  • Presence of user mode memory dumps in the past 30 days
  • Configuration or services that could prevent a memory dump from being generated
  • Unexpected Shutdown Event Logs in the System Log from past 30 days
  • Machine Memory Dump related event logs in the System log from past 30 days
  • Processes with a high number of handles
  • A low number of System Page Table entries (PTEs)
  • Low available memory condition
  • Any Kernel pool memory tag using more than 60% of all allocated memory
  • Non-Supported version of a Service Pack
  • Non-Supported operating system version

References

KB 926079 - Frequently asked questions about the Microsoft Support Diagnostic Tool (MSDT)
http://support.microsoft.com/kb/926079 (http://support.microsoft.com/kb/926079)
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use (http://go.microsoft.com/fwlink/?LinkId=151500) for other considerations.

APPLIES TO
  • Microsoft Exchange Server 2003 Standard Edition
  • Microsoft Exchange Server 2003 Enterprise Edition
  • Microsoft Exchange Server 2003 Service Pack 1
  • Microsoft Exchange Server 2003 Service Pack 2
Keywords: 
kbsurveynew KB2132080