To troubleshoot this kind of kernel crash issue, we need to debug the crashed system dump. This ONLY happens when the Lansweeper Service is running.Handles attachments Errorlog.txt (84kb) downloaded 58 time(s). TECHNOLOGY IN THIS DISCUSSION Microsoft Microsoft Wind...Server 2012 R2 Read these next... © Copyright 2006-2017 Spiceworks Inc. also if any updates were installed you generally get events for them in the system event log. have a peek here
until today 4 p.m. (or possibly several overlapping sessions). Not a member? By all means use it as a tool short term, but leaving a PC open to others to remotely control at any time can't be a good idea.Click to expand... At 11:15am everyday starting 9/29/09 my 2003 system reboots.
Something isn't right. However, as far as I can see, such reboots should happen at most at about 3 a.m. It is stopping & starting.Click to expand... Thanks! 0 LVL 10 Overall: Level 10 MS Legacy OS 4 Windows Server 2008 4 Message Expert Comment by:Kezzi ID: 370568982011-10-31 check the c:\windows\windowsupdate.log to see if it corresponds with
What a pain! Doesn't starting Windows in 'Safe Mode' work on machines these days? It may be some application causing some seroius error, and making the server shutdown. Event Id 1074 Legacy Api Shutdown The windows event logs would be another good place to look.
The culprit now appears to be Windows Update(AU). Event Id 1074 User32 The odd thing it's a restart that's been initiated and not a shutdown... Custom search for *****: Google - Bing - Microsoft - Yahoo Feedback: Send comments or solutions - Notify me when updated Printer friendly Subscribe Subscribe to EventID.Net now!Already a subscriber? Notquiteretired, Jan 29, 2015 #33 Fergieman Member Location: Northumberland This was the first one which will be when the PC was checked over and supplied.
The following corrective action will be taken in 120000 milliseconds: Restart the service.Event Xml:
Friday, January 15, 2010 6:31 PM Reply | Quote 0 Sign in to vote I found the same problem when a vendor, running an application, noticed it caused a shutdown. TheEventId.Net for Splunk Add-onassumes thatSplunkis collecting information from Windows servers and workstation via the Splunk Universal Forwarder. Event Id 1074 Reason Code 0x500ff It has done this 1 time(s). Event Id 109 If they set the rule to apply updates until hh:mm , SCCM will reboot the servers right at that time. 0 LVL 31 Overall: Level 31 Windows Server 2008
Processes related the user's environment such as Exlorer.exe or Winlogon indicate that the shutdown was initiated by a user while other type of processes such as svchost.exe. http://blackplanetsupport.com/event-id/event-id-10016-source-dcom-nt-authority-network-service.html The teamviewer one looks like remote support doing something. Don't give the code to scammers and do shut down Teamviewer after you finish with it. Browse other questions tagged windows-server-2008-r2 wsus or ask your own question. Event Id 1074 Reason Code 0x800000ff
You can then use this information to analyze shutdowns and to develop a more comprehensive understanding of your system environment. Clean Boot the Windows Server 2003 manually a. Click Start, type msconfig in the Start Search box, and then press ENTER. The SCCM team has already denied that it was them and before I push the issue with them I need to do my due diligence to eliminate other possibilities. Check This Out Notquiteretired, Jan 29, 2015 #29 Cowabunga Member Location: Ceredigion,Wales Notquiteretired said: ↑ To make support easier teamviewer can to set to be always allow connection from a trusted party.
Our maximum servers are pending for reboot and waiting for their maintenance windows to get restarted after patch installation. i.e. I am having a similiar issue of users restarting my Citrix/RDS servers when listening to a Cisco ViewMail message. Event Id 1076 It has done this 1 time(s).Event Xml:
See ME293814 and MSW2KDB for more details. For this topic, you can use Windows Server forum for General issues. For your convenience, I made some research on this issue and based on the similar cases reported, the Friday, February 05, 2010 3:44 PM Reply | Quote 0 Sign in to vote The process svchost.exe has initiated the restart of computerXYZ on behalf of user NT AUTHORITY\SYSTEM for the this contact form Unfortunately, debugging is beyond what we can do in the forum.
Difference between if else and && || What is the "crystal ball" in the meteorological station? The process svchost.exe has initiated the restart of computer CTXSVR on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found Reason Code: 0x80070020 Teamviewer would indicate someone remotely shut it down...Click to expand... Well, there might be...
Clean Boot the Windows Server 2003 manually a. Click Start, type msconfig in the Start Search box, and then press ENTER. Update: The nearest event log entries around the shutdown with source WindowsUpdateClient were: immediately after the event#1074 above: Event#27 "Automatic Updates" has been stopped at 13:00 (almost 3 hours before shutdown): support.microsoft.com/kb/2001061I know it is an old article but I can't seem to find an update for this 0 Thai Pepper OP Stephen4570 Oct 22, 2014 at 5:32 UTC For the purposes of this article it doesn’t really matter which so w… Windows Server 2008 Security-Only or Monthly-Rollup: That is the update question.
b. On the General tab, click Selective startup. That great Exchange/Office 365 signature you've created will just appear at the bottom of an email chain.