Server shutdown randomly - winlogon.exe + other clues


hello,

this has started happening since last week. every day (sometimes more once), server (windows server 2003) shut-down or restart itself.

i've investigated in event viewer, , noticed 2 things:

1. every single time happens, in system log, has "the process winlogon.exe has initiated power off of computer", , user32.

2. in security log, @ exact same time above "winlogon.exe", see entry "attempted logon microsoft_authentication_package_v1_0". within seconds of logon, server shuts down itself.

i've ran 2 virus scans, , monitored in process explorer suspicious processes, found nothing. looks shutdown directly related logon attempt.

any appreciated, extremely troublesome.

thank you.

is user32 normal domain account? what's account for? test, temporarily disable account , check result.


Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS