I have a 2008 R2 RDP server that is fully updated. The print spooler, at seemingly random intervals between 1-3 hours, will log the following informational 7036/7040 entries in the system log in this order:
The start type of the Print Spooler service was changed from auto start to demand start.
The Print Spooler service entered the stopped state.
The start type of the Print Spooler service was changed from demand start to auto start.
The Print Spooler service entered the running state.
This starts and completes in less than one second. I'm fairly certain their is no malware. I have already removed *all* printers but the XPS printer, all non-default HKLM\System\CurrentControlSet\Control\Print driver, monitor, and print processor entries. I restarted the print spooler and the problem still occurred.
I'm trying to figure out how to identify what is changing, stopping, changing, and starting this. I thought maybe procmon but that would be a lot of info to search through and odds are whatever is doing it is triggering a Windows related method to change it (maybe not though. Thoughts?
Note: This is a significant issue because upon the print spooler restarting all redirected printers are offline.