i have a gpo for scheduling a task to automatically restart domain computers at a specific time. I have one executive who works late so I want to disable that gpo for him, and as such, moved him and his computer to new ou's in ad. the scheduled task is now removed from his computer, yet the computer keeps restarting at the scheduled time as if the gpo is still in force. I need help figuring out how to prevent his pc from restarting at 6pm. Below are some logs of interest from the event viewer:
Log Name: System
Source: Service Control Manager
Date: 1/3/2019 6:05:15 PM
Event ID: 7045
Task Category: None
Level: Information
Keywords: Classic
User: CONTOSO\Administrator
Computer: DOMAIN-COMPUTER.CONTOSO.LO
CAL
Description:
A service was installed in the system.
Service Name: PsShutdown
Service File Name: %SystemRoot%\PSSDNSVC.EXE
Service Type: user mode service
Service Start Type: demand start
Service Account: LocalSystem
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-
8e1e-26931
d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="16384">7045</E
ventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80800000000000
00</Keywor
ds>
<TimeCreated SystemTime="2019-01-04T02:
05:15.2258
00600Z" />
<EventRecordID>102234</Eve
ntRecordID
>
<Correlation />
<Execution ProcessID="784" ThreadID="904" />
<Channel>System</Channel>
<Computer>DOMAIN-COMPUTER.
CONTOSO.LO
CAL</Compu
ter>
<Security UserID="S-1-5-21-245992603
1-23432486
86-2500913
731-500" />
</System>
<EventData>
<Data Name="ServiceName">PsShutd
own</Data>
<Data Name="ImagePath">%SystemRo
ot%\PSSDNS
VC.EXE</Da
ta>
<Data Name="ServiceType">user mode service</Data>
<Data Name="StartType">demand start</Data>
<Data Name="AccountName">LocalSy
stem</Data
>
</EventData>
</Event>
Log Name: System
Source: Service Control Manager
Date: 1/3/2019 6:05:15 PM
Event ID: 7030
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DOMAIN-COMPUTER.CONTOSO.LO
CAL
Description:
The PsShutdown service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-
8e1e-26931
d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7030</E
ventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80800000000000
00</Keywor
ds>
<TimeCreated SystemTime="2019-01-04T02:
05:15.2258
00600Z" />
<EventRecordID>102235</Eve
ntRecordID
>
<Correlation />
<Execution ProcessID="784" ThreadID="904" />
<Channel>System</Channel>
<Computer>DOMAIN-COMPUTER.
CONTOSO.LO
CAL</Compu
ter>
<Security />
</System>
<EventData>
<Data Name="param1">PsShutdown</
Data>
</EventData>
</Event>
Log Name: System
Source: USER32
Date: 1/3/2019 6:05:16 PM
Event ID: 1074
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: domain-computer.contoso.LO
CAL
Description:
The process wininit.exe (127.0.0.1) has initiated the restart of computer domain-computer on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API shutdown
Reason Code: 0x80070000
Shutdown Type: restart
Comment:
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="USER32" />
<EventID Qualifiers="32768">1074</E
ventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000
</Keywords
>
<TimeCreated SystemTime="2019-01-04T02:
05:16.0000
00000Z" />
<EventRecordID>102236</Eve
ntRecordID
>
<Channel>System</Channel>
<Computer>domain-computer.
contoso.LO
CAL</Compu
ter>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data>wininit.exe (127.0.0.1)</Data>
<Data>domain-computer</Dat
a>
<Data>Legacy API shutdown</Data>
<Data>0x80070000</Data>
<Data>restart</Data>
<Data>
</Data>
<Data>NT AUTHORITY\SYSTEM</Data>
<Binary>000007800000000000
0000000000
0000000000
0000000000
0000000000
0000000000
0000000000
00</Binary
>
</EventData>
</Event>
Log Name: System
Source: Service Control Manager
Date: 1/3/2019 6:05:16 PM
Event ID: 7036
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: DOMAIN-COMPUTER.CONTOSO.LO
CAL
Description:
The PsShutdown service entered the running state.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-
8e1e-26931
d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="16384">7036</E
ventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80800000000000
00</Keywor
ds>
<TimeCreated SystemTime="2019-01-04T02:
05:16.2398
00600Z" />
<EventRecordID>102238</Eve
ntRecordID
>
<Correlation />
<Execution ProcessID="784" ThreadID="904" />
<Channel>System</Channel>
<Computer>DOMAIN-COMPUTER.
CONTOSO.LO
CAL</Compu
ter>
<Security />
</System>
<EventData>
<Data Name="param1">PsShutdown</
Data>
<Data Name="param2">running</Dat
a>
<Binary>500073005300680075
0074006400
6F0077006E
0053007600
63002F0034
000000</Bi
nary>
</EventData>
</Event>
Log Name: System
Source: Service Control Manager
Date: 1/3/2019 6:05:16 PM
Event ID: 7034
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DOMAIN-COMPUTER.CONTOSO.LO
CAL
Description:
The PsShutdown service terminated unexpectedly. It has done this 1 time(s).
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-
8e1e-26931
d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="49152">7034</E
ventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80800000000000
00</Keywor
ds>
<TimeCreated SystemTime="2019-01-04T02:
05:16.2554
00600Z" />
<EventRecordID>102239</Eve
ntRecordID
>
<Correlation />
<Execution ProcessID="784" ThreadID="924" />
<Channel>System</Channel>
<Computer>DOMAIN-COPMUTER.
CONTOSO.LO
CAL</Compu
ter>
<Security />
</System>
<EventData>
<Data Name="param1">PsShutdown</
Data>
<Data Name="param2">1</Data>
</EventData>
</Event>
Shortly after these events the OS logs kernel power manager and shutdown followed by the restart.
I need to get this behavior to stop, so any help would be GREATLY appreciated.
Thanks in advance.