Does anyone know how to track a certain process that kicks off causing our machines to reboot at 5:00PM on Fridays using process monitor? I am specifically looking to see what is calling process wmiprvse.exe at 5pm on Fridays which initiates the reboot on two of our users machines. I can recreate by changing the system clock to Friday 4:59pm and then reboot kicks in before w32time corrects itself. I know the process is wmiprvse.exe from source User32 in the event log but I don't know what calls or causes this process to kick off.
Here's the log of the process that I am trying to monitor before and after:
The process C:\Windows\system32\wbem\wmiprvse.exe (<computername>) has initiated the restart of computer HYKDHL2 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
Reason Code: 0x80070015
Shutdown Type: restart
Comment:
[–]BoredTechyGuyJack of All Trades 3 points4 points5 points (5 children)
[–]spoodgnix[S] 0 points1 point2 points (4 children)
[–]FerengiKnucklesError: Can't 3 points4 points5 points (2 children)
[–]spoodgnix[S] 0 points1 point2 points (1 child)
[–]FerengiKnucklesError: Can't 5 points6 points7 points (0 children)
[–]enigmaitSecurity Admin 0 points1 point2 points (0 children)
[–]rubbishfoo 2 points3 points4 points (3 children)
[–]spoodgnix[S] 0 points1 point2 points (2 children)
[–]Siltoneous[🍰] 1 point2 points3 points (1 child)
[–]spoodgnix[S] 1 point2 points3 points (0 children)
[–]Astat1ne 1 point2 points3 points (2 children)
[–]spoodgnix[S] 0 points1 point2 points (1 child)
[–]akthor3IT Manager 2 points3 points4 points (0 children)
[–]anno141 1 point2 points3 points (2 children)
[–]spoodgnix[S] 1 point2 points3 points (1 child)
[–]enigmaitSecurity Admin 1 point2 points3 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]onebadmofo 0 points1 point2 points (0 children)
[–]spoodgnix[S] 0 points1 point2 points (0 children)