BloodModeratorDecember 3, 2018 at 7:21 am #609947
I was going through the events on our 2008 data server after it rebooted unexpectedly. One of the events referenced a service I’ve not seen before:
Log Name: System
Source: Service Control Manager
Date: 03/12/2018 10:44:46
Event ID: 7036
Task Category: None
The FieldMILIService service entered the running state.
This is followed by ‘… entered the stopped state’ one second later.
I am getting no results from a web search. I have been through all the services listed in services.msc and looked at ‘Properties > General tab > Service name’ but nothing matches. We have Sophos installed and nothing apart from the usual PUA’s (PSKill etc., from SysInternals) has been detected. Enumerating all services via PowerShell: Get-WmiObject win32_service | Select Name, DisplayName, State, StartMode | Sort State, Name does not list this service.
Has anyone come across this service before?
Just searched through the System log and it has cropped up before – during each restart (I usually filter out 7036 events when scanning the logs – whoops!).
- This topic was modified 2 weeks, 1 day ago by Blood. Reason: Additional info
RicklesPParticipantDecember 3, 2018 at 3:41 pm #609982
Blood, have you tried searching the registry for that service name, or some part of it like ‘fieldmili’ or ‘miliservice’, for example? Or how about just looking at reg keys like “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run” or “…RunOnce”, and of course the Wow6432 node of same: “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run” or “RunOnce”, to see if there’s anything called out which you can’t otherwise account for.
Granted that’s a bit manual, but esp. if it’s some legacy thing that (big assumption here, based on the computer name) the NHS still has on its systems, it may be the only way to identify the guilty party.
BloodModeratorDecember 4, 2018 at 5:14 am #610010
Thanks very much for the suggestion. I used SysInternals’ Autoruns64 to scan the system and (with Windows entries visible) it did not find that term or variations of it and a manual scan of the common startup points did not reveal anything odd.
I just find it strange that I cannot discover anything about it.
You must be logged in to reply to this topic.