Windows crashed and restarted by Sysmon Uninstall

Frânçois 21 Reputation points
2021-08-27T06:24:17.937+00:00

My Windows 10 (Version 1909) VM just crashed and restarted when I uninstalled the Sysmon (v13.23).
Very weird as this didn't happened neither on my another Windows 10 (Version 20H2) box nor on Windows Server 2012 R2.

As evidence of crash, following Event IDs were generated after the crash.

I. Event ID 41: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

II. Event ID 6008: The previous system shutdown was unexpected.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,112 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jonny Wiederholm 11 Reputation points
    2021-08-31T07:29:29.363+00:00

    It's the same when trying to uninstall Sysmon (all versions since 6.0) on Windows Server 2016 running Credential Guard ... it generates a BSOD. The only workaround is to disable Sysmon, reboot and then uninstall.

    0 comments No comments