If I had to guess, I would think there is some kind of network discovery mechanism enabled on that server within that application. We see these types of Dcom messages all the time on our main SCCM 2012 primary site server when discovery runs and the machines on the other end are turned off.
-Bonnie From: [email protected] [mailto:[email protected]] On Behalf Of Jesse Rink Sent: Wednesday, February 05, 2014 8:03 AM To: [email protected] Subject: [NTSysADM] DCOM I admit little experience with DCOM. Here's my situation. I have a W2008R2 server running Backup Exec Media Server (2012) and nothing else except the standard HP Agent Software that's loaded on it. No roles associated with it except an MS iSCSI Target. Oddly enough, I am getting countless DCOM errors showing up in the servers System Log. Event id 10006, source is DistributedCOM. The messages are "DCOM got error "2147944122" from computer (computer-name here) when attempting to activate the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} I believe the error is because the machines are turned off, however, **my BIGGER interest is WHY** this server, which only serves as a backup server, is attempting to contact PCs using DCOM. It happens only once a day, and seems to occur between 10:30am and 12:30pm most of the time. I just don't understand what application or process is doing this and WHY. These DCOM errors have been showing in the SYSTEM log, once per day (well, once per attempt of EACH computer, once per day) for over 12 months... so it's definitely not anything new. I'm just finally getting around to looking into it. I'm thinking about setting up a wireshark capture during that time period, but wireshark captures tend to get really BIG and I don't know what to filter on for DCOM. Thoughts?

