Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer
  • AzureMonitor
    Configure Azure Monitor for VMs on Azure Stack Hub AWS/Azure/OpenShift
  • MacOS Catalina Desktop
    Mac FileVault Encryption: How to enable FileVault disk encryption Security | Vulnerability Scans and Assessment
  • gfhj
    Debugging: How to debug a PowerShell script Windows
  • DS923   what is taking up my space
    What is taking up by Synology NAS Volume Space Storage
  • screenshot 2020 03 21 at 22.44.04 1
    How to create a Microsoft HyperV checkpoint Virtualization
  • Windows Defender exclusion
    Mitigate Veeam Threat Hunter Service Scanning Interference Windows Server
  • Webp.net resizeimage 1
    Automate Infrastructure Deployments in the Cloud with Ansible and Azure Pipelines AWS/Azure/OpenShift
  • images 8
    Microsoft Direct Access: Now Always On VPN Windows Server

Detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer

Posted on 28/10/202211/12/2025 Matthew By Matthew No Comments on Detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer
Detect if an application was uninstalled on Windows

The apps installed on your Windows Server, which is running in production, could be crucial. As an administrator, you don’t want anyone to uninstall an application from the server without your permission. What happens if a certain program has been uninstalled? How would you find the person who uninstalled the program? In this article, you will learn how to detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer. Please, see Workaround for there were no pages selected to print or the documents could not be printed from Adobe Acrobat Reader.

Kindly refer to these exciting guides: How to Secure a Web Server on a Windows Virtual Machine in Azure using TLS/SSL Certificates Saved in Azure Kay Vault, how to Manage Windows Defender Antivirus Through Microsoft Endpoint Manager Admin Dashboard and Intune, and

Determine who uninstalled a program

You can determine who uninstalled a program from a Windows Server with the help of a Windows built-in tool. The Windows Event Viewer, without using any outside (third party) program. Windows doesn’t maintain track of application uninstallations.

At least not for all of the programs you remove. Event IDs 1034 and 11724 are the most useful in this situation, even if the event log only records partial uninstalls. The Event IDs 1034 and 11724 record the name of the program that was uninstalled as well as the user account that did so.

Here are other related guides on Windows Server: How to find out who restarted Windows Server, and how to uninstall Internet Explorer from your Windows PC or Windows Server, 

Using the steps in this article. You should be able to track down the user who uninstalled an application from your Windows Server system.

Please, see how to find out who restarted Windows Server, and how to uninstall Internet Explorer from your Windows PC or Windows Server. Also, see how to install Windows Server 2022 on VirtualBox, and how to Install Web Server IIS in Windows Server 2019.

Find Who Uninstalled a Program from the Windows

Here are quick steps to find who uninstalled an application from the Server or your Windows 10 or 11 PC.

To open the Event Viewer, press Win + R to launch the Run dialog box and type eventvwr.

image0-1
Run dialog box

In the Event Viewer, click on Windows Logs and select Application.

image1-6
Windows Event Viewer

You’ll see a list of application events that have occurred in the center pane. In the right pane, click on Filter Current Log.

image2-4
Filtering the event log

Filter the logs with Event ID 1034 or 11724 and click the OK button.

image3-5
Filtering the event log

You will most likely notice a large number of logs with MsiInstaller as the source. Scroll down to find Event ID 11724.

The Event ID 11724 clearly identifies the application that was uninstalled as well as the user account that did it.
image4-5
Event viewer showing uninstalled app details

The person who uninstalled the program should be revealed via one of the events.

Please, see  Network File System: How to install NFS Server on Windows Server, and How to Migrate Roles and Features to Windows Server 2022 using WSMT.

I hope you find this post helpful on how to detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer. If you have any questions, feel free to leave them in the comment section below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: Apache JMeter Load Testing: Test Mobile Apps on Windows
Next Post: Install and conduct performance testing using Apache JMeter on your Web App

Related Posts

  • Featured image 2
    5 Steps to Fix Outlook continually prompts for passwords Windows
  • microsoft confirms some pcs freeze after windows 10
    How to deploy images to computers using PXE Boot Windows
  • group
    How to update PowerShell and Package Management via Group Policy Object Windows Server
  • Was ist Windows Server und wie unterscheidet er sich vom normalen Windows
    Create a certificate template for BitLocker Network Unlock Windows Server
  • cookies9
    How to remove third-party cookies from Microsoft Edge Windows
  • How to Disable Integrated Graphics
    How to Disable Integrated Graphics on Windows Windows

More Related Articles

Featured image 2 5 Steps to Fix Outlook continually prompts for passwords Windows
microsoft confirms some pcs freeze after windows 10 How to deploy images to computers using PXE Boot Windows
group How to update PowerShell and Package Management via Group Policy Object Windows Server
Was ist Windows Server und wie unterscheidet er sich vom normalen Windows Create a certificate template for BitLocker Network Unlock Windows Server
cookies9 How to remove third-party cookies from Microsoft Edge Windows
How to Disable Integrated Graphics How to Disable Integrated Graphics on Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • AzureMonitor
    Configure Azure Monitor for VMs on Azure Stack Hub AWS/Azure/OpenShift
  • MacOS Catalina Desktop
    Mac FileVault Encryption: How to enable FileVault disk encryption Security | Vulnerability Scans and Assessment
  • gfhj
    Debugging: How to debug a PowerShell script Windows
  • DS923   what is taking up my space
    What is taking up by Synology NAS Volume Space Storage
  • screenshot 2020 03 21 at 22.44.04 1
    How to create a Microsoft HyperV checkpoint Virtualization
  • Windows Defender exclusion
    Mitigate Veeam Threat Hunter Service Scanning Interference Windows Server
  • Webp.net resizeimage 1
    Automate Infrastructure Deployments in the Cloud with Ansible and Azure Pipelines AWS/Azure/OpenShift
  • images 8
    Microsoft Direct Access: Now Always On VPN Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,825 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.