The process C:\windows\System32\svchost.exe (xxxxxxxxx ) has initiated the restart of computer xxxxxxxxx on behalf of user NT AUTHORITY\SYSTEM

Anonymous
2023-11-14T13:55:19+00:00

Windows 2016 server , The process C:\windows\System32\svchost.exe (xxxxxxxxx ) has initiated the restart of computer xxxxxxxxx on behalf of user NT AUTHORITY\SYSTEM for the following reason: Other (Unplanned) Reason Code: 0x0 Shutdown Type: restart Comment: A remote client is trying to shutdown this machine through Remote Desktop Services.

how can i find the solution it got happenend and need to find RCA for this case?

Windows for business | Windows Server | Performance | System performance

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2023-11-15T07:24:10+00:00

    Hello

    The message you’re seeing indicates that a restart was initiated by the svchost.exe process on behalf of the NT AUTHORITY\SYSTEM user. The comment “A remote client is trying to shutdown this machine through Remote Desktop Services” suggests that the restart may have been triggered remotely through Remote Desktop Services.

    Here are a few things you can do to investigate this issue:

    Check the Event Viewer: Look for any related events that occurred around the same time as the restart. This might give you more information about what was happening on the system when the restart was initiated.

    Check for Updates: The restart could be related to a Windows Update. Check your Windows Update history to see if any updates were installed around the time of the restart.

    [fade-ab9e-ae6-36d6] (microsoft.com)

    Check Active Sessions: If the restart was initiated through Remote Desktop Services, check the active sessions on the server. You can do this by running the qwinsta command from the command prompt.

    Check Running Services: The svchost.exe process is used by many different services. If the PID of the process is logged, you can look it up in Task Manager, right-click, go to services, and see which service was running under that process.

    [Help needed:] svchost.exe has initiated the restart of computer | My Digital Life Forums

    Best Regards,

    Wesley Li

    1 person found this answer helpful.
    0 comments No comments