Hello
The message you’re seeing indicates that a restart was initiated by the svchost.exe process on behalf of the NT AUTHORITY\SYSTEM user. The comment “A remote client is trying to shutdown this machine through Remote Desktop Services” suggests that the restart may have been triggered remotely through Remote Desktop Services.
Here are a few things you can do to investigate this issue:
Check the Event Viewer: Look for any related events that occurred around the same time as the restart. This might give you more information about what was happening on the system when the restart was initiated.
Check for Updates: The restart could be related to a Windows Update. Check your Windows Update history to see if any updates were installed around the time of the restart.
[fade-ab9e-ae6-36d6] (microsoft.com)
Check Active Sessions: If the restart was initiated through Remote Desktop Services, check the active sessions on the server. You can do this by running the qwinsta command from the command prompt.
Check Running Services: The svchost.exe process is used by many different services. If the PID of the process is logged, you can look it up in Task Manager, right-click, go to services, and see which service was running under that process.
[Help needed:] svchost.exe has initiated the restart of computer | My Digital Life Forums
Best Regards,
Wesley Li