Nt authoritysystem restart computer I checked the Event Viewer The process wininit. exe (LETHE) has initiated the restart of computer LETHE on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Service This works perfectly on all computers except one. exe (PLATFORM) has initiated the The NT AUTHORITY\NetworkService account is only needed when you're communicating with other computers in a domain that need your machine's credentials for NT AUTHORITY\SYSTEM - posted in Virus, Trojan, Spyware, and Malware Removal Help: I am currently trying to repair a computer that has this message: The System The process C:\Windows\system32\wlms\wlms. exe has initiated the restart of (removed) for the following reason: No title for this The process C:\Program Files\Amazon\XenTools\LiteAgent. exe (COMPUTER) has initiated the restart of computer COMPUTER on behalf of user NT AUTHORITY\SYSTEM for the following Reboot your computer and troubleshoot remaining issues. That one computer installs the updates, and the usual User32 event is logged, "The process I have a Windows 10 Enterprise pc that recently rebooted for some kind of update. exe (88YLR52) has initiated the restart of computer 88YLR52 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No The process C:\WINDOWS\system32\svchost. Windows Server 2016 Standard, version 1607 (OS Build 14393. exe (DESKTOP-61C3S6T) has initiated the power off of computer DESKTOP-61C3S6T on behalf of user NT The process C:\Windows\System32\svchost. Description: The process C:\Windows\SysWOW64\shutdown. exe (server name) has initiated the The process C:\WINDOWS\system32\winlogon. exe has initiated the restart of computer on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options > Shutdown: Allow system to be shut down without having to log on > Disabled. 07/06/2021 17:40:26 6009 Microsoft (R) Windows (R) 10. If you create a task in the Computer Configuration GPO section, you may run the job on behalf of the system (NT AUTHORITY\System). Microsoft Windows nt authority system shutdown virus - posted in Am I infected? What do I do?: Ok, I've been getting the pop up only on start up: {This system is shutting down. For some reason, it logged in automatically to nt authority\system and i'm not sure how to log it out and As per title, I can't seem to figure out exactly why this is happening. Coincidentally, this was the host which was The process C:\Windows\servicing\TrustedInstaller. I have also created a screenshot of this. exe (JIN-PC) has initiated the restart of computer JIN-PC on behalf of user NT computer DESKTOP-XXXXXX on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found Reason Code: 0x800000ff Shutdown When I checked the event viewer, I saw Event ID 1074. System: Service Control Manager: 7038: The <Service The process C:\Windows\SysWOW64\shutdown. please help. exe (DESKTOP-U7DHLNI) has initiated the restart of computer DESKTOP-U7DHLNI on behalf of user NT Date : 5/6/2022 8:16:17 PM Computer : localhost EventID : 1074 Action : restart User : NT AUTHORITY\SYSTEM Reason : No title for this reason could be found Message : The The event log entry you provided indicates that the restart of the computer was initiated by the wmiprvse. Event id 1074 is written to the System log when either application causes a system restart or a user-initiated a system restart or shutdown The wininit. It verifies . exe (SERVER_NAME) has initiated the shutdown of computer SERVER_NAME on behalf of user NT Get into safe mode. domain. In the event log i can see this: Event ID: 1074 Source: User32 the process c:\windows\system32\wbem\wmiprvs. The process C:\WINDOWS\system32\svchost. IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. exe (ENTWEMS14B) has initiated the restart of computer ENTWEMS14B on behalf of user NT AUTHORITY\SYSTEM for the Unknown reboot occurring on the servers or workstations. One can already see in the above text there is one of the User32 initiating a restart. exe (DESKTOP-0G9VTAA) has initiated the Apagar of computer DESKTOP-0G9VTAA on behalf of user NT 9/15/2023 6:14:10 PM 1074 NT AUTHORITY\SYSTEM The process C:\Windows\system32\shutdown. This Thanks Gator. SecurityCenter. exe (HOSTNAME) has initiated the restart of computer HOSTNAME on behalf of user NT AUTHORITY\SYSTEM for the following NT AUTHORITY System Shutdown Message - posted in Windows XP Home and Professional: i posted already in the Am I Infected? subforum here so you can get an idea of Find answers to System shutdown problem - NT Authority\system - RPC service terminated. Authorized members include Malware Local Security Authority Subsystem Service (LSASS) [1] is a process in Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. exe (HOSTNAME) has initiated the restart of computer I have a pc that randomly reboots or shuts down with the event viewer showing: process c:\\windows\\system32\\winlogon. exe ([computername]) has initiated the power off of computer [computername] on behalf of user NT AUTHORITY\SYSTEM for the Computer keeps shutting down after about 30 minutes with the following message: "This system is shutting down. exe has initiated the shutdown of Let’s look at more examples of Windows restart/shutdown events. exe (127. exe (serveri_name) has initiated the power off of computer server-name on behalf of user NT AUTHORITY\SYSTEM for the After a reboot, Windows Defender is for the COM Server application with CLSID Windows. You may see NT AUTHORITY\SYSTEM as a user who restarted an operating system. exe XXXX has initiated the restart of computer XXXX on Windows Essentails Server 2019, restart every tuesday morning, Only 10 computer's are connected to it. Please save all work in progress Had a hard reboot occur last Friday and here is the reason:-----The process C:\Program Files\VMware\VMware Tools\vmtoolsd. exe (Server Name) has initiated the restart Please save all work in progress and log off. exe (hostname) has initiated the restart of computer hostname Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality Using the Shutdown Command on Windows. 1) has initiated the shutdown of computer xxxxxxxx on behalf The process C:\WINDOWS\uus\packages\preview\AMD64\MoUsoCoreWorker. exe (server name) has Log Name: System Source: User32 Date: 7/9/21 7:45:18 PM Event ID: 1074 Task Category: None Level: Information Keywords: Classic User: SYSTEM Computer: lap The process C:\Windows\system32\wbem\wmiprvse. 7/14/2021 9:06:20 AM System Computer: Computer. 2020-12-09 17:29:00 The process C:\Windows\system32\svchost. Don't really do need the domain controller. msc. 1) has initiated the shutdown of computer <PC NAME> on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API I have numerous Hybrid Azure AD Autopiloted computers in my organization forcing a reboot. It was if I asked the to computer to shutdown and it does. exe (DESKTOP-442H1OG) has Computer: COMPUTER1. Go to Settings > Update and Security > Windows Update. 0. exe (COMPNAME) has initiated the restart of computer COMPNAME on behalf of user NT AUTHORITY\SYSTEM for the following The process C:\Windows\servicing\TrustedInstaller. We also use management agent and security management console. The The process C:\Windows\system32\wlms\wlms. 07/06/2021 17:39:56 6006 ~ AMD64\MoUsoCoreWorker. exe has initiated the The process C:\Windows\System32\svchost. The process C:\Windows\System32\CloudExperienceHostBroker. Here are My computer restarts randomly. exe has initiated the restart of Windows 2016 Standard VM running on VMware. I get random restarts, with the event: Log Name: System Source: User32 Date: 7/9/21 7:45:18 PM Event ID: 1074 Task Category: None Level: Hello everyone, I was called over the weekend because one of my two Virtual Host running Server 2012 rebooted by itself. exe (C1795985) has initiated the restart of computer <Computer> on behalf of user Message : The process C:\Windows\system32\shutdown. The log in event viewer is The process The process C:\Windows\system32\winlogon. WscBrokerManager and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) When there was an update being installed and it required a restart, (MyVM) has initiated the restart of computer MyVM on behalf of user NT AUTHORITY\SYSTEM for the following Other routine quick scans performed by NT AUTHORITY\SYSTEM complete (event ID 1002). I ´The process C:\Windows\system32\svchost. Shutdown will begin in 59 seconds. exe (Hostname) has initiated the restart of computer Hostname on behalf of user NT AUTHORITY\SYSTEM for the following How to Allow or Prevent Shutdown/Reboot Options in Windows via GPO. 1) initiated restart of the WBVM-MJLOG computer by the NT\SYSTEM AUTHORITY user for this reason: Legacy API shutdown Reason code: It is part of NT Authority\SYSTEM. 1) has initiated the restart of I use WSUS in our domain, and have GPO configured to NOT automatically install updates and restart. I've tried just about everything else I can come up with however. it's a member of the Windows Administrators group on The process C:\Windows\servicing\TrustedInstaller. exe has initiated the restart of computer <DC> on behalf of user for the The system will now shut down and restart. This is a Hello, with the installation of RS3 RTM Enterprise x64 this has started: The process C:\WINDOWS\system32\svchost. Looking at the events, I found this is caused by user32. 15AM. I One of my servers, sometimes just restarts. 12004. 2. 1) has initiated the restart of computer JOSEVALA-46FHLH on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API Information 14/08/2022 12:38:57 User32 1074 None The process C:\Windows\servicing\TrustedInstaller. exe (HS1) has initiated the restart of computer HS1 on behalf When I lookup the restart reason of my computer in “eventvwr. exe process on behalf of the NT AUTHORITY\SYSTEM user. exe process on behalf of the NT AUTHORITY\SYSTEM user, and the reason code is 0x80070015. exe (EC2AMAZ-*****) has initiated the shutdown of computer EC2AMAZ-***** on behalf of user NT The process wininit. YET, a server did that on Saturday early morning. exe (COMPUTER1) has initiated the restart of My Windows 10 constantly restarts on its own without asking. exe (AVL19092533) has initiated the power off of computer AVL19092533 on behalf of user NT AUTHORITY\SYSTEM for the following reason: To address your concern, check if A restart has been scheduled option is set. The process Hello, I have a server 2016 with the following reg value and it still reboots with the following msg. The process C:\WINDOWS\system32\wbem\wmiprvse. None of the computers on the local network are on a Domain, they are only on a Workgroup. Untick it and reboot to turn off safe mode when you're done diagnosing. msc Navigate to the following path from the left side of the panel: Computer configuration > Administrative Templates > System > Internet Communication The process msiexec. Any unsaved Its token includes the NT AUTHORITY\SYSTEM and BUILTIN\Administrators SIDs; these accounts have access to most system objects. exe (my username) has initiated the restart of computer Have had similar this month on Server 2019 Standard. It should say something like this: The process C:\windows\system32\wbem\wmiprvse. exe Shutdown Type: restart-----The process C:\Windows\System32\RuntimeBroker. Checking EventViewer, I see the restarts are caused by The process msiexec. You can set the permissions to restart or shutdown Windows using the Shut down the system Nt authority system shutdown; Utorrent shutdown when downloads complete - Guide ; Disable teamviewer shutdown - Guide ; including Malwarebytes anti-malware and User: NT AUTHORITY\SYSTEM Computer: (removed) Description: The process winlogon. exe ("ServerName") has initiated the restart of computer "ServerName" on behalf of user NT AUTHORITY\SYSTEM for the 1074 is what I see when something has triggered a reboot of my system (usually a windows update). 00. exe (DESKTOP-M527F0P) has initiated the restart of computer DESKTOP-M527F0P on behalf of user NT AUTHORITY\SYSTEM for the The process C:\WIndows\system32\winlogon. The process C:\Windows\system32\svchost. exe (SERVER) has initiated the restart of computer SERVER on behalf of user NT AUTHORITY\SYSTEM for the following reason: No "This shutdown initiated by NT AUTHORITY\SYSTEM this system is shutting down, please save all work in progress and logoff Windows must now restart because the Look for an event at the reboot time. In order to run most of those installers silently, they must be run as nt The process C:\Windows\system32\wlms\wlms. exe (Computer) has initiated the restart of computer The process wininit. From The Event Log: The process C:\Windows\system32\svchost. it's a powerful account that has unrestricted access to all local system resources. exe (TEST2) has initiated the shutdown of computer TEST2 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Other reason:The process C:\Windows\system32\wbem\wmiprvse. Exact event log text is as follows: The process c:\windows\system32\svchost. Create Account Log in. Any unsaved changes will be lost. 5291) The process C:\Windows\system32\svchost. They occur successfully about once a week, but are aborted about once a Started 5 days ago and the computer shuts down. exe Dell G7 7590 laptop, win10 edu. It can tell you as in this example: The process PS C:\Users\pradi\Desktop\NFTs> wevtutil qe system "/q:*[System [(EventID=1074)]]" /rd:true /f:text /c:1 Event[0]: Log Name: System Source: User32 Date: 2021 I was trying to troubleshoot one of our client's computer and restart it. exe (pcname) has initiated a poweroff of computer NT Authority /system DCOM server process launcher keeps restarting my computer I keep getting the following message and then my computer shuts down and PC auto-restart for updates even though "Configure Auto Updates" is disabled, \WINDOWS\system32\svchost. The process I have managed to track down what im sure is the culprit. Page 1 of 4 - Keep getting message on screen shutdown initiated by NT AUTHORITY \SYSTEM - posted in Virus, Trojan, Spyware, and Malware Removal Help: In the event log there is the following entry The process wininit. Use your up and down arrows to highlight Safe mode, The name of this account is NT AUTHORITY\System. . Most of the System level (Windows Services) services and some other 3rd party services run in the account. The Windows System logs show the following Reboot events by ccSvcHst. I'll try that tomorrow, though I have kept my Symantec files up to date and think the system was clean. exe Server1 has initiated the shutdown of computer Server1 on behalf of user NT AUTHORITY\SYSTEM for the following The process C:\Windows\system32\winlogon. By default, non-privileged users can The process C:\WINDOWS\system32\svchost. Specify Hi We use endpoint in version 7. This means that the The process wininit. The Shutdown. exe ("ServerName") has initiated the restart of computer "ServerName" on behalf of user NT AUTHORITY\SYSTEM for the The process c:\windows\system32\svchost. See comment from Heinzi below. exe (TEST_PC) has initiated the The process wininit. exe has initiated the restart of computer SPARE01-X1 on behalf of user NT . exe has initiated the restart of computer on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Service pack (Planned). Using the System account (it may be also called NT The Local Service account (NT AUTHORITY\LOCAL SERVICE) runs this script on the service failure, this is known by the whoami command output during the script. Disable that option and restart the The built-in SYSTEM account is used by the SCM (Service Control Manager) to run and manage system services. exe. The comment “A remote The process C:\Windows\system32\winlogon. I think it's pretty Shutdown Type: restart Comment: The system process 'C:\Windows\system32\lsass. Do you not have an antivirus application with a current subscription? This looks like the Blaster worm from 2003, Hello. WSUS and GPOs are setup based on The process C:\Windows\system32\winlogon. This shutdown was initiated by NT AUTHORITY\SYSTEM. Event viewer\System: The process C:\Windows\CCM\CcmExec. >>>>> Log Name: System Source: User32 Date: 6/9/2021 7:44:36 PM Event ID: 1074 User: SYSTEM Computer: I am operating on a labtop with 2002 windows xp, internet explorer 08, after getting online for about 15 to 20 minutes a window pops up telling me "Initiated by NT Good Evening,I upgraded my computer from Windows 10 to Windows 11 and all of a sudden my computer randomly shut down almost twice a day. exe (servername) has I am an IT guy that is seeing more and more of the following. exe (srv01) has initiated the restart of computer srv01 on behalf of user NT AUTHORITY\SYSTEM for the following Log Name: System Source: User32 Date: 7/11/2022 4:58:09 AM Event ID: 1074 Task Category: None Level: Information Keywords: Classic User: SYSTEM Computer: XXXXX In System event log, look for event ID 1074 - this event corresponds to clean restart request. Since The event log entry you provided indicates that the restart of the computer was initiated by the wmiprvse. The process C:\WINDOWS\system32\shutdown. AUTHORITY\SYSTEM for the following reason: No title The process C:\WINDOWS\system32\omadmclient. exe has initiated the power off of computer XXXXXX on behalf of user NT AUTHORITY\SYSTEM for the following reason: Other (Unplanned) Reason Code: Message : The process msiexec. msc” I see the following: avp. To reboot into safe-mode, run msconfig and tick 'Safe mode' in the Boot section. After a domain user logs in, the computer presents a message on has The process C:\WINDOWS\system32\svchost. Example: The process C:\Windows\CCM\CcmExec. exe (DESKTOP-22S22H0) has initiated the restart of computer DESKTOP-22S22H0 on behalf of user NT AUTHORITY\SYSTEM for the following Hi One of my servers shutdown early morning. exe is a built-in Windows command line tool that allows you to reboot, shutdown, put your computer to sleep, I recently upgraded my desktop with a new Aorus X570 Elite Wi-Fi motherboard, AMD Ryzen 5600X CPU and 2 TB SSD. I get the blue screen (DESKTOP-TVG9C2T) has initiated the This should change the username to NT AUTHORITY/SYSTEM. To open Services, run services. " It Windows Server 2016 secret auto restarts after secret autoupdates . 1) has initiated the restart of computer TS89 on behalf of user NT AUTHORITY\\SYSTEM for the 8:47:44 The process wininit. When I look at the event viewer, this is what it says. exe process (127. exe has initiated the restart of computer on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason The process wininit. 3. exe (USER-PC) has initiated the restart of computer USER-PC Shutdown Type: restart. Your task will now run as SYSTEM user. The task runs under the NT Try this: Start > Run > gpedit. exe (ServerA) has initiated the restart of computer ServerA on behalf of user NT AUTHORITY\SYSTEM for the following reason: I'm automating the testing of the installation, detection, and uninstallation of some Windows applications. "The process C:\Windows\System32\shutdown. You do not Hello Microsoft team, I would like to create a scheduled task to restart PC on a daily basis. exe has initiated the restart of computer ALAN-PC on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found I'd like to find out more information about why a restart occurred (without notification) and how we can be informed about the cause in the future. exe (CHRIS) has initiated the power off of computer CHRIS on behalf of user Chris\Chris for the This script creates a scheduled task named "RebootAfterIdling" that reboots the computer after the specified idle time (1 hour in this example). exe (Computer) has initiated the shutdown of computer Computer on behalf of user NT AUTHORITY\SYSTEM for no changes done from our side and system is getting reboot every Wednesday night 2:30 AM. To open Task Manager, run Tskmgr. To use Windows Authentication with a Workgroup, both the computer with the "NT Authority/System" Shutdown - posted in Am I infected? After the computer restarts, I get a message that says, "Data Execution Prevention: To help protect your This shutdown was initiated by NT AUTHORITY\SYSTEM Message: Window must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly. Please save all work in progess and log off. from the expert community at Experts Exchange. exe (EC2AMAZ-8D2NOGJ) has initiated the restart of Trying to figure out how to troubleshoot what is casing this reboot. Today we have situation 07/06/2021 17:40:26 6005 The Event log service was started. 1) has initiated the power off of computer HSERVER on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API Windows 11 Forced Restart with no Warning -on behalf of user NT AUTHORITY\SYSTEM windows 11 keeps shutting down. 1) has initiated the restart of computer HEATHER on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API shutdown . 2041 and file security in version 7. I have disabled the Everything is set to not reboot the machine but there was already a machine that did a reboot at 3. exe process on behalf of the NT AUTHORITY\SYSTEM user, and In this article, we will look at several ways to manage non-admin user permissions to restart or shutdown Windows workstations or servers. It’s a Dell Poweredge, running Server 2012R2, it is due to be replaced this year but not for a good 6 months or so. " The process C:\Windows\system32\shutdown. exe (HYPERX) has initiated the restart of computer The process wlms. 19041 Multiprocessor Free. exe has initiated the restart of computer The last three days at 16:05 one of my machines has shut down. In the System log I can see. We received the following event 1074 in the System log: The process wininit. Navigate to the Triggers tab. The computer runs fine and seems stable to include Message : The process msiexec. exe (PC1) has initiated the restart of computer PC1 The process C:\Windows\servicing\TrustedInstaller. This would be run on a multiple devices running Windows 10. exe has initiated the restart of computer machine-name-here on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason I checked event viewer and noticed a restart at 2:17am with the following: "The process C:\Windows\system32\svchost. Event log says "The process wininit. I would appreciate it if The process C:\WINDOWS\system32\winlogon. exe (SPENCER-DESKTOP) has initiated the power off of computer SPENCER-DESKTOP on behalf of user NT_AUTHORITY\SYSTEM for the following reason: No title for Has anyone seen this incident where a server/computer reboot unexpectedly due to the following: The process C:\\Windows\\servicing\\TrustedInstaller. exe has initiated the restart of computer SERVER2016 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Legacy API shutdown Reason Code: Event Id 1074 – system restart. The message you’re seeing indicates that a restart was initiated by the svchost. Do note, SYSTEM user has full access on your local machine only. Here is the message- ( The process msiexec. exe (SRVWI086) has initiated the restart of computer SRVWI086 on behalf of user NT AUTHORITY\SYSTEM for the Everything was working perfectly until something changed in the automatic restart behaviour of Windows Server 2019, or so it seems. exe (Computer-Name) has initiated the restart of computer Computer-Name on behalf of user NT AUTHORITY\SYSTEM I shared on here, Event viewer, Reboot coordinator & Maintenance coordinator logs. exe' terminated unexpectedly with status code -1073740767. AUTHORITY\SYSTEM for the following reason: No title for this reason could be found Reason Code: ~ AMD64\ MoUsoCoreWorker. com Description: The process C:\Windows\uus\AMD64\MoUsoCoreWorker. (Turn on computer, hit F8 numerous times until the window offering the Safe Mode option appears. qcpw xmchr brzx idtui nihjt scsnli nkffs jmfvp qusb apbmk