Microsoft-Windows-Wininit

61 events across 4 channels

EventTitleChannelSample
1WaitForWinstationShutdownStartDiagnosticN
2WaitForWinstationShutdownStopDiagnosticN
3PreShutdownNotificationStartDiagnosticN
4PreShutdownNotificationStopDiagnosticN
5WaitForSystemProcessesStartDiagnosticN
6WaitForSystemProcessesStopDiagnosticN
7ShutdownSystemRestoreStartDiagnosticN
8ShutdownSystemRestoreStopDiagnosticN
9ShutdownWindowsStartDiagnosticN
10ShutdownWindowsStopDiagnosticN
11Custom dynamic link libraries are being loaded for every application.SystemN
12LSASS.SystemY
13Credential Guard was started and will protect LSA credentials.SystemY
14Credential Guard configuration: 0, 0SystemY
15Credential Guard and/or VBS Key Isolation are configured but the secure kernel …SystemY
16LsaIso.SystemN
17Error reading Credential Guard.SystemN
18Key Guard was started and will protect VSM-isolated keys.SystemY
19Virtualization Based Security new timer creation status.SystemY
20Virtualization Based Security master key timer start status.SystemN
21Virtualization Based Security previous timer resume status.SystemN
22Virtualization Based Security latch policy status.SystemN
23Boot App Anti-Rollback: Initialize Completed with status.SystemY
24Boot App Anti-Rollback: Timer start completed with status.SystemN
25Boot App Anti-Rollback: Previous timer resumed with status.SystemY
26Boot App Anti-Rollback: Boot.SystemN
51NtShutdownSystemDiagnosticN
53SentLogoffRequestDiagnosticN
55ReceivedShutdownRequestDiagnosticN
100Hybrid shutdown has been overridden by a disk check request.SystemN
1001Event ID 1001OperationalN
1001Event ID 1001SystemN
1015A critical system process, Data_0, failed with status codeApplicationY
1015A critical system process, %1, failed with status codeOperationalY
1015A critical system process, %1, failed with status codeSystemY
3002Windows start-up process has unexpectedly terminatedOperationalN
3002Windows start-up process has unexpectedly terminatedSystemN
3003Windows start-up process has failed to start the remote shutdown serverOperationalN
3003Windows start-up process has failed to start the remote shutdown serverSystemN
3004Windows start-up process has failed to synchronize with the local security …OperationalN
3004Windows start-up process has failed to synchronize with the local security …SystemN
3005Windows start-up process has failed to terminate system processesOperationalN
3005Windows start-up process has failed to terminate system processesSystemN
3006Windows shudown failed with error code %1 in phase:OperationalN
3006Windows shudown failed with error code %1 in phase:SystemN
6001ShutdownDiagnosticsStartDiagnosticN
6002PerfTrackFullShutdown_V1DiagnosticN
1073742825%1.OperationalN
1073742825Event ID 1073742825SystemN
2147486651Windows start-up process has failed to start the remote shutdown server.OperationalN
2147486651Windows start-up process has failed to start the remote shutdown server.SystemN
2147486652Windows start-up process has failed to synchronize with the local security …OperationalN
2147486652Windows start-up process has failed to synchronize with the local security …SystemN
3221226487A critical system process, %1, failed with status code %2.OperationalY
3221226487A critical system process, .SystemY
3221228474Windows start-up process has unexpectedly terminated.OperationalN
3221228474Windows start-up process has unexpectedly terminated.SystemN
3221228477Windows start-up process has failed to terminate system processes.OperationalN
3221228477Windows start-up process has failed to terminate system processes.SystemN
3221228478Windows shudown failed with error code %1 in phase: %2.OperationalN
3221228478Windows shudown failed with error code .SystemN

Event ID 1: WaitForWinstationShutdownStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForWinstationShutdown
Opcode
Start

Event ID 2: WaitForWinstationShutdownStop

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForWinstationShutdown
Opcode
Stop

Event ID 3: PreShutdownNotificationStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PreShutdownNotification
Opcode
Start

Event ID 4: PreShutdownNotificationStop

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PreShutdownNotification
Opcode
Stop

Event ID 5: WaitForSystemProcessesStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForSystemProcesses
Opcode
Start

Event ID 6: WaitForSystemProcessesStop

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
WaitForSystemProcesses
Opcode
Stop

Event ID 7: ShutdownSystemRestoreStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownSystemRestore
Opcode
Start

Event ID 8: ShutdownSystemRestoreStop

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownSystemRestore
Opcode
Stop

Event ID 9: ShutdownWindowsStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 10: ShutdownWindowsStop

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 11: Custom dynamic link libraries are being loaded for every application.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Description

Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Message #

Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Fields #

NameDescription
StringCount UInt32
String UnicodeString

Event ID 12: LSASS.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

LSASS.exe was started as a protected process with level: .

Message #

LSASS.exe was started as a protected process with level: %1.

Fields #

NameDescription
Level

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206F6DEA-D3C5-4D10-BC72-989F03C8B84B}",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T13:53:45.1729140+00:00",
    "event_record_id": 2662,
    "correlation": {},
    "execution": {
      "process_id": 792,
      "thread_id": 796
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Level": "4"
  },
  "message": "LSASS.exe was started as a protected process with level: 4."
}

Event ID 13: Credential Guard was started and will protect LSA credentials.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

Credential Guard was started and will protect LSA credentials.

Message #

Credential Guard was started and will protect LSA credentials.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:27:21.619522+00:00",
    "event_record_id": 2749,
    "correlation": {},
    "execution": {
      "process_id": 928,
      "thread_id": 932
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 14: Credential Guard configuration: 0, 0

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

Credential Guard configuration.

Message #

Credential Guard configuration:

Registry Configuration: %1
Test Configuration: %2
Auto Enablement: %3

Fields #

NameDescription
Config UInt32
IsTestConfig UInt32
IsAutoEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206F6DEA-D3C5-4D10-BC72-989F03C8B84B}",
    "event_source_name": "",
    "event_id": 14,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:32:50.1627758+00:00",
    "event_record_id": 6692,
    "correlation": {},
    "execution": {
      "process_id": 660,
      "thread_id": 664
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Config": "0",
    "IsTestConfig": "0"
  },
  "message": "Credential Guard configuration: 0x0, 0"
}

Event ID 15: Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Warning
Opcode
Info

Description

Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Message #

Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206F6DEA-D3C5-4D10-BC72-989F03C8B84B}",
    "event_source_name": "",
    "event_id": 15,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-27T21:58:49.7100955+00:00",
    "event_record_id": 1201,
    "correlation": {},
    "execution": {
      "process_id": 748,
      "thread_id": 752
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Credential Guard and/or VBS Key Isolation are configured but the secure kernel is not running; continuing without them."
}

Event ID 16: LsaIso.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Description

LsaIso.exe, the host process for Credential Guard and VBS Key Isolation, failed to launch: Level.

Message #

LsaIso.exe, the host process for Credential Guard and VBS Key Isolation, failed to launch: %1

Fields #

NameDescription
Level UInt32

Event ID 17: Error reading Credential Guard.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Description

Error reading Credential Guard (LsaIso.exe) UEFI configuration: Level.

Message #

Error reading Credential Guard (LsaIso.exe) UEFI configuration: %1

Fields #

NameDescription
Level UInt32

Event ID 18: Key Guard was started and will protect VSM-isolated keys.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational
Opcode
Info

Description

VBS Key Isolation was started and will protect VSM-isolated keys.

Message #

VBS Key Isolation was started and will protect VSM-isolated keys.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "206F6DEA-D3C5-4D10-BC72-989F03C8B84B",
    "event_source_name": "",
    "event_id": 18,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:27:21.619506+00:00",
    "event_record_id": 2748,
    "correlation": {},
    "execution": {
      "process_id": 928,
      "thread_id": 932
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19: Virtualization Based Security new timer creation status.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational

Description

Virtualization Based Security new timer creation status.

Message #

Virtualization Based Security new timer creation status

HRESULT: %1
New latch timer needed: %2
New latch timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4
Policy file exists: %5

Fields #

NameDescription
HRESULT Int32
NewLatchTimerNeeded Boolean
NewLatchTimerWaitingSystemUpdateCompletion Boolean
PreviousLatchTimerExistsButDisabled Boolean
PolicyFileExists Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
    "event_source_name": "",
    "event_id": 19,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-18 00:24:11.444918+00:00",
    "event_record_id": 38,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 688,
      "thread_id": 692
    },
    "channel": "System",
    "computer": "USERUSE-I0E7KUG",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "HRESULT": "0",
    "NewLatchTimerNeeded": "False",
    "NewLatchTimerWaitingSystemUpdateCompletion": "False",
    "PreviousLatchTimerExistsButDisabled": "False",
    "PolicyFileExists": "False"
  },
  "message": "Virtualization Based Security new timer creation status\r\n\r\nHRESULT: The operation completed successfully.\r\nNew latch timer needed: false\r\nNew latch timer waiting for system update completion: false\r\nPrevious latch timer exists but disabled by registry: false\r\nPolicy file exists: false\r\n"
}

Event ID 20: Virtualization Based Security master key timer start status.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security master key timer start status.

Message #

Virtualization Based Security master key timer start status

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4
Policy version: %5

Fields #

NameDescription
win32Error UInt32
ftStartTime FILETIME
ullDelay UInt64
ftDueTime FILETIME
PolicyVersion UInt64

Event ID 21: Virtualization Based Security previous timer resume status.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security previous timer resume status.

Message #

Virtualization Based Security previous timer resume status

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Policy version: %5
Attempted recovery increment succeeded: %6
Previous timer invalid: %7
Unlatched policy file exists: %8

Fields #

NameDescription
HRESULT Int32
PreviousTimerPresent Boolean
ftStartTime FILETIME
ullDelay UInt64
PolicyVersion UInt64
fAttemptedRecoveryIncrementCounterSucceeded Boolean
fPreviousLatchTimerInvalid Boolean
fPolicyFileExists Boolean

Event ID 22: Virtualization Based Security latch policy status.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Virtualization Based Security latch policy status.

Message #

Virtualization Based Security latch policy status

HRESULT: %1
TPM counter value: %2
Expected TPM counter value: %3
Policy version: %4
Incremented: %5

Fields #

NameDescription
HRESULT Int32
Counter UInt64
PendingLKeyPkgId UInt64
PendingPolicyVersion UInt64
CounterIncremented Boolean

Event ID 23: Boot App Anti-Rollback: Initialize Completed with status.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational

Description

Boot App Anti-Rollback: Initialize Completed with status.

Message #

Boot App Anti-Rollback: Initialize Completed with status:
HRESULT: %1
New timer needed: %2
New timer waiting for system update completion: %3
Previous latch timer exists but disabled by registry: %4

Fields #

NameDescription
HRESULT Int32
NewTimerNeeded Boolean
NewTimerWaitingUpdateCompletion Boolean
PreviousTimerExistsButDisabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
    "event_source_name": "",
    "event_id": 23,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-18 00:24:11.445660+00:00",
    "event_record_id": 40,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 688,
      "thread_id": 692
    },
    "channel": "System",
    "computer": "USERUSE-I0E7KUG",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "HRESULT": "0",
    "NewTimerNeeded": "False",
    "NewTimerWaitingUpdateCompletion": "False",
    "PreviousTimerExistsButDisabled": "False"
  },
  "message": "Boot App Anti-Rollback: Initialize Completed with status:\r\nHRESULT: The operation completed successfully.\r\nNew timer needed: false\r\nNew timer waiting for system update completion: false\r\nPrevious latch timer exists but disabled by registry: false\r\n"
}

Event ID 24: Boot App Anti-Rollback: Timer start completed with status.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Timer start completed with status.

Message #

Boot App Anti-Rollback: Timer start completed with status:

Win32Error: %1
Start time: %2
Grace period: %3
Due time: %4

Fields #

NameDescription
win32Error UInt32
FileStartTime FILETIME
GracePeriod UInt64
DueTime FILETIME

Event ID 25: Boot App Anti-Rollback: Previous timer resumed with status.

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
Informational

Description

Boot App Anti-Rollback: Previous timer resumed with status.

Message #

Boot App Anti-Rollback: Previous timer resumed with status:

HRESULT: %1
Previous timer present: %2
Start time: %3
Grace period: %4
Attempted recovery enforcement succeeded: %5

Fields #

NameDescription
HRESULT Int32
PreviousTimerExists Boolean
PreviousTimerStartTime FILETIME
GracePeriod UInt64
AttemptedRecoveryEnforcementSucceeded Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
    "event_source_name": "",
    "event_id": 25,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-18 00:24:11.444954+00:00",
    "event_record_id": 39,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 688,
      "thread_id": 692
    },
    "channel": "System",
    "computer": "USERUSE-I0E7KUG",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "HRESULT": "0",
    "PreviousTimerExists": "False",
    "PreviousTimerStartTime": "0001-01-01 00:00:00",
    "GracePeriod": "0",
    "AttemptedRecoveryEnforcementSucceeded": "False"
  },
  "message": "Boot App Anti-Rollback: Previous timer resumed with status:\r\n\r\nHRESULT: The operation completed successfully.\r\nPrevious timer present: false\r\nStart time: ?1601?-?01?-?01T00:00:00.000000000Z\r\nGrace period: 0\r\nAttempted recovery enforcement succeeded: false\r\n"
}

Event ID 26: Boot App Anti-Rollback: Boot.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Boot App Anti-Rollback: Boot.stl Enforcement completed with status.

Message #

Boot App Anti-Rollback: Boot.stl Enforcement completed with status:

HRESULT: %1
Boot Stl Enforced Successfully: %2
WNF Published with result: %3

Fields #

NameDescription
HRESULT Int32
BootStlEnforced Boolean
LocalStatus HexInt32

Event ID 51: NtShutdownSystem

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
NtShutdownSystem

Event ID 53: SentLogoffRequest

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
SentLogoffRequest

Fields #

NameDescription
SessionId UInt32
Flags UInt32

Event ID 55: ReceivedShutdownRequest

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ReceivedShutdownRequest

Fields #

NameDescription
SessionId UInt32
IsRemote UInt32
GracePeriod UInt32
Flags UInt32
Reason UInt32
Message UnicodeString

Event ID 100: Hybrid shutdown has been overridden by a disk check request.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.

Message #

Hybrid shutdown has been overridden by a disk check request. The system will perform a full shutdown instead.

Event ID 1001

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 1001

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 1015: A critical system process, Data_0, failed with status code

#
Provider
Microsoft-Windows-Wininit
Channel
Application
Level
Error

Fields #

NameDescription
Data_0
Data_1
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "guid": "{206f6dea-d3c5-4d10-bc72-989f03c8b84b}",
    "event_source_name": "Wininit",
    "event_id": 1015,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T19:07:39.959249+00:00",
    "event_record_id": 3508,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "C:\\Windows\\system32\\lsass.exe",
    "Data_1": "c0000005",
    "Binary": ""
  },
  "message": ""
}

Event ID 1015: A critical system process, %1, failed with status code

#
Provider
Microsoft-Windows-Wininit
Channel
Operational
Level
2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "event_id": 1015,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:07:39.9592493+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1015: A critical system process, %1, failed with status code

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "event_id": 1015,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:07:39.9592493+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3002: Windows start-up process has unexpectedly terminated

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3002: Windows start-up process has unexpectedly terminated

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3003: Windows start-up process has failed to start the remote shutdown server

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3003: Windows start-up process has failed to start the remote shutdown server

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3004: Windows start-up process has failed to synchronize with the local security subsystem during setup

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3004: Windows start-up process has failed to synchronize with the local security subsystem during setup

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3005: Windows start-up process has failed to terminate system processes

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3005: Windows start-up process has failed to terminate system processes

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 3006: Windows shudown failed with error code %1 in phase:

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Event ID 3006: Windows shudown failed with error code %1 in phase:

#
Provider
Microsoft-Windows-Wininit
Channel
System

Event ID 6001: ShutdownDiagnosticsStart

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
ShutdownDiagnostics
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 6002: PerfTrackFullShutdown_V1

#
Provider
Microsoft-Windows-Wininit
Channel
Diagnostic
Task
PerfTrackFullShutdown

Fields #

NameDescription
ShutdownFlags UInt32
SystemShutdownDuration UInt64
SkuHasLogoff UInt32

Event ID 1073742825: %1.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational
Opcode
Info

Description

%1

Message #

%1

Event ID 1073742825

#
Provider
Microsoft-Windows-Wininit
Channel
System
Opcode
Info

Message #

%1

Event ID 2147486651: Windows start-up process has failed to start the remote shutdown server.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to start the remote shutdown server.

Message #

Windows start-up process has failed to start the remote shutdown server.

Event ID 2147486651: Windows start-up process has failed to start the remote shutdown server.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to start the remote shutdown server.

Event ID 2147486652: Windows start-up process has failed to synchronize with the local security subsystem during setup.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Message #

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Event ID 2147486652: Windows start-up process has failed to synchronize with the local security subsystem during setup.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to synchronize with the local security subsystem during setup.

Event ID 3221226487: A critical system process, %1, failed with status code %2.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational
Level
2

Description

A critical system process, , failed with status code . The machine must now be restarted.

Message #

A critical system process, %1, failed with status code %2.  The machine must now be restarted.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "event_id": 1015,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:07:39.9592493+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221226487: A critical system process, .

#
Provider
Microsoft-Windows-Wininit
Channel
System
Level
2

Description

A critical system process, , failed with status code . The machine must now be restarted.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wininit",
    "event_id": 1015,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:07:39.9592493+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221228474: Windows start-up process has unexpectedly terminated.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has unexpectedly terminated.

Message #

Windows start-up process has unexpectedly terminated.

Event ID 3221228474: Windows start-up process has unexpectedly terminated.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has unexpectedly terminated.

Event ID 3221228477: Windows start-up process has failed to terminate system processes.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows start-up process has failed to terminate system processes.

Message #

Windows start-up process has failed to terminate system processes.

Event ID 3221228477: Windows start-up process has failed to terminate system processes.

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows start-up process has failed to terminate system processes.

Event ID 3221228478: Windows shudown failed with error code %1 in phase: %2.

#
Provider
Microsoft-Windows-Wininit
Channel
Operational

Description

Windows shudown failed with error code in phase: .

Message #

Windows shudown failed with error code %1 in phase: %2.

Event ID 3221228478: Windows shudown failed with error code .

#
Provider
Microsoft-Windows-Wininit
Channel
System

Description

Windows shudown failed with error code in phase: .

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 206f6dea-d3c5-4d10-bc72-989f03c8b84b

Defined in wininit.exe, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4652, captured 2026-06-02

Downloads