Every Shutdown now triggers a restart

Page 4 of 6 FirstFirst ... 23456 LastLast

  1. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #31

    krc52 said:
    I haven't done anything to the clock or time.
    From what you saw in the cmd prompt results I just sent the CBS should have been updated and show the current hour/time?
    Here's the last few lines....
    Code:
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/SOFTWARE
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/SYSTEM
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/SECURITY
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/SAM
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/COMPONENTS
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/System32/config/DEFAULT
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/Users/default/ntuser.dat
    2015-09-13 00:24:02, Info                  CBS    Unloading offline registry hive: {bf1a281b-ad7b-4476-ac95-f47682990ce7}GLOBALROOT/Device/HarddiskVolumeShadowCopy5/windows/system32/smi/store/Machine/schema.dat
    2015-09-13 15:28:46, Info                  CBS    Trusted Installer signaled for shutdown, going to exit.
    2015-09-13 15:28:47, Info                  CBS    Ending the TrustedInstaller main loop.
    2015-09-13 15:28:47, Info                  CBS    Starting TrustedInstaller finalization.
    - over 15 hours between entries!
      My Computer


  2. Posts : 32
    Windows 7 64 bit
    Thread Starter
       #32

    I see what you mean. Do the entries with the 2015-09-13 15:28:46 give you any needed info?
    Anything I can do from here?
    Really appreciate your help.

      My Computer


  3. Posts : 32
    Windows 7 64 bit
    Thread Starter
       #33

    Because I see Teredo listed in the log would it do any good to use regedit and turn that from 8a to 0 or disable? Grasping at straws to get this thing to shutdown. :>( Also, my Windows Updates has Important Updates grayed out. Should I sign in as admin and change that? I'm afraid to hard shutdown each day. Does it help for me to delete pending folders?
      My Computer


  4. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #34

    Ignore Teredo - it's irrelevant to your problems.

    The only reason I can think of for Important Updates being greyed out is being in a non-genuine state...
    I need to see a full copy of the report produced by the MGADiag tool
    (download and save to desktop - http://go.microsoft.com/fwlink/?linkid=52012 )
    Once saved, run the tool.
    Click on the Continue button, which will produce the report.
    To copy the report to your response, click on the Copy button in the tool (ignore any error messages at this point), and then paste (using either r-click/Paste, or Ctrl+V ) into your response.x
      My Computer


  5. Posts : 32
    Windows 7 64 bit
    Thread Starter
       #35

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-4F8HK-M4P73-W8DQG
    Windows Product Key Hash: Xs1iQgVeo0C+sObJxS7eu+FuBPQ=
    Windows Product ID: 00359-OEM-8992687-00057
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {A6758C37-89C9-41AF-82FF-DFAD95FA2052}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Home Premium
    Architecture: 0x00000009
    Build lab: 7601.win7sp1_gdr.150525-0603
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{922F27FB-65CA-476C-8A01-8DBD0BF7CA79}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-W8DQG</PKey><PID>00359-OEM-8992687-00057</PID><PIDType>2</PIDType><SID>S-1-5-21-35071626-1651299499-2114152193</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Satellite C855</Model></SYSTEM><BIOS><Manufacturer>Insyde Corp.</Manufacturer><Version>6.50</Version><SMBIOSVersion major="2" minor="7"/><Date>20121122000000.000000+000</Date></BIOS><HWID>4D363607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>TOSINV</OEMID><OEMTableID>TOSINV00</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7601.17514

    Name: Windows(R) 7, HomePremium edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00178-926-800057-02-1033-7601.0000-0822012
    Installation ID: 015343603622993291331671981111245701161194464641946896
    Processor Certificate URL: SpcService Web Service
    Machine Certificate URL: RacService Web Service
    Use License URL: UseLicenseService Web Service
    Product Key Certificate URL: PkcService Web Service
    Partial Product Key: W8DQG
    License Status: Licensed
    Remaining Windows rearm count: 2
    Trusted time: 9/14/2015 12:03:12 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 7:1:2015 15:47
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: LgAAAAEAAQABAAEAAAACAAAAAgABAAEA6GHk/YRGWPjSn0DyHqm+pFbhetoucw==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC TOSINV TOSINV00
    FACP TOSINV TOSINV00
    HPET TOSINV TOSINV00
    BOOT TOSINV TOSINV00
    MCFG TOSINV TOSINV00
    WDAT TOSINV TOSINV00
    UEFI TOSINV TOSINV00
    ASF! TOSINV TOSINV00
    SLIC TOSINV TOSINV00
    SSDT INSYDE CR CRB
    ASPT TOSINV TOSINV00
    SSDT INSYDE CR CRB
    FPDT TOSINV TOSINV00
    SSDT INSYDE CR CRB
    SSDT INSYDE CR CRB
      My Computer


  6. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #36

    Nothing there - it's perfectly OK, and contains no errors at all.

    I was hoping to see a fairly characteristic error, but I don't get that lucky too often

    Let's go back a bit, and gather a slew of logs at once...

    Please follow the Blue Screen of Death (BSOD) Posting Instructions - instead of posting a new thread just post the resulting file back in your reply here.
      My Computer


  7. Posts : 32
    Windows 7 64 bit
    Thread Starter
       #37

    I wish you/we had been lucky too. :>(
    Here is the file attached.
    Every Shutdown now triggers a restart Attached Files
      My Computer


  8. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #38

    You appear to have a number of items which I'd describe as malware in the startup regime - they may just be residues of things already remove, but we need to check then.

    ot.shot - definite PUP - uninstall it if it's in the Programs listing
    f.lux - optional, but I'd suggest uninstalling it, as it's the type of thing that often comes embedded between adware.
    "Bob_Dylan_Things_Have_Changed" - definitely not wanted on Voyage! - it's being loaded from a very unusual place.

    Please download and install Malwarebytes Anti-malware (free version) from Malwarebytes | Free Anti-Malware Detection & Removal Software - UNtick 'Enable free trial of MBAM Premium' at the end of the installation - and update it, then run a full scan in your main account, and Quick scans in any other user accounts.

    Quarantine everything it finds
      My Computer


  9. Posts : 32
    Windows 7 64 bit
    Thread Starter
       #39

    Okay, I have done this. Shutdown is still restarting. I see there are many files in a PendingRenames folder. Would deleting these do anything? Is there no way to just stop Windows from trying to update so it will cease restarting? If that is the problem??
    I know I do not have enough knowledge to fix this but so tired of working on this since Friday. Thank you for all your help. Should I just find another OS?
    Last edited by krc52; 14 Sep 2015 at 14:51.
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #40

    You always have the option to move to another OS - you may find you prefer it, or you may hate it.

    I'm by no means certain that your problem lies with an update, although I have no real evidence either way.

    Look on this as a learning experience - once we do manage to fix it (hopefully) chances are that you'll know more about fixing Windows than anyone within a mile or two! :)

    My own machine has a number of files in the PendingRenames folder - it's not unusual, and the data is usually irrelevant.

    I couldn't see anything nasty in the BSOD data, so let's have a closer look at the Event logs - which *should* tell us what's causing the reboot if it's actually happening late enough in the boot process....

    Please open Event Viewer
    In the left pane, navigate to the Windows Logs
    right-click on Applications and select 'Save all events as...' save as Apps.evtx
    repeat for the System logs - save as Sys.evtx
    Compress both files, and attach to your reply or upload to your favourite fileshare site (preferably Dropbox or OneDrive/SkyDrive)*and post a link in your reply
      My Computer


 
Page 4 of 6 FirstFirst ... 23456 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:38.
Find Us