Windows Updates, but getting error code 80070246 = READY TO SEND EVENTS AND SYSTEM LO

So both sticks pass individually?

If so, put both sticks back in and run the test again.

They might have just needed to be reseated, which would be excellent.
 
tried both sticks, test indicates orignal error " Replace Memory - this system no longer carries hardware warranty...."
 
I have another computer downstairs that is exactly the same. swapped out the memory and the test passed.OTHER MEMORY CHIPS TESTED PASSED.jpg
 
ive repaired several of the registration keys but theres still a few errors... i dont mind resetting this whole computer to factory setting the only thing im worried about is my windows professional programs but theres a dell product key sticker on the outside will that do me any good in recovering them?
 
The product key on the case would only help for activating Windows, not any of the third party products. Let's try some things to get SURT working.

Let's start with SFC to check for corrupt files:

SFC Scan

  1. Click on the Start
    Start%20Orb.jpg
    button and in the search box, type Command Prompt
  2. When you see Command Prompt on the list, right-click on it and select Run as administrator
  3. When command prompt opens, copy and paste the following commands into it, press enter after each

    sfc /scannow

    Wait for this to finish before you continue

    copy %windir%\logs\cbs\cbs.log %userprofile%\Desktop\cbs.txt
  4. This will create a file, cbs.txt on your Desktop. Please zip and attach this to your next post.
 
I've created the zip and tried to attach it but have not been able to do so, finally figured out how to do so. will upload within the next few hours
 
Sorry about that. If the zip is larger than 8MB it will not attach.

Drop Box or SendSpace etc. would be fine, just include the link with your reply.
 
Looks like there's still a bit flip:

Code:
2016-01-07 01:15:30, Info                  CSI    000001a8 Manifest hash for component [ml:280{140},l:202{101}]"amd64_microsoft-windows-v..-vmwindow.resources_31bf3856ad364e35_7.1.7601.17514_ru-ru_7da10635eba3a9fb" does not match expected value. 
 Expected:    {l:32 b:ce108[COLOR=#ff0000]a[/COLOR]91a0eb2674402ae927984578019537[COLOR=#ff0000]43[/COLOR]96291711cbac2207302539ab88}
 Found:        {l:32 b:ce108[COLOR=#ff0000]2[/COLOR]91a0eb2674402ae927984578019537[COLOR=#ff0000]cb[/COLOR]96291711cbac2207302539ab88}.

SFCFix Script

Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.

  1. Download SFCFix.exe (by niemiro) and save this to your Desktop.
  2. Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
  3. Save any open documents and close all open windows.
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
  6. SFCFix will now process the script.
  7. Upon completion, a file should be created on your Desktop: SFCFix.txt.
  8. Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please - put [CODE][/CODE] tags around the log to break up the text.

View attachment SFCFix.zip

Once SFCFix has completed, I'd like to review the Windows Event Logs.

Event Log Collection

  • Download VEW by Vino Rosso here: VEW.EXE
  • Right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.
  • Click the check boxes next to Application and System located under Select log to query on the upper left.
  • Under Select type to list on the right click the boxes next to Error, Warning and Critical (not XP).
  • Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run.
  • Once it finishes it will display a log file in notepad.
  • Copy and paste its entire contents into your next reply.
 
SFCFix version 2.4.5.0 by niemiro.
Start time: 2016-01-07 23:31:33.031
Microsoft Windows 7 Service Pack 1 - amd64
Using .zip script file at C:\Users\Mark\Desktop\SFCFix.zip [0]








RegistryScript::
Successfully took ownership and permissions for registry key HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-v..-vmwindow.resources_31bf3856ad364e35_7.1.7601.17514_ru-ru_7da10635eba3a9fb.


Successfully imported registry key HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-v..-vmwindow.resources_31bf3856ad364e35_7.1.7601.17514_ru-ru_7da10635eba3a9fb.


Successfully restored ownership and permissions for registry key HKEY_LOCAL_MACHINE\COMPONENTS\DerivedData\Components\amd64_microsoft-windows-v..-vmwindow.resources_31bf3856ad364e35_7.1.7601.17514_ru-ru_7da10635eba3a9fb.
RegistryScript:: directive completed successfully.








Successfully processed all directives.
SFCFix version 2.4.5.0 by niemiro has completed.
Currently storing 18 datablocks.
Finish time: 2016-01-07 23:31:33.375
Script hash: V0q99AmxojzWC34K9ld6oRAraMBQMOAkxaTW+WxVRUg=
----------------------EOF-----------------------
 
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 07/01/2016 11:35:54 PM


Note: All dates below are in the format dd/mm/yyyy


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 07/01/2016 6:30:05 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Shared MUI (English) 2010 - Update 'Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI26746.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:30:02 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office OneNote MUI (English) 2010 - Update 'Security Update for Microsoft OneNote 2010 (KB3054978) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI25edd.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:30:00 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Excel MUI (English) 2010 - Update 'Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI255c9.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:29:58 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Outlook MUI (English) 2010 - Update 'Update for Microsoft Outlook 2010 (KB3101535) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI24bda.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:29:55 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Outlook MUI (English) 2010 - Update 'Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI2419d.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:29:53 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Shared MUI (English) 2010 - Update 'Security Update for Microsoft Office 2010 (KB3085560) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI2357d.LOG.


Log: 'Application' Date/Time: 07/01/2016 6:29:10 PM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office PowerPoint MUI (English) 2010 - Update 'Security Update for Microsoft PowerPoint 2010 (KB2920812) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI186b8.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:17 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Shared MUI (English) 2010 - Update 'Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb783c.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:14 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office OneNote MUI (English) 2010 - Update 'Security Update for Microsoft OneNote 2010 (KB3054978) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb6e0f.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:11 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Excel MUI (English) 2010 - Update 'Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb62f8.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:08 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Outlook MUI (English) 2010 - Update 'Update for Microsoft Outlook 2010 (KB3101535) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb59d4.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:06 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Outlook MUI (English) 2010 - Update 'Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb4ebc.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:03:03 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Shared MUI (English) 2010 - Update 'Security Update for Microsoft Office 2010 (KB3085560) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIb41a2.LOG.


Log: 'Application' Date/Time: 07/01/2016 9:02:18 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office PowerPoint MUI (English) 2010 - Update 'Security Update for Microsoft PowerPoint 2010 (KB2920812) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIa8b10.LOG.


Log: 'Application' Date/Time: 07/01/2016 7:31:22 AM
Type: Error Category: 0
Event: 8193 Source: VSS
Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040154, Class not registered .


Operation:
Set Snapshot Context


Context:
Execution Context: Requestor


Log: 'Application' Date/Time: 07/01/2016 7:31:22 AM
Type: Error Category: 0
Event: 22 Source: VSS
Volume Shadow Copy Service error: A critical component required by the Volume Shadow Copy service is not registered. This might happened if an error occurred during Windows setup or during installation of a Shadow Copy provider. The error returned from CoCreateInstance on class with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} and Name Software Provider is [0x80040154, Class not registered ].


Operation:
Set Snapshot Context


Context:
Execution Context: Requestor


Log: 'Application' Date/Time: 07/01/2016 7:27:19 AM
Type: Error Category: 0
Event: 8193 Source: System Restore
Failed to create restore point (Process = C:\Windows\servicing\TrustedInstaller.exe; Description = Windows Modules Installer; Error = 0x8007043c).


Log: 'Application' Date/Time: 07/01/2016 7:02:03 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Shared MUI (English) 2010 - Update 'Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI1e9b2.LOG.


Log: 'Application' Date/Time: 07/01/2016 7:02:00 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office OneNote MUI (English) 2010 - Update 'Security Update for Microsoft OneNote 2010 (KB3054978) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI1dfd3.LOG.


Log: 'Application' Date/Time: 07/01/2016 7:01:58 AM
Type: Error Category: 0
Event: 1023 Source: MsiInstaller
Product: Microsoft Office Excel MUI (English) 2010 - Update 'Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI1d539.LOG.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 07/01/2016 7:40:23 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Log: 'Application' Date/Time: 07/01/2016 7:40:22 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Log: 'Application' Date/Time: 07/01/2016 7:10:27 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Log: 'Application' Date/Time: 07/01/2016 6:43:55 AM
Type: Warning Category: 3
Event: 3036 Source: Microsoft-Windows-Search
The content source <file:C:/Program Files (x86)/Microsoft Office/Office14/Visio Content/> cannot be accessed.


Context: Application, SystemIndex Catalog


Details:
The object was not found. (HRESULT : 0x80041201) (0x80041201)




Log: 'Application' Date/Time: 07/01/2016 6:09:11 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Log: 'Application' Date/Time: 07/01/2016 6:09:10 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


Log: 'Application' Date/Time: 07/01/2016 6:05:27 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:05:27 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:05:04 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:05:04 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:05:01 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, HiPerfCooker_v1, has been registered in the Windows Management Instrumentation namespace Root\WMI to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:05:01 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, HiPerfCooker_v1, has been registered in the Windows Management Instrumentation namespace Root\WMI to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:58 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:58 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:58 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:58 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:56 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:56 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:56 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


Log: 'Application' Date/Time: 07/01/2016 6:04:56 AM
Type: Warning Category: 0
Event: 63 Source: Microsoft-Windows-WMI
A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/01/2016 9:42:48 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 05/01/2016 5:06:22 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 04/01/2016 11:03:04 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 04/01/2016 10:20:37 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 04/01/2016 9:30:36 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 8:22:16 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 7:33:22 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 5:23:32 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 4:04:19 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 3:35:53 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 2:51:15 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 29/12/2015 12:04:37 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 28/12/2015 9:07:09 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 28/12/2015 6:41:41 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 23/11/2015 9:54:37 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 15/11/2015 5:52:43 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 14/11/2015 9:04:05 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 13/11/2015 9:03:25 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 12/11/2015 9:02:03 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Log: 'System' Date/Time: 11/11/2015 9:19:49 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 07/01/2016 6:30:39 PM
Type: Error Category: 0
Event: 11 Source: Disk
The driver detected a controller error on \Device\Harddisk4\DR4.


Log: 'System' Date/Time: 07/01/2016 6:30:39 PM
Type: Error Category: 0
Event: 11 Source: Disk
The driver detected a controller error on \Device\Harddisk3\DR3.


Log: 'System' Date/Time: 07/01/2016 6:30:39 PM
Type: Error Category: 0
Event: 11 Source: Disk
The driver detected a controller error on \Device\Harddisk2\DR2.


Log: 'System' Date/Time: 07/01/2016 6:30:39 PM
Type: Error Category: 0
Event: 11 Source: Disk
The driver detected a controller error on \Device\Harddisk1\DR1.


Log: 'System' Date/Time: 07/01/2016 6:30:25 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Windows 7 for x64-based Systems (KB3033929).


Log: 'System' Date/Time: 07/01/2016 6:30:05 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:30:02 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft OneNote 2010 (KB3054978) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:30:00 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:29:58 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Outlook 2010 (KB3101535) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:29:55 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:29:53 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office 2010 (KB3085560) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:29:50 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x800b0100: Security Update for Windows 7 for x64-based Systems (KB2984976).


Log: 'System' Date/Time: 07/01/2016 6:29:46 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB3037574).


Log: 'System' Date/Time: 07/01/2016 6:29:39 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x800b0100: Security Update for Windows 7 for x64-based Systems (KB2984972).


Log: 'System' Date/Time: 07/01/2016 6:29:30 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Windows 7 for x64-based Systems (KB3004375).


Log: 'System' Date/Time: 07/01/2016 6:29:10 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft PowerPoint 2010 (KB2920812) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 6:29:05 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Windows 7 for x64-based Systems (KB3031432).


Log: 'System' Date/Time: 07/01/2016 9:07:43 AM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Windows 7 for x64-based Systems (KB3033929).


Log: 'System' Date/Time: 07/01/2016 9:03:19 AM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition.


Log: 'System' Date/Time: 07/01/2016 9:03:19 AM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft OneNote 2010 (KB3054978) 32-Bit Edition.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 08/01/2016 5:25:00 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.00#00000#.


Log: 'System' Date/Time: 08/01/2016 5:24:16 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 6:30:31 PM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.


Log: 'System' Date/Time: 07/01/2016 6:30:31 PM
Type: Warning Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped. Module Path: C:\Windows\system32\athihvs.dll


Log: 'System' Date/Time: 07/01/2016 9:00:15 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 8:24:00 AM
Type: Warning Category: 0
Event: 3 Source: BTHUSB
A command sent to the adapter has timed out. The adapter did not respond.


Log: 'System' Date/Time: 07/01/2016 7:41:51 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.00#00000#.


Log: 'System' Date/Time: 07/01/2016 7:41:01 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 7:40:25 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.


Log: 'System' Date/Time: 07/01/2016 7:09:49 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 7:09:20 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.


Log: 'System' Date/Time: 07/01/2016 7:09:20 AM
Type: Warning Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped. Module Path: C:\Windows\system32\athihvs.dll


Log: 'System' Date/Time: 07/01/2016 6:56:36 AM
Type: Warning Category: 0
Event: 4228 Source: Tcpip
TCP/IP has chosen to restrict the scale factor due to a network condition. This could be related to a problem in a network device and will cause degraded throughput.


Log: 'System' Date/Time: 07/01/2016 6:43:39 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.00#00000#.


Log: 'System' Date/Time: 07/01/2016 6:42:47 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 6:09:13 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.


Log: 'System' Date/Time: 07/01/2016 5:39:14 AM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.


Log: 'System' Date/Time: 07/01/2016 5:38:39 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.


Log: 'System' Date/Time: 07/01/2016 5:38:39 AM
Type: Warning Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped. Module Path: C:\Windows\system32\athihvs.dll


Log: 'System' Date/Time: 07/01/2016 5:20:54 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.00#00000#.
 
I was expecting to see that some services failed to start, but it doesn't appear that is the case.

Let's try resetting some of the Windows services and see if we can get DISM working.

Run Windows Repairs
  1. Download Windows Repair (All-in-One) Portable to your desktop.
  2. Once the file is downloaded, right-click on the file on your desktop and choose Extract All...
    Extract.JPG
  3. Keep the defaults and click the Extract button.
  4. A folder named tweaking.com_windows_repair_aio will be extracted to the desktop. Once the extraction is complete the folder will open.
  5. Inside this folder, there is a folder named Tweaking.com - Windows Repair. Open this folder as well.
    Capture.JPG

  6. Double-click on Repair_Windows.exe to open. Note: Please make sure all of your programs are closed and anything you were working on is saved as we will be rebooting.
  7. When the program opens, click the Reboot to Safe Mode button at the bottom of the screen. Answer Yes to allow.
  8. Once rebooted into Safe Mode, open the program again. When the program opens, click the Repairs tab and click the Open Repairs button.
  9. A backup of your registry will be made. After a few moments you will have many options from which you can choose.
  10. Please click the Unselect All button and then click to enable only the following ones:

    03 - Reset Service Permissions
    04 - Register System Files
    10 - Remove Policies Set By Infection
    14 - Remove Temp Files
    17 - Repair Windows Updates
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Services to Default Startup

  11. Ensure the Restart check box is selected and click the Start Repairs button in the lower right of the screen. This may take some time to run so be patient.
    StartRepairsWithReboot.JPG
  12. Once the fixes are complete you will be prompted to restart your machine. Answer Yes.
 
From that screenshot it would appear that the cryptographic service has a problem.
Let's see if we can get more information from the event logs.
Please restart your computer, then follow the instructions below:

Event Log Collection

  • Download VEW by Vino Rosso here: VEW.EXE
  • Right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.
  • Click the check boxes next to Application and System located under Select log to query on the upper left.
  • Under Select type to list on the right click the boxes next to Error, Warning and Critical (not XP).
  • Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run.
  • Once it finishes it will display a log file in notepad.
  • Copy and paste its entire contents into your next reply.
 
Back
Top