Ok, I’ll have a look at this in a few. The logs take me a while to go over. So I’ll make a reply later tonight or tomorrow after work.
Computer blue screen on shutdown, can't do any Windows updates
Collapse
X
-
-
-
Copy the content of the code box below.
[COLOR=rgb(184, 49, 47)]Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.
Code:Start:: CloseProcesses: SystemRestore: On CreateRestorePoint: RemoveProxy: C:\Windows\system32\drivers\etc\hosts.ics C:\Windows\system32\drivers\etc\hosts Hosts: HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [RuntimeBroker_tMaIE] => wscript.exe "C:\Users\Isaac\AppData\Roaming\tMaIE.vbs" (No File) <==== ATTENTION C:\Users\Isaac\AppData\Roaming\tMaIE.vbs HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [MicrosoftEdgeAutoLaunch_E61B34E8EC343F2555F1806FED7939D1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4088272 2023-07-21] (Microsoft Corporation -> Microsoft Corporation) CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION CHR HomePage: Profile 3 -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311256¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC2KfnG8vMCKm3vGZa%2FXNlWN0tXIMKbngDuAjl4mz0LjLQt%2B1clYw9AXDdKfbY0VltFgRBsV5W1gBD40yD%2Fa%2Bf6hwgm%2FhRnHfjTwklzVl%2B3J4K9qfYAbY8Lx6p15Ot4o2VMpncuztKIV8DD7WOSkR2oO0agq4ALQOJpkIvZ2T05lYxdID%2BhyxQuFtzkYdlagNLI%3D C:\Users\Isaac\AppData\Roaming\1000219050 C:\Users\Isaac\AppData\Roaming\1000071060 ShortcutWithArgument: C:\Users\Isaac\AppData\Roaming\Microsoft\Windows\Start Menu\Яндекс.Игры.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> url="hxxps://gogone.ru/gl/?cid=31444&oid=75XMXY&v=6&utm_campaign=20.8 " <==== Cyrillic HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\StartupApproved\StartupFolder: => "jweupdater.exe" cmd: net stop bits cmd: net stop cryptSvc cmd: net stop wuauserv cmd: net stop msiserver cmd: del /s /q C:\Windows\SoftwareDistribution\download\*.* cmd: net start cryptSvc cmd: net start bits cmd: net start wuauserv cmd: net start msiserver cmd: netsh winsock reset catalog cmd: netsh int ip reset C:\resettcpip.txt cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state ON cmd: Bitsadmin /Reset /Allusers cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: winmgmt /salvagerepository cmd: winmgmt /verifyrepository cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*" CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*" CMD: ipconfig /flushdns C:\Windows\Temp\*.* C:\WINDOWS\system32\*.tmp C:\WINDOWS\syswow64\*.tmp ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions emptytemp: Reboot: End::
Comment
-
If windows update fails after the fix with FRST, we will need to check the status of the services appended to it…
Download and unzip farbar service scanner to your desktop, right click and run as admin…check all boxes and hit scan.
Post the log created.Comment
-
-
This log shows you ran the previous fix again. I need you to run the latest one.
Code:Start:: CloseProcesses: SystemRestore: On CreateRestorePoint: RemoveProxy: C:\Windows\system32\drivers\etc\hosts.ics C:\Windows\system32\drivers\etc\hosts Hosts: HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [RuntimeBroker_tMaIE] => wscript.exe "C:\Users\Isaac\AppData\Roaming\tMaIE.vbs" (No File) <==== ATTENTION C:\Users\Isaac\AppData\Roaming\tMaIE.vbs HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [MicrosoftEdgeAutoLaunch_E61B34E8EC343F2555F1806FED7939D1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4088272 2023-07-21] (Microsoft Corporation -> Microsoft Corporation) CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION CHR HomePage: Profile 3 -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311256¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC2KfnG8vMCKm3vGZa%2FXNlWN0tXIMKbngDuAjl4mz0LjLQt%2B1clYw9AXDdKfbY0VltFgRBsV5W1gBD40yD%2Fa%2Bf6hwgm%2FhRnHfjTwklzVl%2B3J4K9qfYAbY8Lx6p15Ot4o2VMpncuztKIV8DD7WOSkR2oO0agq4ALQOJpkIvZ2T05lYxdID%2BhyxQuFtzkYdlagNLI%3D C:\Users\Isaac\AppData\Roaming\1000219050 C:\Users\Isaac\AppData\Roaming\1000071060 ShortcutWithArgument: C:\Users\Isaac\AppData\Roaming\Microsoft\Windows\Start Menu\Яндекс.Игры.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> url="hxxps://gogone.ru/gl/?cid=31444&oid=75XMXY&v=6&utm_campaign=20.8 " <==== Cyrillic HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\StartupApproved\StartupFolder: => "jweupdater.exe" cmd: net stop bits cmd: net stop cryptSvc cmd: net stop wuauserv cmd: net stop msiserver cmd: del /s /q C:\Windows\SoftwareDistribution\download\*.* cmd: net start cryptSvc cmd: net start bits cmd: net start wuauserv cmd: net start msiserver cmd: netsh winsock reset catalog cmd: netsh int ip reset C:\resettcpip.txt cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state ON cmd: Bitsadmin /Reset /Allusers cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: winmgmt /salvagerepository cmd: winmgmt /verifyrepository cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*" CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*" CMD: ipconfig /flushdns C:\Windows\Temp\*.* C:\WINDOWS\system32\*.tmp C:\WINDOWS\syswow64\*.tmp ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions emptytemp: Reboot: End::
Comment
-
-
-
-
Safe mode or anything?
wuauserv Service is not running. Checking service configuration:
Checking Start type of wuauserv: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll of wuauserv: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
As for this error…
Download the all in one repair tool.
Boot into safe mode and run the tool with all repairs checked.Comment
-
Comment
-
-
Alright I booted it a few times and it just kind of booted suddenly? Gonna try the repair tool now.Comment
-
OK. I am headed to sleep. Post a new FSS log if you still do not have updates after the repair tool. I still need to see the log from the latest FRST fix. When you have time,Comment
-
Comment