Windows 11 restarts when given shutdown command


SwanRonson

Member
Local time
7:54 PM
Posts
3
OS
Windows 11
I recently upgraded my desktop with a new Aorus X570 Elite Wi-Fi motherboard, AMD Ryzen 5600X CPU and 2 TB SSD.

The computer runs fine and seems stable to include running games, however when given the shutdown command, it will restart after a split second of appearing powered down. I do not receive a BSOD. I have tried several methods of shutting down the computer and the only way I can get the computer to shutdown is to hold down the power button.

Here are the list of things I have done that I gathered from other forum posts:

Installed all Windows 11 updates (Version 21H2 OS Build 22000.588)
Installed the latest BIOS for my motherboard (F37a dated February 2022)
Turned off Fast Boot in power options
Disabled the option for the ethernet and wi-fi adapters to wake my computer
Disabled the "automatically restart" option on a crash
Ran sfc /SCANNOW in the command prompt; Windows Resource Protection did not find and integrity violations.
Reseated my CPU, RAM, and GPU and checked all the connections running to the motherboard. Everything is secure
Checked device manager and made sure i was not getting any exclamation marks. Everything looks fine.
I edited the registry like the guy did in this video:

Here is the event log from the tool posted on another post. I would appreciate any help.

OneDrive Link to Event Log :
 
Windows Build/Version
Version 21H2 OS Build 22000.588

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Homemade
    CPU
    AMD Ryzen 5600X
    Motherboard
    Aorus X570 Elite Wi-Fi
    Memory
    G.Skill Trident 32GB DDR4 3200
    Graphics Card(s)
    Nvidia GTX 1080
    Hard Drives
    2 TB Samsung M.2
    PSU
    Corsair RM1000X
    Case
    Corsair Carbide 500R
    Cooling
    Wraith AMD Stock Cooler
    Antivirus
    Windows Defender

zbook

Well-known member
Power User
VIP
Local time
6:54 PM
Posts
1,169
OS
Windows 10
Please run the V2 log collector > upload results into this thread



Code:
Event[1868]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T15:46:11.8030000Z
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info 
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.


Code:
Event[2142]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T16:07:15.8370000Z
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info 
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
Last edited:

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation

zbook

Well-known member
Power User
VIP
Local time
6:54 PM
Posts
1,169
OS
Windows 10
Please post a share link to your other thread.

Code:
SL_GEN_STATE_INVALID_LICENSE




Run the activation troubleshooter:



Run:



Open administrative command prompt or powershell and copy and paste:

GP 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power\' -Name 'HiberbootEnabled'|Select -ExpandProperty HiberbootEnabled
(GP "HKLM:\SYSTEM\CurrentControlSet\Control\Power\")."HibernateEnabled"
WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List


Post images or share links of the commands with results into this thread.
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation

SwanRonson

Member
Thread Starter
Local time
7:54 PM
Posts
3
OS
Windows 11
Windows activated.

Tuneup log is posted in the OneDrive

Here is a screenshot from the last step:

1647739578877.png

Norton Security was installed when I downloaded the App Center for the Motherboard. I uninstalled it, but it still shows up here for some reason.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Homemade
    CPU
    AMD Ryzen 5600X
    Motherboard
    Aorus X570 Elite Wi-Fi
    Memory
    G.Skill Trident 32GB DDR4 3200
    Graphics Card(s)
    Nvidia GTX 1080
    Hard Drives
    2 TB Samsung M.2
    PSU
    Corsair RM1000X
    Case
    Corsair Carbide 500R
    Cooling
    Wraith AMD Stock Cooler
    Antivirus
    Windows Defender

zbook

Well-known member
Power User
VIP
Local time
6:54 PM
Posts
1,169
OS
Windows 10
Please keep the posts in sequence so that the newest information is in the newest post and oldest information is in the oldest post.

Please perform in sequence:

1) Was there another thread?
Please post a link

2) Uninstall Norton software using their uninstall tool:

3) Run: https://aka.ms/GetPCHealthCheckApp
Post images or share links into this thread

4) Place the computer into clean boot:

5) Run a new V2 and post into the newest post

6) Open administrative command prompt and type or copy and paste:

powercfg -h off
(GP "HKLM:\SYSTEM\CurrentControlSet\Control\Power\")."HibernateEnabled"
WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List

Post images or share links of the commands with results into this thread.

Then prepare for a reboot and type:
shutdown /r


Open administrative command prompt and type or copy and paste:
shutdown /s

Report the findings with this command.
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation

SwanRonson

Member
Thread Starter
Local time
7:54 PM
Posts
3
OS
Windows 11
1) There is no other thread. I was just stating that I went through steps to troubleshoot a similar problem other people were having.

2) Norton has been removed using the Norton Remove and Reinstall Tool

3)Images from PC Health Check:

PCHC.png
PCHC2.png

4) Clean Boot completed

5) New V2 results posted in the OneDrive (link in original post)

6) Admin Command Prompt copy/paste complete.
PS.png
System was restarted with shutdown /r and then shutdown with shutdown /s but then immediately powered back up.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Homemade
    CPU
    AMD Ryzen 5600X
    Motherboard
    Aorus X570 Elite Wi-Fi
    Memory
    G.Skill Trident 32GB DDR4 3200
    Graphics Card(s)
    Nvidia GTX 1080
    Hard Drives
    2 TB Samsung M.2
    PSU
    Corsair RM1000X
    Case
    Corsair Carbide 500R
    Cooling
    Wraith AMD Stock Cooler
    Antivirus
    Windows Defender

zbook

Well-known member
Power User
VIP
Local time
6:54 PM
Posts
1,169
OS
Windows 10
Please run:

1) activation troubleshooter:



Code:
License Activation (slui.exe) failed with the following error code:
hr=0x803F7001



2) Get_Powercfg_info.bat - Click here to go to the BSOD batch repository to download and run this batch file.


3)

4) Administrative command prompt and type or copy and paste:

msdt.exe -id PowerDiagnostic
msdt.exe -id DeviceDiagnostic

For each troubleshooter click view detailed information > post images or share links into this thread


5) Uninstall Norton software using their uninstall tool:

6) Make sure Microsoft Defender is on


7) After completely uninstalling Norton and making sure Microsoft defender run administrative command prompt:

WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List

Post images or share links displaying the commands with results.

shutdown /s

Report the findings with shutdown after uninstalling Norton and making sure Microsoft Defender is on.
(Please make sure that Norton remains uninstalled during the troubleshooting)




Code:
Event[566]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:07:34.1630000Z
  Event ID: 187
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
User-mode process attempted to change the system state by calling SetSuspendState or SetSystemPowerState APIs.

Event[567]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:07:34.1830000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 0 to 1.

Reason: 4

Event[568]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:07:34.6460000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: Application API

Event[569]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:07:35.8620000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.


Event[581]
  Log Name: System
  Source: Microsoft-Windows-Power-Troubleshooter
  Date: 2022-03-18T17:08:06.3040000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: DESKTOP-K3HBRDS
  Description:
The system has returned from a low power state.

Sleep Time: ?2022?-?03?-?18T21:07:34.158969600Z
Wake Time: ?2022?-?03?-?18T21:08:05.290406700Z

Wake Source: Unknown


Event[634]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:17:25.4390000Z
  Event ID: 187
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
User-mode process attempted to change the system state by calling SetSuspendState or SetSystemPowerState APIs.

Event[635]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:17:25.4520000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 4 to 5.

Reason: 4

Event[636]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:17:25.9470000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: Application API

Event[637]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:17:27.7040000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.

Event[638]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-18T17:17:54.5000000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system time has changed to ?2022?-?03?-?18T21:17:54.500000000Z from ?2022?-?03?-?18T21:17:27.704409800Z.

Change Reason: System time synchronized with the hardware clock.
Process: '' (PID 4).

RTC time: ?2022?-?03?-?18T17:17:54.500000000Z
Current time zone bias: 240
RTC time is in UTC: false
System time was based on RTC time: false


Event[660]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:18:35.8070000Z
  Event ID: 187
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
User-mode process attempted to change the system state by calling SetSuspendState or SetSystemPowerState APIs.

Event[661]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:18:35.8220000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 8 to 9.

Reason: 4

Event[662]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:18:35.9960000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: Application API

Event[663]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T17:18:37.5960000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.

Event[664]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-19T09:57:52.5000000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system time has changed to ?2022?-?03?-?19T13:57:52.500000000Z from ?2022?-?03?-?18T21:18:37.595863100Z.

Change Reason: System time synchronized with the hardware clock.
Process: '' (PID 4).

RTC time: ?2022?-?03?-?19T09:57:52.500000000Z
Current time zone bias: 240
RTC time is in UTC: false
System time was based on RTC time: false


Event[675]
  Log Name: System
  Source: Microsoft-Windows-Power-Troubleshooter
  Date: 2022-03-19T09:57:55.1580000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: DESKTOP-K3HBRDS
  Description:
The system has returned from a low power state.

Sleep Time: ?2022?-?03?-?18T21:18:35.802900400Z
Wake Time: ?2022?-?03?-?19T13:57:54.213071400Z

Wake Source: Unknown


Event[1018]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:18:28.6810000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:

Event[1019]
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2022-03-19T10:18:34.3960000Z
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
User Logoff Notification for Customer Experience Improvement Program

Event[1020]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T10:18:34.8250000Z
  Event ID: 187
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
User-mode process attempted to change the system state by calling SetSuspendState or SetSystemPowerState APIs.

Event[1021]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T10:18:34.8390000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 0 to 1.

Reason: 7

Event[1022]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T10:18:35.1400000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: Application API

Event[1023]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T10:18:36.7150000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.

Event[1024]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-19T10:19:03.5000000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system time has changed to ?2022?-?03?-?19T14:19:03.500000000Z from ?2022?-?03?-?19T14:18:36.714967100Z.

Change Reason: System time synchronized with the hardware clock.
Process: '' (PID 4).

RTC time: ?2022?-?03?-?19T10:19:03.500000000Z
Current time zone bias: 240
RTC time is in UTC: false
System time was based on RTC time: false


Event[1035]
  Log Name: System
  Source: Microsoft-Windows-Power-Troubleshooter
  Date: 2022-03-19T10:19:06.5230000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: DESKTOP-K3HBRDS
  Description:
The system has returned from a low power state.

Sleep Time: ?2022?-?03?-?19T14:18:34.819633600Z
Wake Time: ?2022?-?03?-?19T14:19:05.531210800Z

Wake Source: Unknown



Event[1332]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:05:04.1140000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 0 to 1.

Reason: 10


Event[1334]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:05.2710000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 1 to 3.

Reason: 10

Event[1335]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:07.0140000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: System Idle



Event[1336]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:08.5390000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.

Event[1337]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-19T11:21:12.5000000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system time has changed to ?2022?-?03?-?19T15:21:12.500000000Z from ?2022?-?03?-?19T15:21:08.539099000Z.

Change Reason: System time synchronized with the hardware clock.
Process: '' (PID 4).

RTC time: ?2022?-?03?-?19T11:21:12.500000000Z
Current time zone bias: 240
RTC time is in UTC: false
System time was based on RTC time: false

Event[1338]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:12.5000000Z
  Event ID: 131
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
Firmware S3 times. ResumeCount: 1, FullResume: 1469, AverageResume: 1469

Event[1339]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:12.5000000Z
  Event ID: 130
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
Firmware S3 times. SuspendStart: 2394899, SuspendEnd: 2395024



Event[1342]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:14.4790000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 3 to 4.

Reason: 10

Event[1343]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:21:14.5470000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 4 to 6.

Reason: 10

Event[1344]
  Log Name: System
  Source: Microsoft-Windows-Power-Troubleshooter
  Date: 2022-03-19T11:21:14.7760000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: DESKTOP-K3HBRDS
  Description:
The system has returned from a low power state.

Sleep Time: ?2022?-?03?-?19T15:21:05.203467100Z
Wake Time: ?2022?-?03?-?19T15:21:14.534508800Z

Wake Source: Unknown


Event[1353]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:22:25.5670000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 6 to 7.

Reason: 10

Event[1354]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:51:39.2040000Z
  Event ID: 566
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The system session has transitioned from 7 to 9.

Reason: 10

Event[1355]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:51:40.7260000Z
  Event ID: 42
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system is entering sleep.

Sleep Reason: System Idle

Event[1356]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:51:42.1780000Z
  Event ID: 107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system has resumed from sleep.

Event[1357]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-19T11:51:45.5000000Z
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The system time has changed to ?2022?-?03?-?19T15:51:45.500000000Z from ?2022?-?03?-?19T15:51:42.178880000Z.

Change Reason: System time synchronized with the hardware clock.
Process: '' (PID 4).

RTC time: ?2022?-?03?-?19T11:51:45.500000000Z
Current time zone bias: 240
RTC time is in UTC: false
System time was based on RTC time: false

Event[1358]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:51:45.5000000Z
  Event ID: 131
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
Firmware S3 times. ResumeCount: 2, FullResume: 1469, AverageResume: 1469

Event[1359]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-19T11:51:45.5000000Z
  Event ID: 130
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
Firmware S3 times. SuspendStart: 4224869, SuspendEnd: 4224993


Code:
Event[1931]
  Log Name: Application
  Source: Microsoft-Windows-Security-SPP
  Date: 2022-03-19T19:41:33.5010000Z
  Event ID: 8198
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
License Activation (slui.exe) failed with the following error code:
hr=0x803F7001
Command-line arguments:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8;NotificationInterval=1440;Trigger=NetworkAvailable



Code:
Event[203]
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2022-03-18T15:48:36.6830000Z
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[204]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-18T15:48:36.9440000Z
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The operating system is shutting down at system time ?2022?-?03?-?18T19:48:36.944682300Z.

Event[205]
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2022-03-18T15:48:51.7300000Z
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The operating system started at system time ?2022?-?03?-?18T19:48:51.500000000Z.


Event[335]
  Log Name: System
  Source: User32
  Date: 2022-03-18T16:47:04.7700000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[394]
  Log Name: System
  Source: Service Control Manager
  Date: 2022-03-18T16:53:45.5250000Z
  Event ID: 7043
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The Windows Security Service service did not shut down properly after receiving a preshutdown control.


Event[481]
  Log Name: System
  Source: User32
  Date: 2022-03-18T17:05:48.6720000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the restart of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: restart
 Comment:


Event[563]
  Log Name: System
  Source: User32
  Date: 2022-03-18T17:07:30.3100000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[817]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:06:46.8130000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\winlogon.exe (DESKTOP-K3HBRDS) has initiated the restart of computer DESKTOP-K3HBRDS on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x500ff
 Shutdown Type: restart
 Comment:


Event[923]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:10:02.1820000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\winlogon.exe (DESKTOP-K3HBRDS) has initiated the restart of computer DESKTOP-K3HBRDS on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x500ff
 Shutdown Type: restart
 Comment:


Event[926]
  Log Name: System
  Source: Service Control Manager
  Date: 2022-03-19T10:10:18.0010000Z
  Event ID: 7043
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: DESKTOP-K3HBRDS
  Description:
The Windows Security Service service did not shut down properly after receiving a preshutdown control.


Event[1018]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:18:28.6810000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[1153]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:37:52.6870000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[1240]
  Log Name: System
  Source: User32
  Date: 2022-03-19T10:40:05.3190000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[1570]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:20:43.3480000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\shutdown.exe (DESKTOP-K3HBRDS) has initiated the shutdown of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: shutdown
 Comment:


Event[1662]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:29:39.4750000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\shutdown.exe (DESKTOP-K3HBRDS) has initiated the shutdown of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: shutdown
 Comment:


Event[1745]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:36:55.5310000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:



Event[1838]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:45:10.1190000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[1914]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:46:22.6100000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\winlogon.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x500ff
 Shutdown Type: power off
 Comment:



Event[2022]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:49:32.9820000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\Windows\System32\RuntimeBroker.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment:


Event[2109]
  Log Name: System
  Source: User32
  Date: 2022-03-19T15:50:18.0250000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\winlogon.exe (DESKTOP-K3HBRDS) has initiated the power off of computer DESKTOP-K3HBRDS on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x500ff
 Shutdown Type: power off
 Comment:


Event[3097]
  Log Name: System
  Source: User32
  Date: 2022-03-20T14:30:22.0470000Z
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
The process C:\WINDOWS\system32\msconfig.exe (DESKTOP-K3HBRDS) has initiated the restart of computer DESKTOP-K3HBRDS on behalf of user DESKTOP-K3HBRDS\craig for the following reason: No title for this reason could be found
 Reason Code: 0x40000
 Shutdown Type: restart
 Comment:



Code:
Event[813]
  Log Name: System
  Source: Service Control Manager
  Date: 2022-03-19T10:06:27.5100000Z
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
A service was installed in the system.

Service Name:  Norton WSC Service
Service File Name:  "C:\Program Files\Norton Security\Engine\22.19.8.65\nsWscSvc.exe"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[814]
  Log Name: System
  Source: Service Control Manager
  Date: 2022-03-19T10:06:27.5110000Z
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
A service was installed in the system.

Service Name:  Symantec Eventing Platform
Service File Name:  C:\Program Files\Norton Security\NortonData\22.19.8.65\SymPlatform\SymEvnt.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account: 

Event[815]
  Log Name: System
  Source: Service Control Manager
  Date: 2022-03-19T10:06:27.5120000Z
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-2810344996-103229178-2558991402-1001
  User Name: DESKTOP-K3HBRDS\craig
  Computer: DESKTOP-K3HBRDS
  Description:
A service was installed in the system.

Service Name:  Norton Security
Service File Name:  "C:\Program Files\Norton Security\Engine\22.19.8.65\NortonSecurity.exe" /s "NortonSecurity" /m "C:\Program Files\Norton Security\Engine\22.19.8.65\diMaster.dll" /prefetch:1
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem
 
Last edited:

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation

Latest Tutorials

Top Bottom