update management
1130 TopicsHow to Stop the Win 11 KB5094126 Installation Loop and Safely Upgrade From March Baseline Risk-Free
Hello, I need some advice regarding a persistent Windows Update installation loop affecting my machine. My system is currently on a March baseline and is out of date. My primary goal is to completely stop this endless installation loop so I can successfully upgrade Windows to the latest version in a risk-free manner that doesn’t mess around with system files . What is the most effective, safe and risk-free way to temporarily stop this automatic background update installation loop without it coming back in a few days or causing a lot of background strain, as I feel like when it’s in the background and disabled it is still hammering my hardware and causing high thermal strain, because it flucationing between abled/disabled a lot, this can’t go on, it’s already been a month. Is it 100% safe to use the Microsoft WUShowHide utility (wushowhide.diagcab) as a block to stop the hardware strain, and will it prevent future brightness fluctuations? Will be permanently disable or come back? How can I fix this loop, with absolutely zero risk to my custom graphics profiles, legacy driver stability, or screen brightness thresholds? Does the newly released July Cumulative Update (KB5101650) wrapper contain the renewed firmware validation keys necessary to clear out this March-to-June servicing stack blockage cleanly? Or could it cause system crash or corruption if installed. Are there known risks or side effects with attempting a repair upgrade or an in-place reinstall for this specific loop? I want to completely avoid anything that resets custom device properties, alters display configurations, or reverts stable graphics card driver profiles or potentially gets stuck, as both take up 20-30 on every attempt and harsh to the system. 6.Since my system is currently out of date on a March baseline, what is the safest path to install a newer, stable update without risking my custom display configurations? 7.Has anyone successfully applied a manual UEFI certificate renewal or a Secure Boot key variable override to bypass the expired Microsoft June 2026 validation timeline on general retail hardware? Any risks? My System Specs: -OS Edition: Windows 11 Home Single Language (Retail Channel) -Version / Build: 25H2 (OS Build 26200.8117 - March 2026 Baseline) -Hardware: ASUS Laptop (Model M413A) -Processor: AMD Ryzen 7 4700U with Radeon Graphics (2.00 GHz, 8 Cores) -Memory: 8.00 GB RAM (7.42 GB usable) -Storage: Local C: Drive has 226 GB used out of 477 GB total capacity (251 GB free) Symptoms I Am Experiencing: The 2026-06 Security Update (KB5094126) and the June Preview Update (KB5095093) download completely to 100%. During initialization, the engine throws error 0x80074101 and restarts the download pipeline. This creates a heavy background loop that pins the CPU to high utilization, causing noticeable thermal strain. When my AC power charger is connected, the cooling fans run at a very high audible RPM. I also experience temporary screen brightness flaring strictly when the charger is active, likely due to voltage shifts on the shared motherboard power tracks between the integrated AMD graphics and the system RAM channels when the update engine collides with my stop scripts. Other non- quality updates and daily Windows Defender definitions continue to download and install flawlessly when updates are enable. The issue is strictly isolated to this specific update package and sometimes previews. Tried So Far: Over the past few days, I have tried several methods to safely pause or stop this loop to protect my hardware from constant heat stress: Cache Resets: Cleared the contents of C:\Windows\SoftwareDistribution multiple times. The loop returns as soon as the folder is regenerated. System Scans: Executed SFC /scannow and DISM /Online /Cleanup-Image /RestoreHealth. Both reports show a completely clean component store with no local system file corruption. Service Management: Used temporary command-line scripts to stop 'wuauserv', 'usosvc', and 'bits', and adjusted service recovery actions to prevent them from instantly restarting in the background. These tend to come and go, but most are usually settled at stopped for 2-3 days, and then installation of this lopping security update will force a reattempt on the 2 or 3 day and I have reenter the commands. Built-in Safeguards: Used the "Pause updates for 5 weeks" toggle in Settings just yesterday, where it greyed out for weeks prior, not sure if it will force the reinstall at random again. However, the Windows 11 Home kernel continues to still run background queries every few hours, triggering the hardware strain and it produces loud sounds when charging or resisting disabled setting even if disabling quiets the fan a lot of the time. Cleaned the software distribution folder. Cross-Forum Context & Certificate Discovery: While researching this, I noticed some initial confusion regarding whether the 26200 build numbering indicated an Insider build, but it appears to be a general retail baseline constraint. Some common suggestions include performing a full clean reinstall or a repair upgrade via USB, but I am hesitant due to the risk of overwriting fine-tuned hardware configurations and custom driver properties. Through cross-referencing documentation uploaded by other users facing identical loops on Build 26200, we uncovered a likely root cause. Logs from 'Get-SecureBootUEFI' show that the motherboard's underlying security certificates (Microsoft KEK CA 2011 and Microsoft Corporation UEFI CA 2011) officially expired in late June 2026. Because the current date has passed the certificate validity timeline, the Secure Boot subsystem appears to reject the cryptographic handshake of the June update files, causing the 0x80074101 database error and the subsequent retry loop. As a temporary fix, I am looking into using the official Microsoft WUShowHide diagnostic utility ('wushowhide.diagcab') from my desktop to hide KB5094126 and stabilize my processor and fan noise while waiting for a working patch wrapper that lets me upgrade safely. I would deeply appreciate any verified engineering insight or workarounds the community has found to help me safely bring this system up to date without side effects. Thank you so much for your time!8Views0likes0CommentsMicrosoft Visual C++ Redistributable rolling back or getting corrupted after every Windows Update.
Hello! So I'm having an issue where multiple users would create a ticket stating they can't access AutoCAD, InDesign, and even sometimes even File Explorer. Now this part is an easy fix, just uninstall/reinstall or repair the Microsoft Visual C++ Redistributable and the issue is fixed. The problem I'm having is that a few days later, the same users would create another ticket with the same issue. I've been going back and forth uninstalling/reinstalling, when a user (that was having this issue before, and I had fixed) brought up that they were able to access AutoCAD fine, until they did a Windows Update and rebooted. Sure enough, I remoted into their PC and their Microsoft Visual C++ Redistributable wasn't updated to the v14. I first contacted AutoCAD and they did some digging and stated the same thing, that the Visual C++ was being rollback. Then I contacted Microsoft and they had me go to Windows support which then they guided me here. So I'm presenting my question here now, anyone else had this issue, and is there a solution to this fix? Thanks!1.8KViews5likes7CommentsWill closing the laptop screen without putting it to sleep damage the computer?
Just switched from a MacBook to a Windows 11 laptop. I'm used to simply closing the laptop lid without manually selecting sleep mode, and I'm concerned whether this action might cause hardware damage or affect the system's lifespan. Need clarification on Windows' default lid-closing behavior and recommended safety settings.31Views0likes1CommentLatest Windows Update Breaks Audio (KB5101650)
The update KB5101650 came in yesterday to my machine running 25H2. Today audio was unusable. I checked all the usual suspects including RTC processor affinity etc. and was unable to find the problem Lenovo Laptop with Intel USB 3.10 eXtesible Host Controller - 1.20 This is the USB 3.0 controler which is connected directly to RME Fireface UCX. I tried to uninstall the update from Settings>Windows Update>Update history>Uninstall Updates But the Update still shows as being installed and no option to uninstall. I uninstalled the RME driver and reinstalled THIS FIXED THE PROBLEM.... wheeeew!101Views0likes1CommentCase Study: Windows Update KB5094126 Causes Data Loss
Two Independent Incidents – Custom Build (ASUS Z390) and HP Pavilion Author: Wasmut Fiedler, Dipl.-Inf. (FH) · IT Consultant · July 19, 2026 Summary The Windows 11 June 2026 Patch Tuesday update KB5094126 (Build 26200.8655 / 26100.8655) caused complete data loss on two unrelated systems due to a BSOD with the error CRITICAL_SERVICE_FAILED (0x5A). Both incidents were carefully documented and forensically investigated using Recovery-Tool. The identical failure pattern on different hardware largely rules out hardware- or manufacturer-specific causes and points to a system-related error in the update. Incident 1 – Doctor’s Office in the Ostalb Region (Custom Build, ASUS Z390) 1.1 System Configuration Hardware: Manufacturer: Custom Build (Alternate), Order No. 271724227, March 18, 2020 Motherboard: ASUS ROG STRIX Z390-E GAMING CPU: Intel Core i7-9700K RAM: 16 GB DDR4-3200 SSD (original): 2x Samsung 970 EVO Plus 500 GB in RAID-1 RAID: Intel RST (Intel RAID 1 Volume) OS: Windows 11 Pro (UEFI boot, originally Win 10 Pro) Build: 26200.8655 after KB5094126 EFI Partition: 100 MB (system partition) Recovery: 1.02 GB, of which 985 MB is used (96% full) 1.2 Sequence of Events July 3, 2026, approx. 6:00 PM: Installation of the CapiCall (Shamrock) software via remote support. After a reboot, a BSOD with the error CRITICAL_SERVICE_FAILED (0x5A) appeared. Initially, CapiCall was suspected as the cause, as the timing seemed to correlate. Extensive recovery attempts over several hours were unsuccessful. A forensic analysis using recovery tool revealed that patient data from the last 6 weeks could no longer be recovered. Older data (dating back to November 2025) was only partially recoverable. All newer file segments found had been overwritten with NULL bytes. The last available complete backup was from May 16, 2026—prior to the June update. The data loss covers the entire period following the last backup, including the complete Q2/2026 quarterly billing statement to the Baden-Württemberg Health Insurance Fund (estimated loss: approximately 100,000 euros). 1.3 Subsequent Findings After the KB5094126 issue came to light due to a second independent incident (see Section 2), the initial suspicion regarding CapiCall was revised. The BSOD error code CRITICAL_SERVICE_FAILED (0x5A) matches exactly the reported symptoms of KB5094126 on other systems. The full recovery partition (985 MB of 1.02 GB used) matches the pattern described by Windows Latest: On devices with a small or full EFI/recovery partition, the Secure Boot certificate update from KB5094126 fails—resulting in a BSOD. Incident 2 – Personal HP Pavilion Laptop 2.1 System Configuration Hardware: Manufacturer: HP (Pavilion, Model 17-cd0111ng) OS: Windows 11 Pro Last update before the incident: March 2026 (all updates through March installed) Update: KB5094126 (June 2026 Patch Tuesday) 2.2 Sequence of Events June 25, 2026: The user started the laptop after a long period of inactivity (last used in March 2026). Windows automatically installed the pending June update KB5094126. After restarting, the system was no longer bootable. All of Windows’ built-in recovery mechanisms failed. A forensic analysis using recovery tool revealed the same damage pattern as in Incident 1: the directory structure was only rudimentarily intact, and most file areas had been overwritten with NULL bytes. Private data—including documents required by the tax office—could not be recovered. A complete reinstallation of Windows was necessary. 2.3 Significance of This Incident This incident is particularly significant from a forensic perspective because it completely rules out third-party software as the cause. The laptop had not undergone any changes since March 2026. The only new element was KB5094126. The identical damage pattern on completely different hardware (HP instead of ASUS, different SSD, different configuration) proves that the cause lies in the update itself. 3. Forensic Findings – Identical Damage Pattern After analysis with recovery tool, both systems exhibited the same pattern: • Directory structure partially still intact (filenames, metadata) • File contents predominantly overwritten with NULL bytes (0x00) • Newer data more severely affected than older data—typical of TRIM activation • Operating system completely compromised • No signs of external interference (no virus, no ransomware) The NULL-byte pattern is characteristic of a TRIM command executed immediately after data loss—which is typical in the case of a BSOD on modern NVMe SSDs. The combination of a BSOD caused by KB5094126 and an immediate TRIM command explains the complete and irreversible data loss. Classification as part of the known KB5094126 issue KB5094126 was released on June 9, 2026, as the June Patch Tuesday update for Windows 11 24H2 and 25H2. Immediately after the rollout, reports of system failures began to surface: • Over 150 reports in less than 48 hours on Windows Latest • BSOD error codes 0xc0430001 and CRITICAL_SERVICE_FAILED (0x5A) • BitLocker recovery loops on affected systems • HP systems particularly affected, but other hardware is also impacted • Cause: The update affects Secure Boot files, certificates, and EFI content • The update fails on devices with a small EFI partition (100 MB) Microsoft has confirmed isolated issues with KB5094126 but has not yet officially acknowledged the BSOD error (as of July 19, 2026). 5. Why this report is important The incidents documented here differ from most reported KB5094126 cases in one key respect: the data loss is irreversible. While most affected users “only” experienced an unbootable PC—a problem that could be resolved by uninstalling the update or performing a system restore—the combination of BSOD and NVMe-TRIM resulted in complete data loss on both systems documented here. Professional data recovery companies (Kroll Ontrack, Attingo, comfor-it) confirmed the irreversibility of the data loss. The financial damage in the business case (approximately 100,000 euros in quarterly revenue) as well as the personal damage in the private case (tax documents) far exceed what can be expected from a security update. 6. Demands and Recommendations To Microsoft: • Official acknowledgment of the BSOD issue caused by KB5094126 on systems with a small EFI/recovery partition • Pre-installation check: Ensure sufficient storage space on the EFI/recovery partition • Warn or block installation if the recovery partition is more than 90% full • Goodwill policy for affected users who have suffered irreversible data loss • Improve TRIM behavior during a BSOD: Do not perform an immediate TRIM before creating a minidump To system administrators and IT support staff: • Check the recovery partition before Patch Tuesday updates—ensure at least 500 MB of free space • Evaluate NVMe TRIM in critical environments—disabling TRIM increases the chances of data recovery • Perform a backup immediately BEFORE Windows updates—not just as part of daily routine backups • On NVMe SSDs: Reevaluate your backup strategy—TRIM makes data recovery after a BSOD virtually impossible 7. Sources and Further Reports Windows Latest, June 14, 2026: ‘Windows 11 KB5094126 causes BSODs on some PCs (HP?), breaks OneDrive in File Explorer’ Windows Latest, June 21, 2026: 'Microsoft confirms issues in Windows 11 KB5094126 June 2026 update' Neowin, June 15, 2026: ‘Windows 11 KB5094126 Causes BSODs, Freezing, and Forces BitLocker Lockout’ allthings.how, June 16, 2026: 'Windows 11 KB5094126 Issues: BSOD, BitLocker, and OneDrive Fixes' WinCentral, June 16, 2026: ‘Windows 11 KB5094126 Issues: BSOD, BitLocker, & OneDrive’ CyberSecurityNews, June 15, 2026: 'Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker Recovery' Microsoft Feedback Hub: Multiple entries regarding CRITICAL_SERVICE_FAILED after KB5094126 The author is available for questions and additional information.6Views0likes0CommentsExcessive DMP Files in System32
I'm not terribly familiar with OS troubleshooting, but in trying to manage storage on my C-drive, I've noticed I have around 43GB of .dmp files in C/Windows/System32 alone. I'm usually under the impression that .dmp are log files more than anything and that I can 'safely' dispose of or move them off of my C-drive, but I'm wary of touching anything in System32 in particular. This machine has never had an issue of crashing, and certainly not as far back as these .dmp go. I also thought that the repository for those would be a different folder or file-name format. Can these be safely deleted/moved to a different volume without impacting my OS? This is on Windows 11 Pro, and the computer is kept up to date. It is my intention to swap out the drive for a larger one in the near future, but it does leave me with some concern as to this problem only growing. Attached is a WinDirStat screengrab for context.61Views0likes2CommentsWhat is an enablement package?
Windows 11, versions 22H2 and 23H2 share a common core operating system with an identical set of system files. As a result, the new features in Windows 11, version 23H2 are included in the latest monthly quality update for Windows 11, version 22H2 but are in an inactive and dormant state. These new features will remain dormant until they are turned on through the “enablement package,” a small, quick-to-install “master switch” that activates the Windows 11, version 23H2 features. The enablement package is a great option for installing a scoped feature update like Windows 11, version 23H2 as it enables an update from version 22H2 to version 23H2 with a single restart, reducing update downtime. This enables devices to take advantage of new features now. For version 22H2 devices that receive updates directly from Windows Update or Windows Server Updates Services (WSUS), devices automatically get the enablement package by installing the feature update to Windows 11, version 23H2.49KViews14likes12CommentsAfter the system update, the network status icon on the lock screen appears as a globe.
After installing a system update, the network status icon in the lower-right corner of the lock screen changed from a Wi-Fi or Ethernet icon to a globe icon, indicating no network access. However, after unlocking the device and accessing the home screen, the network connection works perfectly fine, and both the browser and apps can access the internet. I have tried resetting the network settings and updating the network adapter driver, but the icon issue still persists on the lock screen.27Views0likes1Comment2026-07 Windows 11 Updates, hanging on "do not power off computer..."
Good afternoon, So we patch our fleet with Intune (hotpatching, obviously not a thing in July) our test devices all patched late yesterday into today and so far every one of them has installed what looks to be 2 patches (two reboots) and then hangs on the black screen stating "do not turn off your computer" with the animation going.... We let one sit there for ~30 minutes and another ~20 minutes before hard power cycling them, at which point they booted straight into Windows and all patches were properly applied. It's acting as if the patches applied properly and were completed, Windows just didn't get the **bleep** memo! We are seeing this with both Windows 11 24H2 and 25H2 and Lenovo T14's and X1 Carbons. I have seen reports in the past of a similar issue with Lenovo devices due to their odd power management, however we didn't experience this in January when many others did, so I'm not convinced that is the case.. Anyone else seeing similar behavior with the July 2026 (MASSIVE) update? Thanks, -Corey472Views0likes6Comments