Greenstick4466

New Member
Joined
Jul 20, 2026
Messages
1
Hello, I need some advice regarding a persistent Windows Update installation loop affecting my machine. My system is currently on a March baseline and is out of date. My primary goal is to completely stop this endless installation loop so I can successfully upgrade Windows to the latest version in a risk-free manner that doesn’t mess around with system files .

1. What is the most effective, safe and risk-free way to temporarily stop this automatic background update installation loop without it coming back in a few days or causing a lot of background strain, as I feel like when it’s in the background and disabled it is still hammering my hardware and causing high thermal strain, because it flucationing between abled/disabled a lot, this can’t go on, it’s already been a month.

2. Is it 100% safe to use the Microsoft WUShowHide utility (wushowhide.diagcab) as a block to stop the hardware strain, and will it prevent future brightness fluctuations? Will be permanently disable or come back?

3. How can I fix this loop, with absolutely zero risk to my custom graphics profiles, legacy driver stability, or screen brightness thresholds?

4. Does the newly released July Cumulative Update (KB5101650) wrapper contain the renewed firmware validation keys necessary to clear out this March-to-June servicing stack blockage cleanly? Or could it cause system crash or corruption if installed.

5. Are there known risks or side effects with attempting a repair upgrade or an in-place reinstall for this specific loop? I want to completely avoid anything that resets custom device properties, alters display configurations, or reverts stable graphics card driver profiles or potentially gets stuck, as both take up 20-30 on every attempt and harsh to the system.

6. Since my system is currently out of date on a March baseline, what is the safest path to install a newer, stable update without risking my custom display configurations?

7. Has anyone successfully applied a manual UEFI certificate renewal or a Secure Boot key variable override to bypass the expired Microsoft June 2026 validation timeline on general retail hardware? Any risks?

My System Specs:

* OS Edition: Windows 11 Home Single Language (Retail Channel)

* Version / Build: 25H2 (OS Build 26200.8117 - March 2026 Baseline)

* Hardware: ASUS Laptop (Model M413A)

* Processor: AMD Ryzen 7 4700U with Radeon Graphics (2.00 GHz, 8 Cores)

* Memory: 8.00 GB RAM (7.42 GB usable)

* Storage: Local C: Drive has 226 GB used out of 477 GB total capacity (251 GB free)


Symptoms I Am Experiencing:

The 2026-06 Security Update (KB5094126) and the June Preview Update (KB5095093) download completely to 100%. During initialization, the engine throws error 0x80074101 and restarts the download pipeline.

This creates a heavy background loop that pins the CPU to high utilization, causing noticeable thermal strain. When my AC power charger is connected, the cooling fans run at a very high audible RPM. I also experience temporary screen brightness flaring strictly when the charger is active, likely due to voltage shifts on the shared motherboard power tracks between the integrated AMD graphics and the system RAM channels when the update engine collides with my stop scripts.

Other non- quality updates and daily Windows Defender definitions continue to download and install flawlessly when updates are enable. The issue is strictly isolated to this specific update package and sometimes previews.


Tried So Far:

Over the past few days, I have tried several methods to safely pause or stop this loop to protect my hardware from constant heat stress:

1. Cache Resets: Cleared the contents of C:\Windows\SoftwareDistribution multiple times. The loop returns as soon as the folder is regenerated.

2. System Scans: Executed SFC /scannow and DISM /Online /Cleanup-Image /RestoreHealth. Both reports show a completely clean component store with no local system file corruption.

3. Service Management: Used temporary command-line scripts to stop 'wuauserv', 'usosvc', and 'bits', and adjusted service recovery actions to prevent them from instantly restarting in the background. These tend to come and go, but most are usually settled at stopped for 2-3 days, and then installation of this lopping security update will force a reattempt on the 2 or 3 day and I have reenter the commands.

4. Built-in Safeguards: Used the "Pause updates for 5 weeks" toggle in Settings just yesterday, where it greyed out for weeks prior, not sure if it will force the reinstall at random again. However, the Windows 11 Home kernel continues to still run background queries every few hours, triggering the hardware strain and it produces loud sounds when charging or resisting disabled setting even if disabling quiets the fan a lot of the time.

5. Cleaned the software distribution folder.



Cross-Forum Context & Certificate Discovery:

While researching this, I noticed some initial confusion regarding whether the 26200 build numbering indicated an Insider build, but it appears to be a general retail baseline constraint. Some common suggestions include performing a full clean reinstall or a repair upgrade via USB, but I am hesitant due to the risk of overwriting fine-tuned hardware configurations and custom driver properties.

Through cross-referencing documentation uploaded by other users facing identical loops on Build 26200, we uncovered a likely root cause. Logs from 'Get-SecureBootUEFI' show that the motherboard's underlying security certificates (Microsoft KEK CA 2011 and Microsoft Corporation UEFI CA 2011) officially expired in late June 2026.

Because the current date has passed the certificate validity timeline, the Secure Boot subsystem appears to reject the cryptographic handshake of the June update files, causing the 0x80074101 database error and the subsequent retry loop.

As a temporary fix, I am looking into using the official Microsoft WUShowHide diagnostic utility ('wushowhide.diagcab') from my desktop to hide KB5094126 and stabilize my processor and fan noise while waiting for a working patch wrapper that lets me upgrade safely.

I would deeply appreciate any verified engineering insight or workarounds the community has found to help me safely bring this system up to date without side effects. Thank you so much for your time!
 

ChatGPT

AI
Staff member
Robot
Joined
Mar 14, 2023
Messages
113,494

Bottom line​

Do not manually replace or override UEFI Secure Boot keys. Your certificate-expiry theory is not supported by Microsoft’s documentation. Microsoft explicitly states that systems without the renewed certificates should continue booting and that normal Windows updates should continue installing. Therefore, the expired 2011 certificates alone do not explain 0x80074101.
There is no completely zero-risk update or repair procedure, but the following route has the lowest practical risk.

Safest temporary way to stop the loop​

  1. Leave Pause updates enabled under Settings > Windows Update.
  2. Stop running your update-service scripts and do not keep changing wuauserv, UsoSvc, BITS, or their recovery actions.
  3. Restart Windows once so the services return to their normal trigger-controlled state.
  4. Optionally set your active connection to Metered under Settings > Network & internet > Wi-Fi/Ethernet > your connection > Metered connection.
  5. Turn Metered connection off again when ready to update.
Pause may still allow lightweight update checks and Defender definitions, but it should prevent the cumulative update from continually downloading and staging. Windows Update Medic can undo forced service changes, which probably explains the repeated enabled/disabled behaviour.
Undo: Disable Metered connection and select Resume updates.

About WUShowHide​

wushowhide.diagcab is reasonably safe if it is an authentic Microsoft-signed copy, because it only changes whether an offered update is hidden. It does not rewrite firmware or modify graphics profiles.
However:
  • It is not a permanent block.
  • A superseding cumulative update may replace the hidden update.
  • Windows may offer it again after update metadata changes.
  • It cannot prevent brightness fluctuations or guarantee reduced temperatures.
  • Use Show hidden updates inside the tool to undo the change.
Hiding KB5094126 temporarily is acceptable, but it should not be considered the actual repair.

Recommended upgrade path​

  1. Back up important files and save your Device Encryption/BitLocker recovery key, if encryption is enabled.
  2. Create a restore point.
  3. Export or record your AMD graphics settings, color profiles, refresh rate, scaling, HDR and brightness settings.
  4. Copy ICC profiles from:
C:\Windows\System32\spool\drivers\color
  1. Export third-party driver packages to an external drive:
DISM /Online /Export-Driver /Destination:D:\DriverBackup
  1. Keep the June preview KB5095093 skipped. Preview updates are optional.
  2. Resume Windows Update and allow it to search for the July 14, 2026 cumulative update KB5101650. It is cumulative and includes the June fixes, so KB5094126 does not need to install first. KB5101650 also includes a newer servicing-stack component intended to improve update reliability. Microsoft currently lists no general known issue with it.
  3. Do not manually assemble Catalog packages unless Windows Update continues failing. The Catalog version can contain prerequisite MSU packages that must be installed together or in the documented order.
A newer out-of-band update, KB5121767 dated July 18, 2026, exists, but Microsoft recommends it only for affected Intel IPF systems, mainly a limited group of Dell devices. Your AMD-based ASUS is not the target, so no manual action is needed.

What KB5101650 does—and does not—guarantee​

KB5101650 includes expanded targeting information for Microsoft’s phased Secure Boot certificate rollout. It is not documented as a universal certificate-renewal wrapper, and Microsoft does not guarantee that every machine receives new firmware variables immediately.
Nevertheless, it is the appropriate regular cumulative update to try because it supersedes the failing June packages. Your system’s clock, date and time zone should also be verified before attempting it.

If KB5101650 also fails​

Use Windows 11’s supported repair mechanism before considering a USB reinstall:
  1. Open Settings > System > Recovery.
  2. Find Fix problems using Windows Update.
  3. Select Reinstall now.
  4. Confirm that Windows says your apps, files and settings will be preserved.
  5. Keep the laptop connected to reliable AC power and do not interrupt the process.
This reinstalls the current Windows version and repairs servicing components. It is less disruptive than Reset this PC or a clean installation.
An ISO in-place repair is the next option if Reinstall now is unavailable. Start setup.exe from inside Windows using matching Windows 11 installation media and verify that Keep personal files and apps is selected.
Neither repair method guarantees that every third-party GPU control-panel profile survives. That is why exporting profiles and recording display settings first is important.

Brightness and thermal behaviour​

WUShowHide will not directly fix brightness flaring. The description of “voltage shifts on shared motherboard tracks” is unlikely to be the software-level cause. More likely causes include:
  • AMD Vari-Bright
  • Windows content-adaptive brightness
  • ASUS power-management software
  • Different AC and battery power profiles
  • Display-driver behaviour
  • Charger or display hardware issues
High fan speed during servicing does not normally damage the processor; the Ryzen CPU regulates temperature through boosting and thermal throttling. However, persistent flickering, shutdowns or extreme temperatures should be investigated separately after the update loop is stopped.

Secure Boot key overrides​

Do not manually write KEK, db, dbx, PK or custom Secure Boot variables on this laptop. Possible consequences include:
  • An unbootable Windows installation
  • BitLocker recovery prompts
  • Inability to boot recovery or installation media
  • Loss of OEM factory keys
  • Reduced Secure Boot protection
Use only Microsoft’s automatic rollout and official ASUS firmware for the exact M413A submodel. Do not reset or delete factory Secure Boot keys merely because a certificate displays a 2026 expiration date.