Let's try this one 
Please download MyEventViewer by NirSoft from here:
Unzip it and run by using right-click and choosing Run as administrator
Then wait until it finishes scanning.
When finished, in the upper window go to LOGS on the toolbar.
Leave checked only:- application
- hardware
- system
After each unchecked point wait until it finishes scanning!
Next mark the last 20 events in the upper window, click File -> Save Selected Items and name it somehow.
Open the selected file and post the raport in your reply.
==================================================
Record Number : 1571
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:58
Source : Microsoft-Windows-Dhcp-Client
Category : 4
Event ID : 50037
User Name : LOCAL SERVICE
Computer : ADMIN
Event Data Length : 0
Record Length : 152
Event Description : DHCPv4 client service is stopped. ShutDown Flag value is 1
==================================================
==================================================
Record Number : 1567
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:58
Source : Microsoft-Windows-DHCPv6-Client
Category : 4
Event ID : 51047
User Name : LOCAL SERVICE
Computer : ADMIN
Event Data Length : 0
Record Length : 160
Event Description : DHCPv6 client service is stopped. ShutDown Flag value is 1
==================================================
==================================================
Record Number : 1566
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:58
Source : Microsoft-Windows-Winlogon
Category : 1102
Event ID : 7002
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 244
Event Description : User Log-off Notification for Customer Experience Improvement Program
==================================================
==================================================
Record Number : 1565
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:58
Source : User32
Category : 0
Event ID : 1074
User Name : Admin
Computer : ADMIN
Event Data Length : 0
Record Length : 360
Event Description : The process C:\Windows\system32\winlogon.exe (ADMIN) has initiated the power off of computer ADMIN on behalf of user ADMIN\Admin for the following reason: No title for this reason could be found Reason Code: 0x500ff Shutdown Type: power off Comment:
==================================================
==================================================
Record Number : 1564
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:58
Source : EventLog
Category : 0
Event ID : 6006
User Name :
Computer : ADMIN
Event Data Length : 8
Record Length : 104
Event Description : The Event log service was stopped.
==================================================
==================================================
Record Number : 1748
Log Type : Application
Event Type : Information
Time : 25/07/2013 11:23:58
Source : Microsoft-Windows-User Profiles Service
Category : 0
Event ID : 1532
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 172
Event Description : The User Profile Service has stopped.
==================================================
==================================================
Record Number : 1746
Log Type : Application
Event Type : Warning
Time : 25/07/2013 11:23:57
Source : Microsoft-Windows-User Profiles Service
Category : 0
Event ID : 1530
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 1476
Event Description : Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 3 user registry handles leaked from \Registry\User\S-1-5-21-2076424320-458633515-1502095547-1001: Process 900 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2076424320-458633515-1502095547-1001 Process 472 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2076424320-458633515-1502095547-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall Process 900 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2076424320-458633515-1502095547-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
==================================================
==================================================
Record Number : 1563
Log Type : System
Event Type : Information
Time : 25/07/2013 11:23:56
Source : Microsoft-Windows-Kernel-Power
Category : 103
Event ID : 109
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 168
Event Description :
==================================================
==================================================
Record Number : 1745
Log Type : Application
Event Type : Information
Time : 25/07/2013 11:23:56
Source : Microsoft-Windows-Winsrv
Category : 0
Event ID : 10001
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 172
Event Description : The following application attempted to veto the shutdown: DontSleep.exe.
==================================================
==================================================
Record Number : 1743
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:22:08
Source : Software Protection Platform Service
Category : 0
Event ID : 16384
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 216
Event Description : Successfully scheduled Software Protection service for re-start at 2013-08-01T07:18:08Z. Reason: RulesEngine.
==================================================
==================================================
Record Number : 1741
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:21:38
Source : Software Protection Platform Service
Category : 0
Event ID : 1003
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 2820
Event Description : The Software Protection service has completed licensing status check. Application Id=55c92734-d682-4d71-983e-d6ec3f16059f Licensing Status= 1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 259196)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )] 9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
==================================================
==================================================
Record Number : 1740
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:21:38
Source : Software Protection Platform Service
Category : 0
Event ID : 1066
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 1596
Event Description : Initialization status for service objects. C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
==================================================
==================================================
Record Number : 1739
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:21:37
Source : Software Protection Platform Service
Category : 0
Event ID : 900
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 192
Event Description : The Software Protection service is starting. Parameters:caller=Explorer.EXE
==================================================
==================================================
Record Number : 1738
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:21:24
Source : Microsoft-Windows-LoadPerf
Category : 0
Event ID : 1000
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 256
Event Description : Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
==================================================
==================================================
Record Number : 1737
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:21:24
Source : Microsoft-Windows-LoadPerf
Category : 0
Event ID : 1001
User Name : SYSTEM
Computer : ADMIN
Event Data Length : 0
Record Length : 240
Event Description : Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
==================================================
==================================================
Record Number : 1735
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:19:40
Source : Software Protection Platform Service
Category : 0
Event ID : 16384
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 216
Event Description : Successfully scheduled Software Protection service for re-start at 2013-08-01T07:17:40Z. Reason: RulesEngine.
==================================================
==================================================
Record Number : 1734
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:19:10
Source : Software Protection Platform Service
Category : 0
Event ID : 8230
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 980
Event Description : The rules engine successfully re-evaluated the schedule. Kernel policies: Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2014/01/21:07:18:10;LastConsumptionReason=0x4004f040;LastNotificationId=Cleanup;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=379cccfb-d4e0-48fe-b0f2-0136097be147;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal
==================================================
==================================================
Record Number : 1732
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:19:10
Source : Software Protection Platform Service
Category : 0
Event ID : 1003
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 2820
Event Description : The Software Protection service has completed licensing status check. Application Id=55c92734-d682-4d71-983e-d6ec3f16059f Licensing Status= 1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 0 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 259199)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )] 9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
==================================================
==================================================
Record Number : 1731
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:19:10
Source : Software Protection Platform Service
Category : 0
Event ID : 1033
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 916
Event Description : These policies are being excluded since they are only defined with override-only attribute. Policy Names=(IIS-W3SVC-MaxConcurrentRequests) (Microsoft.Windows.Smc-Enabled) (NetworkProjection-CanRunNetworkProjection) (NetworkProjection-CanStartPresenting) (Security-SPP-Reserved-EnableNotificationMode) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) App Id=55c92734-d682-4d71-983e-d6ec3f16059f Sku Id=a98bcd6d-5343-4603-8afe-5908e4611112
==================================================
==================================================
Record Number : 1730
Log Type : Application
Event Type : Information
Time : 25/07/2013 10:19:09
Source : Software Protection Platform Service
Category : 0
Event ID : 1066
User Name :
Computer : ADMIN
Event Data Length : 0
Record Length : 1596
Event Description : Initialization status for service objects. C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
==================================================