Windows 7 Crash/Random Reboot


  1. Posts : 22
    Windows 7 Home Premium
       #1

    Windows 7 Crash/Random Reboot


    Hey guys,

    I have the same problem that a lot of people here seem to be having. My computer randomly reboots, usually during the night, about once a day. Either that, or it just crahttps://www.sevenforums.com/newthread.php?do=newthread&f=38shes and when I wake up I have to force it to shut down and restart it again. I have a few theories of the cause of this problem, but I am no expert. I believe I may have a virus called vundo, as I have had other problems related to this virus, such as Firefox's search bar not working. Either that, or it may be something to do with Norton 360. I believe it happens over night because I have my Norton 360 set to run during times my computer is idle. I went to run a full system scan today, and withing 30 minutes the computer crashed.

    Anyway, sorry this is so long, but I'm trying to give you as much information as possible. I'll also attach to this the many errors and warnings that I get in event log during the times of the crash. Thank you in advance for your help and support.

    Event log

    Log Name: System
    Source: Service Control Manager
    Date: 2/20/2010 2:27:53 PM
    Event ID: 7011
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    A timeout (30000 milliseconds) was reached while waiting for a transaction response from the N360 service.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7011</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:27:53.421247800Z" />
    <EventRecordID>24777</EventRecordID>
    <Correlation />
    <Execution ProcessID="604" ThreadID="6644" />
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">N360</Data>
    </EventData>
    </Event>

    Log Name: System
    Source: EventLog
    Date: 2/20/2010 2:30:38 PM
    Event ID: 6008
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    The previous system shutdown at 2:29:38 PM on ‎2/‎20/‎2010 was unexpected.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:30:38.000000000Z" />
    <EventRecordID>24783</EventRecordID>
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>2:29:38 PM</Data>
    <Data>‎2/‎20/‎2010</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>34929</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>DA070200060014000E001D0026005801DA0702000600140013001D0026005801100E00003C00000001000000100E 000000000000080700000100000000000000</Binary>
    </EventData>
    </Event>

    Log Name: Security
    Source: Microsoft-Windows-Eventlog
    Date: 2/20/2010 2:30:39 PM
    Event ID: 1101
    Task Category: Event processing
    Level: Error
    Keywords: Audit Success
    User: N/A
    Computer: Tom-VAIO
    Description:
    Audit events have been dropped by the transport. 0
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
    <EventID>1101</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>101</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4020000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:30:39.368041900Z" />
    <EventRecordID>6142</EventRecordID>
    <Correlation />
    <Execution ProcessID="900" ThreadID="1172" />
    <Channel>Security</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <UserData>
    <AuditEventsDropped xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
    <Reason>0</Reason>
    </AuditEventsDropped>
    </UserData>
    </Event>

    Log Name: System
    Source: Disk
    Date: 2/20/2010 2:30:48 PM
    Event ID: 51
    Task Category: None
    Level: Warning
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    An error was detected on device \Device\Harddisk3\DR3 during a paging operation.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Disk" />
    <EventID Qualifiers="32772">51</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:30:48.650058300Z" />
    <EventRecordID>24838</EventRecordID>
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>\Device\Harddisk3\DR3</Data>
    <Binary>030080000100000000000000330004802D0100000E0000C000000000000000000000000000000000AA0800000000 0000FFFFFFFF01000000580000080000000000200A1240032040000000003C00000000000E0000000000F812D90880FAFFFF 0000000000000000B028D90880FAFFFFF07AE40880FAFFFF679C383A0000000028003A389C67000080000000000000000000 00000000000000000000000000000000000000000000</Binary>
    </EventData>
    </Event>

    Log Name: System
    Source: Disk
    Date: 2/20/2010 2:30:48 PM
    Event ID: 51
    Task Category: None
    Level: Warning
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    An error was detected on device \Device\Harddisk3\DR3 during a paging operation.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Disk" />
    <EventID Qualifiers="32772">51</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:30:48.650058300Z" />
    <EventRecordID>24839</EventRecordID>
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>\Device\Harddisk3\DR3</Data>
    <Binary>030080000100000000000000330004802D0100000E0000C000000000000000000000000000000000AA0800000000 0000FFFFFFFF01000000580000080000000000200A1240032040000000003C00000000000F0000000000A814D90880FAFFFF 0000000000000000602CD90880FAFFFFF07AE40880FAFFFFE79C383A0000000028003A389CE7000080000000000000000000 00000000000000000000000000000000000000000000</Binary>
    </EventData>
    </Event>

    Log Name: System
    Source: Service Control Manager
    Date: 2/20/2010 2:30:51 PM
    Event ID: 7009
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    A timeout was reached (30000 milliseconds) while waiting for the Roxio Upnp Server 10 service to connect.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:30:51.695560600Z" />
    <EventRecordID>24879</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="628" />
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Roxio Upnp Server 10</Data>
    </EventData>
    </Event>

    Log Name: Application
    Source: VzCdbSvc
    Date: 2/20/2010 2:31:32 PM
    Event ID: 7
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="VzCdbSvc" />
    <EventID Qualifiers="0">7</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-20T19:31:32.000000000Z" />
    <EventRecordID>7179</EventRecordID>
    <Channel>Application</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
    <Data>0x80042019</Data>
    </EventData>
    </Event>
      My Computer


  2. Posts : 28,845
    Win 8 Release candidate 8400
       #2

    Tomdabomb9 said:
    Hey guys,

    I have the same problem that a lot of people here seem to be having. My computer randomly reboots, usually during the night, about once a day. Either that, or it just crahttps://www.sevenforums.com/newthread.php?do=newthread&f=38shes and when I wake up I have to force it to shut down and restart it again. I have a few theories of the cause of this problem, but I am no expert. I believe I may have a virus called vundo, as I have had other problems related to this virus, such as Firefox's search bar not working. Either that, or it may be something to do with Norton 360. I believe it happens over night because I have my Norton 360 set to run during times my computer is idle. I went to run a full system scan today, and withing 30 minutes the computer crashed.

    Anyway, sorry this is so long, but I'm trying to give you as much information as possible. I'll also attach to this the many errors and warnings that I get in event log during the times of the crash. Thank you in advance for your help and support.
    Code:
    Event log
    
       Log Name:      System
      Source:        Service Control Manager
      Date:          2/20/2010 2:27:53 PM
      Event ID:      7011
      Task Category: None
      Level:         Error
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      A timeout (30000 milliseconds) was reached while waiting for a transaction response from the N360 service.
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
          <EventID Qualifiers="49152">7011</EventID>
          <Version>0</Version>
          <Level>2</Level>
          <Task>0</Task>
          <Opcode>0</Opcode>
          <Keywords>0x8080000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:27:53.421247800Z" />
          <EventRecordID>24777</EventRecordID>
          <Correlation />
          <Execution ProcessID="604" ThreadID="6644" />
          <Channel>System</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data Name="param1">30000</Data>
          <Data Name="param2">N360</Data>
        </EventData>
      </Event>
       
      Log Name:      System
      Source:        EventLog
      Date:          2/20/2010 2:30:38 PM
      Event ID:      6008
      Task Category: None
      Level:         Error
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      The previous system shutdown at 2:29:38 PM on ‎2/‎20/‎2010 was unexpected.
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="EventLog" />
          <EventID Qualifiers="32768">6008</EventID>
          <Level>2</Level>
          <Task>0</Task>
          <Keywords>0x80000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:30:38.000000000Z" />
          <EventRecordID>24783</EventRecordID>
          <Channel>System</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data>2:29:38 PM</Data>
          <Data>‎2/‎20/‎2010</Data>
          <Data>
          </Data>
          <Data>
          </Data>
          <Data>34929</Data>
          <Data>
          </Data>
          <Data>
          </Data>
          <Binary>DA070200060014000E001D0026005801DA0702000600140013001D0026005801100E00003C00000001000000100E000000000000080700000100000000000000</Binary>
        </EventData>
      </Event>
       
      Log Name:      Security
      Source:        Microsoft-Windows-Eventlog
      Date:          2/20/2010 2:30:39 PM
      Event ID:      1101
      Task Category: Event processing
      Level:         Error
      Keywords:      Audit Success
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      Audit events have been dropped by the transport.  0
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
          <EventID>1101</EventID>
          <Version>0</Version>
          <Level>2</Level>
          <Task>101</Task>
          <Opcode>0</Opcode>
          <Keywords>0x4020000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:30:39.368041900Z" />
          <EventRecordID>6142</EventRecordID>
          <Correlation />
          <Execution ProcessID="900" ThreadID="1172" />
          <Channel>Security</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <UserData>
          <AuditEventsDropped xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
            <Reason>0</Reason>
          </AuditEventsDropped>
        </UserData>
      </Event>
       
      Log Name:      System
      Source:        Disk
      Date:          2/20/2010 2:30:48 PM
      Event ID:      51
      Task Category: None
      Level:         Warning
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      An error was detected on device \Device\Harddisk3\DR3 during a paging operation.
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="Disk" />
          <EventID Qualifiers="32772">51</EventID>
          <Level>3</Level>
          <Task>0</Task>
          <Keywords>0x80000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:30:48.650058300Z" />
          <EventRecordID>24838</EventRecordID>
          <Channel>System</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data>\Device\Harddisk3\DR3</Data>
          <Binary>030080000100000000000000330004802D0100000E0000C000000000000000000000000000000000AA08000000000000FFFFFFFF01000000580000080000000000200A1240032040000000003C00000000000E0000000000F812D90880FAFFFF0000000000000000B028D90880FAFFFFF07AE40880FAFFFF679C383A0000000028003A389C6700008000000000000000000000000000000000000000000000000000000000000000</Binary>
        </EventData>
      </Event>
       
      Log Name:      System
      Source:        Disk
      Date:          2/20/2010 2:30:48 PM
      Event ID:      51
      Task Category: None
      Level:         Warning
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      An error was detected on device \Device\Harddisk3\DR3 during a paging operation.
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="Disk" />
          <EventID Qualifiers="32772">51</EventID>
          <Level>3</Level>
          <Task>0</Task>
          <Keywords>0x80000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:30:48.650058300Z" />
          <EventRecordID>24839</EventRecordID>
          <Channel>System</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data>\Device\Harddisk3\DR3</Data>
          <Binary>030080000100000000000000330004802D0100000E0000C000000000000000000000000000000000AA08000000000000FFFFFFFF01000000580000080000000000200A1240032040000000003C00000000000F0000000000A814D90880FAFFFF0000000000000000602CD90880FAFFFFF07AE40880FAFFFFE79C383A0000000028003A389CE700008000000000000000000000000000000000000000000000000000000000000000</Binary>
        </EventData>
      </Event>
       
      Log Name:      System
      Source:        Service Control Manager
      Date:          2/20/2010 2:30:51 PM
      Event ID:      7009
      Task Category: None
      Level:         Error
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      A timeout was reached (30000 milliseconds) while waiting for the Roxio Upnp Server 10 service to connect.
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
          <EventID Qualifiers="49152">7009</EventID>
          <Version>0</Version>
          <Level>2</Level>
          <Task>0</Task>
          <Opcode>0</Opcode>
          <Keywords>0x8080000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:30:51.695560600Z" />
          <EventRecordID>24879</EventRecordID>
          <Correlation />
          <Execution ProcessID="624" ThreadID="628" />
          <Channel>System</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data Name="param1">30000</Data>
          <Data Name="param2">Roxio Upnp Server 10</Data>
        </EventData>
      </Event>
       
      Log Name:      Application
      Source:        VzCdbSvc
      Date:          2/20/2010 2:31:32 PM
      Event ID:      7
      Task Category: None
      Level:         Error
      Keywords:      Classic
      User:          N/A
      Computer:      Tom-VAIO
      Description:
      Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
      Event Xml:
      <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
        <System>
          <Provider Name="VzCdbSvc" />
          <EventID Qualifiers="0">7</EventID>
          <Level>2</Level>
          <Task>0</Task>
          <Keywords>0x80000000000000</Keywords>
          <TimeCreated SystemTime="2010-02-20T19:31:32.000000000Z" />
          <EventRecordID>7179</EventRecordID>
          <Channel>Application</Channel>
          <Computer>Tom-VAIO</Computer>
          <Security />
        </System>
        <EventData>
          <Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
          <Data>0x80042019</Data>
        </EventData>
    </Event>

    You have four different error messages but they all refer to one problem the hard drive

    You should run a chkdsk /r to check it

    you should also run a system file check to verify your system files
    type cmd in search>right click and run as admin>SFC /SCANNOW

    Let us know the results as you might have to ru SFC more than once


    Ken
      My Computer


  3. Posts : 22
    Windows 7 Home Premium
    Thread Starter
       #3

    I did the chkdsk and system file scan, which didn't come up with any problems. Unfortunately it happened again, twice, since I did those. Here is the event viewer for today.

    Log Name: Application
    Source: VzCdbSvc
    Date: 2/21/2010 3:07:39 PM
    Event ID: 7
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="VzCdbSvc" />
    <EventID Qualifiers="0">7</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:07:39.000000000Z" />
    <EventRecordID>7360</EventRecordID>
    <Channel>Application</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
    <Data>0x80042019</Data>
    </EventData>
    </Event>

    Log Name: Microsoft-Windows-PrintService/Admin
    Source: Microsoft-Windows-PrintService
    Date: 2/21/2010 3:07:21 PM
    Event ID: 315
    Task Category: Sharing a printer
    Level: Error
    Keywords: Classic Spooler Event,Printer
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    The print spooler failed to share printer HP Deskjet D2300 series with shared resource name HP Deskjet D2300 series. Error 2114. The printer cannot be used by others on the network.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-PrintService" Guid="{747EF6FD-E535-4D16-B510-42C90F6873A1}" />
    <EventID>315</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>30</Task>
    <Opcode>12</Opcode>
    <Keywords>0x8000000000000820</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:07:21.874851600Z" />
    <EventRecordID>37</EventRecordID>
    <Correlation />
    <Execution ProcessID="1404" ThreadID="2184" />
    <Channel>Microsoft-Windows-PrintService/Admin</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <UserData>
    <ShareFailed xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
    <Param1>2114</Param1>
    <Param2>HP Deskjet D2300 series</Param2>
    <Param3>HP Deskjet D2300 series</Param3>
    </ShareFailed>
    </UserData>
    </Event>

    Log Name: Microsoft-Windows-PrintService/Admin
    Source: Microsoft-Windows-PrintService
    Date: 2/21/2010 3:07:21 PM
    Event ID: 315
    Task Category: Sharing a printer
    Level: Error
    Keywords: Classic Spooler Event,Printer
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    The print spooler failed to share printer HP Deskjet D2300 series (Copy 1) with shared resource name HP Deskjet D2300 series (Copy 1). Error 2114. The printer cannot be used by others on the network.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-PrintService" Guid="{747EF6FD-E535-4D16-B510-42C90F6873A1}" />
    <EventID>315</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>30</Task>
    <Opcode>12</Opcode>
    <Keywords>0x8000000000000820</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:07:21.874851600Z" />
    <EventRecordID>36</EventRecordID>
    <Correlation />
    <Execution ProcessID="1404" ThreadID="2184" />
    <Channel>Microsoft-Windows-PrintService/Admin</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <UserData>
    <ShareFailed xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
    <Param1>2114</Param1>
    <Param2>HP Deskjet D2300 series (Copy 1)</Param2>
    <Param3>HP Deskjet D2300 series (Copy 1)</Param3>
    </ShareFailed>
    </UserData>
    </Event>

    Log Name: System
    Source: Service Control Manager
    Date: 2/21/2010 3:07:20 PM
    Event ID: 7009
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    A timeout was reached (30000 milliseconds) while waiting for the Roxio Upnp Server 10 service to connect.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:07:20.720449600Z" />
    <EventRecordID>25583</EventRecordID>
    <Correlation />
    <Execution ProcessID="616" ThreadID="620" />
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Roxio Upnp Server 10</Data>
    </EventData>
    </Event>

    Log Name: System
    Source: Microsoft-Windows-WLAN-AutoConfig
    Date: 2/21/2010 3:06:10 PM
    Event ID: 4001
    Task Category: None
    Level: Warning
    Keywords:
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    WLAN AutoConfig service has successfully stopped.

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-WLAN-AutoConfig" Guid="{9580D7DD-0379-4658-9870-D5BE7D52D6DE}" />
    <EventID>4001</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>2</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:06:10.775580800Z" />
    <EventRecordID>25514</EventRecordID>
    <Correlation />
    <Execution ProcessID="952" ThreadID="320" />
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
    </Event>

    Log Name: Application
    Source: Microsoft-Windows-User Profiles Service
    Date: 2/21/2010 3:05:45 PM
    Event ID: 1530
    Task Category: None
    Level: Warning
    Keywords:
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    DETAIL -
    10 user registry handles leaked from \Registry\User\S-1-5-21-2977802254-3606878633-1533668675-1000_Classes:
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Wow6432Node\CLSID

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:05:45.300736100Z" />
    <EventRecordID>7339</EventRecordID>
    <Correlation />
    <Execution ProcessID="992" ThreadID="4108" />
    <Channel>Application</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">10 user registry handles leaked from \Registry\User\S-1-5-21-2977802254-3606878633-1533668675-1000_Classes:
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000_CLASSES\Wow6432Node\CLSID
    </Data>
    </EventData>
    </Event>

    Log Name: Application
    Source: Microsoft-Windows-User Profiles Service
    Date: 2/21/2010 3:05:44 PM
    Event ID: 1530
    Task Category: None
    Level: Warning
    Keywords:
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    DETAIL -
    36 user registry handles leaked from \Registry\User\S-1-5-21-2977802254-3606878633-1533668675-1000:
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 5084 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2868 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2128 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\IETld
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\IETld
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows NT\CurrentVersion
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows NT\CurrentVersion

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T20:05:44.957535500Z" />
    <EventRecordID>7338</EventRecordID>
    <Correlation />
    <Execution ProcessID="992" ThreadID="4108" />
    <Channel>Application</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">36 user registry handles leaked from \Registry\User\S-1-5-21-2977802254-3606878633-1533668675-1000:
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 5084 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2868 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 2128 (\Device\HarddiskVolume3\Windows\System32\taskmgr.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\IETld
    Process 3928 (\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Internet Explorer\IETld
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
    Process 2144 (\Device\HarddiskVolume3\Windows\System32\notepad.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows NT\CurrentVersion
    Process 1764 (\Device\HarddiskVolume3\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-2977802254-3606878633-1533668675-1000\Software\Microsoft\Windows NT\CurrentVersion
    </Data>
    </EventData>
    </Event>

    Log Name: Application
    Source: VzCdbSvc
    Date: 2/21/2010 2:58:29 PM
    Event ID: 7
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="VzCdbSvc" />
    <EventID Qualifiers="0">7</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T19:58:29.000000000Z" />
    <EventRecordID>7314</EventRecordID>
    <Channel>Application</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
    <Data>0x80042019</Data>
    </EventData>
    </Event>

    Log Name: Microsoft-Windows-PrintService/Admin
    Source: Microsoft-Windows-PrintService
    Date: 2/21/2010 2:58:22 PM
    Event ID: 315
    Task Category: Sharing a printer
    Level: Error
    Keywords: Classic Spooler Event,Printer
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    The print spooler failed to share printer HP Deskjet D2300 series with shared resource name HP Deskjet D2300 series. Error 2114. The printer cannot be used by others on the network.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-PrintService" Guid="{747EF6FD-E535-4D16-B510-42C90F6873A1}" />
    <EventID>315</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>30</Task>
    <Opcode>12</Opcode>
    <Keywords>0x8000000000000820</Keywords>
    <TimeCreated SystemTime="2010-02-21T19:58:22.841744200Z" />
    <EventRecordID>35</EventRecordID>
    <Correlation />
    <Execution ProcessID="1352" ThreadID="2448" />
    <Channel>Microsoft-Windows-PrintService/Admin</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <UserData>
    <ShareFailed xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
    <Param1>2114</Param1>
    <Param2>HP Deskjet D2300 series</Param2>
    <Param3>HP Deskjet D2300 series</Param3>
    </ShareFailed>
    </UserData>
    </Event>

    Log Name: Microsoft-Windows-PrintService/Admin
    Source: Microsoft-Windows-PrintService
    Date: 2/21/2010 2:58:22 PM
    Event ID: 315
    Task Category: Sharing a printer
    Level: Error
    Keywords: Classic Spooler Event,Printer
    User: SYSTEM
    Computer: Tom-VAIO
    Description:
    The print spooler failed to share printer HP Deskjet D2300 series (Copy 1) with shared resource name HP Deskjet D2300 series (Copy 1). Error 2114. The printer cannot be used by others on the network.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-PrintService" Guid="{747EF6FD-E535-4D16-B510-42C90F6873A1}" />
    <EventID>315</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>30</Task>
    <Opcode>12</Opcode>
    <Keywords>0x8000000000000820</Keywords>
    <TimeCreated SystemTime="2010-02-21T19:58:22.826144200Z" />
    <EventRecordID>34</EventRecordID>
    <Correlation />
    <Execution ProcessID="1352" ThreadID="2448" />
    <Channel>Microsoft-Windows-PrintService/Admin</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    <UserData>
    <ShareFailed xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events">
    <Param1>2114</Param1>
    <Param2>HP Deskjet D2300 series (Copy 1)</Param2>
    <Param3>HP Deskjet D2300 series (Copy 1)</Param3>
    </ShareFailed>
    </UserData>
    </Event>

    Log Name: System
    Source: Service Control Manager
    Date: 2/21/2010 2:58:00 PM
    Event ID: 7009
    Task Category: None
    Level: Error
    Keywords: Classic
    User: N/A
    Computer: Tom-VAIO
    Description:
    A timeout was reached (30000 milliseconds) while waiting for the Roxio Upnp Server 10 service to connect.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2010-02-21T19:58:00.737647900Z" />
    <EventRecordID>25413</EventRecordID>
    <Correlation />
    <Execution ProcessID="612" ThreadID="616" />
    <Channel>System</Channel>
    <Computer>Tom-VAIO</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Roxio Upnp Server 10</Data>
    </EventData>
    </Event>
      My Computer


  4. Posts : 22
    Windows 7 Home Premium
    Thread Starter
       #4

    Ken,

    The daily random crashes are still happening. I'm getting the same stuff in the event viewer. I checked my minidump files and this is what came up from the last minidump.


    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Windows\Minidump\022410-24679-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: *** Invalid ***
    ****************************************************************************
    * Symbol loading may be unreliable without a symbol search path. *
    * Use .symfix to have the debugger choose a symbol path. *
    * After setting your symbol path, use .reload to refresh symbol locations. *
    ****************************************************************************
    Executable search path is:
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for ntoskrnl.exe
    *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
    Windows 7 Kernel Version 7600 MP (2 procs) Free x64
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
    Machine Name:
    Kernel base = 0xfffff800`02e62000 PsLoadedModuleList = 0xfffff800`0309fe50
    Debug session time: Wed Feb 24 02:44:33.892 2010 (GMT-5)
    System Uptime: 0 days 8:13:00.327
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for ntoskrnl.exe
    *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..................................
    Loading User Symbols
    Loading unloaded module list
    ...................
    Unable to load image \SystemRoot\System32\drivers\dxgkrnl.sys, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for dxgkrnl.sys
    *** ERROR: Module load completed but symbols could not be loaded for dxgkrnl.sys
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 116, {fffffa800b98a010, fffff88004e31b90, ffffffffc000009a, 4}

    Unable to load image \SystemRoot\system32\DRIVERS\nvlddmkm.sys, Win32 error 0n2
    *** WARNING: Unable to verify timestamp for nvlddmkm.sys
    *** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    Probably caused by : nvlddmkm.sys ( nvlddmkm+5e8b90 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    VIDEO_TDR_FAILURE (116)
    Attempt to reset the display driver and recover from timeout failed.
    Arguments:
    Arg1: fffffa800b98a010, Optional pointer to internal TDR recovery context (TDR_RECOVERY_CONTEXT).
    Arg2: fffff88004e31b90, The pointer into responsible device driver module (e.g. owner tag).
    Arg3: ffffffffc000009a, Optional error code (NTSTATUS) of the last failed operation.
    Arg4: 0000000000000004, Optional internal context dependent data.

    Debugging Details:
    ------------------

    ***** Kernel symbols are WRONG. Please fix symbols to do analysis.

    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************
    *********************************************************************
    * Symbols can not be loaded because symbol path is not initialized. *
    * *
    * The Symbol Path can be set by: *
    * using the _NT_SYMBOL_PATH environment variable. *
    * using the -y <symbol_path> argument when starting the debugger. *
    * using .sympath and .sympath+ *
    *********************************************************************

    ADDITIONAL_DEBUG_TEXT:
    Use '!findthebuild' command to search for the target build information.
    If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

    FAULTING_MODULE: fffff80002e62000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 4a6e492b

    FAULTING_IP:
    nvlddmkm+5e8b90
    fffff880`04e31b90 4053 push rbx

    DEFAULT_BUCKET_ID: GRAPHICS_DRIVER_TDR_FAULT

    CUSTOMER_CRASH_COUNT: 1

    BUGCHECK_STR: 0x116

    CURRENT_IRQL: 0

    STACK_TEXT:
    fffff880`06a7db48 fffff880`040e1ef8 : 00000000`00000116 fffffa80`0b98a010 fffff880`04e31b90 ffffffff`c000009a : nt+0x71f00
    fffff880`06a7db50 00000000`00000116 : fffffa80`0b98a010 fffff880`04e31b90 ffffffff`c000009a 00000000`00000004 : dxgkrnl+0x5cef8
    fffff880`06a7db58 fffffa80`0b98a010 : fffff880`04e31b90 ffffffff`c000009a 00000000`00000004 00000000`00000001 : 0x116
    fffff880`06a7db60 fffff880`04e31b90 : ffffffff`c000009a 00000000`00000004 00000000`00000001 fffffa80`0b98a010 : 0xfffffa80`0b98a010
    fffff880`06a7db68 ffffffff`c000009a : 00000000`00000004 00000000`00000001 fffffa80`0b98a010 fffff880`040b5867 : nvlddmkm+0x5e8b90
    fffff880`06a7db70 00000000`00000004 : 00000000`00000001 fffffa80`0b98a010 fffff880`040b5867 fffff880`04e31b90 : 0xffffffff`c000009a
    fffff880`06a7db78 00000000`00000001 : fffffa80`0b98a010 fffff880`040b5867 fffff880`04e31b90 fffffa80`07dfe000 : 0x4
    fffff880`06a7db80 fffffa80`0b98a010 : fffff880`040b5867 fffff880`04e31b90 fffffa80`07dfe000 00000000`00000000 : 0x1
    fffff880`06a7db88 fffff880`040b5867 : fffff880`04e31b90 fffffa80`07dfe000 00000000`00000000 ffffffff`c000009a : 0xfffffa80`0b98a010
    fffff880`06a7db90 fffff880`04e31b90 : fffffa80`07dfe000 00000000`00000000 ffffffff`c000009a fffffa80`07de1410 : dxgkrnl+0x30867
    fffff880`06a7db98 fffffa80`07dfe000 : 00000000`00000000 ffffffff`c000009a fffffa80`07de1410 ffffffff`feced300 : nvlddmkm+0x5e8b90
    fffff880`06a7dba0 00000000`00000000 : ffffffff`c000009a fffffa80`07de1410 ffffffff`feced300 fffffa80`07ee1d50 : 0xfffffa80`07dfe000


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    nvlddmkm+5e8b90
    fffff880`04e31b90 4053 push rbx

    SYMBOL_STACK_INDEX: 4

    SYMBOL_NAME: nvlddmkm+5e8b90

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: nvlddmkm

    IMAGE_NAME: nvlddmkm.sys

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner
    ---------
      My Computer


  5. Posts : 6
    W7 ultimate
       #5

    I fixed this random reboot by uninstalling Roxio from Dell . it was ver 9 . I noticed the crash coincided with this install so removing it thus fixed the problem.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 12:24.
Find Us