System administrator has set policies to prevent this installation

Page 2 of 2 FirstFirst 12

  1. Posts : 10
    Windows 7 home premium 64 bit
    Thread Starter
       #11

    no i do not have bonjour i used to but i removed it the only programs from apple i have are apple application support and apple software update and i only have these because i couldnt get them to uninstall
      My Computer


  2. Posts : 10
    Windows 7 home premium 64 bit
    Thread Starter
       #12

    ok got both apple programs uninstalled restarted the comp and still no luck
      My Computer


  3. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #13

    Let's see what VEW shows ... Please download VEW by Vino Rosso http://images.malwareremoval.com/vino/VEW.exe
    and save it to your desktop
    Double click it to start it Note: If running Windows Vista or Windows 7 you will need to right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.
    Click the check boxes next to Application and System located under Select log to query on the upper left
    Under Select type to list on the right click the boxes next to Error and Warning Note: If running Windows Vista or Windows 7 also click the box next to Critical (not XP).
    Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run

    Once it finishes it will display a log file in notepad
    Please copy and paste its entire contents into your next reply
      My Computer


  4. Posts : 10
    Windows 7 home premium 64 bit
    Thread Starter
       #14

    here you go.. Vino's Event Viewer v01c run on Windows 2008 in English
    Report run at 31/12/2010 6:15:44 PM

    Code:
     
    Note: All dates below are in the format dd/mm/yyyy
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 31/12/2010 10:54:40 PM
    Type: Error Category: 0
    Event: 11719 Source: MsiInstaller
    Product: iTunes -- Error 1719. The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.
     
    Log: 'Application' Date/Time: 31/12/2010 10:48:42 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 10:48:20 PM
    Type: Error Category: 0
    Event: 11721 Source: MsiInstaller
    Product: Apple Software Update -- Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: SoftwareUpdate_UnregServer, location: C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe, command: /UnregServer 
     
    Log: 'Application' Date/Time: 31/12/2010 10:48:04 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 10:47:36 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 9:57:39 PM
    Type: Error Category: 0
    Event: 11719 Source: MsiInstaller
    Product: iTunes -- Error 1719. The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.
     
    Log: 'Application' Date/Time: 31/12/2010 9:56:39 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 9:50:26 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: Oblivion.exe, version: 1.2.0.416, time stamp: 0x462392c7 Faulting module name: Oblivion.exe, version: 1.2.0.416, time stamp: 0x462392c7 Exception code: 0xc00000fd Fault offset: 0x00119e26 Faulting process id: 0x1080 Faulting application start time: 0x01cba932c9682390 Faulting application path: C:\Program Files (x86)\Bethesda Softworks\Oblivion\Oblivion.exe Faulting module path: C:\Program Files (x86)\Bethesda Softworks\Oblivion\Oblivion.exe Report Id: f98d9c3e-1527-11e0-ac2e-002185332956
     
    Log: 'Application' Date/Time: 31/12/2010 9:32:19 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: Oblivion.exe, version: 1.2.0.416, time stamp: 0x462392c7 Faulting module name: ntdll.dll, version: 6.1.7600.16559, time stamp: 0x4ba9b29c Exception code: 0xc0000005 Fault offset: 0x00038c19 Faulting process id: 0x1030 Faulting application start time: 0x01cba924a02577d0 Faulting application path: C:\Program Files (x86)\Bethesda Softworks\Oblivion\Oblivion.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll Report Id: 7180df8f-1525-11e0-ac2e-002185332956
     
    Log: 'Application' Date/Time: 31/12/2010 6:58:25 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 6:57:26 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 5:54:10 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 5:54:08 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 5:06:50 PM
    Type: Error Category: 0
    Event: 11719 Source: MsiInstaller
    Product: iTunes -- Error 1719. The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.
     
    Log: 'Application' Date/Time: 31/12/2010 5:03:42 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 5:03:25 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 4:47:59 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 4:47:41 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    Log: 'Application' Date/Time: 31/12/2010 4:19:39 PM
    Type: Error Category: 0
    Event: 11719 Source: MsiInstaller
    Product: iTunes -- Error 1719. The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.
     
    Log: 'Application' Date/Time: 31/12/2010 4:17:27 PM
    Type: Error Category: 0
    Event: 1024 Source: .NET Runtime
    Shim database version C:\Windows\Microsoft.NET\Framework\v4.0.30319 doesn't have a matching runtime directory
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 31/12/2010 10:49:38 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 3096 (\Device\HarddiskVolume2\Windows\SysWOW64\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
     
     
    Log: 'Application' Date/Time: 31/12/2010 10:47:30 PM
    Type: Warning Category: 3
    Event: 4879 Source: Microsoft-Windows-MSDTC Client 2
    MSDTC encountered an error (HR=0x80000171) while attempting to establish a secure connection with system DJSCY-PC.
     
    Log: 'Application' Date/Time: 31/12/2010 6:59:13 PM
    Type: Warning Category: 0
    Event: 1001 Source: MsiInstaller
    Detection of product '{AC76BA86-7AD7-1033-7B44-A94000000001}', feature 'ReaderProgramFiles' failed during request for component '{F95C9759-13AF-4E41-A46B-DBD281608D53}'
     
    Log: 'Application' Date/Time: 31/12/2010 6:58:11 PM
    Type: Warning Category: 0
    Event: 1001 Source: MsiInstaller
    Detection of product '{AC76BA86-7AD7-1033-7B44-A94000000001}', feature 'ReaderProgramFiles' failed during request for component '{F95C9759-13AF-4E41-A46B-DBD281608D53}'
     
    Log: 'Application' Date/Time: 31/12/2010 6:57:03 PM
    Type: Warning Category: 0
    Event: 1001 Source: MsiInstaller
    Detection of product '{AC76BA86-7AD7-1033-7B44-A94000000001}', feature 'ReaderProgramFiles' failed during request for component '{F95C9759-13AF-4E41-A46B-DBD281608D53}'
     
    Log: 'Application' Date/Time: 12/12/2010 4:44:37 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 400 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 06/12/2010 12:37:19 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000_Classes:
    Process 3140 (\Device\HarddiskVolume2\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000_CLASSES
     
     
    Log: 'Application' Date/Time: 06/12/2010 12:37:18 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 2 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 3140 (\Device\HarddiskVolume2\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 3140 (\Device\HarddiskVolume2\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
     
     
    Log: 'Application' Date/Time: 06/12/2010 12:04:00 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000_Classes:
    Process 4636 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000_CLASSES
     
     
    Log: 'Application' Date/Time: 06/12/2010 12:03:57 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 17 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 5216 (\Device\HarddiskVolume2\Windows\SysWOW64\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 4636 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 384 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 04/12/2010 8:28:05 PM
    Type: Warning Category: 0
    Event: 20 Source: Google Update
    The event description cannot be found.
     
    Log: 'Application' Date/Time: 04/12/2010 1:22:58 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 448 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 09/11/2010 3:24:06 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
     
     
    Log: 'Application' Date/Time: 03/11/2010 12:30:42 PM
    Type: Warning Category: 0
    Event: 20 Source: Google Update
    The event description cannot be found.
     
    Log: 'Application' Date/Time: 03/11/2010 11:30:41 AM
    Type: Warning Category: 0
    Event: 20 Source: Google Update
    The event description cannot be found.
     
    Log: 'Application' Date/Time: 23/10/2010 4:53:16 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 22/10/2010 3:36:36 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 21/10/2010 5:22:25 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 21/10/2010 1:25:14 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    Log: 'Application' Date/Time: 20/10/2010 9:53:19 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 12 user registry handles leaked from \Registry\User\S-1-5-21-1770102354-1835381533-4004668212-1000:
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Root
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\My
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\CA
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\trust
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1644 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-1770102354-1835381533-4004668212-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
     
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 31/12/2010 10:52:28 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 29/12/2010 12:31:46 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 20/12/2010 10:32:38 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 15/12/2010 4:10:56 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 26/11/2010 5:21:01 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 22/11/2010 11:44:25 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 18/11/2010 11:06:30 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 26/10/2010 11:50:03 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 22/10/2010 6:23:26 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 17/10/2010 8:30:00 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 10/10/2010 10:09:54 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 21/09/2010 10:45:30 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 02/09/2010 2:02:53 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 28/08/2010 2:22:45 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 20/08/2010 12:18:36 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 14/08/2010 2:48:07 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 12/08/2010 4:37:31 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 11/08/2010 10:19:06 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 10/08/2010 7:40:59 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    Log: 'System' Date/Time: 09/08/2010 4:18:09 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 31/12/2010 10:53:46 PM
    Type: Error Category: 0
    Event: 30013 Source: Microsoft-Windows-SharedAccess_NAT
    The DHCP allocator has disabled itself on IP address 192.168.1.100, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
     
    Log: 'System' Date/Time: 31/12/2010 10:53:46 PM
    Type: Error Category: 0
    Event: 34001 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 failed to configure IPv6 stack.
     
    Log: 'System' Date/Time: 31/12/2010 10:52:37 PM
    Type: Error Category: 0
    Event: 1001 Source: Microsoft-Windows-WER-SystemErrorReporting
    The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff88001bd3238, 0xfffff880037f52c8, 0xfffff880037f4b30). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 123110-21765-01.
     
    Log: 'System' Date/Time: 31/12/2010 9:55:10 PM
    Type: Error Category: 0
    Event: 30013 Source: Microsoft-Windows-SharedAccess_NAT
    The DHCP allocator has disabled itself on IP address 192.168.1.100, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
     
    Log: 'System' Date/Time: 31/12/2010 9:55:10 PM
    Type: Error Category: 0
    Event: 34001 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 failed to configure IPv6 stack.
     
    Log: 'System' Date/Time: 31/12/2010 9:54:31 PM
    Type: Error Category: 0
    Event: 6008 Source: EventLog
    The previous system shutdown at 4:53:13 PM on ?12/?31/?2010 was unexpected.
     
    Log: 'System' Date/Time: 31/12/2010 4:15:37 PM
    Type: Error Category: 0
    Event: 30013 Source: Microsoft-Windows-SharedAccess_NAT
    The DHCP allocator has disabled itself on IP address 192.168.1.100, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
     
    Log: 'System' Date/Time: 31/12/2010 4:15:37 PM
    Type: Error Category: 0
    Event: 34001 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 failed to configure IPv6 stack.
     
    Log: 'System' Date/Time: 31/12/2010 4:15:21 PM
    Type: Error Category: 0
    Event: 6008 Source: EventLog
    The previous system shutdown at 11:14:31 AM on ?12/?31/?2010 was unexpected.
     
    Log: 'System' Date/Time: 31/12/2010 8:02:02 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 30/12/2010 8:02:06 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 29/12/2010 8:01:59 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 29/12/2010 12:32:16 AM
    Type: Error Category: 0
    Event: 30013 Source: Microsoft-Windows-SharedAccess_NAT
    The DHCP allocator has disabled itself on IP address 192.168.1.100, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
     
    Log: 'System' Date/Time: 29/12/2010 12:32:16 AM
    Type: Error Category: 0
    Event: 34001 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 failed to configure IPv6 stack.
     
    Log: 'System' Date/Time: 29/12/2010 12:32:02 AM
    Type: Error Category: 0
    Event: 6008 Source: EventLog
    The previous system shutdown at 7:31:11 PM on ?12/?28/?2010 was unexpected.
     
    Log: 'System' Date/Time: 28/12/2010 8:01:57 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 27/12/2010 8:01:53 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 26/12/2010 8:01:49 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    Log: 'System' Date/Time: 25/12/2010 3:40:03 PM
    Type: Error Category: 0
    Event: 31004 Source: Microsoft-Windows-SharedAccess_NAT
    The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 25/12/2010 8:01:50 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670).
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 31/12/2010 10:53:46 PM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 31/12/2010 10:52:41 PM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 31/12/2010 9:55:10 PM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 31/12/2010 9:54:38 PM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 31/12/2010 4:15:37 PM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 31/12/2010 4:15:26 PM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 29/12/2010 12:32:16 AM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 29/12/2010 12:32:03 AM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 24/12/2010 7:21:41 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name Dogs - Dog Information - Dog Breeds, Pictures and Reviews for over 350 Dog Breeds | GreatDogSite.com timed out after none of the configured DNS servers responded.
     
    Log: 'System' Date/Time: 24/12/2010 3:02:01 AM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 24/12/2010 3:01:49 AM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 24/12/2010 3:01:02 AM
    Type: Warning Category: 0
    Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
    WLAN AutoConfig service has successfully stopped. 
     
    Log: 'System' Date/Time: 24/12/2010 2:56:08 AM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 24/12/2010 2:55:55 AM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 23/12/2010 11:41:19 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name www.merca2.com timed out after none of the configured DNS servers responded.
     
    Log: 'System' Date/Time: 22/12/2010 6:10:19 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name bloggingourway2bombay.com timed out after none of the configured DNS servers responded.
     
    Log: 'System' Date/Time: 21/12/2010 3:50:57 AM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name www.acelayouts.com timed out after none of the configured DNS servers responded.
     
    Log: 'System' Date/Time: 20/12/2010 10:33:10 PM
    Type: Warning Category: 0
    Event: 34005 Source: Microsoft-Windows-SharedAccess_NAT
    The ICS_IPV6 was unable to allocate bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
     
    Log: 'System' Date/Time: 20/12/2010 10:33:01 PM
    Type: Warning Category: 0
    Event: 11 Source: Microsoft-Windows-Wininit
    Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
     
    Log: 'System' Date/Time: 18/12/2010 11:48:43 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name A Sissy Kiss ~*~* For Sissy Baby Girls and Adult Baby Girls timed out after none of the configured DNS servers responded.
    Last edited by Brink; 31 Dec 2010 at 21:35. Reason: code box
      My Computer


  5. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #15

    Is this an upgrade from another OS?
    Did you do a clean install?
    Have you activated your Windows key for Windows 7?

    Three of 20 questions
      My Computer


  6. Posts : 10
    Windows 7 home premium 64 bit
    Thread Starter
       #16

    about 4 months ago i got a bad virus that fried my hard drive so i went and bought a new hd and windows 7. yes this is a clean install, no its not an upgrade and i did use my windows 7 key
      My Computer


  7. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #17

    MSDTC encountered an error (HR=0x80000171)
    See this Problem with MSDTC

    you also have a problem here:
    Faulting application name: Oblivion.exe

    Flush your DNS cache:
    Right click Command prompt to run as Administrator. Type ipconfig /flushdns press 'enter'.

    Now, download Malwarebytes' Anti-Malware to your desktop
    |MG| Malwarebytes Anti-Malware 1.50.1 Download
    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.

    * When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.
      My Computer


  8. Posts : 10
    Windows 7 home premium 64 bit
    Thread Starter
       #18

    ok i cant figure out how to fix the MSDTC problem! the oblivion.exe is a game and it crashed the other day and im unsure why. i have cleared dns and i have had mbam and use it regularly will post log when finished

    Code:
     
    Malwarebytes' Anti-Malware 1.50.1.1100
    Malwarebytes
     
    Database version: 5450
     
    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385
     
    1/4/2011 9:47:59 PM
    mbam-log-2011-01-04 (21-47-59).txt
     
    Scan type: Full scan (C:\|E:\|F:\|)
    Objects scanned: 320547
    Time elapsed: 34 minute(s), 34 second(s)
     
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
     
    Memory Processes Infected:
    (No malicious items detected)
     
    Memory Modules Infected:
    (No malicious items detected)
     
    Registry Keys Infected:
    (No malicious items detected)
     
    Registry Values Infected:
    (No malicious items detected)
     
    Registry Data Items Infected:
    (No malicious items detected)
     
    Folders Infected:
    (No malicious items detected)
     
    Files Infected:
    (No malicious items detected)
    Last edited by Brink; 04 Jan 2011 at 22:49. Reason: merged - code box
      My Computer


  9. Posts : 5,795
    Windows 7 Ultimate x64 SP1
       #19

    djscy1 said:
    about 4 months ago i got a bad virus that fried my hard drive so i went and bought a new hd
    For the record, a virus isn't going to destroy hardware.

    Have you tried creating a second user account and trying your search terms there?
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:57.
Find Us