help me with "windows cannot update ....."


  1. Posts : 1
    Windows 7 Home premium 64
       #1

    Hi to all, I need help with my updating which will not work,
    I have the following notebook:
    1. hp pavilion dv6-2173cl entertainment notebook
    2. intel i3 core inside
    3. windows 7 home premium 64bits
    4. 4gb ram

    The problem started a while ago when I tried to run windows update but keep getting the message " ! windows update cannot currently check for updates, because the service is not running. you may need to restart your computer."
    and even if I restart I get the same.
    I ran also the two Microsoft fix it but no deal.

    By the way after reinstalling my update show that I have no updates
    I ran the avast cleaner but no deal.
    ** I reinstalled 3 time my windows 7 with a full install after a backup of all my archives.
    I ran the sfc and the following is the info on the file received after the run :

    "
    Code:
    *************************************************************
    ********************** Computer Info ************************
    *************************************************************
    Logged in user: SANTOS-PC\SANTOS
    Computer Model: HP Pavilion dv6 Notebook PC
    Computer Manufacturer: Hewlett-Packard
    OS Name: Microsoft Windows 7 Home Premium |C:\Windows|\Device\Harddisk0\Partition2
    OS Version: 6.1.7600
    System Type: x64-based PC
    Total Physical Memory: 4023 MB
    Windows Directory: C:\Windows
    BIOS Version: Default System BIOS
    CPU: Intel(R) Core(TM) i3 CPU       M 330  @ 2.13GHz
    Video Card: NVIDIA GeForce G105M
    Resolution: 1366 x 768 x 4294967296 colors
     
     
    *************************************************************
    *********************** UAC Status **************************
    *************************************************************
    UAC is currently enabled
     
     
    *************************************************************
    ***************** Installed Applications ********************
    *************************************************************
     
    Microsoft Application Error Reporting - Location:  
    HP Customer Experience Enhancements - Location: C:\Program Files (x86)\ 
    PowerDirector - Location: C:\Program Files (x86)\CyberLink\PowerDirector\ 
    Microsoft Works - Location:  
    HP 3D DriveGuard - Location: C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\ 
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 - Location:  
    HP Wireless Assistant - Location: C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\ 
    HP MediaSmart SmartMenu - Location: C:\Program Files\Hewlett-Packard\HP MediaSmart\ 
    Microsoft SQL Server 2005 Compact Edition [ENU] - Location: C:\Program Files (x86)\Microsoft SQL Server Compact Edition\ 
    Norton Online Backup - Location: C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\ 
    Adobe AIR - Location:  
    LightScribe System Software - Location: C:\Program Files (x86)\Common Files\LightScribe\ 
    Power2Go - Location: C:\Program Files (x86)\Cyberlink\Power2Go\ 
    PowerStarter - Location: C:\Program Files (x86)\CyberLink\DVD Suite\ 
    Acrobat.com - Location: C:\Program Files (x86)\Adobe\Acrobat.com 
    Java(TM) 6 Update 35 - Location: C:\Program Files (x86)\Java\jre6\ 
    Java(TM) 6 Update 15 (64-bit) - Location: C:\Program Files\Java\jre6\ 
    Java(TM) SE Development Kit 6 Update 15 (64-bit) - Location: C:\Program Files\Java\jdk1.6.0_15\ 
    HP MediaSmart SlingPlayer - Location: C:\Program Files (x86)\Hewlett-Packard\Media\SlingPlayer\ 
    HPAsset component for HP Active Support Library - Location: C:\Program Files (x86)\Hewlett-Packard\ 
    HP Support Assistant - Location: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\ 
    Adobe Reader 9.1 MUI - Location: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\ 
    Windows Live Sign-in Assistant - Location:  
    HP - Location: c:\Program Files (x86)\Hewlett-Packard\TouchSmart\DVD Menu Pack\ 
    MSVCRT - Location:  
    QLBCASL - Location: C:\Program Files (x86)\Hewlett-Packard\QLBCASL\ 
    HP - Location: c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\ 
    Microsoft Live Search Toolbar - Location: C:\Program Files\MSN\Toolbar\3.0.0566.0 
    Windows Live Essentials - Location:  
    MediaSmart Live TV - Location: c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\ 
    Windows Live Sync - Location:  
    Junk Mail filter update - Location:  
    MediaSmart DVD - Location: c:\Program Files (x86)\Hewlett-Packard\Media\DVD\ 
    HP - Location: c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\ 
    HP Smart Web Printing - Location:  
    ActiveCheck component for HP Active Support Library - Location: C:\Program Files (x86)\Hewlett-Packard\ 
    Microsoft Choice Guard - Location: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Choice Guard\ 
    HP - Location: c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media Movie Theme Pack\ 
    Windows Live Photo Gallery - Location:  
    HP Update - Location: C:\Program Files (x86)\Hp\HP Software Update 
    Microsoft Visual C++ 2005 Redistributable - Location:  
    Windows Live Messenger - Location:  
    PowerRecover - Location: C:\Program Files (x86)\Hewlett-Packard\Recovery\ 
    HP MediaSmart/TouchSmart Netflix - Location: C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Netflix\ 
    Windows Live Call - Location:  
    HP Advisor - Location: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\ 
    LabelPrint - Location: C:\Program Files (x86)\CyberLink\LabelPrint\ 
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - Location:  
    MediaSmart Internet TV - Location: C:\Program Files (x86)\Hewlett-Packard\Media\iTV\ 
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - Location:  
    Microsoft Silverlight - Location:  
    HP MediaSmart Software Notebook Demo - Location: C:\Program Files (x86)\HP\HP MediaSmart Demo\ 
    Windows Live Upload Tool - Location:  
    Windows Live Communications Platform - Location:  
    Windows Live Mail - Location:  
    Windows Live Writer - Location:  
    Java Auto Updater - Location:  
    HP User Guides 0154 - Location: C:\Program Files (x86)\Hewlett-Packard\Documentation\ 
     
     
    *************************************************************
    ************************* Services **************************
    *************************************************************
     
    ------------------------------------------
    Name: Adobe Flash Player Update Service
    Path: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Advanced SystemCare Service 5
    Path: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Application Experience
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Andrea ST Filters Service
    Path: C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Application Layer Gateway Service
    Path: C:\Windows\System32\alg.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Application Host Helper Service
    Path: C:\Windows\system32\svchost.exe -k apphost
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Application Identity
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Application Information
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Windows Audio Endpoint Builder
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Audio
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: avast! Antivirus
    Path: "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: avast! Firewall
    Path: "C:\Program Files\AVAST Software\Avast\afwServ.exe"
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: ActiveX Installer (AxInstSV)
    Path: C:\Windows\system32\svchost.exe -k AxInstSVGroup
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: BitLocker Drive Encryption Service
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Base Filtering Engine
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Background Intelligent Transfer Service
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Computer Browser
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Bluetooth Support Service
    Path: C:\Windows\system32\svchost.exe -k bthsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Certificate Propagation
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Indexing Service
    Path: C:\Windows\system32\CISVC.EXE
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Microsoft .NET Framework NGEN v2.0.50727_X86
    Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Microsoft .NET Framework NGEN v2.0.50727_X64
    Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Com4QLBEx
    Path: "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe"
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: COM+ System Application
    Path: C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Cryptographic Services
    Path: C:\Windows\system32\svchost.exe -k NetworkService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: DCOM Server Process Launcher
    Path: C:\Windows\system32\svchost.exe -k DcomLaunch
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Disk Defragmenter
    Path: C:\Windows\system32\svchost.exe -k defragsvc
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: DHCP Client
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: DNS Client
    Path: C:\Windows\system32\svchost.exe -k NetworkService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Wired AutoConfig
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Diagnostic Policy Service
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Extensible Authentication Protocol
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Encrypting File System (EFS)
    Path: C:\Windows\System32\lsass.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Media Center Receiver Service
    Path: C:\Windows\ehome\ehRecvr.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Media Center Scheduler Service
    Path: C:\Windows\ehome\ehsched.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Event Log
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: COM+ Event System
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Fax
    Path: C:\Windows\system32\fxssvc.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Function Discovery Provider Host
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Function Discovery Resource Publication
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Windows Font Cache Service
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Windows Presentation Foundation Font Cache 3.0.0.0
    Path: C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: GameConsoleService
    Path: "C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe"
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Group Policy Client
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Human Interface Device Access
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Health Key and Certificate Management
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: HomeGroup Listener
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: HomeGroup Provider
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: HP Health Check Service
    Path: "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: hpqwmiex
    Path: "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: HP Service
    Path: C:\Windows\system32\Hpservice.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows CardSpace
    Path: "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: IKE and AuthIP IPsec Keying Modules
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: PnP-X IP Bus Enumerator
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: IP Helper
    Path: C:\Windows\System32\svchost.exe -k NetSvcs
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: CNG Key Isolation
    Path: C:\Windows\system32\lsass.exe
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: KtmRm for Distributed Transaction Coordinator
    Path: C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Server
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Workstation
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: LightScribeService Direct Disc Labeling Service
    Path: "C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Link-Layer Topology Discovery Mapper
    Path: C:\Windows\System32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: TCP/IP NetBIOS Helper
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: LPD Service
    Path: C:\Windows\System32\svchost.exe -k LPDService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Media Center Extender Service
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Multimedia Class Scheduler
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Mozilla Maintenance Service
    Path: "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Firewall
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Distributed Transaction Coordinator
    Path: C:\Windows\System32\msdtc.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Microsoft iSCSI Initiator Service
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Windows Installer
    Path: C:\Windows\system32\msiexec.exe /V
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Network Access Protection Agent
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Netlogon
    Path: C:\Windows\system32\lsass.exe
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Network Connections
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Network List Service
    Path: C:\Windows\System32\svchost.exe -k LocalService
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Net.Tcp Port Sharing Service
    Path: "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Norton Internet Security
    Path: "C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\diMaster.dll" /prefetch:1
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Network Location Awareness
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Network Store Interface Service
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: NVIDIA Display Driver Service
    Path: C:\Windows\system32\nvvsvc.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Peer Networking Identity Manager
    Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Peer Networking Grouping
    Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Program Compatibility Assistant Service
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Performance Counter DLL Host
    Path: C:\Windows\SysWow64\perfhost.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Performance Logs & Alerts
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Plug and Play
    Path: C:\Windows\system32\svchost.exe -k DcomLaunch
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: PNRP Machine Name Publication Service
    Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Peer Name Resolution Protocol
    Path: C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: IPsec Policy Agent
    Path: C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Power
    Path: C:\Windows\system32\svchost.exe -k DcomLaunch
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: User Profile Service
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Protected Storage
    Path: C:\Windows\system32\lsass.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Quality Windows Audio Video Experience
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Remote Access Auto Connection Manager
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Remote Access Connection Manager
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Routing and Remote Access
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Remote Registry
    Path: C:\Windows\system32\svchost.exe -k regsvc
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Cyberlink RichVideo Service(CRVS)
    Path: "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: RPC Endpoint Mapper
    Path: C:\Windows\system32\svchost.exe -k RPCSS
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Remote Procedure Call (RPC) Locator
    Path: C:\Windows\system32\locator.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Remote Procedure Call (RPC)
    Path: C:\Windows\system32\svchost.exe -k rpcss
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Security Accounts Manager
    Path: C:\Windows\system32\lsass.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Smart Card
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Task Scheduler
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Smart Card Removal Policy
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Backup
    Path: C:\Windows\system32\svchost.exe -k SDRSVC
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Secondary Logon
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: System Event Notification Service
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Adaptive Brightness
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Remote Desktop Configuration
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Internet Connection Sharing (ICS)
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Shell Hardware Detection
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: SNMP Trap
    Path: C:\Windows\System32\snmptrap.exe
    StartMode: Disabled
    State: Stopped
    ------------------------------------------
    Name: Print Spooler
    Path: C:\Windows\System32\spoolsv.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Software Protection
    Path: C:\Windows\system32\sppsvc.exe
    StartMode: Auto
    State: Stopped
    ------------------------------------------
    Name: SPP Notification Service
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: SSDP Discovery
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Secure Socket Tunneling Protocol Service
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Audio Service
    Path: C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Image Acquisition (WIA)
    Path: C:\Windows\system32\svchost.exe -k imgsvc
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Microsoft Software Shadow Copy Provider
    Path: C:\Windows\System32\svchost.exe -k swprv
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Superfetch
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Tablet PC Input Service
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Telephony
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: TPM Base Services
    Path: C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Remote Desktop Services
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Themes
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Thread Ordering Server
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Distributed Link Tracking Client
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Modules Installer
    Path: C:\Windows\servicing\TrustedInstaller.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Interactive Services Detection
    Path: C:\Windows\system32\UI0Detect.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: UPnP Device Host
    Path: C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Desktop Window Manager Session Manager
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Credential Manager
    Path: C:\Windows\system32\lsass.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Virtual Disk
    Path: C:\Windows\System32\vds.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Volume Shadow Copy
    Path: C:\Windows\system32\vssvc.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Time
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: World Wide Web Publishing Service
    Path: C:\Windows\system32\svchost.exe -k iissvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Process Activation Service
    Path: C:\Windows\system32\svchost.exe -k iissvcs
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Block Level Backup Engine Service
    Path: "C:\Windows\system32\wbengine.exe"
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Biometric Service
    Path: C:\Windows\system32\svchost.exe -k WbioSvcGroup
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Connect Now - Config Registrar
    Path: C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Color System
    Path: C:\Windows\system32\svchost.exe -k wcssvc
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Diagnostic Service Host
    Path: C:\Windows\System32\svchost.exe -k LocalService
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Diagnostic System Host
    Path: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: WebClient
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Event Collector
    Path: C:\Windows\system32\svchost.exe -k NetworkService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Problem Reports and Solutions Control Panel Support
    Path: C:\Windows\System32\svchost.exe -k netsvcs
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Error Reporting Service
    Path: C:\Windows\System32\svchost.exe -k WerSvcGroup
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Defender
    Path: C:\Windows\System32\svchost.exe -k secsvcs
    StartMode: Auto
    State: Stopped
    ------------------------------------------
    Name: WinHTTP Web Proxy Auto-Discovery Service
    Path: C:\Windows\system32\svchost.exe -k LocalService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Management Instrumentation
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Remote Management (WS-Management)
    Path: C:\Windows\System32\svchost.exe -k NetworkService
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: WLAN AutoConfig
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: WMI Performance Adapter
    Path: C:\Windows\system32\wbem\WmiApSrv.exe
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Windows Media Player Network Sharing Service
    Path: "C:\Program Files\Windows Media Player\wmpnetwk.exe"
    StartMode: Manual
    State: Running
    ------------------------------------------
    Name: Parental Controls
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: Portable Device Enumerator Service
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: WRSVC
    Path: "C:\Program Files\Webroot\WRSA.exe" -service
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Security Center
    Path: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Search
    Path: C:\Windows\system32\SearchIndexer.exe /Embedding
    StartMode: Auto
    State: Stopped
    ------------------------------------------
    Name: Windows Update
    Path: C:\Windows\system32\svchost.exe -k netsvcs
    StartMode: Auto
    State: Running
    ------------------------------------------
    Name: Windows Driver Foundation - User-mode Driver Framework
    Path: C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    StartMode: Manual
    State: Stopped
    ------------------------------------------
    Name: WWAN AutoConfig
    Path: C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    StartMode: Manual
    State: Stopped
    ------------------------------------------
     
     
    *************************************************************
    ******************** Installed Codecs ***********************
    *************************************************************
    ------------------------------------------
    Name: C:\Windows\system32\MSRLE32.DLL Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msrle32
    ------------------------------------------
    Name: C:\Windows\system32\MSVIDC32.DLL Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msvidc32
    ------------------------------------------
    Name: C:\Windows\system32\IMAADP32.ACM Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: imaadp32
    ------------------------------------------
    Name: C:\Windows\system32\MSG711.ACM Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msg711
    ------------------------------------------
    Name: C:\Windows\system32\MSGSM32.ACM Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msgsm32
    ------------------------------------------
    Name: C:\Windows\system32\MSADP32.ACM Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msadp32
    ------------------------------------------
    Name: C:\Windows\system32\MSYUV.DLL Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: msyuv
    ------------------------------------------
    Name: C:\Windows\system32\IYUV_32.DLL Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: iyuv_32
    ------------------------------------------
    Name: C:\Windows\system32\TSBYUV.DLL Description: 
    Version: 6.1.7600.16385
    Path: \windows\system32\
    FileName: tsbyuv
    ------------------------------------------
    Name: C:\Windows\system32\L3CODECA.ACM Description: Fraunhofer IIS MPEG Layer-3 Codec
    Version: 1.9.0.401
    Path: \windows\system32\
    FileName: l3codeca
    ------------------------------------------
     
     
    *************************************************************
    *********************** Hot Fixes ***************************
    *************************************************************
     
     
    *************************************************************
    ************************* Event Log *************************
    *************************************************************
     
    Application - 9/24/2012 10:19:00 PM: Windows Installer reconfigured the product. Product Name: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17. Product Version: 9.0.30729. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:00 PM: Windows Installer reconfigured the product. Product Name: Microsoft Silverlight. Product Version: 1.0.0.0. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:00 PM: Windows Installer reconfigured the product. Product Name: HP MediaSmart Software Notebook Demo. Product Version: 1.00.0000. Product Language: 1033. Manufacturer: Hewlett-Packard. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:00 PM: Windows Installer reconfigured the product. Product Name: Windows Live Upload Tool. Product Version: 14.0.8014.1029. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:01 PM: Windows Installer reconfigured the product. Product Name: Windows Live Communications Platform. Product Version: 14.0.8064.206. Product Language: 0. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:01 PM: Windows Installer reconfigured the product. Product Name: Windows Live Mail. Product Version: 14.0.8089.0726. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:01 PM: Windows Installer reconfigured the product. Product Name: Windows Live Writer. Product Version: 14.0.8089.0726. Product Language: 1033. Manufacturer: Microsoft Corporation. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:01 PM: Windows Installer reconfigured the product. Product Name: Java Auto Updater. Product Version: 2.0.7.1. Product Language: 1033. Manufacturer: Sun Microsystems, Inc.. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:01 PM: Windows Installer reconfigured the product. Product Name: HP User Guides 0154. Product Version: 1.01.0001. Product Language: 1033. Manufacturer: Hewlett-Packard. Reconfiguration success or error status: 0.
    ------------------------------------------
    Application - 9/24/2012 10:19:02 PM: Unsupported service control request (see data below)
    ------------------------------------------
    Security - 9/24/2012 10:16:07 PM: An account was successfully logged on.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SANTOS-PC$
        Account Domain:        ZENAIDASANTOS
        Logon ID:        0x3e7
     
    Logon Type:            5
     
    New Logon:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
        Logon GUID:        {00000000-0000-0000-0000-000000000000}
     
    Process Information:
        Process ID:        0x2e4
        Process Name:        C:\Windows\System32\services.exe
     
    Network Information:
        Workstation Name:    
        Source Network Address:    -
        Source Port:        -
     
    Detailed Authentication Information:
        Logon Process:        Advapi  
        Authentication Package:    Negotiate
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
     
    This event is generated when a logon session is created. It is generated on the computer that was accessed.
     
    The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
     
    The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
     
    The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
     
    The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
     
    The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    ------------------------------------------
    Security - 9/24/2012 10:16:07 PM: Special privileges assigned to new logon.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
     
    Privileges:        SeAssignPrimaryTokenPrivilege
                SeTcbPrivilege
                SeSecurityPrivilege
                SeTakeOwnershipPrivilege
                SeLoadDriverPrivilege
                SeBackupPrivilege
                SeRestorePrivilege
                SeDebugPrivilege
                SeAuditPrivilege
                SeSystemEnvironmentPrivilege
                SeImpersonatePrivilege
    ------------------------------------------
    Security - 9/24/2012 10:16:52 PM: An account was successfully logged on.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SANTOS-PC$
        Account Domain:        ZENAIDASANTOS
        Logon ID:        0x3e7
     
    Logon Type:            5
     
    New Logon:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
        Logon GUID:        {00000000-0000-0000-0000-000000000000}
     
    Process Information:
        Process ID:        0x2e4
        Process Name:        C:\Windows\System32\services.exe
     
    Network Information:
        Workstation Name:    
        Source Network Address:    -
        Source Port:        -
     
    Detailed Authentication Information:
        Logon Process:        Advapi  
        Authentication Package:    Negotiate
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
     
    This event is generated when a logon session is created. It is generated on the computer that was accessed.
     
    The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
     
    The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
     
    The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
     
    The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
     
    The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    ------------------------------------------
    Security - 9/24/2012 10:16:52 PM: Special privileges assigned to new logon.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
     
    Privileges:        SeAssignPrimaryTokenPrivilege
                SeTcbPrivilege
                SeSecurityPrivilege
                SeTakeOwnershipPrivilege
                SeLoadDriverPrivilege
                SeBackupPrivilege
                SeRestorePrivilege
                SeDebugPrivilege
                SeAuditPrivilege
                SeSystemEnvironmentPrivilege
                SeImpersonatePrivilege
    ------------------------------------------
    Security - 9/24/2012 10:17:04 PM: An account was successfully logged on.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SANTOS-PC$
        Account Domain:        ZENAIDASANTOS
        Logon ID:        0x3e7
     
    Logon Type:            5
     
    New Logon:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
        Logon GUID:        {00000000-0000-0000-0000-000000000000}
     
    Process Information:
        Process ID:        0x2e4
        Process Name:        C:\Windows\System32\services.exe
     
    Network Information:
        Workstation Name:    
        Source Network Address:    -
        Source Port:        -
     
    Detailed Authentication Information:
        Logon Process:        Advapi  
        Authentication Package:    Negotiate
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
     
    This event is generated when a logon session is created. It is generated on the computer that was accessed.
     
    The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
     
    The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
     
    The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
     
    The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
     
    The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    ------------------------------------------
    Security - 9/24/2012 10:17:04 PM: Special privileges assigned to new logon.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
     
    Privileges:        SeAssignPrimaryTokenPrivilege
                SeTcbPrivilege
                SeSecurityPrivilege
                SeTakeOwnershipPrivilege
                SeLoadDriverPrivilege
                SeBackupPrivilege
                SeRestorePrivilege
                SeDebugPrivilege
                SeAuditPrivilege
                SeSystemEnvironmentPrivilege
                SeImpersonatePrivilege
    ------------------------------------------
    Security - 9/24/2012 10:18:46 PM: An account was successfully logged on.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SANTOS-PC$
        Account Domain:        ZENAIDASANTOS
        Logon ID:        0x3e7
     
    Logon Type:            5
     
    New Logon:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
        Logon GUID:        {00000000-0000-0000-0000-000000000000}
     
    Process Information:
        Process ID:        0x2e4
        Process Name:        C:\Windows\System32\services.exe
     
    Network Information:
        Workstation Name:    
        Source Network Address:    -
        Source Port:        -
     
    Detailed Authentication Information:
        Logon Process:        Advapi  
        Authentication Package:    Negotiate
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
     
    This event is generated when a logon session is created. It is generated on the computer that was accessed.
     
    The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
     
    The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
     
    The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
     
    The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
     
    The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    ------------------------------------------
    Security - 9/24/2012 10:18:46 PM: Special privileges assigned to new logon.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
     
    Privileges:        SeAssignPrimaryTokenPrivilege
                SeTcbPrivilege
                SeSecurityPrivilege
                SeTakeOwnershipPrivilege
                SeLoadDriverPrivilege
                SeBackupPrivilege
                SeRestorePrivilege
                SeDebugPrivilege
                SeAuditPrivilege
                SeSystemEnvironmentPrivilege
                SeImpersonatePrivilege
    ------------------------------------------
    Security - 9/24/2012 10:19:12 PM: An account was successfully logged on.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SANTOS-PC$
        Account Domain:        ZENAIDASANTOS
        Logon ID:        0x3e7
     
    Logon Type:            5
     
    New Logon:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
        Logon GUID:        {00000000-0000-0000-0000-000000000000}
     
    Process Information:
        Process ID:        0x2e4
        Process Name:        C:\Windows\System32\services.exe
     
    Network Information:
        Workstation Name:    
        Source Network Address:    -
        Source Port:        -
     
    Detailed Authentication Information:
        Logon Process:        Advapi  
        Authentication Package:    Negotiate
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
     
    This event is generated when a logon session is created. It is generated on the computer that was accessed.
     
    The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
     
    The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
     
    The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
     
    The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
     
    The authentication information fields provide detailed information about this specific logon request.
        - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
        - Transited services indicate which intermediate services have participated in this logon request.
        - Package name indicates which sub-protocol was used among the NTLM protocols.
        - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    ------------------------------------------
    Security - 9/24/2012 10:19:12 PM: Special privileges assigned to new logon.
     
    Subject:
        Security ID:        S-1-5-18
        Account Name:        SYSTEM
        Account Domain:        NT AUTHORITY
        Logon ID:        0x3e7
     
    Privileges:        SeAssignPrimaryTokenPrivilege
                SeTcbPrivilege
                SeSecurityPrivilege
                SeTakeOwnershipPrivilege
                SeLoadDriverPrivilege
                SeBackupPrivilege
                SeRestorePrivilege
                SeDebugPrivilege
                SeAuditPrivilege
                SeSystemEnvironmentPrivilege
                SeImpersonatePrivilege
    ------------------------------------------
    System - 9/24/2012 10:16:13 PM: The Windows Search service terminated with service-specific error %%-2147217025.
    ------------------------------------------
    System - 9/24/2012 10:16:13 PM: The Windows Search service terminated unexpectedly.  It has done this 11 time(s).
    ------------------------------------------
    System - 9/24/2012 10:16:58 PM: The Windows Search service entered the stopped state.
    ------------------------------------------
    System - 9/24/2012 10:16:58 PM: The Windows Search service terminated with service-specific error %%-2147217025.
    ------------------------------------------
    System - 9/24/2012 10:16:58 PM: The Windows Search service terminated unexpectedly.  It has done this 12 time(s).
    ------------------------------------------
    System - 9/24/2012 10:17:09 PM: The Windows Search service entered the stopped state.
    ------------------------------------------
    System - 9/24/2012 10:17:09 PM: The Windows Search service terminated with service-specific error %%-2147217025.
    ------------------------------------------
    System - 9/24/2012 10:17:09 PM: The Windows Search service terminated unexpectedly.  It has done this 13 time(s).
    ------------------------------------------
    System - 9/24/2012 10:18:46 PM: The Windows Installer service entered the running state.
    ------------------------------------------
    System - 9/24/2012 10:19:13 PM: The Windows Modules Installer service entered the running state.
    ------------------------------------------
     
     
    *************************************************************
    **************** Windows Experience Index *******************
    *************************************************************
     
    CPU Score: 6.2
    Disk Score: 5.9
    Graphics Score: 4.9
    Direct 3D Score: 5.7
    Memory Score: 5.9
    WEI Score: 4.9
     
     
    *************************************************************
    ************************* Users *****************************
    *************************************************************
    ------------------------------------------
    Name: Administrator Domain: SANTOS-PC
    FullName:  Description: Built-in account for administering the computer/domain
    Disabled: True
    Status: Degraded
    LocalAccount: True
    PasswordChangeable: True
    PasswordExpires: False
    PasswordRequired: True
    ------------------------------------------
    Name: Guest Domain: SANTOS-PC
    FullName:  Description: Built-in account for guest access to the computer/domain
    Disabled: True
    Status: Degraded
    LocalAccount: True
    PasswordChangeable: False
    PasswordExpires: False
    PasswordRequired: False
    ------------------------------------------
    Name: SANTOS Domain: SANTOS-PC
    FullName:  Description: 
    Disabled: False
    Status: OK
    LocalAccount: True
    PasswordChangeable: True
    PasswordExpires: False
    PasswordRequired: False
    ------------------------------------------
     
     
    *************************************************************
    ************************** Memory ***************************
    *************************************************************
     
    ------------------------------------------
    Manufacturer: Micron
    Model: 
    Name: Physical Memory
    Bank Label: BANK 0
    Capacity: 2048 MB
    Description: Physical Memory
    Tag: Physical Memory 0
    ------------------------------------------
    Manufacturer: Micron
    Model: 
    Name: Physical Memory
    Bank Label: BANK 1
    Capacity: 2048 MB
    Description: Physical Memory
    Tag: Physical Memory 1
    ------------------------------------------
     
     
    *************************************************************
    ************************ Video Card *************************
    *************************************************************
     
    Brand: NVIDIA
    Model: NVIDIA GeForce G105M
    Adapter DAC Type: Integrated RAMDAC
    Adapter RAM: 512 MB
    Current BitsPerPixel: 32
    Current Number Of Colors: 4294967296
    Current Refresh Rate: 60
    Driver Date: 11/28/2009 00:00:00
    Driver Version: 8.16.11.8817
    MaxRefreshRate: 60
    MinRefreshRate: 60
    Status: OK
    Video Memory Type: 2
    Video Mode Description: 1366 x 768 x 4294967296 colors
    Video Processor: GeForce G105M
     
     
    *************************************************************
    ************************** Drives ***************************
    *************************************************************
     
    Model: WDC WD5000BPKT-60PK4T0
    Description: Disk drive
    InterfaceType: IDE
    Partitions: 4
    SCSIBus: 0
    SCSILogicalUnit: 0
    SCSIPort: 0
    SCSITargetId: 0
    SectorsPerTrack: 63
    Size: 466 GB
    Status: OK
    ------------------------------------------
     
     
    *************************************************************
    ************************ CD/DVD Rom *************************
    *************************************************************
     
    Name: hp CDDVDW TS-L633N
    Description: CD-ROM Drive
    LastErrorCode: 
    Manufacturer: (Standard CD-ROM drives)
    Media Type: DVD Writer
    ------------------------------------------
     
     
    *************************************************************
    ************************* IDE/SATA **************************
    *************************************************************
     
    ------------------------------------------
    Manufacturer: Intel
    Name: Intel(R) PCHM SATA AHCI Controller 6 Port
    Last Error Code: 
    Status: OK
    ------------------------------------------
     
     
    *************************************************************
    ************************** Network **************************
    *************************************************************
     
     
    Windows IP Configuration
     
       Host Name . . . . . . . . . . . . : SANTOS-PC
       Primary Dns Suffix  . . . . . . . : 
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
     
    Wireless LAN adapter Wireless Network Connection:
     
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Intel(R) WiFi Link 1000 BGN
       Physical Address. . . . . . . . . : 00-26-C7-0F-1A-E8
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::b1c3:cbb7:ca6b:536d%12(Preferred) 
       IPv4 Address. . . . . . . . . . . : 192.168.1.5(Preferred) 
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : Monday, September 24, 2012 9:59:06 PM
       Lease Expires . . . . . . . . . . : Tuesday, September 25, 2012 9:59:06 PM
       Default Gateway . . . . . . . . . : 192.168.1.1
       DHCP Server . . . . . . . . . . . : 192.168.1.1
       DHCPv6 IAID . . . . . . . . . . . : 218113735
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-4D-1E-13-C8-0A-A9-29-50-E3
       DNS Servers . . . . . . . . . . . : 192.168.1.1
       NetBIOS over Tcpip. . . . . . . . : Enabled
     
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter isatap.{A2462ED0-E753-45BA-90E9-E790C7BC7C46}:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
     
    *************************************************************
    ********************* Systerm Restore ***********************
    *************************************************************
     
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/20/2012 13:12:15
    SequenceNumber: 19
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/20/2012 13:12:45
    SequenceNumber: 20
    ------------------------------------------
    Description: Restore Operation
    Creation Time: 09/20/2012 13:29:25
    SequenceNumber: 21
    ------------------------------------------
    Description: Installed Java(TM) 6 Update 35
    Creation Time: 09/20/2012 13:53:56
    SequenceNumber: 22
    ------------------------------------------
    Description: Installed Microsoft Fix it 50202
    Creation Time: 09/20/2012 18:16:07
    SequenceNumber: 24
    ------------------------------------------
    Description: Installed Microsoft Fix it 50202
    Creation Time: 09/20/2012 18:21:58
    SequenceNumber: 25
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/21/2012 02:39:34
    SequenceNumber: 26
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/21/2012 02:44:24
    SequenceNumber: 27
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/21/2012 02:46:02
    SequenceNumber: 28
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/21/2012 02:46:37
    SequenceNumber: 29
    ------------------------------------------
    Description: Windows Modules Installer
    Creation Time: 09/21/2012 02:47:38
    SequenceNumber: 30
    ------------------------------------------
    Description: Removed Microsoft Office Home and Student 2007
    Creation Time: 09/21/2012 04:29:26
    SequenceNumber: 31
    ------------------------------------------
    Description: Removed Microsoft Office Suite Activation Assistant.
    Creation Time: 09/21/2012 04:34:09
    SequenceNumber: 32
    ------------------------------------------
    Description: Removed Microsoft Office PowerPoint Viewer 2007 (English)
    Creation Time: 09/21/2012 04:34:58
    SequenceNumber: 33
    ------------------------------------------
    Description: Removed Compatibility Pack for the 2007 Office system
    Creation Time: 09/21/2012 04:39:11
    SequenceNumber: 34
    ------------------------------------------
    Description: IObit Uninstaller restore point
    Creation Time: 09/22/2012 04:53:08
    SequenceNumber: 35
    ------------------------------------------
    Description: IObit Uninstaller restore point
    Creation Time: 09/25/2012 02:24:23
    SequenceNumber: 36
    ------------------------------------------
    Description: IObit Uninstaller restore point
    Creation Time: 09/25/2012 02:26:20
    SequenceNumber: 37
    ------------------------------------------
     
     
    *************************************************************
    ******************** Running Processes **********************
    *************************************************************
     
    ------------------------------------------
    Name: System Idle Process
    ------------------------------------------
    Name: System
    ------------------------------------------
    Name: smss.exe
    ------------------------------------------
    Name: csrss.exe
    ------------------------------------------
    Name: wininit.exe
    ------------------------------------------
    Name: csrss.exe
    ------------------------------------------
    Name: services.exe
    ------------------------------------------
    Name: lsass.exe
    ------------------------------------------
    Name: lsm.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: ASCService.exe
    ------------------------------------------
    Name: WRSA.exe
    ------------------------------------------
    Name: nvvsvc.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: stacsv64.exe
    ------------------------------------------
    Name: winlogon.exe
    ------------------------------------------
    Name: audiodg.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: hpservice.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: AvastSvc.exe
    ------------------------------------------
    Name: nvvsvc.exe
    ------------------------------------------
    Name: afwServ.exe
    ------------------------------------------
    Name: spoolsv.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: AESTSr64.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: CISVC.EXE
    ------------------------------------------
    Name: LSSrvc.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: ccsvchst.exe
    ------------------------------------------
    Name: RichVideo.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: WmiPrvSE.exe
    ------------------------------------------
    Name: taskhost.exe
    ------------------------------------------
    Name: dwm.exe
    ------------------------------------------
    Name: explorer.exe
    ------------------------------------------
    Name: ccsvchst.exe
    ------------------------------------------
    Name: WRSA.exe
    ------------------------------------------
    Name: sttray64.exe
    ------------------------------------------
    Name: SmartMenu.exe
    ------------------------------------------
    Name: LightScribeControlPanel.exe
    ------------------------------------------
    Name: ASCTray.exe
    ------------------------------------------
    Name: QLBCtrl.exe
    ------------------------------------------
    Name: HPWAMain.exe
    ------------------------------------------
    Name: AvastUI.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    Name: hpqWmiEx.exe
    ------------------------------------------
    Name: taskeng.exe
    ------------------------------------------
    Name: wmpnetwk.exe
    ------------------------------------------
    Name: CLMLSvc.exe
    ------------------------------------------
    Name: Com4QLBEx.exe
    ------------------------------------------
    Name: firefox.exe
    ------------------------------------------
    Name: HpqToaster.exe
    ------------------------------------------
    Name: HPHC_Service.exe
    ------------------------------------------
    Name: VistaForums SysInfo.exe
    ------------------------------------------
    Name: WmiPrvSE.exe
    ------------------------------------------
    Name: msiexec.exe
    ------------------------------------------
    Name: TrustedInstaller.exe
    ------------------------------------------
    Name: dllhost.exe
    ------------------------------------------
    Name: VSSVC.exe
    ------------------------------------------
    Name: svchost.exe
    ------------------------------------------
    "

    Please help me someone and sorry if i left out anything.

    one last question do i have to format the entire HD and then install windows?


    after clean install no update appear at all and no service packs either.
    thanks for what ever help I can get.
    Last edited by santito1216; 24 Sep 2012 at 23:17. Reason: sorry forgot to mention
      My Computer


  2. Posts : 31
    win7
       #2

    Try this -
    Open Windows Update
    Click on Change Settings
    Select 'Never Update...'
    Click OK
    exit Windows Update
    Now open Windows update again
    Click on Change Settings
    Select 'Update automatically'
    Click OK
    exit Windows Update
    Open Windows Update, and do a manual Check for Updates.
    If this does not work then give OPTION TWO in the tutorial below a try to reset Windows Update without losing your update history.
    Windows Update - Reset
      My Computer


  3. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #3

    A few general things to check

    1) There is a reference in teh installed programs list to Norton Online Backup - if you don't use it, then I suggest that you first uninstall it, then run the Norton Removal tool to get rid of that, and the remains of the Norton AV that your machine probably came pre-installed with.

    Download the Norton Removal Tool from here https://www-secure.symantec.com/norton-support/jsp/help-solutions.jsp?lg=english&ct=united+states&docid=20080710133834EN&product=home&version=1&pvid=f-home

    Close all other programs, then run the tool. When it's complete, reboot the machine whether it asks for it or not.

    2) You have some seriously out-of-date Java installs - you MUST uninstall ALL currently installed variants of Java - if you actually use Java at all, then go to www.java.com and install the latest version from there.

      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:50.
Find Us