Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: wierdest problem with network driver

07 Feb 2011   #11
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

it is only showing up to 1/30/2011 not to date
this problem started around the beginning of Jan 2011 to date
I just did it by date from 1/30/2011 to today just in case it showed something else

Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 07/02/2011 12:54:35 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 06/02/2011 4:42:19 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 06/02/2011 3:43:57 PM
Type: Error Category: 0
Event: 1013 Source: MsiInstaller
Product: D-Link DFE-530TX+ -- 1: The InstallScript engine is missing from this machine. If available, please run ISScript.msi, or contact your support personnel for further assistance.

Log: 'Application' Date/Time: 06/02/2011 3:42:08 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 05/02/2011 5:16:34 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 04/02/2011 4:56:02 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 04/02/2011 3:58:39 PM
Type: Error Category: 0
Event: 2000 Source: Microsoft Office 12
Accepted Safe Mode action : Microsoft Office Word.

Log: 'Application' Date/Time: 04/02/2011 2:57:54 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 03/02/2011 3:06:21 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 01/02/2011 3:58:24 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 01/02/2011 12:51:17 AM
Type: Error Category: 16
Event: 4621 Source: Microsoft-Windows-EventSystem
The COM+ Event System could not remove the EventSystem.EventSubscription object {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}.
Object name: SENS Logon Subscription
Object description:
The HRESULT was 80070005.

Log: 'Application' Date/Time: 31/01/2011 4:36:54 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 30/01/2011 4:51:23 PM
Type: Error Category: 0
Event: 8210 Source: System Restore
An unspecified error occurred during System Restore: (Windows Update). Additional information: 0x800703f1.

Log: 'Application' Date/Time: 30/01/2011 4:46:30 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

Log: 'Application' Date/Time: 30/01/2011 4:26:22 PM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program WINWORD.EXE version 12.0.6545.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1008 Start Time: 01cbc09a5d1de540 Termination Time: 16 Application Path: C:\Program Files\Microsoft Office\Office12\WINWORD.EXE Report Id: a6416f81-2c8d-11e0-a289-001372395dde

Log: 'Application' Date/Time: 30/01/2011 4:25:52 PM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program WINWORD.EXE version 12.0.6545.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1244 Start Time: 01cbc09a3bf31ca0 Termination Time: 0 Application Path: C:\Program Files\Microsoft Office\Office12\WINWORD.EXE Report Id: 91be5641-2c8d-11e0-a289-001372395dde

Log: 'Application' Date/Time: 30/01/2011 3:45:34 PM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program notepad.exe version 6.1.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1534 Start Time: 01cbc094a8714f10 Termination Time: 15 Application Path: C:\Windows\system32\notepad.exe Report Id: f3f89ab1-2c87-11e0-937c-001372395dde

Log: 'Application' Date/Time: 30/01/2011 3:36:34 PM
Type: Error Category: 0
Event: 4107 Source: Microsoft-Windows-CAPI2
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. .

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 06/02/2011 11:00:49 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 30 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 2420 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 06/02/2011 4:15:51 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 06/02/2011 3:40:59 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 06/02/2011 3:36:38 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 06/02/2011 3:30:55 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 6:37:06 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 20 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 2264 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 6:29:57 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 6:27:32 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 6:25:37 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 6:16:56 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 6:16:16 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 6:12:40 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 6:08:45 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 5:41:25 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 14 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Internet Explorer\IETld
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 5676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 5:33:11 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 5:28:31 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 05/02/2011 5:14:29 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 05/02/2011 12:06:48 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 35 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 3220 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 04/02/2011 11:10:11 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 04/02/2011 3:12:25 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 04/02/2011 3:08:00 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 04/02/2011 3:04:01 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 04/02/2011 2:59:55 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 17 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 2512 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 04/02/2011 2:52:34 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 04/02/2011 12:52:50 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 03/02/2011 11:00:24 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 03/02/2011 3:01:04 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 01/02/2011 11:56:46 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 01/02/2011 11:49:32 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 01/02/2011 3:50:10 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 01/02/2011 12:51:19 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 31/01/2011 10:24:15 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 31/01/2011 2:25:41 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 31/01/2011 1:10:02 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 512 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 512 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 512 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 512 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 512 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 31/01/2011 12:56:37 AM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:58:20 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:53:10 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 496 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 4:50:44 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:46:49 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 4:39:46 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:27:42 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 504 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 4:21:56 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:19:43 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 20 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Root
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\trust
Process 2136 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 4:04:54 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 4:02:04 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 6 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 3400 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 3:51:01 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 3:47:52 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 3:42:23 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

Log: 'Application' Date/Time: 30/01/2011 3:39:50 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 10 user registry handles leaked from \Registry\User\S-1-5-21-708790234-2997416502-461777958-1016:
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\CA
Process 1180 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1180 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\Disallowed
Process 1180 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1180 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1180 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Policies
Process 500 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-708790234-2997416502-461777958-1016\Software\Microsoft\SystemCertificates\My


Log: 'Application' Date/Time: 30/01/2011 3:35:51 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 is about to expire or already expired.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
No 'System' log Critical events found from 30/01/2011 to 07/02/2011

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 06/02/2011 3:44:41 PM
Type: Error Category: 0
Event: 10001 Source: Microsoft-Windows-DistributedCOM
Unable to start a DCOM Server: {9C0BA3C1-2B67-45EB-BF69-BED9658D28D2} as /. The error: "740" Happened while starting this command: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe -Embedding

Log: 'System' Date/Time: 06/02/2011 3:40:47 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 06/02/2011 3:37:11 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 06/02/2011 3:37:08 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 05/02/2011 6:28:02 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 05/02/2011 6:15:49 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 05/02/2011 5:29:06 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 05/02/2011 5:29:01 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 05/02/2011 5:14:16 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 04/02/2011 5:16:13 PM
Type: Error Category: 0
Event: 5 Source: Microsoft-Windows-Kernel-General
{Registry Hive Recovered} Registry hive (file): '\??\Volume{296410ee-ccba-11db-94af-806d6172696f}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{6AFEFC54-4945-46BC-BCAE-27FC52FB003D}' was corrupted and it has been recovered. Some data might have been lost.

Log: 'System' Date/Time: 04/02/2011 3:12:01 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 04/02/2011 3:08:34 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 04/02/2011 3:08:30 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 04/02/2011 3:03:50 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 04/02/2011 3:00:47 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 04/02/2011 3:00:29 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 04/02/2011 3:00:17 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 03/02/2011 5:16:12 PM
Type: Error Category: 0
Event: 5 Source: Microsoft-Windows-Kernel-General
{Registry Hive Recovered} Registry hive (file): '\??\Volume{296410ee-ccba-11db-94af-806d6172696f}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{DD8703A3-F037-46BB-A960-390B29791D80}' was corrupted and it has been recovered. Some data might have been lost.

Log: 'System' Date/Time: 03/02/2011 3:11:54 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.97.968.0).

Log: 'System' Date/Time: 03/02/2011 3:11:49 PM
Type: Error Category: 0
Event: 2001 Source: Microsoft Antimalware
Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.840.0 Update Source: Microsoft Update Server Update Stage: Install Source Path: Microsoft Corporation Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80070643 Error description: Fatal error during installation.

Log: 'System' Date/Time: 01/02/2011 5:34:30 PM
Type: Error Category: 0
Event: 5 Source: Microsoft-Windows-Kernel-General
{Registry Hive Recovered} Registry hive (file): '\??\Volume{296410ee-ccba-11db-94af-806d6172696f}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{70750B1E-DF8F-4185-B469-FD2D169A6846}' was corrupted and it has been recovered. Some data might have been lost.

Log: 'System' Date/Time: 01/02/2011 3:59:56 PM
Type: Error Category: 0
Event: 2001 Source: Microsoft Antimalware
Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.673.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: Microsoft Corporation Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80240022 Error description: The program can't check for definition updates.

Log: 'System' Date/Time: 01/02/2011 3:59:56 PM
Type: Error Category: 0
Event: 2001 Source: Microsoft Antimalware
Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.97.673.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: Microsoft Corporation Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6502.0 Error code: 0x80240022 Error description: The program can't check for definition updates.

Log: 'System' Date/Time: 31/01/2011 7:18:36 PM
Type: Error Category: 0
Event: 5 Source: Microsoft-Windows-Kernel-General
{Registry Hive Recovered} Registry hive (file): '\??\Volume{296410ee-ccba-11db-94af-806d6172696f}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{3D6D3D2B-8138-44D5-AD77-A66A6AC85885}' was corrupted and it has been recovered. Some data might have been lost.

Log: 'System' Date/Time: 30/01/2011 8:36:11 PM
Type: Error Category: 0
Event: 5 Source: Microsoft-Windows-Kernel-General
{Registry Hive Recovered} Registry hive (file): '\??\Volume{296410ee-ccba-11db-94af-806d6172696f}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C3573B5C-A250-44C4-AB19-755152EC30AA}' was corrupted and it has been recovered. Some data might have been lost.

Log: 'System' Date/Time: 30/01/2011 4:58:15 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 30/01/2011 4:53:40 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 4:50:39 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The Windows Image Acquisition (WIA) service hung on starting.

Log: 'System' Date/Time: 30/01/2011 4:47:19 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 4:28:12 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 4:20:14 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 4:04:46 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

Log: 'System' Date/Time: 30/01/2011 3:48:26 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 30/01/2011 3:48:22 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 3:40:24 PM
Type: Error Category: 0
Event: 7043 Source: Service Control Manager
The Windows Update service did not shut down properly after receiving a preshutdown control.

Log: 'System' Date/Time: 30/01/2011 3:40:20 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.

Log: 'System' Date/Time: 30/01/2011 3:35:17 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The KodakDigitalDisplayService service hung on starting.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 06/02/2011 3:38:59 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 06/02/2011 3:30:13 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 6:29:17 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 6:20:01 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 6:13:49 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 6:12:13 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 05/02/2011 6:11:19 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 05/02/2011 6:07:56 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 5:32:25 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 05/02/2011 5:12:26 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 04/02/2011 3:09:59 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 04/02/2011 3:07:26 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 04/02/2011 3:02:05 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 04/02/2011 2:51:46 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 03/02/2011 3:00:13 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 01/02/2011 3:49:22 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 31/01/2011 2:24:03 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:56:23 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:48:37 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:38:07 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:27:09 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 4:21:23 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:17:38 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 4:15:54 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 4:02:56 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 4:01:09 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 3:49:50 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 3:47:22 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 3:46:10 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 3:41:55 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.

Log: 'System' Date/Time: 30/01/2011 3:40:47 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 3:38:08 PM
Type: Warning Category: 0
Event: 4 Source: bcm4sbxp
Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.

Log: 'System' Date/Time: 30/01/2011 3:33:30 PM
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


My System SpecsSystem Spec
.
07 Feb 2011   #12
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

Quote   Quote: Originally Posted by Joules View Post
I used the microsoft fix to fix it, but is this going to fix this problem i have or another one?

I will not know till i shut it down and restart and that doesn't mean this will fix it because it is intermediate as i have stated.
I am going to reboot now
robin
My System SpecsSystem Spec
07 Feb 2011   #13
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

ok that did NOT work
rebooted and tried to open Devices and Printers
again not there
but here is a thought if it helps
when you told me to download vew- i copied and pasted your directions and printed them out since i did have Devices and Printers showing. When i did the fixit and rebooted I did not have it showing. I rebooted again and now it shows.

I thought it might be something to do with the printer after i print, so i unplugged the usb cable a few days ago from the computer so the printer would not be connected. and after a reboot for the first time i was able to see Devices and Printers. But after a cold start the next day I got the same darn problem and now the printer was not attached.

I have 3 printers that i am using networked from 2 xp pro machines in device and printers. I never had problems with them before.

As said the only new thing i put on was this monitor but i cannot believe the monitor would cause this?

I think tomorrow i will remove the monitor and put the old one back and see what happens because i am running out of what to do unless you guys can figure this out.
robin
My System SpecsSystem Spec
.

07 Feb 2011   #14
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

Quote   Quote: Originally Posted by Joules View Post
From the top of the log file it looks like you also need to install windows installer from here:

Download details: Windows Installer 4.5 Redistributable

Stemming from this in the beginning of the log:

Log: 'Application' Date/Time: 06/02/2011 3:43:57 PM
Type: Error Category: 0
Event: 1013 Source: MsiInstaller
Product: D-Link DFE-530TX+ -- 1: The InstallScript engine is missing from this machine. If available, please run ISScript.msi, or contact your support personnel for further assistance.


Hopefully after those two things you should be on the road to recovery, I would also run an elevated command prompt and run the sfv /scannow command to make sure all your system files are intact....Hope this all helps...
no that was a legitimate mistake by me. I tried to run the driver msi but it would not load, then i found out that that I double clicked the wrong file and it would not work on here and windows 7 would find its own driver which it did. This was after i installed the d link card and way after all the problems i was having. I installed the new card to see if the card on the motherboard was causing this problem in the first place

robin
My System SpecsSystem Spec
07 Feb 2011   #15
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

i opened a command prompt using admin privileges and typed in sfv /scannnow and it tells me sfv is an unknown command

so how do i do this?

robin
My System SpecsSystem Spec
07 Feb 2011   #16
Jacee
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Are you running Avast and MSE together on that machine?
My System SpecsSystem Spec
07 Feb 2011   #17
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

[QUOTE=Joules;1228596]
Quote   Quote: Originally Posted by robinb View Post
i opened a command prompt using admin privileges and typed in sfv /scannnow and it tells me sfv is an unknown command

so how do i do this?

robin

sfc /scannow

my bad

It seems that time stamps are off and everything is the system time on track...as well....

It also says Broadcom 440x 10/100 Integrated Controller: The network link is down. Check to make sure the network cable is properly connected.[/QUOTE

does it say that prior to me disabling the broadcom intergrated controller or after? because, first when i hooked up the de link I forgot to disable it in the bios and saw both in device manager. Once i realized this i disabled the intergrated controller in the bios then rebooted the computer and now it only showed one card. So maybe what you saw was my little boo boo?
robin
My System SpecsSystem Spec
07 Feb 2011   #18
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

Quote   Quote: Originally Posted by Jacee View Post
Are you running Avast and MSE together on that machine?
Of course not! I know you are only suppose to run one antivirus program . Only MSE is on this computer. Avast used to be on it but i used the avast uninstaller to remove it and all traces of avast were gone prior to putting MSE on.
robin
My System SpecsSystem Spec
07 Feb 2011   #19
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

i am running the sfc command now
and i will see what happens when it is done. I will let you know
robin
My System SpecsSystem Spec
07 Feb 2011   #20
robinb9

Windows 7 Pro 32/64 bit and Windows 10 Pro 32 Bit/64bit
 
 

Quote   Quote: Originally Posted by robinb View Post
i am running the sfc command now
and i will see what happens when it is done. I will let you know
robin
here are the results
now what?

Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.

C:\Windows\system32>sfc /scannow

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.

Windows Resource Protection did not find any integrity violations.

C:\Windows\system32>
My System SpecsSystem Spec
Reply

 wierdest problem with network driver




Thread Tools




Similar help and support threads
Thread Forum
Problem with network adapter driver.
Hello everyone, okay? I'm new here on the forum, so I'll introduce you. I'm 14, I live in Belo Horizonte, play dota for some time, and also quite like computing the influence of my brother who is technical. Anyway, my problem is the following: I formatted the computer a client of mine...
Drivers
Network Controller Driver Problem
Hi In device manager under other devices my network controller needs a driver but I can't find the correct one. Under the properties/hardware id I get: PCI\VEN_1814&DEV_0301&SUBSYS_25211814 I have done a google search and then it becomes complicated. PCI\VEN_1814&DEV_0301 hardware ID drivers,...
Drivers
Network Driver Problem on Startup
I have a Realtek network card on my HP desktop running Windows 7 and every time I start up the computer or restart it, the driver doesn't work for the network card. I have to go into device manager and disable the driver and then enable it and then it starts working. How can I fix this?
Drivers
Network card driver problem?
Hello! I have a very wierd problem. When I start the computer, everything goes fine until the OS starts loading network connection. I get the "device plug in sound" and then everything freezes completely. I have to wait about ten seconds and after "device unplugged sound" the computer works, but...
Drivers
wierdest Win7 x64 install problem
Hi all, I am having the wierdest problem installing win7 x64 now. System specs are in my profile. First of all, I bought and installed win7 yesterday without a problem. Then, after installing numerous drivers and using it for ~2 hours it just wouldn't boot anymore, not even safe mode. It went...
Installation & Setup
Network Driver Problem
So i installed Windows 7 RTM 7600 x86, and when i installed Windows the network was already working without having to install any drivers. The problem is that some websites hang and dont load, and when i switch on the computer the network icon on the taskbar says no internet access until i open...
Drivers


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 05:34.
Twitter Facebook Google+ Seven Forums iOS App Seven Forums Android App