Solved need someone to look up some system info on your PC

JimLewandowski

New member
Guru
Local time
6:43 AM
Messages
450
Location
Raleigh, NC
I mucked with my Circular Kernel Context Logger to get some trace data and now it won't start when Win 7 boots. I reset what I recall changing, but I do remember changing some security as the output .etl dataset couldn't be read or takeown'ed by me. However, if I manually start it (right-click START) it does start successfully. Maybe I'm admin (owner of CKCL) and I can thus start it, but the SYSTEM (security/SID) can't??


Control Panel > Administrative Tools > Performance Monitor.

Expand - Data Collector Reports.

Left-click on - Start Event Trace Sessions.

Left-Click once - Circular Kernel Context Logger to highlight it. Then right-click to get context menu, and then click on Properties.

Applet open

Now, click on - Security tile OR Security tab at the top. Then click on Advanced tile.

On this applet, click the Owner tab. What does it list for current owner?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Hello Jim,

Here's what I have as the owner. Hope it helps. :)

The SYSTEM group as all permission options checked but the first one below for me.

owner.jpg
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Administrators is listed as Owner....
 

My Computer My Computer

At a glance

Win7 Home Premium x64 W10Pro&HomeA12 9720p 4+8 TurionII M5206GB 8GBR7
Computer type
Laptop
Computer Manufacturer/Model Number
HP 17-ak0xx, dv7 3173nr
OS
Win7 Home Premium x64 W10Pro&Home
CPU
A12 9720p 4+8 TurionII M520
Motherboard
HP 3839
Memory
6GB 8GB
Graphics Card(s)
R7
Monitor(s) Displays
24" sa550
Screen Resolution
1600x900 1920x1080
Mouse
Logitechx2
Internet Speed
120Mb/s down 12up
Aha.

Yours has DPS (Diagnostic Policy Service) and WdiServiceHost. Maybe because your Win7 Ultimate?

All security for all my Event Traces are listed are pretty much the same (all checked BUT the first box).

Mine has (but most others look this way):

SYSTEM
LOCAL SERVICE
NETWORK SERVICE
Admin (Jim/GLH)
Network Configuration Operators (Jim/GLH)

Maybe I need to add DPS since it might be the service that starts this. I checked other running (via boot, not of my control) traces and see DPS on one.

But, I'm 100% sure I didn't do anything with security other than add a checkmark to Admin (in an attempt to get access to the CKCL.etl file in my local non-OS directory - this DID work).

I'm stumped. I knew modifying it and trying to set it back would neuter it. But, again, I can start it manually and no problems at all. It is set to enabled.....
 
Last edited:

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Would someone be kind enough to STOP the CKCL via the EVENT TRACE SESSIONS branch (it will say RUNNING next to it). Left-click to highlight, right-click to select STOP.

CLOSE the performance monitor window and come all the way back in again (idiosynchracy of perfmon GUI - clicking ACTION > REFRESH won't work for a few minutes).

Go to the original Event Trace Session branch (the ones listed as RUNNING) again and verify that CKCL is physically gone from the list.

If so, go to Startup Event Trace Session branch (the ones listed as enabled/disabled), right-click CKCL and select Properties. What do you have in the lower pane by Keywords(Any) (1st row). My value setting is 0x2005. I now recall, I think this needs to be 0x0000 and I bet whoever starts this adds those keywords in the fly by the equivalent of the logman command.

And it might explain my event ID error for a trace session named "" with 0xC000000D (D/13 is supposed to be invalid parameters).

Afterwards, right-clicking and selecting START should fire it up again. But the keyword thing is peculiar as if yours IS 0x0000, restarting it may simply have a CKCL running by not collecting anything (i.e. parms are provided via LOGMAN command internally in Win7).
 

Attachments

  • ckclprop.jpg
    ckclprop.jpg
    29.2 KB · Views: 19

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
It would think that you should also have DPS and WdiServiceHost listed in addition like mine above.
DPS.jpg
WdiServiceHost.jpg
Inline :)


Go to the original Event Trace Session branch (the ones listed as RUNNING) again and verify that CKCL is physically gone from the list.
Yep, gone afterwards.
If so, go to Startup Event Trace Session branch (the ones listed as enabled/disabled), right-click CKCL and select Properties. What do you have in the lower pane by Keywords(Any) (1st row). My value setting is 0x2005. I now recall, I think this needs to be 0x0000 and I bet whoever starts this adds those keywords in the fly by the equivalent of the logman command.

And it might explain my event ID error for a trace session named "" with 0xC000000D (D/13 is supposed to be invalid parameters).
I have 0x0 (Startup Event Trace Session) with the one in Event stopped as above.

keywords.jpg

Afterwards, right-clicking and selecting START should fire it up again. But the keyword thing is peculiar as if yours IS 0x0000, restarting it may simply have a CKCL running by not collecting anything (i.e. parms are provided via LOGMAN command internally in Win7).
Fired back up.
 
Last edited:

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
I definitely did not delete anything and now thinking back, I would have recognized those "never before seen by me" SIDs/users.

I think the 0x2005 is what's upsetting the restart.

logman is a very, very bizarre interface. If you start CKCL from the command line, it seems to do buffered trace PLUS write to a file even though CKCL is buffered only. And the kicker is the file it writes to is in whatever directory you were in when you issued logman. As I mentioned, with standard security settings, I couldn't read the CKCL.etl file via tracerpt.

I struggled with understanding all this as so much is inconsistent. For example, if you start CKCL with no parms via logman, it will start but will not trace anything honoring the 0x0 keyword setting. But, even if you have those bits set, logman will start CKCL with 0x0 but the right-click GUI start WILL honor the keywords.

Set to 0x00 and will see on next reboot. Thanks.
 
Last edited:

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
No go. Still won't start at bootup/logon. Weird.
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Anyone have any ideas on how to get this trace working?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Jim,

Do you have a restore point available dated before you made changes to the CKCL that you could use?
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Yes, I checked and have at least 2 weeks worth. Interestingly, ALL my restore points related to any system image I've ever taken (going back to 2/28/10 original install date) are available still.

It's just so puzzling. The only thing I can think is that I swore when I originally went to the owner screen, it said "unable to show owner" or something mysterious. But, I was looking at all kinds of traces on that screen.....

It works if I right-click and start it manually. Something can be learned from this and I'm a bit stubborn at the moment.

Even moreso, when you just logoff vs. shutting down, would these traces stay alive?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
I'm afraid that I don't know if they do or not. :(
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
I would also think that system restore only deals with .exe and .dll modules? IOW, if this trace info is in some file somewhere, I doubt System Restore would have an earlier copy of it. And I highly doubt those trace entries are in the registry anywhere...

Just found this. Will check when I get home:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Circular Kernel Context Logger

Well, I'll be.

http://msdn.microsoft.com/en-us/library/windows/desktop/aa363687(v=vs.85).aspx

If anyone would like to export the registry for the above CKCL key and attach in a .txt file......

Brink, if you're game and not averse to chewing up some disk space on the SevenForums server, could you screen shot each panel (Trace session, Stop condition, File, Directory, et. al.) on the right-click > Properties for CKCL? You can skip the security panel as I've gone over that thoroughly.

I recall mucking with the buffering. I think maybe I have the max set to 1 (greyed out option, though) and the min value is 4.

If you're extra energetic, the registry export of that key will possibly help, too.
 
Last edited:

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Here you go Jim. I hope it helps.

In stopped state (Event Trace Sessions):
CKCL-Properties_Stopped.jpg
Default REG export while in running state:
 

Attachments

Last edited:

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Thanks a ton.

This conflicts with an earlier post of your screenshot of CKCL. In that prior screenshot, your keywords(any) had 0x00. I asked for the CKCL primary screen shot from the STARTUP (not running) branch. To verify, was that earlier post's screenshot of the running CKCL or was it in the STARTUP event trace session?

I hope it's my maximum buffer (I think it's greyed out and still set to 1) but I definitely reset the buffering to 4K size (had it larger) and with minimum buffers set to 2.

I will get this damn thing to work again. The Status registry value is the status of the last start command for that. If I see an 0x0D in mine, then I know it's definitely my parameters.
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
The screenshot here was in Startup Event Trace Sessions with the CKCL already stopped and gone in Event Trace Sessions. I also verified this on the laptop, and it had 0x0 as well.
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
OK. Thanks for the clarification.

I'm somewhat surprised there isn't an export/import feature for these traces like there is for Task Scheduler events.

I hope my reg has something funky in it that's easily fixable via regedit or the GUI panels (same thing to some degree).
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
It would be nice if it did. I would just export mine for you.
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
OK. My maximum buffers option was greyed out and set to 0. Obviously illegal settings as minimum buffers is 2. I had a different LogFileMode. I also have ClockType and FlushTimer in my reg entry which I deleted.

Changed everything to match yours. However, when I access the GUI, my "enabled" option is checked whereby yours is greyed out.

I manually edited logfilemode and maximum buffers. Then the gui now has the max buffer no longer greyed out.

Rebooted and still no go. It was alive early in the boot by my status in the registry entry is 0x57 (87 decimal) which is invalid parameter.

However, each time I access the gui, those 2 add'l reg entries get put back in.

**************************

Master Brink, need one more favor.

Can you export:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security

There's a long string for the CKCL GUID.
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Here you go. :)
 

Attachments

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Back
Top