Event Viewer

Page 3 of 5 FirstFirst 12345 LastLast

  1. Posts : 582
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #21

    Checked services & DCOM is 'started'. BUT, it just dawned on me a bit ago that all those DCOM errors showed up during the time that I did the msconfig & was running IE (no add-ons) that day, any connection? I did a re-boot just before posting this so will keep an eye on it.

    Will post this much then try Jacee's link.
      My Computer


  2. Posts : 582
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #22

    VEW log

    Vino's Event Viewer v01c run on Windows 2008 in English
    Report run at 28/05/2012 11:10:19 AM
    Note: All dates below are in the format dd/mm/yyyy
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 28/05/2012 4:35:42 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 27/05/2012 2:23:53 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 27/05/2012 1:28:02 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: IEXPLORE.EXE, version: 9.0.8112.16421, time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x072c00db Faulting process id: 0xddc Faulting application start time: 0x01cd3c0c57679260 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: unknown Report Id: c821f040-a7ff-11e1-8a61-f80f413bc60f
    Log: 'Application' Date/Time: 27/05/2012 1:26:16 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: IEXPLORE.EXE, version: 9.0.8112.16421, time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x00fa00db Faulting process id: 0xf20 Faulting application start time: 0x01cd3c030a4ecfb0 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: unknown Report Id: 89202d80-a7ff-11e1-8a61-f80f413bc60f
    Log: 'Application' Date/Time: 27/05/2012 12:19:03 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: IEXPLORE.EXE, version: 9.0.8112.16421, time stamp: 0x4d76255d Faulting module name: agcore.dll, version: 4.0.50401.0, time stamp: 0x4bb42f15 Exception code: 0xc0000005 Fault offset: 0x00322006 Faulting process id: 0x998 Faulting application start time: 0x01cd3c005dfa26d0 Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\agcore.dll Report Id: 24e8fda0-a7f6-11e1-8a61-f80f413bc60f
    Log: 'Application' Date/Time: 25/05/2012 3:40:38 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 25/05/2012 10:30:59 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 23/05/2012 10:49:12 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 22/05/2012 9:11:05 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 22/05/2012 8:35:58 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 21/05/2012 10:59:54 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 19/05/2012 12:08:24 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 18/05/2012 12:52:25 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 17/05/2012 8:52:44 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 17/05/2012 8:31:23 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 16/05/2012 12:24:32 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 14/05/2012 11:43:27 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 13/05/2012 1:36:01 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 12/05/2012 8:56:48 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 12/05/2012 8:01:50 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 21/05/2012 10:57:21 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 2032 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 17/05/2012 8:50:21 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:

    Log: 'Application' Date/Time: 15/05/2012 11:30:35 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1148 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 13/05/2012 5:25:26 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:

    Log: 'Application' Date/Time: 12/05/2012 7:59:04 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1800 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 12/05/2012 6:07:17 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Windows\explorer.exe' (pid 2772) cannot be restarted - Application SID does not match Conductor SID..
    Log: 'Application' Date/Time: 12/05/2012 6:07:17 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Windows\explorer.exe' (pid 2772) cannot be restarted - Application SID does not match Conductor SID..
    Log: 'Application' Date/Time: 11/05/2012 11:03:18 PM
    Type: Warning Category: 1
    Event: 1008 Source: Microsoft-Windows-Search
    The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}.

    Log: 'Application' Date/Time: 06/05/2012 7:27:06 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 16 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 3820 (\Device\HarddiskVolume3\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1916 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 05/05/2012 11:50:40 AM
    Type: Warning Category: 1
    Event: 1008 Source: Microsoft-Windows-Search
    The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}.

    Log: 'Application' Date/Time: 02/05/2012 11:26:41 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 21 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Internet Explorer\Main
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 740 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1144 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 01/05/2012 11:01:07 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:

    Log: 'Application' Date/Time: 30/04/2012 11:55:44 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 988 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 26/04/2012 11:14:30 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 21 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Internet Explorer\Main
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 2096 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 22/04/2012 3:07:04 PM
    Type: Warning Category: 1
    Event: 1008 Source: Microsoft-Windows-Search
    The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}.

    Log: 'Application' Date/Time: 22/04/2012 12:32:32 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:

    Log: 'Application' Date/Time: 15/04/2012 12:02:27 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1636 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    Log: 'Application' Date/Time: 10/04/2012 12:39:43 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 3900 (\Device\HarddiskVolume3\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts

    Log: 'Application' Date/Time: 09/04/2012 11:23:49 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:

    Log: 'Application' Date/Time: 09/04/2012 3:40:03 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-338772744-2197311649-1972574446-1000:
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\trust
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\Root
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Policies\Microsoft\SystemCertificates
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\My
    Process 1828 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-338772744-2197311649-1972574446-1000\Software\Microsoft\SystemCertificates\CA

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 24/05/2012 9:54:03 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:52:53 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:52:02 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:45:08 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:44:45 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:43:42 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:43:10 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:41:52 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:41:37 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:37:22 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:32:52 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:24:26 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:24:10 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:23:34 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:23:18 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:23:00 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:21:10 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:20:43 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:20:32 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    Log: 'System' Date/Time: 24/05/2012 9:20:08 PM
    Type: Error Category: 0
    Event: 10016 Source: Microsoft-Windows-DistributedCOM
    The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Cherlyn-PC\Cherlyn SID (S-1-5-21-338772744-2197311649-1972574446-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 28/05/2012 4:33:52 PM
    Type: Warning Category: 0
    Event: 20 Source: i8042prt
    Could not set the keyboard indicator lights.
    Log: 'System' Date/Time: 28/05/2012 4:33:52 PM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 28/05/2012 2:33:35 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name live-6a78194f7cca49a99ddf380a61b32051.log.msecndsl.net timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 28/05/2012 1:36:42 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name live-9a8b978e32df4b25a66b49b6b54af61c.log.msecndsl.net timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 27/05/2012 4:38:58 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name idpix.media6degrees.com timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 26/05/2012 11:04:13 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name idpix.media6degrees.com timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 26/05/2012 12:16:05 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name www.avast.com timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 25/05/2012 9:16:38 PM
    Type: Warning Category: 0
    Event: 20 Source: i8042prt
    Could not set the keyboard indicator lights.
    Log: 'System' Date/Time: 25/05/2012 9:16:38 PM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 25/05/2012 9:16:38 PM
    Type: Warning Category: 0
    Event: 17 Source: i8042prt
    The device sent an incorrect response(s) following a keyboard reset.
    Log: 'System' Date/Time: 25/05/2012 3:38:48 PM
    Type: Warning Category: 0
    Event: 20 Source: i8042prt
    Could not set the keyboard indicator lights.
    Log: 'System' Date/Time: 25/05/2012 3:38:48 PM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 24/05/2012 5:04:02 PM
    Type: Warning Category: 0
    Event: 20 Source: i8042prt
    Could not set the keyboard indicator lights.
    Log: 'System' Date/Time: 24/05/2012 5:04:02 PM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 24/05/2012 5:04:02 PM
    Type: Warning Category: 0
    Event: 17 Source: i8042prt
    The device sent an incorrect response(s) following a keyboard reset.
    Log: 'System' Date/Time: 23/05/2012 10:50:24 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name www.avast.com timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 23/05/2012 10:47:21 AM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 22/05/2012 8:34:10 PM
    Type: Warning Category: 0
    Event: 20 Source: i8042prt
    Could not set the keyboard indicator lights.
    Log: 'System' Date/Time: 22/05/2012 8:34:10 PM
    Type: Warning Category: 0
    Event: 19 Source: i8042prt
    Could not set the keyboard typematic rate and delay.
    Log: 'System' Date/Time: 22/05/2012 8:20:33 PM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name download808.avast.com timed out after none of the configured DNS servers responded.
      My Computer


  3. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #23

    Thanks Hammer,

    This WMI msg has bugged for a while - Vista SP? had it too. Since it was related to logging I previously ignored it. I'm running the Mr. Fixit for Windows 7 referenced in the 1st post you linked - I'll post again after I clear the log and boot. It's a Fixit so I expect it to work.

    Fix this problem
    Microsoft Fix it 50688

    HammerHead said:
    Access the services panel by Start menu ---> Type in search box "services.msc" click the small icon which looks like a gear.

    I have found a thread on this forum which is almost identical. Check it out.

    WMI Event ID 10 "//./root/CIMV2

    Here is more info.

    Event ID 10 error every boot
      My Computer


  4. Posts : 582
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #24

    Slartybart said:
    Thanks Hammer,

    This WMI msg has bugged for a while - Vista SP? had it too. Since it was related to logging I previously ignored it. I'm running the Mr. Fixit for Windows 7 referenced in the 1st post you linked - I'll post again after I clear the log and boot. It's a Fixit so I expect it to work.



    Microsoft Fix it 50688


    HammerHead said:
    Access the services panel by Start menu ---> Type in search box "services.msc" click the small icon which looks like a gear.

    I have found a thread on this forum which is almost identical. Check it out.

    WMI Event ID 10 "//./root/CIMV2

    Here is more info.

    Event ID 10 error every boot
    I must be blind. I'd just read Hammer's links before I posted my #21 & either didn't see or register the Fixit part. Anxious for your reply.
      My Computer


  5. Posts : 1,965
    win 7 X64 Ultimate SP1
       #25

    In A Fog


    I have lost where we are at.

    Are you running Mr Fixit? Or where are we at?

    You might clear the event logs so we have current info.
    Last edited by HammerHead; 28 May 2012 at 13:07. Reason: afterthought
      My Computer


  6. Posts : 582
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #26

    HammerHead said:
    I have lost where we are at.

    Are you running Mr Fixit? Or where are we at?

    You might clear the event logs so we have current info.


    I'm in fog too (new med). Finally cleared Events, re-booted, only one there was i8042prt - ID19.

    Slarty's the one gonna run Fixit, anxious for him to reply.
      My Computer


  7. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #27

    Also see this article "WMI error is logged in the application log after every reboot":
    Event ID 10 is logged in the Application log after you install Service Pack 1 for Windows 7 or Windows Server 2008 R2
      My Computer


  8. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #28

    Sounding the "All Clear" alert. Mr Fixit took care of the install hangover. In other words - it worked.
    Hangover
    Mr. Fixit 'cause' said:
    This originated in the Windows 7 SP1 DVD/ISO creation process. There was an issue in the creation process that caused a WMI registration to remain in the DVD/ISO. Since the registration is designed to work only during the DVD/ISO creation process, it fails to run on a live system and causes these events. These events are not indicative of any issue in the system and can be safely ignored. If however you want to prevent these events from getting generated and want to remove this specific WMI registration manually, please follow the steps mentioned in this article for running the workaround script.
    Although, I'm not buying the "originated in..." because I had the same log msgs back in Vista. Regardless, it does stop the msgs in the Events log.
      My Computer


  9. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #29

    What I said -lol!
    Slartybart said:
    Thanks Hammer,

    This WMI msg has bugged for a while - Vista SP? had it too. Since it was related to logging I previously ignored it. I'm running the Mr. Fixit for Windows 7 referenced in the 1st post you linked - I'll post again after I clear the log and boot. It's a Fixit so I expect it to work.
    Jacee said:
    Also see this article "WMI error is logged in the application log after every reboot":
    Event ID 10 is logged in the Application log after you install Service Pack 1 for Windows 7 or Windows Server 2008 R2
      My Computer


  10. Posts : 582
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #30

    Thanx Slarty, I was just about ready to send out the search party for you.
      My Computer


 
Page 3 of 5 FirstFirst 12345 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 12:20.
Find Us