kasparsky updating problem

Page 3 of 9 FirstFirst 12345 ... LastLast

  1. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #21

    Let's see if VEW can shed some light on this ... download VEW by Vino Rosso http://images.malwareremoval.com/vino/VEW.exe
    and save it to your desktop
    Double click it to start it Note: If running Windows Vista or Windows 7 you will need to right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.

    Click the check boxes next to Application and System located under Select log to query on the upper left

    Under Select type to list on the right click the boxes next to Error and Warning Note: If running Windows Vista or Windows 7 also click the box next to Critical (not XP).
    Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run

    Once it finishes it will display a log file in notepad
    Please copy and paste its entire contents into your next reply
      My Computer


  2. Posts : 2,470
    Windows 7 Home Premium
       #22

    frodi, ICit2lol, chris1neji, Jacee...

    There are quite a few reports of KIS hanging at x%, and not updating.

    Someone had success using KIS 2012, instead of 2013.

    The Kaspersky tool was used in Safe Mode to uninstall KIS 2013:
    How to uninstall Kaspersky Internet Security 2013

    KIS 2012 was then installed.

    Paying for a KIS 2013 that doesn't work, and using KIS 2012 is not exactly the best of conditions, but, if the end result is that the computer is protected, well...

    Mind you, this old dog is no expert at anything, and KIS, least of all.

    Just hoping something helps in this conundrum!
      My Computer


  3. Posts : 21,004
    Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
       #23

    cottonball said:
    frodi, ICit2lol, chris1neji, Jacee...

    There are quite a few reports of KIS hanging at x%, and not updating.

    Someone had success using KIS 2012, instead of 2013.

    The Kaspersky tool was used in Safe Mode to uninstall KIS 2013:
    How to uninstall Kaspersky Internet Security 2013

    KIS 2012 was then installed.

    Paying for a KIS 2013 that doesn't work, and using KIS 2012 is not exactly the best of conditions, but, if the end result is that the computer is protected, well...

    Mind you, this old dog is no expert at anything, and KIS, least of all.

    Just hoping something helps in this conundrum!
    Thanks cottonball that could be a solution and then try the 13 again if the 2012 hangs then something it very wrong it isn't (for me at elasat) a very long process.

    That ref you quote is a new one to me and in hindsight I should have pointed out too is that KIS is REGIONAL ie a machine I built for my brother in England and installed KIS on - the KIS would not work at all over there (updating) and he had to install a version for his region, and subsequent research found that one has to get the version for your particular region.
    Now the site I have given Frodi for downloads are the Australian regional ones. Now I know it is highly unlikely but maybe the disk or download site was from another region.
    The uninstall is usually via the All Programs list - that as I said retains the config in the main and or that ref I gave earlier Removal tool for Kaspersky Lab products (kavremover) it will uninstall all Kaspersky products not just the internet suite.

    Mind you I have to say Jacee is far more accomplished and knowledgeable than I shall ever be and that Frodi should stay on track with her advice.
    When this does get resolved though the download of the software as I said has to be from within this region and the main contact site in Melbourne.
      My Computer


  4. Posts : 2,470
    Windows 7 Home Premium
       #24

    ICit2lol,

    Thanks for pointing out the regional aspect of the downloads.
    To be honest, in searching for an answer, this ol' brain did not register where frodi is from.

    As far as malware goes, like chris1neji mentioned, the issue of not being able to connect to websites where security programs are found is normally not a good sign.

    Jacee mentioned KIS updating could be disabled by malware, and she is very well trained to dig malware out.

    However, as we all know, there are certain types that cleverly hide.

    Since frodi's system is basically unprotected, just brought up the KIS 2012 vs. 2013 as an option to explore, and like you mention,
    ...if the 2012 hangs then something is very wrong...
    However if 2012 works...
      My Computer


  5. Posts : 299
    Windows 7 Home Premium 64 bit
    Thread Starter
       #25

    By the way ICit2lol, I cannot even connect to the Australian site for Karspersky. As far as uninstalling goes, I managed to dl the uninstall tool for 2013 and when started was informed that it does not work on my OS. (Windows7 64 bit) Thank you and Cottonball for trying to help. I will stay with Jacee and see if he/she can find a solution.
      My Computer


  6. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #26

    Jacee said:
    Let's see if VEW can shed some light on this ... download VEW by Vino Rosso http://images.malwareremoval.com/vino/VEW.exe
    and save it to your desktop
    Double click it to start it Note: If running Windows Vista or Windows 7 you will need to right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.

    Click the check boxes next to Application and System located under Select log to query on the upper left

    Under Select type to list on the right click the boxes next to Error and Warning Note: If running Windows Vista or Windows 7 also click the box next to Critical (not XP).
    Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run.

    Once it finishes it will display a log file in notepad
    Please copy and paste its entire contents into your next reply
    Please run this tool :)
      My Computer


  7. Posts : 299
    Windows 7 Home Premium 64 bit
    Thread Starter
       #27

    Vino's Event Viewer v01c run on Windows 2008 in English
    Report run at 07/03/2013 9:59:16 AM
    Note: All dates below are in the format dd/mm/yyyy
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 06/03/2013 9:48:23 PM
    Type: Error Category: 0
    Event: 1008 Source: Microsoft-Windows-CEIP
    A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).
    Log: 'Application' Date/Time: 06/03/2013 9:31:12 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 06/03/2013 9:29:30 PM
    Type: Error Category: 100
    Event: 1000 Source: Application Error
    Faulting application name: Wacom_Tablet.exe, version: 6.3.4.3, time stamp: 0x508e9bfe Faulting module name: Wacom_Tablet.exe, version: 6.3.4.3, time stamp: 0x508e9bfe Exception code: 0xc0000005 Fault offset: 0x00000000003503be Faulting process id: 0x628 Faulting application start time: 0x01ce1ab1adbf0ef6 Faulting application path: C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe Faulting module path: C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe Report Id: ed64ca35-86a4-11e2-8d37-3085a99b3fb8
    Log: 'Application' Date/Time: 05/03/2013 8:53:41 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 10:45:33 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 10:40:24 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 9:52:15 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 9:50:37 PM
    Type: Error Category: 0
    Event: 8210 Source: System Restore
    An unspecified error occurred during System Restore: (Restore Operation). Additional information: 0xc0000022.
    Log: 'Application' Date/Time: 04/03/2013 9:46:25 PM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 9:34:51 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 9:33:12 AM
    Type: Error Category: 0
    Event: 8210 Source: System Restore
    An unspecified error occurred during System Restore: (Windows Backup). Additional information: 0xc0000022.
    Log: 'Application' Date/Time: 04/03/2013 9:26:20 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 9:24:41 AM
    Type: Error Category: 0
    Event: 8210 Source: System Restore
    An unspecified error occurred during System Restore: (Windows Backup). Additional information: 0xc0000022.
    Log: 'Application' Date/Time: 04/03/2013 9:07:30 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 8:13:37 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 8:05:30 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 8:02:30 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 7:50:56 AM
    Type: Error Category: 0
      My Computer


  8. Posts : 299
    Windows 7 Home Premium 64 bit
    Thread Starter
       #28

    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 5:43:41 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    Log: 'Application' Date/Time: 04/03/2013 5:11:31 AM
    Type: Error Category: 0
    Event: 10 Source: Microsoft-Windows-WMI
    Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 05/03/2013 7:25:24 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 04/03/2013 9:48:43 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 3 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1812 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1812 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1812 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root

    Log: 'Application' Date/Time: 04/03/2013 9:31:18 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root

    Log: 'Application' Date/Time: 04/03/2013 8:19:19 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1972 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 04/03/2013 8:10:09 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1964 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates

    Log: 'Application' Date/Time: 04/03/2013 8:02:31 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 04/03/2013 7:59:58 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1984 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1984 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1984 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1984 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1984 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates

    Log: 'Application' Date/Time: 04/03/2013 7:57:08 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1952 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root

    Log: 'Application' Date/Time: 04/03/2013 5:43:58 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1001:
    Process 2952 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1001

    Log: 'Application' Date/Time: 04/03/2013 5:40:37 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
      My Computer


  9. Posts : 299
    Windows 7 Home Premium 64 bit
    Thread Starter
       #29

    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1648 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 03/03/2013 6:42:34 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:

    Log: 'Application' Date/Time: 02/03/2013 9:27:31 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:

    Log: 'Application' Date/Time: 28/02/2013 9:12:43 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1988 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 28/02/2013 3:46:31 AM
    Type: Warning Category: 0
    Event: 1001 Source: MsiInstaller
    Detection of product '{91CABF8F-A81C-4CB0-A1B0-D55B25F1B150}', feature 'PainterApp' failed during request for component '{82AB0B03-0C6C-4EE3-A9C6-C2486B65E1AF}'
    Log: 'Application' Date/Time: 27/02/2013 10:18:18 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 0 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:

    Log: 'Application' Date/Time: 27/02/2013 5:39:30 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\TrustedPeople

    Log: 'Application' Date/Time: 27/02/2013 4:00:40 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 12 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\trust
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\My
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\CA
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Disallowed
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Policies\Microsoft\SystemCertificates

    Log: 'Application' Date/Time: 27/02/2013 1:52:33 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 1960 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\SystemCertificates\Root

    Log: 'Application' Date/Time: 27/02/2013 1:38:06 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004_Classes:
    Process 6928 (\Device\HarddiskVolume2\Windows\System32\wisptis.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004_CLASSES

    Log: 'Application' Date/Time: 27/02/2013 1:38:06 AM
    Type: Warning Category: 0
      My Computer


  10. Posts : 299
    Windows 7 Home Premium 64 bit
    Thread Starter
       #30

    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 2 user registry handles leaked from \Registry\User\S-1-5-21-2313290121-3553204520-4293039260-1004:
    Process 6928 (\Device\HarddiskVolume2\Windows\System32\wisptis.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004
    Process 6928 (\Device\HarddiskVolume2\Windows\System32\wisptis.exe) has opened key \REGISTRY\USER\S-1-5-21-2313290121-3553204520-4293039260-1004\Software\Microsoft\Direct3D

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 02/03/2013 8:57:24 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    Log: 'System' Date/Time: 06/01/2013 10:55:29 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    Log: 'System' Date/Time: 04/01/2013 11:12:58 PM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    Log: 'System' Date/Time: 04/01/2013 1:56:52 AM
    Type: Critical Category: 63
    Event: 41 Source: Microsoft-Windows-Kernel-Power
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 05/03/2013 6:44:52 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 6:34:07 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 6:02:36 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 5:38:37 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 5:27:52 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 4:22:06 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 4:11:24 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 4:00:36 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 05/03/2013 3:49:52 AM
    Type: Error Category: 0
    Event: 11 Source: Disk
    The driver detected a controller error on \Device\Harddisk2\DR2.
    Log: 'System' Date/Time: 04/03/2013 10:42:18 PM
    Type: Error Category: 0
    Event: 7034 Source: Service Control Manager
    The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
    Log: 'System' Date/Time: 04/03/2013 9:42:07 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243).
    Log: 'System' Date/Time: 04/03/2013 9:41:30 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x8024002d: Microsoft Office File Validation Add-in.
    Log: 'System' Date/Time: 04/03/2013 9:40:21 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243).
    Log: 'System' Date/Time: 04/03/2013 9:39:40 AM
    Type: Error Category: 1
    Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
    Installation Failure: Windows failed to install the following update with error 0x8024002d: Microsoft Office File Validation Add-in.
    Log: 'System' Date/Time: 04/03/2013 5:30:29 AM
    Type: Error Category: 0
    Event: 7030 Source: Service Control Manager
    The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    Log: 'System' Date/Time: 04/03/2013 5:26:34 AM
    Type: Error Category: 0
    Event: 1060 Source: Application Popup
    \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
    Log: 'System' Date/Time: 04/03/2013 5:19:24 AM
    Type: Error Category: 0
    Event: 7030 Source: Service Control Manager
    The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    Log: 'System' Date/Time: 04/03/2013 5:17:33 AM
    Type: Error Category: 0
    Event: 7031 Source: Service Control Manager
    The Kaspersky Anti-Virus Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
    Log: 'System' Date/Time: 04/03/2013 5:04:57 AM
    Type: Error Category: 0
    Event: 7034 Source: Service Control Manager
    The Kaspersky Anti-Virus Service service terminated unexpectedly. It has done this 3 time(s).
    Log: 'System' Date/Time: 04/03/2013 5:03:00 AM
    Type: Error Category: 0
    Event: 7030 Source: Service Control Manager
    The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 05/03/2013 9:14:36 AM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name plusone.google.com timed out after none of the configured DNS servers responded.
    Log: 'System' Date/Time: 05/03/2013 6:55:07 AM
    Type: Warning Category: 0
    Event: 27 Source: e1cexpress
    Intel(R) 82579V Gigabit Network Connection Network link is disconnected.
      My Computer


 
Page 3 of 9 FirstFirst 12345 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:51.
Find Us