Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 21/04/2011 11:27:30 AM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 21/04/2011 3:38:58 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x434 Faulting application start time: 0x01cc003510aceb9c Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 7881cf9b-6c2d-11e0-9981-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 2:45:56 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x360 Faulting application start time: 0x01cc00311754101c Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 0fed6164-6c26-11e0-952a-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:59:12 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x41c Faulting application start time: 0x01cc00222cd2e5b2 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 26b57e63-6c17-11e0-b013-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 3:12:33 AM
Type: Error Category: 0
Event: 5051 Source: McLogEvent
A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 4084 (0xff4) Thread address : 0x77CF70B4 Thread message : Build VSCORE.14.2.0.794 / 5400.1158 Object being scanned = \Device\HarddiskVolume1\Program Files\McAfee\MSC\mcupdmgr.exe by C:\Windows\system32\svchost.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
Log: 'Application' Date/Time: 21/04/2011 2:53:06 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x1154 Faulting application start time: 0x01cbffc998fb9022 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 7b51d24a-6bc2-11e0-a150-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 2:12:35 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x424 Faulting application start time: 0x01cbffc7f3944e91 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: d242c441-6bbc-11e0-a150-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 1:57:49 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program firefox.exe version 2.0.0.4094 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 3754 Start Time: 01cbffc63cd2415a Termination Time: 78 Application Path: C:\Program Files\Mozilla Firefox\firefox.exe Report Id: bc0ab52f-6bba-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 1:57:44 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: firefox.exe, version: 2.0.0.4094, time stamp: 0x4d8374f3 Faulting module name: IMM32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b845 Exception code: 0xc0000005 Fault offset: 0x000013b2 Faulting process id: 0x35b0 Faulting application start time: 0x01cbffc78138f0c2 Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Windows\system32\IMM32.dll Report Id: bf151728-6bba-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:48:57 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program firefox.exe version 2.0.0.4094 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2b7c Start Time: 01cbffbdd8c6587b Termination Time: 73 Application Path: C:\Program Files\Mozilla Firefox\firefox.exe Report Id: 20cab6e1-6bb1-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:48:56 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: firefox.exe, version: 2.0.0.4094, time stamp: 0x4d8374f3 Faulting module name: IMM32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b845 Exception code: 0xc0000005 Fault offset: 0x000013b2 Faulting process id: 0x2e28 Faulting application start time: 0x01cbffbde5035e31 Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Windows\system32\IMM32.dll Report Id: 22d95346-6bb1-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:48:26 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program firefox.exe version 2.0.0.4094 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2658 Start Time: 01cbffbdb1f909cc Termination Time: 46 Application Path: C:\Program Files\Mozilla Firefox\firefox.exe Report Id: 0ded5ca4-6bb1-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:48:25 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: firefox.exe, version: 2.0.0.4094, time stamp: 0x4d8374f3 Faulting module name: IMM32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b845 Exception code: 0xc0000005 Fault offset: 0x000013b2 Faulting process id: 0x2e64 Faulting application start time: 0x01cbffbdd26ea6c5 Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe Faulting module path: C:\Windows\system32\IMM32.dll Report Id: 1031d6e3-6bb1-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 21/04/2011 12:47:29 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program firefox.exe version 2.0.0.4094 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 4bc Start Time: 01cbffbd83d53778 Termination Time: 99 Application Path: C:\Program Files\Mozilla Firefox\firefox.exe Report Id: e914538b-6bb0-11e0-887d-001bfc31f1ba
Log: 'Application' Date/Time: 20/04/2011 9:34:59 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x1774 Faulting application start time: 0x01cbff9c68a86453 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 0a7ac389-6b96-11e0-a4ec-001bfc31f1ba
Log: 'Application' Date/Time: 20/04/2011 8:49:10 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x428 Faulting application start time: 0x01cbff9ae9dfa183 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: a3b17514-6b8f-11e0-a4ec-001bfc31f1ba
Log: 'Application' Date/Time: 20/04/2011 8:16:30 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x11e0 Faulting application start time: 0x01cbff914371c8f1 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 136f1a76-6b8b-11e0-a201-001bfc31f1ba
Log: 'Application' Date/Time: 20/04/2011 7:31:29 PM
Type: Error Category: 0
Event: 33 Source: SideBySide
Activation context generation failed for "c:\VueScan\dpinst64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.
Log: 'Application' Date/Time: 20/04/2011 7:30:14 PM
Type: Error Category: 0
Event: 63 Source: SideBySide
Activation context generation failed for "c:\program files\mozbackup\dll\DelZip179.dll".Error in manifest or policy file "c:\program files\mozbackup\dll\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid.
Log: 'Application' Date/Time: 20/04/2011 7:29:11 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x424 Faulting application start time: 0x01cbff8913cf2760 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 7734d8ed-6b84-11e0-a201-001bfc31f1ba
Log: 'Application' Date/Time: 20/04/2011 12:24:56 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc100 Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96e Exception code: 0xc0000005 Fault offset: 0x00068aca Faulting process id: 0x14b4 Faulting application start time: 0x01cbff53e50ca047 Faulting application path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 32dc4681-6b49-11e0-b599-001bfc31f1ba
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 21/04/2011 3:00:53 PM
Type: Warning Category: 0
Event: 6001 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <Profiles> failed a notification event.
Log: 'Application' Date/Time: 21/04/2011 3:00:53 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <Profiles> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 21/04/2011 3:00:53 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 21/04/2011 3:00:52 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 21/04/2011 2:33:38 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 21/04/2011 12:44:37 PM
Type: Warning Category: 0
Event: 6001 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> failed a notification event.
Log: 'Application' Date/Time: 21/04/2011 12:44:37 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 19/04/2011 12:58:17 PM
Type: Warning Category: 0
Event: 6001 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> failed a notification event.
Log: 'Application' Date/Time: 19/04/2011 12:58:16 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 18/04/2011 3:17:17 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <Profiles> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 18/04/2011 3:17:17 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 18/04/2011 3:17:16 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 18/04/2011 3:05:23 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 18/04/2011 3:05:23 PM
Type: Warning Category: 0
Event: 6003 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <Profiles> was unavailable to handle a critical notification event.
Log: 'Application' Date/Time: 18/04/2011 12:30:37 PM
Type: Warning Category: 0
Event: 6001 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> failed a notification event.
Log: 'Application' Date/Time: 18/04/2011 12:30:37 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Log: 'Application' Date/Time: 14/04/2011 5:00:38 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-3976758132-2769972021-118469255-1001:
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\trust
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Root
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\My
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2164 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\CA
Log: 'Application' Date/Time: 14/04/2011 3:36:03 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-3976758132-2769972021-118469255-1001:
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\trust
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Root
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\My
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2280 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\CA
Log: 'Application' Date/Time: 14/04/2011 4:30:08 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 12 user registry handles leaked from \Registry\User\S-1-5-21-3976758132-2769972021-118469255-1001:
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\trust
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Policies\Microsoft\SystemCertificates
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Root
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\My
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2032 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3976758132-2769972021-118469255-1001\Software\Microsoft\SystemCertificates\CA
Log: 'Application' Date/Time: 14/04/2011 3:09:54 AM
Type: Warning Category: 0
Event: 10010 Source: Microsoft-Windows-RestartManager
Application 'C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe' (pid 2680) cannot be restarted - Application SID does not match Conductor SID..
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 21/04/2011 3:01:45 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 21/04/2011 2:33:22 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 21/04/2011 12:46:15 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 21/04/2011 2:00:20 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 10:43:49 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 10:34:27 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 10:31:07 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 10:15:24 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 8:37:57 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 6:30:24 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 6:20:26 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 6:07:22 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 12:29:00 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 11:52:10 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 4:17:27 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 20/04/2011 12:15:00 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 19/04/2011 9:10:25 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 19/04/2011 6:51:54 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 19/04/2011 12:59:27 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Log: 'System' Date/Time: 19/04/2011 1:49:25 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 21/04/2011 4:28:59 PM
Type: Error Category: 0
Event: 1012 Source: Microsoft-Windows-DNS-Client
There was an error while attempting to read the local hosts file.
Log: 'System' Date/Time: 21/04/2011 4:28:58 PM
Type: Error Category: 0
Event: 1012 Source: Microsoft-Windows-DNS-Client
There was an error while attempting to read the local hosts file.
Log: 'System' Date/Time: 21/04/2011 3:41:12 PM
Type: Error Category: 0
Event: 1012 Source: Microsoft-Windows-DNS-Client
There was an error while attempting to read the local hosts file.
Log: 'System' Date/Time: 21/04/2011 3:41:07 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
Log: 'System' Date/Time: 21/04/2011 3:41:06 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the IKE and AuthIP IPsec Keying Modules service, but this action failed with the following error: An instance of the service is already running.
Log: 'System' Date/Time: 21/04/2011 3:41:06 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.
Log: 'System' Date/Time: 21/04/2011 3:40:07 PM
Type: Error Category: 0
Event: 7032 Source: Service Control Manager
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
Log: 'System' Date/Time: 21/04/2011 3:39:08 PM
Type: Error Category: 0
Event: 1012 Source: Microsoft-Windows-DNS-Client
There was an error while attempting to read the local hosts file.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Remote Desktop Configuration service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:07 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:06 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:06 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:06 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Log: 'System' Date/Time: 21/04/2011 3:39:06 PM
Type: Error Category: 0
Event: 7031 Source: Service Control Manager
The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 21/04/2011 4:29:17 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 102.199.117.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 3:52:19 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 78.171.221.67.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 3:14:26 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 78.171.221.67.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 2:45:29 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 102.199.117.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 12:54:38 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 72.83.16.199.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 2:35:49 AM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 101.139.121.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 21/04/2011 2:12:18 AM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 55.216.172.69.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 11:03:14 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 152.1.228.129.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 10:38:22 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 9.224.171.66.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 8:49:39 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 102.199.117.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 7:41:18 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 78.171.221.67.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 6:24:45 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name
VirusTotal - Free Online Virus, Malware and URL Scanner timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 6:23:41 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name gateway.messenger.hotmail.com timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 6:23:26 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name
www.msftncsi.com timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 5:59:38 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 35.69.17.209.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 1:25:35 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 102.199.117.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 12:21:34 PM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 102.199.117.74.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 4:47:01 AM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name 78.171.221.67.in-addr.arpa timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 12:37:39 AM
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name pcdoctorreviews.com timed out after none of the configured DNS servers responded.
Log: 'System' Date/Time: 20/04/2011 12:32:09 AM
Type: Warning Category: 0
Event: 2512 Source: Server
The server service was unable to change the domain name from WORKGROUP to WORKGROUP.