Can't install Win7 SP1 for x64 (KB976932)

Page 4 of 4 FirstFirst ... 234

  1. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #31

    Just out of curiosity, if I run "sfc /verifyonly" from the dos prompt as administrator does that check all of all system files for corruption, part of all, or part of some system files? It seems like it's aimed at checking system integrity, but is it reliable?

    Update: I ran it on my original Win 7 installation (without SP1) and it completed with no errors. But when I ran it on the one that's the topic of this thread it only got 30% of the way through and then gave the message: "Windows Resource Protection could not perform the requested operation." I suppose this could be the same issue that prevents a system repair from the original installation disk after SP1 has been installed.
    Last edited by freewheeling; 29 Mar 2011 at 23:05.
      My Computer


  2. Posts : 908
    Vista Home Premium x86 SP2
       #32

    freewheeling said:
    Just out of curiosity, if I run "sfc /verifyonly" from the dos prompt as administrator does that check all of all system files for corruption, part of all, or part of some system files? It seems like it's aimed at checking system integrity, but is it reliable?

    Update: I ran it on my original Win 7 installation (without SP1) and it completed with no errors. But when I ran it on the one that's the topic of this thread it only got 30% of the way through and then gave the message: "Windows Resource Protection could not perform the requested operation." I suppose this could be the same issue that prevents a system repair from the original installation disk after SP1 has been installed.
    Hello!

    sfc /verifyonly checks all System files which it is designed to check = basically all, however, I do recommend sfc /scannow.

    It is reliable, unless it completes in half a second, which it will do on a few rare sorts of corruption. If it ran for about 10minutes, then it is reliable.

    That ...could not complete... message means that it failed to complete due to a large corruption of the store, maybe a badly corrupted whole directory from which it cannot recover. Only a CBS.log can tell (and we have already agreed that that image is completely ruined, and the hard disk is dead)

    Richard
      My Computer


  3. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #33

    niemiro said:
    freewheeling said:
    Just out of curiosity, if I run "sfc /verifyonly" from the dos prompt as administrator does that check all of all system files for corruption, part of all, or part of some system files? It seems like it's aimed at checking system integrity, but is it reliable?

    Update: I ran it on my original Win 7 installation (without SP1) and it completed with no errors. But when I ran it on the one that's the topic of this thread it only got 30% of the way through and then gave the message: "Windows Resource Protection could not perform the requested operation." I suppose this could be the same issue that prevents a system repair from the original installation disk after SP1 has been installed.
    Hello!

    sfc /verifyonly checks all System files which it is designed to check = basically all, however, I do recommend sfc /scannow.

    It is reliable, unless it completes in half a second, which it will do on a few rare sorts of corruption. If it ran for about 10minutes, then it is reliable.

    That ...could not complete... message means that it failed to complete due to a large corruption of the store, maybe a badly corrupted whole directory from which it cannot recover. Only a CBS.log can tell (and we have already agreed that that image is completely ruined, and the hard disk is dead)

    Richard
    Thanks. It appears that my Acronis backups are corrupted, even the early ones. Acronis won't even restore them, so that backup system was a total waste of money. I'm trying to do a clean install but got an error from my first install disk. I figure that was possibly because I hadn't established the drive type and it was just unallocated space, so I set it up and Primary/Active, used a different install disk (after disconnecting the old OS drive) and it hasn't failed yet. I wonder if the first thing I should do is install all of the updates, thru SP1 and then try to access the Easy Transfer File I created after that?

    Update: Drat! I get an error during the Windows 7 installation. I get the message:

    Windows cannot install required files. The file may be corrupt or missing. Make sure all files required for installation are available and restart the installation. Error Code: 0x80070570
    So do I need a driver for the WD 1TB Caviar Green? I thought the installation disk would have that already? I've used this disk to do an installation so I don't think it's corrupt, and surely *both* install disks couldn't be corrupted?? What's going on?

    I may install Acronis Disc Director, but True Image is going in the junk pile.
      My Computer


  4. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #34

    Hmm... I ran Memtest 4.1 and had a ton of memory errors. Traced it to a bad 4GB memory stick, which I've removed and am trying to do the clean install again. I wonder if this could have had anything to do with the other problems, corrupted files, etc.? I mean, I know the Seagate disk is bad because it initially failed the dst tests, but perhaps that wasn't the whole problem?

    Yep, the clean install is about 2/3rds done so it looks like it's going through. Now, if the easy transfer file wasn't corrupted...
      My Computer


  5. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #35

    Errors & Warnings Log


    This is the output from VEW after a (mostly) successful clean install of Win7Pro x64 and Easy Transfer session. I've re-installed a few of my original programs, but by no means all. I also ran "sfc /verifyonly" which responded after about 15 minutes that it found no problems. The main problem I had concerns "Protected Content Migration" at the end of Easy Transfer. I've described the details is this thread: What is "protected content migration?", but I don't think it ever worked properly because the Thunderbird profiles aren't on the disk and they should have been. There is some kind of bug in Easy Transfer, I think, if you happen to not do exactly what it expects in sequence. Here's the content of VEW.txt:

    Vino's Event Viewer v01c run on Windows 2008 in English
    Report run at 31/03/2011 2:26:43 PM

    Note: All dates below are in the format dd/mm/yyyy

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 31/03/2011 5:46:17 AM
    Type: Error Category: 0
    Event: 33 Source: SideBySide
    Activation context generation failed for "C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\mmsBundle.dll". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis.

    Log: 'Application' Date/Time: 31/03/2011 5:46:16 AM
    Type: Error Category: 0
    Event: 33 Source: SideBySide
    Activation context generation failed for "C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\ManagementConsole.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis.

    Log: 'Application' Date/Time: 31/03/2011 5:46:15 AM
    Type: Error Category: 0
    Event: 33 Source: SideBySide
    Activation context generation failed for "C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\RecoveryExpert.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis.

    Log: 'Application' Date/Time: 31/03/2011 5:46:10 AM
    Type: Error Category: 0
    Event: 33 Source: SideBySide
    Activation context generation failed for "C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\systeminfo.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis.

    Log: 'Application' Date/Time: 31/03/2011 2:26:15 AM
    Type: Error Category: 3
    Event: 215 Source: ESENT
    WinMail (1948) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

    Log: 'Application' Date/Time: 31/03/2011 2:26:11 AM
    Type: Error Category: 3
    Event: 215 Source: ESENT
    WinMail (2900) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

    Log: 'Application' Date/Time: 31/03/2011 12:04:35 AM
    Type: Error Category: 0
    Event: 1017 Source: Microsoft-Windows-Security-SPP
    Installation of the Proof of Purchase failed. 0xC004F061 Partial Pkey=HWJYR ACID=e838d943-63ed-4a0b-9fb1-47152908acc9 Detailed Error[?]

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'Application' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'Application' Date/Time: 31/03/2011 3:45:16 PM
    Type: Warning Category: 3
    Event: 3036 Source: Microsoft-Windows-Search
    The content source <file:C:/Users/My Name Here/AppData/Roaming/Thunderbird/Profiles/8fnkkb38.default/News/> cannot be accessed.

    Context: Application, SystemIndex Catalog

    Details:
    The object was not found. (HRESULT : 0x80041201) (0x80041201)


    Log: 'Application' Date/Time: 31/03/2011 3:33:38 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 33 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 800 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 800 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Process 800 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
    Process 800 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Run
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 800 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Search Assistant
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Search Assistant
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Internet Explorer
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunService
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Policies
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
    Process 1924 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks


    Log: 'Application' Date/Time: 31/03/2011 8:39:46 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 33 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 864 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 864 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Process 864 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
    Process 864 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Run
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 864 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Search Assistant
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Search Assistant
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Internet Explorer
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunService
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Policies
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
    Process 1852 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks


    Log: 'Application' Date/Time: 31/03/2011 7:34:06 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 33 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 788 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 788 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    Process 788 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
    Process 788 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Run
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 788 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Search Assistant
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Search Assistant
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Internet Explorer
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunService
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Policies
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
    Process 4460 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks


    Log: 'Application' Date/Time: 31/03/2011 6:39:34 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 840 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 840 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 840 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 840 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 840 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA


    Log: 'Application' Date/Time: 31/03/2011 6:23:00 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 636 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 636 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 636 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 636 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 636 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA


    Log: 'Application' Date/Time: 31/03/2011 5:08:12 AM
    Type: Warning Category: 1
    Event: 1008 Source: Microsoft-Windows-Search
    The Windows Search Service is starting up and attempting to remove the old search index {Reason: Indexer Settings Migration}.


    Log: 'Application' Date/Time: 31/03/2011 2:48:43 AM
    Type: Warning Category: 0
    Event: 1032 Source: MsiInstaller
    An error occured while refreshing environment variables updated during the installation of ''. Some users logged on to the machine may not see these changes until they log off and then log back on.

    Log: 'Application' Date/Time: 31/03/2011 2:07:16 AM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 572 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 572 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 572 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\Disallowed
    Process 572 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\My
    Process 572 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\SystemCertificates\CA


    Log: 'Application' Date/Time: 30/03/2011 10:39:42 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Config.Msi\7c577.rbf' (pid 2520) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 10:39:03 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe' (pid 2372) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 10:39:03 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe' (pid 2520) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 10:29:31 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 2552 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer


    Log: 'Application' Date/Time: 30/03/2011 9:49:48 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Config.Msi\918f9.rbf' (pid 2180) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 9:49:08 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe' (pid 2096) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 9:49:08 PM
    Type: Warning Category: 0
    Event: 10010 Source: Microsoft-Windows-RestartManager
    Application 'C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe' (pid 2180) cannot be restarted - Application SID does not match Conductor SID..

    Log: 'Application' Date/Time: 30/03/2011 9:38:00 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 724 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Explorer


    Log: 'Application' Date/Time: 30/03/2011 8:45:32 PM
    Type: Warning Category: 0
    Event: 1530 Source: Microsoft-Windows-User Profiles Service
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-3739652884-1527416797-3038172721-1000:
    Process 444 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000
    Process 892 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Policies
    Process 892 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 892 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
    Process 892 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3739652884-1527416797-3038172721-1000\Software


    Log: 'Application' Date/Time: 30/03/2011 7:36:40 PM
    Type: Warning Category: 1
    Event: 1008 Source: Microsoft-Windows-Search
    The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 31/03/2011 5:07:11 AM
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register with DCOM within the required timeout.

    Log: 'System' Date/Time: 31/03/2011 12:12:26 AM
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager
    The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.

    Log: 'System' Date/Time: 31/03/2011 12:12:26 AM
    Type: Error Category: 0
    Event: 7038 Source: Service Control Manager
    The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

    Log: 'System' Date/Time: 31/03/2011 12:12:26 AM
    Type: Error Category: 0
    Event: 10005 Source: Microsoft-Windows-DistributedCOM
    DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

    Log: 'System' Date/Time: 30/03/2011 11:23:50 PM
    Type: Error Category: 0
    Event: 7023 Source: Service Control Manager
    The event description cannot be found.

    Log: 'System' Date/Time: 30/03/2011 10:44:28 PM
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager
    The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.

    Log: 'System' Date/Time: 30/03/2011 10:44:28 PM
    Type: Error Category: 0
    Event: 7038 Source: Service Control Manager
    The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

    Log: 'System' Date/Time: 30/03/2011 10:44:27 PM
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager
    The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.

    Log: 'System' Date/Time: 30/03/2011 10:44:27 PM
    Type: Error Category: 0
    Event: 7038 Source: Service Control Manager
    The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

    Log: 'System' Date/Time: 30/03/2011 10:44:28 PM
    Type: Error Category: 0
    Event: 10005 Source: Microsoft-Windows-DistributedCOM
    DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 31/03/2011 1:00:47 AM
    Type: Warning Category: 0
    Event: 1014 Source: Microsoft-Windows-DNS-Client
    Name resolution for the name www.edonkey.com timed out after none of the configured DNS servers responded.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:18 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:58:17 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:54:40 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:54:40 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:54:40 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:54:40 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.

    Log: 'System' Date/Time: 30/03/2011 10:54:40 PM
    Type: Warning Category: 0
    Event: 51 Source: Disk
    An error was detected on device \Device\Harddisk2\DR2 during a paging operation.
      My Computer


  6. Posts : 53,365
    Windows 10 Home x64
       #36

    Don't mean to jump in here, but regarding the Seagate drive, and Seatools. Seatools can often find and repair errors that chkdsk won't. chkdsk may even come up clean, but Seatools will find, and often correct, simple errors. A Guy
      My Computer


  7. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #37

    A Guy said:
    Don't mean to jump in here, but regarding the Seagate drive, and Seatools. Seatools can often find and repair errors that chkdsk won't. chkdsk may even come up clean, but Seatools will find, and often correct, simple errors. A Guy
    Would have been nice to know that. I assumed that the language "dead drive" actually meant the drive was beyond saving and that any "repairs" effected by Sea Tools were only temporary.
      My Computer


  8. Posts : 53,365
    Windows 10 Home x64
       #38

    The drive may indeed have been beyond repair. The point is that the manufacturers own DOS tool may find things that chkdsk does not. Sorry I didn't see the thread sooner. A Guy
      My Computer


  9. Posts : 92
    Windows Vista HP 64-bit, Windows 7 P 64-bit, Leopard 10.5.8, Windows 7 P 32-bit
    Thread Starter
       #39

    Well, the OS was beyond repair that's for sure. And replacing the drive was relatively painless so no harm done. Plus I learned a few things. Now if I can just stave off senility...
      My Computer


 
Page 4 of 4 FirstFirst ... 234

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:47.
Find Us