Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner

please,whon can help on this!!!,thanks in advance!

microsoft.public.windows.vista.performance maintenance






Speedup My PC
Reply
  #1 (permalink)  
Old 12-10-2008
Sunny
 

Posts: n/a
please,whon can help on this!!!,thanks in advance!
Log Name: Application
Source: Microsoft-Windows-Perflib
Date: 10/12/08 22:55:57
Event ID: 1008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Open Procedure for service "WmiApRpl" in DLL
"C:\Windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this
service will not be available. The first four bytes (DWORD) of the Data
section contains the error code.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Perflib"
Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
<EventID Qualifiers="49152">1008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:57.000Z" />
<EventRecordID>53201</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<UserData>
<EventXML
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="Perflib">
<param1>WmiApRpl</param1>
<param2>C:\Windows\system32\wbem\wmiaprpl.dll</param2>
<binaryDataSize>4</binaryDataSize>
<binaryData>15000000</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: Application
Source: Microsoft-Windows-Perflib
Date: 10/12/08 22:55:54
Event ID: 1008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Open Procedure for service "MSDTC" in DLL
"C:\Windows\system32\msdtcuiu.DLL" failed. Performance data for this service
will not be available. The first four bytes (DWORD) of the Data section
contains the error code.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Perflib"
Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
<EventID Qualifiers="49152">1008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:54.000Z" />
<EventRecordID>53200</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<UserData>
<EventXML
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="Perflib">
<param1>MSDTC</param1>
<param2>C:\Windows\system32\msdtcuiu.DLL</param2>
<binaryDataSize>4</binaryDataSize>
<binaryData>02000780</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: Application
Source: Microsoft-Windows-Perflib
Date: 10/12/08 22:55:53
Event ID: 1008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Open Procedure for service "Lsa" in DLL
"C:\Windows\system32\Secur32.dll" failed. Performance data for this service
will not be available. The first four bytes (DWORD) of the Data section
contains the error code.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Perflib"
Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
<EventID Qualifiers="49152">1008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:53.000Z" />
<EventRecordID>53199</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<UserData>
<EventXML
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="Perflib">
<param1>Lsa</param1>
<param2>C:\Windows\system32\Secur32.dll</param2>
<binaryDataSize>4</binaryDataSize>
<binaryData>05000000</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: Application
Source: Microsoft-Windows-Perflib
Date: 10/12/08 22:55:53
Event ID: 1008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Open Procedure for service "ESENT" in DLL
"C:\Windows\system32\esentprf.dll" failed. Performance data for this service
will not be available. The first four bytes (DWORD) of the Data section
contains the error code.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Perflib"
Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
<EventID Qualifiers="49152">1008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:53.000Z" />
<EventRecordID>53198</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<UserData>
<EventXML
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="Perflib">
<param1>ESENT</param1>
<param2>C:\Windows\system32\esentprf.dll</param2>
<binaryDataSize>4</binaryDataSize>
<binaryData>02000000</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: Application
Source: Microsoft-Windows-Perflib
Date: 10/12/08 22:55:52
Event ID: 1008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Open Procedure for service "BITS" in DLL
"C:\Windows\system32\bitsperf.dll" failed. Performance data for this service
will not be available. The first four bytes (DWORD) of the Data section
contains the error code.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Perflib"
Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
<EventID Qualifiers="49152">1008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:52.000Z" />
<EventRecordID>53197</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<UserData>
<EventXML
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="Perflib">
<param1>BITS</param1>
<param2>C:\Windows\system32\bitsperf.dll</param2>
<binaryDataSize>4</binaryDataSize>
<binaryData>05000000</binaryData>
</EventXML>
</UserData>
</Event>

Log Name: System
Source: Microsoft-Windows-LanguagePackSetup
Date: 10/12/08 22:55:39
Event ID: 1001
Task Category: Language Pack Setup Wizard functionality
Level: Error
Keywords:
User: SYSTEM
Computer: Sunny-Notebook
Description:
Application initialization failed. Last error: 0x80070032
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-LanguagePackSetup"
Guid="{7237fff9-a08a-4804-9c79-4a8704b70b87}" />
<EventID>1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>30</Task>
<Opcode>31</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:55:39.174Z" />
<EventRecordID>45191</EventRecordID>
<Correlation />
<Execution ProcessID="352" ThreadID="400" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="Error">0x80070032</Data>
</EventData>
</Event>

Log Name: Application
Source: VzCdbSvc
Date: 10/12/08 22:54:57
Event ID: 7
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
Failed to load the plug-in module. (GUID =
{56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="VzCdbSvc" />
<EventID Qualifiers="0">7</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:57.000Z" />
<EventRecordID>53192</EventRecordID>
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
<Data>0x80042019</Data>
</EventData>
</Event>

Log Name: System
Source: Service Control Manager
Date: 10/12/08 22:54:50
Event ID: 7000
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it
has no enabled devices associated with it.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager"
Guid="{555908D1-A6D7-4695-8E1E-26931D2012F4}" EventSourceName="Service
Control Manager" />
<EventID Qualifiers="49152">7000</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:50.000Z" />
<EventRecordID>45133</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">Parallel port driver</Data>
<Data Name="param2">%%1058</Data>
</EventData>
</Event>

Log Name: Application
Source: Microsoft-Windows-WMI
Date: 10/12/08 22:54:50
Event ID: 10
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60
WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage
> 99" could not be reactivated in namespace "//./root/cimv2" because of error

0x80041003. Events cannot be delivered through this filter until the problem
is corrected.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WMI"
Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" EventSourceName="WinMgmt" />
<EventID Qualifiers="49152">10</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:50.000Z" />
<EventRecordID>53185</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data>//./root/cimv2</Data>
<Data>SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE
TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage >
99</Data>
<Data>0x80041003</Data>
</EventData>
</Event>

Log Name: Application
Source: SQLBrowser
Date: 10/12/08 22:54:24
Event ID: 3
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The configuration of the AdminConnection\TCP protocol in the SQL instance
MSSMLBIZ is not valid.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="SQLBrowser" />
<EventID Qualifiers="49230">3</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:24.000Z" />
<EventRecordID>53154</EventRecordID>
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data>AdminConnection\TCP</Data>
<Data>MSSMLBIZ</Data>
</EventData>
</Event>

Log Name: System
Source: Microsoft-Windows-ResourcePublication
Date: 10/12/08 22:54:22
Event ID: 1002
Task Category: None
Level: Error
Keywords: Event originating from the fdrespub service
User: LOCAL SERVICE
Computer: Sunny-Notebook
Description:
Element Provider\Microsoft.Base.Publication/Publication/Computer failed to
publish. Ensure that both PKEY_PUBSVCS_METADATA and PKEY_PUBSVCS_TYPE are
set properly on the function instance and there were no errors adding the
function instance.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-ResourcePublication"
Guid="{74c2135f-cc76-45c3-879a-ef3bb1eeaf86}" />
<EventID>1002</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000040</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:22.501Z" />
<EventRecordID>45092</EventRecordID>
<Correlation />
<Execution ProcessID="1472" ThreadID="2664" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-19" />
</System>
<UserData>
<ErrorData
xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">

<Argument>Provider\Microsoft.Base.Publication/Publication/Computer</Argument>
</ErrorData>
</UserData>
</Event>

Log Name: System
Source: Microsoft-Windows-Dhcp-Client
Date: 10/12/08 22:54:22
Event ID: 1002
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The IP address lease 192.168.0.111 for the Network Card with network address
00215D8539E0 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Dhcp-Client"
Guid="{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}" EventSourceName="Dhcp" />
<EventID Qualifiers="0">1002</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:22.000Z" />
<EventRecordID>45089</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data>192.168.0.111</Data>
<Data>00215D8539E0</Data>
<Data>192.168.0.1</Data>
</EventData>
</Event>

Log Name: System
Source: Microsoft-Windows-Dhcp-Client
Date: 10/12/08 22:54:22
Event ID: 1003
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The description for Event ID 1003 from source Microsoft-Windows-Dhcp-Client
cannot be found. Either the component that raises this event is not installed
on your local computer or the installation is corrupted. You can install or
repair the component on the local computer.

If the event originated on another computer, the display information had to
be saved with the event.

The following information was included with the event:

00215D8539E0
%%2163146757

The resource loader failed to find MUI file

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Dhcp-Client"
Guid="{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}" EventSourceName="Dhcp" />
<EventID Qualifiers="0">1003</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:22.000Z" />
<EventRecordID>45088</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data>00215D8539E0</Data>
<Data>%%2163146757</Data>
</EventData>
</Event>

Log Name: System
Source: Microsoft-Windows-HttpEvent
Date: 10/12/08 22:54:16
Event ID: 15016
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
Unable to initialize the security package Kerberos for server side
authentication. The data field contains the error number.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-HttpEvent"
Guid="{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}" EventSourceName="HTTP" />
<EventID Qualifiers="49152">15016</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:54:16.407Z" />
<EventRecordID>45086</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="60" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data Name="DeviceObject">\Device\Http\ReqQueue</Data>
<Data Name="SecurityPackage">Kerberos</Data>

<Binary>000004000200300000000000A83A00C00000000000 000000000000000000000000000000000000000E030980</Binary>
</EventData>
</Event>

Log Name: System
Source: Microsoft-Windows-WLAN-AutoConfig
Date: 10/12/08 22:52:58
Event ID: 4001
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: Sunny-Notebook
Description:
WLAN AutoConfig service has successfully stopped.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WLAN-AutoConfig"
Guid="{9580d7dd-0379-4658-9870-d5be7d52d6de}" />
<EventID>4001</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>2</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:52:58.617Z" />
<EventRecordID>45074</EventRecordID>
<Correlation />
<Execution ProcessID="1204" ThreadID="7400" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
</EventData>
</Event>

Log Name: System
Source: Microsoft-Windows-WLAN-AutoConfig
Date: 10/12/08 22:52:58
Event ID: 10002
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: Sunny-Notebook
Description:
WLAN Extensibility Module has stopped.

Module Path: C:\Windows\System32\IWMSSvc.dll

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WLAN-AutoConfig"
Guid="{9580d7dd-0379-4658-9870-d5be7d52d6de}" />
<EventID>10002</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:52:58.617Z" />
<EventRecordID>45073</EventRecordID>
<Correlation />
<Execution ProcessID="1204" ThreadID="7400" />
<Channel>System</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="ExtensibleModulePath">C:\Windows\System32\IW MSSvc.dll</Data>
</EventData>
</Event>

Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 10/12/08 22:52:56
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: Sunny-Notebook
Description:
Windows detected your registry file is still in use by other applications or
services. The file will be unloaded now. The applications or services that
hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from
\Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003_Classes:
Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
opened key
\REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003_CLASSES

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service"
Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:52:56.000Z" />
<EventRecordID>53114</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">1 user registry handles leaked from
\Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003_Classes:
Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
opened key
\REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003_CLASSES
</Data>
</EventData>
</Event>

Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 10/12/08 22:52:56
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: Sunny-Notebook
Description:
Windows detected your registry file is still in use by other applications or
services. The file will be unloaded now. The applications or services that
hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from
\Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003:
Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
opened key \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service"
Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:52:56.000Z" />
<EventRecordID>53113</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">1 user registry handles leaked from
\Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003:
Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
opened key \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003
</Data>
</EventData>
</Event>

Log Name: Application
Source: Microsoft-Windows-EventSystem
Date: 10/12/08 22:52:53
Event ID: 4621
Task Category: Event System
Level: Error
Keywords: Classic
User: N/A
Computer: Sunny-Notebook
Description:
The COM+ Event System could not remove the EventSystem.EventSubscription
object
{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-EventSystem"
Guid="{899daace-4868-4295-afcd-9eb8fb497561}" EventSourceName="EventSystem" />
<EventID Qualifiers="49152">4621</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>16</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-10T14:52:53.000Z" />
<EventRecordID>53110</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Sunny-Notebook</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">80070005</Data>
<Data Name="param2">EventSystem.EventSubscription</Data>
<Data
Name="param3">{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}</Data>
</EventData>
</Event>
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 12-10-2008
Raymond Babbitt
 

Posts: n/a
Re: please,whon can help on this!!!,thanks in advance!
NOBODY
Reply With Quote
  #3 (permalink)  
Old 12-11-2008
Rick Rogers
 

Posts: n/a
Re: please,whon can help on this!!!,thanks in advance!
While details from the system logs can be useful in diagnosing and issue,
you haven't told us exactly what problem you're having. Please describe in
your own terms exactly what's going wrong for you.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Windows help - www.rickrogers.org
My thoughts http://rick-mvp.blogspot.com

"Sunny" <Sunny@discussions.microsoft.com> wrote in message
news:C77E2772-63C4-4086-B2A0-B73913B30C49@microsoft.com...

<snip>

Reply With Quote
  #4 (permalink)  
Old 12-20-2008
Robert
 

Posts: n/a
Re: please,whon can help on this!!!,thanks in advance!
Some day there will be a computer to really analyze all of this and send
back the code to fix it peachy clean!
"Sunny" <Sunny@discussions.microsoft.com> wrote in message
news:C77E2772-63C4-4086-B2A0-B73913B30C49@microsoft.com...
> Log Name: Application
> Source: Microsoft-Windows-Perflib
> Date: 10/12/08 22:55:57
> Event ID: 1008
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Open Procedure for service "WmiApRpl" in DLL
> "C:\Windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this
> service will not be available. The first four bytes (DWORD) of the Data
> section contains the error code.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Perflib"
> Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
> <EventID Qualifiers="49152">1008</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:57.000Z" />
> <EventRecordID>53201</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <UserData>
> <EventXML
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="Perflib">
> <param1>WmiApRpl</param1>
> <param2>C:\Windows\system32\wbem\wmiaprpl.dll</param2>
> <binaryDataSize>4</binaryDataSize>
> <binaryData>15000000</binaryData>
> </EventXML>
> </UserData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-Perflib
> Date: 10/12/08 22:55:54
> Event ID: 1008
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Open Procedure for service "MSDTC" in DLL
> "C:\Windows\system32\msdtcuiu.DLL" failed. Performance data for this
> service
> will not be available. The first four bytes (DWORD) of the Data section
> contains the error code.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Perflib"
> Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
> <EventID Qualifiers="49152">1008</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:54.000Z" />
> <EventRecordID>53200</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <UserData>
> <EventXML
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="Perflib">
> <param1>MSDTC</param1>
> <param2>C:\Windows\system32\msdtcuiu.DLL</param2>
> <binaryDataSize>4</binaryDataSize>
> <binaryData>02000780</binaryData>
> </EventXML>
> </UserData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-Perflib
> Date: 10/12/08 22:55:53
> Event ID: 1008
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Open Procedure for service "Lsa" in DLL
> "C:\Windows\system32\Secur32.dll" failed. Performance data for this
> service
> will not be available. The first four bytes (DWORD) of the Data section
> contains the error code.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Perflib"
> Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
> <EventID Qualifiers="49152">1008</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:53.000Z" />
> <EventRecordID>53199</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <UserData>
> <EventXML
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="Perflib">
> <param1>Lsa</param1>
> <param2>C:\Windows\system32\Secur32.dll</param2>
> <binaryDataSize>4</binaryDataSize>
> <binaryData>05000000</binaryData>
> </EventXML>
> </UserData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-Perflib
> Date: 10/12/08 22:55:53
> Event ID: 1008
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Open Procedure for service "ESENT" in DLL
> "C:\Windows\system32\esentprf.dll" failed. Performance data for this
> service
> will not be available. The first four bytes (DWORD) of the Data section
> contains the error code.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Perflib"
> Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
> <EventID Qualifiers="49152">1008</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:53.000Z" />
> <EventRecordID>53198</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <UserData>
> <EventXML
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="Perflib">
> <param1>ESENT</param1>
> <param2>C:\Windows\system32\esentprf.dll</param2>
> <binaryDataSize>4</binaryDataSize>
> <binaryData>02000000</binaryData>
> </EventXML>
> </UserData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-Perflib
> Date: 10/12/08 22:55:52
> Event ID: 1008
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Open Procedure for service "BITS" in DLL
> "C:\Windows\system32\bitsperf.dll" failed. Performance data for this
> service
> will not be available. The first four bytes (DWORD) of the Data section
> contains the error code.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Perflib"
> Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
> <EventID Qualifiers="49152">1008</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:52.000Z" />
> <EventRecordID>53197</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <UserData>
> <EventXML
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="Perflib">
> <param1>BITS</param1>
> <param2>C:\Windows\system32\bitsperf.dll</param2>
> <binaryDataSize>4</binaryDataSize>
> <binaryData>05000000</binaryData>
> </EventXML>
> </UserData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-LanguagePackSetup
> Date: 10/12/08 22:55:39
> Event ID: 1001
> Task Category: Language Pack Setup Wizard functionality
> Level: Error
> Keywords:
> User: SYSTEM
> Computer: Sunny-Notebook
> Description:
> Application initialization failed. Last error: 0x80070032
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-LanguagePackSetup"
> Guid="{7237fff9-a08a-4804-9c79-4a8704b70b87}" />
> <EventID>1001</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>30</Task>
> <Opcode>31</Opcode>
> <Keywords>0x8000000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:55:39.174Z" />
> <EventRecordID>45191</EventRecordID>
> <Correlation />
> <Execution ProcessID="352" ThreadID="400" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-18" />
> </System>
> <EventData>
> <Data Name="Error">0x80070032</Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: VzCdbSvc
> Date: 10/12/08 22:54:57
> Event ID: 7
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> Failed to load the plug-in module. (GUID =
> {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="VzCdbSvc" />
> <EventID Qualifiers="0">7</EventID>
> <Level>2</Level>
> <Task>0</Task>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:57.000Z" />
> <EventRecordID>53192</EventRecordID>
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data>{56F9312C-C989-4E04-8C23-299DEE3A36F5}</Data>
> <Data>0x80042019</Data>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Service Control Manager
> Date: 10/12/08 22:54:50
> Event ID: 7000
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The Parallel port driver service failed to start due to the following
> error:
> The service cannot be started, either because it is disabled or because it
> has no enabled devices associated with it.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Service Control Manager"
> Guid="{555908D1-A6D7-4695-8E1E-26931D2012F4}" EventSourceName="Service
> Control Manager" />
> <EventID Qualifiers="49152">7000</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:50.000Z" />
> <EventRecordID>45133</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data Name="param1">Parallel port driver</Data>
> <Data Name="param2">%%1058</Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-WMI
> Date: 10/12/08 22:54:50
> Event ID: 10
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN
> 60
> WHERE TargetInstance ISA "Win32_Processor" AND
> TargetInstance.LoadPercentage
>> 99" could not be reactivated in namespace "//./root/cimv2" because of
>> error

> 0x80041003. Events cannot be delivered through this filter until the
> problem
> is corrected.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-WMI"
> Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" EventSourceName="WinMgmt" />
> <EventID Qualifiers="49152">10</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:50.000Z" />
> <EventRecordID>53185</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data>//./root/cimv2</Data>
> <Data>SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE
> TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage >
> 99</Data>
> <Data>0x80041003</Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: SQLBrowser
> Date: 10/12/08 22:54:24
> Event ID: 3
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The configuration of the AdminConnection\TCP protocol in the SQL instance
> MSSMLBIZ is not valid.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="SQLBrowser" />
> <EventID Qualifiers="49230">3</EventID>
> <Level>3</Level>
> <Task>0</Task>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:24.000Z" />
> <EventRecordID>53154</EventRecordID>
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data>AdminConnection\TCP</Data>
> <Data>MSSMLBIZ</Data>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-ResourcePublication
> Date: 10/12/08 22:54:22
> Event ID: 1002
> Task Category: None
> Level: Error
> Keywords: Event originating from the fdrespub service
> User: LOCAL SERVICE
> Computer: Sunny-Notebook
> Description:
> Element Provider\Microsoft.Base.Publication/Publication/Computer failed to
> publish. Ensure that both PKEY_PUBSVCS_METADATA and PKEY_PUBSVCS_TYPE are
> set properly on the function instance and there were no errors adding the
> function instance.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-ResourcePublication"
> Guid="{74c2135f-cc76-45c3-879a-ef3bb1eeaf86}" />
> <EventID>1002</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x8000000000000040</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:22.501Z" />
> <EventRecordID>45092</EventRecordID>
> <Correlation />
> <Execution ProcessID="1472" ThreadID="2664" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-19" />
> </System>
> <UserData>
> <ErrorData
> xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events"
> xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
>
> <Argument>Provider\Microsoft.Base.Publication/Publication/Computer</Argument>
> </ErrorData>
> </UserData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-Dhcp-Client
> Date: 10/12/08 22:54:22
> Event ID: 1002
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The IP address lease 192.168.0.111 for the Network Card with network
> address
> 00215D8539E0 has been denied by the DHCP server 192.168.0.1 (The DHCP
> Server
> sent a DHCPNACK message).
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Dhcp-Client"
> Guid="{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}" EventSourceName="Dhcp" />
> <EventID Qualifiers="0">1002</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:22.000Z" />
> <EventRecordID>45089</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data>192.168.0.111</Data>
> <Data>00215D8539E0</Data>
> <Data>192.168.0.1</Data>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-Dhcp-Client
> Date: 10/12/08 22:54:22
> Event ID: 1003
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The description for Event ID 1003 from source
> Microsoft-Windows-Dhcp-Client
> cannot be found. Either the component that raises this event is not
> installed
> on your local computer or the installation is corrupted. You can install
> or
> repair the component on the local computer.
>
> If the event originated on another computer, the display information had
> to
> be saved with the event.
>
> The following information was included with the event:
>
> 00215D8539E0
> %%2163146757
>
> The resource loader failed to find MUI file
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Dhcp-Client"
> Guid="{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}" EventSourceName="Dhcp" />
> <EventID Qualifiers="0">1003</EventID>
> <Version>0</Version>
> <Level>3</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:22.000Z" />
> <EventRecordID>45088</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data>00215D8539E0</Data>
> <Data>%%2163146757</Data>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-HttpEvent
> Date: 10/12/08 22:54:16
> Event ID: 15016
> Task Category: None
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> Unable to initialize the security package Kerberos for server side
> authentication. The data field contains the error number.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-HttpEvent"
> Guid="{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}" EventSourceName="HTTP" />
> <EventID Qualifiers="49152">15016</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:54:16.407Z" />
> <EventRecordID>45086</EventRecordID>
> <Correlation />
> <Execution ProcessID="4" ThreadID="60" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data Name="DeviceObject">\Device\Http\ReqQueue</Data>
> <Data Name="SecurityPackage">Kerberos</Data>
>
> <Binary>000004000200300000000000A83A00C00000000000 000000000000000000000000000000000000000E030980</Binary>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-WLAN-AutoConfig
> Date: 10/12/08 22:52:58
> Event ID: 4001
> Task Category: None
> Level: Warning
> Keywords:
> User: SYSTEM
> Computer: Sunny-Notebook
> Description:
> WLAN AutoConfig service has successfully stopped.
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-WLAN-AutoConfig"
> Guid="{9580d7dd-0379-4658-9870-d5be7d52d6de}" />
> <EventID>4001</EventID>
> <Version>0</Version>
> <Level>3</Level>
> <Task>0</Task>
> <Opcode>2</Opcode>
> <Keywords>0x4000000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:52:58.617Z" />
> <EventRecordID>45074</EventRecordID>
> <Correlation />
> <Execution ProcessID="1204" ThreadID="7400" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-18" />
> </System>
> <EventData>
> </EventData>
> </Event>
>
> Log Name: System
> Source: Microsoft-Windows-WLAN-AutoConfig
> Date: 10/12/08 22:52:58
> Event ID: 10002
> Task Category: None
> Level: Warning
> Keywords:
> User: SYSTEM
> Computer: Sunny-Notebook
> Description:
> WLAN Extensibility Module has stopped.
>
> Module Path: C:\Windows\System32\IWMSSvc.dll
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-WLAN-AutoConfig"
> Guid="{9580d7dd-0379-4658-9870-d5be7d52d6de}" />
> <EventID>10002</EventID>
> <Version>0</Version>
> <Level>3</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x4000000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:52:58.617Z" />
> <EventRecordID>45073</EventRecordID>
> <Correlation />
> <Execution ProcessID="1204" ThreadID="7400" />
> <Channel>System</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-18" />
> </System>
> <EventData>
> <Data
> Name="ExtensibleModulePath">C:\Windows\System32\IW MSSvc.dll</Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-User Profiles Service
> Date: 10/12/08 22:52:56
> Event ID: 1530
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: SYSTEM
> Computer: Sunny-Notebook
> Description:
> Windows detected your registry file is still in use by other applications
> or
> services. The file will be unloaded now. The applications or services that
> hold your registry file may not function properly afterwards.
>
> DETAIL -
> 1 user registry handles leaked from
> \Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003_Classes:
> Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
> opened key
> \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003_CLASSES
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-User Profiles Service"
> Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
> <EventID Qualifiers="32768">1530</EventID>
> <Version>0</Version>
> <Level>3</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:52:56.000Z" />
> <EventRecordID>53114</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-18" />
> </System>
> <EventData Name="EVENT_HIVE_LEAK">
> <Data Name="Detail">1 user registry handles leaked from
> \Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003_Classes:
> Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
> opened key
> \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003_CLASSES
> </Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-User Profiles Service
> Date: 10/12/08 22:52:56
> Event ID: 1530
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: SYSTEM
> Computer: Sunny-Notebook
> Description:
> Windows detected your registry file is still in use by other applications
> or
> services. The file will be unloaded now. The applications or services that
> hold your registry file may not function properly afterwards.
>
> DETAIL -
> 1 user registry handles leaked from
> \Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003:
> Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
> opened key \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-User Profiles Service"
> Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
> <EventID Qualifiers="32768">1530</EventID>
> <Version>0</Version>
> <Level>3</Level>
> <Task>0</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:52:56.000Z" />
> <EventRecordID>53113</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security UserID="S-1-5-18" />
> </System>
> <EventData Name="EVENT_HIVE_LEAK">
> <Data Name="Detail">1 user registry handles leaked from
> \Registry\User\S-1-5-21-1971929391-261153460-2548609172-1003:
> Process 1060 (\Device\HarddiskVolume2\Windows\System32\svchost. exe) has
> opened key \REGISTRY\USER\S-1-5-21-1971929391-261153460-2548609172-1003
> </Data>
> </EventData>
> </Event>
>
> Log Name: Application
> Source: Microsoft-Windows-EventSystem
> Date: 10/12/08 22:52:53
> Event ID: 4621
> Task Category: Event System
> Level: Error
> Keywords: Classic
> User: N/A
> Computer: Sunny-Notebook
> Description:
> The COM+ Event System could not remove the EventSystem.EventSubscription
> object
> {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}.
> The HRESULT was 80070005.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-EventSystem"
> Guid="{899daace-4868-4295-afcd-9eb8fb497561}"
> EventSourceName="EventSystem" />
> <EventID Qualifiers="49152">4621</EventID>
> <Version>0</Version>
> <Level>2</Level>
> <Task>16</Task>
> <Opcode>0</Opcode>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-12-10T14:52:53.000Z" />
> <EventRecordID>53110</EventRecordID>
> <Correlation />
> <Execution ProcessID="0" ThreadID="0" />
> <Channel>Application</Channel>
> <Computer>Sunny-Notebook</Computer>
> <Security />
> </System>
> <EventData>
> <Data Name="param1">80070005</Data>
> <Data Name="param2">EventSystem.EventSubscription</Data>
> <Data
> Name="param3">{CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}</Data>
> </EventData>
> </Event>


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Advance search freezes jim-g microsoft.public.windows.vista.general 0 01-08-2008 05:16
XMLFox Advance XML and XSD Editor 3.00 VistaDev Vista Software Development Feed 0 04-20-2007 12:26




All times are GMT +1. The time now is 08:39.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com , Win7Heads.com and Win8Heads.com.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.6.0 RC 2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120