Vino's Event Viewer v01c run on Windows Vista in English Report run at 02/01/2010 11:23:18 AM Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 01/01/2010 3:24:59 AM Type: Error Category: 0 Event: 8194 Source: VSS Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {c5a0909e-250c-4cdf-b1d1-fb14b6e21850} Log: 'Application' Date/Time: 24/12/2009 12:02:02 AM Type: Error Category: 3 Event: 3013 Source: Microsoft-Windows-Search The entry in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Log: 'Application' Date/Time: 23/12/2009 12:30:30 AM Type: Error Category: 0 Event: 8194 Source: VSS Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {9f1294d8-7620-4488-aeca-99422d2db10a} Log: 'Application' Date/Time: 18/12/2009 11:30:39 PM Type: Error Category: 0 Event: 8194 Source: VSS Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {33b38449-356f-42cf-bbbf-498d3ba935aa} Log: 'Application' Date/Time: 12/12/2009 3:21:52 AM Type: Error Category: 0 Event: 8194 Source: VSS Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer Data Context: Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {58793519-4058-4964-ac7a-97f6c7748694} ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Information Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 02/01/2010 12:30:06 AM Type: Information Category: 0 Event: 8224 Source: VSS The VSS service is shutting down due to idle timeout. Log: 'Application' Date/Time: 02/01/2010 12:27:06 AM Type: Information Category: 0 Event: 8211 Source: System Restore Successfully created scheduled restore point. Log: 'Application' Date/Time: 02/01/2010 12:27:06 AM Type: Information Category: 0 Event: 8194 Source: System Restore Successfully created restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint). Log: 'Application' Date/Time: 01/01/2010 11:16:55 PM Type: Information Category: 0 Event: 1 Source: Microsoft-Windows-CertificateServicesClient Certificate Services Client has been started successfully. Log: 'Application' Date/Time: 01/01/2010 11:16:50 PM Type: Information Category: 0 Event: 1 Source: Microsoft-Windows-CertificateServicesClient Certificate Services Client has been started successfully. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 27/11/2009 12:57:55 AM Type: Warning Category: 1 Event: 1008 Source: Microsoft-Windows-Search The Windows Search Service is attempting to remove the old catalog. Log: 'Application' Date/Time: 27/11/2009 12:51:37 AM Type: Warning Category: 1 Event: 1008 Source: Microsoft-Windows-Search The Windows Search Service is attempting to remove the old catalog. Log: 'Application' Date/Time: 27/11/2009 12:51:04 AM Type: Warning Category: 1 Event: 1008 Source: Microsoft-Windows-Search The Windows Search Service is attempting to remove the old catalog. Log: 'Application' Date/Time: 27/11/2009 12:03:40 AM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 8 user registry handles leaked from \Registry\User\S-1-5-21-2540761015-277959762-2128358203-1000: Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000 Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000 Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Microsoft\SystemCertificates\SmartCardRoot Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Microsoft\SystemCertificates\CA Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Microsoft\SystemCertificates\Root Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Policies\Microsoft\SystemCertificates Process 2372 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-2540761015-277959762-2128358203-1000\Software\Microsoft\SystemCertificates\trust Log: 'Application' Date/Time: 17/11/2009 4:47:15 AM Type: Warning Category: 0 Event: 6004 Source: Microsoft-Windows-Winlogon The winlogon notification subscriber failed a critical notification event. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 10/11/2009 11:42:28 PM Type: Critical Category: 0 Event: 41 Source: Microsoft-Windows-Kernel-Power The last sleep transition was unsuccessful. This error could be caused if the system stopped responding, failed, or lost power during the sleep transition. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 01/01/2010 11:14:57 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Log: 'System' Date/Time: 01/01/2010 11:14:47 PM Type: Error Category: 403 Event: 412 Source: Microsoft-Windows-TaskScheduler Task Scheduler service failed to launch tasks triggered by computer startup. Additional Data: Error Value: 2147549183. User Action: restart task scheduler service. Log: 'System' Date/Time: 01/01/2010 11:14:40 PM Type: Error Category: 0 Event: 6008 Source: EventLog The previous system shutdown at 9:12:51 AM on 2/01/2010 was unexpected. Log: 'System' Date/Time: 01/01/2010 10:42:29 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Log: 'System' Date/Time: 01/01/2010 10:42:08 PM Type: Error Category: 403 Event: 412 Source: Microsoft-Windows-TaskScheduler Task Scheduler service failed to launch tasks triggered by computer startup. Additional Data: Error Value: 2147549183. User Action: restart task scheduler service. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Information Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 02/01/2010 12:37:24 AM Type: Information Category: 0 Event: 33 Source: volsnap The oldest shadow copy of volume C: was deleted to keep disk space usage for shadow copies of volume C: below the user defined limit. Log: 'System' Date/Time: 02/01/2010 12:33:06 AM Type: Information Category: 0 Event: 7036 Source: Service Control Manager The Microsoft Software Shadow Copy Provider service entered the stopped state. Log: 'System' Date/Time: 02/01/2010 12:30:06 AM Type: Information Category: 0 Event: 7036 Source: Service Control Manager The Volume Shadow Copy service entered the stopped state. Log: 'System' Date/Time: 02/01/2010 12:26:44 AM Type: Information Category: 0 Event: 33 Source: volsnap The oldest shadow copy of volume \\?...2f0-11dc-b028-806e6f6e6963} was deleted to keep disk space usage for shadow copies of volume \\?...2f0-11dc-b028-806e6f6e6963} below the user defined limit. Log: 'System' Date/Time: 02/01/2010 12:25:26 AM Type: Information Category: 0 Event: 7036 Source: Service Control Manager The Microsoft Software Shadow Copy Provider service entered the running state. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 01/01/2010 1:30:00 PM Type: Warning Category: 0 Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig WLAN AutoConfig service has successfully stopped. Log: 'System' Date/Time: 01/01/2010 1:30:00 PM Type: Warning Category: 0 Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\IWMSSvc.dll Log: 'System' Date/Time: 01/01/2010 6:04:59 AM Type: Warning Category: 0 Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig WLAN AutoConfig service has successfully stopped. Log: 'System' Date/Time: 01/01/2010 6:04:59 AM Type: Warning Category: 0 Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\IWMSSvc.dll Log: 'System' Date/Time: 01/01/2010 2:25:39 AM Type: Warning Category: 0 Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig WLAN AutoConfig service has successfully stopped.