Vino's Event Viewer v01c run on Windows Vista in English Report run at 11/02/2016 21:09:53 Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 11/02/2016 20:31:13 Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application TuneUpUtilitiesService32.exe, version 16.13.1.47453, time stamp 0x566adf57, faulting module ntdll.dll, version 6.0.6002.18541, time stamp 0x4ec3e3d5, exception code 0xc0000005, fault offset 0x00066626, process id 0xad0, application start time 0x01d1650ad69fd949. Log: 'Application' Date/Time: 11/02/2016 20:29:11 Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 11/02/2016 20:28:53 Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application AUDIODG.EXE, version 6.0.6002.18005, time stamp 0x49e02218, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x006f0064, process id 0x684, application start time 0x01d1650ac89a1089. Log: 'Application' Date/Time: 11/02/2016 17:42:09 Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application AUDIODG.EXE, version 6.0.6002.18005, time stamp 0x49e02218, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x006f0064, process id 0x6ac, application start time 0x01d164f2b2aef542. Log: 'Application' Date/Time: 11/02/2016 17:36:42 Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 11/02/2016 17:36:40 Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application TuneUpUtilitiesService32.exe, version 16.13.1.47453, time stamp 0x566adf57, faulting module ntdll.dll, version 6.0.6002.18541, time stamp 0x4ec3e3d5, exception code 0xc0000005, fault offset 0x00066626, process id 0xba0, application start time 0x01d164f2bc41fb81. Log: 'Application' Date/Time: 11/02/2016 15:26:51 Type: Error Category: 16 Event: 4621 Source: Microsoft-Windows-EventSystem The COM+ Event System could not remove the EventSystem.EventSubscription object {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005. Log: 'Application' Date/Time: 11/02/2016 15:26:47 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . Log: 'Application' Date/Time: 11/02/2016 15:26:46 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . Log: 'Application' Date/Time: 11/02/2016 15:26:46 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . Log: 'Application' Date/Time: 11/02/2016 15:26:46 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . Log: 'Application' Date/Time: 11/02/2016 15:26:45 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . Log: 'Application' Date/Time: 11/02/2016 15:26:45 Type: Error Category: 0 Event: 256 Source: Microsoft-Windows-CAPI2 The Cryptographic Services service failed to initialize the Catalog Database. The error was: 1392 (0x570) : The file or directory is corrupted and unreadable. . ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 11/02/2016 20:31:16 Type: Warning Category: 0 Event: 6006 Source: Microsoft-Windows-Winlogon The winlogon notification subscriber took 116 second(s) to handle the notification event (CreateSession). Log: 'Application' Date/Time: 11/02/2016 20:30:20 Type: Warning Category: 0 Event: 6005 Source: Microsoft-Windows-Winlogon The winlogon notification subscriber is taking long time to handle the notification event (CreateSession). Log: 'Application' Date/Time: 11/02/2016 15:26:54 Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 11 user registry handles leaked from \Registry\User\S-1-5-21-2805803174-3479283650-3513827087-1000: Process 3800 (\Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000 Process 3800 (\Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000 Process 3800 (\Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000 Process 2252 (\Device\HarddiskVolume1\Program Files\McAfee\SiteAdvisor\McSACore.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Clients Process 2252 (\Device\HarddiskVolume1\Program Files\McAfee\SiteAdvisor\McSACore.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Clients\StartMenuInternet Process 2252 (\Device\HarddiskVolume1\Program Files\McAfee\SiteAdvisor\McSACore.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Clients\StartMenuInternet Process 2168 (\Device\HarddiskVolume1\Program Files\AVG\Framework\Common\avgsvcx.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice Process 2168 (\Device\HarddiskVolume1\Program Files\AVG\Framework\Common\avgsvcx.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice Process 2252 (\Device\HarddiskVolume1\Program Files\McAfee\SiteAdvisor\McSACore.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice Process 3800 (\Device\HarddiskVolume1\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Avg\AWL\Nag Process 2252 (\Device\HarddiskVolume1\Program Files\McAfee\SiteAdvisor\McSACore.exe) has opened key \REGISTRY\USER\S-1-5-21-2805803174-3479283650-3513827087-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice