Vino's Event Viewer v01c run on Windows 2008 in English Report run at 07/01/2018 4:29:27 PM Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 07/01/2018 9:51:57 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 07/01/2018 7:04:03 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 05/01/2018 10:55:01 PM Type: Error Category: 0 Event: 0 Source: Dell System Detect System.Xml.XmlExceptionUpdateLastUpdatedConfig192.168.0.35 Log: 'Application' Date/Time: 05/01/2018 10:54:12 PM Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application name: SupportAssistUI.exe, version: 1.0.0.0, time stamp: 0x59c4c81e Faulting module name: KERNELBASE.dll, version: 6.1.7601.24000, time stamp: 0x5a4996cd Exception code: 0xe0434352 Fault offset: 0x0000845d Faulting process id: 0x610 Faulting application start time: 0x01d3867818e90c42 Faulting application path: C:\program files\dell\supportassistagent\bin\SupportAssistUI.exe Faulting module path: C:\Windows\system32\KERNELBASE.dll Report Id: 5892fd9d-f26b-11e7-a9d6-001111df457c Log: 'Application' Date/Time: 05/01/2018 10:54:10 PM Type: Error Category: 0 Event: 1026 Source: .NET Runtime Application: SupportAssistUI.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.Globalization.CultureNotFoundException at System.Globalization.CultureInfo..ctor(System.String, Boolean) at Dell.Services.SupportAssist.SupportAssistUI.SplashWindow..ctor() at Dell.Services.SupportAssist.SupportAssistUI.ViewModel.AppViewModel.InitializeSpalashScreen() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() Log: 'Application' Date/Time: 05/01/2018 8:26:32 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 05/01/2018 3:38:07 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 05/01/2018 3:09:31 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 05/01/2018 2:53:06 PM Type: Error Category: 0 Event: 33 Source: SideBySide Activation context generation failed for "F:\KINGSTON\v5.3.7220_reflect_setup_free_x64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.101.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Log: 'Application' Date/Time: 05/01/2018 2:37:34 PM Type: Error Category: 0 Event: 33 Source: SideBySide Activation context generation failed for "C:\Program Files\AVG\Antivirus\setup\iplugins\IStats.dll". Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found. Please use sxstrace.exe for detailed diagnosis. Log: 'Application' Date/Time: 04/01/2018 11:40:27 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 04/01/2018 9:58:36 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 04/01/2018 9:55:24 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 04/01/2018 6:30:20 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Log: 'Application' Date/Time: 04/01/2018 8:19:38 PM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 07/01/2018 7:47:06 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 9 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Process 1256 (\Device\HarddiskVolume2\Program Files\AVG\Antivirus\AVGSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Microsoft\SystemCertificates\Root Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Microsoft\SystemCertificates\CA Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Policies\Microsoft\SystemCertificates Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Policies\Microsoft\SystemCertificates Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1120 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001\Software\Microsoft\SystemCertificates\trust Log: 'Application' Date/Time: 06/01/2018 3:11:31 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 1280 (\Device\HarddiskVolume2\Program Files\AVG\Antivirus\AVGSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Log: 'Application' Date/Time: 05/01/2018 8:23:38 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 1252 (\Device\HarddiskVolume2\Program Files\AVG\Antivirus\AVGSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Log: 'Application' Date/Time: 05/01/2018 3:35:25 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 1276 (\Device\HarddiskVolume2\Program Files\AVG\Antivirus\AVGSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Log: 'Application' Date/Time: 05/01/2018 2:10:30 PM Type: Warning Category: 7 Event: 508 Source: ESENT Catalog Database (1168) Catalog Database: A request to write to the file "C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb" at offset 6959104 (0x00000000006a3000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (51144 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem. Log: 'Application' Date/Time: 05/01/2018 2:10:28 PM Type: Warning Category: 7 Event: 508 Source: ESENT Catalog Database (1168) Catalog Database: A request to write to the file "C:\Windows\system32\CatRoot2\edb.log" at offset 130560 (0x000000000001fe00) for 512 (0x00000200) bytes succeeded, but took an abnormally long time (51144 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem. Log: 'Application' Date/Time: 04/01/2018 11:40:27 PM Type: Warning Category: 0 Event: 63 Source: Microsoft-Windows-WMI A provider, InvProv, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Log: 'Application' Date/Time: 04/01/2018 11:40:27 PM Type: Warning Category: 0 Event: 63 Source: Microsoft-Windows-WMI A provider, InvProv, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Log: 'Application' Date/Time: 04/01/2018 10:46:16 PM Type: Warning Category: 1 Event: 1020 Source: ASP.NET 4.0.30319.0 Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i. Log: 'Application' Date/Time: 04/01/2018 10:38:20 PM Type: Warning Category: 1 Event: 1020 Source: ASP.NET 4.0.30319.0 Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i. Log: 'Application' Date/Time: 04/01/2018 10:34:26 PM Type: Warning Category: 1 Event: 1020 Source: ASP.NET 4.0.30319.0 Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i. Log: 'Application' Date/Time: 04/01/2018 9:57:40 PM Type: Warning Category: 1 Event: 1008 Source: Microsoft-Windows-Search The Windows Search Service is starting up and attempting to remove the old search index {Reason: Application Requested}. Log: 'Application' Date/Time: 04/01/2018 9:56:13 PM Type: Warning Category: 0 Event: 6004 Source: Microsoft-Windows-Winlogon The winlogon notification subscriber failed a critical notification event. Log: 'Application' Date/Time: 04/01/2018 9:47:44 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001_Classes: Process 3020 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001_CLASSES Log: 'Application' Date/Time: 04/01/2018 9:47:41 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 3020 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Log: 'Application' Date/Time: 04/01/2018 7:45:59 PM Type: Warning Category: 1 Event: 1020 Source: ASP.NET 4.0.30319.0 Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i. Log: 'Application' Date/Time: 04/01/2018 6:28:02 PM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3626762363-4290406745-3526105290-1001: Process 468 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3626762363-4290406745-3526105290-1001 Log: 'Application' Date/Time: 04/01/2018 6:20:15 PM Type: Warning Category: 1 Event: 1008 Source: Microsoft-Windows-Search The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}. Log: 'Application' Date/Time: 04/01/2018 6:20:09 PM Type: Warning Category: 0 Event: 11 Source: Microsoft-Windows-RPC-Events Possible Memory Leak. Application (C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted) (PID: 996) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)]. [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked. The call originated on the interface with UUID ({3F31C91E-2545-4B7B-9311-9529E8BFFEF6}), Method number (10). User Action: Contact your application vendor for an updated version of the application.