Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

something causing various problems


  • Please log in to reply

#31
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alg
Description REG_SZ Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall.
Type REG_DWORD 0x10
Start REG_DWORD 0x2
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\System32\alg.exe
DisplayName REG_SZ Application Layer Gateway Service
ObjectName REG_SZ NT AUTHORITY\LocalService

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alg\Security
Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B00000000001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\alg\Enum
0 REG_SZ Root\LEGACY_ALG\0000
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1
[SC] StartService FAILED 1056:

An instance of the service is already running.


These Windows services are started:

Apple Mobile Device
Application Layer Gateway Service
Ati HotKey Poller
Automatic Updates
avast! Antivirus
Background Intelligent Transfer Service
Bonjour Service
COM+ Event System
CryptSvc
DCOM Server Process Launcher
DHCP Client
Distributed Link Tracking Client
DNS Client
Error Reporting Service
Event Log
Fast User Switching Compatibility
Help and Support
HTTP SSL
Infrared Monitor
iPod Service
IPSEC Services
Java Quick Starter
Network Connections
Network Location Awareness (NLA)
Plug and Play
Print Spooler
Protected Storage
Remote Access Connection Manager
Remote Procedure Call (RPC)
Remote Registry
Secondary Logon
Security Accounts Manager
Security Center
Server
Shell Hardware Detection
SSDP Discovery Service
System Event Notification
System Restore Service
Task Scheduler
TCP/IP NetBIOS Helper
Telephony
Terminal Services
Themes
ThinkPad PM Service
WebClient
Windows Audio
Windows Firewall/Internet Connection Sharing (ICS)
Windows Image Acquisition (WIA)
Windows Management Instrumentation
Windows Time
Wireless Zero Configuration
Workstation

The command completed successfully.
  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
It says it is running.

Can you run VEW again as before?

Ron
  • 0

#33
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
VEW System log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 06/05/2011 12:16:02 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/05/2011 1:49:58 PM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.6 for the Network Card with network address 00054E4D2E8E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 05/05/2011 12:12:35 PM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.6 for the Network Card with network address 00054E4D2E8E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 04/05/2011 3:44:26 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Windows Image Acquisition (WIA) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 04/05/2011 3:44:26 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Windows Image Acquisition (WIA) service to connect.

Log: 'System' Date/Time: 04/05/2011 2:59:49 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 04/05/2011 2:59:49 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.

Log: 'System' Date/Time: 04/05/2011 2:58:27 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Windows Image Acquisition (WIA) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 04/05/2011 2:58:27 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Windows Image Acquisition (WIA) service to connect.

Log: 'System' Date/Time: 04/05/2011 2:54:00 PM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.6 for the Network Card with network address 00054E4D2E8E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 04/05/2011 12:45:44 PM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.6 for the Network Card with network address 00054E4D2E8E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 04/05/2011 11:07:47 AM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.6 for the Network Card with network address 00054E4D2E8E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 04/05/2011 2:22:39 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswRdr aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT OADevice oahlpXX OAmon OAnet RasAcd Rdbss Tcpip

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:22:12 AM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

Log: 'System' Date/Time: 04/05/2011 2:21:48 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/05/2011 11:52:45 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.

Log: 'System' Date/Time: 05/05/2011 11:37:13 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 05/05/2011 8:39:36 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 05/05/2011 4:33:01 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 05/05/2011 12:12:40 PM
Type: warning Category: 0
Event: 1005 Source: Dhcp
Your computer has detected that the IP address 192.168.1.114 for the Network Card with network address 00054E4D2E8E is already in use on the network. Your computer will automatically attempt to obtain a different address.

Log: 'System' Date/Time: 04/05/2011 2:00:27 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 2:00:26 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:55:01 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:55:01 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:55:01 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:55:01 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:46:00 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 1:46:00 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Log: 'System' Date/Time: 04/05/2011 12:45:59 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.

Log: 'System' Date/Time: 03/05/2011 8:27:48 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 03/05/2011 5:00:07 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 00054E4D2E8E. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 03/05/2011 2:36:08 AM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 02/05/2011 7:54:43 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 02/05/2011 4:34:54 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.

Log: 'System' Date/Time: 02/05/2011 2:11:57 AM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.


Application log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 06/05/2011 12:20:19 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 04/05/2011 8:44:39 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x03459290.

Log: 'Application' Date/Time: 04/05/2011 8:07:11 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x03959294.

Log: 'Application' Date/Time: 04/05/2011 2:21:28 AM
Type: error Category: 50
Event: 4609 Source: EventSystem
The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Log: 'Application' Date/Time: 03/05/2011 1:15:46 AM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application divxupdate.exe, version 1.0.1.10, faulting module msvcp80.dll, version 8.0.50727.4053, fault address 0x000100b5.

Log: 'Application' Date/Time: 02/05/2011 1:15:44 AM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: This network connection does not exist.

Log: 'Application' Date/Time: 02/05/2011 1:15:43 AM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The connection with the server was terminated abnormally

Log: 'Application' Date/Time: 02/05/2011 1:13:57 AM
Type: error Category: 0
Event: 1001 Source: Application Error
Fault bucket 1783041387.

Log: 'Application' Date/Time: 02/05/2011 1:13:50 AM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application tdsskiller.exe, version 2.4.21.0, faulting module tdsskiller.exe, version 2.4.21.0, fault address 0x00056ec9.

Log: 'Application' Date/Time: 02/05/2011 1:12:30 AM
Type: error Category: 0
Event: 1001 Source: Application Error
Fault bucket -1884773766.

Log: 'Application' Date/Time: 02/05/2011 1:12:02 AM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application svchost.exe, version 5.1.2600.5512, faulting module mshtml.dll, version 6.0.2900.6082, fault address 0x000696ff.

Log: 'Application' Date/Time: 02/05/2011 12:45:00 AM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application tdsskiller.exe, version 2.4.21.0, faulting module tdsskiller.exe, version 2.4.21.0, fault address 0x00056ec9.

Log: 'Application' Date/Time: 02/05/2011 12:43:54 AM
Type: error Category: 0
Event: 1001 Source: Application Error
Fault bucket 1783041387.

Log: 'Application' Date/Time: 02/05/2011 12:43:47 AM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application tdsskiller.exe, version 2.4.21.0, faulting module tdsskiller.exe, version 2.4.21.0, fault address 0x00056ec9.

Log: 'Application' Date/Time: 02/05/2011 12:28:21 AM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: This network connection does not exist.

Log: 'Application' Date/Time: 02/05/2011 12:28:19 AM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The connection with the server was terminated abnormally

Log: 'Application' Date/Time: 01/05/2011 11:47:56 PM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application svchost.exe, version 5.1.2600.5512, faulting module icucnv36.dll, version 3.6.0.0, fault address 0x000013df.

Log: 'Application' Date/Time: 01/05/2011 11:41:38 PM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: This network connection does not exist.

Log: 'Application' Date/Time: 01/05/2011 11:41:35 PM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The connection with the server was terminated abnormally

Log: 'Application' Date/Time: 01/05/2011 11:41:11 PM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: This network connection does not exist.

Log: 'Application' Date/Time: 01/05/2011 11:41:03 PM
Type: error Category: 0
Event: 8 Source: crypt32
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The connection with the server was terminated abnormally

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 01/05/2011 11:16:20 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 01/05/2011 6:22:27 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 28/04/2011 1:11:46 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 28/04/2011 12:06:52 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 08/11/2010 1:40:21 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 04/11/2010 11:27:14 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 04/11/2010 4:21:56 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 04/11/2010 4:14:30 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 04/11/2010 3:58:20 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 19/10/2010 2:34:32 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 18/10/2010 10:59:31 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 18/10/2010 3:25:32 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Log: 'Application' Date/Time: 13/10/2010 4:06:25 AM
Type: warning Category: 0
Event: 1015 Source: MsiInstaller
Failed to connect to server. Error: 0x8007043C

Log: 'Application' Date/Time: 13/10/2010 3:49:29 AM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
  • 0

#34
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
You need to install UPHClean per http://support.micro....com/kb/837115. That should at least fix these errors:
Log: 'Application' Date/Time: 01/05/2011 11:16:20 PM
Type: warning Category: 0
Event: 1517 Source: Userenv
Windows saved user DESERT7210\Primo registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

For these:
Log: 'Application' Date/Time: 04/05/2011 2:21:28 AM
Type: error Category: 50
Event: 4609 Source: EventSystem
The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

See http://support.microsoft.com/kb/909444

For these errors:
Log: 'System' Date/Time: 04/05/2011 2:00:27 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk1\D during a paging operation.

Run the disk check again:
1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Start, Run, eventvwr.msc, OK to bring up the Event Viewer. Right click on System and Clear Log or Clear all Events, No (we don't want to save the old log), OK. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.


Run VEW one more time and let's see what errors you are still getting.

Ron
  • 0

#35
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts

You need to install UPHClean per http://support.micro....com/kb/837115. That should at least fix these errors:

I'm sorry, how do I get to UPHClean?
  • 0

#36
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
Don't know what happened to the link - maybe the period at the end of the sentence threw it off.

http://support.microsoft.com/kb/837115
Actual Download is:
http://www.microsoft...70-42470E2F3582
  • 0

#37
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
VEW System log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 08/05/2011 5:39:45 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 08/05/2011 3:43:34 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.


VEW Application log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 08/05/2011 5:41:08 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 08/05/2011 1:54:02 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application skype.exe, version 5.1.0.112, faulting module mshtml.dll, version 6.0.2900.6082, fault address 0x00072529.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#38
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
Something may be wrong with Skpe so make sure you know your account details then uninstall it and if you use it, download the latest version and reinstall.
http://www.skype.com...mputer/windows/

The other error means "the File and Print Service component was not selected during the initial setup of the server or it has been deselected. " But this is net bios which most people no longer use anyway. You can just ignore it or turn off netbios over TCP:

Windows XP by opening Network Connections, right-clicking a connection, clicking the Internet Protocol (TCP/IP) component, clicking Properties, clicking Advanced, clicking the WINS tab, which should give you this:
Posted Image

and then click on
Disable NetBios over TCP/IP and then OK. Reboot.

Run VEW again and let's see if that caused any new problems.

Ron
  • 0

#39
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
System log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 09/05/2011 2:21:23 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 08/05/2011 9:22:22 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.

Log: 'System' Date/Time: 08/05/2011 3:43:34 PM
Type: warning Category: 0
Event: 2504 Source: Server
The server could not bind to the transport \Device\NetBT_Tcpip_{16432401-DAAC-4CC4-9697-3F210049539E}.

Application log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 09/05/2011 2:22:38 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 09/05/2011 1:17:13 AM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application skype.exe, version 5.1.0.112, faulting module skype.exe, version 5.1.0.112, fault address 0x00a224dc.

Log: 'Application' Date/Time: 09/05/2011 1:17:02 AM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application skype.exe, version 5.1.0.112, faulting module unknown, version 0.0.0.0, fault address 0x00000000.

Log: 'Application' Date/Time: 08/05/2011 1:54:02 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application skype.exe, version 5.1.0.112, faulting module mshtml.dll, version 6.0.2900.6082, fault address 0x00072529.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#40
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
Looks like we are down to just the Skype error. Have you tried uninstalling it and downloading a new version?

Are you seeing any other problems?

Ron

PS Going to bed now.
  • 0

Advertisements


#41
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
Yes, I did uninstall and reinstall Skype. I used Regseeker when uninstalling. No other problems that I notice right now
  • 0

#42
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
You had:
Skype™ 5.1

5.3 is out. Can you verify that you have 5.3 now?

Ron
  • 0

#43
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
Yes, it's 5.3
  • 0

#44
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,206 posts
  • MVP
I would have thought they would have updated the skype.exe from version 5.1.0.112 but I guess not. Don't know what to tell you about Skype. Not something I know a lot about. Does it seem to be working anyway? Is it something you use a lot? Don't suppose you would like to use Google talk or Google voice instead. We use Google voice for all our long distance calls on our land line. Great service and it's free for US calls, $.10/minute for overseas and the other party doesn't need a computer. Google Talk is about the same as Skype. Used for Computer to Computer talk.

There is a Skype forum. Perhaps they can help?
http://forum.skype.c...php?showforum=5
Ron
  • 0

#45
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
Skype has worked just fine for me, haven't noticed any unusual problems. I use it for one purpose only, and that's to video chat with my friend in Wales, so it's the best economic choice for me.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP