Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Avast alert CWSinstaller, freezes, only safe mode works


  • Please log in to reply

#31
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Log: 'System' Date/Time: 29/08/2013 22:49:20
Type: Error Category: 0
Event: 5 Source: nvstor32
A parity error was detected on \Device\RaidPort0.


This is ugly. Don't know why Windows insists on setting up a RAID driver when you don't use Raid. You can try and find a newer version of nvstor32.sys and see if that helps. Other people report that reverting back to the Windows drivers solves the problem. I know the Intel RAID driver has a similar problem. Intel claims it is because the SATA drive is not following the specification exactly. There is a registry fix for Intel. Don't know if it would help for nvstor or not.

Let's see if you have an equivalent registry key:

reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32 /s > %userprofile%\desktop\junk.txt
notepad %userprofile%\desktop\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied lines should appear.
Hit Enter. Notepad should open. IF you have any text, copy and paste it in a reply.
  • 0

Advertisements


#32
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts

IF you have any text, copy and paste it in a reply


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32
Type REG_DWORD 0x1
Start REG_DWORD 0x0
ErrorControl REG_DWORD 0x3
Tag REG_DWORD 0x41
ImagePath REG_EXPAND_SZ system32\DRIVERS\nvstor32.sys
Group REG_SZ SCSI Miniport
DisableFilterCache REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32\Parameters
BusType REG_DWORD 0x3

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32\Parameters\PnpInterface
5 REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32\Enum
0 REG_SZ PCI\VEN_10DE&DEV_07F4&SUBSYS_29871019&REV_A2\3&267a616a&0&70
Count REG_DWORD 0x1
NextInstance REG_DWORD 0x1




  • 0

#33
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
The driver is part of the nvidia chipset so see if your PC maker (or motherboard maker if it's home brew) has a new driver for you.

Sometimes it helps to go into Power Options and make sure that turn off hard drive is set to Never.

There is a registry option that I have seen work on some systems:

To try the registry edit:

Copy the text between the lines of stars:

********************************
Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvstor32\Parameters\Port0]
"LPM"=dword:00000000
"LPMDSTATE"=dword:00000000
"DIPM"=dword:00000000

************************

Open Notepad. Paste in the copied text. File, Save As, (to your desktop), "LPMfix.reg" OK. You must have the quotes around LPMfix.reg or it will not work. Close notepad. Right click on LPMfix.reg and Merge. Allow the merge.

Clear alarms and reboot and run VEW again to see if it helped.

Sometimes it just helps to go into Device Manager and uninstall the device. (Probably called AHCI/RAID Controller. Right click on it and select Properties then Driver then Driver Details and look to see if nvstor32.sys is used. If so, Uninstall the driver using the button on the Driver page.) Then Clear alarms and reboot and run VEW again to see if it helped.
  • 0

#34
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
While I am digesting your last post, do you want me to hit the FixMBR button - I still have the program open from last night?
  • 0

#35
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
No need.
  • 0

#36
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts

The driver is part of the nvidia chipset so see if your PC maker (or motherboard maker if it's home brew) has a new driver for you.

Checked - latest driver installed but it doesn't say it's anything to do with RAID??
nvid.jpg


There is a registry option that I have seen work on some systems:

LPMfix.jpg

Clear alarms and reboot and run VEW again to see if it helped.


Vino's Event Viewer v01c run on Windows Vista in English
Report run at 30/08/2013 18:37:58

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Vino's Event Viewer v01c run on Windows Vista in English
Report run at 30/08/2013 18:39:01

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 30/08/2013 17:31:06
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 30/08/2013 17:29:31
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1981138412-3051455907-200072712-1000_Classes:
Process 1676 (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-1981138412-3051455907-200072712-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

I think things look ok? But I am happy to uninstall and reinstall nvstor32.sys provided I have a screen display to work with.
  • 0

#37
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Go back into the same place in Device Manager and click on Port 0 and make a screenshot like you did before. I'm curious what it says.


To uninstall the driver you just click on the Uninstall button and reboot. Windows will automatically reinstall the driver.
  • 0

#38
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts

Go back into the same place in Device Manager and click on Port 0 and make a screenshot like you did before

port0.jpg

I shall now clear the alarms, uninstall and reinstall nvstor.sys, reboot and post the VEW

Edited by UnderSiege, 30 August 2013 - 12:53 PM.

  • 0

#39
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Windows installed one set of drivers and then another set with a system restart on each. After the second restart, a network connection had to be established by using diagnose and repair. Also I have been unable to print anything.

here are the VEW files

Vino's Event Viewer v01c run on Windows Vista in English
Report run at 30/08/2013 20:04:37

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 30/08/2013 18:56:36
Type: Error Category: 0
Event: 54 Source: Microsoft-Windows-PrintSpooler
Document Test Page failed to print and was deleted because of corruption in the spooled file. The associated driver is: Lexmark X543 XL. Try printing the document again.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Vino's Event Viewer v01c run on Windows Vista in English
Report run at 30/08/2013 20:05:51

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 30/08/2013 19:02:52
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 30/08/2013 19:00:02
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 30/08/2013 18:56:53
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




  • 0

#40
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Log: 'System' Date/Time: 30/08/2013 18:56:36
Type: Error Category: 0
Event: 54 Source: Microsoft-Windows-PrintSpooler
Document Test Page failed to print and was deleted because of corruption in the spooled file. The associated driver is: Lexmark X543 XL. Try printing the document again.


Clear and Reset the printer spooler:

http://www.sevenforu...lear-reset.html
  • 0

Advertisements


#41
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts

Clear and Reset the printer spooler:

Ran the batch file ok

Tried to remove the Lex drivers but not allowed by system
lex1.jpg


And following error message event viewer

The document Test Page, owned by Dad, failed to print on printer Lexmark X543 XL. Try to print the document again, or restart the print spooler.

Data type: NT EMF 1.008. Size of the spool file in bytes: 115152. Number of bytes printed: 115092. Total number of pages in the document: 1. Number of pages printed: 1. Client computer: \\DAD-PC. Win32 error code returned by the print processor: 1. Incorrect function.


As an afterthought, before I posted to G2G I tried to set up printing while in safe mode by adding this reg key:

REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpSpooler /VE /T REG_SZ /F /D Service

Would that have casued these printing problems? I can't find that key in the registry so maybe not?

Edited by UnderSiege, 31 August 2013 - 12:07 AM.

  • 0

#42
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
One other piece of possible evidence relating to the printing snag in my previous post was that I had earlier tried to uninstall/reinstall the Lex drivers using the printer server properties when the remove button was enabled, and this is what happened:

lex.jpg

And now the remove button is greyed out. All very curious.

I am sorry about this never-ending string of problems that I keep presenting to you, but I do I think we are very close to resolution.

I won't be able to access my machine until Monday afternoon. Have a good Labour (sic) Day holiday

UnderSiege
  • 0

#43
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
See if you can uninstall your Lexmark software using the Control Panel, Programs and Features. Then download it again and reinstall it.
  • 0

#44
UnderSiege

UnderSiege

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 104 posts
Test page printed successfully :thumbsup:

Unless you have other things you want me to do, then I think we are done, and I would be very happy if you want to close this thread.

Finally Ron, many thanks for your patience, expertise and generosity. Time is a limited and valuable resource, so I am very grateful for the way you unstintingly give of it . I have sent Kwiaht
a donation via Paypal.

best wishes

UnderSiege
  • 0

#45
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Thanks for the donation. I really appreciate it.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP