Hi Dave,
Yes AW_host belongs to PCAnywhere.
Here is the logged event:
8/25/2005 12:12:23 PM Application
Hang Error (101) 1002 N/A HSERVER5 Hanging application rundll32.exe,
version 5.2.3790.0, hang module hungapp, version 0.0.0.0, hang address
0x00000000.
8/24/2005 10:07:26 PM pcAnywhere Error Host
Session 119 N/A HSERVER5 AWHOST.SYS has been disabled.
8/24/2005 10:07:22 PM ESENT Information Logging/Recovery
302 N/A HSERVER5 ntfrs (1384) The database engine has successfully
completed recovery steps.
8/24/2005 10:07:21 PM ESENT Information Logging/Recovery
301 N/A HSERVER5 ntfrs (1384) The database engine has begun replaying
logfile c:\winnt\ntfrs\jet\log\edb.log.
8/24/2005 10:07:20 PM ESENT Information Logging/Recovery
300 N/A HSERVER5 ntfrs (1384) The database engine is initiating
recovery steps.
8/24/2005 10:07:19 PM ESENT Information General
100 N/A HSERVER5 ntfrs (1384) The database engine 5.02.3790.0000
started.
8/24/2005 10:07:19
PM MvWebServer Information None 9 N/A HSERVER5 MvWebServer Service
started.
8/24/2005 10:07:17 PM ESENT Information Logging/Recovery
302 N/A HSERVER5 wins (2168) The database engine has successfully
completed recovery steps.
8/24/2005 10:07:14 PM ESENT Information Logging/Recovery
301 N/A HSERVER5 wins (2168) The database engine has begun replaying
logfile C:\WINNT\system32\wins\j50.log.
8/24/2005 10:07:12 PM ESENT Information Logging/Recovery
300 N/A HSERVER5 wins (2168) The database engine is initiating
recovery steps.
8/24/2005 10:07:12 PM ESENT Information General 100 N/A HSERVER5 wins
(2168) The database engine 5.02.3790.0000 started.
8/24/2005 10:07:06
PM MvServer Information None 9 N/A HSERVER5 MvServer Service started.
8/24/2005 10:07:01 PM Diskeeper Information None 2 N/A HSERVER5 The
Diskeeper Control Center has been started. Diskeeper service started
8/24/2005 10:05:50 PM ccEvtMgr Information None 1 NT
AUTHORITY\SYSTEM HSERVER5 Application started
8/24/2005 10:05:50 PM ccEvtMgr Information None 26 NT
AUTHORITY\SYSTEM HSERVER5 Application starting
8/24/2005 10:05:50 PM ccSetMgr Information None 1 NT
AUTHORITY\SYSTEM HSERVER5 Application started
8/24/2005 10:05:50 PM ccSetMgr Information None 26 NT
AUTHORITY\SYSTEM HSERVER5 Application starting
8/24/2005 10:05:43 PM ESENT Information General 100 N/A HSERVER5
==============
"Dave Patrick" wrote:
> I think AW_host sounds like pcanywhere.
>
> We need to see the complete event viewer message in order to help with that.
> When you view the logged events in Event Viewer (double-click them in the
> right-hand pane) in the upper right corner, third button down is a copy to
> clipboard, then you can paste in the body of a reply message.
>
> Please do so for each of the different System Log events (that are a Type:
> 'Error' or 'Warning') since last boot so we can see all of the event detail.
>
> Also check Device Manager for error codes and or non-starting devices.
>
> You can use this tool to see what process holds the lock.
>
> http://www.sysinternals.com/Utilities/Handle.html
>
> --
> Regards,
>
> Dave Patrick ....Please no email replies - reply in newsgroup.
> Microsoft Certified Professional
> Microsoft MVP [Windows]
> http://www.microsoft.com/protect
>
> "Kinsley" wrote:
> | Hi Dave,
> | I logged in my personal account which is also has Administrative rights.
> I
> | make sure in Task Manager that Administrator account is disconnected and
> | logoff.
> | I try to dele "C:\Documents and Settings\Administrator\Ntuser.dat"
> | It gave "Can Not delet NTUser: It is being used by another person..."
> |
> | I noticed that everytime I cold reboot the server, it also give me the
> | warning" AW_host.sys has been disabled" . I also saw this in the event
> | viewer ID 119.
> |
> | thanks so much Dave,
> | Kinsley.
>
>
>