Gerry said:
John
What is the status of your computer with regards to
Windows updates? Is SP2 installed?
Download and install the User
Profile Hive Cleanup Service
Download details: User Profile Hive Cleanup Service
http://snipurl.com/5b61
UPHClean v1.5e readme.txt
http://snipurl.com/ko8m
This should fix the Userenv Warning.
Thanks I'll try that.
Please copies of the Error / Warnings in the System / Application
logs.
Some common samples are listed at the end of this post.
What version of Zone Alarm do you have?
5.1 ... something. I have tried newer versions but I always go back to
the old standby as it just works and doesn't give me grief or a bunch of
crap I don't want. The true vector errors are meaningless.
---->> NOTE: Actual computer name and usernames have been munged.
***** From 'Applications' ******
1. True Vector error:
Event Type: Error
Event Source: TrueVector Service
Event Category: None
Event ID: 5009
Date: 12/15/2006
Time: 2:30:54 PM
User: N/A
Computer: ComputerName
Description:
TrueVector engine: Timeout on debug mutex
2. userenv warning ...
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 12/7/2006
Time: 8:56:07 AM
User: NT AUTHORITY\SYSTEM
Computer: ComputerName
Description:
Windows saved user ComputerName\username registry while an application
or service was still using the registry during log off. The memory used
by the user's registry has not been freed. The registry will be unloaded
when it is no longer in use.
This is often caused by services running as a user account, try
configuring the services to run in either the LocalService or
NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
3. The 'rundll.exe error ...
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 12/1/2006
Time: 4:12:01 PM
User: N/A
Computer: ComputerName
Description:
Faulting application rundll32.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x0009cf98.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 72 75 6e ure run
0018: 64 6c 6c 33 32 2e 65 78 dll32.ex
0020: 65 20 35 2e 31 2e 32 36 e 5.1.26
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 75 6e 6b 6e 6f in unkno
0038: 77 6e 20 30 2e 30 2e 30 wn 0.0.0
0040: 2e 30 20 61 74 20 6f 66 .0 at of
0048: 66 73 65 74 20 30 30 30 fset 000
0050: 39 63 66 39 38 0d 0a 9cf98..
***** From 'Security' ******
Nothing listed.
***** From 'System' ******
A common 'DCOM' error ...
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/14/2006
Time: 9:20:09 PM
User: ComputerName\SomeUserName
Computer: ComputerName
Description:
DCOM got error "The service cannot be started, either because it is
disabled or because it has no enabled devices associated with it. "
attempting to start the service StiSvc with arguments "" in order to run
the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
A 'W32Time' error ...
Event Type: Error
Event Source: W32Time
Event Category: None
Event ID: 29
Date: 12/8/2006
Time: 11:31:57 AM
User: N/A
Computer: ComputerName
Description:
The time provider NtpClient is configured to acquire time from one or
more time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 15 minutes. NtpClient
has no source of accurate time.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
A 'Gears' warning, evidently the proggie wasn't completely removed, have
to look at this ...
Event Type: Warning
Event Source: Server
Event Category: None
Event ID: 2511
Date: 12/7/2006
Time: 8:46:49 AM
User: N/A
Computer: ComputerName
Description:
The server service was unable to recreate the share Gears because the
directory I:\Icons\Gears no longer exists. Please run "net share Gears
/delete" to delete the share, or recreate the directory I:\Icons\Gears.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
***** Antivirus *****
Typical error ..
Event Type: Error
Event Source: avast!
Event Category: Client
Event ID: 90
Date: 6/4/2006
Time: 8:43:46 AM
User: N/A
Computer: ComputerName
Description:
AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
J:\Hewlett-Packard_G85_Printer_Software\AiO\hp officejet g
series\1124565543\data\1124565543.ini failed, 0000A474.
Typical warning ...
Event Type: Warning
Event Source: avast!
Event Category: Client
Event ID: 90
Date: 12/11/2006
Time: 7:46:51 PM
User: N/A
Computer: ComputerName
Description:
Sign of "Win32:Torvil [Wrm]" has been found in "Incoming news
(comp.os.linux.advocacy) 'Hello, bjoern.wallat, Hi, bjoern.wallat
here´s the document' From:
<
[email protected]>\24.DOC.pif#3367981176" file.
SomeUserName