Windows boot problems

G

Guest

Hi -

I have a problem with windows xp - when I first start up, the task bar at
the bottom of the screen doesn't appear, and I can't start windows explorer
or internet explorer if I go to task manager and try to do a "new task". I
have gone in to "system restore" and tried to restore to previous
checkpoints, but each time i try to do that I get a message saying "unable to
restore to system checkpoint", but no reasons / explanations are given. Any
suggestions for how to troubleshoot this would be greatly appreciated.

This all happened after I was handling some really big files in microsoft
photostory, where it would take the pc several hours to compile and put
together files.

Thanks,
jim
 
D

Dave Patrick

The profile may be corrupt. What happens if you logon as a new user? (create
a new account in 'User Accounts').

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| Hi -
|
| I have a problem with windows xp - when I first start up, the task bar at
| the bottom of the screen doesn't appear, and I can't start windows
explorer
| or internet explorer if I go to task manager and try to do a "new task".
I
| have gone in to "system restore" and tried to restore to previous
| checkpoints, but each time i try to do that I get a message saying "unable
to
| restore to system checkpoint", but no reasons / explanations are given.
Any
| suggestions for how to troubleshoot this would be greatly appreciated.
|
| This all happened after I was handling some really big files in microsoft
| photostory, where it would take the pc several hours to compile and put
| together files.
|
| Thanks,
| jim
 
G

Guest

Thanks for the quick response - when I created a new user, it had the same
symptoms as described below.

When I look at the processes that are running in task manager, it looks like
most of the background processes like anti-virus etc. seem to be running, if
that makes a difference.
 
D

Dave Patrick

What happens when you try to start %systemroot%\explorer.exe ? Also check
Event Viewer for errors. Task Manager|File|New Task
eventvwr.msc

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| Thanks for the quick response - when I created a new user, it had the same
| symptoms as described below.
|
| When I look at the processes that are running in task manager, it looks
like
| most of the background processes like anti-virus etc. seem to be running,
if
| that makes a difference.
|
| --
| jim
 
G

Guest

i'll check that tonight (no access right now), but I'll do that and let you
know what happens. thx again.
 
D

Dave Patrick

OK, sounds good.

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| i'll check that tonight (no access right now), but I'll do that and let
you
| know what happens. thx again.
| --
| jim
 
G

Guest

When I tried to run explorer from %systemroot%\explorer, I get the same
symptoms as before; ie something happens but I don't get any explorer screen
or anything.

Checking the error messages from around when the problem first happened,
this is what I saw:


Date: 4/23/2006
Time: 11:18:11 AM
User: N/A
Computer: YOUR-AT5QGAAC3Z
Description:
The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 800706BA from line 44 of
d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
Microsoft Product Support Services to report this error.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Warning
Event Source: WinMgmt
Event Category: None
Event ID: 63
Date: 4/23/2006
Time: 1:27:01 PM
User: YOUR-AT5QGAAC3Z\Owner
Computer: YOUR-AT5QGAAC3Z
Description:
A provider, OffProv11, has been registered in the WMI namespace,
Root\MSAPPS11, to use the LocalSystem account. This account is privileged
and the provider may cause a security violation if it does not correctly
impersonate user requests.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 4/30/2006
Time: 7:05:16 PM
User: N/A
Computer: YOUR-AT5QGAAC3Z
Description:
Hanging application PhotoStory3.exe, version 3.0.1115.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 50 68 6f 74 6f 53 PhotoS
0018: 74 6f 72 79 33 2e 65 78 tory3.ex
0020: 65 20 33 2e 30 2e 31 31 e 3.0.11
0028: 31 35 2e 30 20 69 6e 20 15.0 in
0030: 68 75 6e 67 61 70 70 20 hungapp
0038: 30 2e 30 2e 30 2e 30 20 0.0.0.0
0040: 61 74 20 6f 66 66 73 65 at offse
0048: 74 20 30 30 30 30 30 30 t 000000
0050: 30 30 00
 
D

Dave Patrick

800706BA = The RPC server is unavailable. No other system log events? What
events led up to this issue?

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| When I tried to run explorer from %systemroot%\explorer, I get the same
| symptoms as before; ie something happens but I don't get any explorer
screen
| or anything.
|
| Checking the error messages from around when the problem first happened,
| this is what I saw:
|
|
| Date: 4/23/2006
| Time: 11:18:11 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BA from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
| Event Type: Warning
| Event Source: WinMgmt
| Event Category: None
| Event ID: 63
| Date: 4/23/2006
| Time: 1:27:01 PM
| User: YOUR-AT5QGAAC3Z\Owner
| Computer: YOUR-AT5QGAAC3Z
| Description:
| A provider, OffProv11, has been registered in the WMI namespace,
| Root\MSAPPS11, to use the LocalSystem account. This account is privileged
| and the provider may cause a security violation if it does not correctly
| impersonate user requests.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
|
| Event Type: Error
| Event Source: Application Hang
| Event Category: (101)
| Event ID: 1002
| Date: 4/30/2006
| Time: 7:05:16 PM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Hanging application PhotoStory3.exe, version 3.0.1115.0, hang module
| hungapp, version 0.0.0.0, hang address 0x00000000.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
| Data:
| 0000: 41 70 70 6c 69 63 61 74 Applicat
| 0008: 69 6f 6e 20 48 61 6e 67 ion Hang
| 0010: 20 20 50 68 6f 74 6f 53 PhotoS
| 0018: 74 6f 72 79 33 2e 65 78 tory3.ex
| 0020: 65 20 33 2e 30 2e 31 31 e 3.0.11
| 0028: 31 35 2e 30 20 69 6e 20 15.0 in
| 0030: 68 75 6e 67 61 70 70 20 hungapp
| 0038: 30 2e 30 2e 30 2e 30 20 0.0.0.0
| 0040: 61 74 20 6f 66 66 73 65 at offse
| 0048: 74 20 30 30 30 30 30 30 t 000000
| 0050: 30 30 00
|
|
| --
| jim
 
G

Guest

I attached more events below. One thing that I remember which is probably
the root cause is that one time when the PC was hanging with no response, I
pressed and held the power button, shutting it down and then rebooted. Is it
possible that I corrupted the registry by doing that? If so is there any way
to recover it?

Here's the event log history; sorry it's so long ...

Event Type: Information
Event Source: McLogEvent
Event Category: None
Event ID: 5000
Date: 4/23/2006
Time: 11:04:35 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
VirusScan McShield service started - scanning for 186639 viruses.
Engine version : 4.4.00
.DAT version : 4739

EXTRA.DAT name : None
Number of virus signatures in EXTRA.DAT : None
Names of viruses that EXTRA.DAT can detect : None


Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 4/23/2006
Time: 11:11:22 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
service was still using the registry during log off. The memory used by the
user's registry has not been freed. The registry will be unloaded when it is
no longer in use.

This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: ccEvtMgr
Event Category: None
Event ID: 26
Date: 4/23/2006
Time: 11:12:16 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
Application starting

Event Type: Information
Event Source: NISUM
Event Category: None
Event ID: 3
Date: 4/23/2006
Time: 11:12:16 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
The service was started.
Event Type: Information
Event Source: SecurityCenter
Event Category: None
Event ID: 1800
Date: 4/23/2006
Time: 11:12:36 AM
User: N/A
Computer: YOUR-AT5QGAAC3Z
Description:
The Windows Security Center Service has started.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: McLogEvent
Event Category: None
Event ID: 5000
Date: 4/23/2006
Time: 11:12:40 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
VirusScan McShield service started - scanning for 186639 viruses.
Engine version : 4.4.00
.DAT version : 4739

EXTRA.DAT name : None
Number of virus signatures in EXTRA.DAT : None
Names of viruses that EXTRA.DAT can detect : None

Event Type: Error
Event Source: EventSystem
Event Category: (50)
Event ID: 4609
Date: 4/23/2006
Time: 11:17:49 AM
User: N/A
Computer: YOUR-AT5QGAAC3Z
Description:
The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 800706BF from line 44 of
d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
Microsoft Product Support Services to report this error.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Error
Event Source: EventSystem
Event Category: (50)
Event ID: 4609
Date: 4/23/2006
Time: 11:18:11 AM
User: N/A
Computer: YOUR-AT5QGAAC3Z
Description:
The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 800706BA from line 44 of
d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
Microsoft Product Support Services to report this error.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: ccEvtMgr
Event Category: None
Event ID: 26
Date: 4/23/2006
Time: 11:20:24 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
Application starting

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 4/23/2006
Time: 11:48:11 AM
User: NT AUTHORITY\SYSTEM
Computer: YOUR-AT5QGAAC3Z
Description:
Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
service was still using the registry during log off. The memory used by the
user's registry has not been freed. The registry will be unloaded when it is
no longer in use.

This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.






--
jim


Dave Patrick said:
800706BA = The RPC server is unavailable. No other system log events? What
events led up to this issue?

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| When I tried to run explorer from %systemroot%\explorer, I get the same
| symptoms as before; ie something happens but I don't get any explorer
screen
| or anything.
|
| Checking the error messages from around when the problem first happened,
| this is what I saw:
|
|
| Date: 4/23/2006
| Time: 11:18:11 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BA from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
| Event Type: Warning
| Event Source: WinMgmt
| Event Category: None
| Event ID: 63
| Date: 4/23/2006
| Time: 1:27:01 PM
| User: YOUR-AT5QGAAC3Z\Owner
| Computer: YOUR-AT5QGAAC3Z
| Description:
| A provider, OffProv11, has been registered in the WMI namespace,
| Root\MSAPPS11, to use the LocalSystem account. This account is privileged
| and the provider may cause a security violation if it does not correctly
| impersonate user requests.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
|
| Event Type: Error
| Event Source: Application Hang
| Event Category: (101)
| Event ID: 1002
| Date: 4/30/2006
| Time: 7:05:16 PM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Hanging application PhotoStory3.exe, version 3.0.1115.0, hang module
| hungapp, version 0.0.0.0, hang address 0x00000000.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
| Data:
| 0000: 41 70 70 6c 69 63 61 74 Applicat
| 0008: 69 6f 6e 20 48 61 6e 67 ion Hang
| 0010: 20 20 50 68 6f 74 6f 53 PhotoS
| 0018: 74 6f 72 79 33 2e 65 78 tory3.ex
| 0020: 65 20 33 2e 30 2e 31 31 e 3.0.11
| 0028: 31 35 2e 30 20 69 6e 20 15.0 in
| 0030: 68 75 6e 67 61 70 70 20 hungapp
| 0038: 30 2e 30 2e 30 2e 30 20 0.0.0.0
| 0040: 61 74 20 6f 66 66 73 65 at offse
| 0048: 74 20 30 30 30 30 30 30 t 000000
| 0050: 30 30 00
|
|
| --
| jim
 
D

Dave Patrick

If you suspect the profile may be corrupt you can try logging as a new user.
(create a new account in 'User Accounts'). I'd guess that something more
than profile corruption is to blame. This tool might help.

http://www.microsoft.com/downloads/...6d-8912-4e18-b570-42470e2f3582&DisplayLang=en

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
|I attached more events below. One thing that I remember which is probably
| the root cause is that one time when the PC was hanging with no response,
I
| pressed and held the power button, shutting it down and then rebooted. Is
it
| possible that I corrupted the registry by doing that? If so is there any
way
| to recover it?
|
| Here's the event log history; sorry it's so long ...
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:04:35 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:11:22 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Information
| Event Source: NISUM
| Event Category: None
| Event ID: 3
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The service was started.
| Event Type: Information
| Event Source: SecurityCenter
| Event Category: None
| Event ID: 1800
| Date: 4/23/2006
| Time: 11:12:36 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The Windows Security Center Service has started.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:12:40 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:17:49 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BF from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:18:11 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BA from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:20:24 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:48:11 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
|
|
|
|
| --
| jim
 
G

Guest

yeah, i did try to create a new user and had the same prob. I'll try the
tool you recommend and see what happens. Thanks Again!
--
jim


Dave Patrick said:
If you suspect the profile may be corrupt you can try logging as a new user.
(create a new account in 'User Accounts'). I'd guess that something more
than profile corruption is to blame. This tool might help.

http://www.microsoft.com/downloads/...6d-8912-4e18-b570-42470e2f3582&DisplayLang=en

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
|I attached more events below. One thing that I remember which is probably
| the root cause is that one time when the PC was hanging with no response,
I
| pressed and held the power button, shutting it down and then rebooted. Is
it
| possible that I corrupted the registry by doing that? If so is there any
way
| to recover it?
|
| Here's the event log history; sorry it's so long ...
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:04:35 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:11:22 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Information
| Event Source: NISUM
| Event Category: None
| Event ID: 3
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The service was started.
| Event Type: Information
| Event Source: SecurityCenter
| Event Category: None
| Event ID: 1800
| Date: 4/23/2006
| Time: 11:12:36 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The Windows Security Center Service has started.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:12:40 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:17:49 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BF from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:18:11 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BA from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:20:24 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:48:11 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
|
|
|
|
| --
| jim
 
G

Guest

Hi - I tried that tool but it didn't report any problems. I ended up taking
the computer in to best buy and they said it looks like we got a virus that
destroyed the restore partition on the drive. I don't know how that happened
since we have mcafee antivirus and spysweeper running and up to date ... On
the other hand, for the longest time it had been hanging when it tried to
install a spysweeper update ...

jim


jim said:
yeah, i did try to create a new user and had the same prob. I'll try the
tool you recommend and see what happens. Thanks Again!
--
jim


Dave Patrick said:
If you suspect the profile may be corrupt you can try logging as a new user.
(create a new account in 'User Accounts'). I'd guess that something more
than profile corruption is to blame. This tool might help.

http://www.microsoft.com/downloads/...6d-8912-4e18-b570-42470e2f3582&DisplayLang=en

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
|I attached more events below. One thing that I remember which is probably
| the root cause is that one time when the PC was hanging with no response,
I
| pressed and held the power button, shutting it down and then rebooted. Is
it
| possible that I corrupted the registry by doing that? If so is there any
way
| to recover it?
|
| Here's the event log history; sorry it's so long ...
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:04:35 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:11:22 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Information
| Event Source: NISUM
| Event Category: None
| Event ID: 3
| Date: 4/23/2006
| Time: 11:12:16 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The service was started.
| Event Type: Information
| Event Source: SecurityCenter
| Event Category: None
| Event ID: 1800
| Date: 4/23/2006
| Time: 11:12:36 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The Windows Security Center Service has started.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: McLogEvent
| Event Category: None
| Event ID: 5000
| Date: 4/23/2006
| Time: 11:12:40 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| VirusScan McShield service started - scanning for 186639 viruses.
| Engine version : 4.4.00
| .DAT version : 4739
|
| EXTRA.DAT name : None
| Number of virus signatures in EXTRA.DAT : None
| Names of viruses that EXTRA.DAT can detect : None
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:17:49 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BF from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Error
| Event Source: EventSystem
| Event Category: (50)
| Event ID: 4609
| Date: 4/23/2006
| Time: 11:18:11 AM
| User: N/A
| Computer: YOUR-AT5QGAAC3Z
| Description:
| The COM+ Event System detected a bad return code during its internal
| processing. HRESULT was 800706BA from line 44 of
| d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact
| Microsoft Product Support Services to report this error.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
| Event Type: Information
| Event Source: ccEvtMgr
| Event Category: None
| Event ID: 26
| Date: 4/23/2006
| Time: 11:20:24 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Application starting
|
| Event Type: Warning
| Event Source: Userenv
| Event Category: None
| Event ID: 1517
| Date: 4/23/2006
| Time: 11:48:11 AM
| User: NT AUTHORITY\SYSTEM
| Computer: YOUR-AT5QGAAC3Z
| Description:
| Windows saved user YOUR-AT5QGAAC3Z\Owner registry while an application or
| service was still using the registry during log off. The memory used by
the
| user's registry has not been freed. The registry will be unloaded when it
is
| no longer in use.
|
| This is often caused by services running as a user account, try
configuring
| the services to run in either the LocalService or NetworkService account.
|
| For more information, see Help and Support Center at
| http://go.microsoft.com/fwlink/events.asp.
|
|
|
|
|
|
| --
| jim
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top