Gerry said:
Harmon
You really need real time protection against malware / spyware. Does any
of your installed software programmes provide this level of protection?
What are you relying on for a firewall?
For Event Viewer Reports only Errors and Warnings from the Application and
System Logs since the last boot please but check whether any copies
provided also occur in previous session and report so. You often get one
off errors which are not really worth investigation. One of the best cures
to a freeze problem can be simply to close down and restart the computer.
I do not usually investigate reports from the security log but perhaps you
had better include thes on the same basis as for the other two logs.
I have yet to hear of any reports in the Internet Explorer log. It was
introduced with Internet Explorer 7 for a reason that has never to my
knowledge been revealed. This equally applies to Vista.
--
Hope this helps.
Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
AFAIK, Norton offers real time protection. It is also my firewall. Iam also
behind a router.
The programs associated with the empty shortcuts still run and not all
"start-all programs" shortcuts are empty. It appears to be random.
I rebooted into Safe Mood and ran a full scan in Norton, AVG/Ewido/ and
AdAware. Then rebooted. Here are the results from Event Viewer:
Applications
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/19/2007
Time: 1:34:22 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/19/2007
Time: 1:27:38 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/18/2007
Time: 10:49:02 AM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/17/2007
Time: 9:02:04 AM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Application Hang
Event Category: None
Event ID: 1001
Date: 8/16/2007
Time: 5:41:21 PM
User: N/A
Computer: LAKEHOUSE
Description:
Fault bucket 337816799.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 42 75 63 6b 65 74 3a 20 Bucket:
0008: 33 33 37 38 31 36 37 39 33781679
0010: 39 0d 0a 9..
Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 8/16/2007
Time: 5:41:13 PM
User: N/A
Computer: LAKEHOUSE
Description:
Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 77 6d 70 6c 61 79 wmplay
0018: 65 72 2e 65 78 65 20 31 er.exe 1
0020: 31 2e 30 2e 35 37 32 31 1.0.5721
0028: 2e 35 31 34 35 20 69 6e .5145 in
0030: 20 68 75 6e 67 61 70 70 hungapp
0038: 20 30 2e 30 2e 30 2e 30 0.0.0.0
0040: 20 61 74 20 6f 66 66 73 at offs
0048: 65 74 20 30 30 30 30 30 et 00000
0050: 30 30 30 000
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/16/2007
Time: 3:46:54 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/16/2007
Time: 3:13:20 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/16/2007
Time: 12:18:29 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1001
Date: 8/15/2007
Time: 6:00:40 PM
User: N/A
Computer: LAKEHOUSE
Description:
Fault bucket 489648316.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 42 75 63 6b 65 74 3a 20 Bucket:
0008: 34 38 39 36 34 38 33 31 48964831
0010: 36 0d 0a 6..
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 8/15/2007
Time: 6:00:29 PM
User: N/A
Computer: LAKEHOUSE
Description:
Faulting application iexplore.exe, version 7.0.6000.16512, faulting module
nppw.dll, version 2006.1.0.57, fault address 0x00036261.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 35 31 32 00.16512
0030: 20 69 6e 20 6e 70 70 77 in nppw
0038: 2e 64 6c 6c 20 32 30 30 .dll 200
0040: 36 2e 31 2e 30 2e 35 37 6.1.0.57
0048: 20 61 74 20 6f 66 66 73 at offs
0050: 65 74 20 30 30 30 33 36 et 00036
0058: 32 36 31 0d 0a 261..
Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 8/15/2007
Time: 4:23:03 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
Windows saved user LAKEHOUSE\Owner registry while an application or service
was still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
This is often caused by services running as a user account, try configuring
the services to run in either the LocalService or NetworkService account.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: LoadPerf
Event Category: None
Event ID: 2002
Date: 8/15/2007
Time: 7:16:06 AM
User: N/A
Computer: LAKEHOUSE
Description:
The MOF file created for the Outlook service could not be loaded. The error
code returned by the MOF Compiler is contained in the Record Data. Before
the performance counters of this service can be collected by WMI the MOF
file will need to be loaded manually. Contact the vendor of this service for
additional information.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 01 00 00 00 bc 13 00 00 ....¼...
System:
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 6:14:22 PM
User: NT AUTHORITY\SYSTEM
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service EventSystem with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 5:04:34 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 4:44:14 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 4:39:13 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 4:29:46 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 2:57:42 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 2:42:31 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 2:42:30 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 2:23:53 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 8/19/2007
Time: 2:08:52 PM
User: LAKEHOUSE\Owner
Computer: LAKEHOUSE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to
start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 8/19/2007
Time: 1:41:33 PM
User: N/A
Computer: LAKEHOUSE
Description:
The following boot-start or system-start driver(s) failed to load:
AFD
AVG Anti-Spyware Driver
BANTExt
eeCtrl
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
prcmondrv
RasAcd
Rdbss
SPBBCDrv
SRTSPX
SYMTDI
Tcpip
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:41:33 PM
User: N/A
Computer: LAKEHOUSE
Description:
The IPSEC Services service depends on the IPSEC driver service which failed
to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:41:33 PM
User: N/A
Computer: LAKEHOUSE
Description:
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to
start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:41:33 PM
User: N/A
Computer: LAKEHOUSE
Description:
The DNS Client service depends on the TCP/IP Protocol Driver service which
failed to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:41:33 PM
User: N/A
Computer: LAKEHOUSE
Description:
The DHCP Client service depends on the NetBios over Tcpip service which
failed to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 8/19/2007
Time: 1:37:41 PM
User: N/A
Computer: LAKEHOUSE
Description:
The following boot-start or system-start driver(s) failed to load:
AFD
AVG Anti-Spyware Driver
BANTExt
eeCtrl
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
prcmondrv
RasAcd
Rdbss
SPBBCDrv
SRTSPX
SYMTDI
Tcpip
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:37:41 PM
User: N/A
Computer: LAKEHOUSE
Description:
The IPSEC Services service depends on the IPSEC driver service which failed
to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:37:41 PM
User: N/A
Computer: LAKEHOUSE
Description:
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to
start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:37:41 PM
User: N/A
Computer: LAKEHOUSE
Description:
The DNS Client service depends on the TCP/IP Protocol Driver service which
failed to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 8/19/2007
Time: 1:37:41 PM
User: N/A
Computer: LAKEHOUSE
Description:
The DHCP Client service depends on the NetBios over Tcpip service which
failed to start because of the following error:
A device attached to the system is not functioning.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1001
Date: 8/19/2007
Time: 1:27:15 PM
User: N/A
Computer: LAKEHOUSE
Description:
Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0012F084DFC6. The
following error occurred:
The operation was canceled by the user. . Your computer will continue to try
and obtain an address on its own from the network address (DHCP) server.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: c7 04 00 00 Ç...
Event Type: Error
Event Source: atapi
Event Category: None
Event ID: 9
Date: 8/18/2007
Time: 10:58:59 PM
User: N/A
Computer: LAKEHOUSE
Description:
The device, \Device\Ide\IdePort1, did not respond within the timeout period.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 0f 00 50 00 01 00 a4 00 ..P...¤.
0008: 00 00 00 00 09 00 04 c0 .......À
0010: 00 01 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 00 00 00 00 00 00 00 00 ........
0030: 00 00 00 00 07 00 00 00 ........
0038: 40 00 00 0e 00 00 00 00 @.......
0040: 00 00 0c 12 40 01 00 00 ....@...
0048: 00 00 01 00 05 00 00 00 ........
0050: 20 60 90 08 28 7b 08 88 `.({.ˆ
0058: 00 00 00 00 f0 fd 08 88 ....ðý.ˆ
0060: 02 00 00 00 00 00 00 00 ........
0068: a8 00 00 22 13 55 00 00 ¨..".U..
0070: 00 20 00 00 00 00 00 00 . ......
Event Type: Error
Event Source: atapi
Event Category: None
Event ID: 9
Date: 8/18/2007
Time: 10:25:02 PM
User: N/A
Computer: LAKEHOUSE
Description:
The device, \Device\Ide\IdePort1, did not respond within the timeout period.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 0f 00 50 00 01 00 a4 00 ..P...¤.
0008: 00 00 00 00 09 00 04 c0 .......À
0010: 00 01 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 00 00 00 00 00 00 00 00 ........
0030: 00 00 00 00 07 00 00 00 ........
0038: 40 00 00 0e 00 00 00 00 @.......
0040: 00 00 0c 12 40 01 00 00 ....@...
0048: 00 00 01 00 05 00 00 00 ........
0050: 08 b0 a7 08 70 ac 4f 88 .°§.p¬Oˆ
0058: 00 00 00 00 10 4e 0f 88 .....N.ˆ
0060: 02 00 00 00 00 00 00 00 ........
0068: a8 00 00 22 98 83 00 00 ¨.."˜ƒ..
0070: 00 20 00 00 00 00 00 00 . ......
Event Type: Error
Event Source: atapi
Event Category: None
Event ID: 9
Date: 8/18/2007
Time: 10:24:50 PM
User: N/A
Computer: LAKEHOUSE
Description:
The device, \Device\Ide\IdePort1, did not respond within the timeout period.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 0f 00 50 00 01 00 a4 00 ..P...¤.
0008: 00 00 00 00 09 00 04 c0 .......À
0010: 00 01 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
0028: 00 00 00 00 00 00 00 00 ........
0030: 00 00 00 00 07 00 00 00 ........
0038: 40 00 00 0e 00 00 00 00 @.......
0040: 00 00 0c 12 40 01 00 00 ....@...
0048: 00 00 01 00 05 00 00 00 ........
0050: 08 d0 98 08 20 b8 f3 87 .И. ¸ó‡
0058: 00 00 00 00 10 4e 0f 88 .....N.ˆ
0060: 02 00 00 00 00 00 00 00 ........
0068: a8 00 00 22 6b 4c 00 00 ¨.."kL..
0070: 00 20 00 00 00 00 00 00 . ......
There are many more but I tought this was plenty.
Thansk again
Harmon