E:\>net helpmsg 2
returns with
The system cannot find the file specified.
The SysmonLog service is the 'Performance Logs and Alerts' service it can't
find or no longer has access to the "Log File Folder" and or the "Current
Log File Name" which are defined in the following key.
Possibly C:\PerfLogs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log
Queries\{SID}
Registry cleaners generally do more damage than good.
--
Regards,
Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect
:
| Event Type: Warning
| Event Source: SysmonLog
| Event Category: None
| Event ID: 2006
| Date: 5/28/2005
| Time: 5:57:20 PM
| User: N/A
| Computer: RCK
| Description:
| Unable to read the Log File Folder value of the new log log or alert
| configuration. The default value will be used. The error code returned
| is in the data.
| Data:
| 0000: 02 00 00 00 ....
| ....
|
|
| Event Type: Warning
| Event Source: SysmonLog
| Event Category: None
| Event ID: 2006
| Date: 5/28/2005
| Time: 5:57:21 PM
| User: N/A
| Computer: RCK
| Description:
| Unable to read the Log File Folder value of the System Overview log or
| alert configuration. The default value will be used. The error code
| returned is in the data.
| Data:
| 0000: 02 00 00 00 ....
|
| >Please do so for each of the different System Log events (that are a
Type:
| >'Error' or 'Warning') since last boot so we can see all of the event
detail.
|
| There's only one kind, but it comes in pairs - as you can see above.
|
| >Tell us about anything that was just installed.
|
| I wish I could recall all the stuff that I have installed and
| uninstalled. I believe Nero OEM was the last thing I installed,
| including something called InCD and Nero Media Player. I have since
| removed all that stuff but the Sysmon warning persists.
|
| Subsequent to experiencing the problem I swabbed the Registry with 5
| different cleaners in the hope of catching a rogue key, but with no
| luck.
|
| >Also check Device Manager
| >for error codes and or non-starting devices.
|
| I have Device Manager open but I can't see where there would be any
| error codes or non-starting devices, other than the some old drivers
| that I have left over from previous use of this OS with other H/W.
|
| If there is a specific place to look, please let me know.
|
| Please keep in mind that I am running Win2K/SP4.
|