Would Like LOG file to Record Shutdown

G

Guest

WXP Pro SP2 Plus all W Security Updates, Norton AV 2006, Office 2003 Nothing
installed recently.
Would someone pls advise how to generate a Log of my Computer's Shutdown.
I'm experiencing 2-3 Min Shutdowns. The Icons disappear and the Desktop
Picture hangs for 2 mins then quickly proceeds through Saved Settings and W
Shutting down screens. I've been on this for 3 days.

Deleted some programs & Acrobat Reader (since reinstalled), PowerToys,
Defragged, Cleaned Registry using JV PwrTools & WRepairPro numerous times
next to nothing appears now. Temp, TIF, Cookies, History,MRU, cleared
nightly using EasyClean. Ad Aware, Spyware Blaster run nightly, Coolswitch
Disabled.
Moved CTFMON.exe to Non Start - wud like to know how to Disable this
program.

One User. No Passwords. No Remote usage. No Network. DSL and Linksys
Wireless Router but haven't connected it to my Laptop yet until I find this
problem and buy a 5.8 Cordless ph.

UPHCLEAN.EXE installed and set to Automatic in Services.
Event Viewer\Application - no Warnings, etc., perfect.
System has 3 IMAPI Event 54 Warnings that appears consistently. IMAPI
Service set to Automatic. Rarely any other Yellow or Red marks.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 6/29/2006
Time: 10:00:38 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be found. The
local computer may not have the necessary registry information or message DLL
files to display messages from a remote computer. You may be able to use the
/AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Any suggestions to correct my shutdowns and how to Disable CTFMON.exe in
case this is the program that's causing the Hang, would be greatly
appreciated. ... Thx Edna.
 
W

Wesley Vogel

Moved CTFMON.exe to Non Start - wud like to know how to Disable this

ctfmon.exe = CTF Loader. Part of Microsoft Office. It activates
the Alternative User Input Text Input Processor (TIP) and the Microsoft
Office XP Language Bar.

When you run a Microsoft Office XP program, the file Ctfmon.exe (Ctfmon)
runs in the background, even after you quit all Office programs.

Ctfmon.exe monitors the active windows and provides text input service
support for speech recognition, handwriting recognition, keyboard,
translation, and other alternative user input technologies.

Can I Remove the Ctfmon.exe File?
http://support.microsoft.com/?kbid=282599#E0LB0ACAAA

Frequently asked questions about Ctfmon.exe
http://support.microsoft.com/kb/282599

HOW TO: Turn Off the Speech Recognition and Handwriting Recognition Features
in Office 2003
http://support.microsoft.com/kb/823586

HOW TO: Turn Off the Speech Recognition and Handwriting Recognition Features
in Office XP
http://support.microsoft.com/kb/326526

ctfmon.exe: This is your "Language Bar." Don't know what it is? I bet you do
not need it. Head to Control Panel -> Regional and Language Options ->
Languages TAB -> Details BUTTON -> Language Bar BUTTON (under
"Preferences") -> select the "Turn off advanced text services" check box.
This little detail will save you between 1.5 MB and 4 MB of RAM. If you are
using a "non-US" version, you may be required to install the English
localization to remove this "feature."
http://web.archive.org/web/20041125021602/www.blackviper.com/WinXP/strangeservice.htm
UPHCLEAN.EXE installed and set to Automatic in Services.

I was going to suggest that you get UPHCLEAN.EXE until I read that.

Rad this to make sure that you have UPHClean set up correctly. There should
be two UPHClean events in the Event Viewer every time you reboot.

UPHClean v1.6d readme.txt
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt


--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 
G

Guest

Hi Wesley, Thx for these references. I hope to get to them tomorrow. I read
on a MVP site that this CTFMON could cause a hang problem. From my limited
reading on it, I don't think I use that program - can u think of any reason
NOT to delete it? I use Outlook all the time but rarely use Word maybe twice
a week.

As to UPHCLEAN I see I have it appearing more often 4 and 5 times with each
boot.

This is another red flag I get although last time 26Jun06.
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 6/26/2006
Time: 8:13:54 AM
User: N/A
Computer: SHARK
Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module
msxml3.dll, version 8.50.2162.0, fault address 0x000304ba.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 32 31 38 30 20 00.2180
0030: 69 6e 20 6d 73 78 6d 6c in msxml
0038: 33 2e 64 6c 6c 20 38 2e 3.dll 8.
0040: 35 30 2e 32 31 36 32 2e 50.2162.
0048: 30 20 61 74 20 6f 66 66 0 at off
0050: 73 65 74 20 30 30 30 33 set 0003
0058: 30 34 62 61 0d 0a 04ba..

This slow shutdown started 14Jun but I couldn't find anything I did that was
out of the ordinary to have caused it. Definitely no downloads and nothing
showing in Event Viewer to give me a clue other than this IMAPI Yellow
warning. What is causing this and can it be "fixed"?
Thx for your informative reply.
 
G

Guest

Hi Wesley, CTFMON.exe is gone Thx to those instructions u sent.
Unfortunately the Hang remains. Thx VM
 
W

Wesley Vogel

Hi Edna,

Check to see if Clear Page File At Shutdown is set to 1.

If ClearPageFileAtShutdown is set to 1, shutdown takes a *long* time.

Check this registry key...
Start | Run | Type: regedit | Click OK |
Navigate to...
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\
Session Manager\Memory Management
Value Name: ClearPageFileAtShutdown
Data Type: REG_DWORD
Value Data: Set to 0

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 
G

Guest

Hi Wes, This sounded like such a good idea but .. it's already set on 0 Darn
it!

Do u know why I'm getting a nbr of Event Viewer\System\IMAPI Warnings. Last
time it was 16.

Also which might give u a clue is a new Warning in Application:
Event Type: Warning
Event Source: SysmonLog
Event Category: None
Event ID: 2006
Date: 7/1/2006
Time: 6:02:41 AM
User: N/A
Computer: SHARK
Description:
Unable to read the Log File Folder value of the System Overview log or alert
configuration. The default value will be used. The error code returned is in
the data.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 02 00 00 00 ....

Geez these kind of aggravations are so time consuming - it could be any file
causing this slow shutdown. I'm plain out of ideas. Whatever it is it's
caused Acronis True Image to seize up for 40 mins before it starts. I
wonder if it could be a setting in Services?

Thx for your Help Wes but keep digging. There must be a solution in your
bag of Fixes.
How about a log file for Shutdown .. is there such a thing? ... Edna
 
W

Wesley Vogel

Edna,

The IMAPI CD-Burning COM Service is for burning CDs. Set it to Disabled or
Manual. If you have 3rd party burning software disable it. Or if using
XP's CD burning capability, disable it unless actually burning a CD.

IMAPI (Image Mastering Applications Programming Interface)

SysmonLog is related to the Alerter and Performance Logs and Alerts
services. I have both Disabled.

Alerter
The Alerter service notifies users of administrative alerts on a network.
This service usually is not required under normal circumstances.
http://web.archive.org/web/20041128020314/www.blackviper.com/WinXP/service411.htm

Alerter
Recommended State Disabled : if you don't need to alert users about system
events over the network.
http://smallvoid.com/tweak/winnt/service/abc.html#ALERTER

Performance Logs and Alerts
Collects performance data from local or remote computers based on
preconfigured schedule parameters, then writes the data to a log or triggers
an alert. If this service is stopped, performance information will not be
collected. If this service is disabled, any services that explicitly depend
on it will fail to start.

Another way to monitor system performance. If the box and network stats
interest you, set this to Manual. If ignorance is bliss, Disabled is the way
to go.
http://www.theeldergeek.com/performance_logs_and_alerts.htm

Performance Logs and Alerts
Collect performance data on a schedule and send the information to a log or
trigger an alert. This may be a super geek tool, but I feel that the
overhead associated with it is not worth the benefit. You decide.
http://web.archive.org/web/20041128020314/www.blackviper.com/WinXP/service411.htm

Have a look at AutoEndTasks

Automatically Ending Hung Applications
http://www.winguides.com/registry/display.php/199/

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 
G

Guest

Hi Wes, I was just checking to see if you had commented on my Reply and I
don't see my Reply. I wonder what I did or what happened to it. It was so
lengthy too and now I don't recall all I told u. Nevertheless, I did enact
all these great suggestions and I do think it knocked off maybe 10 secs max
from the delayed shutdown but it still takes 1-1/2 mins to complete. Meaning
Wes, ya gotta keep thinking! Please!!
Under Event Viewer\Application I don't see any Warnings nor Errors.
Something strange today though, I got 300 yes 300 entries for HHCTRL All
Event 1904 User N/A.

Also there's a regular pattern of the FIRST 4 entries being UPHClean having
to perform in leiu of the actual program closing itself. I'll copy them as
they appear, first to last.

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1412
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
Setup for handle remapping for process explorer.exe (644) failed. Reverting
to closing handle.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

#2
Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
The following handles in user profile hive SHARK\Owner
(S-1-5-21-1060284298-823518204-725345543-1003) have been closed because they
were preventing the profile from unloading successfully:

explorer.exe (644)
HKCU (0x5c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings (0x64)
HKCU\Software\Classes (0x74)
HKCU\Control Panel\MMCPL (0x90)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xa4)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xb4)
HKCU\Software\Classes (0xc4)
HKCU\Software\Classes (0x138)
HKCU\Software\Classes (0x148)
HKCU\Software\Microsoft\Plus!\Themes\Apply (0x154)
HKCU\Software\Classes (0x160)
HKCU\Software\Classes (0x16c)
HKCU\Software\Classes (0x178)
HKCU\Software\Classes (0x1a0)
HKCU\Software\Classes (0x1ac)
HKCU\Software\Classes (0x1e0)
HKCU\Software\Microsoft\Windows\ShellNoRoam (0x1ec)
HKCU\Software\Classes (0x22c)
HKCU\Software\Classes (0x230)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts (0x234)
HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache (0x238)
HKCU\Software\Classes (0x244)
HKCU\Software\Classes (0x24c)
HKCU\Software\Classes (0x258)
HKCU\Software\Microsoft\Windows\Shell (0x25c)
HKCU\Software\Classes (0x260)
HKCU\Software\Classes (0x268)
HKCU\Software\Classes (0x26c)
HKCU\Software\Classes (0x288)
HKCU\Software\Classes (0x28c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(0x294)
HKCU\Software\Classes (0x298)
HKCU\Software\Classes (0x2a8)
HKCU\Software\Classes (0x2b8)
HKCU\Software\Classes (0x2cc)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(0x2d8)
HKCU\Software\Classes (0x2e0)

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count (0x308)

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count (0x310)
HKCU\Software\Classes (0x328)
HKCU\Software\Classes (0x3c0)
HKCU\Software\NVIDIA Corporation\Global\nView\Tweak (0x3c4)
HKCU\Software\Classes (0x3d8)
HKCU\Software\Classes (0x3e0)
HKCU\Software\Classes (0x3e4)
HKCU\Software\Classes (0x3f4)
HKCU\Software\Classes (0x3f8)
HKCU\Software\Classes (0x450)
HKCU\Software\Classes (0x49c)
HKCU\Software\Classes (0x4a4)
HKCU\Software\Classes (0x4b4)
HKCU\Software\Classes (0x4c8)
HKCU\Software\Classes (0x4e4)
HKCU\Software\Classes (0x52c)
HKCU\Software\Classes (0x534)
HKCU\Software\Classes (0x540)
HKCU\Software\Classes (0x55c)
HKCU\Software\Classes (0x564)
HKCU\Software\Classes (0x56c)
HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop (0x590)
HKCU\Software\Classes (0x598)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket (0x59c)
HKCU\Software\Classes (0x5bc)
HKCU\Software\Classes (0x5d0)
HKCU\Software\Classes (0x5fc)
HKCU\Software\Classes (0x664)
HKCU\Software\Classes (0x66c)
HKCU\Software\Classes (0x69c)
HKCU\Software\Classes (0x7c4)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\c (0x7e0)
HKCU\Software\Classes (0x7f0)
HKCU\Software\Classes (0x824)
HKCU\Software\Classes (0x82c)
HKCU\Software\Classes (0x83c)
HKCU\Software\Classes (0x844)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\e (0x864)
HKCU\Software\Classes (0x874)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\d (0x88c)
HKCU\Software\Classes (0x89c)
HKCU\Software\Classes (0x8a4)
HKCU\Software\Classes (0x8ac)
HKCU\Software\Classes (0x8b4)
HKCU\Software\Classes (0x8c0)
HKCU\Software\Classes (0x8cc)
HKCU\Software\Classes (0x8d0)
HKCU\Software\Classes (0x8d8)
HKCU\Software\Classes (0x8dc)
HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop (0x8f0)
HKCU\Software\Classes (0x970)
HKCU\Software\Classes (0x974)
HKCU\Software\Classes (0x980)


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

#3

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
The following handles in user profile hive SHARK\Owner
(S-1-5-21-1060284298-823518204-725345543-1003) have been remapped because
they were preventing the profile from unloading successfully:

svchost.exe (1224)
HKCU (0x238)


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

#4
Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1010
Date: 7/8/2006
Time: 5:31:06 PM
User: N/A
Computer: SHARK
Description:
User profile hive cleanup service stopped successfully.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Under System, I don't get any Errors or Warnings other than 3 IMAPI
Warnings.
My Gosh this is so lengthy! Maybe this too won't reach the Forum. Sorry
about this if I've posted something that's unacceptable. ... Edna.
 
W

Wesley Vogel

Edna,

Your original post said 2 - 3 minute shutdowns. How long did shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be
able to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code execution
http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping did not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed because
they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201 logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic card.

I have all of this NVIDIA crap disabled and suggest that you do the same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock rate and
memory speed for nVidia based graphics cards. This is unnecessary since you
can easily configure these settings the way you want them in the Display
Properties and not have to mess with them again. Also disable the "NVIDIA
Driver Helper Service" if enabled as it can cause this entry to be
re-enabled on re-boot (note that this service can also cause extreme
shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a desktop
larger than the viewable area of the monitor, being able to divide the
display across more than one monitor, managing applications and many more
functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 
G

Guest

Wes I'm so sorry time didn't permit me to respond as I should have and wanted
very much to do. I came here so often to continue and something else would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find now that
the only Warning I'm getting with any regularity is the IMAPI Warning but
it's prolific. I'm talking 15 - 20 entries at once. Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be found. The
local computer may not have the necessary registry information or message DLL
files to display messages from a remote computer. You may be able to use the
/AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or Manual
doesn't make any difference. Obviously I don't need it as it doesn't start
itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've tried but
can't pin down what I'm doing that causes it to go into a multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split. Maybe
it was Norton, maybe not, but it's so nice not to have to wait when shutting
down.
I've used Norton for years but recently I got hit with some Pest thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept my
apology. My failure to reply wasn't by choice. ...

Wesley Vogel said:
Edna,

Your original post said 2 - 3 minute shutdowns. How long did shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be
able to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code execution
http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping did not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed because
they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201 logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic card.

I have all of this NVIDIA crap disabled and suggest that you do the same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock rate and
memory speed for nVidia based graphics cards. This is unnecessary since you
can easily configure these settings the way you want them in the Display
Properties and not have to mess with them again. Also disable the "NVIDIA
Driver Helper Service" if enabled as it can cause this entry to be
re-enabled on re-boot (note that this service can also cause extreme
shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a desktop
larger than the viewable area of the monitor, being able to divide the
display across more than one monitor, managing applications and many more
functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Wes, I was just checking to see if you had commented on my Reply and I
don't see my Reply. I wonder what I did or what happened to it. It was
so
lengthy too and now I don't recall all I told u. Nevertheless, I did
enact
all these great suggestions and I do think it knocked off maybe 10 secs
max
from the delayed shutdown but it still takes 1-1/2 mins to complete.
Meaning
Wes, ya gotta keep thinking! Please!!
Under Event Viewer\Application I don't see any Warnings nor Errors.
Something strange today though, I got 300 yes 300 entries for HHCTRL All
Event 1904 User N/A.

Also there's a regular pattern of the FIRST 4 entries being UPHClean
having
to perform in leiu of the actual program closing itself. I'll copy them
as
they appear, first to last.

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1412
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
Setup for handle remapping for process explorer.exe (644) failed.
Reverting
to closing handle.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

#2
Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
The following handles in user profile hive SHARK\Owner
(S-1-5-21-1060284298-823518204-725345543-1003) have been closed because
they
were preventing the profile from unloading successfully:

explorer.exe (644)
HKCU (0x5c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings (0x64)
HKCU\Software\Classes (0x74)
HKCU\Control Panel\MMCPL (0x90)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xa4)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xb4)
HKCU\Software\Classes (0xc4)
HKCU\Software\Classes (0x138)
HKCU\Software\Classes (0x148)
HKCU\Software\Microsoft\Plus!\Themes\Apply (0x154)
HKCU\Software\Classes (0x160)
HKCU\Software\Classes (0x16c)
HKCU\Software\Classes (0x178)
HKCU\Software\Classes (0x1a0)
HKCU\Software\Classes (0x1ac)
HKCU\Software\Classes (0x1e0)
HKCU\Software\Microsoft\Windows\ShellNoRoam (0x1ec)
HKCU\Software\Classes (0x22c)
HKCU\Software\Classes (0x230)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts (0x234)
HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache (0x238)
HKCU\Software\Classes (0x244)
HKCU\Software\Classes (0x24c)
HKCU\Software\Classes (0x258)
HKCU\Software\Microsoft\Windows\Shell (0x25c)
HKCU\Software\Classes (0x260)
HKCU\Software\Classes (0x268)
HKCU\Software\Classes (0x26c)
HKCU\Software\Classes (0x288)
HKCU\Software\Classes (0x28c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
(0x294)
HKCU\Software\Classes (0x298)
HKCU\Software\Classes (0x2a8)
HKCU\Software\Classes (0x2b8)
HKCU\Software\Classes (0x2cc)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
(0x2d8)
HKCU\Software\Classes (0x2e0)

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780
-7743-11CF-A12B-00AA004AE837}\Count
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700
-EF1F-11D0-9888-006097DEACF9}\Count
(0x310) HKCU\Software\Classes (0x328)
HKCU\Software\Classes (0x3c0)
HKCU\Software\NVIDIA Corporation\Global\nView\Tweak (0x3c4)
HKCU\Software\Classes (0x3d8)
HKCU\Software\Classes (0x3e0)
HKCU\Software\Classes (0x3e4)
HKCU\Software\Classes (0x3f4)
HKCU\Software\Classes (0x3f8)
HKCU\Software\Classes (0x450)
HKCU\Software\Classes (0x49c)
HKCU\Software\Classes (0x4a4)
HKCU\Software\Classes (0x4b4)
HKCU\Software\Classes (0x4c8)
HKCU\Software\Classes (0x4e4)
HKCU\Software\Classes (0x52c)
HKCU\Software\Classes (0x534)
HKCU\Software\Classes (0x540)
HKCU\Software\Classes (0x55c)
HKCU\Software\Classes (0x564)
HKCU\Software\Classes (0x56c)
HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop (0x590)
HKCU\Software\Classes (0x598)
 
G

Gerry Cornell

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Edna said:
Wes I'm so sorry time didn't permit me to respond as I should have and
wanted
very much to do. I came here so often to continue and something else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find now
that
the only Warning I'm getting with any regularity is the IMAPI Warning but
it's prolific. I'm talking 15 - 20 entries at once. Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be found.
The
local computer may not have the necessary registry information or message
DLL
files to display messages from a remote computer. You may be able to use
the
/AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or Manual
doesn't make any difference. Obviously I don't need it as it doesn't start
itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've tried but
can't pin down what I'm doing that causes it to go into a multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest thingie.
I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept my
apology. My failure to reply wasn't by choice. ...

Wesley Vogel said:
Edna,

Your original post said 2 - 3 minute shutdowns. How long did shutdown
take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be
found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be
able to use the /AUXSOURCE= flag to retrieve this description; see Help
and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code execution
http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping did
not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed because
they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201 logged
you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic card.

I have all of this NVIDIA crap disabled and suggest that you do the same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock rate
and
memory speed for nVidia based graphics cards. This is unnecessary since
you
can easily configure these settings the way you want them in the Display
Properties and not have to mess with them again. Also disable the "NVIDIA
Driver Helper Service" if enabled as it can cause this entry to be
re-enabled on re-boot (note that this service can also cause extreme
shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to
manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a desktop
larger than the viewable area of the monitor, being able to divide the
display across more than one monitor, managing applications and many more
functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Wes, I was just checking to see if you had commented on my Reply and
I
don't see my Reply. I wonder what I did or what happened to it. It
was
so
lengthy too and now I don't recall all I told u. Nevertheless, I did
enact
all these great suggestions and I do think it knocked off maybe 10 secs
max
from the delayed shutdown but it still takes 1-1/2 mins to complete.
Meaning
Wes, ya gotta keep thinking! Please!!
Under Event Viewer\Application I don't see any Warnings nor Errors.
Something strange today though, I got 300 yes 300 entries for HHCTRL
All
Event 1904 User N/A.

Also there's a regular pattern of the FIRST 4 entries being UPHClean
having
to perform in leiu of the actual program closing itself. I'll copy
them
as
they appear, first to last.

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1412
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
Setup for handle remapping for process explorer.exe (644) failed.
Reverting
to closing handle.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

#2
Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
The following handles in user profile hive SHARK\Owner
(S-1-5-21-1060284298-823518204-725345543-1003) have been closed because
they
were preventing the profile from unloading successfully:

explorer.exe (644)
HKCU (0x5c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
(0x64)
HKCU\Software\Classes (0x74)
HKCU\Control Panel\MMCPL (0x90)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xa4)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer (0xb4)
HKCU\Software\Classes (0xc4)
HKCU\Software\Classes (0x138)
HKCU\Software\Classes (0x148)
HKCU\Software\Microsoft\Plus!\Themes\Apply (0x154)
HKCU\Software\Classes (0x160)
HKCU\Software\Classes (0x16c)
HKCU\Software\Classes (0x178)
HKCU\Software\Classes (0x1a0)
HKCU\Software\Classes (0x1ac)
HKCU\Software\Classes (0x1e0)
HKCU\Software\Microsoft\Windows\ShellNoRoam (0x1ec)
HKCU\Software\Classes (0x22c)
HKCU\Software\Classes (0x230)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
(0x234)
HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache (0x238)
HKCU\Software\Classes (0x244)
HKCU\Software\Classes (0x24c)
HKCU\Software\Classes (0x258)
HKCU\Software\Microsoft\Windows\Shell (0x25c)
HKCU\Software\Classes (0x260)
HKCU\Software\Classes (0x268)
HKCU\Software\Classes (0x26c)
HKCU\Software\Classes (0x288)
HKCU\Software\Classes (0x28c)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Blocked
(0x294)
HKCU\Software\Classes (0x298)
HKCU\Software\Classes (0x2a8)
HKCU\Software\Classes (0x2b8)
HKCU\Software\Classes (0x2cc)
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Cached
(0x2d8)
HKCU\Software\Classes (0x2e0)

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780
-7743-11CF-A12B-00AA004AE837}\Count
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700
-EF1F-11D0-9888-006097DEACF9}\Count
(0x310) HKCU\Software\Classes (0x328)
HKCU\Software\Classes (0x3c0)
HKCU\Software\NVIDIA Corporation\Global\nView\Tweak (0x3c4)
HKCU\Software\Classes (0x3d8)
HKCU\Software\Classes (0x3e0)
HKCU\Software\Classes (0x3e4)
HKCU\Software\Classes (0x3f4)
HKCU\Software\Classes (0x3f8)
HKCU\Software\Classes (0x450)
HKCU\Software\Classes (0x49c)
HKCU\Software\Classes (0x4a4)
HKCU\Software\Classes (0x4b4)
HKCU\Software\Classes (0x4c8)
HKCU\Software\Classes (0x4e4)
HKCU\Software\Classes (0x52c)
HKCU\Software\Classes (0x534)
HKCU\Software\Classes (0x540)
HKCU\Software\Classes (0x55c)
HKCU\Software\Classes (0x564)
HKCU\Software\Classes (0x56c)
HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop (0x590)
HKCU\Software\Classes (0x598)
 
W

Wesley Vogel

Disable the IMAPI CD-Burning COM Service. It is only needed when using XP's
inbuilt CD burning application. If you use any 3rd party CD burning
software, IMAPI.EXE does not need to run, ever. It can cause conflicts. I
have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio but
after reading comments on Roxio causing hangs, which I was experiencing,
I removed it thoroughly, every reg entry. I was planning, within hours,
to buy the new Nero.

Something possibly relevant I noticed the other night: I bought Acronis
V10 the True Image program, I have to wait 40 mins for it to get through
a hang before it starts. I've completed a Report for the Acronis Techs
but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related. Maybe
not but I recently noticed I got an IMAPI Warning at the very same time I
started Acronis. More work required as I couldn't immediately repeat it.

Now, to answer your question: Yes! LOL ...


Gerry Cornell said:
Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Edna said:
Wes I'm so sorry time didn't permit me to respond as I should have and
wanted
very much to do. I came here so often to continue and something else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find now
that
the only Warning I'm getting with any regularity is the IMAPI Warning
but it's prolific. I'm talking 15 - 20 entries at once. Once I
counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be found.
The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able to use
the
/AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or Manual
doesn't make any difference. Obviously I don't need it as it doesn't
start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've tried
but can't pin down what I'm doing that causes it to go into a multiple
spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept my
apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did shutdown
take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be
found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may
be able to use the /AUXSOURCE= flag to retrieve this description; see
Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping did
not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201 logged
you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user
hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary since
you
can easily configure these settings the way you want them in the
Display Properties and not have to mess with them again. Also disable
the "NVIDIA Driver Helper Service" if enabled as it can cause this
entry to be re-enabled on re-boot (note that this service can also
cause extreme shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to
manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a desktop
larger than the viewable area of the monitor, being able to divide the
display across more than one monitor, managing applications and many
more functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Wes, I was just checking to see if you had commented on my Reply
and I
don't see my Reply. I wonder what I did or what happened to it. It
was
so
lengthy too and now I don't recall all I told u. Nevertheless, I did
enact
all these great suggestions and I do think it knocked off maybe 10
secs max
from the delayed shutdown but it still takes 1-1/2 mins to complete.
Meaning
Wes, ya gotta keep thinking! Please!!
Under Event Viewer\Application I don't see any Warnings nor Errors.
Something strange today though, I got 300 yes 300 entries for HHCTRL
All
Event 1904 User N/A.

Also there's a regular pattern of the FIRST 4 entries being UPHClean
having
to perform in leiu of the actual program closing itself. I'll copy
them
as
they appear, first to last.

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1412
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
Setup for handle remapping for process explorer.exe (644) failed.
Reverting
to closing handle.
 
G

Gerry Cornell

Edna

Go with Wes. He knows more than I. Please post back to say whether the Event
ID 54 errors stop.

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~

Wesley Vogel said:
Disable the IMAPI CD-Burning COM Service. It is only needed when using
XP's
inbuilt CD burning application. If you use any 3rd party CD burning
software, IMAPI.EXE does not need to run, ever. It can cause conflicts.
I
have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio but
after reading comments on Roxio causing hangs, which I was experiencing,
I removed it thoroughly, every reg entry. I was planning, within hours,
to buy the new Nero.

Something possibly relevant I noticed the other night: I bought Acronis
V10 the True Image program, I have to wait 40 mins for it to get through
a hang before it starts. I've completed a Report for the Acronis Techs
but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related. Maybe
not but I recently noticed I got an IMAPI Warning at the very same time I
started Acronis. More work required as I couldn't immediately repeat it.

Now, to answer your question: Yes! LOL ...


Gerry Cornell said:
Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have and
wanted
very much to do. I came here so often to continue and something else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find now
that
the only Warning I'm getting with any regularity is the IMAPI Warning
but it's prolific. I'm talking 15 - 20 entries at once. Once I
counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found.
The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able to
use
the
/AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual
doesn't make any difference. Obviously I don't need it as it doesn't
start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've tried
but can't pin down what I'm doing that causes it to go into a multiple
spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept my
apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did shutdown
take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be
found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may
be able to use the /AUXSOURCE= flag to retrieve this description; see
Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping
did
not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201 logged
you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user
hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since
you
can easily configure these settings the way you want them in the
Display Properties and not have to mess with them again. Also disable
the "NVIDIA Driver Helper Service" if enabled as it can cause this
entry to be re-enabled on re-boot (note that this service can also
cause extreme shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to
manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a
desktop
larger than the viewable area of the monitor, being able to divide the
display across more than one monitor, managing applications and many
more functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE
C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Wes, I was just checking to see if you had commented on my Reply
and I
don't see my Reply. I wonder what I did or what happened to it. It
was
so
lengthy too and now I don't recall all I told u. Nevertheless, I did
enact
all these great suggestions and I do think it knocked off maybe 10
secs max
from the delayed shutdown but it still takes 1-1/2 mins to complete.
Meaning
Wes, ya gotta keep thinking! Please!!
Under Event Viewer\Application I don't see any Warnings nor Errors.
Something strange today though, I got 300 yes 300 entries for HHCTRL
All
Event 1904 User N/A.

Also there's a regular pattern of the FIRST 4 entries being UPHClean
having
to perform in leiu of the actual program closing itself. I'll copy
them
as
they appear, first to last.

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1412
Date: 7/8/2006
Time: 5:31:05 PM
User: SHARK\Owner
Computer: SHARK
Description:
Setup for handle remapping for process explorer.exe (644) failed.
Reverting
to closing handle.
 
W

Wesley Vogel

Edna,

You also have to use your own judgment. Sometimes you have to mess around
and see why something doesn't work because you disabled a particular
service.

A few examples. If you disable LanmanWorkstation (Workstation service),
Local Users and Groups (lusrmgr.msc) in MMC doesn't work right. Or if
Terminal Services is disabled you do not see any names in the User Name
column in Task Manager. Or if you disable the Indexing Service, your
machine runs better. Or if you disable the DHCP Client service you cannot
get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/

http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm

[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default settings
for Services listed in Help & Support are still wrong. I've gotten these
settings by doing a fresh install of both XP Home and Pro and exporting the
Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services
http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Wes! I've just disabled IMAPI. I didn't know that and never would
have thought to Disable it. I've had it on every other setting except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can refer
to as to suggestions for these Settings. I read the explanations for
these Services and many go right over my head. Between my girlfriend and
I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

Wesley Vogel said:
Disable the IMAPI CD-Burning COM Service. It is only needed when using
XP's inbuilt CD burning application. If you use any 3rd party CD burning
software, IMAPI.EXE does not need to run, ever. It can cause conflicts.
I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio but
after reading comments on Roxio causing hangs, which I was experiencing,
I removed it thoroughly, every reg entry. I was planning, within hours,
to buy the new Nero.

Something possibly relevant I noticed the other night: I bought Acronis
V10 the True Image program, I have to wait 40 mins for it to get through
a hang before it starts. I've completed a Report for the Acronis Techs
but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related. Maybe
not but I recently noticed I got an IMAPI Warning at the very same time
I started Acronis. More work required as I couldn't immediately repeat
it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have and
wanted
very much to do. I came here so often to continue and something else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find now
that
the only Warning I'm getting with any regularity is the IMAPI Warning
but it's prolific. I'm talking 15 - 20 entries at once. Once I
counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able to
use the
/AUXSOURCE= flag to retrieve this description; see Help and Support
for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as it
doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've tried
but can't pin down what I'm doing that causes it to go into a multiple
spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be
found.
The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may
be able to use the /AUXSOURCE= flag to retrieve this description; see
Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping
did not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt
-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user
hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since you
can easily configure these settings the way you want them in the
Display Properties and not have to mess with them again. Also disable
the "NVIDIA Driver Helper Service" if enabled as it can cause this
entry to be re-enabled on re-boot (note that this service can also
cause extreme shutdown delays if enabled ]
http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150
NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to
manage
settings for nVidia based graphics cards. May be required for some 3D
applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a
desktop larger than the viewable area of the monitor, being able to
divide the display across more than one monitor, managing
applications and many more functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvMediaCenter
Value Type: REG_SZ
Value Data: RUNDLL32.EXE
C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: nwiz
Value Type: REG_SZ
Value Data: nwiz.exe /install
-----

Download and install ShellExView (shexview.exe)...

ShellExView download
http://www.snapfiles.com/get/shellexview.html

Open ShellExView and disable the Nvidia right click Menu entries.
These five entries...
Extension Name: Desktop Explorer
Extension Name: Desktop Explorer Menu
Extension Name: DesktopContext Class
Extension Name: NVIDIA CPL Extension
Extension Name: nView Desktop Context Menu
 
W

Wesley Vogel

The description for Event ID ( 54 ) in Source ( Imapi ) cannot be found. The
local computer may not have the necessary registry information or message
DLL files to display messages from a remote computer. You may be able to use
the /AUXSOURCE= flag to retrieve this description; see Help and Support for
details. The following information is part of the event:

I usually ignore these types of errors.

This means that imapi.exe does not have any info to send to the Event Viewer
or not enough info. So the Event Viewer shows a message like above and just
confuses most people. It would confuse me also, but I ignore them. ;-)

In my opinion, this is a waste of time, but here ya go.

Detailed Usage of the Event Viewer /AUXSOURCE Switch Option
http://support.microsoft.com/kb/312216

You can only use the /auxsource switch if you are running Event Viewer on a
Windows XP Professional or Windows XP Server-based computer.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Yeah ... he does tend to give u that impression! We'll see how he grades
on this last suggestion. LOL
But Gerry, I'm interested in learning of your theory. It may be
something I can watch for. Come'n share it with me. ...

Gerry Cornell said:
Edna

Go with Wes. He knows more than I. Please post back to say whether the
Event ID 54 errors stop.

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~

Wesley Vogel said:
Disable the IMAPI CD-Burning COM Service. It is only needed when using
XP's
inbuilt CD burning application. If you use any 3rd party CD burning
software, IMAPI.EXE does not need to run, ever. It can cause conflicts.
I
have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio but
after reading comments on Roxio causing hangs, which I was
experiencing, I removed it thoroughly, every reg entry. I was
planning, within hours, to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis V10 the True Image program, I have to wait 40 mins for it to
get through a hang before it starts. I've completed a Report for the
Acronis Techs but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe not but I recently noticed I got an IMAPI Warning at the very
same time I started Acronis. More work required as I couldn't
immediately repeat it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have
and wanted
very much to do. I came here so often to continue and something else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find
now that
the only Warning I'm getting with any regularity is the IMAPI Warning
but it's prolific. I'm talking 15 - 20 entries at once. Once I
counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found.
The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able to
use
the
/AUXSOURCE= flag to retrieve this description; see Help and Support
for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual
doesn't make any difference. Obviously I don't need it as it doesn't
start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried but can't pin down what I'm doing that causes it to go into a
multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due to
a Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot be
found.
The local computer may not have the necessary registry information
or message DLL files to display messages from a remote computer.
You may be able to use the /AUXSOURCE= flag to retrieve this
description; see Help and
Support for details. The following information is part of the event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping
did
not
work, so it tried closing handle the handle.

The following are from:

http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive by
remapping the handles to the user profile hive to the default user
hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button |
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since
you
can easily configure these settings the way you want them in the
Display Properties and not have to mess with them again. Also
disable the "NVIDIA Driver Helper Service" if enabled as it can
cause this entry to be re-enabled on re-boot (note that this
service can also cause extreme shutdown delays if enabled ]

http://www.sysinfo.org/startuplist.php?letter=R&filter=&count=50&offset=150

NvMediaCenter
[[RunDLL32.exe NvMCTray.dll, NvTaskbarInit System Tray icon used to
manage
settings for nVidia based graphics cards. May be required for some
3D applications to recognize your card correctly - such as the game
"Everquest". Otherwise, settings can be changed manually via Display
Properties]]

nwiz.exe = NVIDIA nView Wizard
[[Application enables user to having 32 virtual desktops, get a
desktop
larger than the viewable area of the monitor, being able to divide
the display across more than one monitor, managing applications and
many more functionality.]]
-----

Manually delete these three entries:
NvCplDaemon, NvMediaCenter and nwiz.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Type: REG_SZ
Value Data: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 
G

Gerry Cornell

Edna

The default is disabled.
http://www.theeldergeek.com/hid_input_service.htm

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~

Edna said:
Wes I just shut down and one only IMAPI Warning appeared.
Question: IMAPI Properties, Logon Tab, under Hardware Profile I've got
Profile 1 Enabled. Shouldn't that that too be Disabled?

While I have your attn: Only One more I'm getting and have been getting
since the computer was put together is:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 05/12/2006
Time: 3:10:59 PM
User: N/A
Computer: SHARK
Description:
The HID Input Service service terminated with the following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I have HID Input Service on Automatic but I see it's not Started.
General Tab, Service Status shows Stopped. Profile 1 is Enabled.

I did have a Logitech Wireless Mouse installed by I'm back to my old MS
Mouse.
I've got a Linksys Wireless Router and DSL. I haven't got my Laptop on
the
router yet.
Creative Speakers and I don't use any hot buttons.
That description makes ME think there's a file missing. How would u ever
find out which file? Any ideas. Thx ...

Wesley Vogel said:
Edna,

You also have to use your own judgment. Sometimes you have to mess
around
and see why something doesn't work because you disabled a particular
service.

A few examples. If you disable LanmanWorkstation (Workstation service),
Local Users and Groups (lusrmgr.msc) in MMC doesn't work right. Or if
Terminal Services is disabled you do not see any names in the User Name
column in Task Manager. Or if you disable the Indexing Service, your
machine runs better. Or if you disable the DHCP Client service you
cannot
get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/

http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm

[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default
settings
for Services listed in Help & Support are still wrong. I've gotten these
settings by doing a fresh install of both XP Home and Pro and exporting
the
Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services
http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Wes! I've just disabled IMAPI. I didn't know that and never would
have thought to Disable it. I've had it on every other setting except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can
refer
to as to suggestions for these Settings. I read the explanations for
these Services and many go right over my head. Between my girlfriend
and
I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

:

Disable the IMAPI CD-Burning COM Service. It is only needed when
using
XP's inbuilt CD burning application. If you use any 3rd party CD
burning
software, IMAPI.EXE does not need to run, ever. It can cause
conflicts.
I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus
P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio
but
after reading comments on Roxio causing hangs, which I was
experiencing,
I removed it thoroughly, every reg entry. I was planning, within
hours,
to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis
V10 the True Image program, I have to wait 40 mins for it to get
through
a hang before it starts. I've completed a Report for the Acronis
Techs
but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe
not but I recently noticed I got an IMAPI Warning at the very same
time
I started Acronis. More work required as I couldn't immediately
repeat
it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have
and
wanted
very much to do. I came here so often to continue and something
else
would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find
now
that
the only Warning I'm getting with any regularity is the IMAPI
Warning
but it's prolific. I'm talking 15 - 20 entries at once. Once I
counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able
to
use the
/AUXSOURCE= flag to retrieve this description; see Help and Support
for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..ââ?s¬
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as it
doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any
difference.
I think I'll put it back on Manual and leave it in the Stopped
mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried
but can't pin down what I'm doing that causes it to go into a
multiple
spin.

Oh BTW since abandoning Norton, my shut downs are now lickety
split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls
accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due
to a
Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot
be
found.
The local computer may not have the necessary registry information
or
message DLL files to display messages from a remote computer. You
may
be able to use the /AUXSOURCE= flag to retrieve this description;
see
Help and
Support for details. The following information is part of the
event:
res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle
remapping
did not
work, so it tried closing handle the handle.

The following are from:

http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that
were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive
by
remapping the handles to the user profile hive to the default user
hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event
Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a
graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do
the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button
|
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the
clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since you
 
W

Wesley Vogel

Human Interface Device Access is the Display Name for HidServ (Service
Name).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\HidServ\Parameters
sez: ServiceDll = %SystemRoot%\System32\hidserv.dll
hidserv.dll = depending on the version; HID Service or HID Audio Service.
Mine sez HID Audio Service.

This is interesting...
SYMPTOMS
When you try to shut down a Windows XP-based computer that has Human
Interface Devices (HID) peripherals connected, the time that it takes to
shut down the computer may be longer than when the HID peripherals are not
connected.

Note HID peripherals are Universal Serial Bus (USB) devices such as
keyboards, game controllers, and scanners that comply with the Device Class
Definition for HID 1.11 standard.
from...
Shutting Down Computer Takes Extra Time When HID Devices Are Connected
http://support.microsoft.com/kb/826367

Human Interface Device Access
Disabled, if not using keyboards/mouse/joysticks extended with extra buttons
that need mapping.
Manual, if having many buttons to push.

Human Interface Device Access
You may not have any peripherals that require this service. If one of yours
magically does not function anymore, set it to automatic. Namely, scanners
with function buttons (fax, copy) or even an "Internet" keyboard with volume
or play controls.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is stopped,
hot buttons controlled by this service will no longer function. If this
service is disabled, any services that explicitly depend on it will fail to
start.
*Some peripherals require this service. Internet keyboards with volume and
play control buttons, scanners with fax or copy buttons. I don't have any of
these kinds of peripherals so mine is disabled.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is stopped,
hot buttons controlled by this service will no longer function.

Human Interface Device Access
Comment: Whether or not you should disable this service, depends on other
services you need. If you don't know, turn it off and see if it breaks
anything. It says that it deals with hotkeys, however all the system hotkeys
that most of us enjoy aren't controlled by this service, they are built into
the core OS. Control C, for example, to copy and Control V to past, do not
stop working when you turn this service off. It seems this has more to do
with specific hotkeys that a software vendor may want to insert into their
installed program or internet product. Until you see a reason for it, I'd
turn this one off.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Wes I just shut down and one only IMAPI Warning appeared.
Question: IMAPI Properties, Logon Tab, under Hardware Profile I've got
Profile 1 Enabled. Shouldn't that that too be Disabled?

While I have your attn: Only One more I'm getting and have been getting
since the computer was put together is:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 05/12/2006
Time: 3:10:59 PM
User: N/A
Computer: SHARK
Description:
The HID Input Service service terminated with the following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I have HID Input Service on Automatic but I see it's not Started.
General Tab, Service Status shows Stopped. Profile 1 is Enabled.

I did have a Logitech Wireless Mouse installed by I'm back to my old MS
Mouse. I've got a Linksys Wireless Router and DSL. I haven't got my
Laptop on the router yet.
Creative Speakers and I don't use any hot buttons.
That description makes ME think there's a file missing. How would u ever
find out which file? Any ideas. Thx ...

Wesley Vogel said:
Edna,

You also have to use your own judgment. Sometimes you have to mess
around and see why something doesn't work because you disabled a
particular service.

A few examples. If you disable LanmanWorkstation (Workstation service),
Local Users and Groups (lusrmgr.msc) in MMC doesn't work right. Or if
Terminal Services is disabled you do not see any names in the User Name
column in Task Manager. Or if you disable the Indexing Service, your
machine runs better. Or if you disable the DHCP Client service you
cannot get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/

http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm

[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default
settings for Services listed in Help & Support are still wrong. I've
gotten these settings by doing a fresh install of both XP Home and Pro
and exporting the Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services
http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Hi Wes! I've just disabled IMAPI. I didn't know that and never would
have thought to Disable it. I've had it on every other setting except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can refer
to as to suggestions for these Settings. I read the explanations for
these Services and many go right over my head. Between my girlfriend
and I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

:

Disable the IMAPI CD-Burning COM Service. It is only needed when using
XP's inbuilt CD burning application. If you use any 3rd party CD
burning software, IMAPI.EXE does not need to run, ever. It can cause
conflicts. I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio
but after reading comments on Roxio causing hangs, which I was
experiencing, I removed it thoroughly, every reg entry. I was
planning, within hours, to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis V10 the True Image program, I have to wait 40 mins for it to
get through a hang before it starts. I've completed a Report for the
Acronis Techs but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe not but I recently noticed I got an IMAPI Warning at the very
same time I started Acronis. More work required as I couldn't
immediately repeat it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have
and wanted
very much to do. I came here so often to continue and something
else would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find
now that
the only Warning I'm getting with any regularity is the IMAPI
Warning but it's prolific. I'm talking 15 - 20 entries at once.
Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able to
use the
/AUXSOURCE= flag to retrieve this description; see Help and Support
for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as it
doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any difference.
I think I'll put it back on Manual and leave it in the Stopped mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried but can't pin down what I'm doing that causes it to go into a
multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due
to a Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot
be found.
The local computer may not have the necessary registry information
or message DLL files to display messages from a remote computer.
You may be able to use the /AUXSOURCE= flag to retrieve this
description; see Help and
Support for details. The following information is part of the
event: res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle remapping
did not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt
-------
3) Here the service is telling you that it closed handles that were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive
by remapping the handles to the user profile hive to the default
user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button
| When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since you
 
G

Gerry Cornell

Wes

Just tried to Start mine and got an Error 126!

Spent 30 mins earlier this evening trying to figure out why an Error 126
arose
for Web Client Service to answer a question but could not find the answer?

Any thoughts on either?

--

Regards.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wesley Vogel said:
Human Interface Device Access is the Display Name for HidServ (Service
Name).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\HidServ\Parameters
sez: ServiceDll = %SystemRoot%\System32\hidserv.dll
hidserv.dll = depending on the version; HID Service or HID Audio Service.
Mine sez HID Audio Service.

This is interesting...
SYMPTOMS
When you try to shut down a Windows XP-based computer that has Human
Interface Devices (HID) peripherals connected, the time that it takes to
shut down the computer may be longer than when the HID peripherals are not
connected.

Note HID peripherals are Universal Serial Bus (USB) devices such as
keyboards, game controllers, and scanners that comply with the Device
Class
Definition for HID 1.11 standard.
from...
Shutting Down Computer Takes Extra Time When HID Devices Are Connected
http://support.microsoft.com/kb/826367

Human Interface Device Access
Disabled, if not using keyboards/mouse/joysticks extended with extra
buttons
that need mapping.
Manual, if having many buttons to push.

Human Interface Device Access
You may not have any peripherals that require this service. If one of
yours
magically does not function anymore, set it to automatic. Namely, scanners
with function buttons (fax, copy) or even an "Internet" keyboard with
volume
or play controls.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is stopped,
hot buttons controlled by this service will no longer function. If this
service is disabled, any services that explicitly depend on it will fail
to
start.
*Some peripherals require this service. Internet keyboards with volume and
play control buttons, scanners with fax or copy buttons. I don't have any
of
these kinds of peripherals so mine is disabled.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is stopped,
hot buttons controlled by this service will no longer function.

Human Interface Device Access
Comment: Whether or not you should disable this service, depends on other
services you need. If you don't know, turn it off and see if it breaks
anything. It says that it deals with hotkeys, however all the system
hotkeys
that most of us enjoy aren't controlled by this service, they are built
into
the core OS. Control C, for example, to copy and Control V to past, do not
stop working when you turn this service off. It seems this has more to do
with specific hotkeys that a software vendor may want to insert into their
installed program or internet product. Until you see a reason for it, I'd
turn this one off.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Wes I just shut down and one only IMAPI Warning appeared.
Question: IMAPI Properties, Logon Tab, under Hardware Profile I've got
Profile 1 Enabled. Shouldn't that that too be Disabled?

While I have your attn: Only One more I'm getting and have been getting
since the computer was put together is:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 05/12/2006
Time: 3:10:59 PM
User: N/A
Computer: SHARK
Description:
The HID Input Service service terminated with the following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I have HID Input Service on Automatic but I see it's not Started.
General Tab, Service Status shows Stopped. Profile 1 is Enabled.

I did have a Logitech Wireless Mouse installed by I'm back to my old MS
Mouse. I've got a Linksys Wireless Router and DSL. I haven't got my
Laptop on the router yet.
Creative Speakers and I don't use any hot buttons.
That description makes ME think there's a file missing. How would u ever
find out which file? Any ideas. Thx ...

Wesley Vogel said:
Edna,

You also have to use your own judgment. Sometimes you have to mess
around and see why something doesn't work because you disabled a
particular service.

A few examples. If you disable LanmanWorkstation (Workstation service),
Local Users and Groups (lusrmgr.msc) in MMC doesn't work right. Or if
Terminal Services is disabled you do not see any names in the User Name
column in Task Manager. Or if you disable the Indexing Service, your
machine runs better. Or if you disable the DHCP Client service you
cannot get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/

http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm

[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default
settings for Services listed in Help & Support are still wrong. I've
gotten these settings by doing a fresh install of both XP Home and Pro
and exporting the Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services
http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Wes! I've just disabled IMAPI. I didn't know that and never would
have thought to Disable it. I've had it on every other setting except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can
refer
to as to suggestions for these Settings. I read the explanations for
these Services and many go right over my head. Between my girlfriend
and I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

:

Disable the IMAPI CD-Burning COM Service. It is only needed when
using
XP's inbuilt CD burning application. If you use any 3rd party CD
burning software, IMAPI.EXE does not need to run, ever. It can cause
conflicts. I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus
P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio
but after reading comments on Roxio causing hangs, which I was
experiencing, I removed it thoroughly, every reg entry. I was
planning, within hours, to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis V10 the True Image program, I have to wait 40 mins for it to
get through a hang before it starts. I've completed a Report for the
Acronis Techs but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe not but I recently noticed I got an IMAPI Warning at the very
same time I started Acronis. More work required as I couldn't
immediately repeat it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have
and wanted
very much to do. I came here so often to continue and something
else would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find
now that
the only Warning I'm getting with any regularity is the IMAPI
Warning but it's prolific. I'm talking 15 - 20 entries at once.
Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able
to
use the
/AUXSOURCE= flag to retrieve this description; see Help and Support
for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as it
doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any
difference.
I think I'll put it back on Manual and leave it in the Stopped
mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried but can't pin down what I'm doing that causes it to go into a
multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety
split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait when
shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls
accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due
to a Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot
be found.
The local computer may not have the necessary registry information
or message DLL files to display messages from a remote computer.
You may be able to use the /AUXSOURCE= flag to retrieve this
description; see Help and
Support for details. The following information is part of the
event: res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle
remapping
did not
work, so it tried closing handle the handle.

The following are from:


http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that
were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been remapped
because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive
by remapping the handles to the user profile hive to the default
user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a
graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do
the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop button
| When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the
clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since you
 
W

Wesley Vogel

Hi Gerry,

hidserv.dll is probably not in %SystemRoot%\System32

Mine isn't, it's in %SystemRoot%\System32\dllcache.

I just set HID to Manual and hit the Start button and got...

---------------------------
Services
---------------------------
Could not start the Human Interface Device Access service on Local Computer.

Error 126: The specified module could not be found.
---------------------------

I already know why it wasn't found.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Gerry Cornell said:
Wes

Just tried to Start mine and got an Error 126!

Spent 30 mins earlier this evening trying to figure out why an Error 126
arose
for Web Client Service to answer a question but could not find the answer?

Any thoughts on either?

--

Regards.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wesley Vogel said:
Human Interface Device Access is the Display Name for HidServ (Service
Name).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\HidServ\Parameters
sez: ServiceDll = %SystemRoot%\System32\hidserv.dll
hidserv.dll = depending on the version; HID Service or HID Audio Service.
Mine sez HID Audio Service.

This is interesting...
SYMPTOMS
When you try to shut down a Windows XP-based computer that has Human
Interface Devices (HID) peripherals connected, the time that it takes to
shut down the computer may be longer than when the HID peripherals are
not connected.

Note HID peripherals are Universal Serial Bus (USB) devices such as
keyboards, game controllers, and scanners that comply with the Device
Class
Definition for HID 1.11 standard.
from...
Shutting Down Computer Takes Extra Time When HID Devices Are Connected
http://support.microsoft.com/kb/826367

Human Interface Device Access
Disabled, if not using keyboards/mouse/joysticks extended with extra
buttons
that need mapping.
Manual, if having many buttons to push.

Human Interface Device Access
You may not have any peripherals that require this service. If one of
yours
magically does not function anymore, set it to automatic. Namely,
scanners with function buttons (fax, copy) or even an "Internet"
keyboard with volume
or play controls.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is
stopped, hot buttons controlled by this service will no longer function.
If this service is disabled, any services that explicitly depend on it
will fail to
start.
*Some peripherals require this service. Internet keyboards with volume
and play control buttons, scanners with fax or copy buttons. I don't
have any of
these kinds of peripherals so mine is disabled.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is
stopped, hot buttons controlled by this service will no longer function.

Human Interface Device Access
Comment: Whether or not you should disable this service, depends on other
services you need. If you don't know, turn it off and see if it breaks
anything. It says that it deals with hotkeys, however all the system
hotkeys
that most of us enjoy aren't controlled by this service, they are built
into
the core OS. Control C, for example, to copy and Control V to past, do
not stop working when you turn this service off. It seems this has more
to do with specific hotkeys that a software vendor may want to insert
into their installed program or internet product. Until you see a reason
for it, I'd turn this one off.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Edna said:
Wes I just shut down and one only IMAPI Warning appeared.
Question: IMAPI Properties, Logon Tab, under Hardware Profile I've got
Profile 1 Enabled. Shouldn't that that too be Disabled?

While I have your attn: Only One more I'm getting and have been getting
since the computer was put together is:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 05/12/2006
Time: 3:10:59 PM
User: N/A
Computer: SHARK
Description:
The HID Input Service service terminated with the following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I have HID Input Service on Automatic but I see it's not Started.
General Tab, Service Status shows Stopped. Profile 1 is Enabled.

I did have a Logitech Wireless Mouse installed by I'm back to my old MS
Mouse. I've got a Linksys Wireless Router and DSL. I haven't got my
Laptop on the router yet.
Creative Speakers and I don't use any hot buttons.
That description makes ME think there's a file missing. How would u
ever find out which file? Any ideas. Thx ...

:

Edna,

You also have to use your own judgment. Sometimes you have to mess
around and see why something doesn't work because you disabled a
particular service.

A few examples. If you disable LanmanWorkstation (Workstation
service), Local Users and Groups (lusrmgr.msc) in MMC doesn't work
right. Or if Terminal Services is disabled you do not see any names
in the User Name column in Task Manager. Or if you disable the
Indexing Service, your machine runs better. Or if you disable the
DHCP Client service you cannot get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/
http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm
[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default
settings for Services listed in Help & Support are still wrong. I've
gotten these settings by doing a fresh install of both XP Home and Pro
and exporting the Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services
http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx
--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Wes! I've just disabled IMAPI. I didn't know that and never would
have thought to Disable it. I've had it on every other setting except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can
refer
to as to suggestions for these Settings. I read the explanations for
these Services and many go right over my head. Between my girlfriend
and I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

:

Disable the IMAPI CD-Burning COM Service. It is only needed when
using
XP's inbuilt CD burning application. If you use any 3rd party CD
burning software, IMAPI.EXE does not need to run, ever. It can cause
conflicts. I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus
P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio
but after reading comments on Roxio causing hangs, which I was
experiencing, I removed it thoroughly, every reg entry. I was
planning, within hours, to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis V10 the True Image program, I have to wait 40 mins for it to
get through a hang before it starts. I've completed a Report for
the Acronis Techs but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe not but I recently noticed I got an IMAPI Warning at the very
same time I started Acronis. More work required as I couldn't
immediately repeat it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should have
and wanted
very much to do. I came here so often to continue and something
else would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and find
now that
the only Warning I'm getting with any regularity is the IMAPI
Warning but it's prolific. I'm talking 15 - 20 entries at once.
Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able
to
use the
/AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the
event: . Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as
it doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any
difference.
I think I'll put it back on Manual and leave it in the Stopped
mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried but can't pin down what I'm doing that causes it to go into
a multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety
split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait
when shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls
accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due
to a Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL ) cannot
be found.
The local computer may not have the necessary registry
information or message DLL files to display messages from a
remote computer. You may be able to use the /AUXSOURCE= flag to
retrieve this description; see Help and
Support for details. The following information is part of the
event: res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle
remapping
did not
work, so it tried closing handle the handle.

The following are from:
http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt
-------
3) Here the service is telling you that it closed handles that
were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been
remapped because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile hive
by remapping the handles to the user profile hive to the default
user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a
graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do
the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service |
Under Startup type set to Disabled | Apply | Click the Stop
button
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the
clock
rate and
memory speed for nVidia based graphics cards. This is unnecessary
since you
 
G

Gerry Cornell

Wes

Same here but there are some keys on my Wireless Keyboard which do not
work. Not that that has bothered me to date.

Would copying hidserv.dll to the System32 folder work or is the solution
more
involved?

--

Regards.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wesley Vogel said:
Hi Gerry,

hidserv.dll is probably not in %SystemRoot%\System32

Mine isn't, it's in %SystemRoot%\System32\dllcache.

I just set HID to Manual and hit the Start button and got...

---------------------------
Services
---------------------------
Could not start the Human Interface Device Access service on Local
Computer.

Error 126: The specified module could not be found.
---------------------------

I already know why it wasn't found.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
Gerry Cornell said:
Wes

Just tried to Start mine and got an Error 126!

Spent 30 mins earlier this evening trying to figure out why an Error 126
arose
for Web Client Service to answer a question but could not find the
answer?

Any thoughts on either?

--

Regards.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wesley Vogel said:
Human Interface Device Access is the Display Name for HidServ (Service
Name).

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\HidServ\Parameters
sez: ServiceDll = %SystemRoot%\System32\hidserv.dll
hidserv.dll = depending on the version; HID Service or HID Audio
Service.
Mine sez HID Audio Service.

This is interesting...
SYMPTOMS
When you try to shut down a Windows XP-based computer that has Human
Interface Devices (HID) peripherals connected, the time that it takes to
shut down the computer may be longer than when the HID peripherals are
not connected.

Note HID peripherals are Universal Serial Bus (USB) devices such as
keyboards, game controllers, and scanners that comply with the Device
Class
Definition for HID 1.11 standard.
from...
Shutting Down Computer Takes Extra Time When HID Devices Are Connected
http://support.microsoft.com/kb/826367

Human Interface Device Access
Disabled, if not using keyboards/mouse/joysticks extended with extra
buttons
that need mapping.
Manual, if having many buttons to push.

Human Interface Device Access
You may not have any peripherals that require this service. If one of
yours
magically does not function anymore, set it to automatic. Namely,
scanners with function buttons (fax, copy) or even an "Internet"
keyboard with volume
or play controls.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is
stopped, hot buttons controlled by this service will no longer function.
If this service is disabled, any services that explicitly depend on it
will fail to
start.
*Some peripherals require this service. Internet keyboards with volume
and play control buttons, scanners with fax or copy buttons. I don't
have any of
these kinds of peripherals so mine is disabled.

Human Interface Device Access
Enables generic input access to Human Interface Devices (HID), which
activates and maintains the use of predefined hot buttons on keyboards,
remote controls, and other multimedia devices. If this service is
stopped, hot buttons controlled by this service will no longer function.

Human Interface Device Access
Comment: Whether or not you should disable this service, depends on
other
services you need. If you don't know, turn it off and see if it breaks
anything. It says that it deals with hotkeys, however all the system
hotkeys
that most of us enjoy aren't controlled by this service, they are built
into
the core OS. Control C, for example, to copy and Control V to past, do
not stop working when you turn this service off. It seems this has more
to do with specific hotkeys that a software vendor may want to insert
into their installed program or internet product. Until you see a reason
for it, I'd turn this one off.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Wes I just shut down and one only IMAPI Warning appeared.
Question: IMAPI Properties, Logon Tab, under Hardware Profile I've got
Profile 1 Enabled. Shouldn't that that too be Disabled?

While I have your attn: Only One more I'm getting and have been
getting
since the computer was put together is:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 05/12/2006
Time: 3:10:59 PM
User: N/A
Computer: SHARK
Description:
The HID Input Service service terminated with the following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

I have HID Input Service on Automatic but I see it's not Started.
General Tab, Service Status shows Stopped. Profile 1 is Enabled.

I did have a Logitech Wireless Mouse installed by I'm back to my old MS
Mouse. I've got a Linksys Wireless Router and DSL. I haven't got my
Laptop on the router yet.
Creative Speakers and I don't use any hot buttons.
That description makes ME think there's a file missing. How would u
ever find out which file? Any ideas. Thx ...

:

Edna,

You also have to use your own judgment. Sometimes you have to mess
around and see why something doesn't work because you disabled a
particular service.

A few examples. If you disable LanmanWorkstation (Workstation
service), Local Users and Groups (lusrmgr.msc) in MMC doesn't work
right. Or if Terminal Services is disabled you do not see any names
in the User Name column in Task Manager. Or if you disable the
Indexing Service, your machine runs better. Or if you disable the
DHCP Client service you cannot get online.


http://smallvoid.com/tweak/winnt/services.html

http://www.theeldergeek.com/services_guide.htm#Services

http://web.archive.org/web/20041128094512/http://www.blackviper.com/


http://web.archive.org/web/20041128084144/www.blackviper.com/WinXP/servicecfg.htm

[[Services
Microsoft pulled their services guide that I had linked to previously
because the information was outdated due to SP2. Even the default
settings for Services listed in Help & Support are still wrong. I've
gotten these settings by doing a fresh install of both XP Home and Pro
and exporting the Services configuration as a .csv file.]]
TweakHound's Super XP Tweaking Guide - Services
http://www.tweakhound.com/xp/xptweaks/supertweaks6.htm

Default settings for services

http://www.microsoft.com/resources/.../proddocs/en-us/sys_srv_default_settings.mspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Wes! I've just disabled IMAPI. I didn't know that and never
would
have thought to Disable it. I've had it on every other setting
except
Disable. Do u know of a GOOD/INTELLIGENT/KNOWLEDGABLE Site one can
refer
to as to suggestions for these Settings. I read the explanations
for
these Services and many go right over my head. Between my girlfriend
and I we discuss and decide.
I once put them all on Automatic, Shutdown, Restarted, and those that
didn't show Start, I put on Manual. Whatta Hi Tech Analyzer eh?
Messenger and Secondary Logon and now IMAPI are my only Disables.
Thx I'll let u know in a cple days. ...

:

Disable the IMAPI CD-Burning COM Service. It is only needed when
using
XP's inbuilt CD burning application. If you use any 3rd party CD
burning software, IMAPI.EXE does not need to run, ever. It can
cause
conflicts. I have Nero and have IMAPI disabled.

I know nothing about Acronis.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In Edna <[email protected]> hunted and pecked:
Hi Gerry! I have Nero 6.6.0.18 installed that came with my Asus
P5WD2
Premium MB installed Dec05. I've never used it. I was using Roxio
but after reading comments on Roxio causing hangs, which I was
experiencing, I removed it thoroughly, every reg entry. I was
planning, within hours, to buy the new Nero.

Something possibly relevant I noticed the other night: I bought
Acronis V10 the True Image program, I have to wait 40 mins for it
to
get through a hang before it starts. I've completed a Report for
the Acronis Techs but haven't heard of their finds yet.

I'm suspicious, the IMAPI Warnings and Acronis Hangs are related.
Maybe not but I recently noticed I got an IMAPI Warning at the very
same time I started Acronis. More work required as I couldn't
immediately repeat it.

Now, to answer your question: Yes! LOL ...


:

Edna

Are you using Nero software?

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England

Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~


Wes I'm so sorry time didn't permit me to respond as I should
have
and wanted
very much to do. I came here so often to continue and something
else would
prevent me from concentrating on this.
I did switch my AV from NAV to Zone Alarm Security Suite and
find
now that
the only Warning I'm getting with any regularity is the IMAPI
Warning but it's prolific. I'm talking 15 - 20 entries at once.
Once I counted 60.

Event Type: Warning
Event Source: Imapi
Event Category: None
Event ID: 54
Date: 04/12/2006
Time: 12:37:30 PM
User: N/A
Computer: SHARK
Description:
The description for Event ID ( 54 ) in Source ( Imapi ) cannot be
found. The
local computer may not have the necessary registry information or
message DLL
files to display messages from a remote computer. You may be able
to
use the
/AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the
event: . Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 36 00 04 80 ....6..€
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Presently I have it on Automatic but whether it's on Automatic or
Manual doesn't make any difference. Obviously I don't need it as
it doesn't start itself.
But if it isn't being used why do the Warnings appear?

I've Started IMAPI on occasion but that doesn't make any
difference.
I think I'll put it back on Manual and leave it in the Stopped
mode.

Sometimes I get multiple entries in a row. Sometimes one. I've
tried but can't pin down what I'm doing that causes it to go into
a multiple spin.

Oh BTW since abandoning Norton, my shut downs are now lickety
split.
Maybe
it was Norton, maybe not, but it's so nice not to have to wait
when shutting
down.
I've used Norton for years but recently I got hit with some Pest
thingie. I
was dissappointed NAV didn't protect me so I switched.
Again, Wes, Thank You for the time u spent helping me and pls
accept
my apology. My failure to reply wasn't by choice. ...

:

Edna,

Your original post said 2 - 3 minute shutdowns. How long did
shutdown take
before you installed UPHClean?

I get the Event Source: HHCTRL Event ID: 1904 all the time. Due
to a Windows Critical Update.

Event Type: Information
Event Source: HHCTRL
Event Category: None
Event ID: 1904
Date: 02/23/2006
Time: 1:32:25 PM
User: N/A
Computer: MYPENTIUM450
Description:
The description for Event ID ( 1904 ) in Source ( HHCTRL )
cannot
be found.
The local computer may not have the necessary registry
information or message DLL files to display messages from a
remote computer. You may be able to use the /AUXSOURCE= flag to
retrieve this description; see Help and
Support for details. The following information is part of the
event: res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm,
http://go.microsoft.com/fwlink?LinkID=45840.

http://go.microsoft.com/fwlink?LinkID=45840
resolves to...
MS05-026: A vulnerability in HTML Help could allow remote code
execution http://support.microsoft.com/kb/896358
------

UPHClean 1412: I have no idea what that is. SWAG: handle
remapping
did not
work, so it tried closing handle the handle.

The following are from:



http://download.microsoft.com/download/a/8/7/a87b3d05-cd04-4743-a23b-b16645e075ac/readme.txt

-------
3) Here the service is telling you that it closed handles that
were
preventing
the profile from unloading:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1201
Date: 11/14/2003
Time: 10:26:29 PM
User: RCARONDOM\u1
Computer: RCARONDOM-DC1
Description:
The following handles in user profile hive RCARONDOM\u1
(S-1-5-21-3230802392-3390281410-1560515013-1307) have been
closed
because they
were preventing the profile from unloading successfully:

profleak.exe (1444)
HKCU (0x144)
-------

1201 is just information that UPHClean is doing its job.
-------

8) If you use handle remapping instead of getting event id 1201
logged you
will
get event 1401:

Event Type: Information
Event Source: UPHClean
Event Category: None
Event ID: 1401
Date: 10/26/2004
Time: 9:56:52 PM
User: RCARON2-NC\u1
Computer: RCARON2-NC
Description:
The following handles in user profile hive RCARON2-NC\u1
(S-1-5-21-796845957-1275210071-1801674531-1024) have been
remapped because
they
were preventing the profile from unloading successfully:

regopenkeyex.exe (368)
HKCU\Software\Classes\Software (0x4)
-------

UPHClean assists the operating system to unload user profile
hive
by remapping the handles to the user profile hive to the default
user hive.

UPHClean doing its job.
-------

Event Source: UPHClean
Event Category: None
Event ID: 1010

This will occur eveer time that UPHClean stops and is normal.
-------

I saw HKCU\Software\NVIDIA Corporation\Global\nView\Tweak under
Event Source: UPHClean
Event ID: 1201.

NVIDIA software can mess up a bunch of things. NVIDIA is a
graphic
card.

I have all of this NVIDIA crap disabled and suggest that you do
the
same.

Disable the NVIDIA Display Driver Service...
Start | Run | Type: services.msc | OK |
Scroll down to and double click: NVIDIA Display Driver Service
|
Under Startup type set to Disabled | Apply | Click the Stop
button
When it stops click OK | You may have to reboot

First: NvCplDaemon, NvMediaCenter and nwiz what are they?

NvCplDaemon
[System Tray icon used to change display settings, change the
clock
rate and
memory speed for nVidia based graphics cards. This is
unnecessary
since you
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top