Quote
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 8/17/2009 11:47:34 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: TommysRealm
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-543014975-2786251972-929394339-1001_Classes:
Process 1088 (\Device\HarddiskVolume1\WINDOWS\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001_CLASSES
Process 2024 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourcename="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2009-08-17T18:47:34.000Z" />
<EventRecordID>57643</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>TommysRealm</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData name="EVENT_HIVE_LEAK">
<Data name="Detail">2 user registry handles leaked from \Registry\User\S-1-5-21-543014975-2786251972-929394339-1001_Classes:
Process 1088 (\Device\HarddiskVolume1\WINDOWS\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001_CLASSES
Process 2024 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
</Data>
</EventData>
</Event>
Quote
Log Name: Application
Source: Application Error
Date: 8/17/2009 11:47:33 AM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: TommysRealm
Description:
Faulting application EKDiscovery.exe, version 3.2.1.29, time stamp 0x48ef91f1, faulting module EKDiscovery.exe, version 3.2.1.29, time stamp 0x48ef91f1, exception code 0xc0000005, fault offset 0x00008c54, process id 0x%9, application start time 0x%10.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Level>2</Level>
<Task>100</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2009-08-17T18:47:33.000Z" />
<EventRecordID>57642</EventRecordID>
<Channel>Application</Channel>
<Computer>TommysRealm</Computer>
<Security />
</System>
<EventData>
<Data>EKDiscovery.exe</Data>
<Data>3.2.1.29</Data>
<Data>48ef91f1</Data>
<Data>EKDiscovery.exe</Data>
<Data>3.2.1.29</Data>
<Data>48ef91f1</Data>
<Data>c0000005</Data>
<Data>00008c54</Data>
</EventData>
</Event>
Quote
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 8/17/2009 11:47:33 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: TommysRealm
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-543014975-2786251972-929394339-1001:
Process 1088 (\Device\HarddiskVolume1\WINDOWS\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourcename="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2009-08-17T18:47:33.000Z" />
<EventRecordID>57641</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>TommysRealm</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData name="EVENT_HIVE_LEAK">
<Data name="Detail">1 user registry handles leaked from \Registry\User\S-1-5-21-543014975-2786251972-929394339-1001:
Process 1088 (\Device\HarddiskVolume1\WINDOWS\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-543014975-2786251972-929394339-1001
</Data>
</EventData>
</Event>
Quote
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 8/17/2009 5:05:14 PM
Event ID: 5038
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: TommysRealm
Description:
Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume1\Program Files\SUPERAntiSpyware\SASENUM.SYS
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>5038</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2009-08-18T00:05:14.638Z" />
<EventRecordID>30218</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="52" />
<Channel>Security</Channel>
<Computer>TommysRealm</Computer>
<Security />
</System>
<EventData>
<Data name="param1">\Device\HarddiskVolume1\Program Files\SUPERAntiSpyware\SASENUM.SYS</Data>
</EventData>
</Event>
I am also not sure if this is where I should be posting this, If it needs to be moved I am sorry...I really don't know what I am doing here and these are just shots in the dark to fix this problem.
Also what I have noticed is that I don't get errors DURING the problem but when i restart all these errors repeat on start up. I had a feeling it was a problem that something started or failed to start that caused this and after a certain amount of time what ever had failed to open or work properly causes my connection to drop and causes it to drop repeatedly over and over. Not sure if any of those errors and warnings are significant though, but I hope they are.
Could this possibly be caused by dust inside the computer? I haven't dusted this since I bought it about a year ago and my mom keeps forgetting to bring home some canned air. I haven't done it before so next time im at a store that sells it I will buy a can, anything I need to know before I open the case and spray (I know about grounding my hands and turning off and unplugging the computer and all the connections, but just want to be sure I do it right