BSOD Error Log
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 




BSOD Error LogExpand / Collapse
Author
Message
Posted 12/23/2007 10:54 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 1/19/2008 7:17 PM
Posts: 8, Visits: 17
hello , i've been getting bsod on every restart due to some hardware problem . here's a pstat log , im thinking its a video card problem which i will replace since the video card im using isn't agp 4x/8x (mobo agp slot is 4x/8x) .

Log;



Pstat version 0.3: memory: 2096620 kb uptime: 0 0:27:00.250

PageFile: \??\C:\pagefile.sys
Current Size: 2095104 kb Total Used: 85332 kb Peak Used 93348 kb


ModuleName Load Addr Code Data Paged LinkDate
------------------------------------------------------------------------------
ntkrnlpa.exe 804D7000 475136 106496 1179648 Wed Aug 04 01:58:37 2004
hal.dll 806E2000 35840 42496 30976 Wed Aug 04 01:59:09 2004
KDCOM.DLL BA5A8000 2560 256 1280 Fri Aug 17 16:49:10 2001
BOOTVID.dll BA4B8000 5632 3584 0 Fri Aug 17 16:49:09 2001
ACPI.sys B9F79000 110336 11008 41984 Wed Aug 04 02:07:35 2004
WMILIB.SYS BA5AA000 512 0 1280 Fri Aug 17 17:07:23 2001
pci.sys B9F68000 16000 1664 34176 Wed Aug 04 02:07:45 2004
isapnp.sys BA0A8000 8704 768 18688 Fri Aug 17 16:58:01 2001
avgarkt.sys BA5AC000 2176 128 0 Wed Jan 31 08:33:46 2007
PCIIde.sys BA670000 896 128 0 Fri Aug 17 16:51:49 2001
PCIIDEX.SYS BA328000 5504 512 13056 Wed Aug 04 01:59:40 2004
aliide.sys BA5AE000 2304 896 0 Fri Aug 17 16:51:54 2001
MountMgr.sys BA0B8000 1408 128 33664 Wed Aug 04 01:58:29 2004
ftdisk.sys B9F49000 5888 128 102400 Fri Aug 17 16:52:41 2001
dmload.sys BA5B0000 2560 128 0 Fri Aug 17 16:58:15 2001
dmio.sys B9F23000 120960 15104 1280 Wed Aug 04 02:07:13 2004
PartMgr.sys BA330000 1920 128 11136 Fri Aug 17 21:32:23 2001
VolSnap.sys BA0C8000 2560 128 35200 Wed Aug 04 02:00:14 2004
atapi.sys B9F0B000 44928 3584 29952 Wed Aug 04 01:59:41 2004
disk.sys BA0D8000 8320 384 18048 Wed Aug 04 01:59:53 2004
CLASSPNP.SYS BA0E8000 25472 128 15360 Wed Aug 04 02:14:26 2004
fltMgr.sys B9EEC000 31232 3200 60672 Wed Aug 04 02:01:17 2004
PxHelp20.sys BA0F8000 26336 3776 0 Fri Feb 02 16:23:57 2007
KSecDD.sys B9ED5000 10368 6912 64000 Wed Aug 04 01:59:45 2004
Ntfs.sys B9E48000 96000 7040 412544 Wed Aug 04 02:15:06 2004
NDIS.sys B9E1B000 22272 2688 131328 Wed Aug 04 02:14:27 2004
agpkx.sys BA108000 11008 256 25984 Tue May 03 05:31:54 2005
Mup.sys B9E00000 14592 6272 72832 Wed Aug 04 02:15:20 2004
AmdK8.sys BA2C8000 12288 4096 16384 Mon Mar 07 16:58:10 2005
ati2mtag.sys B9195000 1503232 1015808 266240 Thu Nov 01 23:08:41 2007
VIDEOPRT.SYS B9181000 11008 384 50048 Wed Aug 04 02:07:04 2004
ctaud2k.sys B9115000 206080 62720 115840 Sun Aug 07 17:54:34 2005
portcls.sys B90F1000 44672 10496 65536 Wed Aug 04 02:15:47 2004
drmk.sys BA2E8000 5504 1280 47616 Wed Aug 04 02:07:54 2004
ks.sys B90CE000 31872 128 87808 Wed Aug 04 02:15:20 2004
ctoss2k.sys B909C000 94208 77824 4096 Sun Aug 07 17:54:21 2005
ctprxy2k.sys BA390000 4096 4096 4096 Sun Aug 07 17:54:36 2005
Rtlnicxp.sys B908A000 57600 3456 1664 Thu Dec 02 03:36:06 2004
imapi.sys BA2F8000 11776 256 19584 Wed Aug 04 02:00:12 2004
cdrom.sys BA308000 33536 128 5888 Wed Aug 04 01:59:52 2004
redbook.sys BA318000 6656 1152 36352 Wed Aug 04 01:59:34 2004
usbohci.sys BA398000 13440 384 0 Wed Aug 04 02:08:34 2004
USBPORT.SYS B9067000 119808 1024 10752 Wed Aug 04 02:08:34 2004
usbehci.sys BA3A0000 22400 768 0 Wed Aug 04 02:08:34 2004
serial.sys B94DE000 12160 384 30464 Wed Aug 04 02:15:51 2004
serenum.sys BA5A4000 2944 128 7808 Wed Aug 04 01:59:06 2004
parport.sys B9053000 67072 1280 256 Wed Aug 04 01:59:04 2004
i8042prt.sys B94CE000 12160 256 23040 Wed Aug 04 02:14:36 2004
mouclass.sys BA3A8000 6144 896 5888 Wed Aug 04 01:58:32 2004
kbdclass.sys BA3B0000 6912 896 6528 Wed Aug 04 01:58:32 2004
splitcam.sys B94BE000 8192 4096 4096 Sun Aug 22 10:01:32 2004
STREAM.SYS B94AE000 18048 128 20992 Wed Aug 04 02:07:58 2004
audstub.sys BA6F2000 128 0 512 Fri Aug 17 16:59:40 2001
rasl2tp.sys B949E000 44672 512 0 Wed Aug 04 02:14:21 2004
ndistapi.sys B9DDC000 5248 128 0 Fri Aug 17 16:55:29 2001
ndiswan.sys B903C000 71552 2432 0 Wed Aug 04 02:14:30 2004
raspppoe.sys B948E000 31360 4608 0 Wed Aug 04 02:05:06 2004
raspptp.sys B947E000 40192 896 0 Wed Aug 04 02:14:26 2004
TDI.SYS BA3B8000 10880 512 256 Wed Aug 04 02:07:47 2004
psched.sys B902B000 52480 2176 3968 Wed Aug 04 02:04:16 2004
msgpc.sys B946E000 28416 1408 512 Wed Aug 04 02:04:11 2004
ptilink.sys BA3C0000 12928 256 0 Fri Aug 17 16:49:53 2001
raspti.sys BA3C8000 11008 640 0 Fri Aug 17 16:55:32 2001
rdpdr.sys B8FFA000 75520 4608 92160 Wed Aug 04 02:01:10 2004
termdd.sys B945E000 27520 768 2560 Wed Aug 04 01:58:52 2004
swenum.sys BA5D8000 384 128 640 Wed Aug 04 01:58:41 2004
update.sys B8F9E000 2304 1920 197376 Wed Aug 04 01:58:32 2004
mssmbios.sys B9DBC000 4480 1024 3840 Wed Aug 04 02:07:47 2004
NDProxy.SYS B944E000 29184 2176 0 Fri Aug 17 16:55:30 2001
ha20x2k.sys B085F000 737280 126976 4096 Sun Aug 07 17:54:26 2005
emupia2k.sys B0832000 65536 90112 4096 Sun Aug 07 17:54:16 2005
ctsfm2k.sys B080B000 131072 4096 4096 Sun Aug 07 17:54:16 2005
ctac32k.sys B076F000 217088 368640 4096 Sun Aug 07 17:54:13 2005
usbhub.sys BA168000 28032 768 21120 Wed Aug 04 02:08:40 2004
USBD.SYS BA5DC000 256 0 896 Fri Aug 17 17:02:58 2001
Fs_Rec.SYS BA5DE000 128 128 3584 Fri Aug 17 16:49:37 2001
Null.SYS BA740000 0 128 384 Fri Aug 17 16:47:39 2001
AvgArCln.sys BA741000 1024 128 0 Thu Jan 18 07:00:28 2007
HIDPARSE.SYS BA3D8000 11264 1408 8576 Wed Aug 04 02:08:15 2004
vga.sys BA3E0000 1024 128 15360 Wed Aug 04 02:07:06 2004
mnmdd.SYS BA5E0000 0 0 1792 Fri Aug 17 16:57:28 2001
RDPCDD.sys BA5E2000 0 0 1792 Fri Aug 17 16:46:56 2001
Msfs.SYS BA3E8000 896 128 12032 Wed Aug 04 02:00:37 2004
Npfs.SYS BA3F0000 1792 256 21120 Wed Aug 04 02:00:38 2004
rasacd.sys BA56C000 3840 128 512 Fri Aug 17 16:55:39 2001
ipsec.sys B073C000 62464 2560 1536 Wed Aug 04 02:14:27 2004
tcpip.sys B06E4000 256384 42240 20096 Wed Aug 04 02:14:39 2004
Mpfp.sys B0699000 90112 24576 0 Fri Mar 02 14:16:50 2007
ipnat.sys B0678000 77952 37120 5888 Wed Aug 04 02:04:48 2004
wanarp.sys BA178000 22528 896 3456 Wed Aug 04 02:04:57 2004
ipfltdrv.sys BA188000 19840 2560 3456 Fri Aug 17 16:55:07 2001
netbt.sys B0650000 109824 1664 34048 Wed Aug 04 02:14:36 2004
afd.sys B062E000 4096 2048 111488 Wed Aug 04 02:14:13 2004
netbios.sys BA198000 14976 768 12160 Wed Aug 04 02:03:19 2004
SASKUTIL.sys BA1B8000 0 0 0
SASDIFSV.SYS BA3F8000 0 0 0
rdbss.sys B0562000 35712 2816 113408 Wed Aug 04 02:20:05 2004
mrxsmb.sys B04F3000 114944 18432 276992 Wed Aug 04 02:15:14 2004
Fips.SYS BA1C8000 22016 768 3584 Fri Aug 17 21:31:49 2001
Cdfs.SYS BA208000 6912 640 46336 Wed Aug 04 02:14:09 2004
dump_atapi.sys B04DB000 0 0 0
dump_WMILIB.SYS BA5E6000 0 0 0
win32k.sys BF800000 1614464 77184 0 Wed Aug 04 02:17:30 2004
watchdog.sys BA408000 3712 128 8576 Wed Aug 04 02:07:32 2004
Dxapi.sys B8F83000 6272 384 640 Fri Aug 17 16:53:19 2001
dxg.sys BF000000 61312 896 0 Wed Aug 04 02:00:51 2004
dxgthk.sys BA70C000 128 0 0 Fri Aug 17 16:53:12 2001
ati2dvag.dll BF012000 249856 8192 0 Thu Nov 01 23:09:00 2007
ati2cqag.dll BF057000 229376 221184 0 Thu Nov 01 22:16:54 2007
atikvmag.dll BF0D1000 241664 172032 0 Thu Nov 01 22:24:52 2007
ATMFD.DLL BFFA0000 208512 34560 0 Wed Aug 04 03:56:56 2004
ndisuio.sys AE1A3000 7168 256 768 Wed Aug 04 02:03:10 2004
mrxdav.sys ADF16000 26368 5504 129024 Wed Aug 04 02:00:49 2004
ParVdm.SYS BA656000 1408 128 0 Fri Aug 17 16:49:49 2001
pstrip.sys BA4A8000 10016 256 2400 Tue May 08 05:51:01 2007
HTTP.sys ADDE5000 94592 26624 97920 Wed Aug 04 02:00:09 2004
srv.sys ADD6A000 54400 8192 240896 Wed Aug 04 02:14:44 2004
mfehidk.sys ADA21000 113728 17376 0 Fri Jun 08 22:17:21 2007
mfesmfk.sys BA360000 20160 1568 0 Fri Jun 08 22:20:30 2007
mfebopk.sys BA380000 18080 1568 0 Fri Jun 08 22:19:31 2007
BOCDRIVE.sys BA388000 0 0 0
mfeavfk.sys ADADA000 49440 1600 0 Wed Oct 04 16:56:02 2006
wdmaud.sys AD624000 8832 2048 64384 Wed Aug 04 02:15:03 2004
sysaudio.sys AD739000 3072 128 47360 Wed Aug 04 02:15:54 2004
kmixer.sys AD5D7000 14336 35840 105216 Wed Aug 04 02:07:46 2004
ntdll.dll 7C900000 503808 20480 0 Wed Aug 04 03:56:36 2004
------------------------------------------------------------------------------
Total 9429184 2800416 4901472

EVENTVIEWER:

The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x00000000, 0x0000001c, 0x00000008, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



12/24/200712:07:10 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the running state.
12/24/200712:07:10 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the paused state.
12/24/200712:07:08 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the running state.
12/24/200712:07:08 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the paused state.
12/24/200712:07:05 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The McAfee Real-time Scanner service was successfully sent a continue control.
12/24/200712:07:05 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the running state.
12/24/200712:05:11 AMWindows Update AgentInformationInstallation 18N/AADMIN-62BE8A099Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Monday, December 24, 2007 at 3:00 AM:
- Security Update for Windows XP (KB928843)
- Security Update for Windows XP (KB890859)
- Security Update for Windows XP (KB944653)
- Security Update for Windows XP (KB914389)
- Security Update for Windows XP (KB920683)
- Security Update for Windows XP (KB908519)
- Update for Windows XP (KB894391)
- Security Update for Windows XP (KB935839)
- Security Update for Windows XP (KB896428)
- Security Update for Windows XP (KB913580)
- Security Update for Windows XP (KB905749)
- Security Update for Windows XP (KB908531)
- Microsoft .NET Framework 1.1 Service Pack 1
- Cumulative Security Update for Internet Explorer 6 for Windows XP (KB942615)
- Update for Windows XP (KB930916)
- Update for Windows XP (KB916595)
- Critical Update for Windows XP (KB886185)
- Security Update for Windows XP (KB935840)
- Security Update for Windows XP (KB920213)
- Security Update for Windows XP (KB938127)
- Security Update for Windows XP (KB900725)
- Security Update for Windows XP (KB888302)
- Security Update fo
12/24/200712:04:42 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the stopped state.
12/24/200712:04:39 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The HTTP SSL service entered the running state.
12/24/200712:04:39 AMService Control ManagerInformationNone7035NT AUTHORITY\LOCAL SERVICEADMIN-62BE8A099The HTTP SSL service was successfully sent a start control.
12/24/200712:04:36 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Application Layer Gateway Service service entered the running state.
12/24/200712:04:36 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Application Layer Gateway Service service was successfully sent a start control.
12/24/200712:04:36 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the running state.
12/24/200712:04:36 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Network Location Awareness (NLA) service entered the running state.
12/24/200712:04:36 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The BOClean Kernel Monitor. service was successfully sent a start control.
12/24/200712:04:36 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Network Location Awareness (NLA) service was successfully sent a start control.
12/24/200712:04:36 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The IMAPI CD-Burning COM Service service was successfully sent a start control.
12/24/200712:04:26 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Fast User Switching Compatibility service entered the running state.
12/24/200712:04:26 AMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Fast User Switching Compatibility service was successfully sent a start control.
12/24/200712:04:26 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Terminal Services service entered the running state.
12/24/200712:04:26 AMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the paused state.
12/24/200712:04:26 AMService Control ManagerErrorNone7026N/AADMIN-62BE8A099The following boot-start or system-start driver(s) failed to load:
m5289
12/24/200712:04:00 AMati2mtagErrorCRT 45062N/AADMIN-62BE8A099CRT invalid display type
12/24/200712:03:52 AMredbookInformationNone10N/AADMIN-62BE8A099This drive has not been shown to support digital audio playback.
12/24/200712:04:04 AMSave DumpInformationNone1001N/AADMIN-62BE8A099The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xe790b7d5, 0x00000000, 0xbf82e0f5, 0x00000002). A dump was saved in: C:\WINDOWS\MEMORY.DMP.
12/24/200712:04:03 AMEventLogInformationNone6005N/AADMIN-62BE8A099The Event log service was started.
12/24/200712:04:03 AMEventLogInformationNone6009N/AADMIN-62BE8A099Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.
12/23/200711:56:51 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Performance Logs and Alerts service entered the stopped state.
12/23/200711:56:51 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Performance Logs and Alerts service entered the running state.
12/23/200711:56:51 PMService Control ManagerInformationNone7035ADMIN-62BE8A099\This isADMIN-62BE8A099The Performance Logs and Alerts service was successfully sent a start control.
12/23/200711:56:51 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Performance Logs and Alerts service entered the stopped state.
12/23/200711:56:51 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Performance Logs and Alerts service entered the running state.
12/23/200711:56:51 PMService Control ManagerInformationNone7035ADMIN-62BE8A099\This isADMIN-62BE8A099The Performance Logs and Alerts service was successfully sent a start control.
12/23/200711:49:35 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Distributed Transaction Coordinator service entered the running state.
12/23/200711:49:34 PMService Control ManagerInformationNone7035ADMIN-62BE8A099\This isADMIN-62BE8A099The Distributed Transaction Coordinator service was successfully sent a start control.
12/23/200711:49:32 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The COM+ System Application service entered the running state.
12/23/200711:49:32 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The COM+ System Application service was successfully sent a start control.
12/23/200711:49:10 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Windows Installer service entered the stopped state.
12/23/200711:39:08 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the running state.
12/23/200711:39:08 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Real-time Scanner service entered the paused state.
12/23/200711:35:32 PMWindows File ProtectionInformationNone64002N/AADMIN-62BE8A099File replacement was attempted on the protected system file c:\program files\windows nt\htrn_jis.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.0.
12/23/200711:35:32 PMWindows File ProtectionInformationNone64002N/AADMIN-62BE8A099File replacement was attempted on the protected system file c:\program files\windows nt\dialer.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.2180.
12/23/200711:27:40 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Windows Installer service entered the running state.
12/23/200711:27:40 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Windows Installer service was successfully sent a start control.
12/23/200711:19:20 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200711:19:20 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200711:19:09 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200711:19:09 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200711:18:59 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200711:18:59 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200711:18:48 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200711:18:48 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200711:18:36 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the stopped state.
12/23/200711:18:30 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the running state.
12/23/200711:18:30 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The IMAPI CD-Burning COM Service service was successfully sent a start control.
12/23/200711:18:19 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Fast User Switching Compatibility service entered the running state.
12/23/200711:18:19 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Fast User Switching Compatibility service was successfully sent a start control.
12/23/200711:18:17 PMWindows Update AgentInformationInstallation 18N/AADMIN-62BE8A099Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Monday, December 24, 2007 at 3:00 AM:
- Security Update for Windows XP (KB928843)
- Security Update for Windows XP (KB890859)
- Security Update for Windows XP (KB944653)
- Security Update for Windows XP (KB914389)
- Security Update for Windows XP (KB920683)
- Security Update for Windows XP (KB908519)
- Update for Windows XP (KB894391)
- Security Update for Windows XP (KB935839)
- Security Update for Windows XP (KB896428)
- Security Update for Windows XP (KB913580)
- Security Update for Windows XP (KB905749)
- Security Update for Windows XP (KB908531)
- Microsoft .NET Framework 1.1 Service Pack 1
- Cumulative Security Update for Internet Explorer 6 for Windows XP (KB942615)
- Update for Windows XP (KB930916)
- Update for Windows XP (KB916595)
- Critical Update for Windows XP (KB886185)
- Security Update for Windows XP (KB935840)
- Security Update for Windows XP (KB920213)
- Security Update for Windows XP (KB938127)
- Security Update for Windows XP (KB900725)
- Security Update for Windows XP (KB888302)
- Security Update fo
12/23/200711:18:03 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Terminal Services service entered the running state.
12/23/200711:18:03 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Terminal Services service was successfully sent a start control.
12/23/200711:17:35 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The HTTP SSL service entered the running state.
12/23/200711:17:35 PMService Control ManagerInformationNone7035NT AUTHORITY\LOCAL SERVICEADMIN-62BE8A099The HTTP SSL service was successfully sent a start control.
12/23/200711:17:26 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Application Layer Gateway Service service entered the running state.
12/23/200711:17:26 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Application Layer Gateway Service service was successfully sent a start control.
12/23/200711:17:25 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Network Location Awareness (NLA) service entered the running state.
12/23/200711:17:25 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The BOClean Kernel Monitor. service was successfully sent a start control.
12/23/200711:17:25 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Network Location Awareness (NLA) service was successfully sent a start control.
12/23/200711:17:25 PMService Control ManagerErrorNone7026N/AADMIN-62BE8A099The following boot-start or system-start driver(s) failed to load:
m5289
12/23/200711:17:02 PMati2mtagErrorCRT 45062N/AADMIN-62BE8A099CRT invalid display type
12/23/200711:16:54 PMredbookInformationNone10N/AADMIN-62BE8A099This drive has not been shown to support digital audio playback.
12/23/200711:17:06 PMSave DumpInformationNone1001N/AADMIN-62BE8A099The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x80d54a41, 0x0000001c, 0x00000000, 0x805440b5). A dump was saved in: C:\WINDOWS\MEMORY.DMP.
12/23/200711:17:05 PMEventLogInformationNone6005N/AADMIN-62BE8A099The Event log service was started.
12/23/200711:17:05 PMEventLogInformationNone6009N/AADMIN-62BE8A099Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.
12/23/200710:47:13 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:47:13 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:47:02 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:47:02 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:46:52 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:46:52 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:46:41 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:46:41 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:37:50 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Update Manager service entered the stopped state.
12/23/200710:37:35 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The McAfee Update Manager service entered the running state.
12/23/200710:37:35 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The McAfee Update Manager service was successfully sent a start control.
12/23/200710:11:25 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:11:25 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:11:15 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:11:15 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:11:04 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:11:04 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:10:53 PMService Control ManagerErrorNone7000N/AADMIN-62BE8A099The Messenger Sharing Folders USN Journal Reader service service failed to start due to the following error:
The system cannot find the path specified.
12/23/200710:10:53 PMDCOMErrorNone10005ADMIN-62BE8A099\This isADMIN-62BE8A099"DCOM got error ""The system cannot find the path specified. "" attempting to start the service usnjsvc with arguments """" in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}"
12/23/200710:02:01 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the stopped state.
12/23/200710:01:55 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The IMAPI CD-Burning COM Service service entered the running state.
12/23/200710:01:54 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The IMAPI CD-Burning COM Service service was successfully sent a start control.
12/23/200710:01:44 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Fast User Switching Compatibility service entered the running state.
12/23/200710:01:44 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Fast User Switching Compatibility service was successfully sent a start control.
12/23/20079:58:15 PMWindows Update AgentInformationInstallation 18N/AADMIN-62BE8A099Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Monday, December 24, 2007 at 3:00 AM:
- Security Update for Windows XP (KB928843)
- Security Update for Windows XP (KB890859)
- Security Update for Windows XP (KB944653)
- Security Update for Windows XP (KB914389)
- Security Update for Windows XP (KB920683)
- Security Update for Windows XP (KB908519)
- Update for Windows XP (KB894391)
- Security Update for Windows XP (KB935839)
- Security Update for Windows XP (KB896428)
- Security Update for Windows XP (KB913580)
- Security Update for Windows XP (KB905749)
- Security Update for Windows XP (KB908531)
- Microsoft .NET Framework 1.1 Service Pack 1
- Cumulative Security Update for Internet Explorer 6 for Windows XP (KB942615)
- Update for Windows XP (KB930916)
- Update for Windows XP (KB916595)
- Critical Update for Windows XP (KB886185)
- Security Update for Windows XP (KB935840)
- Security Update for Windows XP (KB920213)
- Security Update for Windows XP (KB938127)
- Security Update for Windows XP (KB900725)
- Security Update for Windows XP (KB888302)
- Security Update fo
12/23/20079:58:05 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Terminal Services service entered the running state.
12/23/20079:58:05 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Terminal Services service was successfully sent a start control.
12/23/20079:57:37 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The HTTP SSL service entered the running state.
12/23/20079:57:37 PMService Control ManagerInformationNone7035NT AUTHORITY\LOCAL SERVICEADMIN-62BE8A099The HTTP SSL service was successfully sent a start control.
12/23/20079:57:28 PMService Control ManagerInformationNone7036N/AADMIN-62BE8A099The Network Location Awareness (NLA) service entered the running state.
12/23/20079:57:28 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The BOClean Kernel Monitor. service was successfully sent a start control.
12/23/20079:57:28 PMService Control ManagerInformationNone7035NT AUTHORITY\SYSTEMADMIN-62BE8A099The Network Location Awareness (NLA) service was successfully sent a start control.
12/23/20079:57:28 PMService Control ManagerErrorNone7026N/AADMIN-62BE8A099The following boot-start or system-start driver(s) failed to load:
m5289
12/23/20079:57:04 PMati2mtagErrorCRT 45062N/AADMIN-62BE8A099CRT invalid display type
12/23/20079:56:56 PMredbookInformationNone10N/AADMIN-62BE8A099This drive has not been shown to support digital audio playback.
12/23/20079:57:08 PMSave DumpInformationNone1001N/AADMIN-62BE8A099The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x00000000, 0x0000001c, 0x00000008, 0x00000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP.
12/23/20079:57:07 PMEventLogInformationNone6005N/AADMIN-62BE8A099The Event log service was started.
12/23/20079:57:07 PMEventLogInformationNone6009N/AADMIN-62BE8A099Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.


application:

12/24/200712:07:04 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/24/200712:04:22 AMMcLogEventErrorNone5022NT AUTHORITY\SYSTEMADMIN-62BE8A099MCSCAN32 Engine Initialisation failed. Engine returned error : 8
12/24/200712:04:21 AMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/24/200712:04:17 AMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/24/200712:04:14 AMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/24/200712:04:13 AMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/200711:49:35 PMMSDTCInformationDisk 2444N/AADMIN-62BE8A099MS DTC started with the following settings:

Security Configuration (OFF = 0 and ON = 1):
Network Administration of Transactions = 0,
Network Clients = 0,
Inbound Distributed Transactions using Native MSDTC Protocol = 0,
Outbound Distributed Transactions using Native MSDTC Protocol = 0,
Transaction Internet Protocol (TIP) = 0,
XA Transactions = 0
12/23/200711:39:09 PMMsiInstallerInformationNone11707ADMIN-62BE8A099\This isADMIN-62BE8A099Product: Windows Support Tools -- Installation operation completed successfully.
12/23/200711:29:49 PMMsiInstallerInformationNone11729ADMIN-62BE8A099\This isADMIN-62BE8A099Product: Debugging Tools for Windows -- Configuration failed.
12/23/200711:28:04 PMMsiInstallerInformationNone11707ADMIN-62BE8A099\This isADMIN-62BE8A099Product: Debugging Tools for Windows -- Installation operation completed successfully.
12/23/200711:17:25 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/23/200711:17:22 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/23/200711:17:14 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/200711:17:14 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/23/200711:17:14 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/200710:37:49 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/23/200710:37:35 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/200710:37:34 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/23/20079:57:28 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/23/20079:57:27 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/23/20079:57:16 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20079:57:16 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/23/20079:57:16 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/20079:42:14 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/23/20079:42:10 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/23/20079:42:02 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20079:42:02 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/23/20079:42:01 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/20079:40:52 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20079:40:47 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/23/20079:40:47 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/20077:30:57 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/23/20077:30:49 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20077:30:49 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/23/20076:08:42 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/23/20076:08:28 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20076:08:28 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/23/20074:31:47 PMApplication ErrorError(100)1004N/AADMIN-62BE8A099Faulting application svchost.exe, version 5.1.2600.2180, faulting module unknown, version 0.0.0.0, fault address 0x006f42c8.
12/23/20074:31:30 PMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/23/20071:39:16 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/23/20071:38:57 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20071:38:57 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/23/20071:38:43 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/23/20071:38:39 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/23/20071:38:33 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20071:38:29 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/23/20071:38:29 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/23/20074:40:19 AMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/23/20073:05:31 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/23/20073:05:15 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/23/20073:05:15 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/22/200711:55:46 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/22/200711:55:46 PMSecurityCenterErrorNone1802N/AADMIN-62BE8A099The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
12/22/200711:53:33 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/22/200711:53:22 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/200711:53:22 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/22/200711:53:21 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/22/200711:52:09 PMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/22/200711:52:08 PMUserenvWarningNone1524ADMIN-62BE8A099\This isADMIN-62BE8A099Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.


12/22/200710:36:25 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/22/200710:36:12 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/200710:36:12 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/22/20078:44:17 PMApplication ErrorError(100)1000N/AADMIN-62BE8A099Faulting application svchost.exe, version 5.1.2600.2180, faulting module unknown, version 0.0.0.0, fault address 0x006f42c8.
12/22/20078:25:02 PMWindows Live MessengerErrorNone1000N/AADMIN-62BE8A099The description for Event ID ( 1000 ) in Source ( Windows Live Messenger ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: msnmsgr.exe, 8.1.178.0, 45b12d6a, mshtml.dll, 6.0.2900.2180, 41109711, 0, 0012be92.
12/22/20078:19:12 PMMSDTCInformationDisk 2444N/AADMIN-62BE8A099MS DTC started with the following settings:

Security Configuration (OFF = 0 and ON = 1):
Network Administration of Transactions = 0,
Network Clients = 0,
Inbound Distributed Transactions using Native MSDTC Protocol = 0,
Outbound Distributed Transactions using Native MSDTC Protocol = 0,
Transaction Internet Protocol (TIP) = 0,
XA Transactions = 0
12/22/20078:15:37 PMApplication HangError(101)1002N/AADMIN-62BE8A099Hanging application paltalk.exe, version 9.91.2725.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
12/22/20076:07:23 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/22/20076:07:07 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/20076:07:07 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/22/20073:35:53 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/22/20073:35:42 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/22/20073:35:30 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/20073:35:29 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/22/20073:35:29 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/22/20071:38:21 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/22/20071:38:01 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/20071:38:01 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/22/20071:37:46 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/22/20071:37:42 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/22/20071:37:34 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/20071:37:34 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/22/20071:37:34 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/22/20071:36:41 PMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\Administrator registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/22/20071:36:41 PMUserenvWarningNone1524ADMIN-62BE8A099\AdministratorADMIN-62BE8A099Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.


12/22/20071:36:02 PMWinlogonInformationNone1002N/AADMIN-62BE8A099The shell stopped unexpectedly and Explorer.exe was restarted.
12/22/20071:35:00 PMWinlogonInformationNone1002N/AADMIN-62BE8A099The shell stopped unexpectedly and Explorer.exe was restarted.
12/22/20071:34:01 PMWinlogonInformationNone1002N/AADMIN-62BE8A099The shell stopped unexpectedly and Explorer.exe was restarted.
12/22/20072:59:53 AMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/22/20072:44:07 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/22/20072:43:50 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/20072:43:50 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/22/20071:24:47 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:37:30 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/22/200712:37:15 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:34:58 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/22/200712:27:42 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:22:57 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/22/200712:22:57 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:22:53 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/22/200712:17:19 AMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/22/200712:17:18 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5191.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/22/200712:17:10 AMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/22/200712:17:06 AMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/22/200712:17:06 AMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/22/200712:15:57 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:15:30 AMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/22/200712:12:50 AMApplication ErrorErrorNone1000N/AADMIN-62BE8A099Faulting application firefox.exe, version 1.8.20071.12718, faulting module myspell.dll, version 1.8.20071.12718, fault address 0x00002c69.
12/22/200712:12:40 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/22/200712:12:40 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32772
12/22/200712:12:36 AMHDD Info ServiceInformationNone7NT AUTHORITY\SYSTEMADMIN-62BE8A099OnDeviceChange. Event type = 32768
12/21/200710:15:45 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/21/200710:15:36 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 0.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/200710:14:48 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/200710:14:48 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/21/200710:01:36 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/21/200710:01:21 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/200710:01:14 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/200710:01:10 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/200710:01:10 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/21/20075:46:30 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/21/20075:45:43 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20075:45:43 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/21/20074:11:47 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/20074:11:45 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/21/20074:11:36 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20074:11:36 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/20074:11:36 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/21/20074:10:26 PMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/21/20074:10:00 PMApplication ErrorErrorNone1000N/AADMIN-62BE8A099Faulting application paltalk.exe, version 9.91.2725.0, faulting module webvideo.dll, version 1.2.2725.0, fault address 0x000112c1.
12/21/20074:09:32 PMApplication ErrorErrorNone1000N/AADMIN-62BE8A099Faulting application paltalk.exe, version 9.91.2725.0, faulting module webvideo.dll, version 1.2.2725.0, fault address 0x000112c1.
12/21/20072:13:44 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/20072:13:39 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/21/20072:13:34 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20072:13:31 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/20072:13:30 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/21/20072:11:10 PMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/21/20072:08:34 PMApplication ErrorErrorNone1000N/AADMIN-62BE8A099Faulting application paltalk.exe, version 9.91.2725.0, faulting module mshtml.dll, version 6.0.2900.2180, fault address 0x0005987e.
12/21/20072:08:28 PMApplication ErrorErrorNone1000N/AADMIN-62BE8A099Faulting application paltalk.exe, version 9.91.2725.0, faulting module mshtml.dll, version 6.0.2900.2180, fault address 0x0005987e.
12/21/20071:37:30 PMWindows Live MessengerErrorNone1000N/AADMIN-62BE8A099The description for Event ID ( 1000 ) in Source ( Windows Live Messenger ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: msnmsgr.exe, 8.1.178.0, 45b12d6a, mshtml.dll, 6.0.2900.2180, 41109711, 0, 0005987e.
12/21/20071:27:49 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/21/20071:27:35 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20071:27:35 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/21/20071:17:39 PMWindows Live MessengerErrorNone1000N/AADMIN-62BE8A099The description for Event ID ( 1000 ) in Source ( Windows Live Messenger ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: msnmsgr.exe, 8.1.178.0, 45b12d6a, mshtml.dll, 6.0.2900.2180, 41109711, 0, 0005987e.
12/21/20071:16:52 PMApplication ErrorError(100)1000N/AADMIN-62BE8A099Faulting application mcupdmgr.exe, version 7.2.142.0, faulting module mcscan32.dll, version 5.200.0.2160, fault address 0x001ae966.
12/21/20071:16:33 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20071:16:32 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/21/20071:16:19 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/20071:16:15 PMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/21/20071:16:07 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20071:16:07 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/20071:16:07 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/21/20071:13:12 PMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20071:13:12 PMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/20071:13:11 PMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/21/20071:09:21 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/21/20071:09:02 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/20071:09:01 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/21/200712:19:58 AMWinlogonInformationNone1002N/AADMIN-62BE8A099The shell stopped unexpectedly and Explorer.exe was restarted.
12/21/200712:06:25 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/21/200712:02:07 AMMcLogEventErrorNone5022NT AUTHORITY\SYSTEMADMIN-62BE8A099MCSCAN32 Engine Initialisation failed. Engine returned error : 8
12/21/200712:02:06 AMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/21/200712:01:59 AMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/21/200712:01:58 AMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/21/200712:01:58 AMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/20/20078:41:36 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/20/20078:41:26 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5190.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/20/20078:39:55 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/20078:39:55 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/20/20075:11:44 PMWindows Live MessengerErrorNone1000N/AADMIN-62BE8A099The description for Event ID ( 1000 ) in Source ( Windows Live Messenger ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: msnmsgr.exe, 8.1.178.0, 45b12d6a, mshtml.dll, 6.0.2900.2180, 41109711, 0, 0012be92.
12/20/20074:11:04 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/20/20074:10:51 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/20074:10:51 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/20/200711:41:42 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/20/200711:41:16 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/200711:41:16 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/20/200711:41:02 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5189.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/20/200711:40:57 AMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/20/200711:40:49 AMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/200711:40:49 AMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/20/200711:40:48 AMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/20/20073:51:59 AMUserenvWarningNone1517NT AUTHORITY\SYSTEMADMIN-62BE8A099Windows saved user ADMIN-62BE8A099\This is registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
12/20/20071:41:31 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5189.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/20/20071:36:30 AMMcLogEventErrorNone5022NT AUTHORITY\SYSTEMADMIN-62BE8A099MCSCAN32 Engine Initialisation failed. Engine returned error : 8
12/20/20071:36:26 AMSecurityCenterInformationNone1800N/AADMIN-62BE8A099The Windows Security Center Service has started.
12/20/20071:36:14 AMMcAfee HackerWatch ServiceInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( McAfee HackerWatch Service ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/20071:36:11 AMHDD Info ServiceNoneNone4NT AUTHORITY\SYSTEMADMIN-62BE8A099Service started
12/20/20071:36:09 AMATI SmartInformationNone105N/AADMIN-62BE8A099The service was started.
12/20/200712:24:39 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service stopped.
12/20/200712:24:26 AMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 5188.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/20/200712:23:38 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/20/200712:23:38 AMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Calling RegisterServiceCtrlHandlerEx()....
12/19/20077:55:25 PMMcLogEventInformationNone5000NT AUTHORITY\SYSTEMADMIN-62BE8A099McShield service started.
Engine version : 5200.2160
DAT version : 0.0000

Number of signatures in EXTRA.DAT : None
Names of threats that EXTRA.DAT can detect : None
12/19/20077:54:26 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
12/19/20077:54:26 PMmcmispupdmgrInformationNone0N/AADMIN-62BE8A099The description for Event ID ( 0 ) in Source ( mcmispupdmgr ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Suppo