No System Restore should work if you
have a valid restore point file. But don't
count on System Restore to fix the problem.
Log Files.
Windows Event logs.
AV software scan results log files.
Hibernation file:
Located in the root of your Windows partition.
typically C:\ and only present if you have hibernation
turned on.
Hard Drive S.M.A.R.T. Check:
HD Tune:
http://www.hdtune.com/
Speedfan: (has an online report of your drives fitness:
http://www.almico.com/speedfan.php
I tried Disk Diagnostic Utilities from:
Western Digital's Data LifeGuard Diagnostics
and after about 8 hours it found no errors or bad sectors.
I used event logger and found some of the following errors or
warnings.
ACEEventLog
1)
Windows Operating System
ID: 4101
Source: Ci
Version: 5.0
Component: Application Event Log
Symbolic Name: MSG_CI_SERVICE_TOO_MANY_BLOCKS
Message: The content index filter for file "%1" generated
content data more than %2 times the file's size.
The content index filter for file "c:\windows\internet
logs\zalog2009.02.07.txt" generated content data more than 8
times the file's size.
2)
Product: Windows Operating System
ID: 1015
Source: EvntAgnt
Version: 5.2
Symbolic Name: SNMPELEA_NO_REGISTRY_TRACE_LEVEL_PARAMETER
Message: TraceLevel parameter not located in registry; Default
trace level used is %1.
Explanation
Debug tracing is turned off. This is the default condition of the
system. Debug tracing should only be turned on when you are debugging
software.
These error events will continue to be logged when you restart the
computer, unless you reconfigure the Evntagnt.dl
3)Type: Error
Date: 7/13/2009
Time: 5:48:09 PM
Event: 259
Source: ColdFusion MX Application Server
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
The ColdFusion MX Application Server service could not be started.
Check the server "default" log files for more information.
4)Type: Error
Date: 7/13/2009
Time: 5:47:31 PM
Event: 4
Source: Media Center Receiver
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
TV tuner malfunction. (0xc0040597) Dazzle DVC90 TVTuner
5)Type: Warning
Date: 7/13/2009
Time: 5:43:48 PM
Event: 1517
Source: Userenv
Category: None
User: \SYSTEM
Computer: 732REDHILLFR
Description:
Windows saved user 732REDHILLFR\HP_Administrator registry while an
application or service was still using the registry during log off.
The memory used by the user's registry has not been freed. The
registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try
configuring the services to run in either the LocalService or
NetworkService account.
6)Type: Error
Date: 7/13/2009
Time: 12:00:39 PM
Event: 1002
Source: MsiInstaller
Category: None
User: 732REDHILLFR\HP_Administrator
Computer: 732REDHILLFR
Description:
Unexpected or missing value (name: 'BeavCom', value: '
Norton_Utilities') in key
'HKLM\Products\AB7687A6AC7B9CC4CABA58AB6468E55E\Features'
Lots of these
7)Type: Error
Date: 7/13/2009
Time: 8:47:05 AM
Event: 20
Source: Google Update
Category: None
User: \SYSTEM
Computer: 732REDHILLFR
Description:
The description for Event ID ( 20 ) in Source ( Google Update ) could
not be found. It contains the following insertion string(s): .
Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=
https://tools.google.com/service/update2
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x800
8)Type: Error
Date: 7/10/2009
Time: 8:04:08 AM
Event: 1002
Source: Application Hang
Category: (101)
User: N/A
Computer: 732REDHILLFR
Description:
Hanging application Weather.exe, version 6.7.0.10, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
9)Type: Error
Date: 7/10/2009
Time: 8:03:00 AM
Event: 1000
Source: Application Error
Category: (100)
User: N/A
Computer: 732REDHILLFR
Description:
Faulting application CCSVCHST.EXE, version 107.0.6.4, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.
APPLICATION LOG
1) Type: Warning
Date: 7/13/2009
Time: 6:10:00 PM
Event: 4101
Source: Ci
Category: CI Service
User: N/A
Computer: 732REDHILLFR
Description:
The content index filter for file "c:\windows\internet
logs\zalog2009.02.07.txt" generated content data more than 8
times the file's size.
2)Type: Warning
Date: 7/13/2009
Time: 5:49:44 PM
Event: 1015
Source: EvntAgnt
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
TraceLevel parameter not located in registry;
Default trace level used is 32.
3)Type: Error
Date: 7/13/2009
Time: 5:48:09 PM
Event: 259
Source: ColdFusion MX Application Server
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
The ColdFusion MX Application Server service could not be started.
Check the server "default" log files for more information.
4)Type: Error
Date: 7/13/2009
Time: 5:47:31 PM
Event: 4
Source: Media Center Receiver
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
TV tuner malfunction. (0xc0040597) Dazzle DVC90 TVTuner
5)Type: Warning
Date: 7/13/2009
Time: 5:43:48 PM
Event: 1517
Source: Userenv
Category: None
User: \SYSTEM
Computer: 732REDHILLFR
Description:
Windows saved user 732REDHILLFR\HP_Administrator registry while an
application or service was still using the registry during log off.
The memory used by the user's registry has not been freed. The
registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try
configuring the services to run in either the LocalService or
NetworkService account.
6_Type: Error
Date: 7/13/2009
Time: 12:00:39 PM
Event: 1002
Source: MsiInstaller
Category: None
User: 732REDHILLFR\HP_Administrator
Computer: 732REDHILLFR
Description:
Unexpected or missing value (name: 'BeavCom', value: '
Norton_Utilities') in key
'HKLM\Products\AB7687A6AC7B9CC4CABA58AB6468E55E\Features'
7)Type: Error
Date: 7/13/2009
Time: 7:47:05 AM
Event: 20
Source: Google Update
Category: None
User: \SYSTEM
Computer: 732REDHILLFR
Description:
The description for Event ID ( 20 ) in Source ( Google Update ) could
not be found. It contains the following insertion string(s): .
Network Request Error.
Error: 0x80040801. Http status code: 0.
Url=
https://tools.google.com/service/update2
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying WinHTTP.
Send request returned 0x80040801. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80040801. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x800
8)Type: Error
Date: 7/12/2009
Time: 8:49:54 PM
Event: 1002
Source: Application Hang
Category: (101)
User: N/A
Computer: 732REDHILLFR
Description:
Hanging application Weather.exe, version 6.7.0.10, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
9)Type: Error
Date: 7/12/2009
Time: 11:56:13 AM
Event: 1027
Source: Speed Disk service
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
The description for Event ID ( 1027 ) in Source ( Speed Disk service )
could not be found. It contains the following insertion string(s): .
C:
10)Type: Error
Date: 7/11/2009
Time: 11:35:03 AM
Event: 8
Source: crypt32
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
Failed auto update retrieval of third-party root list sequence number
from:
<
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested
operation.
OSESSION
1)Type: Error
Date: 6/26/2009
Time: 12:58:11 AM
Event: 7001
Source: Microsoft Office 12 Sessions
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 282 seconds with 240 seconds of active time. This session
ended with a crash.
2)Type: Warning
Date: 6/21/2009
Time: 1:21:45 PM
Event: 7003
Source: Microsoft Office 12 Sessions
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session
was terminated unexpectedly.
SYSTEM
1)Type: Warning
Date: 7/14/2009
Time: 11:05:20 AM
Event: 51
Source: Disk
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
An error was detected on device \Device\Harddisk7\D during a paging
operation.
Note: several of these occured, but none of the software tools I used
found any errors.
2)Type: Warning
Date: 7/14/2009
Time: 10:03:28 AM
Event: 4226
Source: Tcpip
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
TCP/IP has reached the security limit imposed on the number of
concurrent TCP connect attempts.
3)Type: Warning
Date: 7/13/2009
Time: 10:21:00 PM
Event: 36
Source: W3SVC
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
The server failed to load application '/LM/W3SVC/1/ROOT'. The error
was 'Class not registered
'.
For additional information specific to this message please visit the
Microsoft Online Support site located at:
http://www.microsoft.com/contentredirect.asp.
4)Type: Error
Date: 7/13/2009
Time: 5:49:33 PM
Event: 7026
Source: Service Control Manager
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
The following boot-start or system-start driver(s) failed to load:
ftsata2
5)Type: Error
Date: 7/13/2009
Time: 10:16:07 AM
Event: 402
Source: smtpsvc
Category: None
User: N/A
Computer: 732REDHILLFR
Description:
Virtual Server 1:
212.180.41.254 maximum number of connections has been reached.
Connection being closed.
There about 50 of these errors recorded
Harold A Climer
Dept. Of Physics Geology, and Astronomy
U.T, Chattanooga
Rm. 406A Engineering, Math & Computer Science Building
615 McCallie Ave. Chattanooga TN 37403
(e-mail address removed)