Incompatible with Drive Encryption: WinMagic SecureDoc

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc 4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only cure.
I only receive the SD errors when they are preceded by a WinDefend message,
so that's what leads me to believe this is an incompatibility with WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
..
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
..
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
I wanted to get that last post out while I had the information up (I was
afraid a reboot might do me in). I've now had the opportunity to do more
testing and wanted to post my results. Although something Windows Defender
was doing triggered the series of SD errors every time, I don't believe it's
at fault since I have been able to reproduce the problem with other software,
even when Windows Defender is uninstalled. I'll follow up with WinMagic
technical support and will hopefully be able to confirm a working install of
WD under SecureDoc once we get the previously mentioned issues worked out.

Aaron Oneal said:
Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc 4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only cure.
I only receive the SD errors when they are preceded by a WinDefend message,
so that's what leads me to believe this is an incompatibility with WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
Mike Treit is investigating one issue with a drive encryption driver which
prevents scans from completing. I see that you feel Windows Defender is not
the cause of the problems with the driver you are seeing, but I want to
alert you to the fact that scans may well not complete successfully, either.
The problem I'm describing is on the road to a fix in the next UI
release--but I'll make sure that Mike spots your message as well, in case a
different encryption vendor is involved--so he can give the fix broader
testing.

--

Aaron Oneal said:
Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc
4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only
cure.
I only receive the SD errors when they are preceded by a WinDefend
message,
so that's what leads me to believe this is an incompatibility with
WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential
malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential
malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and
Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information
or
message DLL files to display messages from a remote computer. You may be
able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information
or
message DLL files to display messages from a remote computer. You may be
able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
Version 1.1.1347.0 is out.
http://www.microsoft.com/downloads/...e7-da2b-4a6a-afa4-f7f14e605a0d&DisplayLang=en
Users who normally select advanced Spynet membership should be aware that
the install process will set you back to basic membership, so it's a good
idea to revisit both the Spynet membership area of Tools, and the Options
area--to see what's different, and check that your old choices have been
preserved.
--

Aaron Oneal said:
Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc 4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only cure.
I only receive the SD errors when they are preceded by a WinDefend message,
so that's what leads me to believe this is an incompatibility with WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
I've upgraded to the latest build of Windows Defender and the problem seems
to have gone away, though I still need to do a reboot to be sure. Thanks!

Windows Defender Version: 1.1.1347.0
Engine Version: 1.1.1372.0
Definition Version: 1.14.1436.4

Engel said:
Version 1.1.1347.0 is out.
http://www.microsoft.com/downloads/...e7-da2b-4a6a-afa4-f7f14e605a0d&DisplayLang=en
Users who normally select advanced Spynet membership should be aware that
the install process will set you back to basic membership, so it's a good
idea to revisit both the Spynet membership area of Tools, and the Options
area--to see what's different, and check that your old choices have been
preserved.
--

Aaron Oneal said:
Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc 4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only cure.
I only receive the SD errors when they are preceded by a WinDefend message,
so that's what leads me to believe this is an incompatibility with WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
Hi Aaron,

Glad to help and thanx for updating the thread.

(¯`·._.·Еиçеl·._.·´¯)
--


Aaron Oneal said:
I've upgraded to the latest build of Windows Defender and the problem seems
to have gone away, though I still need to do a reboot to be sure. Thanks!

Windows Defender Version: 1.1.1347.0
Engine Version: 1.1.1372.0
Definition Version: 1.14.1436.4

Engel said:
Version 1.1.1347.0 is out.
http://www.microsoft.com/downloads/...e7-da2b-4a6a-afa4-f7f14e605a0d&DisplayLang=en
Users who normally select advanced Spynet membership should be aware that
the install process will set you back to basic membership, so it's a good
idea to revisit both the Spynet membership area of Tools, and the Options
area--to see what's different, and check that your old choices have been
preserved.
--

Aaron Oneal said:
Hello,

I recently encrypted my Motion LE1600 Tablet PC with WinMagic SecureDoc 4.1
SR3. Shortly after startup I receive the messages that follow and this
leaves the SecureDoc driver in an unstable state which results in
applications being unable to write to disk. A swift reboot is the only cure.
I only receive the SD errors when they are preceded by a WinDefend message,
so that's what leads me to believe this is an incompatibility with WinDefend.
I'll be removing WinDefend from this machine to see if that solves the
problem, and if so will post back here with the results and will contact
WinMagic's technical support as well.

Windows Defender Version: 1.1.1051.0
Engine Version: 1.1.1372.0
Signature Version: 1.14.1436.4

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:41 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk;startup:C:\Documents
and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed
Launcher.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:42 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {BF37E182-CC7F-46E3-BF39-9AE7B9DDFCA2}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Warning
Event Source: WinDefend
Event Category: None
Event ID: 3004
Date: 5/4/2006
Time: 9:34:55 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has detected potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Path Found: file:C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\PGPtray.exe.lnk;startup:C:\Documents and Settings\All
Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
Threat Classification: Unknown
Detection Type:


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Information
Event Source: WinDefend
Event Category: None
Event ID: 3005
Date: 5/4/2006
Time: 9:34:57 AM
User: N/A
Computer: VALKYRIE
Description:
Windows Defender Real-Time Protection agent has taken action to protect
this machine from potential malware.
For more information please see the following:
http://www.microsoft.com
Scan ID: {8BF55A5F-5C7C-4C06-A7CC-01146ED50FE8}
User: VALKYRIE\Aaron
Threat Name: Unknown
Threat Id:
Threat Severity:
Threat Category:
Threat Classification: Unknown
Action: Ignore


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE a1e6 sector 6fc7aa7 mode 6
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

Event Type: Error
Event Source: SDDisk2K
Event Category: None
Event ID: 7035
Date: 5/4/2006
Time: 9:37:09 AM
User: N/A
Computer: VALKYRIE
Description:
The description for Event ID ( 7035 ) in Source ( SDDisk2K ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event:
\Device\SecureDocDevice, WM, SDE1 SDstart 6fc722b size a53
.
Data:
0000: 00 00 00 00 03 00 52 00 ......R.
0008: 00 00 00 00 7b 1b 00 00 ....{...
0010: fa 00 00 00 7b 1b 00 00 ú...{...
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........


System Information report written at: 04/05/06 06:55:31
System Name: VALKYRIE
[System Summary]

Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 2 Build 2600
OS Manufacturer Microsoft Corporation
System Name VALKYRIE
System Manufacturer Motion Computing
System Model LE1600
System Type X86-based PC
Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1500 Mhz
BIOS Version/Date Motion Computing - LE1600 A06, 1/18/2006
SMBIOS Version 2.34
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)"
User Name VALKYRIE\Aaron
Time Zone Eastern Standard Time
Total Physical Memory 1,536.00 MB
Available Physical Memory 911.30 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
 
Back
Top