Startup Message

  • Thread starter Thread starter Scott
  • Start date Start date
S

Scott

xp home - on startup i get this "The system could not log you on....." with
a username and filled out password (black dots) in the background. I then
kill the message and get a screen with my username symbol, click it, and
thigns then go normal. What can I do to get rid of the error message.
 
Scott said:
xp home - on startup i get this "The system could not log you on....." with
a username and filled out password (black dots) in the background. I then
kill the message and get a screen with my username symbol, click it, and
thigns then go normal. What can I do to get rid of the error message.


Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

How to perform a clean boot in Windows XP
http://support.microsoft.com/?id=310353
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222/en-us
HTH.
nass
 
I've got a list of errors going back a few months.
I printed out the boot procedurers.

What do I do with them?
--
JSS


nass said:
Scott said:
xp home - on startup i get this "The system could not log you on....." with
a username and filled out password (black dots) in the background. I then
kill the message and get a screen with my username symbol, click it, and
thigns then go normal. What can I do to get rid of the error message.


Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

How to perform a clean boot in Windows XP
http://support.microsoft.com/?id=310353
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222/en-us
HTH.
nass
 
Please copy & paste the error messages to a notepad as Highlighted in my
previous post and paste them in your next post.
Note: If the error reapeated don't copy it as one will suffice!.
For example:
<Quote from another post::>
Event Type: Error
Event Source: Application Hang
Event Category: None
Event ID: 1001
Date: 14/01/2008
Time: 18:29:05
User: N/A
Computer: JON
Description:
Fault bucket 504754043.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 42 75 63 6b 65 74 3a 20 Bucket:
0008: 35 30 34 37 35 34 30 34 50475404
0010: 33 0d 0a 3..


Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 04/01/2008
Time: 18:39:52
User: NT AUTHORITY\SYSTEM
Computer: JON
Description:
Windows saved user JON\Jonathan registry while an application or service was
still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
</Quote from another post::>
HTH

Scott said:
I've got a list of errors going back a few months.
I printed out the boot procedurers.

What do I do with them?
--
JSS


nass said:
Scott said:
xp home - on startup i get this "The system could not log you on....." with
a username and filled out password (black dots) in the background. I then
kill the message and get a screen with my username symbol, click it, and
thigns then go normal. What can I do to get rid of the error message.


Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

How to perform a clean boot in Windows XP
http://support.microsoft.com/?id=310353
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222/en-us
HTH.
nass
 
APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 00 70 00 70 00 6c 00 A.p.p.l.
0008: 69 00 63 00 61 00 74 00 i.c.a.t.
0010: 69 00 6f 00 6e 00 20 00 i.o.n. .
0018: 46 00 61 00 69 00 6c 00 F.a.i.l.
0020: 75 00 72 00 65 00 20 00 u.r.e. .
0028: 20 00 77 00 69 00 6e 00 .w.i.n.
0030: 77 00 6f 00 72 00 64 00 w.o.r.d.
0038: 2e 00 65 00 78 00 65 00 ..e.x.e.
0040: 20 00 31 00 32 00 2e 00 .1.2...
0048: 30 00 2e 00 36 00 32 00 0...6.2.
0050: 31 00 31 00 2e 00 31 00 1.1...1.
0058: 30 00 30 00 30 00 20 00 0.0.0. .
0060: 34 00 36 00 64 00 34 00 4.6.d.4.
0068: 61 00 37 00 64 00 66 00 a.7.d.f.
0070: 20 00 69 00 6e 00 20 00 .i.n. .
0078: 6b 00 65 00 72 00 6e 00 k.e.r.n.
0080: 65 00 6c 00 33 00 32 00 e.l.3.2.
0088: 2e 00 64 00 6c 00 6c 00 ..d.l.l.
0090: 20 00 35 00 2e 00 31 00 .5...1.
0098: 2e 00 32 00 36 00 30 00 ..2.6.0.
00a0: 30 00 2e 00 33 00 31 00 0...3.1.
00a8: 31 00 39 00 20 00 34 00 1.9. .4.
00b0: 36 00 32 00 33 00 39 00 6.2.3.9.
00b8: 62 00 64 00 35 00 20 00 b.d.5. .
00c0: 66 00 44 00 65 00 62 00 f.D.e.b.
00c8: 75 00 67 00 20 00 30 00 u.g. .0.
00d0: 20 00 61 00 74 00 20 00 .a.t. .
00d8: 6f 00 66 00 66 00 73 00 o.f.f.s.
00e0: 65 00 74 00 20 00 30 00 e.t. .0.
00e8: 30 00 30 00 31 00 32 00 0.0.1.2.
00f0: 61 00 35 00 62 00 0d 00 a.5.b...
00f8: 0a 00 ..

3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 0e 00 00 00 04 00 4e 00 ......N.
0008: 00 00 00 00 01 00 00 c0 .......À
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

3.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

9.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1001
Date: 1/6/2008
Time: 12:17:16 PM
User: N/A
Computer: SCOTT123
Description:
Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0004E27C4906. The
following error occurred:
The operation was canceled by the user. . Your computer will continue to try
and obtain an address on its own from the network address (DHCP) server.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: c7 04 00 00 Ç...

10.
Event Type: Error
Event Source: Application Popup
Event Category: None
Event ID: 877
Date: 1/5/2008
Time: 9:46:00 AM
User: N/A
Computer: SCOTT123
Description:
There was error [DATABASE OPEN FAILED] processing the driver database.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 02 00 64 00 ......d.
0008: 00 00 00 00 6d 03 00 c0 ....m..À
0010: 00 00 00 00 6d 03 00 c0 ....m..À
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........

11.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1002
Date: 12/27/2007
Time: 3:30:50 PM
User: N/A
Computer: SCOTT123
Description:
The IP address lease 64.195.65.187 for the Network Card with network address
0007E95E0E3F has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

12.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 12/26/2007
Time: 11:40:14 AM
User: N/A
Computer: SCOTT123
Description:
The following boot-start or system-start driver(s) failed to load:
SYMTDI

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



..

--
JSS


nass said:
Please copy & paste the error messages to a notepad as Highlighted in my
previous post and paste them in your next post.
Note: If the error reapeated don't copy it as one will suffice!.
For example:
<Quote from another post::>
Event Type: Error
Event Source: Application Hang
Event Category: None
Event ID: 1001
Date: 14/01/2008
Time: 18:29:05
User: N/A
Computer: JON
Description:
Fault bucket 504754043.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 42 75 63 6b 65 74 3a 20 Bucket:
0008: 35 30 34 37 35 34 30 34 50475404
0010: 33 0d 0a 3..


Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 04/01/2008
Time: 18:39:52
User: NT AUTHORITY\SYSTEM
Computer: JON
Description:
Windows saved user JON\Jonathan registry while an application or service was
still using the registry during log off. The memory used by the user's
registry has not been freed. The registry will be unloaded when it is no
longer in use.
</Quote from another post::>
HTH

Scott said:
I've got a list of errors going back a few months.
I printed out the boot procedurers.

What do I do with them?
--
JSS


nass said:
:

xp home - on startup i get this "The system could not log you on....." with
a username and filled out password (black dots) in the background. I then
kill the message and get a screen with my username symbol, click it, and
thigns then go normal. What can I do to get rid of the error message.


Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

How to perform a clean boot in Windows XP
http://support.microsoft.com/?id=310353
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222/en-us
HTH.
nass
 
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
9.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1001
Date: 1/6/2008
Time: 12:17:16 PM
User: N/A
Computer: SCOTT123
Description:
Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0004E27C4906. The
following error occurred:
The operation was canceled by the user. . Your computer will continue to try
and obtain an address on its own from the network address (DHCP) server.

Event ID 1001 — DHCP Client Lease Validity
http://technet2.microsoft.com/windo...0bb4-49e4-92be-aabad0f45d6d1033.mspx?mfr=true

How to use automatic TCP/IP addressing without a DHCP server
http://support.microsoft.com/kb/220874

=============================================================================================================
10.
Event Type: Error
Event Source: Application Popup
Event Category: None
Event ID: 877
Date: 1/5/2008
Time: 9:46:00 AM
User: N/A
Computer: SCOTT123
Description:
There was error [DATABASE OPEN FAILED] processing the driver database.

http://www.windowsbbs.com/showthread.php?t=36682
http://www.eventid.net/display.asp?eventid=877&eventno=1992&source=Application Popup&phase=1
============================================================================================================

11.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1002
Date: 12/27/2007
Time: 3:30:50 PM
User: N/A
Computer: SCOTT123
Description:
The IP address lease 64.195.65.187 for the Network Card with network address
0007E95E0E3F has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Your machine should get an Ip address in the range of 192.168.1.X not
64.195.X.X?.
Try to make sure the machine get an Auto IP address from the DHCP (which is
your router).

DHCP Event ID 1002: DHCP Received an Unknown Option 006 of Length 007
http://support.microsoft.com/kb/q181024/

===============================================================================================================

12.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 12/26/2007
Time: 11:40:14 AM
User: N/A
Computer: SCOTT123
Description:
The following boot-start or system-start driver(s) failed to load:
SYMTDI

DHCP Client Initializes Improperly and Causes an Invalid IP Address
http://support.microsoft.com/kb/812335

Good luck.
nass
 
I'm going bonkers.
Downloaded and installed ntbackup.exe. says "Please insure that
e:\backup.bkf is a valid path." and that you have sufficient access.
Background, Christmas I replaced a cd RW with a dvd RW. Don't believe i
told the system anything although I loaded the sony software. I have copied
files using the dvd rw.
I should backup c:\system voulme information to get the directory, right?

I went on and downloaded files you suggested, tryied to find out whad was
happening with the DVD RW and so on.

I ran the norton check and was told I had little protection. I have Norton
360 that was up to date and working a few days ago after much registery work
by norton since parts were turning off everytime I shut down the machine and
rebooted. Norton 360 shows now as green checks across the board.

I'm not sure what I'm working except possible virus stuff. I also have a
problem since I can not create a restore point as of Sat. I had been able to
create restore points but not use them. I had used the site to find out what
to do and gave up for a while and decided to work on the login problem that
started this.

Enough ranting. Sorry.

Got to where you wanted me to download files from bit devender. I can not
download any of the individual files although I can download v10 free,
whatever this is.
Should I download the v10?



--
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
I cleaned caches, internet files and cookies.
I dis-enabled Third Party Browser Estensions.
I dis-enabled all unverified add-ons. they then disappeared. I guess I'll
have a chance to add them as I browse in the future.
I downloaded and / or printed many articles and file programs to run.

I could not backup registery so I did not run any of what I downloaed.
I had replaced a CR RW at Christmas with a DVD RW and did not do anything to
XP. Should I have?
I could not back up to the DVD RW. mseage said "filename.bkp (whatever the
extension was) could not be used or I did not have rights.
Should I be able to backup to a DVD RW. If not, I'll install a hard drive I
had in another PC and reformat or erase it. Is there a simple way to clean
it?
I was trying to backup the c:\System directory (or something close to that
name) I this how to get the registery backuped?

ISymantec program said I had poor protection. I have Norton 360 and had
help about a week ago from Norton going through the Registery so I would not
loose some protection every time I rebooted. It has seemed to be working and
being kept up to date.

I could not download any of the individual bit defender anti virus files I
can download Free Edition v10, whatever this is. It will take a hour or so.
I can also "Try" movile Security V2. Should I try either or both of them?

I only managed to clean outlook and download many files and print many
procedures such as How to Manage Add-Ons. This is why I only downloaded and
did not run. I tried to post yesterday and apparently could not or did not.

I appreciate your help. Thanks!






--
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
I have tried to post about 4 times. This is simplified

1. Should I be able to backup to a DVD RW or should I install a Hard drive I
removed from an older unit to be used for the backup? There is room and I
have done this before and have cables if necessary.

2. Will C:\System contain the Registery?

3. At home or at work I can not download bit defender individual virus
files. Says the page can not be found. I can, but should I, download Free
edition v10.

I have downloaded many files and directions as nass suggested. I have
cleaned Outlook although I have not installed or run any of the files and do
not intend to untill I have the Registery backupped.
 
This is a posting test. I've tried about 5 times yesterday through today.
--
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
-- Test since I canp't seem to post a reply
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
I haven't been able to reply. This is a test.
--
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
This is a test
--
JSS


nass said:
:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft Office 10&phase=1

http://www.microsoft.com/communitie...&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windo...3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPOR...88256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service Control Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
 
Back
Top