Okay, John, see files below; I disabled those 2 services and ran it
again, and, as seems to happen every time, something comes up that I
never saw before. But the clock bit went away. Hibernation results...
still the same. See the Events Log. As for the failing to load, I'll
show you that one again. But now....
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 3/31/2010
Time: 1:26:17 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: COMPAQ-2006
Description:
Successful Logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Logon Type: 5
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name:
Logon GUID: {00000000-0000-0000-0000-000000000000}
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Type Date Time Source Category Event User Computer
Success Audit 3/31/2010 1:26:17 PM Security Privilege
Use 576 NETWORK SERVICE COMPAQ-2006
Success Audit 3/31/2010 1:26:17 PM Security Logon/Logoff
528 NETWORK SERVICE COMPAQ-2006
Success Audit 3/31/2010 12:09:37 PM Security Privilege
Use 576 NETWORK SERVICE COMPAQ-2006
Success Audit 3/31/2010 12:09:37 PM Security
Logon/Logoff 528 NETWORK SERVICE COMPAQ-2006
These Windows services are started:
Automatic Updates
COM+ Event System
Cryptographic Services
DCOM Server Process Launcher
DHCP Client
Distributed Link Tracking Client
DNS Client
Error Reporting Service
Event Log
Fast User Switching Compatibility
Help and Support
IPSEC Services
Network Connections
Network Location Awareness (NLA)
Plug and Play
Print Spooler
Protected Storage
Remote Access Connection Manager
Remote Procedure Call (RPC)
Secondary Logon
Security Accounts Manager
Server
Shell Hardware Detection
System Event Notification
Task Scheduler
TCP/IP NetBIOS Helper
Telephony
Terminal Services
Themes
WebClient
Windows Audio
Windows Firewall/Internet Connection Sharing (ICS)
Windows Management Instrumentation
Wireless Zero Configuration
Workstation
The command completed successfully.
Image Name PID Services
========================= ======
=============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 1200 N/A
csrss.exe 1280 N/A
winlogon.exe 1312 N/A
services.exe 1356 Eventlog, PlugPlay
lsass.exe 1368 PolicyAgent, ProtectedStorage, SamSs
svchost.exe 1528 DcomLaunch, TermService
svchost.exe 1628 RpcSs
svchost.exe 1784 AudioSrv, CryptSvc, Dhcp, ERSvc,
EventSystem,
FastUserSwitchingCompatibility,
helpsvc, lanmanserver, lanmanworkstation,
Netman, Nla, RasMan, Schedule, seclogon,
SENS, SharedAccess, ShellHWDetection,
TapiSrv, Themes, TrkWks, winmgmt,
wuauserv,
WZCSVC
svchost.exe 1928 Dnscache
svchost.exe 240 LmHosts
spoolsv.exe 552 Spooler
explorer.exe 772 N/A
svchost.exe 872 WebClient
mmc.exe 1452 N/A
EditPadLite.exe 172 N/A
cmd.exe 1672 N/A
ntvdm.exe 568 N/A
tasklist.exe 296 N/A
wmiprvse.exe 1572 N/A
I think that's the lot. Note that I started it at 12:09 and at 1:26 an
event interrupted the hibernation process.
I can show you the details of those two events, if you like.
I don't recall seeing events of that type before. Logon/logoff?
Not by me. Privilege use? Huh?