This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Search Engine Redirects

92 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tomk,

Here are the results from gmer:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-19 22:36:52
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xB03D08AC]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xB03D0812]

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xAD82B9AE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xAD82BA45]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xAD82B95C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xAD82B970]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xAD82BA59]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xAD82BA85]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xAD82BAF3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xAD82BADD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xAD82B9EE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xAD82BB1F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xAD82BA31]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xAD82B948]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xAD82B9C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xAD82BB5B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xAD82BAC7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xAD82BAB1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xAD82BA6F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xAD82BB47]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xAD82BB33]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xAD82B99A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xAD82B986]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xAD82BA9B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xAD82BB09]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xAD82BA04]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xAD82B9D8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.14 —-

.text ntoskrnl.exe!ZwYieldExecution 80515A6A 7 Bytes JMP AD82B9DC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80572BF4 5 Bytes JMP AD82BA35 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 80573037 7 Bytes JMP AD82BAB5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 8057791D 5 Bytes JMP AD82BA49 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80578A14 7 Bytes JMP AD82BB5F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 7 Bytes JMP AD82BAF7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8057C328 5 Bytes JMP AD82B9B2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8057CFC0 5 Bytes JMP AD82B98A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057DEF1 5 Bytes JMP AD82BA08 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057E369 7 Bytes JMP AD82B9F2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80581889 7 Bytes JMP AD82B9C6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 8058228C 7 Bytes JMP AD82BA9F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 80587693 7 Bytes JMP AD82BAE1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058B7CD 7 Bytes JMP AD82B974 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80591F8B 7 Bytes JMP AD82BA89 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 80593334 7 Bytes JMP AD82BA5D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B0470 5 Bytes JMP AD82B960 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 805E1939 5 Bytes JMP AD82B94C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 805E218F 5 Bytes JMP AD82BB23 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 80635947 5 Bytes JMP AD82B99E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 80654DB2 7 Bytes JMP AD82BB0D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 806556D8 7 Bytes JMP AD82BACB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 80655B56 7 Bytes JMP AD82BA73 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 80656049 5 Bytes JMP AD82BB37 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 806564B2 5 Bytes JMP AD82BB4B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0FE5
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0F68
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A005D
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F83
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0040
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0025
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0F21
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F32
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0EE1
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0EF2
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A009F
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0F9E
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0F43
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FB9
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0FCA
.text C:\WINDOWS\explorer.exe[156] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A007A
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00290FB9
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290062
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290014
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290FDE
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290047
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290FEF
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00290036
.text C:\WINDOWS\explorer.exe[156] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290025
.text C:\WINDOWS\explorer.exe[156] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C0000
.text C:\WINDOWS\explorer.exe[156] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0025
.text C:\WINDOWS\explorer.exe[156] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C0FE5
.text C:\WINDOWS\explorer.exe[156] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002C0036
.text C:\WINDOWS\explorer.exe[156] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\WINDOWS\explorer.exe[156] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\WINDOWS\explorer.exe[156] WS2_32.dll!socket 71AB4211 5 Bytes JMP 015C0FEF
.text C:\Program Files\Dell Wireless\PRISMCFG.exe[320] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Dell Wireless\PRISMCFG.exe[320] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[936] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[936] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FE5
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0007006B
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00070F76
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070F91
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0007004E
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0007002C
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F40
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00070F5B
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000700CF
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000700BE
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 000700E0
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0007003D
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00070FCA
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00070086
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00070011
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[1376] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 000700A3
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0006002C
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00060F8D
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00060011
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00060FDB
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00060F9E
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00060FB9
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 26, 88 ]
.text C:\WINDOWS\system32\services.exe[1376] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00060FCA
.text C:\WINDOWS\system32\services.exe[1376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0F83
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0F94
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0FA5
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0058
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD009F
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD0F57
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD00BA
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F21
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00CD00D5
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00CD0047
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00CD0011
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00CD0F72
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\system32\lsass.exe[1388] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00CD0F32
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00CC001B
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00CC0F80
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00CC000A
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00CC0FD4
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00CC0F91
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00CC0FEF
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00CC003D
.text C:\WINDOWS\system32\lsass.exe[1388] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00CC002C
.text C:\WINDOWS\system32\lsass.exe[1388] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CA0000
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CB0000
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CB0F9E
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CB0FAF
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CB0087
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CB0076
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CB0040
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CB00BA
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CB0F72
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CB00E6
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CB00D5
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00CB0F32
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00CB005B
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00CB0FE5
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00CB0F83
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00CB0FCA
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00CB0025
.text C:\WINDOWS\system32\svchost.exe[1572] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00CB0F57
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00CA0FE5
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00CA0FA8
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00CA0036
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00CA001B
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00CA0FB9
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00CA000A
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00CA0FCA
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes JMP 50C03388
.text C:\WINDOWS\system32\svchost.exe[1572] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00CA0051
.text C:\WINDOWS\system32\svchost.exe[1572] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C80000
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CB0FEF
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CB008C
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CB0F8D
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CB0F9E
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CB005B
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CB0FAF
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CB00C4
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CB0F7C
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CB00FA
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CB0F61
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00CB0115
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00CB0040
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00CB0FCA
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00CB009D
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00CB001B
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00CB000A
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00CB00D5
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00CA0FB9
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00CA0051
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00CA0FD4
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00CA0FE5
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00CA0036
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00CA0000
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00CA0025
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00CA0F9E
.text C:\WINDOWS\system32\svchost.exe[1620] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C80FE5
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02E40FE5
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02E40F6D
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02E40F88
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02E40062
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02E40047
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02E40FAF
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02E4009A
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02E40F52
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02E40F1C
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02E400B5
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 02E40F01
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 02E40036
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 02E40000
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 02E4007D
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 02E40011
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 02E40FC0
.text C:\WINDOWS\System32\svchost.exe[1660] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 02E40F37
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 02D00FE5
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 02D0007D
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 02D00036
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 02D0001B
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 02D00FC0
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 02D00000
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 02D00062
.text C:\WINDOWS\System32\svchost.exe[1660] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 02D00051
.text C:\WINDOWS\System32\svchost.exe[1660] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02CE0000
.text C:\WINDOWS\System32\svchost.exe[1660] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 02E30FEF
.text C:\WINDOWS\System32\svchost.exe[1660] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 02E30000
.text C:\WINDOWS\System32\svchost.exe[1660] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02E30011
.text C:\WINDOWS\System32\svchost.exe[1660] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 02E30FC0
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00800FE5
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0080008E
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00800073
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00800062
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00800FA5
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00800036
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 008000BA
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00800F7E
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008000F0
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008000CB
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00800101
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00800047
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00800FD4
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 008000A9
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0080001B
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\svchost.exe[1816] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00800F57
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 007F0040
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 007F0FA5
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 007F0FEF
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 007F001B
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 007F006C
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 007F000A
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 007F0FCA
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 9F, 88 ]
.text C:\WINDOWS\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 007F0051
.text C:\WINDOWS\system32\svchost.exe[1816] WS2_32.dll!socket 71AB4211 5 Bytes JMP 007D0FEF
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C60000
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C60F4D
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C60F5E
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C60036
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C60F79
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C60FB9
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C60F2B
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C60067
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C60F06
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C6009F
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C600B0
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C60F94
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C60FE5
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C60F3C
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C60025
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C60FCA
.text C:\WINDOWS\system32\svchost.exe[1844] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C6008E
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 009F002C
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 009F0F9E
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 009F0FE5
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 009F0011
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 009F0FAF
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 009F0000
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 009F005B
.text C:\WINDOWS\system32\svchost.exe[1844] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 009F0FCA
.text C:\WINDOWS\system32\svchost.exe[1844] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\system32\svchost.exe[1844] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00A00000
.text C:\WINDOWS\system32\svchost.exe[1844] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00A0001B
.text C:\WINDOWS\system32\svchost.exe[1844] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00A00FE5
.text C:\WINDOWS\system32\svchost.exe[1844] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00A00FD4
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B80F8D
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B80F9E
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B8006C
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B80FAF
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B80040
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B800BD
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B80F6B
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B80104
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B800E9
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00B80F50
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00B80051
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00B80FE5
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00B80F7C
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00B80FD4
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00B80025
.text C:\WINDOWS\system32\svchost.exe[2208] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00B800D8
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00B70040
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00B7005B
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00B70FE5
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00B7001B
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00B70FA8
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00B70000
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00B70FB9
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ D7, 88 ]
.text C:\WINDOWS\system32\svchost.exe[2208] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00B70FD4
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2392] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[2392] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe[2680] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe[2680] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2924] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[2924] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[3336] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[3336] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\LogMeIn\x86\LogMeInSystray.exe[3916] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\LogMeIn\x86\LogMeInSystray.exe[3916] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3980] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[3980] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\WinZip\WZQKPICK.EXE[4056] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\WinZip\WZQKPICK.EXE[4056] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[4064] shell32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[4064] shell32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Iomega\DriveIcons\ImgIcon.exe[4076] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Iomega\DriveIcons\ImgIcon.exe[4076] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Documents and Settings\Mark\Desktop\gmer.exe[5492] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Documents and Settings\Mark\Desktop\gmer.exe[5492] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.14 —-


-mm
mountainman,

More hoops for you to jump through.

I need you to find this folder ==>C:\Windows\ERDNT\hiv-backups
There are several files in here and I need you to make me two .zip files.

First: Software
Right click on this file and and select Send to and then Compressed (zipped) folder

Next:
* SAM
* SECURITY
* system
* Users (this is a folder)

These can all be zipped into a second file. You can do this be holding the CTRL button and click on each of the files. This will highlight each of them at the same time. Then right click on any of the highlighted files and send to a compressed folder.

Now that you have the two .zip folders, I need you to name the first one Tomk1 and the second one Tomk2. Then I need you to password protect the information in them because there will be personal information in there that you don't want "out-there".

Do this by double clicking on the zipped file. (You won't be extracting them) Then click on File at the top of the window and select Add a password…. Now you are obviously going to add a password. Do not even hint at that password on this thread. I need you to PM it to me. The information will be reviewed and then destroyed.

Then I need you to upload that information as follows:

Please visit this site and follow the instructions for uploading the Tomk1 file.

Do the same with Tomk2

Now while this information is reviewed, I need you to do the following:

Let's have a look at Windows Event Viewer. It might give us a clue as to what is causing these issues

Go to Start > Run - type in eventvwr


[external image: Posted Image]

This is a picture of what the event viewer looks like.
You will see Application, Security & System listed in the left pane.
  • In the left pane click on Application.
  • Click the gray title “Type” at the top of the source name column in the right pane to sort by type name
    Look for “Error” & double-click on the most recent 10, and evaluate the event description for any indication of the cause of the problem.
  • Make note of the Description, EventID and Source of these Event Properties.
  • From the right pane, doubleclick on the line where it says error & you should get a window like the example below


    [external image: Posted Image]


  • In the upper right corner of this picture, you should see 2 arrows. One is pointing up & the other, pointing down.
    There is another button below the 2 arrows. Click once on it. (this will copy some information to clipboard)
  • Open notepad & paste the info in there. This will copy the event information to the clipboard. Paste the information for each event here

Repeat steps 1-6 for System

Keep your chin up. I've got a whole team of really smart people working on your problem with me. :yeah:
Tomk, I've got the zip files ready. There wasn't an explicit option to add a password, so I used encryption (thinking that this was the same). Also, you've lost me with the instructions for uploading the files. Am I simply supposed to supply a link to this forum topic, add the files and a comment, and hit the send button? How does it make it to you from that site? And what does "…PM it to me." mean? -mm :unsure:
Tomk,

Here are the application errors from the event viewer:

Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/14/2008
Time: 8:31:47 PM
User: N/A
Computer: OFFICE
Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 12/9/2008
Time: 11:21:47 PM
User: N/A
Computer: OFFICE
Description:
Hanging application iexplore.exe, version 7.0.6000.16735, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 69 65 78 70 6c 6f iexplo
0018: 72 65 2e 65 78 65 20 37 re.exe 7
0020: 2e 30 2e 36 30 30 30 2e .0.6000.
0028: 31 36 37 33 35 20 69 6e 16735 in
0030: 20 68 75 6e 67 61 70 70 hungapp
0038: 20 30 2e 30 2e 30 2e 30 0.0.0.0
0040: 20 61 74 20 6f 66 66 73 at offs
0048: 65 74 20 30 30 30 30 30 et 00000
0050: 30 30 30 000


Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 12/9/2008
Time: 11:19:16 PM
User: N/A
Computer: OFFICE
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module flash9e.ocx, version 9.0.115.0, fault address 0x00087b08.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 37 33 35 00.16735
0030: 20 69 6e 20 66 6c 61 73 in flas
0038: 68 39 65 2e 6f 63 78 20 h9e.ocx
0040: 39 2e 30 2e 31 31 35 2e 9.0.115.
0048: 30 20 61 74 20 6f 66 66 0 at off
0050: 73 65 74 20 30 30 30 38 set 0008
0058: 37 62 30 38 0d 0a 7b08..


Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 11/10/2008
Time: 9:18:21 PM
User: N/A
Computer: OFFICE
Description:
Hanging application iexplore.exe, version 7.0.6000.16735, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 69 65 78 70 6c 6f iexplo
0018: 72 65 2e 65 78 65 20 37 re.exe 7
0020: 2e 30 2e 36 30 30 30 2e .0.6000.
0028: 31 36 37 33 35 20 69 6e 16735 in
0030: 20 68 75 6e 67 61 70 70 hungapp
0038: 20 30 2e 30 2e 30 2e 30 0.0.0.0
0040: 20 61 74 20 6f 66 66 73 at offs
0048: 65 74 20 30 30 30 30 30 et 00000
0050: 30 30 30 000


Event Type: Error
Event Source: ESENT
Event Category: General
Event ID: 490
Date: 11/10/2008
Time: 8:28:12 PM
User: N/A
Computer: OFFICE
Description:
svchost (1660) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\edb.log" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 11/7/2008
Time: 1:17:49 AM
User: N/A
Computer: OFFICE
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000106f7.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 37 33 35 00.16735
0030: 20 69 6e 20 6e 74 64 6c in ntdl
0038: 6c 2e 64 6c 6c 20 35 2e l.dll 5.
0040: 31 2e 32 36 30 30 2e 35 1.2600.5
0048: 35 31 32 20 61 74 20 6f 512 at o
0050: 66 66 73 65 74 20 30 30 ffset 00
0058: 30 31 30 36 66 37 0d 0a 0106f7..


Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 11/7/2008
Time: 1:17:45 AM
User: N/A
Computer: OFFICE
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000106f7.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 37 33 35 00.16735
0030: 20 69 6e 20 6e 74 64 6c in ntdl
0038: 6c 2e 64 6c 6c 20 35 2e l.dll 5.
0040: 31 2e 32 36 30 30 2e 35 1.2600.5
0048: 35 31 32 20 61 74 20 6f 512 at o
0050: 66 66 73 65 74 20 30 30 ffset 00
0058: 30 31 30 36 66 37 0d 0a 0106f7..


Here are the system errors from the event viewer:

Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10001
Date: 12/15/2008
Time: 9:24:02 PM
User: NT AUTHORITY\SYSTEM
Computer: OFFICE
Description:
Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} as /. The error:
"No process is on the other end of the pipe. "
Happened while starting this command:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe -Embedding

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/14/2008
Time: 9:15:06 PM
User: NT AUTHORITY\SYSTEM
Computer: OFFICE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to start the service McNASvc with arguments "" in order to run the server:
{24F616A1-B755-4053-8018-C3425DC8B68A}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/14/2008
Time: 9:15:05 PM
User: NT AUTHORITY\SYSTEM
Computer: OFFICE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to start the service McNASvc with arguments "" in order to run the server:
{24F616A1-B755-4053-8018-C3425DC8B68A}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 12/14/2008
Time: 9:14:41 PM
User: N/A
Computer: OFFICE
Description:
The following boot-start or system-start driver(s) failed to load:
AFD
AVG Anti-Spyware Driver
Fips
intelppm
IPSec
mfehidk
MPFP
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 12/14/2008
Time: 9:14:41 PM
User: N/A
Computer: OFFICE
Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
A device attached to the system is not functioning.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 12/14/2008
Time: 9:14:41 PM
User: N/A
Computer: OFFICE
Description:
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
A device attached to the system is not functioning.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 12/14/2008
Time: 9:14:41 PM
User: N/A
Computer: OFFICE
Description:
The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
A device attached to the system is not functioning.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7001
Date: 12/14/2008
Time: 9:14:41 PM
User: N/A
Computer: OFFICE
Description:
The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
A device attached to the system is not functioning.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/14/2008
Time: 9:13:49 PM
User: OFFICE\Mark
Computer: OFFICE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to start the service StiSvc with arguments "" in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 12/14/2008
Time: 9:13:37 PM
User: OFFICE\Mark
Computer: OFFICE
Description:
DCOM got error "This service cannot be started in Safe Mode " attempting to start the service netman with arguments "" in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


-mm
mountainman,

I need you to upload another file:

Please visit this site and follow the instructions for uploading the C:\WINDOWS\system32\ntdll.dll file.

This doesn't need to be zipped or protected. :)
mountainman,

Backup Your Registry with ERUNT
  • Download ERUNT from here and save it to your desktop.
  • Right-click erunt.zip, choose Extract All… and follow the prompts to unzip the program
  • Open the erunt folder on your Desktop and double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note:
The backups can be restored from here:
C:\windows\ERDNT\\ERDNT.exe

Please open Notepad

  • Click Start , then Run
  • Type notepad.exe in the Run Box.
    Copy and Paste everything from the Quote box into Notepad:

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "UserEnvDebugLevel"=dword:00030002


    Make sure there are NO blank lines before REGEDIT4
    Make sure there IS one blank line at the end of the file.

    Go to File > Save As
    Save File name as Fix.reg
    Change Save as Type to All Files and save the file to your desktop.

    Close Notepad, and double-click Fix.reg on your Desktop. When it asks if you want to merge the info to the registry, hit YES/OK. Reboot the computer.

Using Windows Explorer (Windows Key + E), locate the following file:
C:\WINDOWS\Debug\UserMode\userenv.log <–This file

Open it with Notepad and Copy/Paste the information here:
Tomk, Here's userenv.log: USERENV(538.894) 19:11:29:078 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.1a0) 19:58:12:406 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.894) 20:59:29:125 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.1a0) 21:39:12:484 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.894) 22:47:29:140 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(4c8.500) 22:50:50:750 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(954.ab0) 22:50:50:906 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(538.53c) 08:38:06:593 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(538.53c) 08:38:06:609 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(538.53c) 08:38:06:609 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(538.790) 08:38:09:921 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.990) 08:38:28:781 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 10:08:28:937 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.18c) 10:28:09:937 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 11:54:28:953 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.18c) 12:24:10:109 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 13:25:28:968 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.1370) 14:08:59:218 MyRegUnLoadKey: Failed to unmount hive 00000005 USERENV(538.1370) 14:08:59:218 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4124423304-592752288-1644981653-1008 USERENV(538.1370) 14:08:59:218 UnloadUserProfileP: Didn't unload user profile USERENV(538.1370) 14:08:59:328 UnloadUserProfileI: UnloadUserProfileP failed with 0 USERENV(538.18c) 14:23:10:171 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 15:12:28:984 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.18c) 16:10:10:250 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 16:59:29:000 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.18c) 18:00:10:312 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 18:32:29:015 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.560) 18:44:44:359 MyRegUnLoadKey: Failed to unmount hive 00000005 USERENV(538.560) 18:44:44:359 DumpOpenRegistryHandle: 2 user registry Handles leaked from \Registry\User\S-1-5-21-4124423304-592752288-1644981653-1008 USERENV(538.560) 18:44:44:359 UnloadUserProfileP: Didn't unload user profile USERENV(538.560) 18:44:44:421 UnloadUserProfileI: UnloadUserProfileP failed with 0 USERENV(538.18c) 19:38:10:375 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 20:20:29:031 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.18c) 21:34:10:453 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(538.9b8) 21:54:29:046 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(500.5a0) 22:34:18:953 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(a0c.5b0) 22:34:19:031 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(388.110c) 22:34:19:031 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(370.3d8) 22:34:19:406 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(534.538) 13:43:41:765 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 13:43:41:781 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 13:43:41:781 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.754) 13:43:45:390 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(534.828) 13:44:02:265 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(898.c60) 14:01:29:921 LibMain: Process Name: C:\WINDOWS\system32\logonui.exe USERENV(9bc.bc8) 14:01:43:375 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(4a8.5a4) 14:01:43:531 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(17c.3e8) 14:01:43:640 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(1780.df0) 14:01:43:765 LibMain: Process Name: C:\WINDOWS\system32\wuauclt.exe USERENV(38c.40c) 14:01:43:906 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(38c.3d0) 14:01:43:921 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(534.538) 14:02:20:640 InitializePolicyProcessing: Initialised Machine Mutex/Events USERENV(534.538) 14:02:20:640 InitializePolicyProcessing: Initialised User Mutex/Events USERENV(534.538) 14:02:20:640 LibMain: Process Name: \??\C:\WINDOWS\system32\winlogon.exe USERENV(534.538) 14:02:21:250 Entering CUserProfile::Initialize … USERENV(534.538) 14:02:21:265 CUserProfile::Initialize called by winlogon USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: critical section initialized USERENV(534.538) 14:02:21:265 CSyncManager::Initialize: critical section initialized USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: registry key Software\Microsoft\Windows NT\CurrentVersion\ProfileList opened USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-500 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-500 added in bucket 8 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-500 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1008 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1008 added in bucket 14 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1008 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1007 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1007 added in bucket 13 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1007 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-20 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 2, state is 00000000 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-19 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 2, state is 00000000 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: Proccessing S-1-5-18 USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:21:265 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:21:265 CHashTable::HashAdd: S-1-5-18 added in bucket 11 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 14:02:21:265 CUserProfile::GetRefCountAndFlags: Ref count is 1, state is 00000000 USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:21:265 CHashTable::HashDelete: S-1-5-18 deleted USERENV(534.538) 14:02:21:265 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:21:265 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 14:02:21:265 CUserProfile::Initialize: RpcServerRegisterIfEx successful USERENV(534.538) 14:02:21:265 Exiting CUserProfile::Initialize, successful USERENV(560.564) 14:02:21:296 LibMain: Process Name: C:\WINDOWS\system32\services.exe USERENV(56c.570) 14:02:21:328 LibMain: Process Name: C:\WINDOWS\system32\lsass.exe USERENV(534.538) 14:02:21:375 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(620.624) 14:02:21:875 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(560.564) 14:02:22:000 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 14:02:22:000 ========================================================= USERENV(560.564) 14:02:22:000 LoadUserProfile: Entering, hToken = <0x2a0>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 14:02:22:000 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 14:02:22:000 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 14:02:22:000 LoadUserProfile: NULL central profile path USERENV(560.564) 14:02:22:000 LoadUserProfile: NULL default profile path USERENV(560.564) 14:02:22:000 LoadUserProfile: NULL server name USERENV(560.564) 14:02:22:000 GetInterface: Returning rpc binding handle USERENV(534.54c) 14:02:22:000 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:22:000 DropClientContext: Got client token 00000600, sid = S-1-5-18 USERENV(534.54c) 14:02:22:000 MIDL_user_allocate enter USERENV(534.54c) 14:02:22:000 DropClientContext: load profile object successfully made USERENV(534.54c) 14:02:22:000 DropClientContext: Returning 0 USERENV(560.564) 14:02:22:000 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.648) 14:02:22:000 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:22:000 In LoadUserProfileP USERENV(534.648) 14:02:22:000 LoadUserProfile: Running as client USERENV(534.648) 14:02:22:000 ========================================================= USERENV(534.648) 14:02:22:000 LoadUserProfile: Entering, hToken = <0x608>, lpProfileInfo = 0xe9cfc0 USERENV(534.648) 14:02:22:000 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.648) 14:02:22:000 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.648) 14:02:22:000 LoadUserProfile: NULL central profile path USERENV(534.648) 14:02:22:000 LoadUserProfile: NULL default profile path USERENV(534.648) 14:02:22:000 LoadUserProfile: NULL server name USERENV(534.648) 14:02:22:000 LoadUserProfile: User sid: S-1-5-20 USERENV(534.648) 14:02:22:000 CSyncManager::EnterLock USERENV(534.648) 14:02:22:000 CSyncManager::EnterLock: No existing entry found USERENV(534.648) 14:02:22:000 CSyncManager::EnterLock: New entry created USERENV(534.648) 14:02:22:000 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.648) 14:02:22:000 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.648) 14:02:22:000 RestoreUserProfile: Entering USERENV(534.648) 14:02:22:000 IsCentralProfileReachable: Entering USERENV(534.648) 14:02:22:000 IsCentralProfileReachable: Null path. Leaving USERENV(534.648) 14:02:22:000 RestoreUserProfile: Profile path = <> USERENV(534.648) 14:02:22:000 ExtractProfileFromBackup: A profile already exists USERENV(534.648) 14:02:22:000 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.648) 14:02:22:000 CreateLocalProfileKey: Not setting additional Security USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\NetworkService> USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.648) 14:02:22:015 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.648) 14:02:22:015 Local Existing Profile Image is reachable USERENV(534.648) 14:02:22:015 Local profile name is USERENV(534.648) 14:02:22:015 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.648) 14:02:22:015 MyRegLoadKey: Returning 00000000 USERENV(534.648) 14:02:22:015 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.648) 14:02:22:031 MyRegLoadKey: Returning 00000000 USERENV(534.648) 14:02:22:031 CreateClassHive: existing user classes hive found USERENV(534.648) 14:02:22:031 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.648) 14:02:22:031 Profile was successfully loaded. USERENV(534.648) 14:02:22:031 lpProfile->lpRoamingProfile = <> USERENV(534.648) 14:02:22:031 lpProfile->lpLocalProfile = USERENV(534.648) 14:02:22:031 lpProfile->dwInternalFlags = 0x0 USERENV(534.648) 14:02:22:031 RestoreUserProfile: Leaving. USERENV(534.648) 14:02:22:046 UpgradeProfile: Entering USERENV(534.648) 14:02:22:046 UpgradeProfile: Build numbers match USERENV(534.648) 14:02:22:046 UpgradeProfile: Leaving Successfully USERENV(534.648) 14:02:22:046 GetProfileType: Profile already loaded. USERENV(534.648) 14:02:22:046 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.648) 14:02:22:046 GetProfileType: ProfileFlags is 0 USERENV(534.648) 14:02:22:062 Profile Ref Count is 1 USERENV(534.648) 14:02:22:062 LoadUserProfile: Leaving critical Section. USERENV(534.648) 14:02:22:062 CSyncManager::LeaveLock USERENV(534.648) 14:02:22:062 CSyncManager::LeaveLock: Lock released USERENV(534.648) 14:02:22:062 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.648) 14:02:22:062 CSyncManager::LeaveLock: Lock deleted USERENV(534.648) 14:02:22:062 LoadUserProfile: Impersonated user: 00000608, 00000614 USERENV(56c.5b0) 14:02:22:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5b0) 14:02:22:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.648) 14:02:22:062 LoadUserProfile: Reverted to user: 00000000 USERENV(534.648) 14:02:22:062 LoadUserProfile: Reverted back to user <00000000> USERENV(534.648) 14:02:22:062 LoadUserProfile: Leaving with a value of 1. USERENV(534.648) 14:02:22:062 ========================================================= USERENV(534.648) 14:02:22:062 LoadUserProfileI: returning 0 USERENV(560.564) 14:02:22:062 LoadUserProfile: Running as self USERENV(560.564) 14:02:22:062 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 14:02:22:062 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 14:02:22:062 lpProfileInfo->UserName = USERENV(560.564) 14:02:22:062 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 14:02:22:062 lpProfileInfo->dwFlags = 0x9 USERENV(534.54c) 14:02:22:062 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:22:062 ReleaseClientContext: Releasing context USERENV(534.54c) 14:02:22:062 ReleaseClientContext_s: Releasing context USERENV(534.54c) 14:02:22:062 MIDL_user_free enter USERENV(560.564) 14:02:22:062 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 14:02:22:062 LoadUserProfile: Returning TRUE. hProfile = <0x314> USERENV(560.564) 14:02:22:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(650.654) 14:02:22:093 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(678.67c) 14:02:22:187 LibMain: Process Name: C:\WINDOWS\System32\svchost.exe USERENV(560.564) 14:02:22:203 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 14:02:22:203 ========================================================= USERENV(560.564) 14:02:22:203 LoadUserProfile: Entering, hToken = <0x35c>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 14:02:22:203 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 14:02:22:203 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 14:02:22:203 LoadUserProfile: NULL central profile path USERENV(560.564) 14:02:22:203 LoadUserProfile: NULL default profile path USERENV(560.564) 14:02:22:203 LoadUserProfile: NULL server name USERENV(560.564) 14:02:22:203 GetInterface: Returning rpc binding handle USERENV(534.648) 14:02:22:203 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:22:218 DropClientContext: Got client token 00000600, sid = S-1-5-18 USERENV(534.648) 14:02:22:218 MIDL_user_allocate enter USERENV(534.648) 14:02:22:218 DropClientContext: load profile object successfully made USERENV(534.648) 14:02:22:218 DropClientContext: Returning 0 USERENV(560.564) 14:02:22:218 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 14:02:22:218 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:22:218 In LoadUserProfileP USERENV(534.54c) 14:02:22:218 LoadUserProfile: Running as client USERENV(534.54c) 14:02:22:218 ========================================================= USERENV(534.54c) 14:02:22:218 LoadUserProfile: Entering, hToken = <0x614>, lpProfileInfo = 0xe05b90 USERENV(534.54c) 14:02:22:218 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.54c) 14:02:22:218 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.54c) 14:02:22:218 LoadUserProfile: NULL central profile path USERENV(534.54c) 14:02:22:218 LoadUserProfile: NULL default profile path USERENV(534.54c) 14:02:22:218 LoadUserProfile: NULL server name USERENV(534.54c) 14:02:22:218 LoadUserProfile: User sid: S-1-5-20 USERENV(534.54c) 14:02:22:218 CSyncManager::EnterLock USERENV(534.54c) 14:02:22:218 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 14:02:22:218 CSyncManager::EnterLock: New entry created USERENV(534.54c) 14:02:22:218 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.54c) 14:02:22:218 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.54c) 14:02:22:218 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.54c) 14:02:22:218 Profile Ref Count is 2 USERENV(534.54c) 14:02:22:218 LoadUserProfile: Leaving critical Section. USERENV(534.54c) 14:02:22:218 CSyncManager::LeaveLock USERENV(534.54c) 14:02:22:218 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 14:02:22:218 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.54c) 14:02:22:218 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 14:02:22:218 LoadUserProfile: Impersonated user: 00000614, 00000638 USERENV(534.54c) 14:02:22:218 LoadUserProfile: Reverted to user: 00000000 USERENV(534.54c) 14:02:22:218 LoadUserProfile: Reverted back to user <00000000> USERENV(534.54c) 14:02:22:218 LoadUserProfile: Leaving with a value of 1. USERENV(534.54c) 14:02:22:218 ========================================================= USERENV(534.54c) 14:02:22:218 LoadUserProfileI: returning 0 USERENV(560.564) 14:02:22:218 LoadUserProfile: Running as self USERENV(560.564) 14:02:22:218 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 14:02:22:218 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 14:02:22:218 lpProfileInfo->UserName = USERENV(560.564) 14:02:22:218 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 14:02:22:218 lpProfileInfo->dwFlags = 0x9 USERENV(534.648) 14:02:22:218 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:22:218 ReleaseClientContext: Releasing context USERENV(534.648) 14:02:22:218 ReleaseClientContext_s: Releasing context USERENV(534.648) 14:02:22:218 MIDL_user_free enter USERENV(560.564) 14:02:22:218 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 14:02:22:218 LoadUserProfile: Returning TRUE. hProfile = <0x33c> USERENV(560.564) 14:02:22:218 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(6cc.6d0) 14:02:22:265 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(560.564) 14:02:22:265 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 14:02:22:265 ========================================================= USERENV(560.564) 14:02:22:265 LoadUserProfile: Entering, hToken = <0x36c>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 14:02:22:265 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 14:02:22:265 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 14:02:22:265 LoadUserProfile: NULL central profile path USERENV(560.564) 14:02:22:265 LoadUserProfile: NULL default profile path USERENV(560.564) 14:02:22:265 LoadUserProfile: NULL server name USERENV(560.564) 14:02:22:265 GetInterface: Returning rpc binding handle USERENV(534.54c) 14:02:22:265 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:22:265 DropClientContext: Got client token 00000600, sid = S-1-5-18 USERENV(534.54c) 14:02:22:265 MIDL_user_allocate enter USERENV(534.54c) 14:02:22:265 DropClientContext: load profile object successfully made USERENV(534.54c) 14:02:22:265 DropClientContext: Returning 0 USERENV(560.564) 14:02:22:265 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.648) 14:02:22:265 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:22:265 In LoadUserProfileP USERENV(534.648) 14:02:22:265 LoadUserProfile: Running as client USERENV(534.648) 14:02:22:265 ========================================================= USERENV(534.648) 14:02:22:265 LoadUserProfile: Entering, hToken = <0x614>, lpProfileInfo = 0xe05c90 USERENV(534.648) 14:02:22:265 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.648) 14:02:22:265 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.648) 14:02:22:265 LoadUserProfile: NULL central profile path USERENV(534.648) 14:02:22:265 LoadUserProfile: NULL default profile path USERENV(534.648) 14:02:22:265 LoadUserProfile: NULL server name USERENV(534.648) 14:02:22:265 LoadUserProfile: User sid: S-1-5-19 USERENV(534.648) 14:02:22:265 CSyncManager::EnterLock USERENV(534.648) 14:02:22:265 CSyncManager::EnterLock: No existing entry found USERENV(534.648) 14:02:22:265 CSyncManager::EnterLock: New entry created USERENV(534.648) 14:02:22:265 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.648) 14:02:22:265 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.648) 14:02:22:281 RestoreUserProfile: Entering USERENV(534.648) 14:02:22:281 IsCentralProfileReachable: Entering USERENV(534.648) 14:02:22:281 IsCentralProfileReachable: Null path. Leaving USERENV(534.648) 14:02:22:281 RestoreUserProfile: Profile path = <> USERENV(534.648) 14:02:22:281 ExtractProfileFromBackup: A profile already exists USERENV(534.648) 14:02:22:281 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.648) 14:02:22:281 CreateLocalProfileKey: Not setting additional Security USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\LocalService> USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.648) 14:02:22:281 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.648) 14:02:22:281 Local Existing Profile Image is reachable USERENV(534.648) 14:02:22:281 Local profile name is USERENV(534.648) 14:02:22:281 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.648) 14:02:22:281 MyRegLoadKey: Returning 00000000 USERENV(534.648) 14:02:22:296 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.648) 14:02:22:296 MyRegLoadKey: Returning 00000000 USERENV(534.648) 14:02:22:296 CreateClassHive: existing user classes hive found USERENV(534.648) 14:02:22:296 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.648) 14:02:22:296 Profile was successfully loaded. USERENV(534.648) 14:02:22:296 lpProfile->lpRoamingProfile = <> USERENV(534.648) 14:02:22:296 lpProfile->lpLocalProfile = USERENV(534.648) 14:02:22:296 lpProfile->dwInternalFlags = 0x0 USERENV(534.648) 14:02:22:296 RestoreUserProfile: Leaving. USERENV(534.648) 14:02:22:296 UpgradeProfile: Entering USERENV(534.648) 14:02:22:296 UpgradeProfile: Build numbers match USERENV(534.648) 14:02:22:296 UpgradeProfile: Leaving Successfully USERENV(534.648) 14:02:22:296 GetProfileType: Profile already loaded. USERENV(534.648) 14:02:22:296 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.648) 14:02:22:296 GetProfileType: ProfileFlags is 0 USERENV(534.648) 14:02:22:312 Profile Ref Count is 1 USERENV(534.648) 14:02:22:312 LoadUserProfile: Leaving critical Section. USERENV(534.648) 14:02:22:312 CSyncManager::LeaveLock USERENV(534.648) 14:02:22:312 CSyncManager::LeaveLock: Lock released USERENV(534.648) 14:02:22:312 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.648) 14:02:22:312 CSyncManager::LeaveLock: Lock deleted USERENV(534.648) 14:02:22:312 LoadUserProfile: Impersonated user: 00000614, 00000640 USERENV(56c.5d0) 14:02:22:312 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d0) 14:02:22:312 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.648) 14:02:22:343 LoadUserProfile: Reverted to user: 00000000 USERENV(534.648) 14:02:22:343 LoadUserProfile: Reverted back to user <00000000> USERENV(534.648) 14:02:22:343 LoadUserProfile: Leaving with a value of 1. USERENV(534.648) 14:02:22:343 ========================================================= USERENV(534.648) 14:02:22:343 LoadUserProfileI: returning 0 USERENV(560.564) 14:02:22:343 LoadUserProfile: Running as self USERENV(560.564) 14:02:22:343 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 14:02:22:343 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 14:02:22:343 lpProfileInfo->UserName = USERENV(560.564) 14:02:22:343 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 14:02:22:343 lpProfileInfo->dwFlags = 0x9 USERENV(534.54c) 14:02:22:343 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:22:343 ReleaseClientContext: Releasing context USERENV(534.54c) 14:02:22:343 ReleaseClientContext_s: Releasing context USERENV(534.54c) 14:02:22:343 MIDL_user_free enter USERENV(560.564) 14:02:22:343 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 14:02:22:343 LoadUserProfile: Returning TRUE. hProfile = <0x358> USERENV(560.564) 14:02:22:343 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(730.734) 14:02:22:375 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(7ac.7b0) 14:02:22:875 LibMain: Process Name: C:\WINDOWS\system32\logonui.exe USERENV(534.7f4) 14:02:22:937 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(fc.104) 14:02:23:015 LibMain: Process Name: C:\WINDOWS\system32\spoolsv.exe USERENV(164.180) 14:02:23:453 LibMain: Process Name: C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe USERENV(534.7f4) 14:02:23:484 ApplyGroupPolicy: Entering. Flags = b USERENV(534.7f4) 14:02:23:484 ProcessGPOs: USERENV(534.7f4) 14:02:23:484 ProcessGPOs: USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Starting computer Group Policy (Async forground) processing… USERENV(534.7f4) 14:02:23:484 ProcessGPOs: USERENV(534.7f4) 14:02:23:484 ProcessGPOs: USERENV(534.7f4) 14:02:23:484 EnterCriticalPolicySectionEx: Entering with timeout 600000 and flags 0x0 USERENV(534.7f4) 14:02:23:484 EnterCriticalPolicySectionEx: Machine critical section has been claimed. Handle = 0x78c USERENV(534.7f4) 14:02:23:484 EnterCriticalPolicySectionEx: Leaving successfully. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Machine role is 0. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for dskquota.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for iedkcs32.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for scecli.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for C:\WINDOWS\System32\cscui.dll. USERENV(534.7f4) 14:02:23:484 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {35378EAC-683F-11D2-A89A-00C04FBBCFA2} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {25537BA6-77A8-11D2-9B6C-0000F8080861} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {3610eda5-77ef-11d2-8dc5-00c04fa31a66} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {426031c0-0b47-4852-b0ca-ac3d37bfcb39} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {42B5FAAE-6536-11d2-AE5A-0000F87571E3} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {827D319E-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {B587E2B1-4D59-4e7e-AED9-22B9DF11D053} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {C631DF4C-088F-4156-B058-4375F0853CD8} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {c6dc5466-785a-11d2-84d0-00c04fb169f7} USERENV(534.7f4) 14:02:23:484 ReadExtStatus: Reading Previous Status for extension {e437bc1c-aa7d-11d2-a382-00c04f991e27} USERENV(534.7f4) 14:02:23:484 ProcessGPOs: No site name defined. Skipping site policy. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Calling GetGPOInfo for normal policy mode USERENV(534.7f4) 14:02:23:484 GetGPOInfo: ******************************** USERENV(534.7f4) 14:02:23:484 GetGPOInfo: Entering… USERENV(534.7f4) 14:02:23:484 GetGPOInfo: lpHostName or lpDNName is NULL. Skipping DS stuff. USERENV(534.7f4) 14:02:23:484 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(534.7f4) 14:02:23:484 GetGPOInfo: Leaving with 1 USERENV(534.7f4) 14:02:23:484 GetGPOInfo: ******************************** USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Logging Data for Target . USERENV(534.7f4) 14:02:23:484 ProcessGPOs: OpenThreadToken failed with error 1008, assuming thread is not impersonating USERENV(534.7f4) 14:02:23:484 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Processing extension Registry USERENV(534.7f4) 14:02:23:484 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:484 CheckGPOs: No GPO changes but couldn't read extension Registry's status or policy time. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Extension Registry skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Processing extension Wireless USERENV(534.7f4) 14:02:23:484 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:484 CheckGPOs: No GPO changes but couldn't read extension Wireless's status or policy time. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Extension Wireless skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:484 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:484 ProcessGPOs: Processing extension Folder Redirection USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Folder Redirection skipped with flags 0x1000b. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Microsoft Disk Quota USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Microsoft Disk Quota skipped with flags 0x1000b. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension QoS Packet Scheduler USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension QoS Packet Scheduler's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension QoS Packet Scheduler skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Scripts USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Scripts's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Scripts skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Internet Explorer Zonemapping USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Internet Explorer Zonemapping skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Security USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Security's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Security skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Internet Explorer Branding USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Internet Explorer Branding skipped with flags 0x1000b. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension EFS recovery USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension EFS recovery's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension EFS recovery skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension 802.3 Group Policy USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension 802.3 Group Policy skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Microsoft Offline Files USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Microsoft Offline Files's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Microsoft Offline Files skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension Software Installation USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension Software Installation's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension Software Installation skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: ———————– USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Processing extension IP Security USERENV(534.7f4) 14:02:23:500 CompareGPOLists: The lists are the same. USERENV(534.7f4) 14:02:23:500 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Extension IP Security skipped because both deleted and changed GPO lists are empty. USERENV(534.7f4) 14:02:23:500 SetFgRefreshInfo: Previous Machine Fg policy Asynchronous, Reason: NoNeedForSync. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: No WMI logging done in this policy cycle. USERENV(534.7f4) 14:02:23:500 LeaveCriticalPolicySection: Critical section 0x78c has been released. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Computer Group Policy has been applied. USERENV(534.7f4) 14:02:23:500 ProcessGPOs: Leaving with 1. USERENV(534.7f4) 14:02:23:500 ApplyGroupPolicy: Leaving successfully. USERENV(534.198) 14:02:23:531 GPOThread: Next refresh will happen in 119 minutes USERENV(1fc.200) 14:02:23:656 LibMain: Process Name: C:\Program Files\ewido anti-malware\ewidoctrl.exe USERENV(2bc.2c0) 14:02:24:296 LibMain: Process Name: C:\Program Files\LogMeIn\x86\RaMaint.exe USERENV(2d8.2e0) 14:02:24:375 LibMain: Process Name: C:\Program Files\LogMeIn\x86\LogMeIn.exe USERENV(344.490) 14:02:27:375 LibMain: Process Name: c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe USERENV(344.490) 14:02:27:390 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(4e4.4e8) 14:02:27:703 LibMain: Process Name: C:\WINDOWS\system32\nvsvc32.exe USERENV(480.4cc) 14:02:27:765 LibMain: Process Name: C:\Program Files\McAfee\MPF\MPFSrv.exe USERENV(480.4cc) 14:02:27:937 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(3d4.400) 14:02:28:171 LibMain: Process Name: C:\Program Files\McAfee\VirusScan\McShield.exe USERENV(3d4.400) 14:02:28:281 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(784.788) 14:02:29:546 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(770.8a8) 14:02:33:171 LibMain: Process Name: C:\Program Files\Dell Support Center\bin\sprtsvc.exe USERENV(770.8a8) 14:02:33:171 ImpersonateUser: Failed to impersonate user with 5. USERENV(770.8a8) 14:02:33:187 GetUserNameAndDomain Failed to impersonate user USERENV(770.8a8) 14:02:33:187 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(a00.a04) 14:02:37:781 LibMain: Process Name: C:\WINDOWS\system32\mpnotify.exe USERENV(534.538) 14:02:39:968 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(534.538) 14:02:39:968 ========================================================= USERENV(534.538) 14:02:39:968 LoadUserProfile: Entering, hToken = <0x714>, lpProfileInfo = 0x6e3e0 USERENV(534.538) 14:02:39:968 LoadUserProfile: lpProfileInfo->dwFlags = <0x0> USERENV(534.538) 14:02:39:968 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.538) 14:02:39:984 LoadUserProfile: NULL central profile path USERENV(534.538) 14:02:39:984 LoadUserProfile: NULL default profile path USERENV(534.538) 14:02:39:984 LoadUserProfile: NULL server name USERENV(534.538) 14:02:39:984 LoadUserProfile: In console winlogon process USERENV(534.538) 14:02:39:984 In LoadUserProfileP USERENV(534.538) 14:02:39:984 ========================================================= USERENV(534.538) 14:02:39:984 LoadUserProfile: Entering, hToken = <0x714>, lpProfileInfo = 0x6e3e0 USERENV(534.538) 14:02:39:984 LoadUserProfile: lpProfileInfo->dwFlags = <0x0> USERENV(534.538) 14:02:40:000 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.538) 14:02:40:000 LoadUserProfile: NULL central profile path USERENV(534.538) 14:02:40:000 LoadUserProfile: NULL default profile path USERENV(534.538) 14:02:40:000 LoadUserProfile: NULL server name USERENV(534.538) 14:02:40:000 LoadUserProfile: User sid: S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.538) 14:02:40:000 CSyncManager::EnterLock USERENV(534.538) 14:02:40:000 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 14:02:40:000 CSyncManager::EnterLock: New entry created USERENV(534.538) 14:02:40:000 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.538) 14:02:40:000 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.538) 14:02:40:000 RestoreUserProfile: Entering USERENV(534.538) 14:02:40:000 RestoreUserProfile: User is a Admin USERENV(534.538) 14:02:40:000 IsCentralProfileReachable: Entering USERENV(534.538) 14:02:40:015 IsCentralProfileReachable: Null path. Leaving USERENV(534.538) 14:02:40:015 RestoreUserProfile: Profile path = <> USERENV(534.538) 14:02:40:015 ExtractProfileFromBackup: A profile already exists USERENV(534.538) 14:02:40:015 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.538) 14:02:40:015 CreateLocalProfileKey: Not setting additional Security USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\Mark> USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.538) 14:02:40:015 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.538) 14:02:40:031 Local Existing Profile Image is reachable USERENV(534.538) 14:02:40:031 Local profile name is USERENV(534.538) 14:02:40:031 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.538) 14:02:40:281 MyRegLoadKey: Returning 00000000 USERENV(534.538) 14:02:40:281 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 14:02:40:296 MyRegLoadKey: Returning 00000000 USERENV(534.538) 14:02:40:312 CreateClassHive: existing user classes hive found USERENV(534.538) 14:02:40:312 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.538) 14:02:40:312 Profile was successfully loaded. USERENV(534.538) 14:02:40:312 lpProfile->lpRoamingProfile = <> USERENV(534.538) 14:02:40:312 lpProfile->lpLocalProfile = USERENV(534.538) 14:02:40:312 lpProfile->dwInternalFlags = 0x100 USERENV(534.538) 14:02:40:312 RestoreUserProfile: Leaving. USERENV(534.538) 14:02:40:312 UpgradeProfile: Entering USERENV(534.538) 14:02:40:312 UpgradeProfile: Build numbers match USERENV(534.538) 14:02:40:312 UpgradeProfile: Leaving Successfully USERENV(534.538) 14:02:40:328 GetProfileType: Profile already loaded. USERENV(534.538) 14:02:40:328 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.538) 14:02:40:328 GetProfileType: ProfileFlags is 0 USERENV(534.538) 14:02:40:531 Profile Ref Count is 1 USERENV(534.538) 14:02:40:531 LoadUserProfile: Leaving critical Section. USERENV(534.538) 14:02:40:531 CSyncManager::LeaveLock USERENV(534.538) 14:02:40:531 CSyncManager::LeaveLock: Lock released USERENV(534.538) 14:02:40:531 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.538) 14:02:40:531 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 14:02:40:531 LoadUserProfile: Impersonated user: 00000714, 00000000 USERENV(56c.5b0) 14:02:40:531 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5b0) 14:02:40:625 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 14:02:40:718 LoadUserProfile: Reverted to user: 00000000 USERENV(534.538) 14:02:40:734 LoadUserProfile: Leaving with a value of 1. USERENV(534.538) 14:02:40:734 ========================================================= USERENV(534.538) 14:02:40:734 LoadUserProfile: LoadUserProfileP succeeded USERENV(534.538) 14:02:40:750 LoadUserProfile: Returning success. Final Information follows: USERENV(534.538) 14:02:40:750 lpProfileInfo->UserName = USERENV(534.538) 14:02:40:750 lpProfileInfo->lpProfilePath = <> USERENV(534.538) 14:02:40:750 lpProfileInfo->dwFlags = 0x0 USERENV(534.538) 14:02:40:750 LoadUserProfile: Returning TRUE. hProfile = <0x6c0> USERENV(534.538) 14:02:40:750 ApplySystemPolicy: Entering USERENV(534.538) 14:02:40:750 ApplySystemPolicy: No Policy file. Leaving. USERENV(534.538) 14:02:40:796 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 14:02:40:906 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(534.b14) 14:02:40:921 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(534.b14) 14:02:40:921 ApplyGroupPolicy: Entering. Flags = a USERENV(534.b14) 14:02:40:953 ProcessGPOs: USERENV(534.b14) 14:02:40:953 ProcessGPOs: USERENV(534.b14) 14:02:40:953 ProcessGPOs: Starting user Group Policy (Async forground) processing… USERENV(534.b14) 14:02:40:953 ProcessGPOs: USERENV(534.b14) 14:02:40:953 ProcessGPOs: USERENV(534.b14) 14:02:40:968 EnterCriticalPolicySectionEx: Entering with timeout 600000 and flags 0x0 USERENV(534.b14) 14:02:40:968 EnterCriticalPolicySectionEx: User critical section has been claimed. Handle = 0x86c USERENV(534.b14) 14:02:41:125 EnterCriticalPolicySectionEx: Leaving successfully. USERENV(534.b14) 14:02:41:125 ProcessGPOs: Machine role is 0. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for dskquota.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for iedkcs32.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for scecli.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for C:\WINDOWS\System32\cscui.dll. USERENV(534.b14) 14:02:41:265 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.b14) 14:02:41:265 ReadExtStatus: Reading Previous Status for extension {35378EAC-683F-11D2-A89A-00C04FBBCFA2} USERENV(534.b14) 14:02:41:500 ReadExtStatus: Reading Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} USERENV(534.b14) 14:02:41:562 ReadExtStatus: Reading Previous Status for extension {25537BA6-77A8-11D2-9B6C-0000F8080861} USERENV(534.b14) 14:02:41:578 ReadExtStatus: Reading Previous Status for extension {3610eda5-77ef-11d2-8dc5-00c04fa31a66} USERENV(534.b14) 14:02:41:625 ReadExtStatus: Reading Previous Status for extension {426031c0-0b47-4852-b0ca-ac3d37bfcb39} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {42B5FAAE-6536-11d2-AE5A-0000F87571E3} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {827D319E-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {B587E2B1-4D59-4e7e-AED9-22B9DF11D053} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {C631DF4C-088F-4156-B058-4375F0853CD8} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {c6dc5466-785a-11d2-84d0-00c04fb169f7} USERENV(534.b14) 14:02:41:640 ReadExtStatus: Reading Previous Status for extension {e437bc1c-aa7d-11d2-a382-00c04f991e27} USERENV(534.b14) 14:02:41:640 ProcessGPOs: No site name defined. Skipping site policy. USERENV(534.b14) 14:02:41:640 ProcessGPOs: Calling GetGPOInfo for normal policy mode USERENV(534.b14) 14:02:41:640 GetGPOInfo: ******************************** USERENV(534.b14) 14:02:41:640 GetGPOInfo: Entering… USERENV(534.b14) 14:02:41:718 GetGPOInfo: lpHostName or lpDNName is NULL. Skipping DS stuff. USERENV(534.b14) 14:02:41:718 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(534.b14) 14:02:41:734 GetGPOInfo: Leaving with 1 USERENV(534.b14) 14:02:41:734 GetGPOInfo: ******************************** USERENV(534.b14) 14:02:41:734 ProcessGPOs: Logging Data for Target . USERENV(534.b14) 14:02:41:734 ProcessGPOs: OpenThreadToken failed with error 1008, assuming thread is not impersonating USERENV(534.b14) 14:02:41:734 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:734 ProcessGPOs: Processing extension Registry USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:734 CheckGPOs: No GPO changes but couldn't read extension Registry's status or policy time. USERENV(534.b14) 14:02:41:734 ProcessGPOs: Extension Registry skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:41:734 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:734 ProcessGPOs: Processing extension Wireless USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:734 CheckGPOs: No GPO changes but couldn't read extension Wireless's status or policy time. USERENV(534.b14) 14:02:41:734 ProcessGPOs: Extension Wireless skipped with flags 0x1000a. USERENV(534.b14) 14:02:41:734 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:734 ProcessGPOs: Processing extension Folder Redirection USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:734 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time. USERENV(534.b14) 14:02:41:734 ProcessGPOs: Extension Folder Redirection skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:41:734 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:734 ProcessGPOs: Processing extension Microsoft Disk Quota USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:734 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time. USERENV(534.b14) 14:02:41:734 ProcessGPOs: Extension Microsoft Disk Quota skipped with flags 0x1000a. USERENV(534.b14) 14:02:41:734 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:734 ProcessGPOs: Processing extension QoS Packet Scheduler USERENV(534.b14) 14:02:41:734 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:765 CheckGPOs: No GPO changes but couldn't read extension QoS Packet Scheduler's status or policy time. USERENV(534.b14) 14:02:41:859 ProcessGPOs: Extension QoS Packet Scheduler skipped with flags 0x1000a. USERENV(534.b14) 14:02:41:968 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:968 ProcessGPOs: Processing extension Scripts USERENV(534.b14) 14:02:41:968 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:968 CheckGPOs: No GPO changes but couldn't read extension Scripts's status or policy time. USERENV(534.b14) 14:02:41:968 ProcessGPOs: Extension Scripts skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:41:968 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:968 ProcessGPOs: Processing extension Internet Explorer Zonemapping USERENV(534.b14) 14:02:41:968 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:968 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping's status or policy time. USERENV(534.b14) 14:02:41:968 ProcessGPOs: Extension Internet Explorer Zonemapping skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:41:968 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:968 ProcessGPOs: Processing extension Security USERENV(534.b14) 14:02:41:968 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:41:968 CheckGPOs: No GPO changes but couldn't read extension Security's status or policy time. USERENV(534.b14) 14:02:41:968 ProcessGPOs: Extension Security skipped with flags 0x1000a. USERENV(534.b14) 14:02:41:968 ProcessGPOs: ———————– USERENV(534.b14) 14:02:41:968 ProcessGPOs: Processing extension Internet Explorer Branding USERENV(534.b14) 14:02:41:968 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:078 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time. USERENV(534.b14) 14:02:42:203 ProcessGPOs: Extension Internet Explorer Branding skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:42:203 ProcessGPOs: ———————– USERENV(534.b14) 14:02:42:234 ProcessGPOs: Processing extension EFS recovery USERENV(534.b14) 14:02:42:234 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:265 CheckGPOs: No GPO changes but couldn't read extension EFS recovery's status or policy time. USERENV(534.b14) 14:02:42:265 ProcessGPOs: Extension EFS recovery skipped with flags 0x1000a. USERENV(534.b14) 14:02:42:265 ProcessGPOs: ———————– USERENV(534.b14) 14:02:42:265 ProcessGPOs: Processing extension 802.3 Group Policy USERENV(534.b14) 14:02:42:265 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:265 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time. USERENV(534.b14) 14:02:42:265 ProcessGPOs: Extension 802.3 Group Policy skipped with flags 0x1000a. USERENV(534.b14) 14:02:42:265 ProcessGPOs: ———————– USERENV(534.b14) 14:02:42:281 ProcessGPOs: Processing extension Microsoft Offline Files USERENV(534.b14) 14:02:42:281 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:281 CheckGPOs: No GPO changes but couldn't read extension Microsoft Offline Files's status or policy time. USERENV(534.b14) 14:02:42:281 ProcessGPOs: Extension Microsoft Offline Files skipped with flags 0x1000a. USERENV(534.b14) 14:02:42:281 ProcessGPOs: ———————– USERENV(534.b14) 14:02:42:281 ProcessGPOs: Processing extension Software Installation USERENV(534.b14) 14:02:42:281 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:281 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:281 CheckGPOs: No GPO changes but couldn't read extension Software Installation's status or policy time. USERENV(534.b14) 14:02:42:281 ProcessGPOs: Extension Software Installation skipped because both deleted and changed GPO lists are empty. USERENV(534.b14) 14:02:42:281 ProcessGPOs: ———————– USERENV(534.b14) 14:02:42:281 ProcessGPOs: Processing extension IP Security USERENV(534.b14) 14:02:42:281 CompareGPOLists: The lists are the same. USERENV(534.b14) 14:02:42:281 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time. USERENV(534.b14) 14:02:42:281 ProcessGPOs: Extension IP Security skipped with flags 0x1000a. USERENV(534.b14) 14:02:42:281 SetFgRefreshInfo: Previous User Fg policy Asynchronous, Reason: NoNeedForSync. USERENV(534.b14) 14:02:42:281 ProcessGPOs: No WMI logging done in this policy cycle. USERENV(534.b14) 14:02:42:281 LeaveCriticalPolicySection: Critical section 0x86c has been released. USERENV(534.b14) 14:02:42:281 ProcessGPOs: User Group Policy has been applied. USERENV(534.b14) 14:02:42:281 ProcessGPOs: Leaving with 1. USERENV(534.b14) 14:02:42:281 ApplyGroupPolicy: Leaving successfully. USERENV(c40.c44) 14:02:42:390 LibMain: Process Name: C:\WINDOWS\system32\wbem\wmiprvse.exe USERENV(534.c38) 14:02:42:390 GPOThread: Next refresh will happen in 108 minutes USERENV(678.cc4) 14:02:45:250 GetProfileType: Profile already loaded. USERENV(678.cc4) 14:02:45:265 LoadProfileInfo: Failed to query central profile with error 2 USERENV(678.cc4) 14:02:45:265 GetProfileType: ProfileFlags is 0 USERENV(560.bac) 14:02:46:343 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.bac) 14:02:46:343 ========================================================= USERENV(560.bac) 14:02:46:343 LoadUserProfile: Entering, hToken = <0x1bc>, lpProfileInfo = 0x11df6e8 USERENV(560.bac) 14:02:46:343 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.bac) 14:02:46:343 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.bac) 14:02:46:343 LoadUserProfile: NULL central profile path USERENV(560.bac) 14:02:46:343 LoadUserProfile: NULL default profile path USERENV(560.bac) 14:02:46:343 LoadUserProfile: NULL server name USERENV(560.bac) 14:02:46:343 GetInterface: Returning rpc binding handle USERENV(534.648) 14:02:46:343 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:46:343 DropClientContext: Got client token 000001A8, sid = S-1-5-18 USERENV(534.648) 14:02:46:343 MIDL_user_allocate enter USERENV(534.648) 14:02:46:343 DropClientContext: load profile object successfully made USERENV(534.648) 14:02:46:343 DropClientContext: Returning 0 USERENV(560.bac) 14:02:46:343 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 14:02:46:343 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:46:343 In LoadUserProfileP USERENV(534.54c) 14:02:46:343 LoadUserProfile: Running as client USERENV(534.54c) 14:02:46:343 ========================================================= USERENV(534.54c) 14:02:46:343 LoadUserProfile: Entering, hToken = <0x850>, lpProfileInfo = 0xebb848 USERENV(534.54c) 14:02:46:343 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.54c) 14:02:46:343 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.54c) 14:02:46:343 LoadUserProfile: NULL central profile path USERENV(534.54c) 14:02:46:343 LoadUserProfile: NULL default profile path USERENV(534.54c) 14:02:46:343 LoadUserProfile: NULL server name USERENV(534.54c) 14:02:46:343 LoadUserProfile: User sid: S-1-5-19 USERENV(534.54c) 14:02:46:359 CSyncManager::EnterLock USERENV(534.54c) 14:02:46:359 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 14:02:46:359 CSyncManager::EnterLock: New entry created USERENV(534.54c) 14:02:46:359 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.54c) 14:02:46:359 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.54c) 14:02:46:359 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.54c) 14:02:46:359 Profile Ref Count is 2 USERENV(534.54c) 14:02:46:359 LoadUserProfile: Leaving critical Section. USERENV(534.54c) 14:02:46:359 CSyncManager::LeaveLock USERENV(534.54c) 14:02:46:359 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 14:02:46:359 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.54c) 14:02:46:359 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 14:02:46:359 LoadUserProfile: Impersonated user: 00000850, 00000820 USERENV(534.54c) 14:02:46:359 LoadUserProfile: Reverted to user: 00000000 USERENV(534.54c) 14:02:46:359 LoadUserProfile: Reverted back to user <00000000> USERENV(534.54c) 14:02:46:359 LoadUserProfile: Leaving with a value of 1. USERENV(534.54c) 14:02:46:359 ========================================================= USERENV(534.54c) 14:02:46:359 LoadUserProfileI: returning 0 USERENV(560.bac) 14:02:46:359 LoadUserProfile: Running as self USERENV(560.bac) 14:02:46:359 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.bac) 14:02:46:359 LoadUserProfile: Returning success. Final Information follows: USERENV(560.bac) 14:02:46:359 lpProfileInfo->UserName = USERENV(560.bac) 14:02:46:359 lpProfileInfo->lpProfilePath = <> USERENV(560.bac) 14:02:46:359 lpProfileInfo->dwFlags = 0x9 USERENV(534.648) 14:02:46:359 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:46:359 ReleaseClientContext: Releasing context USERENV(534.648) 14:02:46:359 ReleaseClientContext_s: Releasing context USERENV(534.648) 14:02:46:359 MIDL_user_free enter USERENV(560.bac) 14:02:46:359 ReleaseInterface: Releasing rpc binding handle USERENV(560.bac) 14:02:46:359 LoadUserProfile: Returning TRUE. hProfile = <0x1c0> USERENV(560.bac) 14:02:46:359 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(620.63c) 14:02:46:687 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(4e4.4e8) 14:02:46:750 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(4e4.4e8) 14:02:46:750 ========================================================= USERENV(4e4.4e8) 14:02:46:750 LoadUserProfile: Entering, hToken = <0x188>, lpProfileInfo = 0x12fc08 USERENV(4e4.4e8) 14:02:46:765 LoadUserProfile: lpProfileInfo->dwFlags = <0x1> USERENV(4e4.4e8) 14:02:46:765 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(4e4.4e8) 14:02:46:765 LoadUserProfile: NULL central profile path USERENV(4e4.4e8) 14:02:46:765 LoadUserProfile: NULL default profile path USERENV(4e4.4e8) 14:02:46:765 LoadUserProfile: NULL server name USERENV(4e4.4e8) 14:02:46:765 GetInterface: Returning rpc binding handle USERENV(534.54c) 14:02:46:796 IProfileSecurityCallBack: client authenticated. USERENV(678.910) 14:02:46:796 GetProfileType: Profile already loaded. USERENV(534.54c) 14:02:46:796 DropClientContext: Got client token 00000874, sid = S-1-5-18 USERENV(534.54c) 14:02:46:796 MIDL_user_allocate enter USERENV(678.910) 14:02:46:796 GetProfileType: ProfileFlags is 0 USERENV(534.54c) 14:02:46:796 DropClientContext: load profile object successfully made USERENV(534.54c) 14:02:46:796 DropClientContext: Returning 0 USERENV(4e4.4e8) 14:02:46:796 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.648) 14:02:46:796 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:46:796 In LoadUserProfileP USERENV(534.648) 14:02:46:796 LoadUserProfile: Running as client USERENV(534.648) 14:02:46:796 ========================================================= USERENV(534.648) 14:02:46:796 LoadUserProfile: Entering, hToken = <0x71c>, lpProfileInfo = 0xeb2b48 USERENV(534.648) 14:02:46:796 LoadUserProfile: lpProfileInfo->dwFlags = <0x1> USERENV(534.648) 14:02:46:796 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.648) 14:02:46:796 LoadUserProfile: NULL central profile path USERENV(534.648) 14:02:46:796 LoadUserProfile: NULL default profile path USERENV(534.648) 14:02:46:796 LoadUserProfile: NULL server name USERENV(534.648) 14:02:46:796 LoadUserProfile: User sid: S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.648) 14:02:46:796 CSyncManager::EnterLock USERENV(534.648) 14:02:46:796 CSyncManager::EnterLock: No existing entry found USERENV(534.648) 14:02:46:796 CSyncManager::EnterLock: New entry created USERENV(534.648) 14:02:46:796 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.648) 14:02:46:796 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.648) 14:02:46:796 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.648) 14:02:46:796 Profile Ref Count is 2 USERENV(534.648) 14:02:46:796 LoadUserProfile: Leaving critical Section. USERENV(534.648) 14:02:46:796 CSyncManager::LeaveLock USERENV(534.648) 14:02:46:796 CSyncManager::LeaveLock: Lock released USERENV(534.648) 14:02:46:796 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.648) 14:02:46:796 CSyncManager::LeaveLock: Lock deleted USERENV(534.648) 14:02:46:796 LoadUserProfile: Impersonated user: 0000071c, 0000011c USERENV(534.648) 14:02:46:796 LoadUserProfile: Reverted to user: 00000000 USERENV(534.648) 14:02:46:796 LoadUserProfile: Reverted back to user <00000000> USERENV(534.648) 14:02:46:796 LoadUserProfile: Leaving with a value of 1. USERENV(534.648) 14:02:46:796 ========================================================= USERENV(534.648) 14:02:46:812 LoadUserProfileI: returning 0 USERENV(4e4.4e8) 14:02:46:812 LoadUserProfile: Running as self USERENV(4e4.4e8) 14:02:46:812 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(678.944) 14:02:46:812 GetProfileType: ProfileFlags is 0 USERENV(4e4.4e8) 14:02:46:812 LoadUserProfile: Returning success. Final Information follows: USERENV(4e4.4e8) 14:02:46:812 lpProfileInfo->UserName = USERENV(4e4.4e8) 14:02:46:812 lpProfileInfo->lpProfilePath = <> USERENV(4e4.4e8) 14:02:46:812 lpProfileInfo->dwFlags = 0x1 USERENV(534.54c) 14:02:46:812 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:46:812 ReleaseClientContext: Releasing context USERENV(534.54c) 14:02:46:812 ReleaseClientContext_s: Releasing context USERENV(534.54c) 14:02:46:812 MIDL_user_free enter USERENV(4e4.4e8) 14:02:46:812 ReleaseInterface: Releasing rpc binding handle USERENV(4e4.4e8) 14:02:46:812 LoadUserProfile: Returning TRUE. hProfile = <0x19c> USERENV(e74.ef0) 14:02:47:171 LibMain: Process Name: C:\WINDOWS\System32\alg.exe USERENV(4e4.4e8) 14:02:47:265 UnloadUserProfile: Entering, hProfile = <0x19c> USERENV(4e4.4e8) 14:02:47:265 GetInterface: Returning rpc binding handle USERENV(534.ef4) 14:02:47:265 IProfileSecurityCallBack: client authenticated. USERENV(534.ef4) 14:02:47:281 DropClientContext: Got client token 000009EC, sid = S-1-5-18 USERENV(534.ef4) 14:02:47:281 MIDL_user_allocate enter USERENV(534.ef4) 14:02:47:281 DropClientContext: load profile object successfully made USERENV(534.ef4) 14:02:47:281 DropClientContext: Returning 0 USERENV(4e4.4e8) 14:02:47:281 UnLoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 14:02:47:281 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 14:02:47:312 UnloadUserProfileP: Entering, hProfile = <0x654> USERENV(534.54c) 14:02:47:312 UnloadUserProfileP: ImpersonateUser <000009ec>, old token is <00000000> USERENV(534.54c) 14:02:47:421 GetExclusionListFromRegistry: Policy list is empty, returning user list = USERENV(534.54c) 14:02:47:437 CSyncManager::EnterLock USERENV(534.54c) 14:02:47:437 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 14:02:47:437 CSyncManager::EnterLock: New entry created USERENV(534.54c) 14:02:47:437 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.54c) 14:02:47:437 UnloadUserProfileP: Wait succeeded. In critical section. USERENV(534.54c) 14:02:47:890 UnloadUserProfileP: Didn't unload user profile, Ref Count is 1 USERENV(534.54c) 14:02:47:906 UnloadUserProfileP: Reverted back to user <00000000> USERENV(534.54c) 14:02:47:906 CSyncManager::LeaveLock USERENV(534.54c) 14:02:47:906 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 14:02:47:906 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.54c) 14:02:47:906 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 14:02:47:906 UnloadUserProfileP: Leave critical section. USERENV(534.54c) 14:02:47:906 UnloadUserProfileP: Leaving with a return value of 1 USERENV(534.54c) 14:02:47:906 UnloadUserProfileI: returning 0 USERENV(4e4.4e8) 14:02:47:906 UnloadUserProfile: Calling UnloadUserProfileI succeeded USERENV(534.648) 14:02:47:906 IProfileSecurityCallBack: client authenticated. USERENV(534.648) 14:02:47:906 ReleaseClientContext: Releasing context USERENV(534.648) 14:02:47:906 ReleaseClientContext_s: Releasing context USERENV(534.648) 14:02:47:906 MIDL_user_free enter USERENV(4e4.4e8) 14:02:47:906 ReleaseInterface: Releasing rpc binding handle USERENV(4e4.4e8) 14:02:47:906 UnloadUserProfile: returning 1 USERENV(770.8a8) 14:02:48:250 ImpersonateUser: Failed to impersonate user with 5. USERENV(678.888) 14:02:48:250 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(770.8a8) 14:02:48:265 GetUserNameAndDomain Failed to impersonate user USERENV(770.8a8) 14:02:48:265 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(f00.f04) 14:02:49:328 LibMain: Process Name: c:\PROGRA~1\mcafee.com\agent\mcagent.exe USERENV(f00.f04) 14:02:49:343 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(678.778) 14:02:55:328 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(678.c24) 14:03:00:562 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(ea4.eac) 14:03:15:750 LibMain: Process Name: C:\WINDOWS\system32\wuauclt.exe USERENV(f8c.f94) 14:03:20:265 LibMain: Process Name: C:\WINDOWS\system32\taskmgr.exe USERENV(678.d7c) 14:03:23:468 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(f8c.f94) 14:03:27:031 GetProfileType: Profile already loaded. USERENV(f8c.f94) 14:03:27:031 GetProfileType: ProfileFlags is 0 USERENV(49c.4ec) 14:03:27:625 LibMain: Process Name: C:\WINDOWS\explorer.exe USERENV(4a4.508) 14:03:28:234 LibMain: Process Name: C:\Program Files\McAfee\MSK\MskSrver.exe USERENV(49c.5a0) 14:03:28:906 GetProfileType: Profile already loaded. USERENV(49c.5a0) 14:03:28:906 GetProfileType: ProfileFlags is 0 USERENV(49c.5a0) 14:03:29:984 GetProfileType: Profile already loaded. USERENV(49c.5a0) 14:03:29:984 GetProfileType: ProfileFlags is 0 USERENV(49c.5a0) 14:03:30:046 GetProfileType: Profile already loaded. USERENV(49c.5a0) 14:03:30:046 GetProfileType: ProfileFlags is 0 USERENV(ae0.a74) 14:03:37:750 LibMain: Process Name: C:\WINDOWS\system32\imapi.exe USERENV(678.d7c) 14:03:38:156 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.bd8) 14:03:39:015 LibMain: Process Name: C:\WINDOWS\system32\RUNDLL32.EXE USERENV(678.c24) 14:03:40:953 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(ff0.ff8) 14:03:52:781 LibMain: Process Name: C:\Program Files\Iomega\DriveIcons\deskup.exe USERENV(9d4.9d8) 14:04:11:875 LibMain: Process Name: C:\WINDOWS\system32\ctfmon.exe USERENV(9d4.9d8) 14:04:11:906 GetProfileType: Profile already loaded. USERENV(9d4.9d8) 14:04:11:906 GetProfileType: ProfileFlags is 0 USERENV(b70.b74) 14:04:19:109 LibMain: Process Name: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe USERENV(b58.b6c) 14:04:21:015 LibMain: Process Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe USERENV(310.350) 14:04:26:062 LibMain: Process Name: C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe USERENV(310.350) 14:04:26:093 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.a78) 14:04:27:093 LibMain: Process Name: C:\Program Files\Internet Explorer\iexplore.exe USERENV(b50.a64) 14:04:27:359 ImpersonateUser: Failed to impersonate user with 5. USERENV(b50.a64) 14:04:27:468 GetUserNameAndDomain Failed to impersonate user USERENV(b50.a64) 14:04:27:484 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.a64) 14:04:29:187 ImpersonateUser: Failed to impersonate user with 5. USERENV(b50.a64) 14:04:29:218 GetUserNameAndDomain Failed to impersonate user USERENV(b50.a64) 14:04:29:218 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(c78.c7c) 14:04:35:453 LibMain: Process Name: C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe USERENV(c78.bac) 14:04:36:078 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(310.3bc) 14:04:36:859 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(310.3bc) 14:04:37:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(a10.e8c) 14:04:44:765 LibMain: Process Name: C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE USERENV(a10.e8c) 14:04:44:765 ImpersonateUser: Failed to impersonate user with 5. USERENV(a10.e8c) 14:04:44:765 GetUserNameAndDomain Failed to impersonate user USERENV(a10.e8c) 14:04:44:765 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(a10.e8c) 14:04:44:828 ImpersonateUser: Failed to impersonate user with 5. USERENV(a10.e8c) 14:04:44:828 GetUserNameAndDomain Failed to impersonate user USERENV(a10.e8c) 14:04:44:843 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(a10.e8c) 14:04:44:906 ImpersonateUser: Failed to impersonate user with 5. USERENV(a10.e8c) 14:04:44:921 GetUserNameAndDomain Failed to impersonate user USERENV(a10.e8c) 14:04:44:921 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b38.af4) 14:04:47:093 LibMain: Process Name: C:\Program Files\Dell Support Center\gs_agent\dsc.exe USERENV(56c.5cc) 14:04:50:171 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5cc) 14:04:50:171 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5cc) 14:04:50:171 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5cc) 14:04:50:328 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5cc) 14:04:50:328 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5cc) 14:04:50:328 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5cc) 14:04:51:515 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5cc) 14:04:51:515 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5cc) 14:04:51:515 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5cc) 14:04:51:562 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5cc) 14:04:51:562 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5cc) 14:04:51:562 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(328.354) 14:04:51:687 LibMain: Process Name: c:\program files\common files\mcafee\mna\mcnasvc.exe USERENV(56c.748) 14:04:51:703 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.748) 14:04:51:703 GetUserNameAndDomain Failed to impersonate user USERENV(56c.748) 14:04:51:703 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(328.354) 14:04:51:703 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.748) 14:04:51:734 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.748) 14:04:51:734 GetUserNameAndDomain Failed to impersonate user USERENV(56c.748) 14:04:51:734 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(328.354) 14:04:51:859 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(328.354) 14:04:51:937 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(620.63c) 14:04:52:187 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(620.674) 14:04:54:375 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(620.674) 14:04:57:218 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(1324.1328) 14:04:57:484 LibMain: Process Name: C:\WINDOWS\system32\wbem\wmiprvse.exe USERENV(620.c3c) 14:04:58:484 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.1414) 14:05:02:703 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.1414) 14:05:04:000 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.748) 14:05:04:296 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.748) 14:05:04:296 GetUserNameAndDomain Failed to impersonate user USERENV(56c.748) 14:05:04:296 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(1064.1068) 14:05:06:062 LibMain: Process Name: C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN USERENV(b38.af4) 14:06:17:187 GetProfileType: Profile already loaded. USERENV(b38.af4) 14:06:17:187 GetProfileType: ProfileFlags is 0 USERENV(116c.46c) 14:06:30:953 LibMain: Process Name: \\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE USERENV(1190.14c) 14:06:31:593 LibMain: Process Name: C:\WINDOWS\system32\wbem\wmiprvse.exe USERENV(730.7e8) 14:06:35:531 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(730.7e8) 14:06:35:546 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(134c.1350) 14:07:25:375 LibMain: Process Name: C:\PROGRA~1\McAfee\MSK\MskAgent.exe USERENV(be8.bec) 14:08:40:671 LibMain: Process Name: C:\Program Files\Java\jre6\bin\jusched.exe USERENV(be8.bec) 14:08:40:687 ImpersonateUser: Failed to impersonate user with 5. USERENV(be8.bec) 14:08:40:687 GetUserNameAndDomain Failed to impersonate user USERENV(be8.bec) 14:08:40:687 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(be8.bec) 14:08:40:703 ImpersonateUser: Failed to impersonate user with 5. USERENV(be8.bec) 14:08:40:703 GetUserNameAndDomain Failed to impersonate user USERENV(be8.bec) 14:08:40:703 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(be8.bec) 14:08:40:718 ImpersonateUser: Failed to impersonate user with 5. USERENV(be8.bec) 14:08:40:718 GetUserNameAndDomain Failed to impersonate user USERENV(be8.bec) 14:08:40:734 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(88c.1624) 14:09:13:765 LibMain: Process Name: C:\WINDOWS\system32\NOTEPAD.EXE -mm
Kindly rename the current copy of userenv.log to another name. Eg - userenv-OLD.log
Then create & merge this registry script into your machine.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"RunLogonScriptSync"=-
"MaxGPOScriptWait"=dword:0000003c

* Reboot the machine

* Repeat the earlier exercise with userenv.log. A new one shall be created

* Allow at least 90 seconds to pass while waiting for explorer.exe to load. If it doesn't show up within 90 seconds, start explorer.exe using task manager.

* Then post (or attach) the resultant userenv.log.
sUBs, userinit.exe is running. explorer.exe still didn't load. Here are the new results: USERENV(1584.b90) 18:08:08:359 LibMain: Process Name: C:\WINDOWS\SYSTEM32\notepad.exe USERENV(1584.b90) 18:10:46:843 GetProfileType: Profile already loaded. USERENV(1584.b90) 18:10:46:843 GetProfileType: ProfileFlags is 0 USERENV(81c.d64) 18:12:20:531 LibMain: Process Name: C:\WINDOWS\regedit.exe USERENV(d9c.9b8) 18:13:28:343 LibMain: Process Name: C:\WINDOWS\system32\logonui.exe USERENV(534.538) 18:13:40:531 UnloadUserProfile: Entering, hProfile = <0x6c0> USERENV(534.538) 18:13:40:531 UnloadUserProfile: In console winlogon process USERENV(534.538) 18:13:40:531 UnloadUserProfileP: Entering, hProfile = <0x6c0> USERENV(534.538) 18:13:40:531 GetExclusionListFromRegistry: Policy list is empty, returning user list = USERENV(534.538) 18:13:40:531 CSyncManager::EnterLock USERENV(534.538) 18:13:40:531 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:13:40:531 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:13:40:531 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.538) 18:13:40:531 UnloadUserProfileP: Wait succeeded. In critical section. USERENV(534.538) 18:13:40:796 MyRegUnLoadKey: Returning 1. USERENV(534.538) 18:13:40:796 UnloadUserProfileP: Succesfully unloaded profile USERENV(534.538) 18:13:40:812 MyRegUnLoadKey: Returning 1. USERENV(534.538) 18:13:40:812 UnLoadClassHive: Successfully unmounted S-1-5-21-4124423304-592752288-1644981653-1006_Classes USERENV(534.538) 18:13:40:812 UnloadUserProfileP: Successfully unloaded user classes USERENV(534.538) 18:13:40:812 UnloadUserProfileP: Impersonated user USERENV(534.538) 18:13:40:812 UnloadUserProfileP: Writing local ini file USERENV(534.538) 18:13:40:828 UnloadUserProfileP: Reverting to Self USERENV(534.538) 18:13:40:828 UnloadUserProfileP: exitting and cleaning up USERENV(534.538) 18:13:40:828 CSyncManager::LeaveLock USERENV(534.538) 18:13:40:828 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:13:40:843 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.538) 18:13:40:843 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:13:40:843 UnloadUserProfileP: Leave critical section. USERENV(534.538) 18:13:40:843 UnloadUserProfileP: Leaving with a return value of 1 USERENV(534.538) 18:13:40:843 UnloadUserProfile: UnloadUserProfileP succeeded USERENV(534.538) 18:13:40:843 UnloadUserProfile: returning 1 USERENV(344.6d4) 18:13:41:437 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(c78.bac) 18:13:42:937 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(c78.bac) 18:13:42:953 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(480.4a8) 18:13:42:953 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(480.4a8) 18:13:42:968 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(328.12a4) 18:13:43:125 GetUserNameAndDomain: MyGetUserNameEx failed for NT4 style name with 1115 USERENV(328.12a4) 18:13:43:125 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(1318.14e4) 18:13:43:312 LibMain: Process Name: C:\WINDOWS\system32\wuauclt.exe USERENV(534.538) 18:14:18:515 InitializePolicyProcessing: Initialised Machine Mutex/Events USERENV(534.538) 18:14:18:515 InitializePolicyProcessing: Initialised User Mutex/Events USERENV(534.538) 18:14:18:515 LibMain: Process Name: \??\C:\WINDOWS\system32\winlogon.exe USERENV(534.538) 18:14:19:109 Entering CUserProfile::Initialize … USERENV(534.538) 18:14:19:109 CUserProfile::Initialize called by winlogon USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: critical section initialized USERENV(534.538) 18:14:19:109 CSyncManager::Initialize: critical section initialized USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: registry key Software\Microsoft\Windows NT\CurrentVersion\ProfileList opened USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-500 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-500 added in bucket 8 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:109 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-500 deleted USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1008 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1008 added in bucket 14 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:109 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1008 deleted USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1007 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1007 added in bucket 13 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:109 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1007 deleted USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 0, state is 00000100 USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:109 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-20 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 2, state is 00000000 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:109 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.538) 18:14:19:109 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:109 CUserProfile::Initialize: Proccessing S-1-5-19 USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:109 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:109 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.538) 18:14:19:109 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:109 CUserProfile::GetRefCountAndFlags: Ref count is 2, state is 00000000 USERENV(534.538) 18:14:19:125 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:125 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:125 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:125 CUserProfile::Initialize: Proccessing S-1-5-18 USERENV(534.538) 18:14:19:125 CSyncManager::EnterLock USERENV(534.538) 18:14:19:125 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:19:125 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:19:125 CHashTable::HashAdd: S-1-5-18 added in bucket 11 USERENV(534.538) 18:14:19:125 CUserProfile::CleanupUserProfile: Enter critical section. USERENV(534.538) 18:14:19:125 CUserProfile::GetRefCountAndFlags: Ref count is 1, state is 00000000 USERENV(534.538) 18:14:19:125 CUserProfile::CleanupUserProfile: Ref Count is not 0 USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:19:125 CHashTable::HashDelete: S-1-5-18 deleted USERENV(534.538) 18:14:19:125 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:19:125 CUserProfile::CleanupUserProfile: Leave critical section USERENV(534.538) 18:14:19:125 CUserProfile::Initialize: RpcServerRegisterIfEx successful USERENV(534.538) 18:14:19:125 Exiting CUserProfile::Initialize, successful USERENV(560.564) 18:14:19:156 LibMain: Process Name: C:\WINDOWS\system32\services.exe USERENV(56c.570) 18:14:19:171 LibMain: Process Name: C:\WINDOWS\system32\lsass.exe USERENV(534.538) 18:14:19:218 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(628.62c) 18:14:19:718 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(560.564) 18:14:19:859 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 18:14:19:859 ========================================================= USERENV(560.564) 18:14:19:859 LoadUserProfile: Entering, hToken = <0x2a8>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 18:14:19:859 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 18:14:19:859 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 18:14:19:859 LoadUserProfile: NULL central profile path USERENV(560.564) 18:14:19:859 LoadUserProfile: NULL default profile path USERENV(560.564) 18:14:19:859 LoadUserProfile: NULL server name USERENV(560.564) 18:14:19:859 GetInterface: Returning rpc binding handle USERENV(534.54c) 18:14:19:859 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:19:859 DropClientContext: Got client token 00000600, sid = S-1-5-18 USERENV(534.54c) 18:14:19:859 MIDL_user_allocate enter USERENV(534.54c) 18:14:19:859 DropClientContext: load profile object successfully made USERENV(534.54c) 18:14:19:859 DropClientContext: Returning 0 USERENV(560.564) 18:14:19:859 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.654) 18:14:19:859 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:19:859 In LoadUserProfileP USERENV(534.654) 18:14:19:859 LoadUserProfile: Running as client USERENV(534.654) 18:14:19:859 ========================================================= USERENV(534.654) 18:14:19:859 LoadUserProfile: Entering, hToken = <0x604>, lpProfileInfo = 0xeace30 USERENV(534.654) 18:14:19:859 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.654) 18:14:19:859 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.654) 18:14:19:859 LoadUserProfile: NULL central profile path USERENV(534.654) 18:14:19:859 LoadUserProfile: NULL default profile path USERENV(534.654) 18:14:19:859 LoadUserProfile: NULL server name USERENV(534.654) 18:14:19:859 LoadUserProfile: User sid: S-1-5-20 USERENV(534.654) 18:14:19:859 CSyncManager::EnterLock USERENV(534.654) 18:14:19:859 CSyncManager::EnterLock: No existing entry found USERENV(534.654) 18:14:19:859 CSyncManager::EnterLock: New entry created USERENV(534.654) 18:14:19:859 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.654) 18:14:19:859 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.654) 18:14:19:859 RestoreUserProfile: Entering USERENV(534.654) 18:14:19:859 IsCentralProfileReachable: Entering USERENV(534.654) 18:14:19:859 IsCentralProfileReachable: Null path. Leaving USERENV(534.654) 18:14:19:859 RestoreUserProfile: Profile path = <> USERENV(534.654) 18:14:19:859 ExtractProfileFromBackup: A profile already exists USERENV(534.654) 18:14:19:859 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.654) 18:14:19:859 CreateLocalProfileKey: Not setting additional Security USERENV(534.654) 18:14:19:859 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.654) 18:14:19:859 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\NetworkService> USERENV(534.654) 18:14:19:859 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.654) 18:14:19:875 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.654) 18:14:19:875 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.654) 18:14:19:875 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.654) 18:14:19:875 Local Existing Profile Image is reachable USERENV(534.654) 18:14:19:875 Local profile name is USERENV(534.654) 18:14:19:875 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.654) 18:14:19:875 MyRegLoadKey: Returning 00000000 USERENV(534.654) 18:14:19:875 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.654) 18:14:19:890 MyRegLoadKey: Returning 00000000 USERENV(534.654) 18:14:19:890 CreateClassHive: existing user classes hive found USERENV(534.654) 18:14:19:890 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.654) 18:14:19:890 Profile was successfully loaded. USERENV(534.654) 18:14:19:890 lpProfile->lpRoamingProfile = <> USERENV(534.654) 18:14:19:890 lpProfile->lpLocalProfile = USERENV(534.654) 18:14:19:890 lpProfile->dwInternalFlags = 0x0 USERENV(534.654) 18:14:19:890 RestoreUserProfile: Leaving. USERENV(534.654) 18:14:19:921 UpgradeProfile: Entering USERENV(534.654) 18:14:19:921 UpgradeProfile: Build numbers match USERENV(534.654) 18:14:19:921 UpgradeProfile: Leaving Successfully USERENV(534.654) 18:14:19:921 GetProfileType: Profile already loaded. USERENV(534.654) 18:14:19:921 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.654) 18:14:19:921 GetProfileType: ProfileFlags is 0 USERENV(534.654) 18:14:19:968 Profile Ref Count is 1 USERENV(534.654) 18:14:19:968 LoadUserProfile: Leaving critical Section. USERENV(534.654) 18:14:19:968 CSyncManager::LeaveLock USERENV(534.654) 18:14:19:968 CSyncManager::LeaveLock: Lock released USERENV(534.654) 18:14:19:968 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.654) 18:14:19:968 CSyncManager::LeaveLock: Lock deleted USERENV(534.654) 18:14:19:968 LoadUserProfile: Impersonated user: 00000604, 00000610 USERENV(56c.5b4) 18:14:19:968 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5b4) 18:14:19:984 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.654) 18:14:19:984 LoadUserProfile: Reverted to user: 00000000 USERENV(534.654) 18:14:19:984 LoadUserProfile: Reverted back to user <00000000> USERENV(534.654) 18:14:19:984 LoadUserProfile: Leaving with a value of 1. USERENV(534.654) 18:14:19:984 ========================================================= USERENV(534.654) 18:14:19:984 LoadUserProfileI: returning 0 USERENV(560.564) 18:14:19:984 LoadUserProfile: Running as self USERENV(560.564) 18:14:19:984 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 18:14:19:984 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 18:14:19:984 lpProfileInfo->UserName = USERENV(560.564) 18:14:19:984 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 18:14:19:984 lpProfileInfo->dwFlags = 0x9 USERENV(534.54c) 18:14:19:984 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:19:984 ReleaseClientContext: Releasing context USERENV(534.54c) 18:14:19:984 ReleaseClientContext_s: Releasing context USERENV(534.54c) 18:14:19:984 MIDL_user_free enter USERENV(560.564) 18:14:19:984 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 18:14:19:984 LoadUserProfile: Returning TRUE. hProfile = <0x31c> USERENV(560.564) 18:14:19:984 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(65c.660) 18:14:20:015 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(684.688) 18:14:20:125 LibMain: Process Name: C:\WINDOWS\System32\svchost.exe USERENV(560.564) 18:14:20:140 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 18:14:20:140 ========================================================= USERENV(560.564) 18:14:20:140 LoadUserProfile: Entering, hToken = <0x360>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 18:14:20:140 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 18:14:20:140 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 18:14:20:140 LoadUserProfile: NULL central profile path USERENV(560.564) 18:14:20:140 LoadUserProfile: NULL default profile path USERENV(560.564) 18:14:20:140 LoadUserProfile: NULL server name USERENV(560.564) 18:14:20:140 GetInterface: Returning rpc binding handle USERENV(534.654) 18:14:20:140 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:20:140 DropClientContext: Got client token 00000614, sid = S-1-5-18 USERENV(534.654) 18:14:20:140 MIDL_user_allocate enter USERENV(534.654) 18:14:20:140 DropClientContext: load profile object successfully made USERENV(534.654) 18:14:20:140 DropClientContext: Returning 0 USERENV(560.564) 18:14:20:140 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 18:14:20:140 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:20:140 In LoadUserProfileP USERENV(534.54c) 18:14:20:140 LoadUserProfile: Running as client USERENV(534.54c) 18:14:20:140 ========================================================= USERENV(534.54c) 18:14:20:140 LoadUserProfile: Entering, hToken = <0x610>, lpProfileInfo = 0xeb6f40 USERENV(534.54c) 18:14:20:140 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.54c) 18:14:20:140 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.54c) 18:14:20:140 LoadUserProfile: NULL central profile path USERENV(534.54c) 18:14:20:140 LoadUserProfile: NULL default profile path USERENV(534.54c) 18:14:20:140 LoadUserProfile: NULL server name USERENV(534.54c) 18:14:20:140 LoadUserProfile: User sid: S-1-5-20 USERENV(534.54c) 18:14:20:140 CSyncManager::EnterLock USERENV(534.54c) 18:14:20:140 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 18:14:20:140 CSyncManager::EnterLock: New entry created USERENV(534.54c) 18:14:20:140 CHashTable::HashAdd: S-1-5-20 added in bucket 4 USERENV(534.54c) 18:14:20:140 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.54c) 18:14:20:140 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.54c) 18:14:20:140 Profile Ref Count is 2 USERENV(534.54c) 18:14:20:140 LoadUserProfile: Leaving critical Section. USERENV(534.54c) 18:14:20:140 CSyncManager::LeaveLock USERENV(534.54c) 18:14:20:140 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 18:14:20:140 CHashTable::HashDelete: S-1-5-20 deleted USERENV(534.54c) 18:14:20:140 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 18:14:20:156 LoadUserProfile: Impersonated user: 00000610, 00000604 USERENV(534.54c) 18:14:20:156 LoadUserProfile: Reverted to user: 00000000 USERENV(534.54c) 18:14:20:156 LoadUserProfile: Reverted back to user <00000000> USERENV(534.54c) 18:14:20:156 LoadUserProfile: Leaving with a value of 1. USERENV(534.54c) 18:14:20:156 ========================================================= USERENV(534.54c) 18:14:20:156 LoadUserProfileI: returning 0 USERENV(560.564) 18:14:20:156 LoadUserProfile: Running as self USERENV(560.564) 18:14:20:156 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 18:14:20:156 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 18:14:20:156 lpProfileInfo->UserName = USERENV(560.564) 18:14:20:156 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 18:14:20:156 lpProfileInfo->dwFlags = 0x9 USERENV(534.654) 18:14:20:156 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:20:156 ReleaseClientContext: Releasing context USERENV(534.654) 18:14:20:156 ReleaseClientContext_s: Releasing context USERENV(534.654) 18:14:20:156 MIDL_user_free enter USERENV(560.564) 18:14:20:156 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 18:14:20:156 LoadUserProfile: Returning TRUE. hProfile = <0x344> USERENV(560.564) 18:14:20:156 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(6f0.6f4) 18:14:20:187 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(560.564) 18:14:20:203 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.564) 18:14:20:203 ========================================================= USERENV(560.564) 18:14:20:203 LoadUserProfile: Entering, hToken = <0x374>, lpProfileInfo = 0x7fcf8 USERENV(560.564) 18:14:20:203 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.564) 18:14:20:203 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.564) 18:14:20:203 LoadUserProfile: NULL central profile path USERENV(560.564) 18:14:20:203 LoadUserProfile: NULL default profile path USERENV(560.564) 18:14:20:203 LoadUserProfile: NULL server name USERENV(560.564) 18:14:20:203 GetInterface: Returning rpc binding handle USERENV(534.54c) 18:14:20:203 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:20:203 DropClientContext: Got client token 00000614, sid = S-1-5-18 USERENV(534.54c) 18:14:20:203 MIDL_user_allocate enter USERENV(534.54c) 18:14:20:203 DropClientContext: load profile object successfully made USERENV(534.54c) 18:14:20:203 DropClientContext: Returning 0 USERENV(560.564) 18:14:20:203 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.654) 18:14:20:203 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:20:203 In LoadUserProfileP USERENV(534.654) 18:14:20:203 LoadUserProfile: Running as client USERENV(534.654) 18:14:20:203 ========================================================= USERENV(534.654) 18:14:20:203 LoadUserProfile: Entering, hToken = <0x610>, lpProfileInfo = 0xeb6f18 USERENV(534.654) 18:14:20:203 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.654) 18:14:20:203 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.654) 18:14:20:203 LoadUserProfile: NULL central profile path USERENV(534.654) 18:14:20:203 LoadUserProfile: NULL default profile path USERENV(534.654) 18:14:20:203 LoadUserProfile: NULL server name USERENV(534.654) 18:14:20:218 LoadUserProfile: User sid: S-1-5-19 USERENV(534.654) 18:14:20:218 CSyncManager::EnterLock USERENV(534.654) 18:14:20:218 CSyncManager::EnterLock: No existing entry found USERENV(534.654) 18:14:20:218 CSyncManager::EnterLock: New entry created USERENV(534.654) 18:14:20:218 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.654) 18:14:20:218 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.654) 18:14:20:218 RestoreUserProfile: Entering USERENV(534.654) 18:14:20:218 IsCentralProfileReachable: Entering USERENV(534.654) 18:14:20:218 IsCentralProfileReachable: Null path. Leaving USERENV(534.654) 18:14:20:218 RestoreUserProfile: Profile path = <> USERENV(534.654) 18:14:20:218 ExtractProfileFromBackup: A profile already exists USERENV(534.654) 18:14:20:218 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.654) 18:14:20:218 CreateLocalProfileKey: Not setting additional Security USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\LocalService> USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.654) 18:14:20:218 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.654) 18:14:20:218 Local Existing Profile Image is reachable USERENV(534.654) 18:14:20:218 Local profile name is USERENV(534.654) 18:14:20:218 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.654) 18:14:20:218 MyRegLoadKey: Returning 00000000 USERENV(534.654) 18:14:20:218 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.654) 18:14:20:234 MyRegLoadKey: Returning 00000000 USERENV(534.654) 18:14:20:234 CreateClassHive: existing user classes hive found USERENV(534.654) 18:14:20:234 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.654) 18:14:20:234 Profile was successfully loaded. USERENV(534.654) 18:14:20:234 lpProfile->lpRoamingProfile = <> USERENV(534.654) 18:14:20:234 lpProfile->lpLocalProfile = USERENV(534.654) 18:14:20:234 lpProfile->dwInternalFlags = 0x0 USERENV(534.654) 18:14:20:234 RestoreUserProfile: Leaving. USERENV(534.654) 18:14:20:234 UpgradeProfile: Entering USERENV(534.654) 18:14:20:234 UpgradeProfile: Build numbers match USERENV(534.654) 18:14:20:234 UpgradeProfile: Leaving Successfully USERENV(534.654) 18:14:20:234 GetProfileType: Profile already loaded. USERENV(534.654) 18:14:20:234 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.654) 18:14:20:234 GetProfileType: ProfileFlags is 0 USERENV(534.654) 18:14:20:234 Profile Ref Count is 1 USERENV(534.654) 18:14:20:234 LoadUserProfile: Leaving critical Section. USERENV(534.654) 18:14:20:234 CSyncManager::LeaveLock USERENV(534.654) 18:14:20:234 CSyncManager::LeaveLock: Lock released USERENV(534.654) 18:14:20:234 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.654) 18:14:20:234 CSyncManager::LeaveLock: Lock deleted USERENV(534.654) 18:14:20:234 LoadUserProfile: Impersonated user: 00000610, 00000604 USERENV(56c.5d8) 18:14:20:250 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d8) 18:14:20:250 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.654) 18:14:20:265 LoadUserProfile: Reverted to user: 00000000 USERENV(534.654) 18:14:20:265 LoadUserProfile: Reverted back to user <00000000> USERENV(534.654) 18:14:20:265 LoadUserProfile: Leaving with a value of 1. USERENV(534.654) 18:14:20:265 ========================================================= USERENV(534.654) 18:14:20:265 LoadUserProfileI: returning 0 USERENV(560.564) 18:14:20:265 LoadUserProfile: Running as self USERENV(560.564) 18:14:20:265 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.564) 18:14:20:265 LoadUserProfile: Returning success. Final Information follows: USERENV(560.564) 18:14:20:265 lpProfileInfo->UserName = USERENV(560.564) 18:14:20:265 lpProfileInfo->lpProfilePath = <> USERENV(560.564) 18:14:20:265 lpProfileInfo->dwFlags = 0x9 USERENV(534.54c) 18:14:20:265 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:20:265 ReleaseClientContext: Releasing context USERENV(534.54c) 18:14:20:265 ReleaseClientContext_s: Releasing context USERENV(534.54c) 18:14:20:265 MIDL_user_free enter USERENV(560.564) 18:14:20:265 ReleaseInterface: Releasing rpc binding handle USERENV(560.564) 18:14:20:265 LoadUserProfile: Returning TRUE. hProfile = <0x364> USERENV(560.564) 18:14:20:265 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(73c.740) 18:14:20:312 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(7b8.7bc) 18:14:20:890 LibMain: Process Name: C:\WINDOWS\system32\logonui.exe USERENV(534.7fc) 18:14:20:953 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(100.104) 18:14:21:046 LibMain: Process Name: C:\WINDOWS\system32\spoolsv.exe USERENV(534.7fc) 18:14:21:453 ApplyGroupPolicy: Entering. Flags = b USERENV(534.7fc) 18:14:21:453 ProcessGPOs: USERENV(534.7fc) 18:14:21:453 ProcessGPOs: USERENV(534.7fc) 18:14:21:453 ProcessGPOs: Starting computer Group Policy (Async forground) processing… USERENV(534.7fc) 18:14:21:453 ProcessGPOs: USERENV(534.7fc) 18:14:21:453 ProcessGPOs: USERENV(534.7fc) 18:14:21:453 EnterCriticalPolicySectionEx: Entering with timeout 600000 and flags 0x0 USERENV(534.7fc) 18:14:21:453 EnterCriticalPolicySectionEx: Machine critical section has been claimed. Handle = 0x774 USERENV(534.7fc) 18:14:21:453 EnterCriticalPolicySectionEx: Leaving successfully. USERENV(534.7fc) 18:14:21:453 ProcessGPOs: Machine role is 0. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for dskquota.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for iedkcs32.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for scecli.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for C:\WINDOWS\System32\cscui.dll. USERENV(534.7fc) 18:14:21:453 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {35378EAC-683F-11D2-A89A-00C04FBBCFA2} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {25537BA6-77A8-11D2-9B6C-0000F8080861} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {3610eda5-77ef-11d2-8dc5-00c04fa31a66} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {426031c0-0b47-4852-b0ca-ac3d37bfcb39} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {42B5FAAE-6536-11d2-AE5A-0000F87571E3} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {827D319E-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {B587E2B1-4D59-4e7e-AED9-22B9DF11D053} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {C631DF4C-088F-4156-B058-4375F0853CD8} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {c6dc5466-785a-11d2-84d0-00c04fb169f7} USERENV(534.7fc) 18:14:21:453 ReadExtStatus: Reading Previous Status for extension {e437bc1c-aa7d-11d2-a382-00c04f991e27} USERENV(534.7fc) 18:14:21:453 ProcessGPOs: No site name defined. Skipping site policy. USERENV(534.7fc) 18:14:21:453 ProcessGPOs: Calling GetGPOInfo for normal policy mode USERENV(534.7fc) 18:14:21:453 GetGPOInfo: ******************************** USERENV(534.7fc) 18:14:21:453 GetGPOInfo: Entering… USERENV(534.7fc) 18:14:21:453 GetGPOInfo: lpHostName or lpDNName is NULL. Skipping DS stuff. USERENV(534.7fc) 18:14:21:453 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(534.7fc) 18:14:21:453 GetGPOInfo: Leaving with 1 USERENV(534.7fc) 18:14:21:453 GetGPOInfo: ******************************** USERENV(534.7fc) 18:14:21:453 ProcessGPOs: Logging Data for Target . USERENV(534.7fc) 18:14:21:453 ProcessGPOs: OpenThreadToken failed with error 1008, assuming thread is not impersonating USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Registry USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Registry's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Registry skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Wireless USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Wireless's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Wireless skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Folder Redirection USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Folder Redirection skipped with flags 0x1000b. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Microsoft Disk Quota USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Microsoft Disk Quota skipped with flags 0x1000b. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension QoS Packet Scheduler USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension QoS Packet Scheduler's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension QoS Packet Scheduler skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Scripts USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Scripts's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Scripts skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Internet Explorer Zonemapping USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Internet Explorer Zonemapping skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Security USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Security's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Security skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Internet Explorer Branding USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Internet Explorer Branding skipped with flags 0x1000b. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension EFS recovery USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension EFS recovery's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension EFS recovery skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension 802.3 Group Policy USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension 802.3 Group Policy skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Microsoft Offline Files USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Microsoft Offline Files's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Microsoft Offline Files skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension Software Installation USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension Software Installation's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension Software Installation skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: ———————– USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Processing extension IP Security USERENV(534.7fc) 18:14:21:468 CompareGPOLists: The lists are the same. USERENV(534.7fc) 18:14:21:468 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: Extension IP Security skipped because both deleted and changed GPO lists are empty. USERENV(534.7fc) 18:14:21:468 SetFgRefreshInfo: Previous Machine Fg policy Asynchronous, Reason: NoNeedForSync. USERENV(534.7fc) 18:14:21:468 ProcessGPOs: No WMI logging done in this policy cycle. USERENV(534.7fc) 18:14:21:484 LeaveCriticalPolicySection: Critical section 0x774 has been released. USERENV(534.7fc) 18:14:21:484 ProcessGPOs: Computer Group Policy has been applied. USERENV(534.7fc) 18:14:21:484 ProcessGPOs: Leaving with 1. USERENV(534.7fc) 18:14:21:484 ApplyGroupPolicy: Leaving successfully. USERENV(534.174) 18:14:21:484 GPOThread: Next refresh will happen in 97 minutes USERENV(16c.190) 18:14:21:562 LibMain: Process Name: C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe USERENV(200.204) 18:14:22:171 LibMain: Process Name: C:\Program Files\ewido anti-malware\ewidoctrl.exe USERENV(2ac.2b4) 18:14:22:359 LibMain: Process Name: C:\Program Files\LogMeIn\x86\RaMaint.exe USERENV(2d0.2d4) 18:14:22:453 LibMain: Process Name: C:\Program Files\LogMeIn\x86\LogMeIn.exe USERENV(340.3dc) 18:14:26:468 LibMain: Process Name: c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe USERENV(340.3dc) 18:14:26:484 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(84.3e0) 18:14:26:781 LibMain: Process Name: C:\Program Files\McAfee\VirusScan\McShield.exe USERENV(84.3e0) 18:14:27:890 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(484.4d4) 18:14:27:953 LibMain: Process Name: C:\Program Files\McAfee\MPF\MPFSrv.exe USERENV(484.4d4) 18:14:27:953 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(510.518) 18:14:27:984 LibMain: Process Name: C:\WINDOWS\system32\nvsvc32.exe USERENV(698.69c) 18:14:28:890 LibMain: Process Name: C:\WINDOWS\system32\mpnotify.exe USERENV(81c.820) 18:14:30:000 LibMain: Process Name: C:\WINDOWS\system32\svchost.exe USERENV(534.538) 18:14:32:156 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(534.538) 18:14:32:156 ========================================================= USERENV(534.538) 18:14:32:156 LoadUserProfile: Entering, hToken = <0x710>, lpProfileInfo = 0x6e3e0 USERENV(534.538) 18:14:32:156 LoadUserProfile: lpProfileInfo->dwFlags = <0x0> USERENV(534.538) 18:14:32:156 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL central profile path USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL default profile path USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL server name USERENV(534.538) 18:14:32:156 LoadUserProfile: In console winlogon process USERENV(534.538) 18:14:32:156 In LoadUserProfileP USERENV(534.538) 18:14:32:156 ========================================================= USERENV(534.538) 18:14:32:156 LoadUserProfile: Entering, hToken = <0x710>, lpProfileInfo = 0x6e3e0 USERENV(534.538) 18:14:32:156 LoadUserProfile: lpProfileInfo->dwFlags = <0x0> USERENV(534.538) 18:14:32:156 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL central profile path USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL default profile path USERENV(534.538) 18:14:32:156 LoadUserProfile: NULL server name USERENV(534.538) 18:14:32:156 LoadUserProfile: User sid: S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.538) 18:14:32:156 CSyncManager::EnterLock USERENV(534.538) 18:14:32:156 CSyncManager::EnterLock: No existing entry found USERENV(534.538) 18:14:32:156 CSyncManager::EnterLock: New entry created USERENV(534.538) 18:14:32:156 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.538) 18:14:32:156 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.538) 18:14:32:156 RestoreUserProfile: Entering USERENV(534.538) 18:14:32:156 RestoreUserProfile: User is a Admin USERENV(534.538) 18:14:32:156 IsCentralProfileReachable: Entering USERENV(534.538) 18:14:32:156 IsCentralProfileReachable: Null path. Leaving USERENV(534.538) 18:14:32:156 RestoreUserProfile: Profile path = <> USERENV(534.538) 18:14:32:156 ExtractProfileFromBackup: A profile already exists USERENV(534.538) 18:14:32:156 PatchNewProfileIfRequred: A profile already exists with the current sid, exitting USERENV(534.538) 18:14:32:156 CreateLocalProfileKey: Not setting additional Security USERENV(534.538) 18:14:32:156 GetExistingLocalProfileImage: Found entry in profile list for existing local profile USERENV(534.538) 18:14:32:171 GetExistingLocalProfileImage: Local profile image filename = <%SystemDrive%\Documents and Settings\Mark> USERENV(534.538) 18:14:32:171 GetExistingLocalProfileImage: Expanded local profile image filename = USERENV(534.538) 18:14:32:171 GetExistingLocalProfileImage: No local mandatory profile. Error = 2 USERENV(534.538) 18:14:32:171 GetExistingLocalProfileImage: Found local profile image file ok USERENV(534.538) 18:14:32:171 GetExistingLocalProfileImage: Failed to query low profile unload time with error 2 USERENV(534.538) 18:14:32:171 Local Existing Profile Image is reachable USERENV(534.538) 18:14:32:171 Local profile name is USERENV(534.538) 18:14:32:171 RestoreUserProfile: No central profile. Attempting to load local profile. USERENV(534.538) 18:14:32:421 MyRegLoadKey: Returning 00000000 USERENV(534.538) 18:14:32:421 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 18:14:32:468 MyRegLoadKey: Returning 00000000 USERENV(534.538) 18:14:32:468 CreateClassHive: existing user classes hive found USERENV(534.538) 18:14:32:468 RestoreUserProfile: About to Leave. Final Information follows: USERENV(534.538) 18:14:32:468 Profile was successfully loaded. USERENV(534.538) 18:14:32:468 lpProfile->lpRoamingProfile = <> USERENV(534.538) 18:14:32:468 lpProfile->lpLocalProfile = USERENV(534.538) 18:14:32:468 lpProfile->dwInternalFlags = 0x100 USERENV(534.538) 18:14:32:468 RestoreUserProfile: Leaving. USERENV(534.538) 18:14:32:468 UpgradeProfile: Entering USERENV(534.538) 18:14:32:468 UpgradeProfile: Build numbers match USERENV(534.538) 18:14:32:468 UpgradeProfile: Leaving Successfully USERENV(534.538) 18:14:32:484 GetProfileType: Profile already loaded. USERENV(534.538) 18:14:32:484 LoadProfileInfo: Failed to query central profile with error 2 USERENV(534.538) 18:14:32:484 GetProfileType: ProfileFlags is 0 USERENV(534.538) 18:14:33:046 Profile Ref Count is 1 USERENV(534.538) 18:14:33:046 LoadUserProfile: Leaving critical Section. USERENV(534.538) 18:14:33:046 CSyncManager::LeaveLock USERENV(534.538) 18:14:33:046 CSyncManager::LeaveLock: Lock released USERENV(534.538) 18:14:33:046 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.538) 18:14:33:046 CSyncManager::LeaveLock: Lock deleted USERENV(534.538) 18:14:33:046 LoadUserProfile: Impersonated user: 00000710, 00000000 USERENV(56c.5d8) 18:14:33:046 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d8) 18:14:33:109 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 18:14:33:156 LoadUserProfile: Reverted to user: 00000000 USERENV(534.538) 18:14:33:156 LoadUserProfile: Leaving with a value of 1. USERENV(534.538) 18:14:33:156 ========================================================= USERENV(534.538) 18:14:33:156 LoadUserProfile: LoadUserProfileP succeeded USERENV(534.538) 18:14:33:156 LoadUserProfile: Returning success. Final Information follows: USERENV(534.538) 18:14:33:156 lpProfileInfo->UserName = USERENV(534.538) 18:14:33:156 lpProfileInfo->lpProfilePath = <> USERENV(534.538) 18:14:33:156 lpProfileInfo->dwFlags = 0x0 USERENV(534.538) 18:14:33:156 LoadUserProfile: Returning TRUE. hProfile = <0x758> USERENV(534.538) 18:14:33:156 ApplySystemPolicy: Entering USERENV(534.538) 18:14:33:250 ApplySystemPolicy: No Policy file. Leaving. USERENV(534.538) 18:14:33:375 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(7d0.890) 18:14:33:593 LibMain: Process Name: C:\Program Files\Dell Support Center\bin\sprtsvc.exe USERENV(7d0.890) 18:14:33:718 ImpersonateUser: Failed to impersonate user with 5. USERENV(7d0.890) 18:14:33:718 GetUserNameAndDomain Failed to impersonate user USERENV(7d0.890) 18:14:34:046 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(534.538) 18:14:34:437 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(534.96c) 18:14:34:437 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(534.96c) 18:14:35:062 ApplyGroupPolicy: Entering. Flags = a USERENV(534.96c) 18:14:35:062 ProcessGPOs: USERENV(534.96c) 18:14:35:062 ProcessGPOs: USERENV(534.96c) 18:14:35:062 ProcessGPOs: Starting user Group Policy (Async forground) processing… USERENV(534.96c) 18:14:35:062 ProcessGPOs: USERENV(534.96c) 18:14:35:062 ProcessGPOs: USERENV(534.96c) 18:14:35:062 EnterCriticalPolicySectionEx: Entering with timeout 600000 and flags 0x0 USERENV(534.96c) 18:14:35:062 EnterCriticalPolicySectionEx: User critical section has been claimed. Handle = 0x814 USERENV(534.96c) 18:14:35:062 EnterCriticalPolicySectionEx: Leaving successfully. USERENV(534.96c) 18:14:35:109 ProcessGPOs: Machine role is 0. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for dskquota.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for iedkcs32.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for scecli.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for C:\WINDOWS\System32\cscui.dll. USERENV(534.96c) 18:14:35:109 ReadGPExtensions: Rsop entry point not found for gptext.dll. USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {35378EAC-683F-11D2-A89A-00C04FBBCFA2} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {25537BA6-77A8-11D2-9B6C-0000F8080861} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {3610eda5-77ef-11d2-8dc5-00c04fa31a66} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {426031c0-0b47-4852-b0ca-ac3d37bfcb39} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {42B5FAAE-6536-11d2-AE5A-0000F87571E3} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {827D319E-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {B587E2B1-4D59-4e7e-AED9-22B9DF11D053} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {C631DF4C-088F-4156-B058-4375F0853CD8} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {c6dc5466-785a-11d2-84d0-00c04fb169f7} USERENV(534.96c) 18:14:35:109 ReadExtStatus: Reading Previous Status for extension {e437bc1c-aa7d-11d2-a382-00c04f991e27} USERENV(534.96c) 18:14:35:140 ProcessGPOs: No site name defined. Skipping site policy. USERENV(534.96c) 18:14:35:140 ProcessGPOs: Calling GetGPOInfo for normal policy mode USERENV(534.96c) 18:14:35:140 GetGPOInfo: ******************************** USERENV(534.96c) 18:14:35:140 GetGPOInfo: Entering… USERENV(534.96c) 18:14:35:296 GetGPOInfo: lpHostName or lpDNName is NULL. Skipping DS stuff. USERENV(534.96c) 18:14:35:296 GetGPOInfo: Local GPO's gpt.ini is not accessible, assuming default state. USERENV(534.96c) 18:14:35:296 GetGPOInfo: Leaving with 1 USERENV(534.96c) 18:14:35:296 GetGPOInfo: ******************************** USERENV(534.96c) 18:14:35:296 ProcessGPOs: Logging Data for Target . USERENV(534.96c) 18:14:35:296 ProcessGPOs: OpenThreadToken failed with error 1008, assuming thread is not impersonating USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Registry USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Registry's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Registry skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Wireless USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Wireless's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Wireless skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Folder Redirection USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Folder Redirection skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Microsoft Disk Quota USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Microsoft Disk Quota skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension QoS Packet Scheduler USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension QoS Packet Scheduler's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension QoS Packet Scheduler skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Scripts USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Scripts's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Scripts skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Internet Explorer Zonemapping USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Internet Explorer Zonemapping skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Security USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Security's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Security skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension Internet Explorer Branding USERENV(534.96c) 18:14:35:296 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:296 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time. USERENV(534.96c) 18:14:35:296 ProcessGPOs: Extension Internet Explorer Branding skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:296 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:296 ProcessGPOs: Processing extension EFS recovery USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CheckGPOs: No GPO changes but couldn't read extension EFS recovery's status or policy time. USERENV(534.96c) 18:14:35:312 ProcessGPOs: Extension EFS recovery skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:312 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:312 ProcessGPOs: Processing extension 802.3 Group Policy USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time. USERENV(534.96c) 18:14:35:312 ProcessGPOs: Extension 802.3 Group Policy skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:312 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:312 ProcessGPOs: Processing extension Microsoft Offline Files USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CheckGPOs: No GPO changes but couldn't read extension Microsoft Offline Files's status or policy time. USERENV(534.96c) 18:14:35:312 ProcessGPOs: Extension Microsoft Offline Files skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:312 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:312 ProcessGPOs: Processing extension Software Installation USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CheckGPOs: No GPO changes but couldn't read extension Software Installation's status or policy time. USERENV(534.96c) 18:14:35:312 ProcessGPOs: Extension Software Installation skipped because both deleted and changed GPO lists are empty. USERENV(534.96c) 18:14:35:312 ProcessGPOs: ———————– USERENV(534.96c) 18:14:35:312 ProcessGPOs: Processing extension IP Security USERENV(534.96c) 18:14:35:312 CompareGPOLists: The lists are the same. USERENV(534.96c) 18:14:35:312 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time. USERENV(534.96c) 18:14:35:312 ProcessGPOs: Extension IP Security skipped with flags 0x1000a. USERENV(534.96c) 18:14:35:312 SetFgRefreshInfo: Previous User Fg policy Asynchronous, Reason: NoNeedForSync. USERENV(534.96c) 18:14:35:312 ProcessGPOs: No WMI logging done in this policy cycle. USERENV(534.96c) 18:14:35:609 LeaveCriticalPolicySection: Critical section 0x814 has been released. USERENV(534.96c) 18:14:35:609 ProcessGPOs: User Group Policy has been applied. USERENV(534.96c) 18:14:35:609 ProcessGPOs: Leaving with 1. USERENV(534.96c) 18:14:35:609 ApplyGroupPolicy: Leaving successfully. USERENV(534.9ec) 18:14:38:984 GPOThread: Next refresh will happen in 107 minutes USERENV(534.538) 18:14:39:703 IsSyncForegroundPolicyRefresh: Asynchronous, Reason: NoNeedForSync USERENV(ad8.adc) 18:14:40:000 LibMain: Process Name: C:\WINDOWS\system32\userinit.exe USERENV(af0.af4) 18:14:40:500 LibMain: Process Name: C:\WINDOWS\system32\WgaTray.exe USERENV(af0.af4) 18:14:40:546 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(af0.af4) 18:14:40:687 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(b50.b54) 18:14:40:875 LibMain: Process Name: C:\WINDOWS\system32\wbem\wmiprvse.exe USERENV(684.d3c) 18:14:47:859 GetProfileType: Profile already loaded. USERENV(684.d3c) 18:14:47:875 LoadProfileInfo: Failed to query central profile with error 2 USERENV(684.d3c) 18:14:47:906 GetProfileType: ProfileFlags is 0 USERENV(628.b4c) 18:14:48:484 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(560.648) 18:14:48:515 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(560.648) 18:14:48:515 ========================================================= USERENV(560.648) 18:14:48:515 LoadUserProfile: Entering, hToken = <0x534>, lpProfileInfo = 0x9af6e8 USERENV(560.648) 18:14:48:515 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(560.648) 18:14:48:515 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(560.648) 18:14:48:515 LoadUserProfile: NULL central profile path USERENV(560.648) 18:14:48:515 LoadUserProfile: NULL default profile path USERENV(560.648) 18:14:48:515 LoadUserProfile: NULL server name USERENV(560.648) 18:14:48:515 GetInterface: Returning rpc binding handle USERENV(534.654) 18:14:48:515 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:48:515 DropClientContext: Got client token 00000650, sid = S-1-5-18 USERENV(534.654) 18:14:48:515 MIDL_user_allocate enter USERENV(534.654) 18:14:48:515 DropClientContext: load profile object successfully made USERENV(534.654) 18:14:48:515 DropClientContext: Returning 0 USERENV(560.648) 18:14:48:515 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 18:14:48:531 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:48:531 In LoadUserProfileP USERENV(534.54c) 18:14:48:531 LoadUserProfile: Running as client USERENV(534.54c) 18:14:48:531 ========================================================= USERENV(534.54c) 18:14:48:531 LoadUserProfile: Entering, hToken = <0xc>, lpProfileInfo = 0xef8c68 USERENV(534.54c) 18:14:48:531 LoadUserProfile: lpProfileInfo->dwFlags = <0x9> USERENV(534.54c) 18:14:48:531 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.54c) 18:14:48:531 LoadUserProfile: NULL central profile path USERENV(534.54c) 18:14:48:531 LoadUserProfile: NULL default profile path USERENV(534.54c) 18:14:48:531 LoadUserProfile: NULL server name USERENV(534.54c) 18:14:48:531 LoadUserProfile: User sid: S-1-5-19 USERENV(534.54c) 18:14:48:531 CSyncManager::EnterLock USERENV(534.54c) 18:14:48:531 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 18:14:48:531 CSyncManager::EnterLock: New entry created USERENV(684.a5c) 18:14:48:531 GetProfileType: Profile already loaded. USERENV(534.54c) 18:14:48:531 CHashTable::HashAdd: S-1-5-19 added in bucket 12 USERENV(534.54c) 18:14:48:531 LoadUserProfile: Wait succeeded. In critical section. USERENV(684.a5c) 18:14:48:531 GetProfileType: ProfileFlags is 0 USERENV(534.54c) 18:14:48:531 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.54c) 18:14:48:531 Profile Ref Count is 2 USERENV(534.54c) 18:14:48:531 LoadUserProfile: Leaving critical Section. USERENV(534.54c) 18:14:48:531 CSyncManager::LeaveLock USERENV(534.54c) 18:14:48:531 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 18:14:48:531 CHashTable::HashDelete: S-1-5-19 deleted USERENV(534.54c) 18:14:48:531 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 18:14:48:531 LoadUserProfile: Impersonated user: 0000000c, 00000844 USERENV(534.54c) 18:14:48:531 LoadUserProfile: Reverted to user: 00000000 USERENV(534.54c) 18:14:48:531 LoadUserProfile: Reverted back to user <00000000> USERENV(534.54c) 18:14:48:531 LoadUserProfile: Leaving with a value of 1. USERENV(534.54c) 18:14:48:531 ========================================================= USERENV(534.54c) 18:14:48:531 LoadUserProfileI: returning 0 USERENV(560.648) 18:14:48:531 LoadUserProfile: Running as self USERENV(560.648) 18:14:48:531 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(560.648) 18:14:48:531 LoadUserProfile: Returning success. Final Information follows: USERENV(560.648) 18:14:48:531 lpProfileInfo->UserName = USERENV(560.648) 18:14:48:531 lpProfileInfo->lpProfilePath = <> USERENV(560.648) 18:14:48:531 lpProfileInfo->dwFlags = 0x9 USERENV(534.654) 18:14:48:546 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:48:546 ReleaseClientContext: Releasing context USERENV(534.654) 18:14:48:546 ReleaseClientContext_s: Releasing context USERENV(534.654) 18:14:48:546 MIDL_user_free enter USERENV(560.648) 18:14:48:546 ReleaseInterface: Releasing rpc binding handle USERENV(560.648) 18:14:48:546 LoadUserProfile: Returning TRUE. hProfile = <0x1bc> USERENV(560.648) 18:14:48:546 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(684.a58) 18:14:48:546 GetProfileType: Profile already loaded. USERENV(684.a58) 18:14:48:562 GetProfileType: ProfileFlags is 0 USERENV(510.518) 18:14:48:578 LoadUserProfile: Yes, we can impersonate the user. Running as self USERENV(510.518) 18:14:48:578 ========================================================= USERENV(510.518) 18:14:48:578 LoadUserProfile: Entering, hToken = <0x188>, lpProfileInfo = 0x12fc08 USERENV(510.518) 18:14:48:578 LoadUserProfile: lpProfileInfo->dwFlags = <0x1> USERENV(510.518) 18:14:48:578 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(510.518) 18:14:48:578 LoadUserProfile: NULL central profile path USERENV(510.518) 18:14:48:578 LoadUserProfile: NULL default profile path USERENV(510.518) 18:14:48:578 LoadUserProfile: NULL server name USERENV(510.518) 18:14:48:593 GetInterface: Returning rpc binding handle USERENV(534.54c) 18:14:48:593 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:48:593 DropClientContext: Got client token 0000000C, sid = S-1-5-18 USERENV(534.54c) 18:14:48:593 MIDL_user_allocate enter USERENV(534.54c) 18:14:48:593 DropClientContext: load profile object successfully made USERENV(534.54c) 18:14:48:593 DropClientContext: Returning 0 USERENV(510.518) 18:14:48:593 LoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.654) 18:14:48:593 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:48:593 In LoadUserProfileP USERENV(534.654) 18:14:48:593 LoadUserProfile: Running as client USERENV(534.654) 18:14:48:593 ========================================================= USERENV(534.654) 18:14:48:593 LoadUserProfile: Entering, hToken = <0x7c4>, lpProfileInfo = 0xecb9f0 USERENV(534.654) 18:14:48:593 LoadUserProfile: lpProfileInfo->dwFlags = <0x1> USERENV(534.654) 18:14:48:593 LoadUserProfile: lpProfileInfo->lpUserName = USERENV(534.654) 18:14:48:593 LoadUserProfile: NULL central profile path USERENV(534.654) 18:14:48:593 LoadUserProfile: NULL default profile path USERENV(534.654) 18:14:48:593 LoadUserProfile: NULL server name USERENV(534.654) 18:14:48:593 LoadUserProfile: User sid: S-1-5-21-4124423304-592752288-1644981653-1006 USERENV(534.654) 18:14:48:593 CSyncManager::EnterLock USERENV(534.654) 18:14:48:593 CSyncManager::EnterLock: No existing entry found USERENV(534.654) 18:14:48:593 CSyncManager::EnterLock: New entry created USERENV(534.654) 18:14:48:593 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.654) 18:14:48:593 LoadUserProfile: Wait succeeded. In critical section. USERENV(534.654) 18:14:48:609 TestIfUserProfileLoaded: Profile already loaded. USERENV(534.654) 18:14:48:609 Profile Ref Count is 2 USERENV(534.654) 18:14:48:609 LoadUserProfile: Leaving critical Section. USERENV(534.654) 18:14:48:609 CSyncManager::LeaveLock USERENV(534.654) 18:14:48:609 CSyncManager::LeaveLock: Lock released USERENV(534.654) 18:14:48:609 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.654) 18:14:48:609 CSyncManager::LeaveLock: Lock deleted USERENV(534.654) 18:14:48:609 LoadUserProfile: Impersonated user: 000007c4, 000008c0 USERENV(534.654) 18:14:48:609 LoadUserProfile: Reverted to user: 00000000 USERENV(534.654) 18:14:48:609 LoadUserProfile: Reverted back to user <00000000> USERENV(534.654) 18:14:48:609 LoadUserProfile: Leaving with a value of 1. USERENV(534.654) 18:14:48:609 ========================================================= USERENV(534.654) 18:14:48:609 LoadUserProfileI: returning 0 USERENV(510.518) 18:14:48:609 LoadUserProfile: Running as self USERENV(510.518) 18:14:48:609 LoadUserProfile: Calling LoadUserProfileI (as user) succeeded USERENV(510.518) 18:14:48:609 LoadUserProfile: Returning success. Final Information follows: USERENV(510.518) 18:14:48:609 lpProfileInfo->UserName = USERENV(510.518) 18:14:48:609 lpProfileInfo->lpProfilePath = <> USERENV(510.518) 18:14:48:609 lpProfileInfo->dwFlags = 0x1 USERENV(534.54c) 18:14:48:609 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:48:609 ReleaseClientContext: Releasing context USERENV(534.54c) 18:14:48:609 ReleaseClientContext_s: Releasing context USERENV(534.54c) 18:14:48:609 MIDL_user_free enter USERENV(510.518) 18:14:48:609 ReleaseInterface: Releasing rpc binding handle USERENV(510.518) 18:14:48:625 LoadUserProfile: Returning TRUE. hProfile = <0x19c> USERENV(510.518) 18:14:48:812 UnloadUserProfile: Entering, hProfile = <0x19c> USERENV(510.518) 18:14:48:812 GetInterface: Returning rpc binding handle USERENV(534.e60) 18:14:48:812 IProfileSecurityCallBack: client authenticated. USERENV(534.e60) 18:14:48:812 DropClientContext: Got client token 00000844, sid = S-1-5-18 USERENV(534.e60) 18:14:48:812 MIDL_user_allocate enter USERENV(534.e60) 18:14:48:812 DropClientContext: load profile object successfully made USERENV(534.e60) 18:14:48:812 DropClientContext: Returning 0 USERENV(510.518) 18:14:48:812 UnLoadUserProfile: Calling DropClientToken (as self) succeeded USERENV(534.54c) 18:14:48:828 IProfileSecurityCallBack: client authenticated. USERENV(534.54c) 18:14:48:843 UnloadUserProfileP: Entering, hProfile = <0x848> USERENV(534.54c) 18:14:48:843 UnloadUserProfileP: ImpersonateUser <00000844>, old token is <00000000> USERENV(534.54c) 18:14:48:843 GetExclusionListFromRegistry: Policy list is empty, returning user list = USERENV(534.54c) 18:14:48:843 CSyncManager::EnterLock USERENV(534.54c) 18:14:48:843 CSyncManager::EnterLock: No existing entry found USERENV(534.54c) 18:14:48:843 CSyncManager::EnterLock: New entry created USERENV(534.54c) 18:14:48:843 CHashTable::HashAdd: S-1-5-21-4124423304-592752288-1644981653-1006 added in bucket 12 USERENV(534.54c) 18:14:48:859 UnloadUserProfileP: Wait succeeded. In critical section. USERENV(534.54c) 18:14:49:187 UnloadUserProfileP: Didn't unload user profile, Ref Count is 1 USERENV(534.54c) 18:14:49:187 UnloadUserProfileP: Reverted back to user <00000000> USERENV(534.54c) 18:14:49:187 CSyncManager::LeaveLock USERENV(534.54c) 18:14:49:187 CSyncManager::LeaveLock: Lock released USERENV(534.54c) 18:14:49:187 CHashTable::HashDelete: S-1-5-21-4124423304-592752288-1644981653-1006 deleted USERENV(534.54c) 18:14:49:187 CSyncManager::LeaveLock: Lock deleted USERENV(534.54c) 18:14:49:187 UnloadUserProfileP: Leave critical section. USERENV(534.54c) 18:14:49:187 UnloadUserProfileP: Leaving with a return value of 1 USERENV(534.54c) 18:14:49:187 UnloadUserProfileI: returning 0 USERENV(510.518) 18:14:49:187 UnloadUserProfile: Calling UnloadUserProfileI succeeded USERENV(534.654) 18:14:49:187 IProfileSecurityCallBack: client authenticated. USERENV(534.654) 18:14:49:187 ReleaseClientContext: Releasing context USERENV(534.654) 18:14:49:187 ReleaseClientContext_s: Releasing context USERENV(534.654) 18:14:49:187 MIDL_user_free enter USERENV(510.518) 18:14:49:187 ReleaseInterface: Releasing rpc binding handle USERENV(510.518) 18:14:49:187 UnloadUserProfile: returning 1 USERENV(e64.e68) 18:14:49:250 LibMain: Process Name: C:\WINDOWS\System32\alg.exe USERENV(684.dc4) 18:14:49:843 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(7d0.890) 18:14:49:859 ImpersonateUser: Failed to impersonate user with 5. USERENV(7d0.890) 18:14:49:859 GetUserNameAndDomain Failed to impersonate user USERENV(7d0.890) 18:14:49:859 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(e80.e90) 18:14:50:078 LibMain: Process Name: c:\PROGRA~1\mcafee.com\agent\mcagent.exe USERENV(e80.e90) 18:14:50:078 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(684.dc4) 18:14:57:906 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(684.bc) 18:15:00:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(684.d8c) 18:15:03:156 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(3dc.708) 18:15:07:031 LibMain: Process Name: C:\WINDOWS\system32\msfeedssync.exe USERENV(3dc.da0) 18:15:07:250 ImpersonateUser: Failed to impersonate user with 5. USERENV(3dc.da0) 18:15:07:250 GetUserNameAndDomain Failed to impersonate user USERENV(3dc.da0) 18:15:07:250 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(3dc.da0) 18:15:07:250 ImpersonateUser: Failed to impersonate user with 5. USERENV(3dc.da0) 18:15:07:250 GetUserNameAndDomain Failed to impersonate user USERENV(3dc.da0) 18:15:07:265 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(3dc.da0) 18:15:07:265 ImpersonateUser: Failed to impersonate user with 5. USERENV(3dc.da0) 18:15:07:265 GetUserNameAndDomain Failed to impersonate user USERENV(3dc.da0) 18:15:07:265 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(ecc.ed4) 18:15:18:250 LibMain: Process Name: C:\WINDOWS\system32\wuauclt.exe USERENV(684.d8c) 18:15:25:031 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(4e8.6cc) 18:15:28:921 LibMain: Process Name: C:\Program Files\McAfee\MSK\MskSrver.exe USERENV(318.244) 18:16:23:437 LibMain: Process Name: C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe USERENV(318.244) 18:16:23:437 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(318.374) 18:16:24:015 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(318.374) 18:16:24:046 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(32c.ec8) 18:16:26:078 LibMain: Process Name: c:\program files\common files\mcafee\mna\mcnasvc.exe USERENV(32c.ec8) 18:16:26:078 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(32c.ec8) 18:16:26:109 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(32c.ec8) 18:16:26:109 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(aa4.d0) 18:16:28:921 LibMain: Process Name: C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe USERENV(aa4.c4) 18:16:29:062 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(628.b4c) 18:16:40:156 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(d4.d88) 18:18:00:421 LibMain: Process Name: C:\WINDOWS\system32\taskmgr.exe USERENV(d4.d88) 18:18:20:671 GetProfileType: Profile already loaded. USERENV(d4.d88) 18:18:20:671 GetProfileType: ProfileFlags is 0 USERENV(9f8.fe8) 18:18:22:531 LibMain: Process Name: C:\WINDOWS\explorer.exe USERENV(9f8.ffc) 18:18:22:921 GetProfileType: Profile already loaded. USERENV(9f8.ffc) 18:18:22:921 GetProfileType: ProfileFlags is 0 USERENV(9f8.ffc) 18:18:23:062 GetProfileType: Profile already loaded. USERENV(9f8.ffc) 18:18:23:062 GetProfileType: ProfileFlags is 0 USERENV(9f8.ffc) 18:18:23:156 GetProfileType: Profile already loaded. USERENV(9f8.ffc) 18:18:23:156 GetProfileType: ProfileFlags is 0 USERENV(684.da0) 18:18:27:578 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(4e4.828) 18:18:27:875 LibMain: Process Name: C:\WINDOWS\system32\RUNDLL32.EXE USERENV(684.da0) 18:18:31:531 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(8c8.fa0) 18:18:33:265 LibMain: Process Name: C:\WINDOWS\system32\imapi.exe USERENV(994.998) 18:18:33:312 LibMain: Process Name: \\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE USERENV(73c.df4) 18:18:38:156 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(73c.df4) 18:18:38:281 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(ce8.fb0) 18:18:41:031 LibMain: Process Name: C:\WINDOWS\system32\wbem\wmiprvse.exe USERENV(ad0.ccc) 18:18:42:437 LibMain: Process Name: C:\Program Files\Iomega\DriveIcons\deskup.exe USERENV(a54.ed0) 18:18:49:312 LibMain: Process Name: C:\WINDOWS\system32\ctfmon.exe USERENV(a54.ed0) 18:18:49:453 GetProfileType: Profile already loaded. USERENV(a54.ed0) 18:18:49:453 GetProfileType: ProfileFlags is 0 USERENV(ce4.bb0) 18:18:57:765 LibMain: Process Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe USERENV(5d8.b48) 18:19:05:578 LibMain: Process Name: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe USERENV(8c8.cc0) 18:19:16:296 LibMain: Process Name: C:\Program Files\Dell Support Center\gs_agent\dsc.exe USERENV(da4.cd4) 18:19:22:593 LibMain: Process Name: C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE USERENV(da4.cd4) 18:19:22:625 ImpersonateUser: Failed to impersonate user with 5. USERENV(da4.cd4) 18:19:22:640 GetUserNameAndDomain Failed to impersonate user USERENV(da4.cd4) 18:19:22:640 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(da4.cd4) 18:19:22:656 ImpersonateUser: Failed to impersonate user with 5. USERENV(da4.cd4) 18:19:22:656 GetUserNameAndDomain Failed to impersonate user USERENV(da4.cd4) 18:19:22:656 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(da4.cd4) 18:19:22:937 ImpersonateUser: Failed to impersonate user with 5. USERENV(da4.cd4) 18:19:22:937 GetUserNameAndDomain Failed to impersonate user USERENV(da4.cd4) 18:19:22:937 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(cf8.a98) 18:19:24:609 LibMain: Process Name: C:\PROGRA~1\McAfee\MSK\MskAgent.exe USERENV(404.5c4) 18:19:34:843 LibMain: Process Name: C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN USERENV(848.1360) 18:19:49:171 LibMain: Process Name: C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe USERENV(848.1360) 18:19:49:171 ImpersonateUser: Failed to impersonate user with 5. USERENV(848.1360) 18:19:49:171 GetUserNameAndDomain Failed to impersonate user USERENV(848.1360) 18:19:49:171 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(848.1360) 18:19:49:187 ImpersonateUser: Failed to impersonate user with 5. USERENV(848.1360) 18:19:49:187 GetUserNameAndDomain Failed to impersonate user USERENV(848.1360) 18:19:49:187 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(848.1360) 18:19:49:203 ImpersonateUser: Failed to impersonate user with 5. USERENV(848.1360) 18:19:49:203 GetUserNameAndDomain Failed to impersonate user USERENV(848.1360) 18:19:49:218 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(1284.130c) 18:20:43:328 LibMain: Process Name: C:\Program Files\Internet Explorer\iexplore.exe USERENV(1284.130c) 18:20:43:343 GetProfileType: Profile already loaded. USERENV(1284.130c) 18:20:43:343 GetProfileType: ProfileFlags is 0 USERENV(1284.1300) 18:20:43:531 ImpersonateUser: Failed to impersonate user with 5. USERENV(1284.1300) 18:20:43:531 GetUserNameAndDomain Failed to impersonate user USERENV(1284.1300) 18:20:43:531 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(1284.1300) 18:20:43:578 ImpersonateUser: Failed to impersonate user with 5. USERENV(1284.1300) 18:20:43:578 GetUserNameAndDomain Failed to impersonate user USERENV(1284.1300) 18:20:43:578 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d4) 18:20:46:453 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5d4) 18:20:46:453 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5d4) 18:20:46:453 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d4) 18:20:46:531 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5d4) 18:20:46:531 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5d4) 18:20:46:531 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(8c8.cc0) 18:20:46:843 GetProfileType: Profile already loaded. USERENV(8c8.cc0) 18:20:46:843 GetProfileType: ProfileFlags is 0 USERENV(56c.5d4) 18:20:47:250 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5d4) 18:20:47:250 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5d4) 18:20:47:250 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.5d4) 18:20:47:281 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.5d4) 18:20:47:281 GetUserNameAndDomain Failed to impersonate user USERENV(56c.5d4) 18:20:47:281 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.754) 18:20:47:375 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.754) 18:20:47:375 GetUserNameAndDomain Failed to impersonate user USERENV(56c.754) 18:20:47:375 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(56c.754) 18:20:47:406 ImpersonateUser: Failed to impersonate user with 5. USERENV(56c.754) 18:20:47:406 GetUserNameAndDomain Failed to impersonate user USERENV(56c.754) 18:20:47:406 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(17b0.17b4) 18:23:14:828 LibMain: Process Name: C:\WINDOWS\system32\NOTEPAD.EXE USERENV(8c0.8c4) 18:23:28:578 LibMain: Process Name: C:\Program Files\Java\jre6\bin\jusched.exe USERENV(8c0.8c4) 18:23:28:578 ImpersonateUser: Failed to impersonate user with 5. USERENV(8c0.8c4) 18:23:28:578 GetUserNameAndDomain Failed to impersonate user USERENV(8c0.8c4) 18:23:28:578 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(8c0.8c4) 18:23:28:593 ImpersonateUser: Failed to impersonate user with 5. USERENV(8c0.8c4) 18:23:28:593 GetUserNameAndDomain Failed to impersonate user USERENV(8c0.8c4) 18:23:28:593 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(8c0.8c4) 18:23:28:625 ImpersonateUser: Failed to impersonate user with 5. USERENV(8c0.8c4) 18:23:28:625 GetUserNameAndDomain Failed to impersonate user USERENV(8c0.8c4) 18:23:28:625 GetUserDNSDomainName: Computer is running standalone. No DNS domain name available. USERENV(152c.1530) 18:24:01:468 LibMain: Process Name: C:\WINDOWS\system32\NOTEPAD.EXE USERENV(1708.170c) 18:24:14:390 LibMain: Process Name: C:\WINDOWS\system32\NOTEPAD.EXE -mm
Mark, I have been looking at you logs the last 7 hours. Regrettably, I do not see anything that may be causing these explorer issues. Here's what we shall be attempting to do.

We will be using Windows' System Restore to take us back to a time before your first ComboFix run.
Click on the Start button & navigate to this location :

Programs > Accessories > System Tools > System Restore

When the system restore applet launches, select "Restore My Computer to an earlier time"
Then click the 'Next' button. The next windows shows a calender of sorts. Look for entries with bolded dates
ComboFix on it's first run created a restore point at approximately this time - 2008-12-11 22:12:09.
We shall need to restore to that time OR a time earlier than that.

Kindly take note that this may restore your previous infection. We shall need to address that later
Please let us know how it goes.
Open NOTEPAD.exe and copy/paste the text in the quotebox below into it:

@echo off
swreg acl hklm\system\controlset003 /reset
swreg delete hklm\system\controlset003
swreg add hklm\system\setup /v cmdline /t reg_multi_sz /d "c:\windows\system32\oobe\msoobe.exe /update"
swreg add "hklm\software\microsoft\windows nt\currentversion\winlogon" /v userenvdebuglevel /t reg_dword /d 0
del %0

Save this as fix.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Double click on fix.bat & allow it to run


——-


After doing that, delete your existing copy of ComboFix.
Download an updated copy from here > http://www.forospyware.com/sUBs/ComboFix.exe

Run this copy of ComboFix from safe mode.
If it reboots the machine, make sure it returns to safe mode to complete the run
Then show me the log it produces.
Also let me know if explorer still refuses to load

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI