Here you go
DaveDoug
Edit:----------------^
This I hope works out better then the last time, still have that hard drive ready to plug in as a slave. See
here for details.
SYSTEM SEEMS TO BE RUNNING OK TO DATE, THOUGH STOP SCREENS HAPPEN FOR A REASON, RIGHT!
System Information report written at: 02/11/09 12:39:14
System Name: LEO
[Problem Devices]
Device PNP Device ID Error Code
~~~ No Problem Devices ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
These events start when I had to reinstall Windows OS XP Home Edition SP2, Now Updated to SP3.
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6009
Date:
29/11/2008
Time: 3:21:15 AM
User: N/A
Computer: MACHINENAME
Description:
Microsoft ® Windows ® 5.01. 2600 Service Pack 2 Uniprocessor Free.
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6005
Date: 29/11/2008
Time: 3:21:15 AM
User: N/A
Computer: MACHINENAME
Description:
The Event log service was started.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
These are the Events leading up to the 1st STOP screen message stating: IRQL_NOT_LESS_OR_EQUAL 0x00000
(This Event has regularly continued to appear up to this date)
Event Type: Warning
Event Source: W32Time
Event Category: None
Event ID: 36
Date: 8/02/2009
Time: 12:35:33 AM
User: N/A
Computer: LEO
Description:
The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp.
The system clock is unsynchronized.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 2:49:02 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The Universal Plug and Play Device Host service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 2:49:02 PM
User: N/A
Computer: LEO
Description:
The Universal Plug and Play Device Host service entered the running state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 2:53:51 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 2:53:51 PM
User: N/A
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service entered the running state.
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 8/02/2009
Time: 3:04:56 PM
User: N/A
Computer: LEO
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Data:
0000: 00 00 00 00 01 00 54 00
0008: 00 00 00 00 82 10 00 80
0010: 01 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Warning
Event Source: AvgTdiX
Event Category: None
Event ID: 54
Date: 8/02/2009
Time: 3:12:16 PM
User: N/A
Computer: LEO
Description:
The description for Event ID ( 54 ) in Source ( AvgTdiX ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 58 00
0008: 00 00 00 00 36 00 04 80
0010: 00 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Warning
Event Source: AvgTdiX
Event Category: None
Event ID: 54
Date: 8/02/2009
Time: 3:12:16 PM
User: N/A
Computer: LEO
Description:
The description for Event ID ( 54 ) in Source ( AvgTdiX ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 58 00
0008: 00 00 00 00 36 00 04 80
0010: 00 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
(This same Event repeats several times until the following Event)
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6009
Date: 8/02/2009
Time: 3:21:23 PM
User: N/A
Computer: LEO
Description:
Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free.
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6005
Date: 8/02/2009
Time: 3:21:23 PM
User: N/A
Computer: LEO
Description:
The Event log service was started.
Event Type: Information
Event Source: Save Dump
Event Category: None
Event ID: 1001
Date: 8/02/2009
Time: 3:21:25 PM
User: N/A
Computer: LEO
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x1000000a (0x000000e8, 0x00000002, 0x00000001, 0x806e6a16). A dump was saved in: C:\WINDOWS\Minidump\Mini020809-01.dmp.
I have tried to access this "C:\WINDOWS\Minidump\Mini020809-01.dmp" with a result of " Windows cannot open this file: To open this file, Windows needs to know what program created it.Windows can go online to look it up automatically, or you can manually select from a list of programs on your computer.
(At this point I cancelled the request to open, until further advice.)
There are 2 similar files in the Minidump Folder,Mini020809-02.dmp and Mini020809-03.dmp.
The following Events will show similar Events leading up to them being created.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:22:15 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:22:15 PM
User: N/A
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service entered the running state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:22:15 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The SSDP Discovery Service service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:22:19 PM
User: N/A
Computer: LEO
Description:
The SSDP Discovery Service service entered the running state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:22:19 PM
User: LEO\Owner
Computer: LEO
Description:
The Remote Access Connection Manager service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:22:21 PM
User: N/A
Computer: LEO
Description:
The Remote Access Connection Manager service entered the running state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:22:25 PM
User: N/A
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service entered the stopped state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:22:37 PM
User: N/A
Computer: LEO
Description:
The Google Software Updater service entered the stopped state.
Event Type: Error
Event Source: System Error
Event Category: (102)
Event ID: 1003
Date: 8/02/2009
Time: 3:23:13 PM
User: N/A
Computer: LEO
Description:
Error code 1000000a, parameter1 000000e8, parameter2 00000002, parameter3 00000001, parameter4 806e6a16.
Data:
0000: 53 79 73 74 65 6d 20 45 System E
0008: 72 72 6f 72 20 20 45 72 rror Er
0010: 72 6f 72 20 63 6f 64 65 ror code
0018: 20 31 30 30 30 30 30 30 1000000
0020: 61 20 20 50 61 72 61 6d a Param
0028: 65 74 65 72 73 20 30 30 eters 00
0030: 30 30 30 30 65 38 2c 20 0000e8,
0038: 30 30 30 30 30 30 30 32 00000002
0040: 2c 20 30 30 30 30 30 30 , 000000
0048: 30 31 2c 20 38 30 36 65 01, 806e
0050: 36 61 31 36 6a16
(No user action is required.)--->
http://go.microsoft....link/events.asp.
(Possible Variant of Sdbot Virus)??? requires more research!(On my part)
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:37:07 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The Universal Plug and Play Device Host service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:37:07 PM
User: N/A
Computer: LEO
Description:
The Universal Plug and Play Device Host service entered the running state.
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 8/02/2009
Time: 3:38:12 PM
User: N/A
Computer: LEO
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Data:
0000: 00 00 00 00 01 00 54 00
0008: 00 00 00 00 82 10 00 80
0010: 01 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:38:30 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:38:30 PM
User: N/A
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service entered the running state.
Event Type: Warning
Event Source: AvgTdiX
Event Category: None
Event ID: 54
Date: 8/02/2009
Time: 3:46:41 PM
User: N/A
Computer: LEO
Description:
The description for Event ID ( 54 ) in Source ( AvgTdiX ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 58 00
0008: 00 00 00 00 36 00 04 80
0010: 00 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Warning
Event Source: AvgTdiX
Event Category: None
Event ID: 54
Date: 8/02/2009
Time: 3:46:41 PM
User: N/A
Computer: LEO
Description:
The description for Event ID ( 54 ) in Source ( AvgTdiX ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 58 00
0008: 00 00 00 00 36 00 04 80
0010: 00 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6009
Date: 8/02/2009
Time: 3:49:09 PM
User: N/A
Computer: LEO
Description:
Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free.
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6005
Date: 8/02/2009
Time: 3:49:09 PM
User: N/A
Computer: LEO
Description:
The Event log service was started.
Event Type: Information
Event Source: Save Dump
Event Category: None
Event ID: 1001
Date: 8/02/2009
Time: 3:49:10 PM
User: N/A
Computer: LEO
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x1000000a (0x000000e8, 0x00000002, 0x00000001, 0x806e6a16). A dump was saved in: C:\WINDOWS\Minidump\Mini020809-02.dmp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 3:49:38 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The Network Location Awareness (NLA) service was successfully sent a start control.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:50:17 PM
User: N/A
Computer: LEO
Description:
The IMAPI CD-Burning COM Service service entered the stopped state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:50:21 PM
User: N/A
Computer: LEO
Description:
The Remote Access Connection Manager service entered the running state.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 3:50:23 PM
User: N/A
Computer: LEO
Description:
The Google Software Updater service entered the stopped state.
Event Type: Error
Event Source: System Error
Event Category: (102)
Event ID: 1003
Date: 8/02/2009
Time: 3:50:59 PM
User: N/A
Computer: LEO
Description:
Error code 1000000a, parameter1 000000e8, parameter2 00000002, parameter3 00000001, parameter4 806e6a16.
Data:
0000: 53 79 73 74 65 6d 20 45 System E
0008: 72 72 6f 72 20 20 45 72 rror Er
0010: 72 6f 72 20 63 6f 64 65 ror code
0018: 20 31 30 30 30 30 30 30 1000000
0020: 61 20 20 50 61 72 61 6d a Param
0028: 65 74 65 72 73 20 30 30 eters 00
0030: 30 30 30 30 65 38 2c 20 0000e8,
0038: 30 30 30 30 30 30 30 32 00000002
0040: 2c 20 30 30 30 30 30 30 , 000000
0048: 30 31 2c 20 38 30 36 65 01, 806e
0050: 36 61 31 36 6a16
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 4:04:43 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The Universal Plug and Play Device Host service was successfully sent a start control.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 8/02/2009
Time: 4:04:43 PM
User: N/A
Computer: LEO
Description:
The Universal Plug and Play Device Host service entered the running state.
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 8/02/2009
Time: 4:05:23 PM
User: N/A
Computer: LEO
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Data:
0000: 00 00 00 00 01 00 54 00
0008: 00 00 00 00 82 10 00 80
0010: 01 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Warning
Event Source: AvgTdiX
Event Category: None
Event ID: 54
Date: 8/02/2009
Time: 4:13:51 PM
User: N/A
Computer: LEO
Description:
The description for Event ID ( 54 ) in Source ( AvgTdiX ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: .
Data:
0000: 00 00 00 00 01 00 58 00
0008: 00 00 00 00 36 00 04 80
0010: 00 00 00 00 00 00 00 00
0018: 00 00 00 00 00 00 00 00
0020: 00 00 00 00 00 00 00 00
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6009
Date: 8/02/2009
Time: 6:15:58 PM
User: N/A
Computer: LEO
Description:
Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free.
Event Type: Information
Event Source: EventLog
Event Category: None
Event ID: 6005
Date: 8/02/2009
Time: 6:15:58 PM
User: N/A
Computer: LEO
Description:
The Event log service was started.
Event Type: Information
Event Source: Save Dump
Event Category: None
Event ID: 1001
Date: 8/02/2009
Time: 6:15:59 PM
User: N/A
Computer: LEO
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x1000000a (0x000000e8, 0x00000002, 0x00000001, 0x806e6a16). A dump was saved in: C:\WINDOWS\Minidump\Mini020809-03.dmp.
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 8/02/2009
Time: 6:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: LEO
Description:
The Fast User Switching Compatibility service was successfully sent a start control.
A few attempts at a system restore failed until the following event.(This happened to be the only restore point left to try)
Event Type: Information
Event Source: SRService
Event Category: None
Event ID: 110
Date: 8/02/2009
Time: 7:49:10 PM
User: N/A
Computer: LEO
Description:
A restoration to "cleaned before HJT" restore point occurred successfully.
Event Type: Information
Event Source: W32Time
Event Category: None
Event ID: 35
Date: 8/02/2009
Time: 7:49:20 PM
User: N/A
Computer: LEO
Description:
The time service is now synchronizing the system time with the time source time.windows.com (ntp.m|0x1|
For more information, see Help and Support Center at
http://go.microsoft....link/events.asp.
Everything in the log from 12:10pm 11-02-09 AEST(Australian Eastern Standard Time) is without Error.(After the verifier /reset)
Hope this will help you, help me.
Many Thanks in Advance
Jkc73
Edited by Jkc73, 11 February 2009 - 10:08 AM.