techlinden
asked on
Windows 7 logon issue
Hello all and thanks for any assistance you can give me.
I have a Dell Vostro 260S - Dells stock image (yeah mistake i know) running win7 pro 64bit. Â Of course I could just nuke the machine with a fresh non-dell image but that wouldn't be any fun at all. Â This machine is a person who happens to be a very difficult setup.
This person works from home through a VPN. Â I was getting reports that she would be connecting okay for days, then suddenly someone has to power cycle the machine. Â This goes on and off for days at a time (i am offsite). Â So I finally got down to her location one day to check the machine when it was locked up. Â
The machine showed the login screen (press cntrl alt delete) I do so and it takes me to her login screen, enter her password, and it brings me right back to the login screen - not an incorrect password - it just does nothing. Â Eventually you have to power cycle.
I changed the RAM in the machine. Â A few days later the problem popped up again.
So i changed the machine out (moved the harddrive over to a new machine) and the problem persists.
The company has a domain policy set for windows updates to run at 1pm. Â When i arrived back with the new machine a bit after 1pm, the screen was back to login, and exhibiting the same behavior. Â Windows updates fail with error 800B0001. Â I will mention gotomypc is also on the machine.
Below is a list of events popping up constantly. Â And the problem does not SEEM to be the hard disk. Â I've run tests with no failures. Â Of course this is my last resort. Â Thanks again all.
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. Â
 DETAIL -
 0 user registry handles leaked from \Registry\User\S-1-5-21-21 25281132-3 400958297- 2518728906 -9306:
Failed to create restore point (Process = C:\Windows\system32\rundll 32.exe /d srrstr.dll,ExecuteSchedule dSPPCreati on; Description = Scheduled Checkpoint; Error = 0x80070422).
Notifications for the volume C:\ are not active.
Context: Windows Application
Details:
      Insufficient quota to complete the requested service.  (HRESULT : 0x800705ad) (0x800705ad)
An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): '\SystemRoot\System32\Conf ig\SOFTWAR E'.
wuaueng.dll (888) SUS20ClientDataStore: An attempt to write to the file "C:\Windows\SoftwareDistri bution\Dat aStore\Dat aStore.edb " at offset 0 (0x0000000000000000) for 32768 (0x00008000) bytes failed after 0 seconds with system error 1453 (0x000005ad): "Insufficient quota to complete the requested service. ". Â The write operation will fail with error -1011 (0xfffffc0d). Â If this error persists then the file may be damaged and may need to be restored from a previous backup.
Log Name: Â Â Â Application
Source: Â Â Â Â ESENT
Date: Â Â Â Â Â 7/14/2012 9:40:38 PM
Event ID: Â Â Â 104
Task Category: General
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â LVMHTRV02.dkintl.com
Description:
wuaueng.dll (888) SUS20ClientDataStore: The database engine stopped the instance (0) with error (-1090).
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="ESENT" />
  <EventID Qualifiers="0">104</EventI D>
  <Level>2</Level>
  <Task>1</Task>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-15T01: 40:38.0000 00000Z" />
  <EventRecordID>7268</Event RecordID>
  <Channel>Application</Chan nel>
  <Computer>0002.d000000tl.c om</Comput er>
  <Security />
 </System>
 <EventData>
  <Data>wuaueng.dll</Data>
  <Data>888</Data>
  <Data>SUS20ClientDataStore : </Data>
  <Data>0</Data>
  <Data>-1090</Data>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys tem
Date: Â Â Â Â Â 7/15/2012 12:36:48 PM
Event ID: Â Â Â 4622
Task Category: Event Service
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 0000000.000000.com
Description:
The COM+ Event System could not marshal the subscriber for subscription {CEB8B221-89C5-41A8-98CE-7 9B413BF150 B}-{000000 00-0000-00 00-0000-00 0000000000 }-{0000000 0-0000-000 0-0000-000 000000000} . Â The HRESULT was 80010100.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev entSystem" Guid="{899daace-4868-4295- afcd-9eb8f b497561}" EventSourceName="EventSyst em" />
  <EventID Qualifiers="49152">4622</E ventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-15T16: 36:48.0000 00000Z" />
  <EventRecordID>7271</Event RecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan nel>
  <Computer>00000.00000.com< /Computer>
  <Security />
 </System>
 <EventData>
  <Data Name="param1">80010100</Da ta>
  <Data Name="param2">{CEB8B221-89 C5-41A8-98 CE-79B413B F150B}-{00 000000-000 0-0000-000 0-00000000 0000}-{000 00000-0000 -0000-0000 -000000000 000}</Data >
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys tem
Date: Â Â Â Â Â 7/15/2012 2:53:31 PM
Event ID: Â Â Â 4609
Task Category: Event Service
Level: Â Â Â Â Warning
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 00000.00000.com
Description:
The COM+ Event System detected a bad return code during its internal processing. Â HRESULT was 80070005 from line 586 of d:\w7rtm\com\complus\src\e vents\tier 2\eventsys tem2.cpp. Â This warning may be expected if the computer is low on resources. Â If the computer is not low on resources, and these warnings persist, it may indicate a problem in the COM+ Event System.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev entSystem" Guid="{899daace-4868-4295- afcd-9eb8f b497561}" EventSourceName="EventSyst em" />
  <EventID Qualifiers="32768">4609</E ventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-15T18: 53:31.0000 00000Z" />
  <EventRecordID>7275</Event RecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan nel>
  <Computer>000000.000000.co m</Compute r>
  <Security />
 </System>
 <EventData>
  <Data Name="param1">d:\w7rtm\com \complus\s rc\events\ tier2\even tsystem2.c pp</Data>
  <Data Name="param2">586</Data>
  <Data Name="param3">80070005</Da ta>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys tem
Date: Â Â Â Â Â 7/15/2012 3:55:51 PM
Event ID: Â Â Â 4622
Task Category: Event Service
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000.00000.com
Description:
The COM+ Event System could not marshal the subscriber for subscription {CEB8B221-89C5-41A8-98CE-7 9B413BF150 B}-{000000 00-0000-00 00-0000-00 0000000000 }-{0000000 0-0000-000 0-0000-000 000000000} . Â The HRESULT was 800700a4.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev entSystem" Guid="{899daace-4868-4295- afcd-9eb8f b497561}" EventSourceName="EventSyst em" />
  <EventID Qualifiers="49152">4622</E ventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-15T19: 55:51.0000 00000Z" />
  <EventRecordID>7276</Event RecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan nel>
  <Computer>000000000.com</C omputer>
  <Security />
 </System>
 <EventData>
  <Data Name="param1">800700a4</Da ta>
  <Data Name="param2">{CEB8B221-89 C5-41A8-98 CE-79B413B F150B}-{00 000000-000 0-0000-000 0-00000000 0000}-{000 00000-0000 -0000-0000 -000000000 000}</Data >
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â Microsoft-Windows-Distribu tedCOM
Date: Â Â Â Â Â 7/16/2012 5:09:06 AM
Event ID: Â Â Â 10000
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000.com
Description:
Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4 EFFB68962F 2}. The error:
"1450"
Happened while starting this command:
C:\Windows\system32\wbem\w miprvse.ex e -secured -Embedding
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Di stributedC OM" Guid="{1B562E86-B7AA-4131- BADC-B6F3A 001407E}" EventSourceName="DCOM" />
  <EventID Qualifiers="49152">10000</ EventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-16T09: 09:06.0000 00000Z" />
  <EventRecordID>55909</Even tRecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>System</Channel>
  <Computer>0000000V.com</Co mputer>
  <Security />
 </System>
 <EventData>
  <Data Name="param1">C:\Windows\s ystem32\wb em\wmiprvs e.exe -secured -Embedding</Data>
  <Data Name="param2">1450</Data>
  <Data Name="param3">{1F87137D-0E 7C-44D5-8C 73-4EFFB68 962F2}</Da ta>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-WMI
Date: Â Â Â Â Â 7/16/2012 9:23:21 AM
Event ID: Â Â Â 10
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 00000.com
Description:
Event filter with query "SELECT * FROM __InstanceModificationEven t WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercent age >Â 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-WM I" Guid="{1edeee53-0afe-4609- b846-d8c0b 2075b1f}" EventSourceName="WinMgmt" />
  <EventID Qualifiers="49152">10</Eve ntID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-16T13: 23:21.0000 00000Z" />
  <EventRecordID>7299</Event RecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan nel>
  <Computer>0000000.com</Com puter>
  <Security />
 </System>
 <EventData>
  <Data>//./root/CIMV2</Data >
  <Data>SELECT * FROM __InstanceModificationEven t WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercent age > 99</Data>
  <Data>0x80041003</Data>
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â Microsoft-Windows-WindowsU pdateClien t
Date: Â Â Â Â Â 7/16/2012 9:25:38 AM
Event ID: Â Â Â 16
Task Category: Automatic Updates
Level: Â Â Â Â Warning
Keywords: Â Â Â Connection
User: Â Â Â Â Â SYSTEM
Computer: Â Â Â 00000.com
Description:
Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Wi ndowsUpdat eClient" Guid="{945A8954-C147-4ACD- 923F-40C45 405A658}" />
  <EventID>16</EventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>2</Task>
  <Opcode>11</Opcode>
  <Keywords>0x80000000000000 01</Keywor ds>
  <TimeCreated SystemTime="2012-07-16T13: 25:38.8996 98600Z" />
  <EventRecordID>56029</Even tRecordID>
  <Correlation />
  <Execution ProcessID="920" ThreadID="5736" />
  <Channel>System</Channel>
  <Computer>0000.com</Comput er>
  <Security UserID="S-1-5-18" />
 </System>
 <EventData>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â System Restore
Date: Â Â Â Â Â 7/16/2012 1:43:16 PM
Event ID: Â Â Â 8193
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000000.com
Description:
Failed to create restore point (Process = C:\Windows\system32\rundll 32.exe /d srrstr.dll,ExecuteSchedule dSPPCreati on; Description = Scheduled Checkpoint; Error = 0x80070422).
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="System Restore" />
  <EventID Qualifiers="0">8193</Event ID>
  <Level>2</Level>
  <Task>0</Task>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-16T17: 43:16.0000 00000Z" />
  <EventRecordID>7330</Event RecordID>
  <Channel>Application</Chan nel>
  <Computer>0000000.com</Com puter>
  <Security />
 </System>
 <EventData>
  <Data>C:\Windows\system32\ rundll32.e xe /d srrstr.dll,ExecuteSchedule dSPPCreati on</Data>
  <Data>Scheduled Checkpoint</Data>
  <Data>0x80070422</Data>
  <Binary>220407809D01000087 0100009501 000022CE28 677C6DDA79 E28C1C0000 0000000000 0000</Bina ry>
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â RTL8167
Date: Â Â Â Â Â 7/16/2012 11:19:41 AM
Event ID: Â Â Â 1
Task Category: None
Level: Â Â Â Â Warning
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â 00000.com
Description:
Realtek PCIe GBE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="RTL8167" />
  <EventID Qualifiers="32768">1</Even tID>
  <Level>3</Level>
  <Task>0</Task>
  <Keywords>0x80000000000000 </Keywords >
  <TimeCreated SystemTime="2012-07-16T15: 19:41.9321 95500Z" />
  <EventRecordID>56076</Even tRecordID>
  <Channel>System</Channel>
  <Computer>00000000.com</Co mputer>
  <Security />
 </System>
 <EventData>
  <Data>\Device\NDMP14</Data >
  <Data>Realtek PCIe GBE Family Controller</Data>
  <Binary>000000000200300000 0000000100 0080000000 0000000000 0000000000 0000000000 0000000000 00</Binary >
 </EventData>
</Event>
I have a Dell Vostro 260S - Dells stock image (yeah mistake i know) running win7 pro 64bit. Â Of course I could just nuke the machine with a fresh non-dell image but that wouldn't be any fun at all. Â This machine is a person who happens to be a very difficult setup.
This person works from home through a VPN. Â I was getting reports that she would be connecting okay for days, then suddenly someone has to power cycle the machine. Â This goes on and off for days at a time (i am offsite). Â So I finally got down to her location one day to check the machine when it was locked up. Â
The machine showed the login screen (press cntrl alt delete) I do so and it takes me to her login screen, enter her password, and it brings me right back to the login screen - not an incorrect password - it just does nothing. Â Eventually you have to power cycle.
I changed the RAM in the machine. Â A few days later the problem popped up again.
So i changed the machine out (moved the harddrive over to a new machine) and the problem persists.
The company has a domain policy set for windows updates to run at 1pm. Â When i arrived back with the new machine a bit after 1pm, the screen was back to login, and exhibiting the same behavior. Â Windows updates fail with error 800B0001. Â I will mention gotomypc is also on the machine.
Below is a list of events popping up constantly. Â And the problem does not SEEM to be the hard disk. Â I've run tests with no failures. Â Of course this is my last resort. Â Thanks again all.
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. Â
 DETAIL -
 0 user registry handles leaked from \Registry\User\S-1-5-21-21
Failed to create restore point (Process = C:\Windows\system32\rundll
Notifications for the volume C:\ are not active.
Context: Windows Application
Details:
      Insufficient quota to complete the requested service.  (HRESULT : 0x800705ad) (0x800705ad)
An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): '\SystemRoot\System32\Conf
wuaueng.dll (888) SUS20ClientDataStore: An attempt to write to the file "C:\Windows\SoftwareDistri
Log Name: Â Â Â Application
Source: Â Â Â Â ESENT
Date: Â Â Â Â Â 7/14/2012 9:40:38 PM
Event ID: Â Â Â 104
Task Category: General
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â LVMHTRV02.dkintl.com
Description:
wuaueng.dll (888) SUS20ClientDataStore: The database engine stopped the instance (0) with error (-1090).
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="ESENT" />
  <EventID Qualifiers="0">104</EventI
  <Level>2</Level>
  <Task>1</Task>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-15T01:
  <EventRecordID>7268</Event
  <Channel>Application</Chan
  <Computer>0002.d000000tl.c
  <Security />
 </System>
 <EventData>
  <Data>wuaueng.dll</Data>
  <Data>888</Data>
  <Data>SUS20ClientDataStore
  <Data>0</Data>
  <Data>-1090</Data>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys
Date: Â Â Â Â Â 7/15/2012 12:36:48 PM
Event ID: Â Â Â 4622
Task Category: Event Service
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 0000000.000000.com
Description:
The COM+ Event System could not marshal the subscriber for subscription {CEB8B221-89C5-41A8-98CE-7
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev
  <EventID Qualifiers="49152">4622</E
  <Version>0</Version>
  <Level>2</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-15T16:
  <EventRecordID>7271</Event
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan
  <Computer>00000.00000.com<
  <Security />
 </System>
 <EventData>
  <Data Name="param1">80010100</Da
  <Data Name="param2">{CEB8B221-89
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys
Date: Â Â Â Â Â 7/15/2012 2:53:31 PM
Event ID: Â Â Â 4609
Task Category: Event Service
Level: Â Â Â Â Warning
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 00000.00000.com
Description:
The COM+ Event System detected a bad return code during its internal processing. Â HRESULT was 80070005 from line 586 of d:\w7rtm\com\complus\src\e
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev
  <EventID Qualifiers="32768">4609</E
  <Version>0</Version>
  <Level>3</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-15T18:
  <EventRecordID>7275</Event
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan
  <Computer>000000.000000.co
  <Security />
 </System>
 <EventData>
  <Data Name="param1">d:\w7rtm\com
  <Data Name="param2">586</Data>
  <Data Name="param3">80070005</Da
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-EventSys
Date: Â Â Â Â Â 7/15/2012 3:55:51 PM
Event ID: Â Â Â 4622
Task Category: Event Service
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000.00000.com
Description:
The COM+ Event System could not marshal the subscriber for subscription {CEB8B221-89C5-41A8-98CE-7
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Ev
  <EventID Qualifiers="49152">4622</E
  <Version>0</Version>
  <Level>2</Level>
  <Task>17</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-15T19:
  <EventRecordID>7276</Event
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan
  <Computer>000000000.com</C
  <Security />
 </System>
 <EventData>
  <Data Name="param1">800700a4</Da
  <Data Name="param2">{CEB8B221-89
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â Microsoft-Windows-Distribu
Date: Â Â Â Â Â 7/16/2012 5:09:06 AM
Event ID: Â Â Â 10000
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000.com
Description:
Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4
"1450"
Happened while starting this command:
C:\Windows\system32\wbem\w
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Di
  <EventID Qualifiers="49152">10000</
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-16T09:
  <EventRecordID>55909</Even
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>System</Channel>
  <Computer>0000000V.com</Co
  <Security />
 </System>
 <EventData>
  <Data Name="param1">C:\Windows\s
  <Data Name="param2">1450</Data>
  <Data Name="param3">{1F87137D-0E
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â Microsoft-Windows-WMI
Date: Â Â Â Â Â 7/16/2012 9:23:21 AM
Event ID: Â Â Â 10
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 00000.com
Description:
Event filter with query "SELECT * FROM __InstanceModificationEven
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-WM
  <EventID Qualifiers="49152">10</Eve
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-16T13:
  <EventRecordID>7299</Event
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>Application</Chan
  <Computer>0000000.com</Com
  <Security />
 </System>
 <EventData>
  <Data>//./root/CIMV2</Data
  <Data>SELECT * FROM __InstanceModificationEven
  <Data>0x80041003</Data>
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â Microsoft-Windows-WindowsU
Date: Â Â Â Â Â 7/16/2012 9:25:38 AM
Event ID: Â Â Â 16
Task Category: Automatic Updates
Level: Â Â Â Â Warning
Keywords: Â Â Â Connection
User: Â Â Â Â Â SYSTEM
Computer: Â Â Â 00000.com
Description:
Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="Microsoft-Windows-Wi
  <EventID>16</EventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>2</Task>
  <Opcode>11</Opcode>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-16T13:
  <EventRecordID>56029</Even
  <Correlation />
  <Execution ProcessID="920" ThreadID="5736" />
  <Channel>System</Channel>
  <Computer>0000.com</Comput
  <Security UserID="S-1-5-18" />
 </System>
 <EventData>
 </EventData>
</Event>
Log Name: Â Â Â Application
Source: Â Â Â Â System Restore
Date: Â Â Â Â Â 7/16/2012 1:43:16 PM
Event ID: Â Â Â 8193
Task Category: None
Level: Â Â Â Â Error
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â Â 000000000.com
Description:
Failed to create restore point (Process = C:\Windows\system32\rundll
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="System Restore" />
  <EventID Qualifiers="0">8193</Event
  <Level>2</Level>
  <Task>0</Task>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-16T17:
  <EventRecordID>7330</Event
  <Channel>Application</Chan
  <Computer>0000000.com</Com
  <Security />
 </System>
 <EventData>
  <Data>C:\Windows\system32\
  <Data>Scheduled Checkpoint</Data>
  <Data>0x80070422</Data>
  <Binary>220407809D01000087
 </EventData>
</Event>
Log Name: Â Â Â System
Source: Â Â Â Â RTL8167
Date: Â Â Â Â Â 7/16/2012 11:19:41 AM
Event ID: Â Â Â 1
Task Category: None
Level: Â Â Â Â Warning
Keywords: Â Â Â Classic
User: Â Â Â Â Â N/A
Computer: Â Â 00000.com
Description:
Realtek PCIe GBE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
  <Provider Name="RTL8167" />
  <EventID Qualifiers="32768">1</Even
  <Level>3</Level>
  <Task>0</Task>
  <Keywords>0x80000000000000
  <TimeCreated SystemTime="2012-07-16T15:
  <EventRecordID>56076</Even
  <Channel>System</Channel>
  <Computer>00000000.com</Co
  <Security />
 </System>
 <EventData>
  <Data>\Device\NDMP14</Data
  <Data>Realtek PCIe GBE Family Controller</Data>
  <Binary>000000000200300000
 </EventData>
</Event>
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
We encountered this problem with a few Dell Vostro 260s systems, resulting in unusual system behavior including read/write errors to system files.
We managed to track the issue down to a bug in the "Wireless Keyboard Caps Lock Indicator" service resulting in exhaustion of system file handles. We removed this software via Add/Remove programs and the systems have been stable since.
The "Wireless Keyboard Caps Lock Indicator" is apparently needed to create an on-screen caps lock indicator because the wireless keyboards shipped with these systems don't have a caps-lock light. Perhaps a new version would help too but we weren't prepared to be bitten again.
We managed to track the issue down to a bug in the "Wireless Keyboard Caps Lock Indicator" service resulting in exhaustion of system file handles. We removed this software via Add/Remove programs and the systems have been stable since.
The "Wireless Keyboard Caps Lock Indicator" is apparently needed to create an on-screen caps lock indicator because the wireless keyboards shipped with these systems don't have a caps-lock light. Perhaps a new version would help too but we weren't prepared to be bitten again.
ASKER