mrobaer

New Member
Joined
Jan 4, 2014
Messages
1
I noticed something off when in my system tray, hardly anything that should have been running on startup was not there. I tried to run some programs and received a bad parameter error of some sorts. However, when I select the option to "run as administrator" some programs will work.

When I go into safemode, it works fine. I did a system restore twice, each to a restore point where I didn't have this issue, and the issue persisted.

If this helps at all, my problem began when I plugged an Xbox 360 controller into my PC. I suspect that's the culprit but I do not know how to undo what has been done. :(

Nothing in the Event Viewer stands out, but here are the entries from when this began:

Log Name: Application
Source: Microsoft-Windows-CAPI2
Date: 1/4/2014 4:20:42 PM
Event ID: 513
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: JESUSBOX
Description:
Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.

System Error:
The system cannot find the file specified.
.
Event Xml:
<Event xmlns="Link Removed">
<System>
<Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />
<EventID Qualifiers="0">513</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2014-01-04T21:20:42.563779800Z" />
<EventRecordID>23209</EventRecordID>
<Correlation />
<Execution ProcessID="1180" ThreadID="97852" />
<Channel>Application</Channel>
<Computer>JESUSBOX</Computer>
<Security />
</System>
<EventData>
<Data>

Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.

System Error:
The system cannot find the file specified.
</Data>
</EventData>
</Event>

There were two similar ones after that, then something that seems more serious when I rebooted:

Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 1/4/2014 4:42:59 PM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: JESUSBOX
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
17 user registry handles leaked from \Registry\User\S-1-5-21-2264177528-1673522143-2424897341-1000:
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 620 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 496 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\My
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\CA
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Root
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\trust
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\TrustedPeople

Event Xml:
<Event xmlns="Link Removed">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-04T21:42:59.351348000Z" />
<EventRecordID>23228</EventRecordID>
<Correlation />
<Execution ProcessID="412" ThreadID="97296" />
<Channel>Application</Channel>
<Computer>JESUSBOX</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">17 user registry handles leaked from \Registry\User\S-1-5-21-2264177528-1673522143-2424897341-1000:
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 620 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 496 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\My
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\CA
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Root
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\trust
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\TrustedPeople
</Data>
</EventData>
</Event>

Does anyone know what I can do?
 


Solution
Hi,
looking at the above it looks like Avast has been having some issues too. Try un-installing and running MSE for the interim:
Link Removed

Also check your machine for malware using this app here:
http://www.malwarebytes.org/

Try running a system file checker scan. Find cmd prompt in the start menu and right click on it. Choose properties and run as admin. Type:
sfc /scannow
Press enter and await results.

Run Disk clean advanced. Again open a admin cmd prompt. Type:
cleanmgr/sageset:1
Press enter and you'll see the disk clean app appear but with far more check-boxes. Tick them and click ok. Now it's set up you need to run it. In an admin cmd prompt type:
cleanmgr/sagerun:1
Press enter and the app will cycle.

Afterwards...
Hi,
looking at the above it looks like Avast has been having some issues too. Try un-installing and running MSE for the interim:
Link Removed

Also check your machine for malware using this app here:
http://www.malwarebytes.org/

Try running a system file checker scan. Find cmd prompt in the start menu and right click on it. Choose properties and run as admin. Type:
sfc /scannow
Press enter and await results.

Run Disk clean advanced. Again open a admin cmd prompt. Type:
cleanmgr/sageset:1
Press enter and you'll see the disk clean app appear but with far more check-boxes. Tick them and click ok. Now it's set up you need to run it. In an admin cmd prompt type:
cleanmgr/sagerun:1
Press enter and the app will cycle.

Afterwards try using this app for general cleaning:
Link Removed

Did you install any drivers for the controller? If not go here and download the software needed:
http://support.xbox.com/en-GB/xbox-360/accessories/connect-wired-controller-computer
 


Solution
Back
Top