mrobaer
New Member
- Joined
- Jan 4, 2014
- Messages
- 1
- Thread Author
- #1
I noticed something off when in my system tray, hardly anything that should have been running on startup was not there. I tried to run some programs and received a bad parameter error of some sorts. However, when I select the option to "run as administrator" some programs will work.
When I go into safemode, it works fine. I did a system restore twice, each to a restore point where I didn't have this issue, and the issue persisted.
If this helps at all, my problem began when I plugged an Xbox 360 controller into my PC. I suspect that's the culprit but I do not know how to undo what has been done.
Nothing in the Event Viewer stands out, but here are the entries from when this began:
There were two similar ones after that, then something that seems more serious when I rebooted:
Does anyone know what I can do?
When I go into safemode, it works fine. I did a system restore twice, each to a restore point where I didn't have this issue, and the issue persisted.
If this helps at all, my problem began when I plugged an Xbox 360 controller into my PC. I suspect that's the culprit but I do not know how to undo what has been done.
Nothing in the Event Viewer stands out, but here are the entries from when this began:
Log Name: Application
Source: Microsoft-Windows-CAPI2
Date: 1/4/2014 4:20:42 PM
Event ID: 513
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: JESUSBOX
Description:
Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
System Error:
The system cannot find the file specified.
.
Event Xml:
<Event xmlns="Link Removed">
<System>
<Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />
<EventID Qualifiers="0">513</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2014-01-04T21:20:42.563779800Z" />
<EventRecordID>23209</EventRecordID>
<Correlation />
<Execution ProcessID="1180" ThreadID="97852" />
<Channel>Application</Channel>
<Computer>JESUSBOX</Computer>
<Security />
</System>
<EventData>
<Data>
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
System Error:
The system cannot find the file specified.
</Data>
</EventData>
</Event>
There were two similar ones after that, then something that seems more serious when I rebooted:
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 1/4/2014 4:42:59 PM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: JESUSBOX
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
17 user registry handles leaked from \Registry\User\S-1-5-21-2264177528-1673522143-2424897341-1000:
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 620 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 496 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\My
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\CA
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Root
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\trust
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Event Xml:
<Event xmlns="Link Removed">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-04T21:42:59.351348000Z" />
<EventRecordID>23228</EventRecordID>
<Correlation />
<Execution ProcessID="412" ThreadID="97296" />
<Channel>Application</Channel>
<Computer>JESUSBOX</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">17 user registry handles leaked from \Registry\User\S-1-5-21-2264177528-1673522143-2424897341-1000:
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 620 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 496 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\My
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\CA
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Policies\Microsoft\SystemCertificates
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Root
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\trust
Process 1268 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2264177528-1673522143-2424897341-1000\Software\Microsoft\SystemCertificates\TrustedPeople
</Data>
</EventData>
</Event>
Does anyone know what I can do?