none
On startup of WHS there is a 30 minute delay before fully functional. There are errors. RRS feed

  • Question

  • Hey everyone,

    So my WHS has been glitchy for several months now, I just haven't had time to look at it (and still don't, but here I go).

    SYMPTOMS

    The server starts up within the normal amount of time and so does the GUI, no error pop-ups. You would think all is fine. But...

    - No machines can see the WHS
    - You cannot ping it
    - If you right click "My Network Places", Properties, then right-click to disble any NIC, the status never updates (even if you refresh) to show "Disabled; however, if you go and look in Device Manager, you can see the NIC now has a red X. You can Enable/Disable from here fine.
    - No Internet: Cannot get to any web sites. When errors DO pop-up, you cannot send an error report or click the link for more info (of course, because there is no net... yet).
    - If you try to uninstall an application from Add/Remove programs, you get the "Uninstalling" window.... then a long wait (say, 30 minutes)
    - You can launch Task Manger, and do just about anything you want, including Ending Processes. You can kill Explorer, re-launch, but same issue.
    - Trying to launch some programs (such as the WHS Console), also results in a long... 30 minute wait.
    - There are more symptoms, but I think you get the picture.

    I only discovered tonight that the window is 30 minutes, almost like clockwork, before the system becomes fully functional. I THINK however that the server is not fully stable though. Some of the issues I have seen over the past few months include:

    - Slow connects to server shares
    - Unresoponsivness from the GUI
    - Sometimes I think the WHS has restarted itself (but it was up and running when I went to use so have not researched.)

    After the 30 minute period, you get the pop-up window telling you that a driver or service failed to start. Here are some of the errors from the logs:

    (This is the comma delimited System Log) 

    5/20/2010,11:16:18 PM,Application Popup,Information,None,26,N/A,WCWHS,"Application popup: Service Control Manager  : At least one service or driver failed during system startup.  Use Event Viewer to examine the event log for details.
    "
    5/20/2010,10:44:52 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,10:44:49 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,10:44:43 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,10:44:42 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,10:44:40 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,10:44:15 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,10:44:10 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,10:44:30 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,10:44:22 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,10:44:22 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,10:44:22 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,10:44:22 PM,EventLog,Error,None,6008,N/A,WCWHS,The previous system shutdown at 10:43:06 PM on 5/20/2010 was unexpected.
    5/20/2010,10:43:06 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,10:21:47 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,10:21:44 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,10:21:39 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,10:21:38 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,10:21:37 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,10:21:11 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,10:21:06 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,10:21:26 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,10:21:18 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,10:21:18 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,10:21:18 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,10:20:02 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,10:18:06 PM,W3SVC,Error,None,1005,N/A,WCWHS,The World Wide Web Publishing Service is exiting due to an error. The data field contains the error number.
    5/20/2010,10:16:11 PM,Virtual Disk Service,Information,None,4,N/A,WCWHS,Service stopped.
    5/20/2010,10:16:11 PM,Virtual Disk Service,Error,None,17,N/A,WCWHS,VDS fails to launch provider {F96544E6-5C8D-47B9-AA6E-FD19AB278629}. Error code: 8004241B@02000012
    5/20/2010,10:16:11 PM,VDS Dynamic Provider 1.1,Error,None,1,N/A,WCWHS,The provider failed to load. Error(8004241B).
    5/20/2010,10:08:38 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,10:08:34 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,10:08:28 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,10:08:27 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,10:08:26 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,10:07:59 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,10:07:54 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,10:08:14 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,10:08:06 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,10:08:06 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,10:08:06 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,10:06:50 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,9:58:02 PM,Virtual Disk Service,Information,None,4,N/A,WCWHS,Service stopped.
    5/20/2010,9:58:02 PM,Virtual Disk Service,Error,None,17,N/A,WCWHS,VDS fails to launch provider {F96544E6-5C8D-47B9-AA6E-FD19AB278629}. Error code: 8004241B@02000012
    5/20/2010,9:58:02 PM,VDS Dynamic Provider 1.1,Error,None,1,N/A,WCWHS,The provider failed to load. Error(8004241B).
    5/20/2010,9:44:14 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,9:44:11 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,9:44:04 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:44:03 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:44:02 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,9:43:36 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,9:43:31 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,9:43:51 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,9:43:43 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:43:43 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:43:43 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,9:42:27 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,9:38:41 PM,Virtual Disk Service,Information,None,4,N/A,WCWHS,Service stopped.
    5/20/2010,9:38:41 PM,Virtual Disk Service,Error,None,17,N/A,WCWHS,VDS fails to launch provider {F96544E6-5C8D-47B9-AA6E-FD19AB278629}. Error code: 8004241B@02000012
    5/20/2010,9:38:41 PM,VDS Dynamic Provider 1.1,Error,None,1,N/A,WCWHS,The provider failed to load. Error(8004241B).
    5/20/2010,9:31:22 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,9:31:18 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,9:31:12 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:31:11 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:31:10 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,9:30:44 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,9:30:39 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,9:30:59 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,9:30:51 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:30:51 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:30:51 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,9:24:46 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,9:18:02 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,9:17:59 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,9:17:53 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:17:52 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:17:50 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,9:17:25 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,9:17:20 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,9:17:39 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,9:17:32 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:17:31 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:17:31 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,9:16:16 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,9:15:22 PM,DCOM,Error,None,10005,N/A,WCWHS,"DCOM got error ""This service cannot be started in Safe Mode "" attempting to start the service EventSystem with arguments """" in order to run the server:
    {1BE1F766-5536-11D1-B726-00C04FB926AF}"
    5/20/2010,9:15:14 PM,DCOM,Error,None,10005,N/A,WCWHS,"DCOM got error ""This service cannot be started in Safe Mode "" attempting to start the service netman with arguments """" in order to run the server:
    {BA126AE5-2166-11D1-B1D0-00805FC1270E}"
    5/20/2010,9:14:29 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:14:29 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:14:28 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:14:28 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:14:28 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,9:13:20 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,9:05:45 PM,System Error,Error,(102),1003,N/A,WCWHS,"Error code 000000d1, parameter1 00000000, parameter2 d0000007, parameter3 00000000, parameter4 b4fde766."
    5/20/2010,9:04:16 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,9:04:13 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,9:04:08 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:04:06 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:04:05 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,9:03:32 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,9:03:27 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,9:03:54 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,9:03:47 PM,Save Dump,Information,None,1001,N/A,WCWHS,"The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000d1 (0x00000000, 0xd0000007, 0x00000000, 0xb4fde766). A dump was saved in: C:\WINDOWS\MEMORY.DMP."
    5/20/2010,9:03:46 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:03:46 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:03:46 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,9:03:46 PM,EventLog,Error,None,6008,N/A,WCWHS,The previous system shutdown at 9:00:01 PM on 5/20/2010 was unexpected.
    5/20/2010,9:00:33 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,9:00:30 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,9:00:23 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,9:00:22 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,9:00:21 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,8:59:54 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,8:59:49 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,9:00:09 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,9:00:01 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,9:00:01 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,9:00:01 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,8:58:48 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,8:31:01 PM,Application Popup,Information,None,26,N/A,WCWHS,"Application popup: Service Control Manager  : At least one service or driver failed during system startup.  Use Event Viewer to examine the event log for details.
    "
    5/20/2010,7:59:27 PM,WMConnectCDS,Information,None,14204,N/A,WCWHS,Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.
    5/20/2010,7:59:24 PM,WMConnectCDS,Information,None,14202,N/A,WCWHS,Service 'WMConnectCDS' started.
    5/20/2010,7:59:18 PM,Virtual Disk Service,Information,None,3,N/A,WCWHS,Service started.
    5/20/2010,7:59:17 PM,SBCore,Information,None,1000,N/A,WCWHS,The SBCore service started successfully.
    5/20/2010,7:59:16 PM,IPSec,Information,None,4294,N/A,WCWHS,"The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer."
    5/20/2010,7:58:48 PM,Tcpip,Information,None,4201,N/A,WCWHS,"The system detected that network adapter Realtek...Adapter for Ethernet Extended Features was connected to the network, and has initiated normal operation over the network adapter."
    5/20/2010,7:58:42 PM,IPSec,Information,None,4295,N/A,WCWHS,"The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start."
    5/20/2010,7:59:04 PM,AeLookupSvc,Information,None,3,N/A,WCWHS,The Application Experience Lookup service started successfully.
    5/20/2010,7:58:56 PM,DCOM,Information,None,10026,N/A,WCWHS,The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
    5/20/2010,7:58:55 PM,EventLog,Information,None,6005,N/A,WCWHS,The Event log service was started.
    5/20/2010,7:58:55 PM,EventLog,Information,None,6009,N/A,WCWHS,Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
    5/20/2010,7:57:40 PM,EventLog,Information,None,6006,N/A,WCWHS,The Event log service was stopped.
    5/20/2010,7:56:38 PM,Application Popup,Information,None,26,N/A,WCWHS,"Application popup: Windows : Other people are logged on to this computer. Restarting Windows might cause them to lose data.

    Do you want to continue restarting?"
    5/20/2010,5:36:35 PM,Application Popup,Information,None,26,N/A,WCWHS,"Application popup: Service Control Manager  : At least one service or driver failed during system startup.  Use Event Viewer to examine the event log for details.

    (This is the comma delimited Home Server Log) 

    5/20/2010,11:40:29 PM,HomeServer,Information,Backup,277,N/A,WCWHS,Cleanup of the backup database has completed.
    5/20/2010,11:21:48 PM,HomeServer,Information,Backup,276,N/A,WCWHS,Cleanup of the backup database has begun.
    5/20/2010,11:16:41 PM,HomeServer,Information,Backup,256,N/A,WCWHS,The Client Backup Service has started.
    5/20/2010,11:16:30 PM,HomeServer,Information,QSM,512,N/A,WCWHS,Windows home storage manager service started.
    5/20/2010,10:44:49 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,10:35:02 PM,HomeServer,Error,Admin,2315,N/A,WCWHS,The Windows Home Server Console cannot open because the following file is blocking it: C:\Program Files\Windows Home Server\HomeServerConsoleTab.Media.dll.
    5/20/2010,10:21:44 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,10:19:12 PM,HomeServer,Error,Backup,267,N/A,WCWHS,Client Backup server failed at d:\wssg_src\whs_pp3\qhs\src\backup\server\service\qsminterface.cpp(112)
    5/20/2010,10:19:12 PM,HomeServer,Error,Backup,271,N/A,WCWHS,Unexpected error 0x800706ba from IQSMSvc::CreateNamedFolder: The RPC server is unavailable.
    5/20/2010,10:19:12 PM,HomeServer,Error,PersistentDriveLetter,1280,N/A,WCWHS,Persistent Drive Letter Service failed: Registering for QSM events: The remote procedure call failed.
    5/20/2010,10:08:34 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,9:59:08 PM,HomeServer,Error,Backup,267,N/A,WCWHS,Client Backup server failed at d:\wssg_src\whs_pp3\qhs\src\backup\server\service\qsminterface.cpp(112)
    5/20/2010,9:59:08 PM,HomeServer,Error,Backup,271,N/A,WCWHS,Unexpected error 0x800706ba from IQSMSvc::CreateNamedFolder: The RPC server is unavailable.
    5/20/2010,9:59:08 PM,HomeServer,Error,PersistentDriveLetter,1280,N/A,WCWHS,Persistent Drive Letter Service failed: Registering for QSM events: The remote procedure call failed.
    5/20/2010,9:44:11 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,9:41:59 PM,HomeServer,Error,Admin,2311,N/A,WCWHS,"Server backup failed.  The Windows Home Server Storage Manager service is not running.  Exception: System.Runtime.InteropServices.COMException (0x800706BA): Retrieving the COM class factory for component with CLSID {1187C69A-233B-4108-934C-E161F9862442} failed due to the following error: 800706ba.
       at Microsoft.HomeServer.Controls.ShareManager.GetQSMInstance() "
    5/20/2010,9:41:01 PM,HomeServer,Error,Admin,2311,N/A,WCWHS,"Server backup failed.  The Windows Home Server Storage Manager service is not running.  Exception: System.Runtime.InteropServices.COMException (0x800706BA): Retrieving the COM class factory for component with CLSID {1187C69A-233B-4108-934C-E161F9862442} failed due to the following error: 800706ba.
       at Microsoft.HomeServer.Controls.QSM.QSMMgr.Init() "
    5/20/2010,9:41:01 PM,HomeServer,Error,Admin,2311,N/A,WCWHS,"Server backup failed.  The Windows Home Server Storage Manager service is not running.  Exception: System.Runtime.InteropServices.COMException (0x800706BA): Retrieving the COM class factory for component with CLSID {1187C69A-233B-4108-934C-E161F9862442} failed due to the following error: 800706ba.
       at Microsoft.HomeServer.Controls.QSM.QSMMgr.Init() "
    5/20/2010,9:40:20 PM,HomeServer,Error,Backup,267,N/A,WCWHS,Client Backup server failed at d:\wssg_src\whs_pp3\qhs\src\backup\server\service\qsminterface.cpp(112)
    5/20/2010,9:40:20 PM,HomeServer,Error,Backup,271,N/A,WCWHS,Unexpected error 0x800706ba from IQSMSvc::CreateNamedFolder: The RPC server is unavailable.
    5/20/2010,9:40:20 PM,HomeServer,Error,PersistentDriveLetter,1280,N/A,WCWHS,Persistent Drive Letter Service failed: Registering for QSM events: The remote procedure call failed.
    5/20/2010,9:38:14 PM,HomeServer,Error,Admin,2315,N/A,WCWHS,The Windows Home Server Console cannot open because the following file is blocking it: C:\Program Files\Windows Home Server\HomeServerConsoleTab.Sharing.dll.
    5/20/2010,9:31:18 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,9:17:59 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,9:04:13 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,9:00:30 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,8:31:26 PM,HomeServer,Information,Backup,256,N/A,WCWHS,The Client Backup Service has started.
    5/20/2010,8:31:14 PM,HomeServer,Information,QSM,512,N/A,WCWHS,Windows home storage manager service started.
    5/20/2010,8:05:50 PM,HomeServer,Error,Admin,2315,N/A,WCWHS,The Windows Home Server Console cannot open because the following file is blocking it: C:\Program Files\Windows Home Server\HomeServerConsoleTab.Media.dll.
    5/20/2010,7:59:24 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,5:54:34 PM,HomeServer,Information,Backup,277,N/A,WCWHS,Cleanup of the backup database has completed.
    5/20/2010,5:53:17 PM,HomeServer,Information,Backup,276,N/A,WCWHS,Cleanup of the backup database has begun.
    5/20/2010,5:36:59 PM,HomeServer,Information,Backup,256,N/A,WCWHS,The Client Backup Service has started.
    5/20/2010,5:36:48 PM,HomeServer,Information,QSM,512,N/A,WCWHS,Windows home storage manager service started.
    5/20/2010,5:04:59 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,4:30:57 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,4:20:13 PM,HomeServer,Information,Backup,256,N/A,WCWHS,The Client Backup Service has started.
    5/20/2010,4:20:01 PM,HomeServer,Information,QSM,512,N/A,WCWHS,Windows home storage manager service started.
    5/20/2010,4:03:32 PM,HomeServer,Error,Admin,2315,N/A,WCWHS,The Windows Home Server Console cannot open because the following file is blocking it: C:\Program Files\Windows Home Server\HomeServerConsoleTab.Storage.dll.
    5/20/2010,3:48:15 PM,HomeServer,Information,Connection,1815,N/A,WCWHS,The Windows Home Server Transport service started successfully.
    5/20/2010,3:21:56 PM,HomeServer,Information,Backup,256,N/A,WCWHS,The Client Backup Service has started.
    5/20/2010,3:21:44 PM,HomeServer,Information,QSM,512,N/A,WCWHS,Windows home storage manager service started.

    ====> I will post the other logs too.

    Friday, May 21, 2010 7:17 AM

All replies

  • (This is the comma delimited Application Log) 

    5/20/2010,11:17:03 PM,Application Error,Error,None,1001,N/A,WCWHS,Fault bucket 272635265.
    5/20/2010,11:16:34 PM,DriveExtenderMigrator,Information,None,0,N/A,WCWHS,Drive Extender Migrator Service started successfully.
    5/20/2010,11:16:22 PM,DriveExtenderMigrator,Information,None,0,N/A,WCWHS,Drive Extender Migrator Service started successfully.
    5/20/2010,11:16:22 PM,NMIndexingService,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( NMIndexingService ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Service started.
    5/20/2010,10:46:18 PM,Application Error,Information,(100),1004,N/A,WCWHS,"Reporting queued error: faulting application vds.exe, version 5.2.3790.3959, faulting module unknown, version 0.0.0.0, fault address 0x73df75ba."
    5/20/2010,10:45:48 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,10:45:32 PM,Application Error,Information,(100),1004,N/A,WCWHS,"Reporting queued error: faulting application whsbackup.exe, version 6.0.2423.0, faulting module whsbackup.exe, version 6.0.2423.0, fault address 0x000635d7."
    5/20/2010,10:45:16 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,10:44:57 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,10:44:53 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,10:44:51 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,10:44:50 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,10:44:50 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2428) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,10:44:48 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2428) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,10:44:47 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2428) Windows: The database engine is initiating recovery steps.
    5/20/2010,10:44:47 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2428) Windows: The database engine started a new instance (0).
    5/20/2010,10:44:47 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2428) The database engine 5.02.3790.3959 started.
    5/20/2010,10:44:40 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,10:44:40 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,10:44:36 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,10:44:34 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,10:44:30 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,10:44:30 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,10:43:04 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,10:24:55 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,10:23:07 PM,Application Error,Information,(100),1004,N/A,WCWHS,"Reporting queued error: faulting application whsbackup.exe, version 6.0.2423.0, faulting module whsbackup.exe, version 6.0.2423.0, fault address 0x000635d7."
    5/20/2010,10:22:51 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,10:21:52 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,10:21:48 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,10:21:46 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,10:21:46 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2356) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,10:21:45 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,10:21:43 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2356) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,10:21:43 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2356) Windows: The database engine is initiating recovery steps.
    5/20/2010,10:21:43 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2356) Windows: The database engine started a new instance (0).
    5/20/2010,10:21:43 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2356) The database engine 5.02.3790.3959 started.
    5/20/2010,10:21:37 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,10:21:37 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,10:21:32 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,10:21:30 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,10:21:26 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,10:21:26 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,10:20:01 PM,Application Error,Error,(100),1000,N/A,WCWHS,"Faulting application vds.exe, version 5.2.3790.3959, faulting module unknown, version 0.0.0.0, fault address 0x73df75ba."
    5/20/2010,10:19:59 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,10:19:59 PM,EventSystem,Error,(50),4609,N/A,WCWHS,The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\nt\com\complus\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.
    5/20/2010,10:16:15 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BA.
    5/20/2010,10:16:15 PM,EventSystem,Warning,(54),4353,N/A,WCWHS,The COM+ Event System attempted to fire the EventObjectChange::ChangedSubscription event but received a bad return code.  HRESULT was 80040201.
    5/20/2010,10:16:15 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BE.
    5/20/2010,10:09:33 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,10:09:18 PM,Application Error,Information,(100),1004,N/A,WCWHS,"Reporting queued error: faulting application whsbackup.exe, version 6.0.2423.0, faulting module whsbackup.exe, version 6.0.2423.0, fault address 0x000635d7."
    5/20/2010,10:09:03 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,10:08:44 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,10:08:38 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,10:08:38 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2396) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,10:08:37 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,10:08:35 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,10:08:33 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2396) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,10:08:32 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2396) Windows: The database engine is initiating recovery steps.
    5/20/2010,10:08:32 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2396) Windows: The database engine started a new instance (0).
    5/20/2010,10:08:32 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2396) The database engine 5.02.3790.3959 started.
    5/20/2010,10:08:25 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,10:08:25 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,10:08:21 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,10:08:19 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,10:08:15 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,10:08:14 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,10:06:21 PM,.NET Runtime 2.0 Error Reporting,Error,None,5000,N/A,WCWHS,"EventType clr20r3, P1 homeserverconsole.exe, P2 6.0.0.0, P3 4acceb5f, P4 whscommon, P5 6.0.0.0, P6 4accead8, P7 334, P8 1b, P9 system.argumentexception, P10 NIL."
    5/20/2010,10:03:24 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,10:03:24 PM,EventSystem,Error,(50),4609,N/A,WCWHS,The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\nt\com\complus\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.
    5/20/2010,9:59:56 PM,Application Error,Error,(100),1000,N/A,WCWHS,"Faulting application whsbackup.exe, version 6.0.2423.0, faulting module whsbackup.exe, version 6.0.2423.0, fault address 0x000635d7."
    5/20/2010,9:58:06 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BA.
    5/20/2010,9:58:06 PM,EventSystem,Warning,(54),4353,N/A,WCWHS,The COM+ Event System attempted to fire the EventObjectChange::ChangedSubscription event but received a bad return code.  HRESULT was 80040201.
    5/20/2010,9:58:06 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BE.
    5/20/2010,9:45:02 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,9:44:39 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,9:44:24 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,9:44:15 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,9:44:13 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,9:44:13 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2408) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,9:44:11 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,9:44:09 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2408) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,9:44:09 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2408) Windows: The database engine is initiating recovery steps.
    5/20/2010,9:44:09 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2408) Windows: The database engine started a new instance (0).
    5/20/2010,9:44:08 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2408) The database engine 5.02.3790.3959 started.
    5/20/2010,9:44:02 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,9:44:01 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,9:43:57 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,9:43:55 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,9:43:51 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,9:43:51 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,9:42:25 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,9:42:25 PM,EventSystem,Error,(50),4609,N/A,WCWHS,The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\nt\com\complus\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.
    5/20/2010,9:42:00 PM,.NET Runtime 2.0 Error Reporting,Error,None,5000,N/A,WCWHS,"EventType clr20r3, P1 homeserverconsole.exe, P2 6.0.0.0, P3 4acceb5f, P4 whscommon, P5 6.0.0.0, P6 4accead8, P7 334, P8 1b, P9 system.argumentexception, P10 NIL."
    5/20/2010,9:41:24 PM,EventSystem,Error,(50),4609,N/A,WCWHS,The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\nt\com\complus\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.
    5/20/2010,9:41:03 PM,.NET Runtime 2.0 Error Reporting,Error,None,5000,N/A,WCWHS,"EventType clr20r3, P1 homeserverconsole.exe, P2 6.0.0.0, P3 4acceb5f, P4 whscommon, P5 6.0.0.0, P6 4accead8, P7 334, P8 1b, P9 system.argumentexception, P10 NIL."
    5/20/2010,9:38:45 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BA.
    5/20/2010,9:38:45 PM,EventSystem,Warning,(54),4353,N/A,WCWHS,The COM+ Event System attempted to fire the EventObjectChange::ChangedSubscription event but received a bad return code.  HRESULT was 80040201.
    5/20/2010,9:38:45 PM,EventSystem,Warning,(52),4356,N/A,WCWHS,The COM+ Event System failed to create an instance of the subscriber {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}.  StandardCreateInstance returned HRESULT 800706BE.
    5/20/2010,9:32:10 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,9:31:45 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,9:31:26 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,9:31:23 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,9:31:22 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2392) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,9:31:21 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2392) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,9:31:20 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,9:31:19 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,9:31:17 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2392) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS106E0.log.
    5/20/2010,9:31:17 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2392) Windows: The database engine is initiating recovery steps.
    5/20/2010,9:31:16 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2392) Windows: The database engine started a new instance (0).
    5/20/2010,9:31:16 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2392) The database engine 5.02.3790.3959 started.
    5/20/2010,9:31:10 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,9:31:09 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,9:31:05 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,9:31:03 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,9:30:59 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,9:30:59 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,9:24:44 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,9:18:56 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,9:18:25 PM,secars,Information,None,1,N/A,WCWHS,Secars started!
    5/20/2010,9:18:07 PM,Windows Search Service,Information,Search service ,1003,N/A,WCWHS,"The Windows Search Service started.
    "
    5/20/2010,9:18:03 PM,IAANTmon,Information,None,7500,N/A,WCWHS,"Intel RAID Controller: Unknown Controller
    Number of Serial ATA ports: 6
     
    RAID Option ROM Version: Unknown
    Driver Version: 8.9.0.1023
    RAID Plug-In Version: 8.9.0.1023
    Language Resource Version of the RAID Plug-In: File not found
    Create Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume Wizard: File not found
    Create Volume from Existing Hard Drive Wizard Version: 8.9.0.1023
    Language Resource Version of the Create Volume from Existing Hard Drive Wizard: File not found
    Modify Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Modify Volume Wizard: File not found
    Delete Volume Wizard Version: 8.9.0.1023
    Language Resource Version of the Delete Volume Wizard: File not found
    ISDI Library Version: 8.9.0.1023
    Event Monitor User Notification Tool Version: 8.9.0.1023
    Language Resource Version of the Event Monitor User Notification Tool: File not found
    Event Monitor Version: 8.9.0.1023
     
    Hard Drive 0
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 0
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0141675
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 1
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 1
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0281351
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 2
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 2
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0282804
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Hard Drive 3
    Usage: Unknown hard drive usage
    Status: Normal
    Device Port: 3
    Device Port Location: Internal
    Current Serial ATA Transfer Mode: Generation 2
    Model: WDC WD5000AAKS-00A7B0
    Serial Number: WD-WMASY0119194
    Firmware: 01.03B01
    Native Command Queuing Support: Yes
    System Hard Drive: No
    Size: 465.7 GB
    Physical Sector Size: 512 Bytes
    Logical Sector Size: 512 Bytes
     
    Unused Port 0
    Device Port: 4
    Device Port Location: Internal
     
    Unused Port 1
    Device Port: 5
    Device Port Location: Internal
    "
    5/20/2010,9:18:01 PM,WMServer,Information,Multimedia,300,N/A,WCWHS,The Windows Media service has started.
    5/20/2010,9:18:00 PM,ESENT,Information,Logging/Recovery ,302,N/A,WCWHS,Windows (2436) Windows: The database engine has successfully completed recovery steps.
    5/20/2010,9:18:00 PM,semsrv,Information,None,4,N/A,WCWHS,The semsrv service has started.
    5/20/2010,9:17:58 PM,ESENT,Information,Logging/Recovery ,301,N/A,WCWHS,Windows (2436) Windows: The database engine has begun replaying logfile C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log.
    5/20/2010,9:17:57 PM,ESENT,Information,Logging/Recovery ,300,N/A,WCWHS,Windows (2436) Windows: The database engine is initiating recovery steps.
    5/20/2010,9:17:57 PM,ESENT,Information,General ,102,N/A,WCWHS,Windows (2436) Windows: The database engine started a new instance (0).
    5/20/2010,9:17:57 PM,ESENT,Information,General ,100,N/A,WCWHS,SearchIndexer (2436) The database engine 5.02.3790.3959 started.
    5/20/2010,9:17:50 PM,PLFlash DeviceIoControl Service,Information,None,105,N/A,WCWHS,The service was started.
    5/20/2010,9:17:50 PM,Nero BackItUp Scheduler 3,Information,None,0,N/A,WCWHS,The description for Event ID ( 0 ) in Source ( Nero BackItUp Scheduler 3 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Nero BackItUp Scheduler 3 is started. HRESULT: 1.
    5/20/2010,9:17:46 PM,EventSystem,Information,None,4625,N/A,WCWHS,The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.
    5/20/2010,9:17:43 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Successfully started service ASANYs_sem5."
    5/20/2010,9:17:40 PM,ASA 9.0,Information,None,1,N/A,WCWHS,"The description for Event ID ( 1 ) in Source ( ASA 9.0 ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: ASANYs_sem5, Starting service ASANYs_sem5."
    5/20/2010,9:17:39 PM,MSDTC,Information,TM,4193,N/A,WCWHS,"MS DTC started with the following settings (OFF = 0 and ON = 1):

      Security Configuration:
          Network Administration of Transactions = 0,
          Network Clients = 0,
          Inbound Distributed Transactions using Native MSDTC Protocol = 0,
          Outbound Distributed Transactions using Native MSDTC Protocol = 0,
          Transaction Internet Protocol (TIP) = 0,
          XA Transactions = 0
      Filtering Duplicate events = 1"
    5/20/2010,9:14:31 PM,VSS,Error,None,8211,N/A,WCWHS,Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode.
    5/20/2010,9:10:51 PM,Userenv,Warning,None,1524,WCWHS\Administrator,WCWHS,"Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. 

    "
    5/20/2010,9:07:08 PM,Windows Search Service,Information,Gatherer ,3044,N/A,WCWHS,"The gatherer index resumed.

    Context:  Application, SystemIndex Catalog
    "
    5/20/2010,9:06:59 PM,CqvSvc,Information,None,0,N/A,WCWHS,Service stopped successfully.

    ==================================================================

    Sorry for how long this is, but I hope it will provide enough info to help us all resolve the issues quickly and take up less of our time.

    THANK YOU! :|

    Friday, May 21, 2010 7:18 AM
  • Hey everyone,
    So my WHS has been glitchy for several months now, I just haven't had time to look at it (and still don't, but here I go).

    Hi,

    Sorry, but from only a dump from your WHS's application log we can only conclude there "is a problem with your server".

    If this is an OEM product (like the HP MediaSmart and others) you should contact support (they will probably suggest a factory reset).
    If this is a "home build" server you are your own support: RDP to the desktop and start checking your server's hardware and driver configuration. Worst case you'll need to re-install of the OS.

    - Theo.

     


    No home server like Home Server
    Saturday, May 22, 2010 10:05 PM
    Moderator