Quantcast
Channel: Notebook Boot and Lockup topics
Viewing all articles
Browse latest Browse all 62211

Windows error recovery, dpagent, HP client security not functiong properly

$
0
0

Brand new HP ZBook 17

Win 7 pro

i7 4800

16 GB ram

750gb 7200 RPM HD

32 GB flash cache SSD

Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz

NVIDIA Quadro K3100M

Intel(R) HD Graphics 4600

Board:  190A KBC Version 94.47

Bios:  L70 Ver. 01.06

 

 

Had first crash while viewing the workstation laptop screen

Windows Error Recovery

Windows did not shut down correctly

 

event viewer info:

 

Faulting application path: c:\program files (x86)\hewlett-packard\hp protecttools security manager\bin\dpagent.exe

 

 

 

With fresh boot there is no longer an opton to use the finger print reader

 

The display is:

HP Client Security

The Biometric Authentication Service is not functioning properly

 

choices are to:

log on without biometrics

or

wait 30 sec and prompt me again

 

Whe waiting there is no improvement.

 

 

 

This is the information from the microsoft event viewer:

 

 

Log Name:      Application
Source:        Application Error
Date:          1/30/2014 10:04:18 PM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
Faulting application name: dpagent.exe, version: 6.0.0.2935, time stamp: 0x524dc5b6
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x006fb308
Faulting process id: 0xc4c
Faulting application start time: 0x01cf1e3977e8fbf4
Faulting application path: c:\program files (x86)\hewlett-packard\hp protecttools security manager\bin\dpagent.exe
Faulting module path: unknown
Report Id: c131b331-8a2c-11e3-a3d1-fcf8ae13c094
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Application Error" />
    <EventID Qualifiers="0">1000</EventID>
    <Level>2</Level>
    <Task>100</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:04:18.000000000Z" />
    <EventRecordID>4111</EventRecordID>
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data>dpagent.exe</Data>
    <Data>6.0.0.2935</Data>
    <Data>524dc5b6</Data>
    <Data>unknown</Data>
    <Data>0.0.0.0</Data>
    <Data>00000000</Data>
    <Data>c0000005</Data>
    <Data>006fb308</Data>
    <Data>c4c</Data>
    <Data>01cf1e3977e8fbf4</Data>
    <Data>c:\program files (x86)\hewlett-packard\hp protecttools security manager\bin\dpagent.exe</Data>
    <Data>unknown</Data>
    <Data>c131b331-8a2c-11e3-a3d1-fcf8ae13c094</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      System
Source:        Microsoft-Windows-Wininit
Date:          1/30/2014 10:03:53 PM
Event ID:      11
Task Category: None
Level:         Warning
Keywords:     
User:          SYSTEM
Computer:      aa
Description:
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Wininit" Guid="{206F6DEA-D3C5-4D10-BC72-989F03C8B84B}" />
    <EventID>11</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:03:53.580434100Z" />
    <EventRecordID>8785</EventRecordID>
    <Correlation />
    <Execution ProcessID="656" ThreadID="688" />
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="StringCount">1</Data>
    <Data Name="String">C:\Windows\system32\nvinitx.dll</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Security
Source:        Microsoft-Windows-Eventlog
Date:          1/30/2014 10:03:47 PM
Event ID:      1101
Task Category: Event processing
Level:         Error
Keywords:      Audit Success
User:          N/A
Computer:      aa
Description:
Audit events have been dropped by the transport.  0
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
    <EventID>1101</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>101</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4020000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:03:47.508824600Z" />
    <EventRecordID>2428</EventRecordID>
    <Correlation />
    <Execution ProcessID="1056" ThreadID="1276" />
    <Channel>Security</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <UserData>
    <AuditEventsDropped xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
      <Reason>0</Reason>
    </AuditEventsDropped>
  </UserData>
< /Event>

 

 

 

 

Log Name:      System
Source:        Microsoft-Windows-WER-SystemErrorReporting
Date:          1/30/2014 10:03:46 PM
Event ID:      1001
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      AA
Description:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000009f (0x0000000000000003, 0xfffffa80181f1a10, 0xfffff80000b9c3d8, 0xfffffa802894ab00). A dump was saved in: C:\Windows\Minidump\013014-13228-01.dmp. Report Id: 013014-13228-01.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:03:46.000000000Z" />
    <EventRecordID>8720</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>AA</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">0x0000009f (0x0000000000000003, 0xfffffa80181f1a10, 0xfffff80000b9c3d8, 0xfffffa802894ab00)</Data>
    <Data Name="param2">C:\Windows\Minidump\013014-13228-01.dmp</Data>
    <Data Name="param3">013014-13228-01</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      System
Source:        EventLog
Date:          1/30/2014 10:03:46 PM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The previous system shutdown at 10:01:45 PM on ‎1/‎30/‎2014 was unexpected.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:03:46.000000000Z" />
    <EventRecordID>8716</EventRecordID>
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data>10:01:45 PM</Data>
    <Data>‎1/‎30/‎2014</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>204731</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>DE07010004001E00160001002D000D02DE07010005001F00040001002D000D02600900003C000000010000006009000000000000B0040000010000001B620000</Binary>
  </EventData>
< /Event>

 

 

 

 

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          1/30/2014 10:03:37 PM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (2)
User:          SYSTEM
Computer:      aa
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
    <EventID>41</EventID>
    <Version>2</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000002</Keywords>
    <TimeCreated SystemTime="2014-01-31T04:03:37.743207400Z" />
    <EventRecordID>8701</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">159</Data>
    <Data Name="BugcheckParameter1">0x3</Data>
    <Data Name="BugcheckParameter2">0xfffffa80181f1a10</Data>
    <Data Name="BugcheckParameter3">0xfffff80000b9c3d8</Data>
    <Data Name="BugcheckParameter4">0xfffffa802894ab00</Data>
    <Data Name="SleepInProgress">false</Data>
    <Data Name="PowerButtonTimestamp">0</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-CEIP
Date:          1/30/2014 9:16:34 AM
Event ID:      1008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CEIP" Guid="{A402FE09-DA6E-45F2-82AF-3CB37170EE0C}" EventSourceName="Customer Experience Improvement Program" />
    <EventID Qualifiers="49152">1008</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-30T15:16:34.000000000Z" />
    <EventRecordID>4080</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">80004005</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Validity USDK
Date:          1/30/2014 8:20:26 AM
Event ID:      6
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
User identification failed: Result:0x00000041.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Validity USDK" />
    <EventID Qualifiers="32769">6</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-30T14:20:26.000000000Z" />
    <EventRecordID>4077</EventRecordID>
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data>Result:0x00000041</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Validity USDK
Date:          1/30/2014 8:20:21 AM
Event ID:      42
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
WinUsb_Initialize processing was delayed:  (437 ms) .
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Validity USDK" />
    <EventID Qualifiers="32769">42</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-30T14:20:21.000000000Z" />
    <EventRecordID>4031</EventRecordID>
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data> (437 ms) </Data>
  </EventData>
< /Event>

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-CEIP
Date:          1/29/2014 11:08:56 AM
Event ID:      1008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80004005).
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CEIP" Guid="{A402FE09-DA6E-45F2-82AF-3CB37170EE0C}" EventSourceName="Customer Experience Improvement Program" />
    <EventID Qualifiers="49152">1008</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-29T17:08:56.000000000Z" />
    <EventRecordID>3829</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">80004005</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-CEIP
Date:          1/28/2014 4:20:45 PM
Event ID:      1008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 90080108).
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-CEIP" Guid="{A402FE09-DA6E-45F2-82AF-3CB37170EE0C}" EventSourceName="Customer Experience Improvement Program" />
    <EventID Qualifiers="49152">1008</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T22:20:45.000000000Z" />
    <EventRecordID>3722</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">90080108</Data>
  </EventData>
< /Event>

 

 

 

 

 

 

Log Name:      System
Source:        Service Control Manager
Date:          1/28/2014 6:11:56 AM
Event ID:      7032
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
An instance of the service is already running.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7032</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:56.308299400Z" />
    <EventRecordID>7639</EventRecordID>
    <Correlation />
    <Execution ProcessID="728" ThreadID="3028" />
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">1</Data>
    <Data Name="param2">Restart the service</Data>
    <Data Name="param3">Windows Search</Data>
    <Data Name="param4">%%1056</Data>
  </EventData>
< /Event>

The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:

 

An instance of the service is already running.

 

 

 

Log Name:      Application
Source:        Application Error
Date:          1/28/2014 6:11:33 AM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
Faulting application name: dpagent.exe, version: 6.0.0.2935, time stamp: 0x524dc5b6
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00bda8c8
Faulting process id: 0x10f0
Faulting application start time: 0x01cf1c220be3fcd9
Faulting application path: c:\program files (x86)\hewlett-packard\hp protecttools security manager\bin\dpagent.exe
Faulting module path: unknown
Report Id: 535bdbdb-8815-11e3-9335-fcf8ae13c094
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Application Error" />
    <EventID Qualifiers="0">1000</EventID>
    <Level>2</Level>
    <Task>100</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:33.000000000Z" />
    <EventRecordID>3686</EventRecordID>
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data>dpagent.exe</Data>
    <Data>6.0.0.2935</Data>
    <Data>524dc5b6</Data>
    <Data>unknown</Data>
    <Data>0.0.0.0</Data>
    <Data>00000000</Data>
    <Data>c0000005</Data>
    <Data>00bda8c8</Data>
    <Data>10f0</Data>
    <Data>01cf1c220be3fcd9</Data>
    <Data>c:\program files (x86)\hewlett-packard\hp protecttools security manager\bin\dpagent.exe</Data>
    <Data>unknown</Data>
    <Data>535bdbdb-8815-11e3-9335-fcf8ae13c094</Data>
  </EventData>
< /Event>

 

 

 

 

 

Log Name:      System
Source:        Service Control Manager
Date:          1/28/2014 6:11:26 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.295445600Z" />
    <EventRecordID>7625</EventRecordID>
    <Correlation />
    <Execution ProcessID="728" ThreadID="6032" />
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Windows Search</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">30000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
  </EventData>
< /Event>

 

 

 

Log Name:      System
Source:        Service Control Manager
Date:          1/28/2014 6:11:26 AM
Event ID:      7024
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The Windows Search service terminated with service-specific error %%-1073473535.
Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7024</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.295445600Z" />
    <EventRecordID>7624</EventRecordID>
    <Correlation />
    <Execution ProcessID="728" ThreadID="3028" />
    <Channel>System</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Windows Search</Data>
    <Data Name="param2">%%-1073473535</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      1008
Task Category: Search service
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The Windows Search Service is starting up and attempting to remove the old search index {Reason: Index Corruption}.

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="32768">1008</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>1</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3682</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">
    </Data>
    <Data Name="Reason">Index Corruption</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      7010
Task Category: Gatherer
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The index cannot be initialized.

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="49152">7010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>3</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3680</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
< /Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      3058
Task Category: Gatherer
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The application cannot be initialized.

Context: Windows Application

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="49152">3058</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>3</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3679</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">

Context: Windows Application

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
< /Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      3028
Task Category: Gatherer
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="49152">3028</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>3</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3678</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
< /Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      3029
Task Category: Gatherer
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 Element not found.  (HRESULT : 0x80070490) (0x80070490)

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="49152">3029</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>3</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3677</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">

Context: Windows Application, SystemIndex Catalog

Details:
 Element not found.  (HRESULT : 0x80070490) (0x80070490)
< /Data>
    <Data Name="Plugin">Search.TripoliIndexer</Data>
  </EventData>
< /Event>

 

 

 

 

Log Name:      Application
Source:        Microsoft-Windows-Search
Date:          1/28/2014 6:11:26 AM
Event ID:      3029
Task Category: Gatherer
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      aa
Description:
The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)

Event Xml:
< Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
    <EventID Qualifiers="49152">3029</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>3</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-28T12:11:26.000000000Z" />
    <EventRecordID>3676</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>aa</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="ExtraInfo">

Context: Windows Application, SystemIndex Catalog

Details:
 The content index catalog is corrupt.  (HRESULT : 0xc0041801) (0xc0041801)
< /Data>
    <Data Name="Plugin">Search.JetPropStore</Data>
  </EventData>
< /Event>

 

 

 

I ran as administrator in command prompt sfc /scannow and it did not find any integrity problems

 

The HP support assistant has been used daily and all the drivers and windows updates are up to date

 

I used windows defender and there is no infection

 

Also I checked with malwarebytes and there is no infection

 

 

 

 

What is corrupted and how does it get fixed?

 

What else is being reported in the event viewer that needs fixing?

 

 

I downloaded two software:  whocrashed and bluescreen view.

 

These are the results for each:

 

 

Whocrashed
Crash dump directory: C:\Windows\Minidump

Crash dumps are enabled on your computer.

On Fri 1/31/2014 4:02:45 AM GMT your computer crashed
crash dump file: C:\Windows\Minidump\013014-13228-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x75BC0)
Bugcheck code: 0x9F (0x3, 0xFFFFFA80181F1A10, 0xFFFFF80000B9C3D8, 0xFFFFFA802894AB00)
Error: DRIVER_POWER_STATE_FAILURE
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This bug check indicates that the driver is in an inconsistent or invalid power state.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

 

 

 

Bluescreenview

 

013014-13228-01.dmp 1/30/2014 10:02:45 PM DRIVER_POWER_STATE_FAILURE 0x0000009f 00000000`00000003 fffffa80`181f1a10 fffff800`00b9c3d8 fffffa80`2894ab00 ntoskrnl.exe ntoskrnl.exe+75bc0 NT Kernel & System Microsoft® Windows® Operating System Microsoft Corporation 6.1.7601.18247 (win7sp1_gdr.130828-1532) x64 ntoskrnl.exe+75bc0     C:\Windows\Minidump\013014-13228-01.dmp 8 15 7601 342,454 1/30/2014 10:03:42 PM 

 

 

 

What happened to produce the crash?

 

How does the HP Client Security get fixed to function properly?

 

What troubleshooting steps are needed now?

 

How do I prevent or at least reduce the likelihood of this happening again?

 

 

 

 

thx in advance


Viewing all articles
Browse latest Browse all 62211

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>