ElfFile. 2cElfChnknn DU | 2iraW M{j]*R/'V6a1a2&g$W**/0` Z2&Z2\1$eAYM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAj{ProviderG=KNameDesktop Window ManagerAMaEventID') QualifiersdLevelE{Task$'jKeywordsAPR; TimeCreated'{j<{ SystemTime .F EventRecordID 8aChannel Application:R;nComputer MediaserverAB^.SecurityfLUserID ! !1#@D`O F.F%g>9{p(xlUD EventData}oData !Binary0x40010004AL** G` [@ [@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=)GuidA  " Version    iOpcode 'AR {  A Correlation\F} ActivityID 5RelatedActivityID AmW ExecutionHF|  ProcessID 9ThreadID    MediaserverA^  !  N!/0`p PMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication  &/Ô*FgA[U'=EVENT_HIVE_LEAKA#}=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA 8y **`ڠ` [@   N=!G`pQMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg'ygػ$<[7J.UAAcDg`**8>` [@   N!ڠ`$xRMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg'AwDAIAA8**\` AþAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561}^`EventSourceName EventSystemA      i 'AR {  AF AW F|     Application  MediaserverA^  ! Q!@>`S 2{vE`Qi^_UA#}=param1 A#}=param2 A#}=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogAAw//D**\` :S5G:S5GS(j System.Data.SqlClient.SqlException: A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: TCP Provider, error: 0 - No connection could be made because the target machine actively refused it.) at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connec...gUAEDA **` ,R,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTA    'AR {    Application  MediaserverA^  ! s!f`_ F.PWindows3444Windows: 060176010000ry-ms<**B` ,R Q!,`` F..Windows3444Windows: mRHXXlm**o` ,R !-B`a F.Windows3444Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.logAIA** ` wW we}%ƿ:AMsj5http://schemas.microsoft.com/win/2004/08/events/event#A4+=Application ErrorA    'AR {    Application  MediaserverA^  ! !do`b F.bMPExtended.Applications.ServiceConfigurator.exe0.5.4.051e2a826KERNELBASE.dll6.1.7601.1822951fb1116e04343520000c41f83001cf601bc93c5d96C:\Program Files (x86)\MPExtended\Service\MPExtended.Applications.ServiceConfigurator.exeC:\Windows\syswow64\KERNELBASE.dll46b89b9b-cc0f-11e3-9b1b-00155872cd7bQwBH**2 ` ,R Q!. `c F..Windows3444Windows: qAAAAsH**Z` ]O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchF&{CA4E628D-8567-4896-AB6B-835B221F373F}Windows Search ServiceA      i 'AR {  AF AW F|     Application  MediaserverA^  ! s!@2 `d Z(6aZ(Ux ҤB6UA)}= ExtraInfo  **`tL` $a$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingA    'AR {    Application  MediaserverA^  ! !Z`e F.0CLR20r3Not available03QX3DGLKNUIBNNXRXLSOM2J0SUF3ONYR0.5.0.051e2a826Hardcodet.Wpf.TaskbarNotification1.0.4.04e8c1cf03f2bSystem.Windows.Markup.XamlParseC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_3QX3DGLKNUIBNNXR_7dbfdc35fb64a21149b3614e4ced5adb470cb25_0f16d864046b89b9b-cc0f-11e3-9b1b-00155872cd7b0uOpB`** XM` R&gR *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}$Software Protection Platform ServiceA      i 'AR {  AF AW F|     Application  MediaserverA^  ! #!@tL`f F.**M`  ?jG ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    'AR {    Application  MediaserverA^  ! #! XM`g F.A**M` R&g k!*@M`h F.HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 dL**H M` R&g  !@M`i F.z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] *kH **a` R&g A!@M`j F.6.1.7601.17514ame**맻` Z2& 9!1#@a`k F.0x40010004ed**` [@   No!맻`$lMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication  X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA ES**8{` [@   N!`$xmMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg' A8**X ` Aþ !@{`n 2 2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogoDaX**!` My! #!``o F.**"*` :S5G O!@`p F.,0x000000000x00000001**8#` [@   N!*`qMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg'ntRe8**$` ̬8V =!p`r F.SessionEnv**%` :$ _!`s F.<Service started successfully.**&` u ^' #!N@`t F.//**p'` Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSfLp**(` u ^' #! N`v F.Dat**)` >B MEDIASERVER\SQLEXPRESSft.***` >B MEDIASERVER\SQLEXPRESS2BD**+` 1776>B MEDIASERVER\SQLEXPRESSask**,` MIXED>; MEDIASERVER\SQLEXPRESSd**->` c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**p.>` `| F.d>199225/04/2014 9:35:06 AM24/04/2014 11:35:06 PM>C MEDIASERVER\SQLEXPRESSnp**/K` `} F.> -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSAc**0K` b7.* #!K`~ F.cat**1k` b7.* #!K` F.**2k` > C MEDIASERVER\SQLEXPRESS022**3k` 2> C MEDIASERVER\SQLEXPRESS ** 4k` 25005000>B MEDIASERVER\SQLEXPRESS( **X5k` 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSmsfX**6k` master>B MEDIASERVER\SQLEXPRESS** 7\` master1>~ MEDIASERVER\SQLEXPRESSa4 **88w` model>B MEDIASERVER\SQLEXPRESSs**H=A` A` >B MEDIASERVER\SQLEXPRESScti**@y ` tempdb>B MEDIASERVER\SQLEXPRESS**8Ay ` >e MEDIASERVER\SQLEXPRESS=**0G` 'any'ipv61433>e MEDIASERVER\SQLEXPRESS App0**0H` 'any'ipv41433>e MEDIASERVER\SQLEXPRESSTD 0**HI` \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSenH**XJ` \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESStforX**K` 7806>/C MEDIASERVER\SQLEXPRESS** L` 0x54b3>e MEDIASERVER\SQLEXPRESS  **M` >B MEDIASERVER\SQLEXPRESS@**(N` A?RmSessionEventFMwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/*L RmSessionId ,2=K UTCStartTime ~`itiP**]~` ߰V @!' ~`@  O)1Microsoft-Windows-RestartManagerF,$r$Application j8_.j8_N#JI 2ARmRestartEventF/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/  .@ nApplications YDC Applications*r0 Application .'*^ RebootReasons 0SQL Server (SQLEXPRESS)i**H^` ߰V @'!'~`@  O)1Microsoft-Windows-RestartManagerF,$r$Application I~`H**H_` ߰V @'!'`@  O)1Microsoft-Windows-RestartManagerF,$r$Application I`H**`` ߰V @_!'`@  O)1Microsoft-Windows-RestartManagerF,$r$Application j8_0SQL Server (SQLEXPRESS)**Ha5qI` ߰V @'!'`@  O)1Microsoft-Windows-RestartManagerF,$r$Application I`H**HbZN` ߰V @'!'5qI`@  O)1Microsoft-Windows-RestartManagerF,$r$Application IKI`H**cgO` ߰V @_!'ZN`@  O)1Microsoft-Windows-RestartManagerF,$r$Application j8_0SQL Server (SQLEXPRESS)**HdOl` ߰V @'!'gO`@  O)1Microsoft-Windows-RestartManagerF,$r$Application IKI`H**Hep` ߰V @'!'Ol`@  O)1Microsoft-Windows-RestartManagerF,$r$Application IOl`H**fs:q` ߰V @_!'p`@  O)1Microsoft-Windows-RestartManagerF,$r$Application j8_0SQL Server (SQLEXPRESS)**Hg` ߰V @'!'s:q`@  O)1Microsoft-Windows-RestartManagerF,$r$Application IOl`H**HhIz` ߰V @'!'`@  O)1Microsoft-Windows-RestartManagerF,$r$Application Iۊ`H**i쏁` ߰V @_!'Iz`@  O)1Microsoft-Windows-RestartManagerF,$r$Application j8_0SQL Server (SQLEXPRESS)**Hjf` ߰V @'!'쏁`@  O)1Microsoft-Windows-RestartManagerF,$r$Application Iۊ`H**kf` @'9F,C&D!&\f** ooʴ` [@ &[@ 5ņAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAY{Provider6F=KNameX)GuidAMzaEventID'X) Qualifiers " Version dLevelE{Task ?Opcode$fjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FF ActivityIDmz5RelatedActivityID Am ExecutionHFF ProcessID9ThreadID "aChannel:F;nComputer MediaserverAB.SecurityfLUserID !  N!j2`HMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication /Ô*FAD EventData'=EVENT_HIVE_LEAKA5GoData=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA **`pU;` [@ &  N=!oʴ`Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygygػ$<[7J.So`**q` AfAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFX&{899daace-4868-4295-afcd-9eb8fb497561}`EventSourceName EventSystemAz      ? fA   AFFmAF   Application F MediaserverA  ! Q!@U;` {vE`Qi^_A#G=param1 A#G=param2 A#G=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogft.**8r ` [@ &  N!`$tMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygmA8**s ` :S5G:S5GS(j9{p(J> G !Binary,0x000000000x00000001i**t` ̬8̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonFX&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}WlclntfyAz      ? fA   AFFmAF   Application F MediaserverA  ! =!p ` FSessionEnv**u` My6MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAz    fA     Application F MediaserverA  ! #!`` Fes**v_ ` :!:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Az    fA     Application F MediaserverA  ! _!` F<Service started successfully.****w_ ` u $u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAz    fA     Application F MediaserverA  ! #!N@_ ` Fta**xV` u $ #! N_ ` Fn/**xy` b7.'$b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFX&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtAz      ? fA   AFFmAF   Application F MediaserverA  ! #!V` Fenx**z\ ` b7.' #!` FA**{Ҽ0` dF,d3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAz    fA     Application F MediaserverA  ! _!\ ` F<Service started successfully.** |·3` t[/t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerAz    fA     Application F MediaserverA  ! [!Ҽ0` F8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: TCP Provider, error: 0 - No connection could be made because the target machine actively refused it.) at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connec...t) **}·3` ,9,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTAz    fA     Application F MediaserverA  ! s!f·3` FPWindows3448Windows: 060176010000rea**~YP4` ,9 Q!,·3` F.Windows3448Windows: ng.**5` ,9 !-YP4` FWindows3448Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log **6` ,9 Q!.5` F.Windows3448Windows: nWr**x` >@O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchFX&{CA4E628D-8567-4896-AB6B-835B221F373F}Windows Search ServiceAz      ? fA   AFFmAF   Application F MediaserverA  ! s!@6` Z(CZ(Ux ҤB6A)G= ExtraInfo  **ty` R&DR *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPFX&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}$Software Protection Platform ServiceAz      ? fA   AFFmAF   Application F MediaserverA  ! #!@x` F**! z`  ?G/ ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterAz    fA     Application F MediaserverA  ! #!ty` Frr**! z` R&D k!*@! z` FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 d **H ! z` R&D  !@! z` Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] iH **` R&D A!@! z` F6.1.7601.175142cd**Ua` Z2\Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAz    fA     Application F MediaserverA  ! 9!1#@` F0x40010004** -#` [@ &  N!Ua`$0Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 21 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Internet Explorer\Main Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Policies Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 628 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\Shell\Bags\1\Desktop Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows NT\CurrentVersion Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings  **9z` [@ &  N!-#`$0Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 10 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000_Classes: Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\845\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\845\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\845\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\845\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 1652 (\Device\HarddiskVolume4\Windows\explorer.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell ****8Y` [@ &  N!9z`$tMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg8**X`@̧` Af !@Y`  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogMicX**8` [@ &  N!`@̧`Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygows8**` My6 #!`` F**` :S5G O!@` F,0x000000000x00000001**` ̬8 =!p` FSessionEnv**#` :! _!` F<Service started successfully.**#` u $ #!N@#` FR\S**#` u $ #! N#` F F**)` b7.' #!#` F**V` b7.' #!)` FS\M**pV` Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSSSp**V` >B MEDIASERVER\SQLEXPRESS`**V` >B MEDIASERVER\SQLEXPRESS****V` 1792>B MEDIASERVER\SQLEXPRESS3**V` MIXED>; MEDIASERVER\SQLEXPRESSk**V` c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**pV` 177625/04/2014 10:30:31 AM25/04/2014 12:30:31 AM>C MEDIASERVER\SQLEXPRESSp**V`  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**V` > C MEDIASERVER\SQLEXPRESS**V` 2> C MEDIASERVER\SQLEXPRESS*** V` 25005000>B MEDIASERVER\SQLEXPRESSer **XV` 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**텫` master>B MEDIASERVER\SQLEXPRESS** 텫` master1>~ MEDIASERVER\SQLEXPRESS **8텫` model>B MEDIASERVER\SQLEXPRESS**H` >B MEDIASERVER\SQLEXPRESS!**݀` tempdb>B MEDIASERVER\SQLEXPRESS**8݀` >e MEDIASERVER\SQLEXPRESSN**0t` 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0t` 'any'ipv41433>e MEDIASERVER\SQLEXPRESST0**Ht` \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS;H**Xt` \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**t` 7806>/C MEDIASERVER\SQLEXPRESS** t` 0x54b3>e MEDIASERVER\SQLEXPRESS **v` >B MEDIASERVER\SQLEXPRESSog**(v` @ !@aX` Z(C 8fe-**H ` Z2\ 9!1#@` F0x40010004b6b6**` [@ &  No!H `8Microsoft-Windows-User Profiles Service鱉ZDD XEApplication X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA ** ` t[/ u!` FRService has been successfully shut down.߰ **` >B MEDIASERVER\SQLEXPRESS ** ` dF, u!` FRService has been successfully shut down. ** 7K` :! u!` FRService has been successfully shut down. **8T#` [@ &  N!7K`Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygtart8**Xlxu#` Af !@T#`  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogMicrX**8#` [@ &  N!lxu#`@Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygtp:8**#` :S5G O!@#` F,0x000000000x00000001**#` ̬8 =!p#` FSessionEnv**D$` My6 #!`#` F**D$` :! _!D$` F<Service started successfully.r**D$` u $ #!N@D$` F**%` u $ #! ND$` Fcat**%` b7.' #!%`  F@**5'` b7.' #!%`! F**5'` Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**5'` >B MEDIASERVER\SQLEXPRESSndow**5'` >B MEDIASERVER\SQLEXPRESS**5'` 1904>B MEDIASERVER\SQLEXPRESS**5'` MIXED>; MEDIASERVER\SQLEXPRESS***5'` c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS@**p5'` 179225/04/2014 10:40:44 AM25/04/2014 12:40:44 AM>C MEDIASERVER\SQLEXPRESSp**5'`  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS **5'` > C MEDIASERVER\SQLEXPRESSLL**5'` 2> C MEDIASERVER\SQLEXPRESS** %{*` 25005000>B MEDIASERVER\SQLEXPRESS 0x40010004ElfChnk^^P픆W3M<<&a`_/;_:;``yF:z;^h<Ms&BN9N2&=cqy_** 1` d&d3# ޾]AQM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAb{Provider?=KNameMPExtended ServiceAMaEventID') QualifiersdLevelE{Task$jKeywordsAPJ; TimeCreated'sj<{ SystemTime .F EventRecordID 8aChannel Application:J;nComputer MediaserverABV.SecurityyfLUserID ! !%{*`- F&F%g>9{p(xlMD EventDatauoData !Binary<Service started successfully.N**  1` 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESS0 **31` master>B MEDIASERVER\SQLEXPRESS** 31` master1>~ MEDIASERVER\SQLEXPRESS60 **831` model>B MEDIASERVER\SQLEXPRESS**(:2` >B MEDIASERVER\SQLEXPRESStio**`2` tempdb>B MEDIASERVER\SQLEXPRESSi**8`2`  F&>>e MEDIASERVER\SQLEXPRESS{DB**0`2` 'any'ipv61433>e MEDIASERVER\SQLEXPRESSF0**0`2` 'any'ipv41433>e MEDIASERVER\SQLEXPRESSnv0**H`2` \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS H**X`2` \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**`2` 7806>/C MEDIASERVER\SQLEXPRESSz** `2` 0x54b3>e MEDIASERVER\SQLEXPRESS **k3` >B MEDIASERVER\SQLEXPRESS/sc**($4`  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...k t **n9` ,2,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTA    AJ s    Application  MediaserverAV y ! s!fn9`I F&PWindows3312Windows: 060176010000at **n9` ,2 Q!,n9`J F&.Windows3312Windows: - **n9` ,2 !-n9`K F&Windows3312Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.logd**\<` ,2 Q!.n9`L F&.Windows3312Windows: enC** ~` N9O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/eventEAF=Microsoft-Windows-SearchFF:)Guid&{CA4E628D-8567-4896-AB6B-835B221F373F}:V`EventSourceNameWindows Search ServiceA  "/; Version    z;Opcode AJ s  A; Correlation\F<u ActivityID,<5RelatedActivityIDAmh< ExecutionHF<< ProcessID<9ThreadID   Application  MediaserverAV y ! s!@\<`M Z(=Z(Ux ҤB6MA)u= ExtraInfo  **7` R^>R *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPFF:&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}:$Software Protection Platform ServiceA  /;    z; AJ s  A;F<,<Ah<F<<   Application  MediaserverAV y ! #!@ ~`N F&**O`  ?B.( ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    AJ s    Application  MediaserverAV y ! #!7`O F&t.**O` R^> k!*@O`P F&HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H O` R^>  !@O`Q F&z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] (?H **¸3 ` R^> A!@O`R F&6.1.7601.17514)(2 **U#!` R^> #!@¸3 `S F&)] **(J)!` 8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA    AJ s    Application  MediaserverAV y ! !!Z`^ F&Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**0` smHv !`_ F&@$defragmentationSystem Reserved$"Q)k^o0**(i͋` smHv }!`` F&6$defragmentationvideo (E:)$"Q)k^cr(**(̍`  gȺN gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA    AJ s    Application  MediaserverAV y ! ! i͋`a F&- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004452- TID: 00004988- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**@э` smHv !̍`b F&J$defragmentationFreeAgent Drive (G:)$"Q)k^1-13@**( ` smHv !э`c F&8$defragmentationbackup (F:)$"Q)k^n(**xI+`  gȺN ! `d F&- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004740- TID: 00001612- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 cex**0v]` t[.( !I+`e F&`PowerEvent handled successfully by the service.icr0**0v]` t[.( !v]`f F&`PowerEvent handled successfully by the service.\RE0**0|%` t[.( !v]`g F&`PowerEvent handled successfully by the service.-8E0**0` 2}2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    AJ s    Application  MediaserverAV y ! ! |%`h F&t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|mys\0**x؀`  gȺN ! `i F&- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004252- TID: 00004560- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 Mix**0=ka` t[.( !؀`j F&`PowerEvent handled successfully by the service.5560**0b` t[.( !=ka`k F&`PowerEvent handled successfully by the service.0**0Va t[.( !b`l F&`PowerEvent handled successfully by the service.0**Wa 8c !Vam F&Application: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at MediaPortal.Plugins.MovingPictures.LocalMediaManagement.MovieImporter.ScanAndMonitorPaths() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() **x S]a wvm !dWan F&MediaPortal.exe1.7.0.05347c7f3unknown0.0.0.000000000c000000511be16ed17d401cf61145323d3ebC:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknown95e6e275-cd07-11e3-bb35-00155872cd7bedix**@!"a $q !S]ao F&r0CLR20r3Not available0mediaportal.exe1.7.0.05347c7f3MovingPictures1.5.1.1487512b6a3c5171a5System.NullReferenceExceptionC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mediaportal.exe_fcc33c5f18a9496897105117e46ee99e49785b6_1103722a095e6e275-cd07-11e3-bb35-00155872cd7b0@**0"Ȃ#a t[.( !"ap F&`PowerEvent handled successfully by the service.0**0##a t[.( !Ȃ#aq F&`PowerEvent handled successfully by the service.B 0**0$2G@fa t[.( !#ar F&`PowerEvent handled successfully by the service.SER0**0%Uska t[.( !2G@fas F&`PowerEvent handled successfully by the service.Ser0**0&Ila t[.( !Uskat F&`PowerEvent handled successfully by the service.V0**' Mla R^> #!@Ilau F&XPR**( Mla R^> k!*@ Mlav F&HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 ER\**H ) Mla R^>  !@ Mlaw F&z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H ***kla R^> A!@ Mlax F&6.1.7601.17514**+ xna R^> #!@klay F&IAS**0,{na smHv ! xnaz F&@$defragmentationSystem Reserved$"Q)k^L0**X-\na y !!{na{ F&Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exeEX**0.kyoa smHv !\na| F&@$defragmentationSystem Reserved$"Q)k^P0**/{oa MyvMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    AJ s    Application  MediaserverAV y ! '!kyoa} F&**0aoa My '!{oa~ F&**(1woa smHv }!aoa F&6$defragmentationvideo (E:)$"Q)k^t(**x2pa  gȺN ! woa F&- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004540- TID: 00003960- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**@3? pa smHv !pa F&J$defragmentationFreeAgent Drive (G:)$"Q)k^@**(4oqa smHv !? pa F&8$defragmentationbackup (F:)$"Q)k^(**85hua smHv !oqa F&B$boot optimizationTV System (C:)$"0dyl8**060>a t[.( !hua F&`PowerEvent handled successfully by the service.0**07@Aa t[.( !0>a F&`PowerEvent handled successfully by the service.0**082a t[.( !@Aa F&`PowerEvent handled successfully by the service.!0**09оa t[.( !2a F&`PowerEvent handled successfully by the service.!0**0:Tia t[.( !оa F&`PowerEvent handled successfully by the service.!0**0;j<b t[.( !Tia F&`PowerEvent handled successfully by the service.0**0<b1b t[.( !j<b F&`PowerEvent handled successfully by the service.0**0=s2b t[.( !b1b F&`PowerEvent handled successfully by the service.0**0>f!;b t[.( !s2b F&`PowerEvent handled successfully by the service.0**?͗";b My '!f!;b F&**@b;b My '!͗";b F&7**xA;=b  gȺN ! b;b F&- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003116- TID: 00003544- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 @x**0BLb t[.( !;=b F&`PowerEvent handled successfully by the service.-Us0**0CZrLb t[.( !Lb F&`PowerEvent handled successfully by the service.roc0**0DMb t[.( !ZrLb F&`PowerEvent handled successfully by the service. (\0**0E:Sb t[.( !Mb F&`PowerEvent handled successfully by the service.Har0**0F:Sb t[.( !:Sb F&`PowerEvent handled successfully by the service.ica0**0G״FVb t[.( !:Sb F&`PowerEvent handled successfully by the service.79-0**0H!P۸b t[.( !״FVb F&`PowerEvent handled successfully by the service.-130**0I!P۸b t[.( !!P۸b F&`PowerEvent handled successfully by the service.0**0J,b t[.( !!P۸b F&`PowerEvent handled successfully by the service.0**0Kyc t[.( !,b F&`PowerEvent handled successfully by the service.0**0Lyc t[.( !yc F&`PowerEvent handled successfully by the service.vic0**0M)-c t[.( !yc F&`PowerEvent handled successfully by the service.ofi0**0NtCc t[.( !)-c F&`PowerEvent handled successfully by the service.ppr0**0O8Cc t[.( !tCc F&`PowerEvent handled successfully by the service.icr0**0PY?]Pc t[.( !8Cc F&`PowerEvent handled successfully by the service.0**0QsQc t[.( !Y?]Pc F&`PowerEvent handled successfully by the service.0**0R{2tQc t[.( !sQc F&`PowerEvent handled successfully by the service.0**0S8Zc t[.( !{2tQc F&`PowerEvent handled successfully by the service.!0**0T\c t[.( !8Zc F&`PowerEvent handled successfully by the service.0**0U轄c t[.( !\c F&`PowerEvent handled successfully by the service.0**0V&c t[.( !轄c F&`PowerEvent handled successfully by the service.ros0**0Wq;c t[.( !&c F&`PowerEvent handled successfully by the service.dow0**0Xc t[.( !q;c F&`PowerEvent handled successfully by the service.50**hYβc 2} ! c F&t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myRVEh**0Zc t[.( !βc F&`PowerEvent handled successfully by the service.RES0**0[5c t[.( !c F&`PowerEvent handled successfully by the service.**0**0\Mc t[.( !5c F&`PowerEvent handled successfully by the service.S\M0**] c  gȺN M! Mc F& Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {46217268-9677-4891-8e73-138d485c12fd}- Code: WRTDELET00000313- Call: WRTDELET00000248- PID: 00006136- TID: 00001652- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **^بY c Z2vmZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA    AJ s    Application  MediaserverAV y ! 9!1#@ c F&0x400100042> C ME [@ v[@ 5ņESAMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=F:A  /;    z; AJ s  A;F<,< ElfChnk__@`i<W=Uf?mMFN6;΋Wr$&**_ c [@ &[@ 5ņAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAY{Provider6F=KNameX)GuidAMzaEventID'X) Qualifiers " Version dLevelE{Task ?Opcode$fjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FF ActivityIDmz5RelatedActivityID Am ExecutionHFF ProcessID9ThreadID "aChannel:F;nComputer MediaserverAB.SecurityfLUserID !  N< !بY c@9{p(J> W !BinaryRService has been successfully shut down.@**bD}M$c >B MEDIASERVER\SQLEXPRESS**`cjoc [@ &  N=!D}M$c@Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygygػ$<[7J.`**dDoc AAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFX&{899daace-4868-4295-afcd-9eb8fb497561}U`EventSourceName EventSystemAz      ? fA   AFFmAF   Application F MediaserverA  ! Q!@joc r{vE`Qi^_A#W=param1 A#W=param2 A#W=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog**8e4qc [@ &  N!Doc|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg8**f4qc My"MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAz    fA     Application F MediaserverA  ! #!`4qc F**g4qc :$:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Az    fA     Application F MediaserverA  ! _!4qc F<Service started successfully.NT**h4qc Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**i4qc >B MEDIASERVER\SQLEXPRESSed **j4qc >B MEDIASERVER\SQLEXPRESSd=M**k4qc 1648>B MEDIASERVER\SQLEXPRESSte**l4qc MIXED>; MEDIASERVER\SQLEXPRESSS**m4qc c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSe.D**pn4qc 190430/04/2014 5:49:21 AM29/04/2014 7:49:21 PM>C MEDIASERVER\SQLEXPRESSerp**o4qc  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS **p4qc > C MEDIASERVER\SQLEXPRESS06**q4qc 2> C MEDIASERVER\SQLEXPRESSdo**r4qc u 6u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAz    fA     Application F MediaserverA  ! #!N@4qc F**s4qc u 6 #! N4qc Fnt** t4qc 25005000>B MEDIASERVER\SQLEXPRESS **xu1qc b7.6;6b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFX&{1edeee53-0afe-4609-b846-d8c0b2075b1f}UWinMgmtAz      ? fA   AFFmAF   Application F MediaserverA  ! #!4qc FMx**Xv1qc 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSectiX**w1qc master>B MEDIASERVER\SQLEXPRESS **x1qc b7.6; #!1qc F** y1qc master1>~ MEDIASERVER\SQLEXPRESSSe **8z1qc model>B MEDIASERVER\SQLEXPRESS**(erc >e MEDIASERVER\SQLEXPRESS] 3:**0erc 'any'ipv61433>e MEDIASERVER\SQLEXPRESS [0x0**0erc 'any'ipv41433>e MEDIASERVER\SQLEXPRESS])(10**Herc \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSxC0H**Xerc \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS-a36X**erc 7806>/C MEDIASERVER\SQLEXPRESS, 0** erc 0x54b3>e MEDIASERVER\SQLEXPRESS1: c **erc >B MEDIASERVER\SQLEXPRESS8d64**^rc >B MEDIASERVER\SQLEXPRESS, [(**^rc  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...j **/tc tempdb>B MEDIASERVER\SQLEXPRESS**8/tc ]LHMEDIASERVER\SQLEXPRESSmaster**0~e t[ !UB~e  F`PowerEvent handled successfully by the service.}0**(f e 5=Desktop Window ManagerAz    fA     Application F MediaserverA  ! 9!1#@f e  F0x40010004**xa e [@ &  No! e@pFc| Microsoft-Windows-User Profiles Service鱉ZDD XEApplication X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA **( e >B MEDIASERVER\SQLEXPRESS**8?@\e [@ &  N! e|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg8**X\ؚ\e A !@?@\e r 2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog'!X**8\e [@ &  N!\ؚ\e Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg;8**\e My" #!`\e F- Cal**\e :S5G O!@\e F,0x000000000x00000001**lq]e ̬8̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonFX&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}UWlclntfyAz      ? fA   AFFmAF   Application F MediaserverA  ! =!p\e FSessionEnv**lq]e :$ _!lq]e F<Service started successfully.**lq]e Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSנ**lq]e >B MEDIASERVER\SQLEXPRESS**lq]e >B MEDIASERVER\SQLEXPRESS**lq]e 1892>B MEDIASERVER\SQLEXPRESS**lq]e MIXED>; MEDIASERVER\SQLEXPRESS**lq]e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSc**hlq]e 16482/05/2014 6:50:58 AM1/05/2014 8:50:58 PM>C MEDIASERVER\SQLEXPRESSEh**lq]e  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**lq]e > C MEDIASERVER\SQLEXPRESSt[.(**lq]e 2> C MEDIASERVER\SQLEXPRESS*** lq]e 25005000>B MEDIASERVER\SQLEXPRESS **lq]e u 6 #!N@lq]e# FPo**lq]e u 6 #! Nlq]e$ F**X ^e 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX** ^e b7.6; #! ^e& F**^e master>B MEDIASERVER\SQLEXPRESS** ^e master1>~ MEDIASERVER\SQLEXPRESS** **^e b7.6; #!^e) Fows**8^e model>B MEDIASERVER\SQLEXPRESSec**H_e >e MEDIASERVER\SQLEXPRESS **0_e 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0_e 'any'ipv41433>e MEDIASERVER\SQLEXPRESSF:0A  9{p(xlID EventDataqoData !Binary:>\\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS0 H**X_e \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSuseX**_e 7806>/C MEDIASERVER\SQLEXPRESS\S** _e 0x54b3>e MEDIASERVER\SQLEXPRESSSys **_e >B MEDIASERVER\SQLEXPRESSndo**\l`e d d3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA    AF o    Application  MediaserverAR u ! _!_e9 F"<Service started successfully.**ae >B MEDIASERVER\SQLEXPRESSHar**ae  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ....mi **ae ]LHMEDIASERVER\SQLEXPRESSmaster**ae  F">tempdb>B MEDIASERVER\SQLEXPRESS**8ae **1ee ,$ Q!.ceG F".Windows3428Windows: **$e +O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/eventEAF=Microsoft-Windows-SearchF,)Guid&{CA4E628D-8567-4896-AB6B-835B221F373F}M-R`EventSourceNameWindows Search ServiceA  "- Version    .Opcode AF o  A|. Correlation\F.q ActivityID.5RelatedActivityIDAm/ ExecutionHF-/. ProcessIDR/9ThreadID   Application  MediaserverAR u ! s!@1eeH Z(j0Z(Ux ҤB6IA)q= ExtraInfo  01**BUe R0R *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF,&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}M-$Software Protection Platform ServiceA  -    . AF o  A|.F..A/F-/R/   Application  MediaserverAR u ! #!@$eI F"**BUe R0 k!*@BUeJ F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H BUe R0  !@BUeK F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] FH **e R0 A!@BUeL F"6.1.7601.17514**#Ke  ?G ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    AF o    Application  MediaserverAR u ! #!eM F"!**(ne `**,e t[ _!neQ F"<Service started successfully.**X ]e 8fN8۹H8͋y4AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA*!= .NET RuntimeA    AF o    Application  MediaserverAR u ! !,eR F"Application: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at MediaPortal.Plugins.MovingPictures.LocalMediaManagement.MovieImporter.ScanAndMonitorPaths() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() X **@e wѾXwe}%ƿ:AMsj5http://schemas.microsoft.com/win/2004/08/events/event#A4+=Application ErrorA    AF o    Application  MediaserverAR u ! !d]eS F"MediaPortal.exe1.7.0.05347c7f3unknown0.0.0.000000000c00000051115bb9d121401cf657fbe23d3afC:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknown0111f2b3-d173-11e3-b918-00155872cd7b@**7]e $\$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingA    AF o    Application  MediaserverAR u ! !eT F"r0CLR20r3Not available0mediaportal.exe1.7.0.05347c7f3MovingPictures1.5.1.1487512b6a3c5171a5System.NullReferenceExceptionC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mediaportal.exe_fcc33c5f18a9496897105117e46ee99e49785b6_07dce49f00111f2b3-d173-11e3-b918-00155872cd7b0**sY)e R0 #!@7]eU F"eck**0_e t[ !sY)eV F"`PowerEvent handled successfully by the service.0**0 1`e t[ !_eW F"`PowerEvent handled successfully by the service.0** 1`e 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005380x000000000ec000>A MEDIASERVER\SQLEXPRESS**0 `e t[ !1`eY F"`PowerEvent handled successfully by the service.0** Be 5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@eh F"0x40010004 ** *e [@ .[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=,A  -    . AF o  A|.F.. A/F-/R/    MediaserverAR u !  N!'e` iMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication 5n/Ô*FgA[I'=EVENT_HIVE_LEAKA#q=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA ch  **e >B MEDIASERVER\SQLEXPRESSicat**`EN%e [@ .  N=!e kMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygWygػ$<[7J.I`**%e AöAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF,&{899daace-4868-4295-afcd-9eb8fb497561}M- EventSystemA  -    . AF o  A|.F..A/F-/R/   Application  MediaserverAR u ! Q!@EN%el {vE`Qi^_IA#q=param1 A#q=param2 A#q=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogm**8%e [@ .  N!%e mMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygWIASE8** %e My殝&MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    AF o    Application  MediaserverAR u ! #!`%en F"**!r&e :S5GN:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS **%r&e >B MEDIASERVER\SQLEXPRESS**&r&e >B MEDIASERVER\SQLEXPRESS**'r&e 1820>B MEDIASERVER\SQLEXPRESS**(r&e MIXED>; MEDIASERVER\SQLEXPRESS[**)r&e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**h*r&e 18922/05/2014 6:24:03 PM2/05/2014 8:24:03 AM>C MEDIASERVER\SQLEXPRESSth**+r&e  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**,r&e > C MEDIASERVER\SQLEXPRESS**-r&e 2> C MEDIASERVER\SQLEXPRESS** . 'e 25005000>B MEDIASERVER\SQLEXPRESS **/ 'e u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    AF o    Application  MediaserverAR u ! #!N@ 'e} F"**0 'e u  #! N 'e~ F"ull**X1'e 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESS.X**x2'e b7.fb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF,&{1edeee53-0afe-4609-b846-d8c0b2075b1f}M-WinMgmtA  -    . AF o  A|.F..A/F-/R/   Application  MediaserverAR u ! #!'e F"x**3'e b7.f #!'e F" **46I(e master>B MEDIASERVER\SQLEXPRESS** 56I(e master1>~ MEDIASERVER\SQLEXPRESS **86(e master111281267>] MEDIASERVER\SQLEXPRESSsof8**87(e model>B MEDIASERVER\SQLEXPRESS**>cz)e >e MEDIASERVER\SQLEXPRESS**(?cz)e 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0Acz)e 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HBcz)e \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XCcz)e \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**Dcz)e 7806>/C MEDIASERVER\SQLEXPRESS** Ecz)e 0x54b3>e MEDIASERVER\SQLEXPRESSF= **F*e >B MEDIASERVER\SQLEXPRESS **G*e >B MEDIASERVER\SQLEXPRESS** I&D+e t[ [!*e F"8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... ** J+e ,$ s!f&D+e F"PWindows3160Windows: 060176010000 **K+e ,$ Q!,+e F".Windows3160Windows: mdf **L+e ,$ !-+e F"Windows3160Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS23494.logE**M+e ,$ !-+e F"Windows3160Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log**NSu,e ,$ Q!.+e F".Windows3160Windows: **OSu,e tempdb>B MEDIASERVER\SQLEXPRESS**P -e + !@Su,e Z(j0 **8Q -e **UIcse R0 #!@re F"**Vse  ?G #!Icse F"@**Wse R0 k!*@se F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 elB MEDIAS R0 @se F"!D@_e/ F.LMEDIASERVER\SQLEXPRESSLD MEDIASERVER\SQLEXPRESSmaster96H**(_e >e MEDIASERVER\SQLEXPRESS **0_e 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0_e 'any'ipv41433>e MEDIASERVER\SQLEXPRESSF:0A  {F'^FtLM*~!&.F?v**Xse R&R *Ny^cAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAZ{Provider7F=KNameMicrosoft-Windows-Security-SPPF)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}`EventSourceName$Software Protection Platform ServiceAM{aEventID') Qualifiers " Version dLevelE{Task @Opcode$gjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FG ActivityIDn{5RelatedActivityIDAm ExecutionHFG ProcessID9ThreadID 8aChannel Application:];nComputer MediaserverAB.SecurityfLUserID ! - !@se FnF%g>9{p(xlD EventDataoData !Binaryz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] ed **Y\}e R& A!@se Fn6.1.7601.17514 st**Ze Z2Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@\}e Fn0x40010004n(D**[e >B MEDIASERVER\SQLEXPRESSo**h\e [@ F[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N=!e Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygMygػ$<[7J.h**]*e AîAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA{      @ gA   AFGnAF   Application ] MediaserverA  ! Q!@e !{vE`Qi^_A#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog**8^$:e [@ F  N!*e Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygMom/8**_$:e My$nMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA{    gA     Application ] MediaserverA  ! #!`$:e Fn**`$:e :S5GF':S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSA**d$:e >B MEDIASERVER\SQLEXPRESS**e$:e >B MEDIASERVER\SQLEXPRESS 0x0**f$:e 1932>B MEDIASERVER\SQLEXPRESS ms**g$:e MIXED>; MEDIASERVER\SQLEXPRESSin**he c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSe**hie 18202/05/2014 6:30:17 PM2/05/2014 8:30:17 AM>C MEDIASERVER\SQLEXPRESS1h**je  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSF0**ke > C MEDIASERVER\SQLEXPRESS, 0]**le 2> C MEDIASERVER\SQLEXPRESS7:** me 25005000>B MEDIASERVER\SQLEXPRESS 0 **ne u Au YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA{    gA     Application ] MediaserverA  ! #!N@e Fn0]**oe u A #! Ne Fn], **Xpe 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**xqQke b7.^FAb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!e Fnx**rQke master>B MEDIASERVER\SQLEXPRESS**sQke b7.^F #!Qke FnME** te master1>~ MEDIASERVER\SQLEXPRESS20 **ue dLd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA{    gA     Application ] MediaserverA  ! _!e Fn<Service started successfully.**8ve model>B MEDIASERVER\SQLEXPRESS.**(|~e >B MEDIASERVER\SQLEXPRESS5h**~~e >e MEDIASERVER\SQLEXPRESS **0~e 'any'ipv61433>e MEDIASERVER\SQLEXPRESSiaP0**0~e 'any'ipv41433>e MEDIASERVER\SQLEXPRESSPor0**H~e \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSAH**X~e \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**~e 7806>/C MEDIASERVER\SQLEXPRESS48** ~e 0x54b3>e MEDIASERVER\SQLEXPRESS33c **5e >B MEDIASERVER\SQLEXPRESS**5e  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...Cod **e tempdb>B MEDIASERVER\SQLEXPRESSe**8e {O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchF&{CA4E628D-8567-4896-AB6B-835B221F373F}Windows Search ServiceA{      @ gA   AFGnAF   Application ] MediaserverA  ! s!@_ e Z(~Z(Ux ҤB6A)= ExtraInfo  **Oe R& #!@7TOe Fn0c**dPe  ?^d ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA{    gA     Application ] MediaserverA  ! #!Oe Fnhe**dPe R& k!*@dPe FnHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 \**H Qe R&  !@dPe Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] DH **#pe R& A!@Qe Fn6.1.7601.17514997**(#pe f t[^d !Ֆ f Fn`PowerEvent handled successfully by the service.0**0>f t[^d !>f Fn`PowerEvent handled successfully by the service.M0**0$mf t[^d !>f Fn`PowerEvent handled successfully by the service. 0**of t[^d _!$mf Fn<Service stopped successfully.**(o4sf f t[^d !H7f Fn`PowerEvent handled successfully by the service.%0**0q-f t[^d !>f Fn`PowerEvent handled successfully by the service.0**0Of t[^d !q-f Fn`PowerEvent handled successfully by the service.0**0#f 2}v2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA{    gA     Application ] MediaserverA  ! ! Of Fnt$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myRR0**0) N g t[^d !#f Fn`PowerEvent handled successfully by the service.05/0**0N g t[^d !) N g Fn`PowerEvent handled successfully by the service.y0**(VQO g  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA{    gA     Application ] MediaserverA  ! ! N g Fn- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003500- TID: 00005216- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**0P g t[^d !VQO g Fn`PowerEvent handled successfully by the service.EDI0**1 g ,t O!P g Fn,wuaueng.dll496SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb50757632 (0x0000000003068000)32768 (0x00008000)11938**K_ g Z2 9!1#@1 g Fn0x40010004 Ap** ܓ g [@ F  N!K_ g$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ?/Ô*FgA['=EVENT_HIVE_LEAKA#=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA @ ** u g t[^d u!ܓ g FnRService has been successfully shut down.@ **) g >B MEDIASERVER\SQLEXPRESS**8^Y g [@ F  N!) g Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygM8**X  g Aî !@^Y g ! 2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogX**8 g [@ F  N!  g$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygM@8** g My$ #!` g  Fnd **"# g :. _! g  Fn<Service started successfully.**"# g Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**"# g >B MEDIASERVER\SQLEXPRESS**"# g >B MEDIASERVER\SQLEXPRESS**"# g 1648>B MEDIASERVER\SQLEXPRESS**"# g MIXED>; MEDIASERVER\SQLEXPRESS**"# g c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS!**h"# g 19324/05/2014 6:23:44 AM3/05/2014 8:23:44 PM>C MEDIASERVER\SQLEXPRESSch**"# g  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**"# g > C MEDIASERVER\SQLEXPRESS80::**"# g 2> C MEDIASERVER\SQLEXPRESS@**"# g u A #!N@"# g Fn**"# g u A #! N"# g Fnase** "# g 25005000>B MEDIASERVER\SQLEXPRESSst **X"# g 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSientX**"# g b7.^F #!"# g Fnfor** g b7.^F #!"# g Fn ** g master>B MEDIASERVER\SQLEXPRESSC**  g master1>~ MEDIASERVER\SQLEXPRESS **8 g model>B MEDIASERVER\SQLEXPRESS**OT g dL _!OT g# Fn<Service started successfully.**(OT g >e MEDIASERVER\SQLEXPRESSLSe**0OT g 'any'ipv61433>e MEDIASERVER\SQLEXPRESS&0**0OT g 'any'ipv41433>e MEDIASERVER\SQLEXPRESS F0**HOT g \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSIASH**XOT g \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**OT g 7806>/C MEDIASERVER\SQLEXPRESSe** OT g 0x54b3>e MEDIASERVER\SQLEXPRESSsppo **OT g >B MEDIASERVER\SQLEXPRESS0, 0**OT g >B MEDIASERVER\SQLEXPRESSspp/**OT g >e MEDIASERVER\SQLEXPRESS **0_e 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0_e 'any'ipv41433>e MEDIASERVER\SQLEXPRESSF:0A  ;"=9Lg Ma-&ff){~6** | g t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !OT g/ FF%g>9{p(xl;D EventDatacoData !Binary8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...] **| g tempdb>B MEDIASERVER\SQLEXPRESS 0**8| g  F**5=.g  ?ٶ-& ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterAq    A8 a    Application  MediaserverAD g ! #!-g? Fdi**bn/g R) k!*@5=.g@ FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 ** bn/g R) s! @bn/gA FPmsmpeg2vdec-H264VideoDecoderV2AddIn100 **(bn/g R) y! @bn/gB FV(IIS-W3SVC-MaxConcurrentRequests) (MathRecognizerEventsLicensing-EnableMathRecognizer) (Microsoft.Windows.Smc-Enabled) (TabletPC-MathInputLicensing-EnableMathInput) (TabletPCAccessories-EnableJournal) (TabletPCAccessories-EnableStickyNotes) (TabletPCCoreInkRecognitionLicensing-EnableText) (TabletPCInputPanel-EnableTIP) (TabletPCInputPanel-EnableTIPSynced) (TabletPCInputPersonalization-EnablePersonalization) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA) 55c92734-d682-4d71-983e-d6ec3f16059f7cfd4696-69a9-4af7-af36-ff3d12b6b6c8SQL\(**H bn/g R)  !@bn/gC Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **kTg R) A!@bn/gD F6.1.7601.17514r**0kTg 5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! #!+#@3g` F!**X0Mg Z2x 9!1#@3Lga F0x40010004tp:**m4_g [@ {[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=Aq       A8 a  ALFu AF"    MediaserverAD g !  N!X0MgxbMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication 깭~x/Ô*FgA[;'=EVENT_HIVE_LEAKA#c=Detail 1 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1008: Process 292 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1008\Printers\DevModePerUser **m4_g :S5G O!@m4_gc F,0x000000000x00000001F**zg Z2x #!+#@m4_gd F F**B&uzg Z2x 9!1#@zge F0x40010004indo**Pr6g [@ {  N-!B&uzglfMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication 깭~1 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1008: Process 292 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1008\Printers\DevModePerUser 000P**0(g t[& !r6gg F`PowerEvent handled successfully by the service.c3f0**0(g t[& !(gh F`PowerEvent handled successfully by the service. 1,0**020Ah t[& !(gi F`PowerEvent handled successfully by the service.(1 0**0h t[& !20Ahj F`PowerEvent handled successfully by the service.4F00**0ih t[& !hk F`PowerEvent handled successfully by the service.?)(0**0 h t[& !ihl F`PowerEvent handled successfully by the service.e770**J h :S5G O!@ hm F,0x000000000x000000014** f\h Z2x #!+#@J hn FF01**0!`wOh t[& !f\ho F`PowerEvent handled successfully by the service.b3e0**0".lh t[& !`wOhp F`PowerEvent handled successfully by the service.04F0**0#ݟh t[& !.lhq F`PowerEvent handled successfully by the service.D0**0$R۶h t[& !ݟhr F`PowerEvent handled successfully by the service.0**0%ރܶh t[& !R۶hs F`PowerEvent handled successfully by the service.0**0& Oh t[& !ރܶht F`PowerEvent handled successfully by the service.0**0'Kh t[& ! Ohu F`PowerEvent handled successfully by the service.0**(yh 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005380x000000000b4000>A MEDIASERVER\SQLEXPRESSs**)h ȁi t[& !Ֆki F`PowerEvent handled successfully by the service.r P0**0?i t[& !ȁi F`PowerEvent handled successfully by the service.st0**0@)2¸i t[& !i F`PowerEvent handled successfully by the service.\S0**0A!6i t[& !)2¸i F`PowerEvent handled successfully by the service.130**0Bn2>i t[& !!6i F`PowerEvent handled successfully by the service.-40**0Cn2>i t[& !n2>i F`PowerEvent handled successfully by the service. k0**0DSShi t[& !n2>i F`PowerEvent handled successfully by the service.\S0**0EIj t[& !SShi F`PowerEvent handled successfully by the service.u0**0F^G j t[& !Ij F`PowerEvent handled successfully by the service.Vn0**G)m j smHsmHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragAq    A8 a    Application  MediaserverAD g ! !^G j F@$defragmentationSystem Reserved$"Q)k^te**0Hڅ j smH !)m j F@$defragmentationSystem Reserved$"Q)k^w0**IU!j )8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideAq    A8 a    Application  MediaserverAD g ! !!څ j FMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**xJa''j  gȺf ! U!j F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00006136- TID: 00006120- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0KaE3j t[& !a''j F`PowerEvent handled successfully by the service.>0**0LcLj t[& !aE3j F`PowerEvent handled successfully by the service.DIA0**0MNeLj t[& !cLj F`PowerEvent handled successfully by the service.QLE0**0N{fLj t[& !NeLj F`PowerEvent handled successfully by the service.SSQ0**O{fLj ]LHMEDIASERVER\SQLEXPRESSmasterIASE**PEjLj ]LHMEDIASERVER\SQLEXPRESSmastericro**(Q]zNj 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006440x000000000e8000>A MEDIASERVER\SQLEXPRESSS**0g22k t[& !Y6"k F`PowerEvent handled successfully by the service.LEX0**0h"2k t[& !22k F`PowerEvent handled successfully by the service.0**0i Cjzk t[& !"2k F`PowerEvent handled successfully by the service.OT0**0jkEk t[& ! Cjzk F`PowerEvent handled successfully by the service.0**0kkEk t[& !kEk F`PowerEvent handled successfully by the service.52f0**0l&k t[& !kEk F`PowerEvent handled successfully by the service. F0**0m#Kk t[& !&k F`PowerEvent handled successfully by the service.R\S0**0nDKk t[& !#Kk F`PowerEvent handled successfully by the service.ESS0**0o#^l t[& !DKk F`PowerEvent handled successfully by the service.ESS0**0p il t[& !#^l F`PowerEvent handled successfully by the service.ESS0F:0A t[&  il F F,< ElfChnkqq8$S;[[=^Zn [gZ Z[[[MaF>tv6vlwp{VYi]V** qzll t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! ! il FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service.l **rTMml smHFsmHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragAq    A8 a    Application  MediaserverAD g ! !zll F@$defragmentationSystem Reserved$"Q)k^d.**0sSoml smHF !TMml F@$defragmentationSystem Reserved$"Q)k^0**t*ml  8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideAq    A8 a    Application  MediaserverAD g ! !!Soml FMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**uml MyFMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! '!*ml F**v]nl My '!ml FR**(w;pl  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! ! ]nl F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00006352- TID: 00003680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**8xq.sl smHF !;pl FB$boot optimizationTV System (C:)$"0dyl8**0yrzl t[& !q.sl F`PowerEvent handled successfully by the service.nt0**zrzl 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006440x000000000b4000>A MEDIASERVER\SQLEXPRESS0**{zl 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006440x000000000aa000>A MEDIASERVER\SQLEXPRESSo**0a4Mm t[& !a4Mm F`PowerEvent handled successfully by the service.0**0"GYm t[& !a4Mm F`PowerEvent handled successfully by the service.00,0**0׫"m t[& !"GYm F`PowerEvent handled successfully by the service.key0**0׫"m t[& !׫"m F`PowerEvent handled successfully by the service.ft:0**0^wm t[& !׫"m F`PowerEvent handled successfully by the service.0000**0k\=n t[& !^wm F`PowerEvent handled successfully by the service.0**0k\=n t[& !k\=n F`PowerEvent handled successfully by the service.erE0**0ّ?n t[& !k\=n F`PowerEvent handled successfully by the service.) (0**0Fn t[& !ّ?n F`PowerEvent handled successfully by the service.ync0**0Fn t[& !Fn F`PowerEvent handled successfully by the service.ls-0**0>-tn t[& !Fn F`PowerEvent handled successfully by the service.69a0**0n t[& !>-tn F`PowerEvent handled successfully by the service.9830**0n t[& !n F`PowerEvent handled successfully by the service.d820**0=n t[& !n F`PowerEvent handled successfully by the service.(?)0**0f+n t[& !=n F`PowerEvent handled successfully by the service. 1 0**w+n 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006440x000000000e4000>A MEDIASERVER\SQLEXPRESS)**0w+n t[& !w+n F`PowerEvent handled successfully by the service.d3b0**0R115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006440x0000000037c000>A MEDIASERVER\SQLEXPRESSU**hn 5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@s-o F0x40010004.dl** 7o [@ VY[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=Z)GuidAq  "^Z Version    ZOpcode A8 a  A [ Correlation\F4[c ActivityID[[q5RelatedActivityID Am[ ExecutionHF[4[ ProcessID[9ThreadID    MediaserverAD g !  N! /o@>B MEDIASERVER\SQLEXPRESS**`ьo [@ VY  N=!fIo$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yglygػ$<[7J.;`** o ANmAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFZ&{899daace-4868-4295-afcd-9eb8fb497561}nD`EventSourceName EventSystemAq  ^Z    Z A8 a  A [F4[[[A[F[[   Application  MediaserverAD g ! Q!@ьo p{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogQLE**8)jo [@ VY  N! o$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygl the8**)jo My #!`)jo F F**)jo :S5G>t:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**o >B MEDIASERVER\SQLEXPRESSm**o >B MEDIASERVER\SQLEXPRESS**o 1844>B MEDIASERVER\SQLEXPRESS****o MIXED>; MEDIASERVER\SQLEXPRESS**o c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS-5-2**po 164814/05/2014 10:05:44 AM14/05/2014 12:05:44 AM>C MEDIASERVER\SQLEXPRESSdp**o  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**o > C MEDIASERVER\SQLEXPRESS**o 2> C MEDIASERVER\SQLEXPRESS** o 25005000>B MEDIASERVER\SQLEXPRESS **o u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@o Fnt**o u  #! No F**XVo 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSqX**Vo master>B MEDIASERVER\SQLEXPRESS**xVo b7.vb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFZ&{1edeee53-0afe-4609-b846-d8c0b2075b1f}nWinMgmtAq  ^Z    Z A8 a  A [F4[[[A[F[[   Application  MediaserverAD g ! #!Vo Fx** Vo master1>~ MEDIASERVER\SQLEXPRESS **8Vo model>B MEDIASERVER\SQLEXPRESS**3o b7.v #!3o FRw**(3o >e MEDIASERVER\SQLEXPRESSvice**03o 'any'ipv61433>e MEDIASERVER\SQLEXPRESSvice0**03o 'any'ipv41433>e MEDIASERVER\SQLEXPRESSvice0**H3o \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS**H**X3o \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**3o 7806>/C MEDIASERVER\SQLEXPRESS y** 3o 0x54b3>e MEDIASERVER\SQLEXPRESS** **3o >B MEDIASERVER\SQLEXPRESS ser**3o >B MEDIASERVER\SQLEXPRESScess**̏o ]LHMEDIASERVER\SQLEXPRESSmaster** ̏o t[& [!̏o& F8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...LET00 **.o dvd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAq    A8 a    Application  MediaserverAD g ! _!̏o' F<Service started successfully.**.o tempdb>B MEDIASERVER\SQLEXPRESS**8.o  F`PowerEvent handled successfully by the service.k0**0$!Go t[& ! ~Fo? F`PowerEvent handled successfully by the service.#0**0t4xo t[& !$!Go@ F`PowerEvent handled successfully by the service.#0**0wo t[& !t4xoA F`PowerEvent handled successfully by the service.0**0wo t[& !woB F`PowerEvent handled successfully by the service.Y60**0o t[& !woC F`PowerEvent handled successfully by the service.SSQ0** o t[& _!oD F<Service stopped successfully.**Rdo t[& _! oE F<Service started successfully.**0p9o t[& !RdoF F`PowerEvent handled successfully by the service.0**0p9o t[& !p9oG F`PowerEvent handled successfully by the service.0**0ro t[& !p9oH F`PowerEvent handled successfully by the service.0**0C5o 2}VNm2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! roI Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myuc0**xQ]o  gȺ ! C5oJ F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00000884- TID: 00003692- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 *x**0p t[& !Q]oK F`PowerEvent handled successfully by the service.**0**0Kp t[& !pL F`PowerEvent handled successfully by the service.0F:0A t t[& KpM F,< ElfChnkfB;nTV}g. mMaNs#^>RV[&@-C.S** `G9p t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !KpM FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service.l **0q*_p t[& !`G9pN F`PowerEvent handled successfully by the service.0**0N_p t[& !q*_pO F`PowerEvent handled successfully by the service.0**0N{_p 2}Ԧ 2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! N_pP Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0**0}_p t[& !N{_pQ F`PowerEvent handled successfully by the service.0** j5sp yqyqn{jj"AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA*!= MsiInstallerAq    A8 a    Application  MediaserverAD g !  !}_pR FC:\Windows\Installer\186cf5.msi5884(NULL)(NULL)(NULL)(NULL) **.6sp 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb_log.LDFMpTvDb5000000000000052C0x00000000102c00>A MEDIASERVER\SQLEXPRESS**0e7sp t[& !.6spT F`PowerEvent handled successfully by the service.18 0**0Masp t[& !e7spU F`PowerEvent handled successfully by the service.0**8vsp ߰f߰Y{MAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=.)GuidAq  "n Version    Opcode A8 a  A Correlation\FDc ActivityIDkq5RelatedActivityID Am ExecutionHFD ProcessID9ThreadID    MediaserverAD g $mk5DUserData!  @!'Masp VMicrosoft-Windows-RestartManagerF,$r$Application IfIG5[3(>A?RmSessionEventFMwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/*L RmSessionId ,.=K UTCStartTime Masp08**  sp ߰f  4!vsp WMicrosoft-Windows-LoadPerf.GAeшm@Application   RnUdAX]EventXMLF/http://schemas.microsoft.com/win/2004/08/eventsjLoadPerf Vzparam1  }zparam2 0kbinaryDataSize (. binaryData L({890c10c3-8c2a-4fe3-a36a-9eca153d47cb}ServiceModel 4.0.0.0 ** G:sp ߰f  4w!sp\ XMicrosoft-Windows-LoadPerf.GAeшm@Application  "" SMSvcHost 4.0.0.0SMSvcHost 4.0.0.0 TT4** ֩sp ߰f  4!G:spt HYMicrosoft-Windows-LoadPerf.GAeшm@Application  (( MSDTC Bridge 4.0.0.0MSDTC Bridge 4.0.0.0 TT4**( 5sp  gȺ# gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! ! ֩spZ F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00000716- TID: 00003960- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (** 5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@;vpi F0x40010004t[&**8 Ro=vp [@ &@[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=.Aq  n     A8 a  AFDk AF    MediaserverAD g !  N !mc>B MEDIASERVER\SQLEXPRESS.**` Lvp [@ &@  N=!Uvp$nMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygRygػ$<[7J.;t[&`**!p#vp A.S AÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF.&{899daace-4868-4295-afcd-9eb8fb497561}TD`EventSourceName EventSystemAq  n     A8 a  AFDkAF   Application  MediaserverAD g ! Q!@Lvpo V{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLoga**8"vp [@ &@  N!p#vp|pMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygR8**#vp MyNY&MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! #!`vpq F **$vp :[:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Aq    A8 a    Application  MediaserverAD g ! _!vpr F<Service started successfully.88**%vp Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**&vp >B MEDIASERVER\SQLEXPRESStem**'vp >B MEDIASERVER\SQLEXPRESS455**(vp 1668>B MEDIASERVER\SQLEXPRESSs **)vp MIXED>; MEDIASERVER\SQLEXPRESS***vp c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSrofi**p+vp 184416/05/2014 5:46:04 AM15/05/2014 7:46:04 PM>C MEDIASERVER\SQLEXPRESSowsp**,vp  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSVE**-vp > C MEDIASERVER\SQLEXPRESSles **.vp 2> C MEDIASERVER\SQLEXPRESS/** /vp 25005000>B MEDIASERVER\SQLEXPRESStS **0vp u ou YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@vp~ F**1vp u o #! Nvp F**X2vp 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**x3Evp b7.sob7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF.&{1edeee53-0afe-4609-b846-d8c0b2075b1f}TWinMgmtAq  n     A8 a  AFDkAF   Application  MediaserverAD g ! #!vp Fx**4Evp master>B MEDIASERVER\SQLEXPRESS**5Evp b7.s #!Evp FDB** 6Evp 3master1>N MEDIASERVER\SQLEXPRESSA ** 7Evp 0master1>O MEDIASERVER\SQLEXPRESS ** 8Evp master1>~ MEDIASERVER\SQLEXPRESSSe **89Evp Gvp model>B MEDIASERVER\SQLEXPRESS**(?Gvp >e MEDIASERVER\SQLEXPRESS**0AGvp 'any'ipv61433>e MEDIASERVER\SQLEXPRESS'any'ipv41433>e MEDIASERVER\SQLEXPRESS\SQL0**HCGvp \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS0.SH**XDGvp \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSLEXPX**EGvp 7806>/C MEDIASERVER\SQLEXPRESSo** FGvp 0x54b3>e MEDIASERVER\SQLEXPRESS **GGvp >B MEDIASERVER\SQLEXPRESS**Hrvp >B MEDIASERVER\SQLEXPRESSom/**Irvp d>d3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAq    A8 a    Application  MediaserverAD g ! _!rvp F<Service started successfully.**Jrvp ]LHMEDIASERVER\SQLEXPRESSmasterB@**Krvp tempdb>B MEDIASERVER\SQLEXPRESS**8Lrvp  System.Data.SqlClient.SqlException: A connection was successfully established with the server, but then an error occurred during the login process. (provider: Shared Memory Provider, error: 0 - No process is on the other end of the pipe.) at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception st... **Qvp :S5G:S5GS(j**Tvp ,^ !-vp FWindows2936Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS23BE8.log**Uvp ,^ !-vp FWindows2936Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS23BE9.log**Vvp ,^ !-vp FWindows2936Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS23BEA.log**Wvp ,^ !-vp FWindows2936Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.logco**X3vp ,^ Q!.vp F.Windows2936Windows: =MpT**YVvp NO|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchF.&{CA4E628D-8567-4896-AB6B-835B221F373F}TWindows Search ServiceAq  n     A8 a  AFDkAF   Application  MediaserverAD g ! s!@3vp Z(Z(Ux ҤB6;A)c= ExtraInfo  **Zvp R6R *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF.&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}T$Software Protection Platform ServiceAq  n     A8 a  AFDkAF   Application  MediaserverAD g ! #!@Vvp F**[Gvp  ?& ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterAq    A8 a    Application  MediaserverAD g ! #!vp FV**\vp R6 k!*@Gvp FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 o** ]ovp R6 s! @vp FPmsmpeg2vdec-H264VideoDecoderV2AddIn100t. **(^ovp R6 y! @ovp FV(IIS-W3SVC-MaxConcurrentRequests) (MathRecognizerEventsLicensing-EnableMathRecognizer) (Microsoft.Windows.Smc-Enabled) (TabletPC-MathInputLicensing-EnableMathInput) (TabletPCAccessories-EnableJournal) (TabletPCAccessories-EnableStickyNotes) (TabletPCCoreInkRecognitionLicensing-EnableText) (TabletPCInputPanel-EnableTIP) (TabletPCInputPanel-EnableTIPSynced) (TabletPCInputPersonalization-EnablePersonalization) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA) 55c92734-d682-4d71-983e-d6ec3f16059f7cfd4696-69a9-4af7-af36-ff3d12b6b6c8ns\W(**H _ovp R6  !@ovp Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **`ةwp R6 A!@ovp F6.1.7601.17514**axp R6 #!@ةwp Fspp**(bzxp 2B)5n!~**`Vxq  gȺ& gȺqlJG?A3M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAD{Provider!=KNameVSSAMeaEventID') QualifiersdLevelE{Task$jKeywordsAP,; TimeCreated'Uj<{ SystemTime .F EventRecordID 8aChannel Application:,;nComputer MediaserverAB8.Security[fLUserID ! ]! .q FF%g>9{p(xl/D EventDataWoData z!Binary- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004704- TID: 00003316- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 `**R"r t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerAe    A, U    Application  MediaserverA8 [ ! !Vxq F`PowerEvent handled successfully by the service.**0/S"r t[ !R"r F`PowerEvent handled successfully by the service.0**ŌT"r 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000001480x0000000009e000>A MEDIASERVER\SQLEXPRESS**ŌT"r 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000001480x0000000012e000>A MEDIASERVER\SQLEXPRESS**UXr 5=Desktop Window ManagerAe    A, U    Application  MediaserverA8 [ ! 9!1#@eYr F0x40010004a-4**-p؂Yr >B MEDIASERVER\SQLEXPRESSMicr**`tHYr [@ n![@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=6")GuidAe  "v" Version    "Opcode A, U  A## Correlation\FL#W ActivityIDs#e5RelatedActivityID Am# ExecutionHF#L# ProcessID#9ThreadID    MediaserverA8 [ !  N=!-p؂Yr|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygq%ygػ$<[7J./`**bzYr A%AÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF6"&{899daace-4868-4295-afcd-9eb8fb497561}%'8`EventSourceName EventSystemAe  v"    " A, U  A##FL#s#A#F##   Application  MediaserverA8 [ ! Q!@tHYr B){vE`Qi^_/A#W=param1 A#W=param2 A#W=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog**8 Yr [@ n!  N!bzYr0Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygq%48** Yr My+ MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAe    A, U    Application  MediaserverA8 [ ! #!` Yr F** Yr :S5G.:S5GS(j2̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonF6"&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}%'WlclntfyAe  v"    " A, U  A##FL#s#A#F##   Application  MediaserverA8 [ ! =!p Yr FSessionEnv **yYr :5:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Ae    A, U    Application  MediaserverA8 [ ! _!yYr F<Service started successfully.4.**yYr Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**yYr >B MEDIASERVER\SQLEXPRESS**yYr >B MEDIASERVER\SQLEXPRESS8 ss**yYr 1992>B MEDIASERVER\SQLEXPRESSger**yYr MIXED>; MEDIASERVER\SQLEXPRESS**yYr c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS **pyYr 166818/05/2014 3:24:35 PM18/05/2014 5:24:35 AM>C MEDIASERVER\SQLEXPRESSp**yYr  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS-**yYr > C MEDIASERVER\SQLEXPRESS842**yYr 2> C MEDIASERVER\SQLEXPRESS1**yYr u Gu YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAe    A, U    Application  MediaserverA8 [ ! #!N@yYr F01**yYr u G #! NyYr FWi** 7Yr 25005000>B MEDIASERVER\SQLEXPRESS **X7Yr 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSstryX**ΪYr master>B MEDIASERVER\SQLEXPRESSs** ΪYr master1>~ MEDIASERVER\SQLEXPRESS **xΪYr b7.OGb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF6"&{1edeee53-0afe-4609-b846-d8c0b2075b1f}%'WinMgmtAe  v"    " A, U  A##FL#s#A#F##   Application  MediaserverA8 [ ! #!ΪYr Fx**8ΪYr model>B MEDIASERVER\SQLEXPRESS**(dCYr >e MEDIASERVER\SQLEXPRESS **0۽Yr 'any'ipv61433>e MEDIASERVER\SQLEXPRESS%0**0۽Yr 'any'ipv41433>e MEDIASERVER\SQLEXPRESS29 20**H۽Yr \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSSQLH**X۽Yr \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**۽Yr 7806>/C MEDIASERVER\SQLEXPRESS** ۽Yr 0x54b3>e MEDIASERVER\SQLEXPRESS **۽Yr >B MEDIASERVER\SQLEXPRESS**tYr >B MEDIASERVER\SQLEXPRESS\Log**tYr dfd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAe    A, U    Application  MediaserverA8 [ ! _!tYr  F<Service started successfully.**tYr tempdb>B MEDIASERVER\SQLEXPRESS **tYr ]LHMEDIASERVER\SQLEXPRESSmasterERVE** ( Yr t[ [!tYr  F8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...A **8( Yr  F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004720- TID: 00001680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 nx**x5t  gȺ& ! e54t? F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004764- TID: 00000168- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0jp:t t[ !5t@ F`PowerEvent handled successfully by the service.0**q:t 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb5000000000000014C0x000000000b4000>A MEDIASERVER\SQLEXPRESS**0w4r:t t[ !q:tC F`PowerEvent handled successfully by the service.0**0ϑBt t[ !w4r:tD F`PowerEvent handled successfully by the service.0**0Ft t[ !ϑBtE F`PowerEvent handled successfully by the service.0**0SFt t[ !FtF F`PowerEvent handled successfully by the service.0**0|t t[ !SFtG F`PowerEvent handled successfully by the service.0**0}+|t 2}~%2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAe    A, U    Application  MediaserverA8 [ ! ! |tH Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0**}+|t  gȺ& M! }+|tI F\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy29\Windows\softwaredistribution\Download\8afdd89a80c9aa938accb95d92927299*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {34e66a6d-22a7-4730-92ea-84d1d57aea5b}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002040- TID: 00002008- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **}+|t  gȺ&  ! }+|tJ F@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy29\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {34e66a6d-22a7-4730-92ea-84d1d57aea5b}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002040- TID: 00002008- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 han**ߕ=}t  gȺ& ! }+|tK F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy29\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {34e66a6d-22a7-4730-92ea-84d1d57aea5b}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002040- TID: 00002008- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18  **x t  gȺ& ! ߕ=}tL F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00002040- TID: 00005076- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 Ax**0t t[ ! tM F`PowerEvent handled successfully by the service.Dl0**0xt t[ !tN F`PowerEvent handled successfully by the service.$0**0u t[ !xtO F`PowerEvent handled successfully by the service.0 t[ uP FKpM F,< ElfChnkvvXp3l-;;l;>=>:T:g9 Y: <G;MaY=Yv.\f|S_θf-V2=65~cEHnS** a u t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !uP FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service.vs **0- u t[& !a uQ F`PowerEvent handled successfully by the service. TV0**0fhu t[& !- uR F`PowerEvent handled successfully by the service.0**0u t[& !fhuS F`PowerEvent handled successfully by the service.0**2u 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb5000000000000014C0x000000000bc000>A MEDIASERVER\SQLEXPRESSRE**0_ǰu t[& !2uU F`PowerEvent handled successfully by the service.0**0u5v t[& !_ǰuV F`PowerEvent handled successfully by the service.0880**0 0qqHv t[& !u5vW F`PowerEvent handled successfully by the service.ent0**0  rHv t[& !0qqHvX F`PowerEvent handled successfully by the service.ent0**0 |v t[& ! rHvY F`PowerEvent handled successfully by the service.ent0** 2nv smH smHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragAq    A8 a    Application  MediaserverAD g ! !|vZ F@$defragmentationSystem Reserved$"Q)k^**0 'v t[& !2nv[ F`PowerEvent handled successfully by the service.0**0'v t[& !'v\ F`PowerEvent handled successfully by the service.0000**0w t[& !'v] F`PowerEvent handled successfully by the service. F0**0Zw t[& !w^ F`PowerEvent handled successfully by the service.n/0**0Zw t[& !Zw_ F`PowerEvent handled successfully by the service.00**0w t[& !Zw` F`PowerEvent handled successfully by the service.0**X $w 88۹H8͋y4AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA*!= .NET RuntimeAq    A8 a    Application  MediaserverAD g ! !wa FApplication: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at MediaPortal.Plugins.MovingPictures.LocalMediaManagement.MovieImporter.ScanAndMonitorPaths() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() X **@_w w&)we}%ƿ:AMsj5http://schemas.microsoft.com/win/2004/08/events/event#A4+=Application ErrorAq    A8 a    Application  MediaserverAD g ! !d$wb FMediaPortal.exe1.7.0.05347c7f3unknown0.0.0.000000000c000000510dba8dd16a401cf77b1f0fad172C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknown348756b1-e3a5-11e3-9165-00155872cd7b@**w $f-$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingAq    A8 a    Application  MediaserverAD g ! !_wc Fr0CLR20r3Not available0mediaportal.exe1.7.0.05347c7f3MovingPictures1.5.1.1487512b6a3c5171a5System.NullReferenceExceptionC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mediaportal.exe_fcc33c5f18a9496897105117e46ee99e49785b6_30efd0ae0348756b1-e3a5-11e3-9165-00155872cd7b0**w $f-  !wd F0AppHangB1Not available0WatchDog.exe1.7.0.05347c7c57d6f0C:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppHang_WatchDog.exe_967b62dde918b7cbc55ac41f834443c7f87ca3_30433ae30c0e06c28-e3a5-11e3-9165-00155872cd7b0**,*_w 9j9659j9'oxAMsj5http://schemas.microsoft.com/win/2004/08/events/event!A2)=Application HangAq    A8 a    Application  MediaserverAD g ! [!ewe F&WatchDog.exe1.7.0.059001cf77b2553aca4128C:\Program Files (x86)\Team MediaPortal\MediaPortal\WatchDog.exec0e06c28-e3a5-11e3-9165-00155872cd7bUnknown**Hz_w ߰9߰Y{MAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=9)GuidAq  ": Version    Y:Opcode A8 a  A: Correlation\F:c ActivityID ;q5RelatedActivityID AmG; ExecutionHFl;: ProcessID;9ThreadID    MediaserverAD g $ < ;5DUserData! @!',*_w4 f O)1Microsoft-Windows-RestartManagerF,$r$Application I2=9IG5[3(>AY=?RmSessionEventF=Mwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/*>L RmSessionId ,>=K UTCStartTime ,*_wH**Hbw ߰9 @'!'z_w4 g O)1Microsoft-Windows-RestartManagerF,$r$Application I2=,*_wLH**Hbw ߰9 @'!'bw4 h O)1Microsoft-Windows-RestartManagerF,$r$Application I2=bwH**Hw ߰9 @'!'bw4 i O)1Microsoft-Windows-RestartManagerF,$r$Application I2=bwH**@rw Z2&C&)Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@wj F0x40010004** ݍw [@ E[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=9Aq  :    Y: A8 a  A:F: ; AG;Fl;;    MediaserverAD g !  N!@rwkMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication H&C/Ô*FgA[;'=EVENT_HIVE_LEAKA#c=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA MIF **@w >B MEDIASERVER\SQLEXPRESSA**`(_سw [@ E  N=!@w0mMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygSygػ$<[7J.;`** ڊaسw AnSAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF9&{899daace-4868-4295-afcd-9eb8fb497561}TD`EventSourceName EventSystemAq  :    Y: A8 a  A:F: ;AG;Fl;;   Application  MediaserverAD g ! Q!@(_سwn V{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog@**8!سw [@ E  N!ڊaسw(oMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygSd8**"سw MyYMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! #!`سwp FL**#سw :S5G.\:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**'Uٳw >B MEDIASERVER\SQLEXPRESS**(Uٳw >B MEDIASERVER\SQLEXPRESS1888>B MEDIASERVER\SQLEXPRESSe.***Uٳw MIXED>; MEDIASERVER\SQLEXPRESS**+Uٳw c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSctio**p,Uٳw 199225/05/2014 10:52:08 AM25/05/2014 12:52:08 AM>C MEDIASERVER\SQLEXPRESSep**-Uٳw  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSio**.Uٳw > C MEDIASERVER\SQLEXPRESSerPr**/Uٳw 2> C MEDIASERVER\SQLEXPRESSor** 0Uٳw 25005000>B MEDIASERVER\SQLEXPRESSer **X1Uٳw 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSRESSX**2Uٳw u wu YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@Uٳw F**3Uٳw u w #! NUٳw FES**4(ڳw master>B MEDIASERVER\SQLEXPRESS**x5(ڳw b7.f|wb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF9&{1edeee53-0afe-4609-b846-d8c0b2075b1f}TWinMgmtAq  :    Y: A8 a  A:F: ;AG;Fl;;   Application  MediaserverAD g ! #!(ڳw Fx** 6(ڳw 1master1>N MEDIASERVER\SQLEXPRESSp ** 7(ڳw 0master1>O MEDIASERVER\SQLEXPRESS3 ** 8(ڳw master1>~ MEDIASERVER\SQLEXPRESS **89(ڳw ڳw model>B MEDIASERVER\SQLEXPRESS**@ڳw >e MEDIASERVER\SQLEXPRESS **0Aڳw 'any'ipv61433>e MEDIASERVER\SQLEXPRESSros0**0Bڳw 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HCڳw \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XDڳw \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSbjs.X**(Eڳw 7806>/C MEDIASERVER\SQLEXPRESSms/** Gڳw 0x54b3>e MEDIASERVER\SQLEXPRESS** **HZ۳w >B MEDIASERVER\SQLEXPRESS1: 0**IZ۳w >B MEDIASERVER\SQLEXPRESS260e**JZ۳w ]LHMEDIASERVER\SQLEXPRESSmaster 0],** KZ۳w t[& [!Z۳w F8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **Lsݳw dǦd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAq    A8 a    Application  MediaserverAD g ! _!Z۳w F<Service started successfully.**M U޳w ]LHMEDIASERVER\SQLEXPRESSmaster**N U޳w tempdb>B MEDIASERVER\SQLEXPRESS**8O U޳w 0**0gwRx t[& !wx F`PowerEvent handled successfully by the service.0**0h-!x t[& !wRx F`PowerEvent handled successfully by the service.0**i<"x ^8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideAq    A8 a    Application  MediaserverAD g ! !!-!x FMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**(j%x  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! ! <"x F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003840- TID: 00002460- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**8k>k2x smH !%x FB$boot optimizationTV System (C:)$"0dyl the8**0l]Jx t[& !>k2x F`PowerEvent handled successfully by the service.the0**0m^_Jx t[& !]Jx F`PowerEvent handled successfully by the service.the0**0n{Wx t[& !^_Jx F`PowerEvent handled successfully by the service.0**0o qzx t[& !{Wx F`PowerEvent handled successfully by the service.0**0pѺszx t[& ! qzx F`PowerEvent handled successfully by the service.0**0qx t[& !Ѻszx F`PowerEvent handled successfully by the service.oad0**0rVx t[& !x F`PowerEvent handled successfully by the service.miz0**0s3Թx t[& !Vx F`PowerEvent handled successfully by the service. 0**0tx t[& !3Թx F`PowerEvent handled successfully by the service.**0**u* x R^ #!@x FBAL**v* x R^ k!*@* x FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 s\stwaredistrib R^ en@* x Fext: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {34e66a6d-22a7-4730-92ea-84d1d57aea5b}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002040- TID: 00002008- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18  **x t  gȺ& ! ߕ=}tL F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00002040- TID: 00005076- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 Ax**0t t[ ! tM F`PowerEvent handled successfully by the service.Dl0**0xt t[ !tN F`PowerEvent handled successfully by the service.$0**0u t[ !xtO F`PowerEvent handled successfully by the service.0 t[ uP FKpM F,< ElfChnkww`tXZ=g@nM]vnx^_r|NIQ2v&΂~okr**w* x R&R *Ny^cAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAZ{Provider7F=KNameMicrosoft-Windows-Security-SPPF)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}`EventSourceName$Software Protection Platform ServiceAM{aEventID') Qualifiers " Version dLevelE{Task @Opcode$gjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FG ActivityIDn{5RelatedActivityIDAm ExecutionHFG ProcessID9ThreadID 8aChannel Application:];nComputer MediaserverAB.SecurityfLUserID ! - !@* x FnF%g>9{p(xlD EventDataoData !Binaryz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] **x_x R& A!@* x Fn6.1.7601.17514ows-**yCx R& #!@_x Fner**zA'y t[~t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA{    gA     Application ] MediaserverA  ! !Cx Fn`PowerEvent handled successfully by the service.**0{nX y t[~ !A'y Fn`PowerEvent handled successfully by the service.0**0| y t[~ !nX y Fn`PowerEvent handled successfully by the service.0**}"y ]LHMEDIASERVER\SQLEXPRESSmaster/**(~ky"y 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000002700x000000000aa000>A MEDIASERVER\SQLEXPRESS**0z t[~ !z Fn`PowerEvent handled successfully by the service.590**0z t[~ !z Fn`PowerEvent handled successfully by the service.0**9IOz 0**0az t[~ !`z Fn`PowerEvent handled successfully by the service.lia0**0{ t[~ !az Fn`PowerEvent handled successfully by the service.'0**0jR{ t[~ !{ Fn`PowerEvent handled successfully by the service.@0**0E{ t[~ !jR{ Fn`PowerEvent handled successfully by the service.0**09115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005040x00000000434000>A MEDIASERVER\SQLEXPRESS**R| Z2knMZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@| Fn0x40010004S\M**z| >B MEDIASERVER\SQLEXPRESSz**hvS| [@ ~o[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N=!z|(Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygrygػ$<[7J.\MSSh**vS| Ar.\AÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA{      @ gA   AFGnAF   Application ] MediaserverA  ! Q!@vS| 2v{vE`Qi^_A#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog>**8 'T| [@ ~o  N!vS|,Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygr SQ8** 'T| :S5Gx:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**T| >B MEDIASERVER\SQLEXPRESS**T| >B MEDIASERVER\SQLEXPRESS**T| 2040>B MEDIASERVER\SQLEXPRESS**T| MIXED>; MEDIASERVER\SQLEXPRESS**T| c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS FӨ**pT| 188831/05/2014 7:02:44 PM31/05/2014 9:02:44 AM>C MEDIASERVER\SQLEXPRESSQLEp**T|  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**T| > C MEDIASERVER\SQLEXPRESS2> C MEDIASERVER\SQLEXPRESSZ** T| 25005000>B MEDIASERVER\SQLEXPRESS **T| u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA{    gA     Application ] MediaserverA  ! #!N@T| FnEX**T| u  #! NT| Fn**X9XU| 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSeachX**U| master>B MEDIASERVER\SQLEXPRESS\**xU| b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!U| Fnoux** U| 1master1>N MEDIASERVER\SQLEXPRESSv ** U| 0master1>O MEDIASERVER\SQLEXPRESSx ** U| master1>~ MEDIASERVER\SQLEXPRESS= **U| b7. #!U| Fn **8U| model>B MEDIASERVER\SQLEXPRESSF**(fV| >e MEDIASERVER\SQLEXPRESS**0fV| 'any'ipv61433>e MEDIASERVER\SQLEXPRESSindo0**0fV| 'any'ipv41433>e MEDIASERVER\SQLEXPRESS60**fV| >B MEDIASERVER\SQLEXPRESS**HfV| \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSndoH**XfV| \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSO|0X**fV| 7806>/C MEDIASERVER\SQLEXPRESS-A** fV| 0x54b3>e MEDIASERVER\SQLEXPRESSG; **!W| >B MEDIASERVER\SQLEXPRESSZ(θ**!W|  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...000 **!W| tempdb>B MEDIASERVER\SQLEXPRESS**8!W|  Fn by** |  ?~ ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA{    gA     Application ] MediaserverA  ! #!ٟ|? Fni** | R& k!*@ |@ FnHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H  | R&  !@ |A Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **AS| R& A!@ |B Fn6.1.7601.17514**X| R& #!@AS|C Fn****%| $Q o!X|D FnL0WindowsUpdateFailureNot available07.6.7600.25680072efe00000000-0000-0000-0000-000000000000Scan101Unmanaged0028d3002-e8ba-11e3-990d-00155872cd7b0/**d| $Q i!%|E FnF0WindowsUpdateFailureNot available07.6.7600.25680072efe00000000-0000-0000-0000-000000000000Scan101UnmanagedC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.6.7600.256_f60d217b0ef5821ea0713c8e66188b7dbc489d_cab_092647ba0028d3002-e8ba-11e3-990d-00155872cd7b4sppo**0|VY| t[~ !d|F Fn`PowerEvent handled successfully by the service.en0**0<| t[~ !|VY|G Fn`PowerEvent handled successfully by the service.8-40**0| t[~ !<|H Fn`PowerEvent handled successfully by the service.ll: W0**ʼn-| smHv.smHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragA{    gA     Application ] MediaserverA  ! !|I Fn@$defragmentationSystem Reserved$"Q)k^by**0@| smHv !ʼn-|J Fn@$defragmentationSystem Reserved$"Q)k^y0he service. &8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA{    gA     Application ] MediaserverA  ! p!@|K F ElfChnkpp(0o)=ee=>d sdicd;eweMcF4Nw vWq{>F,*u6c9gq**PS| &8y  \PMAAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAR{Provider/=KName SideBySideAMsaEventID') QualifiersdLevelE{Task$jKeywordsAP:; TimeCreated'cj<{ SystemTime .F EventRecordID 8aChannel Application::;nComputer MediaserverABF.SecurityifLUserID ! ?!!@|K FF%g>9{p(xl=D EventDataeoData !BinaryMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe* P**i| MyvMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAs    A: c    Application  MediaserverAF i ! '!S|L F**]u| Myv '!i|M F**(T%|  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAs    A: c    Application  MediaserverAF i ! ! ]u|N F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003688- TID: 00003120- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**Y$r} t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerAs    A: c    Application  MediaserverAF i ! !T%|O F`PowerEvent handled successfully by the service.4, **0r} t[ !Y$r}P F`PowerEvent handled successfully by the service.bb0**0s4} t[ !r}Q F`PowerEvent handled successfully by the service.140**0TX} t[ !s4}R F`PowerEvent handled successfully by the service..760**0TX} t[ !TX}S F`PowerEvent handled successfully by the service.i#0**0TX} t[ !TX}T F`PowerEvent handled successfully by the service. 0**VX} 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005400x00000000058000>A MEDIASERVER\SQLEXPRESS**`} $defragmentationTV System (C:)$"Q)k^0**0`A} t[ !}h F`PowerEvent handled successfully by the service.{0**0`A} t[ !`A}i F`PowerEvent handled successfully by the service.|0**0d} t[ !`A}j F`PowerEvent handled successfully by the service.|0**0f`} t[ !d}k F`PowerEvent handled successfully by the service.|0**0I`} t[ !f`}l F`PowerEvent handled successfully by the service.m/0**00~ t[ !I`}m F`PowerEvent handled successfully by the service.er0**0 [4~ t[ !0~n F`PowerEvent handled successfully by the service.300**0!*9~ t[ ![4~o F`PowerEvent handled successfully by the service.**0**0"e~ t[ !*9~p F`PowerEvent handled successfully by the service.0**0#i~ t[ !e~q F`PowerEvent handled successfully by the service.0**0$i~ t[ !i~r F`PowerEvent handled successfully by the service.\T0**0%4wӗ~ t[ !i~s F`PowerEvent handled successfully by the service.A0**&ԗ~ 8 !4wӗ~t FApplication: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at MediaPortal.Plugins.MovingPictures.LocalMediaManagement.MovieImporter.ScanAndMonitorPaths() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() Mp**p'-!~ w( !dԗ~u FMediaPortal.exe1.7.0.05347c7f3unknown0.0.0.000000000c0000005111cec2d18001cf7e97cf7e598fC:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknown12469f3e-ea8b-11e3-990d-00155872cd7bep**@(1~ $F, !-!~v Fr0CLR20r3Not available0mediaportal.exe1.7.0.05347c7f3MovingPictures1.5.1.1487512b6a3c5171a5System.NullReferenceExceptionC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mediaportal.exe_fcc33c5f18a9496897105117e46ee99e49785b6_05df6025012469f3e-ea8b-11e3-990d-00155872cd7b0 @**)?22~ Z2v`(Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAs    A: c    Application  MediaserverAF i ! 9!1#@1~w F0x40010004 F** *4~ [@ 6c[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=c)GuidAs  ">d Version    dOpcode A: c  Ad Correlation\Fee ActivityID;es5RelatedActivityID Amwe ExecutionHFee ProcessIDe9ThreadID    MediaserverAF i !  N!?22~ xMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication 9gv`/Ô*FgA[='=EVENT_HIVE_LEAKA#e=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 604 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA E **+7~ >B MEDIASERVER\SQLEXPRESSA**`,xm~ [@ 6c  N=!7~,zMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygWqygػ$<[7J.=`**-Bn~ AöqAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFc&{899daace-4868-4295-afcd-9eb8fb497561} sF`EventSourceName EventSystemAs  >d    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! Q!@xm~{ *u{vE`Qi^_=A#e=param1 A#e=param2 A#e=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogp**8.jq~ [@ 6c  N!Bn~ <|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygWq8**/r~ :S5Gw:S5GS(jd    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! O!@jq~} F,0x000000000x00000001 **0Iv~ ̬8{̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonFc&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538} sWlclntfyAs  >d    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! =!pr~~ FSessionEnvon**1Q~ Myv #!`Iv~ FFn**2d8~ ::R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1As    A: c    Application  MediaserverAF i ! _!Q~ F<Service started successfully.**3d8~ Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**4d8~ >B MEDIASERVER\SQLEXPRESSoft **5d8~ >B MEDIASERVER\SQLEXPRESS4-bi**6d8~ 444>B MEDIASERVER\SQLEXPRESS**7d8~ MIXED>; MEDIASERVER\SQLEXPRESS**8Џ~ c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSQLEX**h9Џ~ 20403/06/2014 5:24:00 AM2/06/2014 7:24:00 PM>C MEDIASERVER\SQLEXPRESSh**:i~  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**;i~ > C MEDIASERVER\SQLEXPRESSQLEX**<i~ 2> C MEDIASERVER\SQLEXPRESSic**=i~ u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAs    A: c    Application  MediaserverAF i ! #!N@i~ F**>r_~ u  #! Ni~ F!** ?&$~ 25005000>B MEDIASERVER\SQLEXPRESSi **X@~ 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESS X**xA~ b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFc&{1edeee53-0afe-4609-b846-d8c0b2075b1f} sWinMgmtAs  >d    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! #!~ Fx**B蟘~ master>B MEDIASERVER\SQLEXPRESS** Cp~ 1master1>N MEDIASERVER\SQLEXPRESS ** Dp~ 0master1>O MEDIASERVER\SQLEXPRESS ** Ep~ master1>~ MEDIASERVER\SQLEXPRESS! **8F~ master12605376393>] MEDIASERVER\SQLEXPRESS8**G4K~ b7. #!~ F**8H~ model>B MEDIASERVER\SQLEXPRESS**HMޥ~ >B MEDIASERVER\SQLEXPRESSf**PQw~ >e MEDIASERVER\SQLEXPRESSema**0QQw~ 'any'ipv61433>e MEDIASERVER\SQLEXPRESSplic0**0RQw~ 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HSQw~ \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XT~ \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**U~ 7806>/C MEDIASERVER\SQLEXPRESS** V~ 0x54b3>e MEDIASERVER\SQLEXPRESS **W~~ >B MEDIASERVER\SQLEXPRESS|**X~~ dvd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAs    A: c    Application  MediaserverAF i ! _!~~ F<Service started successfully.**YA~ 8 m!~~ FJApplication: MPExtended.Applications.ServiceConfigurator.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.Windows.Markup.XamlParseException Stack: at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) at System.Windows.Threading.DispatcherOperation.InvokeImpl() at System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Windows.Threading.DispatcherOperation.Invoke() at System.Windows.Threading.Dispatcher.ProcessQueue() at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) at System.Windows.Threading.Dispatcher.InvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame) at System.Windows.Application.RunDispatcher(System.Object) at System.Windows.Application.RunInternal(System.Windows.Window) at System.Windows.Application.Run(System.Windows.Window) at MPExtended.Applications.ServiceConfigurator.App.Main() /**ZA~ ]LHMEDIASERVER\SQLEXPRESSmaster** \٨~ t[ [!٨~ F8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **]Br~ tempdb>B MEDIASERVER\SQLEXPRESSr**8^Br~ d    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! s!@^~ Z(>Z(Ux ҤB6=A)e= ExtraInfo  **(kMĘ~ d    d A: c  AdFe;eAweFee   Application  MediaserverAF i ! #!@7`~ F**p)~  ?N ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterAs    A: c    Application  MediaserverAF i ! #!d~ F R ti*@)~ F"Q)k^y0he service. &8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA{    gA     Application ] MediaserverA  ! p!@|K F ElfChnkqq$v=g@nM]qn6t^:VkzE:o&6x~[^k**` q)~ R&R *Ny^cAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAZ{Provider7F=KNameMicrosoft-Windows-Security-SPPF)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}`EventSourceName$Software Protection Platform ServiceAM{aEventID') Qualifiers " Version dLevelE{Task @Opcode$gjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FG ActivityIDn{5RelatedActivityIDAm ExecutionHFG ProcessID9ThreadID 8aChannel Application:];nComputer MediaserverAB.SecurityfLUserID ! !*@)~ FnF%g>9{p(xlD EventDataoData !BinaryHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 ` **H r)~ R&  !@)~ Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] FH **sY~ R& A!@)~ Fn6.1.7601.17514oft**tdw~ R& #!@Y~ Fn**u`?~ t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA{    gA     Application ] MediaserverA  ! !dw~ Fn`PowerEvent handled successfully by the service.**0vN@~ t[ !`?~ Fn`PowerEvent handled successfully by the service.0**0wz~ t[ !N@~ Fn`PowerEvent handled successfully by the service.ss0**0xw~ t[ !z~ Fn`PowerEvent handled successfully by the service.aM0**0y +j~ t[ !w~ Fn`PowerEvent handled successfully by the service.on0**zj~ R& #!@ +j~ Fnra**{j~ R& k!*@j~ FnHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H |j~ R&  !@j~ Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] sH **}~ R& A!@j~ Fn6.1.7601.17514**0~, 2}^62}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA{    gA     Application ] MediaserverA  ! ! ~ Fnt$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0**Jl R& #!@, Fn**(DM  gȺ^: gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA{    gA     Application ] MediaserverA  ! ! Jl Fn- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003624- TID: 00003880- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**0?/- t[ !DM Fn`PowerEvent handled successfully by the service.0**0}c t[ !?/- Fn`PowerEvent handled successfully by the service.0**0}c t[ !}c Fn`PowerEvent handled successfully by the service. F0**0A t[ !}c Fn`PowerEvent handled successfully by the service. F0**0@հ t[ !A Fn`PowerEvent handled successfully by the service. F0**0@հ t[ !@հ Fn`PowerEvent handled successfully by the service. F0**0A t[ !@հ Fn`PowerEvent handled successfully by the service. F0** $E$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingA{    gA     Application ] MediaserverA  ! #!A Fn0PnPGenericDriverFoundNot available0x64USB\VID_04E8&PID_6860&REV_0400C:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_627939aa4eaad5f23ff5748fa434d5e2e7b5429_cab_1462440607f2ff8e2-ebb1-11e3-afe2-00155872cd7b4**0{  t[ ! Fn`PowerEvent handled successfully by the service.~0**0{  t[ !{  Fn`PowerEvent handled successfully by the service.~0**0^ t[ !{  Fn`PowerEvent handled successfully by the service.~0**0 t[ !^ Fn`PowerEvent handled successfully by the service.~0**0 t[ ! Fn`PowerEvent handled successfully by the service.~0**0x t[ ! Fn`PowerEvent handled successfully by the service.~0**0q+ t[ !x Fn`PowerEvent handled successfully by the service.~0**0q+ t[ !q+ Fn`PowerEvent handled successfully by the service.n. 0**0__2 t[ !q+ Fn`PowerEvent handled successfully by the service.) 0**0T t[ !__2 Fn`PowerEvent handled successfully by the service.Run0**0nT t[ !T Fn`PowerEvent handled successfully by the service.nIn0**0ܢU t[ !nT Fn`PowerEvent handled successfully by the service.ng.0**YFU Z2XZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@ܢU Fn0x40010004** U [@ ~[[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N!YFU `Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 깅^X/Ô*FgA['=EVENT_HIVE_LEAKA#=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 632 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 632 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 632 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 632 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 632 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA  ** 45U t[ u!U FnRService has been successfully shut down.K **TU >B MEDIASERVER\SQLEXPRESS-**`U [@ ~[  N=!TU <Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygkygػ$<[7J.42`**U Ak^6AÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA{      @ gA   AFGnAF   Application ] MediaserverA  ! Q!@U :o{vE`Qi^_A#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog**8*#U [@ ~[  N!UMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygk8***#U MyqgMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA{    gA     Application ] MediaserverA  ! #!`*#U Fn ***#U :S5Gt:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**U >B MEDIASERVER\SQLEXPRESS**U >B MEDIASERVER\SQLEXPRESS**U 1732>B MEDIASERVER\SQLEXPRESSion**U MIXED>; MEDIASERVER\SQLEXPRESS**U c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS>>**pU 4445/06/2014 10:32:45 AM5/06/2014 12:32:45 AM>C MEDIASERVER\SQLEXPRESS7p**U  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**U > C MEDIASERVER\SQLEXPRESS**U 2> C MEDIASERVER\SQLEXPRESSL **U u ΍u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA{    gA     Application ] MediaserverA  ! #!N@U Fn**U u ΍ #! NU Fn** U 25005000>B MEDIASERVER\SQLEXPRESS: **XU 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSiasX**xU b7.΍b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!U Fnx**U b7. #!U Fnb**U master>B MEDIASERVER\SQLEXPRESS**U dd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA{    gA     Application ] MediaserverA  ! _!U Fn<Service started successfully.** U master1>~ MEDIASERVER\SQLEXPRESS F **8U model>B MEDIASERVER\SQLEXPRESS**GOU >e MEDIASERVER\SQLEXPRESSRESS**0GOU 'any'ipv61433>e MEDIASERVER\SQLEXPRESSESS0**0GOU 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HGOU \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XGOU \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**GOU 7806>/C MEDIASERVER\SQLEXPRESS** GOU 0x54b3>e MEDIASERVER\SQLEXPRESS **GOU >B MEDIASERVER\SQLEXPRESS]LHMEDIASERVER\SQLEXPRESSmaster** U t[ [!U Fn8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...ndo **U >B MEDIASERVER\SQLEXPRESSject**U tempdb>B MEDIASERVER\SQLEXPRESSh**8U 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005400x0000000002c000>A MEDIASERVER\SQLEXPRESS**0w t[ !w1 Fn`PowerEvent handled successfully by the service.0**0p t[ !w2 Fn`PowerEvent handled successfully by the service.A0**0lNq t[ !p3 Fn`PowerEvent handled successfully by the service.F10**0/q t[ !lNq4 Fn`PowerEvent handled successfully by the service.0**04x t[ !/q5 Fn`PowerEvent handled successfully by the service.)0**0hLy t[ !4x6 Fn`PowerEvent handled successfully by the service.0**02Ny t[ !hLy7 Fn`PowerEvent handled successfully by the service. F0**0[ t[ !2Ny8 Fn`PowerEvent handled successfully by the service.\P0**0n t[ ![9 Fn`PowerEvent handled successfully by the service. 0    t[ n: Fnp!@|K F ElfChnknn8fov;=-#CgV Ma^~*&M pdw!F.J%1!** 1 t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !n: FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service. **0 t[& !1; F`PowerEvent handled successfully by the service.)0**0@ 2}v2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! < Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my/T0**(ҁ  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! ! @= F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003792- TID: 00004688- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**ҁ Z2Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@ҁ> F0x40010004 0x** ҁ [@ [@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=V)GuidAq  " Version    Opcode A8 a  AC Correlation\Flc ActivityIDq5RelatedActivityID Am ExecutionHFl ProcessID9ThreadID    MediaserverAD g !  N!ҁl?Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 깑/Ô*FgA[;'=EVENT_HIVE_LEAKA#c=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 600 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA  **%Ӂ >B MEDIASERVER\SQLEXPRESSo**`9Ӂ [@   N=!%ӁAMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygw!ygػ$<[7J.;ess`***9Ӂ A!vAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFV&{899daace-4868-4295-afcd-9eb8fb497561}-#D`EventSourceName EventSystemAq       A8 a  ACFlAF   Application  MediaserverAD g ! Q!@9ӁB J%{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog, 0**8:Ӂ [@   N!*9Ӂ$CMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygw!me/s8**":Ӂ My'MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! #!`:ӁD F[(**":Ӂ :S5G*:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSy**":Ӂ >B MEDIASERVER\SQLEXPRESS**":Ӂ >B MEDIASERVER\SQLEXPRESS**":Ӂ 1812>B MEDIASERVER\SQLEXPRESSgȺ^:**":Ӂ MIXED>; MEDIASERVER\SQLEXPRESS**":Ӂ c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSsystem3**p":Ӂ 17327/06/2014 8:02:25 AM6/06/2014 10:02:25 PM>C MEDIASERVER\SQLEXPRESSp**":Ӂ  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**":Ӂ > C MEDIASERVER\SQLEXPRESS**":Ӂ 2> C MEDIASERVER\SQLEXPRESS** ":Ӂ 25005000>B MEDIASERVER\SQLEXPRESS **":Ӂ u Du YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@":ӁS Fti**L;Ӂ u D #! N":ӁT F **XL;Ӂ 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSx64X**L;Ӂ master>B MEDIASERVER\SQLEXPRESS**  O;Ӂ master1>~ MEDIASERVER\SQLEXPRESS **8 O;Ӂ model>B MEDIASERVER\SQLEXPRESSby**|=Ӂ >e MEDIASERVER\SQLEXPRESSdled**0|=Ӂ 'any'ipv61433>e MEDIASERVER\SQLEXPRESS=0**0|=Ӂ 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**H|=Ӂ \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSn/H**X|=Ӂ \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS X**(|=Ӂ 7806>/C MEDIASERVER\SQLEXPRESS26** |=Ӂ 0x54b3>e MEDIASERVER\SQLEXPRESS262 **|=Ӂ >B MEDIASERVER\SQLEXPRESS-21**|=Ӂ >B MEDIASERVER\SQLEXPRESS\S-**|=Ӂ  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **@Ӂ ,p,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTAq    A8 a    Application  MediaserverAD g ! s!f@Ӂm FPWindows3308Windows: 060176010000tio** @Ӂ ,p Q!,@Ӂn F.Windows3308Windows: **!@Ӂ ,p !-@Ӂo FWindows3308Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS24627.log{**"@Ӂ tempdb>B MEDIASERVER\SQLEXPRESS**#BAӁ ,p !-@Ӂq FWindows3308Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.logi**8$BAӁ Nq My' '!1p Fd**x?Rxt  gȺ  ! Nq F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003720- TID: 00003000- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0@$ t[& !Rxt F`PowerEvent handled successfully by the service.vid0**0Ag$ t[& !$ F`PowerEvent handled successfully by the service.ata0**0B t[& !g$ F`PowerEvent handled successfully by the service.The0**0Cr  t[& ! F`PowerEvent handled successfully by the service.ata0**0D  t[& !r  F`PowerEvent handled successfully by the service.nne0**0E  t[& !  F`PowerEvent handled successfully by the service.erv0**F9R͂ 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005340x000000000ec000>A MEDIASERVER\SQLEXPRESS**0Gd9 t[& !9R͂ F`PowerEvent handled successfully by the service.pdb0**0H t[& !d9 F`PowerEvent handled successfully by the service.L0**0I0E  t[& ! F`PowerEvent handled successfully by the service.rro0**0J$Q2 t[& !0E  F`PowerEvent handled successfully by the service. 0**0KbX: t[& !$Q2 F`PowerEvent handled successfully by the service.RVE0**0L^Z= t[& !bX: F`PowerEvent handled successfully by the service.{0**0MA t[& !^Z= F`PowerEvent handled successfully by the service.0**0NFA t[& !A F`PowerEvent handled successfully by the service.0**0OC t[& !FA F`PowerEvent handled successfully by the service.0**0Poа t[& !C F`PowerEvent handled successfully by the service.0**Q2Ұ 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005340x00000000b36000>A MEDIASERVER\SQLEXPRESSo**0R2Ұ t[& !2Ұ F`PowerEvent handled successfully by the service.ear0**0Sփ t[& !2Ұ F`PowerEvent handled successfully by the service. A0**0TH] t[& !փ F`PowerEvent handled successfully by the service.0**0UH] t[& !H] F`PowerEvent handled successfully by the service.0**0V  t[& !H] F`PowerEvent handled successfully by the service.0**0WN t[& !  F`PowerEvent handled successfully by the service.0**0XN t[& !N F`PowerEvent handled successfully by the service.em30**0YҪ[ t[& !N F`PowerEvent handled successfully by the service.0000**0Z4} t[& !Ҫ[ F`PowerEvent handled successfully by the service.ule0**0[T t[& !4} F`PowerEvent handled successfully by the service.ll,0**h\ 2}v ! T Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my55h**]if  gȺ  M!  F Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {fb17905f-633c-454b-95fd-57511c1093ae}- Code: WRTDELET00000313- Call: WRTDELET00000248- PID: 00006092- TID: 00002944- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 hm**x^1ͫ  gȺ  ! if F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00006092- TID: 00003724- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 1,x**0_&ٜ t[& !1ͫ F`PowerEvent handled successfully by the service.(1 0**0`?⠄ t[& !&ٜ F`PowerEvent handled successfully by the service.1, 0**0aM t[& !?⠄ F`PowerEvent handled successfully by the service.(1 0**0b7 t[& !M F`PowerEvent handled successfully by the service., 10**c7 315c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005340x000000000e8000>A MEDIASERVER\SQLEXPRESS**0dv t[& !7 F`PowerEvent handled successfully by the service.VER0**0eY t[& !v F`PowerEvent handled successfully by the service.RVE0**0fq t[& !Y F`PowerEvent handled successfully by the service.p_m0**gq GCF&>L48C**oVU R&R *Ny^cAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAZ{Provider7F=KNameMicrosoft-Windows-Security-SPPF)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}`EventSourceName$Software Protection Platform ServiceAM{aEventID') Qualifiers " Version dLevelE{Task @Opcode$gjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FG ActivityIDn{5RelatedActivityIDAm ExecutionHFG ProcessID9ThreadID 8aChannel Application:];nComputer MediaserverAB.SecurityfLUserID ! - !@VU FnF%g>9{p(xlD EventDataoData !Binaryz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] **p%Z R& A!@VU Fn6.1.7601.17514ion**q{&q R& #!@%Z Fned**r\ t[~t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA{    gA     Application ] MediaserverA  ! !{&q Fn`PowerEvent handled successfully by the service.\Ha**0s\ t[~ !\ Fn`PowerEvent handled successfully by the service.ic0**0t' t[~ !\ Fn`PowerEvent handled successfully by the service.790**0u=떅 2}2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA{    gA     Application ] MediaserverA  ! ! ' Fnt$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myA0**vi8  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA{    gA     Application ] MediaserverA  ! M! =떅 Fn Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {fb535f1f-373d-4bb4-bbe8-ef205ec6ece2}- Code: WRTDELET00000313- Call: WRTDELET00000248- PID: 00005340- TID: 00004084- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **0wM t[~ !i8 Fn`PowerEvent handled successfully by the service.0**xxN  gȺ ! M Fn- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005340- TID: 00001724- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0y!`R t[~ !N Fn`PowerEvent handled successfully by the service.os0**0z t[~ !!`R Fn`PowerEvent handled successfully by the service. 0**{ď t[~ _! Fn<Service stopped successfully.**|ܪ t[~ _!ď Fn<Service started successfully.**x}:C  gȺ ! ܪ Fn- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004480- TID: 00004360- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**~(F t[~ _!:C Fn<Service stopped successfully.**HJ .2Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@q  Fn0x40010004** 1 [@ 4[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N!UMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication 8>2/Ô*FgA['=EVENT_HIVE_LEAKA#=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 608 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 608 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 608 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 608 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 608 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA mas ** Ȱ t[~ u!1 FnRService has been successfully shut down.SQ **r  . a!B@Ȱ Fn>>B MEDIASERVER\SQLEXPRESS C@**`eO [@ 4  N=!r $Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygGCygػ$<[7J.`**O AæCAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA{      @ gA   AFGnAF   Application ] MediaserverA  ! Q!@eO F{vE`Qi^_A#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog****8(P [@ 4  N!OMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygGCLEXP8**(P MyI>.MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA{    gA     Application ] MediaserverA  ! #!`(P Fn**(P :>L:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1A{    gA     Application ] MediaserverA  ! _!(P Fn<Service started successfully.**(P . !B@(P Fn>Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSS**(P . a!B@(P Fn>>B MEDIASERVER\SQLEXPRESS**(P . a!B@(P Fn>>B MEDIASERVER\SQLEXPRESSm**(P . k!B@(P Fn >1636>B MEDIASERVER\SQLEXPRESSSQL**(P . m!;@(P Fn >MIXED>; MEDIASERVER\SQLEXPRESSSS**(P . !B@(P Fn>c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**p(P . !C@(P Fnb>181212/06/2014 5:41:04 AM11/06/2014 7:41:04 PM>C MEDIASERVER\SQLEXPRESSp**(P . ]!B@(P Fn> -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**(P . a! C@(P Fn>> C MEDIASERVER\SQLEXPRESSquer**(P . e! C@(P Fn>2> C MEDIASERVER\SQLEXPRESS** (P . u!B@(P Fn>25005000>B MEDIASERVER\SQLEXPRESS **x|Q b7.V_b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!(P FnVEx**|Q u bV_u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA{    gA     Application ] MediaserverA  ! #!N@|Q Fnmi**|Q u b #! N|Q Fn**|Q b7.V_ #!|Q Fn**X|Q . !C@|Q FnH>000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSlX**UR . o!B@|Q Fn>master>B MEDIASERVER\SQLEXPRESSr** UR . s!~ @UR Fn>master1>~ MEDIASERVER\SQLEXPRESSlog **8UR . !@UR FnL00SQLEXPRESSL MEDIASERVER\SQLEXPRESSmasterlo8**(UR . y!VJ@UR Fn L1saLVJ MEDIASERVER\SQLEXPRESSmaster at(**@UR . !B@UR Fn(LmssqlsystemresourceLB MEDIASERVER\SQLEXPRESSmasterC@**0UR . !@UR FnL10.00.2531L MEDIASERVER\SQLEXPRESSmasterQL0**HUR . !D@UR Fn.LMEDIASERVER\SQLEXPRESSLD MEDIASERVER\SQLEXPRESSmasterinH**UR . m!B@UR Fn >model>B MEDIASERVER\SQLEXPRESSq**(UR . y!B@UR Fn LmsdbLB MEDIASERVER\SQLEXPRESSmaster(**UR . a!e@UR Fn>>e MEDIASERVER\SQLEXPRESS**0UR . !e@UR Fn >'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0UR . !e@UR Fn >'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HUR . !e@UR Fn:>\\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XUR . !e@UR FnH>\\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX**UR . k!/C@UR Fn >7806>/C MEDIASERVER\SQLEXPRESS** UR . q!e@UR Fn>0x54b3>e MEDIASERVER\SQLEXPRESS̬ **R . a!B@UR Fn>>B MEDIASERVER\SQLEXPRESSaste**R . a!B@R Fn>>B MEDIASERVER\SQLEXPRESS****R . ;!HR FnLsa Reason: Failed to open the explicitly specified database. [CLIENT: fe80::952f:f825:41b2:6937%17]LHMEDIASERVER\SQLEXPRESSmasterA** R t[~ [!R Fn8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **R d>d3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA{    gA     Application ] MediaserverA  ! _!R Fn<Service started successfully.**R . o!B@R Fn>tempdb>B MEDIASERVER\SQLEXPRESSn**8R . !%@R FnLService BrokerL% MEDIASERVER\SQLEXPRESSmasteren8**@R . !%@R Fn&LDatabase MirroringL% MEDIASERVER\SQLEXPRESSmaster83@**R . o!%@R FnLL% MEDIASERVER\SQLEXPRESSmasterb**6 X . o!P @R FnLLP MEDIASERVER\SQLEXPRESSmaster,**ͣX R& #!@6 X Fn 1,**ͣX R& k!*@ͣX FnHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 )]**c. }!B@@u FnLMpTvDbLB MEDIASERVER\SQLEXPRESSmaster*(**0 . !B@ FnLxplog70.dllLB MEDIASERVER\SQLEXPRESSmaster0**` . !@ FnFLxplog70.dll2007.100.1600xp_msverL MEDIASERVER\SQLEXPRESSmaster`**e t[~ _! Fn<Service started successfully.**X   ?~ ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA{    gA     Application ] MediaserverA  ! #!e Fn**XJ R& #!@X  Fnser**0ʕʅ t[~ !XJ Fn`PowerEvent handled successfully by the service.ser0**0cʅ t[~ !ʕʅ Fn`PowerEvent handled successfully by the service.ser0**0d˅ t[~ !cʅ Fn`PowerEvent handled successfully by the service.ser0**Khf˅ t[~ _!d˅ Fn<Service stopped successfully.\**(hj˅ . }!B@Khf˅ FnLMpTvDbLB MEDIASERVER\SQLEXPRESSmaster(**ۅ t[~ _!hj˅ Fn<Service started successfully.r**0~ t[~ !ۅ Fn`PowerEvent handled successfully by the service.ser0**0i t[~ !~ Fn`PowerEvent handled successfully by the service.ser0**0lx t[~ !i Fn`PowerEvent handled successfully by the service.ser0**0/@ t[~ !lx Fn`PowerEvent handled successfully by the service.ser0**0aC t[~ !/@  Fn`PowerEvent handled successfully by the service.ser0**0F t[~ !aC! Fn`PowerEvent handled successfully by the service.ser0**0Uh t[~ !F" Fn`PowerEvent handled successfully by the service.ser0**Uh . _!A@Uh# Fn>115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005480x000000002b8000>A MEDIASERVER\SQLEXPRESS**0Uh t[~ !Uh$ Fn`PowerEvent handled successfully by the service.0**0' t[~ !Uh% Fn`PowerEvent handled successfully by the service. 0**Nx Z2>2 9!1#@'& Fn0x40010004Cont**u  [@ 4  No!Nx'Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 8X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA ll** . a!B@u ( Fn>>B MEDIASERVER\SQLEXPRESSogra**85I [@ 4  N!)Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygGCd8**XI AæC !@5I* F 2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogX**8L _!. !B@bJ0 Fn>Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**bJ . a!B@bJ1 Fn>>B MEDIASERVER\SQLEXPRESSV**bJ . a!B@bJ2 Fn>>B MEDIASERVER\SQLEXPRESSws\s**bJ . k!B@bJ3 Fn >1700>B MEDIASERVER\SQLEXPRESS000**bJ . m!;@bJ4 Fn >MIXED>; MEDIASERVER\SQLEXPRESSt:**bJ . !B@bJ5 Fn>c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**pbJ . !C@bJ6 Fnb>163612/06/2014 5:58:05 PM12/06/2014 7:58:05 AM>C MEDIASERVER\SQLEXPRESSthep**bJ . ]!B@bJ7 Fn> -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**bJ . a! C@bJ8 Fn>> C MEDIASERVER\SQLEXPRESS**bJ . e! C@bJ9 Fn>2> C MEDIASERVER\SQLEXPRESS**bJ u b #!N@bJ: Fnser** bJ . u!B@bJ; Fn>25005000>B MEDIASERVER\SQLEXPRESSby **bJ u b #! NbJ< Fn**XbJ . !C@bJ= FnH>000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSpX@|K F ElfChnk||h55T"I~ Y = u0F  4 Mo"6E=>5-@n.ν**bJ  F"F%g>9{p(xlID EventDataqoData !Binary>master>B MEDIASERVER\SQLEXPRESS**mK b7.>b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-WMIF0)Guid&{1edeee53-0afe-4609-b846-d8c0b2075b1f}R`EventSourceNameWinMgmtA  " Version    F Opcode AF o  A Correlation\F q ActivityID 5RelatedActivityIDAm4 ExecutionHFY ProcessID~ 9ThreadID   Application  MediaserverAR u ! #!bJ? F"** mK master1>~ MEDIASERVER\SQLEXPRESS 0 **mK b7.> #!mKA F"18**8mK model>B MEDIASERVER\SQLEXPRESS**(L >e MEDIASERVER\SQLEXPRESS08/**0L 'any'ipv61433>e MEDIASERVER\SQLEXPRESS 0**0L 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HL \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XL \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS5hX**L 7806>/C MEDIASERVER\SQLEXPRESS ** L 0x54b3>e MEDIASERVER\SQLEXPRESS\Wi **&L >B MEDIASERVER\SQLEXPRESSema**&L >B MEDIASERVER\SQLEXPRESSppli** &L t[ t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA    AF o    Application  MediaserverAR u ! [!&LR F"8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: A connection was successfully established with the server, but then an error occurred during the login process. (provider: TCP Provider, error: 0 - The network connection was aborted by the local system.) at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception ... **&L tempdb>B MEDIASERVER\SQLEXPRESS**8O 0**0$a}c t[  !ar F"`PowerEvent handled successfully by the service.DIA0**0%>Ɔ t[  !a}cs F"`PowerEvent handled successfully by the service.ASE0**0&҆ t[  !>Ɔt F"`PowerEvent handled successfully by the service.R\S0**0'҆ t[  !҆u F"`PowerEvent handled successfully by the service.ME0**0(Ն t[  !҆v F"`PowerEvent handled successfully by the service.MED0**0)-ن t[  !Նw F"`PowerEvent handled successfully by the service.ESS0**0*̖^ن t[  !-نx F"`PowerEvent handled successfully by the service.B0**0+x t[  !̖^نy F"`PowerEvent handled successfully by the service.ERV0**0,O t[  !xz F"`PowerEvent handled successfully by the service.EXP0**0-O t[  !O{ F"`PowerEvent handled successfully by the service.EXP0**0.k t[  !O| F"`PowerEvent handled successfully by the service.EXP0**0/ t[  !k} F"`PowerEvent handled successfully by the service.DIA0**00 t[  !~ F"`PowerEvent handled successfully by the service.ql\0**015 t[  ! F"`PowerEvent handled successfully by the service./C 0**02Ӌ t[  !5 F"`PowerEvent handled successfully by the service.IAS0**03. t[  !Ӌ F"`PowerEvent handled successfully by the service.ESS0**4A smH.|&smHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragA    AF o    Application  MediaserverAR u ! !. F"@$defragmentationSystem Reserved$"Q)k^****05e.H smH.| !A F"@$defragmentationSystem Reserved$"Q)k^a0**6RA. nvA8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA    AF o    Application  MediaserverAR u ! !!e.H F"Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**7. My憄.|MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    AF o    Application  MediaserverAR u ! '!RA. F"**82 My憄 '!. F"e**(9 l  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA    AF o    Application  MediaserverAR u ! ! 2 F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005860- TID: 00002988- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**8:' smH.| ! l F"B$boot optimizationTV System (C:)$"0dyl.8**0;$! t[  !' F"`PowerEvent handled successfully by the service.0**0<$! t[  !$! F"`PowerEvent handled successfully by the service.0**0=L t[  !$! F"`PowerEvent handled successfully by the service.V>.0**0>iñ t[  !L F"`PowerEvent handled successfully by the service.0**0?iñ t[  !iñ F"`PowerEvent handled successfully by the service.0**0@%r>! t[  !iñ F"`PowerEvent handled successfully by the service.msf0**0A%|: t[  !%r>! F"`PowerEvent handled successfully by the service.em30**B: 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000001140x0000000049a000>A MEDIASERVER\SQLEXPRESS0**0C: t[  !: F"`PowerEvent handled successfully by the service.nen0**0De t[  !: F"`PowerEvent handled successfully by the service.0**0Eyg t[  !e F"`PowerEvent handled successfully by the service.S-W0**0F)g t[  !yg F"`PowerEvent handled successfully by the service.ath0**0GuF t[  !)g F"`PowerEvent handled successfully by the service.el-0**0H  t[  !uF F"`PowerEvent handled successfully by the service.ice0**0IA\ t[  !  F"`PowerEvent handled successfully by the service.c920**0Ji͈ t[  !A\ F"`PowerEvent handled successfully by the service.0**KNi͈ 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000001140x00000000182000>A MEDIASERVER\SQLEXPRESS9**Q 7 n !!6Aq6 F"Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exelX**xh3:  gȺ ! w>7 F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005128- TID: 00002452- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0i++@c t[  !3: F"`PowerEvent handled successfully by the service.0**0jX\Ac t[  !++@c F"`PowerEvent handled successfully by the service.0**0k xܩ t[  !X\Ac F"`PowerEvent handled successfully by the service.0**lݩ RvA #!@ xܩ F" by**mݩ RvA k!*@ݩ F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H nݩ RvA  !@ݩ F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] XPH **oy RvA A!@ݩ F"6.1.7601.17514er P**p  RvA #!@y F"**0q] smH.| !  F"@$defragmentationSystem Reserved$"Q)k^0**0rR smH.| !] F"@$defragmentationSystem Reserved$"Q)k^0**0s( t[  !R F"`PowerEvent handled successfully by the service.-0**0t( t[  !( F"`PowerEvent handled successfully by the service.0x0**0u_3 t[  !( F"`PowerEvent handled successfully by the service.ft-0**0v,V t[  !_3 F"`PowerEvent handled successfully by the service. A0**0wV t[  !,V F"`PowerEvent handled successfully by the service.0**0x8o t[  !V F"`PowerEvent handled successfully by the service.r 20**0y, t[  !8o F"`PowerEvent handled successfully by the service.> (0**0zg t[  !, F"`PowerEvent handled successfully by the service. F0**0{,1 t[  !g F"`PowerEvent handled successfully by the service. 0**|2 Z2.Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@,1 F"0x40010004  [@ [@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=0A      F  AF o  A F   A4 FY ~     MediaserverAR u !  N !2 Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ./Ô*FgA[I'=EVENT_HIVE_LEAKA#q=Detail x6 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 920 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA  F8 ElfChnk} } `m/G=Uf?mMFV}kFuT!r)&**}3 [@ &[@ 5ņAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAY{Provider6F=KNameX)GuidAMzaEventID'X) Qualifiers " Version dLevelE{Task ?Opcode$fjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FF ActivityIDmz5RelatedActivityID Am ExecutionHFF ProcessID9ThreadID "aChannel:F;nComputer MediaserverAB.SecurityfLUserID !  N< !2 Microsoft-Windows-User Profiles Service鱉ZDD XEApplication /Ô*FAD EventData'=EVENT_HIVE_LEAKA5GoData=Detail x6 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 920 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA **@~u[A [@ &  N!3 Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 1 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000_Classes: Process 920 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES B@@**8SC S 9{p(J> G !Binary>>B MEDIASERVER\SQLEXPRESS8**`L? [@ &  N=!SC SlMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygygػ$<[7J.K`**׎ AAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFX&{899daace-4868-4295-afcd-9eb8fb497561}U`EventSourceName EventSystemAz      ? fA   AFFmAF   Application F MediaserverA  ! Q!@L? r{vE`Qi^_A#G=param1 A#G=param2 A#G=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogO**׎ :S5G:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**  >B MEDIASERVER\SQLEXPRESST**  >B MEDIASERVER\SQLEXPRESS**  1584>B MEDIASERVER\SQLEXPRESS**  MIXED>; MEDIASERVER\SQLEXPRESS@**  c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSR\SQ**p  170019/06/2014 5:51:19 PM19/06/2014 7:51:19 AM>C MEDIASERVER\SQLEXPRESSp**   -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS** > C MEDIASERVER\SQLEXPRESS** 2> C MEDIASERVER\SQLEXPRESSg**  25005000>B MEDIASERVER\SQLEXPRESScr **X<: 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSws: X**<: u ~=u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAz    fA     Application F MediaserverA  ! #!N@<: F**<: u ~= #! N<: F**ґ master>B MEDIASERVER\SQLEXPRESS** ґ 1master1>N MEDIASERVER\SQLEXPRESSt ** ґ 0master1>O MEDIASERVER\SQLEXPRESS ** ґ master1>~ MEDIASERVER\SQLEXPRESS **8ґ master1121724722>] MEDIASERVER\SQLEXPRESS8**8ik model>B MEDIASERVER\SQLEXPRESS-d**( >e MEDIASERVER\SQLEXPRESS[0xC**0 'any'ipv61433>e MEDIASERVER\SQLEXPRESSorit0**0 'any'ipv41433>e MEDIASERVER\SQLEXPRESS 1, 0**H \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSac9H**X \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS)(?)X** dTd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAz    fA     Application F MediaserverA  ! _! F<Service started successfully.** 7806>/C MEDIASERVER\SQLEXPRESS [(**  0x54b3>e MEDIASERVER\SQLEXPRESS01.1 ** >B MEDIASERVER\SQLEXPRESS [CLIENT: 192.168.178.27]>#CMEDIASERVER\SQLEXPRESS@** >B MEDIASERVER\SQLEXPRESS**  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...Po **-5 ]LHMEDIASERVER\SQLEXPRESSmaster**x-5 b7.k~=b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFX&{1edeee53-0afe-4609-b846-d8c0b2075b1f}UWinMgmtAz      ? fA   AFFmAF   Application F MediaserverA  ! #!-5 Fx**͔ b7.k #!-5 Fsuc**͔ tempdb>B MEDIASERVER\SQLEXPRESSt**8͔ $defragmentationTV System (C:)$"Q)k^0**0ό t[._ !EY" F`PowerEvent handled successfully by the service.0**0ό t[._ !ό# F`PowerEvent handled successfully by the service.0**0vь t[._ !ό$ F`PowerEvent handled successfully by the service.0**0҆Ҍ 2}Զ2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAz    fA     Application F MediaserverA  ! ! vь% Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0**x'!  gȺF ! ҆Ҍ& F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004656- TID: 00001640- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0 t[._ !'!' F`PowerEvent handled successfully by the service.ho0**0 t[._ !( F`PowerEvent handled successfully by the service.0**0J t[._ !) F`PowerEvent handled successfully by the service.ite0**0J t[._ !J* F`PowerEvent handled successfully by the service.d4-0**0Y` t[._ !J+ F`PowerEvent handled successfully by the service.0**0ct t[._ !Y`, F`PowerEvent handled successfully by the service.e0**0,IV t[._ !ct- F`PowerEvent handled successfully by the service.f0**0,IV t[._ !,IV. F`PowerEvent handled successfully by the service.g0**0r t[._ !,IV/ F`PowerEvent handled successfully by the service.oke0**0Zڗ t[._ !r0 F`PowerEvent handled successfully by the service.30**0tڗ t[._ !Zڗ1 F`PowerEvent handled successfully by the service.- Use0**0AJ} t[._ !tڗ2 F`PowerEvent handled successfully by the service.ull0**&%~ Z2Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAz    fA     Application F MediaserverA  ! 9!1#@AJ}3 F0x40010004** [@ &  No!&%~ 4Microsoft-Windows-User Profiles Service鱉ZDD XEApplication X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA 89**Ŝ >B MEDIASERVER\SQLEXPRESS0000**868 [@ &  N!Ŝ6Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg5: 88**XZ} A !@687 r 2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog(?)(X**8 [@ &  N!Z}8Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg1-648** Myn& #!`9 F3d6** :S5G O!@: F,0x000000000x00000001C**ci ̬8! =!p; FSessionEnv0]**ci :) _!ci< F<Service started successfully. **ci u ~= #!N@ci= F )]**ci u ~= #! Nci> F**ci Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**ci >B MEDIASERVER\SQLEXPRESS**ci >B MEDIASERVER\SQLEXPRESS**ci 1952>B MEDIASERVER\SQLEXPRESS_**ci MIXED>; MEDIASERVER\SQLEXPRESSt-**ci c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**pci 158422/06/2014 8:41:23 PM22/06/2014 10:41:23 AM>C MEDIASERVER\SQLEXPRESSp**ci  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**ci > C MEDIASERVER\SQLEXPRESS|** 2> C MEDIASERVER\SQLEXPRESS**  25005000>B MEDIASERVER\SQLEXPRESS **X 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSAX**'3 b7.k #!K FF **'3 b7.k #!'3L F**'3 master>B MEDIASERVER\SQLEXPRESS**  '3 1master1>N MEDIASERVER\SQLEXPRESS **  '3 0master1>O MEDIASERVER\SQLEXPRESS **  '3 master1>~ MEDIASERVER\SQLEXPRESSsk ** '3 dT _!'3Q F<Service started successfully.**8  9{p(xlID EventDataqoData !BinaryL10.00.2531L MEDIASERVER\SQLEXPRESSmaster0**H  model>B MEDIASERVER\SQLEXPRESSm**( Td >e MEDIASERVER\SQLEXPRESSlum**0 Td 'any'ipv61433>e MEDIASERVER\SQLEXPRESSndo0**0 Td 'any'ipv41433>e MEDIASERVER\SQLEXPRESSPro0**H Td \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSemH**X Td \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESScroX** Td 7806>/C MEDIASERVER\SQLEXPRESSofi**  Td 0x54b3>e MEDIASERVER\SQLEXPRESSlass ** Td >B MEDIASERVER\SQLEXPRESS2184**p Td  [CLIENT: 2001:44b8:2130:6900:2433:e13a:4d01:981f]>#CMEDIASERVER\SQLEXPRESSp**  >B MEDIASERVER\SQLEXPRESS!**   System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... ** . ]LHMEDIASERVER\SQLEXPRESSmasterSes** . ,%,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTA    AF o    Application  MediaserverAR u ! s!f.f F"PWindows3284Windows: 060176010000 **  ,% Q!,.g F".Windows3284Windows:  F**  ,% !-h F"Windows3284Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS24EC8.log**  ,% !-i F"Windows3284Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log**  ,% Q!.j F".Windows3284Windows: 1.0 ** ) ,O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/eventEAF=Microsoft-Windows-SearchF-)Guid&{CA4E628D-8567-4896-AB6B-835B221F373F}U.R`EventSourceNameWindows Search ServiceA  ". Version    "/Opcode AF o  A/ Correlation\F/q ActivityID/5RelatedActivityIDAm0 ExecutionHF50/ ProcessIDZ09ThreadID   Application  MediaserverAR u ! s!@k Z(r1Z(Ux ҤB6IA)q= ExtraInfo  ** ) tempdb>B MEDIASERVER\SQLEXPRESS**8 ) @**! ) 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005400x000000000e8000>A MEDIASERVER\SQLEXPRESS**08 p t[~ !WW F"`PowerEvent handled successfully by the service.0**09 p t[~ !p F"`PowerEvent handled successfully by the service.e50**0: H t[~ !p F"`PowerEvent handled successfully by the service.0**0; h t[~ !H F"`PowerEvent handled successfully by the service.͔0**0<  t[~ !h F"`PowerEvent handled successfully by the service.0**0= 3 t[~ ! F"`PowerEvent handled successfully by the service.0**0> |7 t[~ !3 F"`PowerEvent handled successfully by the service.%@0**0? ˭8 t[~ !|7 F"`PowerEvent handled successfully by the service.0**0@  t[~ !˭8 F"`PowerEvent handled successfully by the service.0**0A 0bA t[~ !  F"`PowerEvent handled successfully by the service.040**0B bA t[~ !0bA F"`PowerEvent handled successfully by the service. 0**0C B t[~ !bA F"`PowerEvent handled successfully by the service.0**0D F t[~ !B F"`PowerEvent handled successfully by the service.0**0E U F t[~ !F F"`PowerEvent handled successfully by the service.**0**0F ][R t[~ !U F F"`PowerEvent handled successfully by the service.Dat0**0G $~ t[~ !][R F"`PowerEvent handled successfully by the service.ndo0**0H (q? t[~ !$~ F"`PowerEvent handled successfully by the service.ear0**0I d݀ 2}~2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    AF o    Application  MediaserverAR u ! ! (q? F"t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my5h0**xJ   gȺ_ ! d݀ F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00000696- TID: 00004768- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 zx**0K "0 t[~ ! F"`PowerEvent handled successfully by the service.0**0L j t[~ !"0 F"`PowerEvent handled successfully by the service.ma0**0M  t[~ !j F"`PowerEvent handled successfully by the service.tio0**0N J'y t[~ ! F"`PowerEvent handled successfully by the service.0**O y  t[~ !! F"`PowerEvent handled successfully by the service.0**0l ,ҧo t[~ !tj> F"`PowerEvent handled successfully by the service.0**0m ,ҧo t[~ !,ҧo F"`PowerEvent handled successfully by the service.0**0n 5E t[~ !,ҧo F"`PowerEvent handled successfully by the service.0**0o 8ґ t[~ !5E F"`PowerEvent handled successfully by the service.0**0p >ґ t[~ !8ґ F"`PowerEvent handled successfully by the service.0**0q  t[~ !>ґ F"`PowerEvent handled successfully by the service.0**0r >`$ t[~ ! F"`PowerEvent handled successfully by the service.0**0s k#b$ t[~ !>`$ F"`PowerEvent handled successfully by the service.sc0**0t ( t[~ !k#b$ F"`PowerEvent handled successfully by the service.0**0u E t[~ !( F"`PowerEvent handled successfully by the service.0**v bE 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005400x0000000006e000>A MEDIASERVER\SQLEXPRESSe**w bE ]LHMEDIASERVER\SQLEXPRESSmaster79-1**({ ve (**0|  t[~ !ve F"`PowerEvent handled successfully by the service.es 0**0}  t[~ ! F"`PowerEvent handled successfully by the service.ssD0**0~ *q t[~ ! F"`PowerEvent handled successfully by the service.sof0**h \ 2}~ ! *q F"t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myh**x W   gȺ_ ! \ F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003044- TID: 00005396- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0 [< smH !W  F"@$defragmentationSystem Reserved$"Q)k^e0**0 jY smH ![< F"@$defragmentationSystem Reserved$"Q)k^0**X z‡ ^X !!jY F"Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exexX**x f#  gȺ_ ! z‡ F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004408- TID: 00005912- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x** T Myv\ '!f# F"** 4( Myv\ '!T F"**8 ^ smH !4( F"B$boot optimizationTV System (C:)$"0dyl8**0 bw t[~ !^ F"`PowerEvent handled successfully by the service.0**0 Ĉ t[~ !bw F"`PowerEvent handled successfully by the service.RVE0**0 Z! smH !Ĉ F"@$defragmentationSystem Reserved$"Q)k^20**0  smH !Z! F"@$defragmentationSystem Reserved$"Q)k^ 0**( *  smH }! F"6$defragmentationvideo (E:)$"Q)k^\M(**(  smH !*  F"8$defragmentationbackup (F:)$"Q)k^(**0 +Z t[~ ! F"`PowerEvent handled successfully by the service.0**0 X t[~ !+Z F"`PowerEvent handled successfully by the service.0**0  t[~ !X F"`PowerEvent handled successfully by the service.0**0 >͓ t[~ !  F"`PowerEvent handled successfully by the service.0**0 n͓ t[~ !>͓ F"`PowerEvent handled successfully by the service.0**0 / t[~ !n͓ F"`PowerEvent handled successfully by the service.VER0**0  4 t[~ !/ F"`PowerEvent handled successfully by the service.XPR0**0 J? t[~ ! 4 F"`PowerEvent handled successfully by the service.0**0 ܭd? t[~ !J? F"`PowerEvent handled successfully by the service. 0**0 ܭd? t[~ !ܭd? F"`PowerEvent handled successfully by the service.0**0 ` t[~ !ܭd? F"`PowerEvent handled successfully by the service.0**0 Ԗ t[~ !` F"`PowerEvent handled successfully by the service.0**0 Ԗ t[~ !Ԗ F"`PowerEvent handled successfully by the service.Vf0\Microsoft\SystemCer@F8 ElfChnk ) ) h ~*;܌=~E+g> ɋ{Ma&vv u&f-bEv**  H4 t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !Ԗ FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service.m **0 ?5 2}F2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! H4 Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0**( 8  gȺv gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! ! ?5 F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005764- TID: 00003336- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**0 xc t[& !8 F`PowerEvent handled successfully by the service.!0**0 xc t[& !xc F`PowerEvent handled successfully by the service.0**0 nk t[& !xc F`PowerEvent handled successfully by the service.0**0 :s t[& !nk F`PowerEvent handled successfully by the service.0**0 &8c4000000008001A1A002564560034160894>E MEDIASERVER\SQLEXPRESSow0** 僖 ƍt)ƍt:M(;קAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= SQLDUMPERAq    A8 a    Application  MediaserverAD g ! A!݃ FSQLException64sqlservr.exe2007.100.2531.00000000049D03092sqlservr.exe2007.100.2531.00000000049D0309200000000001961AE70000000000000278** Aǖ $f-$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingAq    A8 a    Application  MediaserverAD g ! o!僖 FL6889766555SQLException64Not available0sqlservr.exe2007.100.2531.00000000049D03092sqlservr.exe2007.100.2531.00000000049D0309200000000001961AE70000000000000278 c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\SQLDump0001.mft c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\SQLDump0001.mdmp c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\SQLDump0001.txt c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\SQLDump0001.logC:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_sqlservr.exe_8d3bc4c48fc7c76a191b681a19a510cf4057149e_3a6a760101b41cfc5-0277-11e4-993f-00005872cd7b0ASE**0 W t[& !Aǖ F`PowerEvent handled successfully by the service.EXP0**0 QX t[& !W F`PowerEvent handled successfully by the service.ste0**0 oNqt t[& !QX F`PowerEvent handled successfully by the service.*0**0 X3 t[& !oNqt F`PowerEvent handled successfully by the service.0**0 X3 t[& !X3 F`PowerEvent handled successfully by the service.VER0**0 L t[& !X3  F`PowerEvent handled successfully by the service.y.0**h '} 2}F ! L  Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my5Fh**x   gȺv  ! '}  F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003776- TID: 00000300- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 nx**0 ). t[& !  F`PowerEvent handled successfully by the service.A0**0 O t[& !).  F`PowerEvent handled successfully by the service. 0** -O smHA&smHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragAq    A8 a    Application  MediaserverAD g ! ! O F@$defragmentationSystem Reserved$"Q)k^/p**0 XKO smHA !-O F@$defragmentationSystem Reserved$"Q)k^m0** BQ E8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideAq    A8 a    Application  MediaserverAD g ! !!XKO FMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**x AW  gȺv  ! BQ F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005996- TID: 00003344- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 f7x**( X smHA }!AW F6$defragmentationvideo (E:)$"Q)k^hm(**( X smHA !X F8$defragmentationbackup (F:)$"Q)k^ (**8 /Y smHA !X FB$boot optimizationTV System (C:)$"0dyl004F8**x ݆k  gȺv  ! /Y F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005352- TID: 00005272- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 , x**0 '}K t[& !݆k F`PowerEvent handled successfully by the service.(1 0**0 ׍K t[& !'}K F`PowerEvent handled successfully by the service., 10**0 _+?M t[& !׍K F`PowerEvent handled successfully by the service.])(0** _+?M $f- !_+?M F0NetworkDiagnosticsFrameworkV3Not available0MicrosoftAddressAcquisition [1.0]28008F906{07D37F7B-FA5E-4443-BDA7-AB107B29AFB9}AddressAcquisition [1.0]{AA537141-C1AF-4bf0-B8A3-FCF94C877AEF}rt64win7.sys7.2.1127.2008 13/07/2009 C:\Windows\System32\NDF\{5B49E4B3-E64B-49E3-9EAD-352A6410B4E8}-WER-07082014-1137.etlC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_78585a9a1168e4cbb50531f3aaa757a4c4710e0_cab_51e72f5e07c82aec8-0640-11e4-993f-00005872cd7b4** U $f- !_+?M F0NetworkDiagnosticsFrameworkV3Not available0MicrosoftAddressAcquisition [1.0]20{00000000-0000-0000-0000-000000000000}AddressAcquisition [1.0]{AA537141-C1AF-4bf0-B8A3-FCF94C877AEF}rt64win7.sys7.2.1127.2008 13/07/2009 C:\Windows\System32\NDF\{5B49E4B3-E64B-49E3-9EAD-352A6410B4E8}-WER-07082014-1137.etlC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_b617f55ff462b27678c75bfa422f46141dba3252_cab_51e7316207c82aec9-0640-11e4-993f-00005872cd7b4**0 ˳N t[& !U F`PowerEvent handled successfully by the service.0**0 ˳N t[& !˳N F`PowerEvent handled successfully by the service.0**0 "Y t[& !˳N F`PowerEvent handled successfully by the service. 0**0 \ t[& !"Y F`PowerEvent handled successfully by the service.!0**0 }Z \ t[& !\ F`PowerEvent handled successfully by the service.0**0 |] t[& !}Z \  F`PowerEvent handled successfully by the service.0**0 ._ t[& !|]! F`PowerEvent handled successfully by the service.0**0 ._ t[& !._" F`PowerEvent handled successfully by the service.0**0  t[& !._# F`PowerEvent handled successfully by the service.030**0 u t[& !$ F`PowerEvent handled successfully by the service.0**0 vB t[& !u% F`PowerEvent handled successfully by the service.MED0**0 U t[& ! vB& F`PowerEvent handled successfully by the service.ull0**0 u t[& !U' F`PowerEvent handled successfully by the service.ull0**0 u t[& !u( F`PowerEvent handled successfully by the service.ull0**0 ']H t[& !u) F`PowerEvent handled successfully by the service.ull0**0 㐙~ t[& !']H* F`PowerEvent handled successfully by the service.ull0**0 V t[& !㐙~+ F`PowerEvent handled successfully by the service.ull0**h ڶ8 2}F ! V, Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my**h**x =`  gȺv  ! ڶ8- F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005280- TID: 00005324- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0 ګ t[& !=`. F`PowerEvent handled successfully by the service.0** \⫚ dǖu)d3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAq    A8 a    Application  MediaserverAD g ! _!ګ/ F<Service stopped successfully.**  dǖu _!\⫚0 F<Service started successfully.**0 Fǚ t[& !1 F`PowerEvent handled successfully by the service.0**0 xǚ t[& !Fǚ2 F`PowerEvent handled successfully by the service.0**0 ϸΚ t[& !xǚ3 F`PowerEvent handled successfully by the service.0**0 ?A t[& !ϸΚ4 F`PowerEvent handled successfully by the service.0**0 A t[& !?A5 F`PowerEvent handled successfully by the service.n/0**0  t[& !A6 F`PowerEvent handled successfully by the service.ve0**0 Q t[& !7 F`PowerEvent handled successfully by the service.te0**0 т t[& !Q8 F`PowerEvent handled successfully by the service.- PID0**0 o  t[& !т9 F`PowerEvent handled successfully by the service.0**0 z5< t[& !o : F`PowerEvent handled successfully by the service.0**0 < t[& !z5<; F`PowerEvent handled successfully by the service.0**0 6p t[& !<< F`PowerEvent handled successfully by the service.0** +r Z2Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@6p= F0x40010004** Dw [@ v[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=>)GuidAq  "~ Version    ɋOpcode A8 a  A+ Correlation\FTc ActivityID{q5RelatedActivityID Am ExecutionHF܌T ProcessID9ThreadID    MediaserverAD g !  N!+r@Lkc#Ӭ@ >Microsoft-Windows-User Profiles Service鱉ZDD XEApplication 깉/Ô*FgA[;'=EVENT_HIVE_LEAKA#c=Detail 11 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Internet Explorer\Main Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Policies Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software Process 404 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings F**  hx t[& u!Dw? FRService has been successfully shut down.46 ** Q} >B MEDIASERVER\SQLEXPRESS5h**` ` [@ v  N=!Q}AMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygygػ$<[7J.;n`**  AFAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF>&{899daace-4868-4295-afcd-9eb8fb497561}ED`EventSourceName EventSystemAq  ~    ɋ A8 a  A+FT{AF܌   Application  MediaserverAD g ! Q!@`B b{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog885**8  [@ v  N!  CMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg8**  MyAMyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! #!`D F**  ::R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Aq    A8 a    Application  MediaserverAD g ! _!E F<Service started successfully.di**  :S5Gv:S5GS(j&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}EWinlogonAq  ~    ɋ A8 a  A+FT{AF܌   Application  MediaserverAD g ! O!@F F,0x000000000x00000001**  ̬8&̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonF>&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}EWlclntfyAq  ~    ɋ A8 a  A+FT{AF܌   Application  MediaserverAD g ! =!pG FSessionEnvser**  Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**  >B MEDIASERVER\SQLEXPRESS****  >B MEDIASERVER\SQLEXPRESS ser**  1792>B MEDIASERVER\SQLEXPRESSull**  MIXED>; MEDIASERVER\SQLEXPRESSFa**  c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**h  19529/07/2014 7:06:22 AM8/07/2014 9:06:22 PM>C MEDIASERVER\SQLEXPRESSrh**   -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**  > C MEDIASERVER\SQLEXPRESS!**  2> C MEDIASERVER\SQLEXPRESS**  u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@R F,**   25005000>B MEDIASERVER\SQLEXPRESS **  u  #! NT F**X * 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**x * b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF>&{1edeee53-0afe-4609-b846-d8c0b2075b1f}EWinMgmtAq  ~    ɋ A8 a  A+FT{AF܌   Application  MediaserverAD g ! #!*V Fx** Iû master>B MEDIASERVER\SQLEXPRESS** Iû b7. #!IûX Fled**  [ master1>~ MEDIASERVER\SQLEXPRESS\Pr **8 [ model>B MEDIASERVER\SQLEXPRESSL**H v >e MEDIASERVER\SQLEXPRESSwerE**0 v 'any'ipv61433>e MEDIASERVER\SQLEXPRESSwerE0**0 v 'any'ipv41433>e MEDIASERVER\SQLEXPRESS\Win0**H v \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS FH**X v \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX** v 7806>/C MEDIASERVER\SQLEXPRESS**  v 0x54b3>e MEDIASERVER\SQLEXPRESS ** v >B MEDIASERVER\SQLEXPRESSe="w**p v  [CLIENT: 2001:44b8:2130:6900:952f:f825:41b2:6937]>#CMEDIASERVER\SQLEXPRESSzp**  >B MEDIASERVER\SQLEXPRESSMyv\**   System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...the ** g ]LHMEDIASERVER\SQLEXPRESSmaster!**! g ,,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTAq    A8 a    Application  MediaserverAD g ! s!fgo FPWindows3324Windows: 060176010000ess**"  , Q!,gp F.Windows3324Windows: Po**#  , !-q FWindows3324Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS2502E.loge**$  , !- r FWindows3324Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log**% * , Q!. s F.Windows3324Windows:  **& * tempdb>B MEDIASERVER\SQLEXPRESS**8' * vg ^cn*** Q 9{p(xlID EventDataqoData !BinaryLLP MEDIASERVER\SQLEXPRESSmaster**+ / >O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/eventEAF=Microsoft-Windows-SearchF6)Guid&{CA4E628D-8567-4896-AB6B-835B221F373F}R`EventSourceNameWindows Search ServiceA  "  Version    j Opcode AF o  A Correlation\F q ActivityID 5RelatedActivityIDAmX ExecutionHF} ProcessID 9ThreadID   Application  MediaserverAR u ! s!@Qy Z( Z(Ux ҤB6IA)q= ExtraInfo  **, D RN R *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF6&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}$Software Protection Platform ServiceA       j  AF o  A F  AX F}     Application  MediaserverAR u ! #!@/z F"**- \  ? ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    AF o    Application  MediaserverAR u ! #!D{ F"**. \ RN  k!*@\| F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H / \ RN   !@\} F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] byH **0 5 RN  A!@\~ F"6.1.7601.17514Po**(1   { t[( !P=y F"`PowerEvent handled successfully by the service.smHA0**0? { t[( !{ F"`PowerEvent handled successfully by the service.E0**@ + } ]LHMEDIASERVER\SQLEXPRESSmaster**(A 8 5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@5Sr{ F"0x40010004tti** o [{ t[( u!PÊ{ F"RService has been successfully shut down.1 **p r{ >B MEDIASERVER\SQLEXPRESS560**hq N{ [@ [@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=6A       j  AF o  A F   AX F}      MediaserverAR u !  N=!r{ Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg ygػ$<[7J.Iicah**r #{ AnwAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF6&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA       j  AF o  A F  AX F}     Application  MediaserverAR u ! Q!@N{ {vE`Qi^_IA#q=param1 A#q=param2 A#q=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog F**8s { [@   N!#{ Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg er P8**t { Myf_MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    AF o    Application  MediaserverAR u ! #!`{ F"**u { ::R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1A    AF o    Application  MediaserverAR u ! _!{ F"<Service started successfully.og**v { Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**w { >B MEDIASERVER\SQLEXPRESSD**x { >B MEDIASERVER\SQLEXPRESS**y { 1644>B MEDIASERVER\SQLEXPRESS**z { MIXED>; MEDIASERVER\SQLEXPRESSA**{ { c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**p| { 179211/07/2014 6:14:25 AM10/07/2014 8:14:25 PM>C MEDIASERVER\SQLEXPRESSp**} {  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSr**~ { > C MEDIASERVER\SQLEXPRESS2> C MEDIASERVER\SQLEXPRESSr **  { 25005000>B MEDIASERVER\SQLEXPRESS) ** { u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    AF o    Application  MediaserverAR u ! #!N@{ F"V&**x { b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF6&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA       j  AF o  A F  AX F}     Application  MediaserverAR u ! #!{ F"MEx** E{ u  #! N{ F"** E{ b7. #!E{ F"r**X E{ 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSDATAX** E{ master>B MEDIASERVER\SQLEXPRESSS**  E{ master1>~ MEDIASERVER\SQLEXPRESSC@ **8 E{ model>B MEDIASERVER\SQLEXPRESS **( I{ >B MEDIASERVER\SQLEXPRESSA** { dǾd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA    AF o    Application  MediaserverAR u ! _!r{ F"<Service started successfully.** { tempdb>B MEDIASERVER\SQLEXPRESS**8 { >e MEDIASERVER\SQLEXPRESS**0 6{ 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0 6{ 'any'ipv41433>e MEDIASERVER\SQLEXPRESSv0**H 6{ \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSvH**X 6{ \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX** 6{ 7806>/C MEDIASERVER\SQLEXPRESS'a**  6{ 0x54b3>e MEDIASERVER\SQLEXPRESS ** 6{ >B MEDIASERVER\SQLEXPRESS**( k{ F. .EdkfVg&B'q>aN\** { :S5G&:S5GS(j9{p(xlUD EventData}oData !Binary,0x000000000x00000001 ** }M{ ,. ,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTA; \   'AR {    Application  MediaserverA^  ! s!f{ F.PWindows3084Windows: 0601760100006** }M{ ,.  Q!,}M{ F..Windows3084Windows: ven** }M{ ,.  !-}M{ F.Windows3084Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS2511B.log** }M{ ,.  !-}M{ F.Windows3084Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log** ~{ ,.  Q!.}M{ F..Windows3084Windows: tyCe** #%| O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchF&{CA4E628D-8567-4896-AB6B-835B221F373F}Windows Search ServiceA; \      'AR {  AF.AjF   Application  MediaserverA^  ! s!@~{ Z(fZ(Ux ҤB6UA)}= ExtraInfo  ** '|  ? ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA; \   'AR {    Application  MediaserverA^  ! #!#%| F.00** ' RR *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}$Software Protection Platform ServiceA; \      'AR {  AF.AjF   Application  MediaserverA^  ! #!@'| F.**  t[Nt[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA; \   'AR {    Application  MediaserverA^  ! !' F.`PowerEvent handled successfully by the service.)(?**0 ;0 t[N ! F.`PowerEvent handled successfully by the service.-640**0 cmɜ t[N !;0 F.`PowerEvent handled successfully by the service.(?)0** Y G &G zԯ6l02'AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-CAPI2F&{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}Microsoft-Windows-CAPI2A; \      'AR {  AF.AjF   Application  MediaserverA^  ! a!cmɜP F.>Friday, 4 July 2014 7:02:52 AM**P  ߰v$߰Y{MA Msj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A; \      'AR {  AF. AjF    MediaserverA^  $&.5DUserData! @!'Y`, O)1Microsoft-Windows-RestartManagerF,$r$Application I'v$IG5[3(>A'?RmSessionEventF'Mwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/*!)L RmSessionId ,R)=K UTCStartTime YP**  t[N _! F.<Service stopped successfully.** w ߰v$ @!'`, O)1Microsoft-Windows-RestartManagerF,$r$Application -֊B+-֊BMM\1A+%/RmApplicationEventF'/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/ !) $?-FullPath *j--T DisplayName (-? AppVersion "-[AppType *-, TSSessionId  $.-Status K.R)Pid  l.\inFiles =.-W<Files.File  C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\TvService.exeTVServiceC:\Program Files (x86)\LAV Filters\x86\avutil-lav-52.dllC:\Program Files (x86)\LAV Filters\x86\libbluray.dllC:\Program Files (x86)\LAV Filters\x86\avformat-lav-55.dllC:\Program Files (x86)\LAV Filters\x86\avcodec-lav-55.dllsft** < F+ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA; \   'AR {    Application  MediaserverA^  ! ! H/ָ F.- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00006004- TID: 00004008- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**0 >ʝ t[N ! S: F.`PowerEvent handled successfully by the service.0**0 /j t[N !>ʝ F.`PowerEvent handled successfully by the service.0**0 "?j t[N !/j F.`PowerEvent handled successfully by the service.0**0 _?j sa Reason: Failed to open the database configured in the login object while revalidating the login on the connection. [CLIENT: <local machine>]>HMEDIASERVER\SQLEXPRESS0**0 @j sa Reason: Failed to open the database configured in the login object while revalidating the login on the connection. [CLIENT: <local machine>]>HMEDIASERVER\SQLEXPRESS0** @j 5446>FMEDIASERVER\SQLEXPRESS ** DIj 5246>FMEDIASERVER\SQLEXPRESS**0 .k t[N !DIj F.`PowerEvent handled successfully by the service.**0**( Y7k 5=Desktop Window ManagerA; \   'AR {    Application  MediaserverA^  ! 9!1#@o$ F.0x40010004ice**  o t[N u!hwo% F.RService has been successfully shut down.s- ** 7ڟo >B MEDIASERVER\SQLEXPRESS**h o [@ >a[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A; \      'AR {  AF. AjF    MediaserverA^  !  N=!7ڟo 'Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygEdygػ$<[7J.U h** go AædAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA; \      'AR {  AF.AjF   Application  MediaserverA^  ! Q!@o( g{vE`Qi^_UA#}=param1 A#}=param2 A#}=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog**8 >[o [@ >a  N!gop)Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygEd5-18 8** >[o :S5G& O!@>[o* F.,0x000000000x00000001)** o ̬8k̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonF&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}WlclntfyA; \      'AR {  AF.AjF   Application  MediaserverA^  ! =!p>[o+ F.SessionEnvthe** Ao My6o1MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA; \   'AR {    Application  MediaserverA^  ! #!`o, F.** vo :q:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1A; \   'AR {    Application  MediaserverA^  ! _!Ao- F.<Service started successfully.** vo Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESSo** vo >B MEDIASERVER\SQLEXPRESS004** vo >B MEDIASERVER\SQLEXPRESS** vo 1868>B MEDIASERVER\SQLEXPRESS -** vo MIXED>; MEDIASERVER\SQLEXPRESS** p c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSindo**p p 164413/07/2014 5:53:53 PM13/07/2014 7:53:53 AM>C MEDIASERVER\SQLEXPRESSmizp** (p  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSF** (p u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA; \   'AR {    Application  MediaserverA^  ! #!N@(p6 F.Na** (p u  #! N(p7 F.Code:** (p > C MEDIASERVER\SQLEXPRESS** p 2> C MEDIASERVER\SQLEXPRESSOp**  { p 25005000>B MEDIASERVER\SQLEXPRESSri **X Vp 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSe95}X**x Vp b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA; \      'AR {  AF.AjF   Application  MediaserverA^  ! #!Vp< F.Wrx** qp master>B MEDIASERVER\SQLEXPRESSH**  qp  F.>master1>~ MEDIASERVER\SQLEXPRESS004 **8 s;p master12597219528>] MEDIASERVER\SQLEXPRESS8**8 lp model>B MEDIASERVER\SQLEXPRESS **H 'p >e MEDIASERVER\SQLEXPRESS&**0 p 'any'ipv61433>e MEDIASERVER\SQLEXPRESSA0**0 p 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**H p \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**X p \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSV]zX** p 7806>/C MEDIASERVER\SQLEXPRESS**  p 0x54b3>e MEDIASERVER\SQLEXPRESS ** p >B MEDIASERVER\SQLEXPRESS** p >B MEDIASERVER\SQLEXPRESS** p  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...RLO ** p tempdb>B MEDIASERVER\SQLEXPRESS**8 p 0WindowsUpdateFailureNot available07.6.7600.25680072efe00000000-0000-0000-0000-000000000000Scan101UnmanagedC:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.6.7600.256_f60d217b0ef5821ea0713c8e66188b7dbc489d_1aa5c37b0d8195eb6-0c0a-11e4-be91-00005872cd7b4etPC**0* mf t[N !F3x F.`PowerEvent handled successfully by the service.Fil0**0+ ]f t[N !mfy F.`PowerEvent handled successfully by the service.e-d0**0, /ul t[N !]fz F.`PowerEvent handled successfully by the service.0**0- "l 2}d2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA; \   'AR {    Application  MediaserverA^  ! ! /ul{ F.t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my1,0**0. lנ t[N !"l| F.`PowerEvent handled successfully by the service.: 80**x/ i6נ  gȺ>F ! lנ} F.- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003444- TID: 00005460- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ])x**00 7ݠ t[N !i6נ~ F.`PowerEvent handled successfully by the service.5, 0**01 %. t[N !7ݠ F.`PowerEvent handled successfully by the service.])(0**02 ,) t[N !%. F.`PowerEvent handled successfully by the service.9c,0**03 ,) t[N !,) F.`PowerEvent handled successfully by the service.?)]0**04 Uo+ t[N !,) F.`PowerEvent handled successfully by the service.0**5 }p+ R #!@Uo+ F.E5Gf:S5GS(j9{p(xlD EventDataoData !BinaryHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 ` **H 7 }p+ R&  !@}p+ Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **8 #, R& A!@}p+ Fn6.1.7601.17514**9 5 R& #!@#, Fni#**: Ad t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA{    gA     Application ] MediaserverA  ! !5 Fn`PowerEvent handled successfully by the service.**0; e t[ !Ad Fn`PowerEvent handled successfully by the service.0**0<   t[ !e Fn`PowerEvent handled successfully by the service.2'0**0= + t[ !  Fn`PowerEvent handled successfully by the service.b}0**0>  t[ !+ Fn`PowerEvent handled successfully by the service.ppl0**0? *X t[ ! Fn`PowerEvent handled successfully by the service.M0**0@ N; t[ !*X Fn`PowerEvent handled successfully by the service.0**0A 4 < t[ ! N; Fn`PowerEvent handled successfully by the service.!0**0B < t[ !4 < Fn`PowerEvent handled successfully by the service.?0**C < t[ _!< Fn<Service stopped successfully.s**D <  t[ _!< Fn<Service started successfully.**0F 08j t[ !E> Fn`PowerEvent handled successfully by the service.ion0**0G ]115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005680x000000004ba000>A MEDIASERVER\SQLEXPRESS**S c 7 smHC)smHO0c<<AMsj5http://schemas.microsoft.com/win/2004/08/events/event1AB9=Microsoft-Windows-DefragA{    gA     Application ] MediaserverA  ! !115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000001480x00000000182000>A MEDIASERVER\SQLEXPRESS **0 } t[ !} Fn`PowerEvent handled successfully by the service. 0**0 k t[ !} Fn`PowerEvent handled successfully by the service.0**0  t[ !k Fn`PowerEvent handled successfully by the service.0**0  t[ ! Fn`PowerEvent handled successfully by the service.?0**0 ʌ t[ ! Fn`PowerEvent handled successfully by the service.0**0  t[ !ʌ Fn`PowerEvent handled successfully by the service.0**0  t[ ! Fn`PowerEvent handled successfully by the service.ERV0** x] ]LHMEDIASERVER\SQLEXPRESSmaster**( wC  5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@Z Fn0x40010004p** gUq >B MEDIASERVER\SQLEXPRESS5**h  [@ 6[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N=!gUqpMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg=ygػ$<[7J.h** Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS]** 1K >B MEDIASERVER\SQLEXPRESSce77** 1K >B MEDIASERVER\SQLEXPRESS 0],** 1K 1712>B MEDIASERVER\SQLEXPRESSc61** 1K MIXED>; MEDIASERVER\SQLEXPRESS, ** 1K c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS0 [0**p 1K 186824/07/2014 12:24:38 PM24/07/2014 2:24:38 AM>C MEDIASERVER\SQLEXPRESS p** 1K  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS** 1K > C MEDIASERVER\SQLEXPRESSt[N** 1K 2> C MEDIASERVER\SQLEXPRESS***  1K 25005000>B MEDIASERVER\SQLEXPRESS ** 1K u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA{    gA     Application ] MediaserverA  ! #!N@1K Fn[N** 1K u  #! N1K  Fness**X  000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSviceX**  master>B MEDIASERVER\SQLEXPRESSy**x ^| b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!  Fnucx**  ^| 1master1>N MEDIASERVER\SQLEXPRESS **  ^| 0master1>O MEDIASERVER\SQLEXPRESS **  ^| master1>~ MEDIASERVER\SQLEXPRESS00 **8 ^| model>B MEDIASERVER\SQLEXPRESS**(  F(**  >B MEDIASERVER\SQLEXPRESStem32\v**  >e MEDIASERVER\SQLEXPRESSwerE**0  'any'ipv61433>e MEDIASERVER\SQLEXPRESSwerE0**0  'any'ipv41433>e MEDIASERVER\SQLEXPRESSwerE0**H  \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSledH**X  \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS theX**  7806>/C MEDIASERVER\SQLEXPRESS\Microsoft\SystemCer*@}p+F8 ElfChnk 9 9 H`IWeI''=Oy@xW&x%'un%&v'Mo"?v$F^mw֨(FUitp6|>**   9{p(xlID EventDataqoData !Binary>0x54b3>e MEDIASERVER\SQLEXPRESS8 **  >B MEDIASERVER\SQLEXPRESS** "F  t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA    AF o    Application  MediaserverAR u ! [!"F# F"8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... b2 ** | ]LHMEDIASERVER\SQLEXPRESSmaster2431** A tempdb>B MEDIASERVER\SQLEXPRESS(** A  ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    AF o    Application  MediaserverAR u ! #!4 F"**(    _!C8 F"<Service started successfully.**X A  8F8۹H8͋y4AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA*!= .NET RuntimeA    AF o    Application  MediaserverAR u ! !~9 F"Application: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.NullReferenceException Stack: at MediaPortal.Plugins.MovingPictures.LocalMediaManagement.MovieImporter.ScanAndMonitorPaths() at System.Threading.ThreadHelper.ThreadStart_Context(System.Object) at System.Threading.ExecutionContext.runTryCode(System.Object) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode, CleanupCode, System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) at System.Threading.ThreadHelper.ThreadStart() X **@ " wFQwe}%ƿ:AMsj5http://schemas.microsoft.com/win/2004/08/events/event#A4+=Application ErrorA    AF o    Application  MediaserverAR u ! !dA : F"MediaPortal.exe1.8.0.053a6f5afunknown0.0.0.000000000c000000511c5cb4d119801cfa6e703130adbC:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknown46efe152-12da-11e4-ac6b-00155872cd7b@** 9Χ $U$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingA    AF o    Application  MediaserverAR u ! !"; F"p0CLR20r3Not available0mediaportal.exe1.8.0.053a6f5afMovingPictures1.5.1.1487512b6a3c5171a5System.NullReferenceExceptionC:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mediaportal.exe_66c6c55a368440ff46a8b8602f7a3d81d9b059_0ad33b45046efe152-12da-11e4-ac6b-00155872cd7b0** | R) #!@9Χ< F"ess**0 Qz\  t[>  !|= F"`PowerEvent handled successfully by the service.ess0**0 ?ǚ t[>  !Qz\ > F"`PowerEvent handled successfully by the service.ess0**0 YE t[>  !?ǚ? F"`PowerEvent handled successfully by the service.ess0**0 n t[>  !YE@ F"`PowerEvent handled successfully by the service.ess0**0 n t[>  ! nA F"`PowerEvent handled successfully by the service.ess0**0 2o t[>  ! nB F"`PowerEvent handled successfully by the service.ess0**0 <( t[>  !2oC F"`PowerEvent handled successfully by the service.ess0**0 e* t[>  !<(D F"`PowerEvent handled successfully by the service.ess0**0 k1 t[>  !e*E F"`PowerEvent handled successfully by the service.ess0**0 : t[>  !k1F F"`PowerEvent handled successfully by the service.ess0**0 X t[>  !:G F"`PowerEvent handled successfully by the service.ess0**0 & t[>  !XH F"`PowerEvent handled successfully by the service.ess0** ?i i)8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA    AF o    Application  MediaserverAR u ! !!&I F"Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**(   gȺm gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA    AF o    Application  MediaserverAR u ! ! ?iJ F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004416- TID: 00004712- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (** o 9j9p9j9'oxAMsj5http://schemas.microsoft.com/win/2004/08/events/event!A2)=Application HangA    AF o    Application  MediaserverAR u ! k!eK F"6SetupTv.exe1.8.0.012b401cfa7fc37a6e8f69C:\Program Files (x86)\Team MediaPortal\MediaPortal TV Server\SetupTv.exe15446b86-13f0-11e4-ac6b-00155872cd7bUnknown** 3  ߰t߰Y{MA Msj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=n%A  W&    & AF o  A'F-'T' A'F''    MediaserverAR u $vT'5DUserData! 0!'o L O)1Microsoft-Windows-Winsrv=UD$H7$֚/Application bwb'se#84tiA]x_- HungAppEventF@xMwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsj9http://manifests.microsoft.com/win/2004/08/windows/winsrv"Oy @AppName MediaPortal.exe** 5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@3 M F"0x40010004**  [@ |[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=n%A  W&    & AF o  A'F-'T' A'F''    MediaserverAR u !  N!>B MEDIASERVER\SQLEXPRESS**` Vm [@ |  N=!*1|RMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygygػ$<[7J.I`** <#n ANAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemFn%&{899daace-4868-4295-afcd-9eb8fb497561}% EventSystemA  W&    & AF o  A'F-'T'A'F''   Application  MediaserverAR u ! Q!@VmS {vE`Qi^_IA#q=param1 A#q=param2 A#q=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogN@**8 ݂q [@ |  N!<#nlTMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygXPRE8** tr :S5GF:S5GS(jN2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    AF o    Application  MediaserverAR u ! ! *l F"t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myv0** %*  gȺm M! %*m F"\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy23\Windows\softwaredistribution\Download\70bf659b42dfee7640ed0c15607040d0*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {099b2d04-1a98-42e9-ab34-b56d4a4816c5}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001204- TID: 00003680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 )** %*  gȺm  ! %*n F"@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy23\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {099b2d04-1a98-42e9-ab34-b56d4a4816c5}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001204- TID: 00003680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 07/**! |7*  gȺm ! %*o F".\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy23\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {099b2d04-1a98-42e9-ab34-b56d4a4816c5}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001204- TID: 00003680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS$**% >B MEDIASERVER\SQLEXPRESS09-**& >B MEDIASERVER\SQLEXPRESSF**' 4332>B MEDIASERVER\SQLEXPRESS**( MIXED>; MEDIASERVER\SQLEXPRESSPR**) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**p* 171225/07/2014 9:40:00 PM25/07/2014 11:40:00 AM>C MEDIASERVER\SQLEXPRESS0p**+ H  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**, H > C MEDIASERVER\SQLEXPRESS**- 'nH 2> C MEDIASERVER\SQLEXPRESSM** . 'nH 25005000>B MEDIASERVER\SQLEXPRESS **X/ H 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSsfuX**0 H master>B MEDIASERVER\SQLEXPRESSD** 1 H 1master1>N MEDIASERVER\SQLEXPRESS ** 2 H 0master1>O MEDIASERVER\SQLEXPRESSA ** 3 TH master1>~ MEDIASERVER\SQLEXPRESSIAS **84 TH model>B MEDIASERVER\SQLEXPRESSRV\SQLEXPRESS 9{p(xlID EventDataqoData !Binary LmsdbLB MEDIASERVER\SQLEXPRESSmaster**(**; H >e MEDIASERVER\SQLEXPRESS****0< H 'any'ipv61433>e MEDIASERVER\SQLEXPRESStaba0**0= H 'any'ipv41433>e MEDIASERVER\SQLEXPRESS.mi0**H> H \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSerH**X? H \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSommX**@ H 7806>/C MEDIASERVER\SQLEXPRESSsi** A H 0x54b3>e MEDIASERVER\SQLEXPRESSSql **B H >B MEDIASERVER\SQLEXPRESSovi**C I >B MEDIASERVER\SQLEXPRESSbCo**D 2I tempdb>B MEDIASERVER\SQLEXPRESS**8E 2I 2 t[. ! F"`PowerEvent handled successfully by the service. 7:0**0] >2 t[. !>2 F"`PowerEvent handled successfully by the service.[0x0**0^  t[. !>2 F"`PowerEvent handled successfully by the service.10:0**0_ J t[. !  F"`PowerEvent handled successfully by the service. [00**0` J t[. !J F"`PowerEvent handled successfully by the service.] 10**a J 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000005200x00000000182000>A MEDIASERVER\SQLEXPRESS**0c 4@g t[. !ԲJ F"`PowerEvent handled successfully by the service.Mp0**0d qm t[. !4@g F"`PowerEvent handled successfully by the service.og70**0e qm t[. !qm F"`PowerEvent handled successfully by the service.og70**0f g t[. !qm F"`PowerEvent handled successfully by the service.80**0g c  t[. !g F"`PowerEvent handled successfully by the service.nt0**0h ZZ  t[. !c  F"`PowerEvent handled successfully by the service.0**0i :Ω t[. !ZZ  F"`PowerEvent handled successfully by the service.ro0**0j :Ω t[. !:Ω F"`PowerEvent handled successfully by the service.Me0**0k ة t[. !:Ω F"`PowerEvent handled successfully by the service.io0**0l dT t[. !ة F"`PowerEvent handled successfully by the service.Ob0**0m T t[. !dT F"`PowerEvent handled successfully by the service.st0**0n L t[. !T F"`PowerEvent handled successfully by the service.Ex0**0o  t[. !L F"`PowerEvent handled successfully by the service.()0**0p  t[. ! F"`PowerEvent handled successfully by the service. 0**0q q@e t[. ! F"`PowerEvent handled successfully by the service.!d0**xr f  gȺ.) ! q@e F"- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00001436- TID: 00003348- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ix**0s SI t[. !f F"`PowerEvent handled successfully by the service.en0**0t SI t[. !SI F"`PowerEvent handled successfully by the service.A0**0u ሡ t[. !SI F"`PowerEvent handled successfully by the service.f0**0v Թ t[. !ሡ F"`PowerEvent handled successfully by the service.ap0**0w 幪 t[. !Թ F"`PowerEvent handled successfully by the service.0**0x * t[. !幪 F"`PowerEvent handled successfully by the service.0**y Ѩ 5229>FMEDIASERVER\SQLEXPRESS**z  Z2F]Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@Ѩ F"0x40010004 by** {  [@ `[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=`)GuidA  "a Version    YaOpcode AF o  Aa Correlation\Faq ActivityID b5RelatedActivityID AmGb ExecutionHFlba ProcessIDb9ThreadID    MediaserverAR u !  N!lXMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication  dF]/Ô*FgA[I'=EVENT_HIVE_LEAKA#q=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 624 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 624 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 624 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 624 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 624 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA  **| Ț >B MEDIASERVER\SQLEXPRESS3"**`} nX [@ `  N=!ȚlMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg'nygػ$<[7J.I/e`**~ |- AÆnAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF`&{899daace-4868-4295-afcd-9eb8fb497561}oR`EventSourceName EventSystemA  a    Ya AF o  AaFa bAGbFlbb   Application  MediaserverAR u ! Q!@nX q{vE`Qi^_IA#q=param1 A#q=param2 A#q=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogF"**8  [@ `  N!|-Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg'n1558**  My0 #!` F"04**  :S5Gvu:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS** 2" >B MEDIASERVER\SQLEXPRESS0 P** 2" >B MEDIASERVER\SQLEXPRESS79-** 2" 1896>B MEDIASERVER\SQLEXPRESSIS** 2" MIXED>; MEDIASERVER\SQLEXPRESSw** 2" c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**p 2" 433229/07/2014 9:21:53 AM28/07/2014 11:21:53 PM>C MEDIASERVER\SQLEXPRESS6bp** 2"  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS3f** 2" > C MEDIASERVER\SQLEXPRESSB ** 2" 2> C MEDIASERVER\SQLEXPRESSUs**  2" 25005000>B MEDIASERVER\SQLEXPRESS. **X 2" 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX** 2" u 6u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    AF o    Application  MediaserverAR u ! #!N@2" F"ar** 2" u 6 #! N2" F"<#n** Ⱥ master>B MEDIASERVER\SQLEXPRESS**  Ⱥ 1master1>N MEDIASERVER\SQLEXPRESSo **  Ⱥ 0master1>O MEDIASERVER\SQLEXPRESS **  Ⱥ master1>~ MEDIASERVER\SQLEXPRESS(v **8 Ⱥ model>B MEDIASERVER\SQLEXPRESS**(  >e MEDIASERVER\SQLEXPRESSema**0  'any'ipv61433>e MEDIASERVER\SQLEXPRESSn 0**0  'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**H  \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS/eH**X  \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS X**  7806>/C MEDIASERVER\SQLEXPRESS**   0x54b3>e MEDIASERVER\SQLEXPRESSA **  >B MEDIASERVER\SQLEXPRESSR **  >B MEDIASERVER\SQLEXPRESS**x | b7.Ϋ6b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF`&{1edeee53-0afe-4609-b846-d8c0b2075b1f}oWinMgmtA  a    Ya AF o  AaFa bAGbFlbb   Application  MediaserverAR u ! #! F"7.x** | dFd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA    AF o    Application  MediaserverAR u ! _!| F"<Service started successfully.** | b7.Ϋ #!| F"** | ]LHMEDIASERVER\SQLEXPRESSmasters31** | ]LHMEDIASERVER\SQLEXPRESSmaster **  t[. [!| F"8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ..., 0 **  tempdb>B MEDIASERVER\SQLEXPRESSc**8  115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000003CC0x000000000a0000>A MEDIASERVER\SQLEXPRESSL** Ӑ 1 t[. !l F"`PowerEvent handled successfully by the service.0**8 |-4 smHV, !>1 F"B$boot optimizationTV System (C:)$"0dyl\8crosoft\SystemCerB@7HF8 ElfChnk ` ` hT́-;@@=W?>@gR> ?T@@Ma& v **  b^d t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !|-4 FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service. **0 d t[& !b^d F`PowerEvent handled successfully by the service.0**0 ci t[& !d F`PowerEvent handled successfully by the service.0**0 i 2}Ԧ 2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! ci Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|mypi0** i  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! M! i F\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy26\Windows\softwaredistribution\Download\4763d368c554df877e76d62c8e8ad395*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {69231475-0d13-4c90-ae5f-57dc9128c231}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001408- TID: 00002680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ** i  gȺ   ! i  F@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy26\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {69231475-0d13-4c90-ae5f-57dc9128c231}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001408- TID: 00002680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ** 5 j  gȺ  ! i! F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy26\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {69231475-0d13-4c90-ae5f-57dc9128c231}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00001408- TID: 00002680- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **x   gȺ  ! 5 j" F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00001408- TID: 00001624- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0 U؇ t[& !# F`PowerEvent handled successfully by the service.0**0 U؇ t[& !U؇$ F`PowerEvent handled successfully by the service.0**0 5_ t[& !U؇% F`PowerEvent handled successfully by the service.0**0 % t[& !5_& F`PowerEvent handled successfully by the service.0**0 m t[& !%' F`PowerEvent handled successfully by the service.0**0 K% t[& !m( F`PowerEvent handled successfully by the service.5h0**0 ? t[& !K%) F`PowerEvent handled successfully by the service. Ap0**0 *k@ t[& !?* F`PowerEvent handled successfully by the service.rA0**0 0 t[& !*k@+ F`PowerEvent handled successfully by the service.Dl0**0 \ t[& !0, F`PowerEvent handled successfully by the service.0**0 #  t[& !\- F`PowerEvent handled successfully by the service. 0**0 t[* t[& !# . F`PowerEvent handled successfully by the service.<0** F>]* ]* t[& !F>]*0 F`PowerEvent handled successfully by the service.t.0**0 (N4 t[& !F>]*1 F`PowerEvent handled successfully by the service.0**0 N t[& !(N42 F`PowerEvent handled successfully by the service.0**0 `O t[& !N3 F`PowerEvent handled successfully by the service. F0**0 : "_ t[& !`O4 F`PowerEvent handled successfully by the service. F0**0 Za t[& !: "_5 F`PowerEvent handled successfully by the service. F0**0 C[a t[& !Za6 F`PowerEvent handled successfully by the service. F0**0 &s t[& !C[a7 F`PowerEvent handled successfully by the service. F0**0 }͌ t[& !&s8 F`PowerEvent handled successfully by the service. F0**0 $ t[& !}͌9 F`PowerEvent handled successfully by the service. F0**0 W t[& !$: F`PowerEvent handled successfully by the service. F0**  RN=R *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventmA.%F=Microsoft-Windows-Security-SPPFR>)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}>D`EventSourceName$Software Protection Platform ServiceAq  "W? Version    ?Opcode A8 a  A@ Correlation\F-@c ActivityIDT@q5RelatedActivityIDAm@ ExecutionHF@-@ ProcessID@9ThreadID   Application  MediaserverAD g ! #!@W; F**  RN= k!*@< FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 Po**H  RN=  !@= Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] dH ** YV RN= A!@> F6.1.7601.17514: CORS** ,Ƭ RN= #!@YV? F**0 { t[& !,Ƭ@ F`PowerEvent handled successfully by the service.0**0 { t[& !{A F`PowerEvent handled successfully by the service.0**0 > t[& !{B F`PowerEvent handled successfully by the service.0**0 ļU t[& !>C F`PowerEvent handled successfully by the service.0**0 ] t[& !ļUD F`PowerEvent handled successfully by the service.0**h zX^ 2}Ԧ  ! ]E Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my!h**x %Jn  gȺ  ! zX^F F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005324- TID: 00005280- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0 0 t[& !%JnG F`PowerEvent handled successfully by the service.0**0 ډŭ t[& !0H F`PowerEvent handled successfully by the service.mi0**0 ډŭ t[& !ډŭI F`PowerEvent handled successfully by the service.0**0  t[& !ډŭJ F`PowerEvent handled successfully by the service.0**0  t[& !K F`PowerEvent handled successfully by the service.ppl0**0 rW t[& !L F`PowerEvent handled successfully by the service.600**0 * t[& !rWM F`PowerEvent handled successfully by the service.810**  t[& _!*N F<Service stopped successfully.**( 8  t[& !.3yW F`PowerEvent handled successfully by the service.0**0 o t[& !>X F`PowerEvent handled successfully by the service.20**0 9 t[& !oY F`PowerEvent handled successfully by the service.0** o® $defragmentationTV System (C:)$"Q)k^ 60**0 P t[& !.U8m F`PowerEvent handled successfully by the service.A0**0 SP t[& !Pn F`PowerEvent handled successfully by the service.0**0! W t[& !SPo F`PowerEvent handled successfully by the service.0**0" T=q t[& !Wp F`PowerEvent handled successfully by the service.0**0# >q t[& !T=qq F`PowerEvent handled successfully by the service.!0**0$ ; t[& !>qr F`PowerEvent handled successfully by the service.0**0% ) t[& !;s F`PowerEvent handled successfully by the service.0**0& Cж t[& !)t F`PowerEvent handled successfully by the service.0**0'  t[& !Cжu F`PowerEvent handled successfully by the service.0**0( 1 t[& ! v F`PowerEvent handled successfully by the service.0**0) 1 t[& !1w F`PowerEvent handled successfully by the service.0**0* •! t[& !1x F`PowerEvent handled successfully by the service.0**0+ : t[& !•!y F`PowerEvent handled successfully by the service.0**0, : t[& !:z F`PowerEvent handled successfully by the service.0**0- Yb t[& !:{ F`PowerEvent handled successfully by the service.0**0. Pz t[& !Yb| F`PowerEvent handled successfully by the service.0**0/ F t[& !Pz} F`PowerEvent handled successfully by the service.0**00 T t[& !F~ F`PowerEvent handled successfully by the service.0**01 1IU t[& !T F`PowerEvent handled successfully by the service.0**02  t[& !1IU F`PowerEvent handled successfully by the service.0**x3 ?,  gȺ  !  F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003100- TID: 00003472- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 VEx**04 Fǰ t[& !?, F`PowerEvent handled successfully by the service.0**05 Fǰ t[& !Fǰ F`PowerEvent handled successfully by the service.ed0**06 %ɰ t[& !Fǰ F`PowerEvent handled successfully by the service.lb0**h7 ɰ 2}Ԧ  ! %ɰ Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myAh**8 ɰ  gȺ  M! ɰ F\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy32\Windows\softwaredistribution\Download\4763d368c554df877e76d62c8e8ad395*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {31e534b2-2093-484e-8f63-9f95ce4e45cc}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002564- TID: 00005200- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 RV**9 ɰ  gȺ   ! ɰ F@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy32\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {31e534b2-2093-484e-8f63-9f95ce4e45cc}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002564- TID: 00005200- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 r I**: lʰ  gȺ  ! ɰ F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy32\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {31e534b2-2093-484e-8f63-9f95ce4e45cc}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002564- TID: 00005200- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 .Ope**x; C  gȺ  ! lʰ F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00002564- TID: 00004084- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 Exx**0< #f t[& !C F`PowerEvent handled successfully by the service.VER0**0= #f t[& !#f F`PowerEvent handled successfully by the service.SQL0**0> #  t[& !#f F`PowerEvent handled successfully by the service.ASE0**0? ?Z8 t[& !#  F`PowerEvent handled successfully by the service.EXP0**0@ ?Z8 t[& !?Z8 F`PowerEvent handled successfully by the service.ste0**0A a+ t[& !?Z8 F`PowerEvent handled successfully by the service.0**0B zB t[& !a+ F`PowerEvent handled successfully by the service.0**0C zB t[& !zB F`PowerEvent handled successfully by the service. F0**0D 6-r t[& !zB F`PowerEvent handled successfully by the service.8W0**0E }‘ t[& !6-r F`PowerEvent handled successfully by the service.0**0F [ t[& !}‘ F`PowerEvent handled successfully by the service.0**0G `*H t[& ![ F`PowerEvent handled successfully by the service.p:0**0H bF˱ t[& !`*H F`PowerEvent handled successfully by the service.ch 0**0I PG˱ t[& !bF˱ F`PowerEvent handled successfully by the service.di0**0J  t[& !PG˱ F`PowerEvent handled successfully by the service. 0**0K :%  t[& ! F`PowerEvent handled successfully by the service.330**0L ~o t[& !:%  F`PowerEvent handled successfully by the service. A0**0M :G6 t[& !~o F`PowerEvent handled successfully by the service.0**0N ,dI t[& !:G6 F`PowerEvent handled successfully by the service.0**0O ,dI t[& !,dI F`PowerEvent handled successfully by the service.0**0P \O t[& !,dI F`PowerEvent handled successfully by the service.ows0**0Q t t[& !\O F`PowerEvent handled successfully by the service. 0x0**R Qt 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000006640x000000000f4000>A MEDIASERVER\SQLEXPRESS0**S Vt GFM3^D**@a (>a smH&smHO0c<9{p(xlYD EventDataoData !Binary@$defragmentationSystem Reserved$"Q)k^@**b w f8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA    +AV     Application ! MediaserverAb  ! !!(>a F2Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**(c   gȺ~ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA    +AV     Application ! MediaserverAb  ! ! w F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003332- TID: 00003024- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**(d  smH& }! F26$defragmentationvideo (E:)$"Q)k^r(**(e J smH& ! F28$defragmentationbackup (F:)$"Q)k^(**f ]?N t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA    +AV     Application ! MediaserverAb  ! !J F2`PowerEvent handled successfully by the service.**0g N t[ !]?N F2`PowerEvent handled successfully by the service.ion0**0h O t[ !N F2`PowerEvent handled successfully by the service.r C0**xi P  gȺ~  ! O F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005008- TID: 00005068- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 D: x**0j Q 2}Ծ2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    +AV     Application ! MediaserverAb  ! ! P F2t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myCl0**k Q  gȺ~  M! Q F2\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy35\Windows\softwaredistribution\Download\4763d368c554df877e76d62c8e8ad395*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {d85b6979-3ee7-4dc1-a5ab-e46e9647a4ae}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003700- TID: 00003052- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **l Q  gȺ~   ! Q F2@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy35\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {d85b6979-3ee7-4dc1-a5ab-e46e9647a4ae}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003700- TID: 00003052- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **m 兛Q  gȺ~  ! Q F2.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy35\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {d85b6979-3ee7-4dc1-a5ab-e46e9647a4ae}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003700- TID: 00003052- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **xn [  gȺ~  ! 兛Q F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003700- TID: 00005712- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0o Yy t[ ![ F2`PowerEvent handled successfully by the service.0**0p y t[ !Yy F2`PowerEvent handled successfully by the service.os0**0q { t[ !y F2`PowerEvent handled successfully by the service. 0**r M{ t[ _! { F2<Service stopped successfully.**s 4*| t[ _!M{ F2<Service started successfully.**t @B| Z2^0Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA    +AV     Application ! MediaserverAb  ! 9!1#@4*| F20x40010004!** u | [@ 3[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=3)GuidA  "&4 Version    q4Opcode +AV   A4 Correlation\F4 ActivityID#55RelatedActivityID Am_5 ExecutionHF54 ProcessID59ThreadID   ! MediaserverAb  !  N!@B|$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication !7^0/Ô*FgA[Y'=EVENT_HIVE_LEAKA#=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA t ** v Px| t[ u!| F2RService has been successfully shut down. **w ;/| >B MEDIASERVER\SQLEXPRESSp**`x c(} [@ 3  N=!;/|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg'Dygػ$<[7J.Yyst`**y (8(} AÆDAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF3&{899daace-4868-4295-afcd-9eb8fb497561}Eb`EventSourceName EventSystemA  &4    q4 +AV   A4F4#5A_5F55   Application ! MediaserverAb  ! Q!@c(} G{vE`Qi^_YA#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogd82**8z )} [@ 3  N!(8(}Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg'D(?)]8**{ '\*} MyJN@MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    +AV     Application ! MediaserverAb  ! #!`)} F29c**| '\*} :FM:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1A    +AV     Application ! MediaserverAb  ! _!'\*} F2<Service started successfully. 0**} '\*} Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS **~ '\*} >B MEDIASERVER\SQLEXPRESSRN=** '\*} >B MEDIASERVER\SQLEXPRESS** '\*} 1660>B MEDIASERVER\SQLEXPRESS** '\*} MIXED>; MEDIASERVER\SQLEXPRESS** '\*} c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS suc**p '\*} 18969/08/2014 12:51:49 PM9/08/2014 2:51:49 AM>C MEDIASERVER\SQLEXPRESSp** '\*}  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS** '\*} > C MEDIASERVER\SQLEXPRESS**** '\*} 2> C MEDIASERVER\SQLEXPRESSer**  '\*} 25005000>B MEDIASERVER\SQLEXPRESSby **X '\*} 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX** '\*} u au YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    +AV     Application ! MediaserverAb  ! #!N@'\*} F2** '\*} u a #! N'\*} F2ull**x '\*} b7.eab7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF3&{1edeee53-0afe-4609-b846-d8c0b2075b1f}EWinMgmtA  &4    q4 +AV   A4F4#5A_5F55   Application ! MediaserverAb  ! #!'\*} F2Sx** '\*} master>B MEDIASERVER\SQLEXPRESS** *} b7.e #!'\*} F2Se**  *} master1>~ MEDIASERVER\SQLEXPRESS  **8 *} model>B MEDIASERVER\SQLEXPRESSce**( T+} >B MEDIASERVER\SQLEXPRESS`** T+} >e MEDIASERVER\SQLEXPRESS]**0 T+} 'any'ipv61433>e MEDIASERVER\SQLEXPRESS^0**0 T+} 'any'ipv41433>e MEDIASERVER\SQLEXPRESS_0**H T+} \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**X T+} \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS hanX** T+} 7806>/C MEDIASERVER\SQLEXPRESSPo**  T+} 0x54b3>e MEDIASERVER\SQLEXPRESSven ** T+} >B MEDIASERVER\SQLEXPRESS ** T+}  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...- Cod ** -} tempdb>B MEDIASERVER\SQLEXPRESS**8 -} 8۹H8͋y4AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA*!= .NET RuntimeA    +AV     Application ! MediaserverAb  ! !g  F2Application: MediaPortal.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: exception code c0000005, exception address 76EEDFE4 e **@  w^!7we}%ƿ:AMsj5http://schemas.microsoft.com/win/2004/08/events/event#A4+=Application ErrorA    +AV     Application ! MediaserverAb  ! !db  F2MediaPortal.exe1.8.0.053a6f5afunknown0.0.0.000000000000000000000000020001cfb37e5eb56a25C:\Program Files (x86)\Team MediaPortal\MediaPortal\MediaPortal.exeunknownf2156260-1f85-11e4-9c4a-00005872cd7b@** {%޳ $$8 &X_ AMsj5http://schemas.microsoft.com/win/2004/08/events/event/A@7=Windows Error ReportingA    +AV     Application ! MediaserverAb  ! Y!  F260APPCRASHNot available0MediaPortal.exe1.8.0.053a6f5afunknown0.0.0.0000000000000000000000000C:\Users\TV\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_MediaPortal.exe_373fecb61beeb4290132eac3a7fd45d7d1d4d_0e62172e0f2156260-1f85-11e4-9c4a-00005872cd7b0**0 _ t[ !{%޳  F2`PowerEvent handled successfully by the service.0**0 $ t[ !_  F2`PowerEvent handled successfully by the service.0**0 z2; t[ !$ F2`PowerEvent handled successfully by the service.0**0 2=P t[ !z2; F2`PowerEvent handled successfully by the service.0**0 ըP t[ !2=P F2`PowerEvent handled successfully by the service.SQL0**0 I\ t[ !ըP F2`PowerEvent handled successfully by the service.2580**0 \ t[ !I\ F2`PowerEvent handled successfully by the service.0**0 \ t[ !\ F2`PowerEvent handled successfully by the service.0**0 g= t[ !\ F2`PowerEvent handled successfully by the service.0**X { f !!g= F2Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exepX**x ġ  gȺ~  ! { F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00001880- TID: 00003392- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 00x**8 <ݡ smH& !ġ F2B$boot optimizationTV System (C:)$"0dyl/ser8**0 Ŧ t[ !<ݡ F2`PowerEvent handled successfully by the service.0**0 <ɫ t[ !Ŧ F2`PowerEvent handled successfully by the service.(I0** ʫ MyJ '!<ɫ F2.**  MyJ '!ʫ F2C**x ~j  gȺ~  !  F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004900- TID: 00003304- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 rsx**0 gWŴ t[ !~j F2`PowerEvent handled successfully by the service.ntc0**0 gWŴ t[ !gWŴ F2`PowerEvent handled successfully by the service.-0**0 9q*ٴ t[ !gWŴ F2`PowerEvent handled successfully by the service.3-80**0 ~v t[ !9q*ٴ  F2`PowerEvent handled successfully by the service.)(?0**0 ~v t[ !~v! F2`PowerEvent handled successfully by the service.-ff0**0 Iv% t[ !~v" F2`PowerEvent handled successfully by the service. 0x0**0 ]p1 t[ !Iv%# F2`PowerEvent handled successfully by the service.-410**0 ng; t[ !]p1$ F2`PowerEvent handled successfully by the service.], 0**0 < t[ !ng;% F2`PowerEvent handled successfully by the service.4ad0** < gRkFpSWg**  mε t[&t[&sz`qi#KA?M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAP{Provider-=KName TV ServerAMqaEventID') QualifiersdLevelE{Task$ jKeywordsAP8; TimeCreated'aj<{ SystemTime .F EventRecordID 8aChannel Application:8;nComputer MediaserverABD.SecuritygfLUserID ! !rlε. FF%g>9{p(xl;D EventDatacoData !Binary`PowerEvent handled successfully by the service. **0 ؤ t[& !mε/ F`PowerEvent handled successfully by the service. 0**0 m\ t[& !ؤ0 F`PowerEvent handled successfully by the service.!0**0 3 t[& !m\1 F`PowerEvent handled successfully by the service.400**0  t[& !32 F`PowerEvent handled successfully by the service.os0**  115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x000000009f8000>A MEDIASERVER\SQLEXPRESSe **0 R t[& ! 4 F`PowerEvent handled successfully by the service.]?0**0 Fr 2}2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreAq    A8 a    Application  MediaserverAD g ! ! R5 Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my0** Fr  gȺ> gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSAq    A8 a    Application  MediaserverAD g ! M! Fr6 F\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy19\Windows\softwaredistribution\Download\c8b6821d45d33e0cf812eb49db13e9a2*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {13edcf4d-bc63-48de-bda8-dfd2e732d673}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003852- TID: 00004092- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ** Fr  gȺ>  ! Fr7 F@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy19\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {13edcf4d-bc63-48de-bda8-dfd2e732d673}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003852- TID: 00004092- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ws\sy**   gȺ> ! Fr8 F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy19\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {13edcf4d-bc63-48de-bda8-dfd2e732d673}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003852- TID: 00004092- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 - CMD: **0  t[& !9 F`PowerEvent handled successfully by the service.BAL0**x   gȺ> ! : F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003852- TID: 00003084- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 atx**0  t[& !; F`PowerEvent handled successfully by the service. Wr0**0 Z# t[& !< F`PowerEvent handled successfully by the service.**0** R*34 N)8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideAq    A8 a    Application  MediaserverAD g ! !!Z#= FMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**0 Qks t[& !R*34> F`PowerEvent handled successfully by the service.0**0 Qks t[& !Qks? F`PowerEvent handled successfully by the service.0**0  t[& !Qks@ F`PowerEvent handled successfully by the service.m/0**0 ** t[& !A F`PowerEvent handled successfully by the service.!0**0  t[& !**B F`PowerEvent handled successfully by the service.0**0 w&# t[& !C F`PowerEvent handled successfully by the service. 0**0  t[& !w&#D F`PowerEvent handled successfully by the service. 0**0 @ t[& !E F`PowerEvent handled successfully by the service.ndo0**h ?wg 2} ! @F Ft$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my13h**0 а* t[& !?wgG F`PowerEvent handled successfully by the service.0-0**0 i* t[& !а*H F`PowerEvent handled successfully by the service.070** i*  gȺ> M! i*I F\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy22\Windows\softwaredistribution\Download\1175227e05ed3a664171f9fdd852732a*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {f9842356-8ee2-4c4c-aa2b-b2d35f8d4650}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00005440- TID: 00005704- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ** i*  gȺ>  ! i*J F@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy22\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {f9842356-8ee2-4c4c-aa2b-b2d35f8d4650}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00005440- TID: 00005704- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ػ$** i*  gȺ> ! i*K F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy22\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {f9842356-8ee2-4c4c-aa2b-b2d35f8d4650}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00005440- TID: 00005704- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 cat** *  gȺ> M!" i*L F Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {f9842356-8ee2-4c4c-aa2b-b2d35f8d4650}- Code: WRTDELET00000470- Call: WRTDELET00000444- PID: 00005440- TID: 00005704- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 `**0 8+ t[& !*M F`PowerEvent handled successfully by the service.=0**x,  gȺ> ! 8+N F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00005440- TID: 00005556- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**x -  gȺ> ! ,O F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003900- TID: 00004104- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 .0x** - Z2QZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAq    A8 a    Application  MediaserverAD g ! 9!1#@ -P F0x40010004**0  \- [@ S[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=T)GuidAq  "T Version    1UOpcode A8 a  AU Correlation\FUc ActivityIDUq5RelatedActivityID AmV ExecutionHFDVU ProcessIDiV9ThreadID    MediaserverAD g !  N ! - QMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication WQ/Ô*FgA[;'=EVENT_HIVE_LEAKA#c=Detail z6 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 2708 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 588 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA 0 **@)- [@ S  N! \- RMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication W1 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000_Classes: Process 2708 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000_CLASSES *@** +- t[& u!)-S FRService has been successfully shut down.j **;5- >B MEDIASERVER\SQLEXPRESS5b1**`@&p- [@ S  N=!;5-UMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yggygػ$<[7J.;`**Np- AgAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemFT&{899daace-4868-4295-afcd-9eb8fb497561}5iD`EventSourceName EventSystemAq  T    1U A8 a  AUFUUAVFDViV   Application  MediaserverAD g ! Q!@@&p-V Rk{vE`Qi^_;A#c=param1 A#c=param2 A#c=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogter**8 r- [@ S  N!Np-|WMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygg**8** r- Mym MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceAq    A8 a    Application  MediaserverAD g ! #!`r-X F** 0!s- :p:R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1Aq    A8 a    Application  MediaserverAD g ! _!r-Y F<Service started successfully.** 0!s- Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS** 0!s- >B MEDIASERVER\SQLEXPRESS**0!s- >B MEDIASERVER\SQLEXPRESS**0!s- 1704>B MEDIASERVER\SQLEXPRESS**0!s- MIXED>; MEDIASERVER\SQLEXPRESS**0!s- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS2**p0!s- 166014/08/2014 5:31:24 AM13/08/2014 7:31:24 PM>C MEDIASERVER\SQLEXPRESSSQLp**0!s-  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**0!s- > C MEDIASERVER\SQLEXPRESS**0!s- 2> C MEDIASERVER\SQLEXPRESS17** 0!s- 25005000>B MEDIASERVER\SQLEXPRESS **x0!s- b7.b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIFT&{1edeee53-0afe-4609-b846-d8c0b2075b1f}5iWinMgmtAq  T    1U A8 a  AUFUUAVFDViV   Application  MediaserverAD g ! #!0!s-e Flex**X0!s- 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSctorX**0!s- u u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAq    A8 a    Application  MediaserverAD g ! #!N@0!s-g Fio**0!s- u  #! N0!s-h Frin**0!s- master>B MEDIASERVER\SQLEXPRESSL**ǹs- b7. #!0!s-j F** ǹs- 3master1>N MEDIASERVER\SQLEXPRESS ** ǹs- 0master1>O MEDIASERVER\SQLEXPRESS ** ǹs- master1>~ MEDIASERVER\SQLEXPRESS @ **8 ǹs- model>B MEDIASERVER\SQLEXPRESSL3**(&]Rt- >B MEDIASERVER\SQLEXPRESSatio**(]Rt- >e MEDIASERVER\SQLEXPRESSs36**0)]Rt- 'any'ipv61433>e MEDIASERVER\SQLEXPRESS!0**0*]Rt- 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**H+]Rt- \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSmaH**X,]Rt- \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS &4X**-]Rt- 7806>/C MEDIASERVER\SQLEXPRESS** .]Rt- 0x54b3>e MEDIASERVER\SQLEXPRESS **/t- >B MEDIASERVER\SQLEXPRESSF3**0v- dd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAq    A8 a    Application  MediaserverAD g ! _!t-~ F<Service started successfully.**1v- tempdb>B MEDIASERVER\SQLEXPRESS**82v- - RF y! @- FV(IIS-W3SVC-MaxConcurrentRequests) (MathRecognizerEventsLicensing-EnableMathRecognizer) (Microsoft.Windows.Smc-Enabled) (TabletPC-MathInputLicensing-EnableMathInput) (TabletPCAccessories-EnableJournal) (TabletPCAccessories-EnableStickyNotes) (TabletPCCoreInkRecognitionLicensing-EnableText) (TabletPCInputPanel-EnableTIP) (TabletPCInputPanel-EnableTIPSynced) (TabletPCInputPersonalization-EnablePersonalization) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA) 55c92734-d682-4d71-983e-d6ec3f16059f7cfd4696-69a9-4af7-af36-ff3d12b6b6c8(**H ?- RF  !@- Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] oH **@lj- RF A!@- F6.1.7601.17514ort**A;- :S5G.:S5GS(j`>MFP**\[C R&R *Ny^cAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAZ{Provider7F=KNameMicrosoft-Windows-Security-SPPF)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}`EventSourceName$Software Protection Platform ServiceAM{aEventID') Qualifiers " Version dLevelE{Task @Opcode$gjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FG ActivityIDn{5RelatedActivityIDAm ExecutionHFG ProcessID9ThreadID 8aChannel Application:];nComputer MediaserverAB.SecurityfLUserID ! - !@[C FnF%g>9{p(xlD EventDataoData !Binaryz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] .mi**]: R& A!@[C Fn6.1.7601.17514 **^h;G R& #!@: Fn**x_h;G G ~G zԯ6l02'AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-CAPI2F&{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}Microsoft-Windows-CAPI2A{      @ gA   AFGnAF   Application ] MediaserverA  ! !h;G FnCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USA8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436x**`1E G ~ !h;G FnCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USA8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436hot **aL0׸ t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA{    gA     Application ] MediaserverA  ! !1E Fn`PowerEvent handled successfully by the service.1-5-18**0b׸ t[ !L0׸ Fn`PowerEvent handled successfully by the service.9\W0**0c t[ !׸ Fn`PowerEvent handled successfully by the service.on 0**0d t[ ! Fn`PowerEvent handled successfully by the service.ter0**0e t[ ! Fn`PowerEvent handled successfully by the service. 0**0fcZ t[ ! Fn`PowerEvent handled successfully by the service. 0**0g9 t[ !cZ Fn`PowerEvent handled successfully by the service.c.exe0**0hŒ t[ !9 Fn`PowerEvent handled successfully by the service.ess0**0iV t[ !Œ Fn`PowerEvent handled successfully by the service.ess0**0jf t[ !V Fn`PowerEvent handled successfully by the service.eBy0**0k t[ !f Fn`PowerEvent handled successfully by the service.0**0l t[ ! Fn`PowerEvent handled successfully by the service.="0**0m% t[ ! Fn`PowerEvent handled successfully by the service.0**0n 6 t[ !% Fn`PowerEvent handled successfully by the service.0**0oK N t[ ! 6 Fn`PowerEvent handled successfully by the service.0**0pK N t[ !K N Fn`PowerEvent handled successfully by the service.0**0qcO/l t[ !K N Fn`PowerEvent handled successfully by the service.0**r1l R& #!@cO/l Fn **s1l R& k!*@1l FnHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H t1l R&  !@1l Fnz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **uFl R& A!@1l Fn6.1.7601.17514ibut**vo R& #!@Fl Fn: S**womo Z2FZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA{    gA     Application ] MediaserverA  ! 9!1#@o Fn0x40010004** xo t[ u!omo FnRService has been successfully shut down.ut **yo >B MEDIASERVER\SQLEXPRESS**hzPo [@ >M[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=A{      @ gA   AFGn AF   ] MediaserverA  !  N=!o|Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygEPygػ$<[7J.55- PIDh**{4Qo AæPAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA{      @ gA   AFGnAF   Application ] MediaserverA  ! Q!@Po S{vE`Qi^_A#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogOp**8|Qo [@ >M  N!4Qo$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygEP9Th8**}Qo :S5GV~:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**G/Ro >B MEDIASERVER\SQLEXPRESSA**G/Ro >B MEDIASERVER\SQLEXPRESS **G/Ro 1860>B MEDIASERVER\SQLEXPRESSos**G/Ro MIXED>; MEDIASERVER\SQLEXPRESSfi**G/Ro c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**pG/Ro 170418/08/2014 9:00:39 AM17/08/2014 11:00:39 PM>C MEDIASERVER\SQLEXPRESSp**G/Ro  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**G/Ro > C MEDIASERVER\SQLEXPRESSight**Ro 2> C MEDIASERVER\SQLEXPRESSER** Ro 25005000>B MEDIASERVER\SQLEXPRESSSS **XRo 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**xRo b7.^xVcb7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-WMIF&{1edeee53-0afe-4609-b846-d8c0b2075b1f}WinMgmtA{      @ gA   AFGnAF   Application ] MediaserverA  ! #!Ro FnVEx**Ro master>B MEDIASERVER\SQLEXPRESS2**t`So b7.^x #!Ro Fn** t`So 1master1>N MEDIASERVER\SQLEXPRESS ** t`So 0master1>O MEDIASERVER\SQLEXPRESSS ** t`So master1>~ MEDIASERVER\SQLEXPRESS **8t`So model>B MEDIASERVER\SQLEXPRESSME**( So >e MEDIASERVER\SQLEXPRESS**0 So 'any'ipv61433>e MEDIASERVER\SQLEXPRESSh0** So >B MEDIASERVER\SQLEXPRESS **0 So 'any'ipv41433>e MEDIASERVER\SQLEXPRESS\\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSH**XTo \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESS~ @X**To dǖd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA{    gA     Application ] MediaserverA  ! _!To Fn<Service started successfully.**To 7806>/C MEDIASERVER\SQLEXPRESS ** To 0x54b3>e MEDIASERVER\SQLEXPRESS2531 **Zo >B MEDIASERVER\SQLEXPRESS**Zo ]LHMEDIASERVER\SQLEXPRESSmaster [CLIENT: fe80::952f:f825:41b2:6937%17]>#CMEDIASERVER\SQLEXPRESS`**Zo  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...nt **\o ,,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTA{    gA     Application ] MediaserverA  ! s!f\o FnPWindows3344Windows: 060176010000te**r]o tempdb>B MEDIASERVER\SQLEXPRESSe**8r]o &8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA{    gA     Application ] MediaserverA  ! !!Dߺ FnMicrosoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**0: t[ !c Fn`PowerEvent handled successfully by the service.0**0: t[ !: Fn`PowerEvent handled successfully by the service.0**0m&# t[ !: Fn`PowerEvent handled successfully by the service.0**0>: t[ !m&# Fn`PowerEvent handled successfully by the service.0**0>: t[ !>:  Fn`PowerEvent handled successfully by the service.0**0z/H t[ !>:! Fn`PowerEvent handled successfully by the service.0**0CY t[ !z/H" Fn`PowerEvent handled successfully by the service.0**0CY t[ !CY# Fn`PowerEvent handled successfully by the service.0**0E] t[ !CY$ Fn`PowerEvent handled successfully by the service.0**0aa t[ !E]% Fn`PowerEvent handled successfully by the service.0**0yJo t[ !aa& Fn`PowerEvent handled successfully by the service.0**0" z t[ !yJo' Fn`PowerEvent handled successfully by the service.0**" z 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x0000000012e000>A MEDIASERVER\SQLEXPRESS0**0" z t[ !" z) Fn`PowerEvent handled successfully by the service.rvi0**N끻 9{p(xlYD EventDataoData !Binary@$defragmentationSystem Reserved$"Q)k^@**)%A t[ft[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA    +AV     Application ! MediaserverAb  ! !;`. F2`PowerEvent handled successfully by the service.: 4**0)%A t[f !)%A/ F2`PowerEvent handled successfully by the service.C00**0F̱ t[f !)%A0 F2`PowerEvent handled successfully by the service.th0**(켙  gȺ gȺqlJGAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA=VSSA    +AV     Application ! MediaserverAb  ! ! F̱1 F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004396- TID: 00004988- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 (**0U smH& !켙2 F2@$defragmentationSystem Reserved$"Q)k^0**0ݗ smH& !U3 F2@$defragmentationSystem Reserved$"Q)k^0**8 smH& !ݗ4 F2B$boot optimizationTV System (C:)$"0dyl0 [8**0 t[f !5 F2`PowerEvent handled successfully by the service.(20**0k t[f !6 F2`PowerEvent handled successfully by the service.&0**0G t[f !k7 F2`PowerEvent handled successfully by the service.os0**0 2}2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    +AV     Application ! MediaserverAb  ! ! G8 F2t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|myl 0**  gȺ  M! 9 F2\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy25\Windows\softwaredistribution\Download\70bf659b42dfee7640ed0c15607040d0*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a1877d9b-c81d-4a20-8c86-142a6a46e9d0}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002680- TID: 00005884- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 o**  gȺ   ! : F2@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy25\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a1877d9b-c81d-4a20-8c86-142a6a46e9d0}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002680- TID: 00005884- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **J9  gȺ  ! ; F2.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy25\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {a1877d9b-c81d-4a20-8c86-142a6a46e9d0}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002680- TID: 00005884- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **x>#  gȺ  ! J9< F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00002680- TID: 00002448- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 ucx**05 t[f !>#= F2`PowerEvent handled successfully by the service.suc0**05 t[f !5> F2`PowerEvent handled successfully by the service.suc0**0A" t[f !5? F2`PowerEvent handled successfully by the service.suc0**0+ t[f !A"@ F2`PowerEvent handled successfully by the service.suc0**0379 t[f !+A F2`PowerEvent handled successfully by the service.suc0**0=? t[f !379B F2`PowerEvent handled successfully by the service.suc0**>? 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x000000000de000>A MEDIASERVER\SQLEXPRESSdo**0lk?? t[f !>?D F2`PowerEvent handled successfully by the service., 00**0u t[f !lk??E F2`PowerEvent handled successfully by the service.es/0**0 t[f !uF F2`PowerEvent handled successfully by the service.t0**0 t[f !G F2`PowerEvent handled successfully by the service.-920**0м t[f !H F2`PowerEvent handled successfully by the service.?)(0**0tܼ t[f !мI F2`PowerEvent handled successfully by the service.af30**0tܼ t[f !tܼJ F2`PowerEvent handled successfully by the service./4.0**0bd޼ t[f !tܼK F2`PowerEvent handled successfully by the service.3300**0Np޼ t[f !bd޼L F2`PowerEvent handled successfully by the service.0, 0**0Np޼ t[f !Np޼M F2`PowerEvent handled successfully by the service.acd0**0! t[f !Np޼N F2`PowerEvent handled successfully by the service.0, 0**0`B smH& !!O F2@$defragmentationSystem Reserved$"Q)k^d0**0`B smH& !`BP F2@$defragmentationSystem Reserved$"Q)k^00** nD8y  \PAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SideBySideA    +AV     Application ! MediaserverAb  ! !!`BQ F2Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exe**xцJ  gȺ  ! R F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003900- TID: 00003192- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**0  t[f !цJS F2`PowerEvent handled successfully by the service.nt0**05 t[f ! T F2`PowerEvent handled successfully by the service.!0**0jky6 t[f !5U F2`PowerEvent handled successfully by the service.M0**0gt t[f !jky6V F2`PowerEvent handled successfully by the service.0**0 ht t[f !gtW F2`PowerEvent handled successfully by the service.M0**0 I115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x0000000009e000>A MEDIASERVER\SQLEXPRESSQ**0 t[f !{ֽ] F2`PowerEvent handled successfully by the service.3-0**0% t[f !^ F2`PowerEvent handled successfully by the service. 0**V 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x0000000064c000>A MEDIASERVER\SQLEXPRESS**0V t[f !V` F2`PowerEvent handled successfully by the service.0**03R  t[f !Va F2`PowerEvent handled successfully by the service.=0**0 D t[f !3R b F2`PowerEvent handled successfully by the service./e0**0d D t[f ! Dc F2`PowerEvent handled successfully by the service.0**0wE t[f !d Dd F2`PowerEvent handled successfully by the service.mi0** E RanDR *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventmA.%F=Microsoft-Windows-Security-SPPFb)Guid&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}ybb`EventSourceName$Software Protection Platform ServiceA  "c Version    bcOpcode +AV   Ac Correlation\Fc ActivityIDd5RelatedActivityIDAmPd ExecutionHFudc ProcessIDd9ThreadID   Application ! MediaserverAb  ! #!@wEe F2** E Ra k!*@ Ef F2HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H  E Ra  !@ Eg F2z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **;F Ra A!@ Eh F26.1.7601.17514LEXP**F Ra #!@;Fi F2en**h#F 2} ! Fj F2t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|my h**#F  gȺ  M! #Fk F2\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy28\Windows\softwaredistribution\Download\9b1fd27f7aca994956425ec72072da60*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {9160b2c8-6485-456f-b6bf-24bb02e5eaab}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003464- TID: 00003056- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **#F  gȺ   ! #Fl F2@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy28\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {9160b2c8-6485-456f-b6bf-24bb02e5eaab}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003464- TID: 00003056- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 FӸ**YɃG  gȺ  ! #Fm F2.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy28\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {9160b2c8-6485-456f-b6bf-24bb02e5eaab}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00003464- TID: 00003056- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 B@**x KL  gȺ  ! YɃGn F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00003464- TID: 00005468- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 MEx**0!T t[f !KLo F2`PowerEvent handled successfully by the service.ME0**0" t[f !Tp F2`PowerEvent handled successfully by the service.EXP0**0#^U t[f !q F2`PowerEvent handled successfully by the service.EXP0**$ 115c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\MpTvDb.mdfMpTvDb500000000000004F40x0000000006e000>A MEDIASERVER\SQLEXPRESS**0)f[ t[f !U#d[w F2`PowerEvent handled successfully by the service.0**0*n t[f !f[x F2`PowerEvent handled successfully by the service.ast0**0+? t[f !ny F2`PowerEvent handled successfully by the service.0**0,Z t[f !?z F2`PowerEvent handled successfully by the service.to 0**0- smH& !Z{ F2@$defragmentationSystem Reserved$"Q)k^0**X.y瀫 nD !!| F2Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"c:\program files (x86)\soundgraph\iMON\system\RegDll64.exeIX**0/[ smH& !y瀫} F2@$defragmentationSystem Reserved$"Q)k^T0**0?\ My掟&1MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    +AV     Application ! MediaserverAb  ! '![~ F2**1ɬ My掟 '!?\ F2n**x2t  gȺ  ! ɬ F2- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00004336- TID: 00006024- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 orx**83 d smH& !t F2B$boot optimizationTV System (C:)$"0dylENT8**04v$ҿ t[f ! d F2`PowerEvent handled successfully by the service.0**05v$ҿ t[f !v$ҿ F2`PowerEvent handled successfully by the service.!0**06>yٿ t[f !v$ҿ F2`PowerEvent handled successfully by the service.0**07_ t[f !>yٿ F2`PowerEvent handled successfully by the service.r0**08_ t[f !_ F2`PowerEvent handled successfully by the service.0**09[( t[f !_ F2`PowerEvent handled successfully by the service.0**0:[= t[f ![( F2`PowerEvent handled successfully by the service. F0**0;[= t[f ![= F2`PowerEvent handled successfully by the service.4W0**0<W;> t[f ![= F2`PowerEvent handled successfully by the service.0**=<> Z2^Z2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerA    +AV     Application ! MediaserverAb  ! 9!1#@W;> F20x40010004ent** > J> [@ [@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=bA  c    bc +AV   AcFcd APdFudd   ! MediaserverAb  !  N!<>Microsoft-Windows-User Profiles Service鱉ZDD XEApplication %^/Ô*FgA[Y'=EVENT_HIVE_LEAKA#=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 580 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA d71 **?~Y>  F2>>B MEDIASERVER\SQLEXPRESS-838**`@aF [@   N=!~Y>$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication ygGygػ$<[7J.Y?)]`**A\DbF AæAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemFb&{899daace-4868-4295-afcd-9eb8fb497561}yb EventSystemA  c    bc +AV   AcFcdAPdFudd   Application ! MediaserverAb  ! Q!@aF {vE`Qi^_YA#=param1 A#=param2 A#=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLog?)(**8B"cF [@   N!\DbFMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication ygG24318**C"cF :S5G:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**HfF >B MEDIASERVER\SQLEXPRESS**IfF >B MEDIASERVER\SQLEXPRESS**JfF 2396>B MEDIASERVER\SQLEXPRESS04**KfF MIXED>; MEDIASERVER\SQLEXPRESSA**LfF c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESS**pMfF 186025/08/2014 6:26:39 PM25/08/2014 8:26:39 AM>C MEDIASERVER\SQLEXPRESS!p**NfF  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**OfF > C MEDIASERVER\SQLEXPRESSy by**PfF 2> C MEDIASERVER\SQLEXPRESSed** QfF 25005000>B MEDIASERVER\SQLEXPRESSA **XRfF 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSX**S?GgF master>B MEDIASERVER\SQLEXPRESS**T?GgF u Fu YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    +AV     Application ! MediaserverAb  ! #!N@?GgF F2ic**U?GgF u F #! N?GgF F2** V?GgF master1>~ MEDIASERVER\SQLEXPRESS **W?GgF dd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceA    +AV     Application ! MediaserverAb  ! _!?GgF F2<Service started successfully.**8X?GgF model>B MEDIASERVER\SQLEXPRESS**(^gF >e MEDIASERVER\SQLEXPRESSm Fi**0agF 'any'ipv61433>e MEDIASERVER\SQLEXPRESS0**0bgF 'any'ipv41433>e MEDIASERVER\SQLEXPRESS0**HcgF \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESS80H**XdgF \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSwerEX**egF 7806>/C MEDIASERVER\SQLEXPRESS** fgF 0x54b3>e MEDIASERVER\SQLEXPRESS Fn@.defragmentationSystem Reserved$HF8 ElfChnkggH@A6܃>Iv Q = u(>  , Mo"6E(~n`!f?xF>,6LZ{&/il>**ggF 9{p(xlID EventDataqoData !Binary>>B MEDIASERVER\SQLEXPRESServ**hgF b7.6b7.jz,,$}AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-WMIF()Guid&{1edeee53-0afe-4609-b846-d8c0b2075b1f}R`EventSourceNameWinMgmtA  " Version    > Opcode AF o  A Correlation\F q ActivityID 5RelatedActivityIDAm, ExecutionHFQ ProcessIDv 9ThreadID   Application  MediaserverAR u ! #!gF F"**ilxhF >B MEDIASERVER\SQLEXPRESS gȺ **jlxhF ]LHMEDIASERVER\SQLEXPRESSmaster** kiF t[t[&sz`qi#AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA$= TV ServerA    AF o    Application  MediaserverAR u ! [!lxhF F"8Service cannot be started. Error: DatabaseUnavailableUnclassified Gentle.Common.GentleException: The database backend (provider SQLServer) could not be reached. Check the connection string: Password=MediaPortal;Persist Security Info=True;User ID=sa;Initial Catalog=MpTvDb;Data Source=Mediaserver\SQLEXPRESS;Connection Timeout=30; ---> System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **l0BjF ]LHMEDIASERVER\SQLEXPRESSmastermeSh**m0BjF tempdb>B MEDIASERVER\SQLEXPRESSh**8n0BjF   AF o  A F  A, FQ v    Application  MediaserverAR u ! s!@vF Z(>,Z(Ux ҤB6IA)q= ExtraInfo  **(x&F   AF o  A F  A, FQ v    Application  MediaserverAR u ! #!@F F"**{3WF R&/ k!*@3WF F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 F**H |3WF R&/  !@3WF F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] $H **}`F R&/ A!@3WF F"6.1.7601.17514ent**~QF  ?6E ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterA    AF o    Application  MediaserverAR u ! #!`F F"0.**0QF 5=Desktop Window ManagerA    AF o    Application  MediaserverAR u ! 9!1#@_ӗ F"0x40010004rvi**( O֗ [@ i[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=(A      >  AF o  A F   A, FQ v     MediaserverAR u !  N!iԗ@|prGFMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication l&g/Ô*FgA[I'=EVENT_HIVE_LEAKA#q=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 584 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 584 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 584 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 584 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 584 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA 486( ** O֗ t[ u!O֗ F"RService has been successfully shut down.4, **|Hٗ >B MEDIASERVER\SQLEXPRESS1 )(**`_ [@ i  N=!|HٗMicrosoft-Windows-User Profiles Service鱉ZDD XEApplication yg?xygػ$<[7J.I`**z_ AÞxAÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/eventAF=Microsoft-Windows-EventSystemF(&{899daace-4868-4295-afcd-9eb8fb497561} EventSystemA      >  AF o  A F  A, FQ v    Application  MediaserverAR u ! Q!@_ {{vE`Qi^_IA#q=param1 A#q=param2 A#q=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogtex**8I` [@ i  N!z_$Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg?x85-48**I` :S5G~:S5GS(j  AF o  A F  A, FQ v    Application  MediaserverAR u ! O!@I` F",0x000000000x00000001ss**` ̬8F̬8YѾVZ=AMsj5http://schemas.microsoft.com/win/2004/08/events/event AF=Microsoft-Windows-WinlogonF(&{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}WlclntfyA      >  AF o  A F  A, FQ v    Application  MediaserverAR u ! =!pI` F"SessionEnvent**` My&MyV]z*C2 AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=LightScribeServiceA    AF o    Application  MediaserverAR u ! #!`` F"ndow**` ::R"bVwAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA"=Service1A    AF o    Application  MediaserverAR u ! _!` F"<Service started successfully.ll**Jza Microsoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS**Jza >B MEDIASERVER\SQLEXPRESS7893**Jza >B MEDIASERVER\SQLEXPRESS**Jza 1932>B MEDIASERVER\SQLEXPRESS**Jza MIXED>; MEDIASERVER\SQLEXPRESSc**Jza c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSR\SQ**pJza 239626/08/2014 5:07:39 AM25/08/2014 7:07:39 PM>C MEDIASERVER\SQLEXPRESSSSQp**Jza  -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESSer**Jza > C MEDIASERVER\SQLEXPRESScess**Jza 2> C MEDIASERVER\SQLEXPRESSnt** Jza 25005000>B MEDIASERVER\SQLEXPRESSde **Jza u 6u YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserA    AF o    Application  MediaserverAR u ! #!N@Jza F"Re**Jza u  #! NJza F"}**Xb 000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSentX**b b7.6 #!b F"**b master>B MEDIASERVER\SQLEXPRESS** wb master1>~ MEDIASERVER\SQLEXPRESS **wb b7.6 #!wb F"ws\sy**8wb model>B MEDIASERVER\SQLEXPRESS**( Dc >e MEDIASERVER\SQLEXPRESS=**0 Dc 'any'ipv61433>e MEDIASERVER\SQLEXPRESS 0**0 Dc 'any'ipv41433>e MEDIASERVER\SQLEXPRESS;>0**H Dc \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSAH**X Dc \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSX** Dc 7806>/C MEDIASERVER\SQLEXPRESSEV**  Dc 0x54b3>e MEDIASERVER\SQLEXPRESSoce ** Dc >B MEDIASERVER\SQLEXPRESS000** Dc >B MEDIASERVER\SQLEXPRESS997** Dc  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...  **ge ]LHMEDIASERVER\SQLEXPRESSmasterZD** ge ,! s!fge  F"PWindows2896Windows: 060176010000F= **ge ,! Q!,ge  F".Windows2896Windows:  **ge ,! !-ge  F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS266CB.log**ge ,! !-ge  F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS266CC.log**>f tempdb>B MEDIASERVER\SQLEXPRESSu**>f ,! !->f F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log**8>f f F"LService BrokerL% MEDIASERVER\SQLEXPRESSmaster48**@>f f F"&LDatabase MirroringL% MEDIASERVER\SQLEXPRESSmaster@**>f f F"LL% MEDIASERVER\SQLEXPRESSmaster**>f f F"LLP MEDIASERVER\SQLEXPRESSmaster1**Hk ,! Q!.>f F".Windows2896Windows: Pack** ( !@Hk Z(>, **] R&/ #!@ F"**] R&/ k!*@] F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H ] R&/  !@] F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **, R&/ A!@] F"6.1.7601.17514?Gg**  ?6E #!, F"M**(y⺘ x2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    AF o    Application  MediaserverAR u ! ! VP % F"t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|mySS0** l   gȺn` M! l & F"\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy30\Windows\softwaredistribution\Download\4763d368c554df877e76d62c8e8ad395*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {3548d411-3864-4ee2-970b-5ad1b2233278}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002844- TID: 00001156- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 XPSSwerEX  gȺn`  l ' F" F2 >7806>/C MEDIASERVER\SQLEXPRESS** fgF 0x54b3>e MEDIASERVER\SQLEXPRESS Fn@.defragmentationSystem Reserved$HF8 ElfChnk--xH!N h/qLh+z[9'MU97f0r&ރP'*V4-:6=*** l   gȺ& gȺqlJG?A3M Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAD{Provider!=KNameVSSAMeaEventID') QualifiersdLevelE{Task$jKeywordsAP,; TimeCreated'Uj<{ SystemTime .F EventRecordID 8aChannel Application:,;nComputer MediaserverAB8.Security[fLUserID ! ! l ' FF%g>9{p(xl/D EventDataWoData z!Binary@\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy30\Windows\softwaredistribution\Download*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {3548d411-3864-4ee2-970b-5ad1b2233278}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002844- TID: 00001156- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 **   gȺ& ! l ( F.\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy30\Windows\softwaredistribution*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {3548d411-3864-4ee2-970b-5ad1b2233278}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002844- TID: 00001156- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 s/e**xW   gȺ& !  ) F- Code: CORSVCC00000773- Call: CORSVCC00000755- PID: 00002844- TID: 00000300- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 x**H,W  ߰߰Y{MAMsj5http://schemas.microsoft.com/win/2004/08/events/eventVA-$F=)GuidAe  " Version    9Opcode A, U  A Correlation\FW ActivityIDe5RelatedActivityID Am' ExecutionHFL ProcessIDq9ThreadID    MediaserverA8 [ $5DUserData! @!'W * O)1Microsoft-Windows-RestartManagerF,$r$Application IIG5[3(>A9?RmSessionEventFhMwxmlns:auto-ns2/http://schemas.microsoft.com/win/2004/08/eventsjDhttp://www.microsoft.com/2005/08/Windows/Reliability/RestartManager/*L RmSessionId ,=K UTCStartTime W tH**H[  ߰ @'!',W + O)1Microsoft-Windows-RestartManagerF,$r$Application IW H**ev  Z2vZ2\1$AMsj5http://schemas.microsoft.com/win/2004/08/events/event-A>5=Desktop Window ManagerAe    A, U    Application  MediaserverA8 [ ! 9!1#@[ , F0x40010004ast** jB  [@ 6[@ 5ņAMsj5http://schemas.microsoft.com/win/2004/08/events/eventZAF=Ae      9 A, U  AF A'FLq    MediaserverA8 [ !  N!ev 0-Microsoft-Windows-User Profiles Service鱉ZDD XEApplication =v/Ô*FgA[/'=EVENT_HIVE_LEAKA#W=Detail X5 user registry handles leaked from \Registry\User\S-1-5-21-1326245560-4010088107-2184259979-1000: Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000 Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\Disallowed Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\My Process 592 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1326245560-4010088107-2184259979-1000\Software\Microsoft\SystemCertificates\CA S26 **Q  >B MEDIASERVER\SQLEXPRESS**`a  [@ 6  N=!Q $/Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg'*ygػ$<[7J./erv`**  AÆ*AÒMy~hVTp{l/AMsj5http://schemas.microsoft.com/win/2004/08/events/event=AF=Microsoft-Windows-EventSystemF&{899daace-4868-4295-afcd-9eb8fb497561}+8`EventSourceName EventSystemAe      9 A, U  AFA'FLq   Application  MediaserverA8 [ ! Q!@a 0 -{vE`Qi^_/A#W=param1 A#W=param2 A#W=param3  2N86400SuppressDuplicateDurationSoftware\Microsoft\EventSystem\EventLogA**8#  [@ 6  N! |1Microsoft-Windows-User Profiles Service鱉ZDD XEApplication yg'*6}8**#  :S5G0:S5GS(jMicrosoft SQL Server 2008 (SP1) - 10.0.2531.0 (X64) Mar 29 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1) >B MEDIASERVER\SQLEXPRESS,**A&  >B MEDIASERVER\SQLEXPRESS 10:**A&  >B MEDIASERVER\SQLEXPRESSee61**A&  1780>B MEDIASERVER\SQLEXPRESS(?)**A&  MIXED>; MEDIASERVER\SQLEXPRESS***A&  c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG>B MEDIASERVER\SQLEXPRESSs/e**pA&  193226/08/2014 6:50:17 PM26/08/2014 8:50:17 AM>C MEDIASERVER\SQLEXPRESSp**A&   -d c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\master.mdf -e c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Log\ERRORLOG -l c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\DATA\mastlog.ldf>B MEDIASERVER\SQLEXPRESS**A&   F>> C MEDIASERVER\SQLEXPRESSrq**׾  2> C MEDIASERVER\SQLEXPRESSj** ׾  25005000>B MEDIASERVER\SQLEXPRESS **X׾  000000000000000030000000000000003>C MEDIASERVER\SQLEXPRESSmewX**׾  master>B MEDIASERVER\SQLEXPRESS**׾  dPd3# ޾AMsj5http://schemas.microsoft.com/win/2004/08/events/event%A6-=MPExtended ServiceAe    A, U    Application  MediaserverA8 [ ! _!׾ C F<Service started successfully.**׾  u Ru YCپ0AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA&= SQLBrowserAe    A, U    Application  MediaserverA8 [ ! #!N@׾ D FTh**׾  u R #! N׾ E Fad** nW  master1>~ MEDIASERVER\SQLEXPRESS= **8nW  master11214915>] MEDIASERVER\SQLEXPRESS8**8nW  model>B MEDIASERVER\SQLEXPRESS8**(  >e MEDIASERVER\SQLEXPRESS M**0  'any'ipv61433>e MEDIASERVER\SQLEXPRESSMD: C:0**0  'any'ipv41433>e MEDIASERVER\SQLEXPRESS han0**H  \\.\pipe\SQLLocal\SQLEXPRESS>e MEDIASERVER\SQLEXPRESSessH**X  \\.\pipe\MSSQL$SQLEXPRESS\sql\query>e MEDIASERVER\SQLEXPRESSviceX**  7806>/C MEDIASERVER\SQLEXPRESSdow**   0x54b3>e MEDIASERVER\SQLEXPRESS **  >B MEDIASERVER\SQLEXPRESSema**   >B MEDIASERVER\SQLEXPRESS ** 1!  ]LHMEDIASERVER\SQLEXPRESSmasterg** ȹ  ]LHMEDIASERVER\SQLEXPRESSmasterd k** ȹ  tempdb>B MEDIASERVER\SQLEXPRESS**8 ȹ   System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ... **  ,ރ,A5+*OAMsj5http://schemas.microsoft.com/win/2004/08/events/event A=ESENTAe    A, U    Application  MediaserverA8 [ ! s!f b FPWindows2648Windows: 060176010000%**  ,ރ Q!, c F.Windows2648Windows: ias**  ,ރ !- d FWindows2648Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS2670A.log**?H  ,ރ !- e FWindows2648Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log_**?H  ,ރ Q!.?H f F.Windows2648Windows: **,f  O|0:AMsj5http://schemas.microsoft.com/win/2004/08/events/event!AF=Microsoft-Windows-SearchF&{CA4E628D-8567-4896-AB6B-835B221F373F}+Windows Search ServiceAe      9 A, U  AFA'FLq   Application  MediaserverA8 [ ! s!@?H g Z(Z(Ux ҤB6/A)W= ExtraInfo  **f  RR *Ny^cAMsj5http://schemas.microsoft.com/win/2004/08/events/eventIAF=Microsoft-Windows-Security-SPPF&{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}+$Software Protection Platform ServiceAe      9 A, U  AFA'FLq   Application  MediaserverA8 [ ! #!@,f h F**g   ?fy ?{RgT2hœWdAMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=SecurityCenterAe    A, U    Application  MediaserverA8 [ ! #!f i F**g  R k!*@g j FHC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H g  R  !@g k Fz 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **^  R A!@g l F6.1.7601.17514**  R #!@^ m FM**(   >B MEDIASERVER\SQLEXPRESS997** Dc  System.Data.SqlClient.SqlException: Cannot open database "MpTvDb" requested by the login. The login failed. Login failed for user 'sa'. at System.Data.ProviderBase.DbConnectionPool.GetConnection(DbConnection owningObject) at System.Data.ProviderBase.DbConnectionFactory.GetConnection(DbConnection owningConnection) at System.Data.ProviderBase.DbConnectionClosed.OpenConnection(DbConnection outerConnection, DbConnectionFactory connectionFactory) at System.Data.SqlClient.SqlConnection.Open() at Gentle.Provider.SQLServer.SQLServerProvider.GetConnection() --- End of inner exception stack trace --- at Gentle.Common.Check.FailWith(Severity severity, Error error, Exception e, String ...  **ge ]LHMEDIASERVER\SQLEXPRESSmasterZD** ge ,! s!fge  F"PWindows2896Windows: 060176010000F= **ge ,! Q!,ge  F".Windows2896Windows:  **ge ,! !-ge  F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS266CB.log**ge ,! !-ge  F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS266CC.log**>f tempdb>B MEDIASERVER\SQLEXPRESSu**>f ,! !->f F"Windows2896Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log**8>f f F"LService BrokerL% MEDIASERVER\SQLEXPRESSmaster48**@>f f F"&LDatabase MirroringL% MEDIASERVER\SQLEXPRESSmaster@**>f f F"LL% MEDIASERVER\SQLEXPRESSmaster**>f f F"LLP MEDIASERVER\SQLEXPRESSmaster1**Hk ,! Q!.>f F".Windows2896Windows: Pack** ( !@Hk Z(>, **] R&/ #!@ F"**] R&/ k!*@] F"HC:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 **H ] R&/  !@] F"z 55c92734-d682-4d71-983e-d6ec3f16059f 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F032 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] H **, R&/ A!@] F"6.1.7601.17514?Gg**  ?6E #!, F"M**(y⺘ x2}!'AMsj5http://schemas.microsoft.com/win/2004/08/events/eventA.%=System RestoreA    AF o    Application  MediaserverAR u ! ! VP % F"t$C:\Windows\system32\svchost.exe -k netsvcsWindows Update$"(g|mySS0** l   gȺn` M! l & F"\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy30\Windows\softwaredistribution\Download\4763d368c554df877e76d62c8e8ad395*.*WUA Operation: OnPostSnapshot event PostSnapshot Event Context: Execution Context: Shadow Copy Optimization Writer Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {3548d411-3864-4ee2-970b-5ad1b2233278}- Code: WRTDELET00000808- Call: WRTDELET00000766- PID: 00002844- TID: 00001156- CMD: C:\Windows\system32\vssvc.exe - User: Name: NT AUTHORITY\SYSTEM, SID:S-1-5-18 XPSSwerEX  gȺn`  l ' F" F2 >7806>/C MEDIASERVER\SQLEXPRESS** fgF 0x54b3>e MEDIASERVER\SQLEXPRESS Fn@.defragmentationSystem Reserved$HF8