1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

MS Shadow Copy Service Not Working

Discussion in 'Windows XP' started by mechanic, 2015/02/09.

  1. 2015/02/09
    mechanic

    mechanic Well-Known Member Thread Starter

    Joined:
    2002/02/17
    Messages:
    54
    Likes Received:
    0
    I have a Dell Dimension running Win XP SP3. I tried to clone the hard drive with Macrium recently and got an error which I was able to trace to the MS Shadow Copy Service. I was unable to get it to start, and tried a number of repairs to no avail.

    I looked around some more and found a thread online where they claimed that the issue for them was incorrect registry entries related to permissions.
    Located at: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E
    OwnerSID=S-1-5-21-1547161642-682003330-725345543-1003
    TypeLib=C:\\Documents and Settings\\Bob\\EVENTCLS.DLL

    They replaced the above lines with:
    OwnerSID = S-1-5-18
    TypeLib = C\Windows\System32\EventsCLS.dll

    I checked my other XP machine where the Shadow Copy works and it indeed has the bottom lines as shown in the registry.

    So I would like to know if this will work and is it a safe change to make? Will it mess up any software I am running? I have a backup point and exported a copy the registry, but I am anxious about making these types of changes.

    It would also be good to understand where the existing lines came from. I would appreciate any insights you can share here.
     
  2. 2015/02/09
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    The SID does check out here, and as long as that folder does contain Eventcls.Dll, it appears that it should work.
    As to what may have happened, I have these two guesses.
    1. When a file appears in the user folder such as here, I immediately suspect malware. But this appears to be something that keeps coming up somewhere so not very likely the case.
    2. A mistake in coding. Perhaps using %userprofile%\Eventcls.Dll instead of %windir%\system32\Eventcls.Dll .
    BTW, does Eventcls.Dll exist in the "false" location?
     

  3. to hide this advert.

  4. 2015/02/10
    mechanic

    mechanic Well-Known Member Thread Starter

    Joined:
    2002/02/17
    Messages:
    54
    Likes Received:
    0
    Here is the entire registry key on the machine with the issue:

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}]
    "Active "=dword:00000001
    "EventClassID "= "{FAF53CC4-BD73-4E36-83F1-2B23F46E513E} "
    "EventClassName "= "VssEvent "
    "OwnerSID "= "S-1-5-21-1547161642-682003330-725345543-1003 "
    "TypeLib "= "C:\\Documents and Settings\\Bob\\EVENTCLS.DLL "
    "AllowInprocActivation "=dword:ffffffff
    "FireInParallel "=dword:00000000
    "EventClassPartitionID "= "{00000000-0000-0000-0000-000000000000} "
    "EventClassApplicationID "= "{00000000-0000-0000-0000-000000000000} "
    "AllowPerUserInprocActivation "=dword:00000000
    "AllowPerUserActivateAsActivator "=dword:00000000
    "AllowPerUserMoniker "=dword:00000000

    Possibly the result of a repair install?
     
  5. 2015/02/10
    Barbara-Ann

    Barbara-Ann Inactive

    Joined:
    2002/01/07
    Messages:
    124
    Likes Received:
    3
    mechanic - I am running a Dell Dimension 9150 from 2005.

    Here is what I have in the registry - Hope this helps

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}]
    "Active "=dword:00000001
    "EventClassID "= "{FAF53CC4-BD73-4E36-83F1-2B23F46E513E} "
    "EventClassName "= "VssEvent "
    "OwnerSID "= "S-1-5-18 "
    "TypeLib "= "C:\\WINDOWS\\system32\\EVENTCLS.DLL "
    "AllowInprocActivation "=dword:ffffffff
    "FireInParallel "=dword:00000000
    "EventClassPartitionID "= "{00000000-0000-0000-0000-000000000000} "
    "EventClassApplicationID "= "{00000000-0000-0000-0000-000000000000} "
     
    mechanic likes this.
  6. 2015/02/10
    mechanic

    mechanic Well-Known Member Thread Starter

    Joined:
    2002/02/17
    Messages:
    54
    Likes Received:
    0
    Thanks Barbara-Ann!

    Your registry lines look like they are the same as my other machine. and what they are proposing at the other thread I saw.

    So I think I can make a change without too much risk. This is the info I need.
     
  7. 2015/02/11
    Barbara-Ann

    Barbara-Ann Inactive

    Joined:
    2002/01/07
    Messages:
    124
    Likes Received:
    3
    Most welcome mechanic - glad I could help
     
    Last edited: 2015/02/11
  8. 2015/02/11
    Barbara-Ann

    Barbara-Ann Inactive

    Joined:
    2002/01/07
    Messages:
    124
    Likes Received:
    3
    If you need anything more about your Dell Dimension, send me a message and I will do my best to help
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.