PDA

View Full Version : may i log windows xp boot activity?


mantra
November 1st, 2009, 10:03 AM
Hi

is there a program to log windows Xp boot activity ?

from the boot to log in (windows loaded) ?

i did a search but did not find , but i'm sure there is a topic about such program

i did a search +windows +log :(


thanks

philby
November 1st, 2009, 10:15 AM
You need to create Ntblog.txt - see here (http://www.windowsreference.com/general/how-to-create-a-bootlog-in-windows-2000xp-and-later/).

You can also get a lot of info. re. warnings, errors etc. by running eventvwr.exe.

HTH

philby

andyman35
November 1st, 2009, 10:16 AM
The information you need is all here:

http://www.watchingthenet.com/how-to-enable-boot-logging-for-fixing-startup-problems-in-windows.html


*edit* Seems like Mr Philby is quicker on the draw this afternoon!

philby
November 1st, 2009, 10:22 AM
I need to get out more... :blink:

philby

andyman35
November 1st, 2009, 10:23 AM
-{ Quote: "I need to get out more... :blink:

philby" }-
LOL ;D

Seer
November 1st, 2009, 10:37 AM
-{ Quote: "is there a program to log windows Xp boot activity ?
" }-

Yes. Take a look at Greatis (makers of RegRun) BootlogXP (http://www.greatis.com/utilities/bootlogxp/). It is the best boot logger I've tried, and it's a payware.

As a simpler, free solution, you shoud look at Sysinternals' Process Monitor (http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx) -

213436

It will not log network events though. Just read the help file, it explains the process.

mantra
November 1st, 2009, 10:42 AM
-{ Quote: "You need to create Ntblog.txt - see here (http://www.windowsreference.com/general/how-to-create-a-bootlog-in-windows-2000xp-and-later/).

You can also get a lot of info. re. warnings, errors etc. by running eventvwr.exe.

HTH

philby" }-

thanks

i get

Service Pack 211 1 2009 16:28:02.375
Loaded driver \WINDOWS\system32\ntoskrnl.exe
Loaded driver \WINDOWS\system32\hal.dll
Loaded driver \WINDOWS\system32\KDCOM.DLL
Loaded driver \WINDOWS\system32\BOOTVID.dll
Loaded driver d347bus.sys
Loaded driver ACPI.sys
Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver pciide.sys
Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Loaded driver intelide.sys
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver VolSnap.sys
Loaded driver atapi.sys
Loaded driver iteraid.sys
Loaded driver \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
Loaded driver d347prt.sys
Loaded driver disk.sys
Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Loaded driver fltMgr.sys
Loaded driver PxHelp20.sys
Loaded driver KSecDD.sys
Loaded driver Ntfs.sys
Loaded driver NDIS.sys
Loaded driver Mup.sys
Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
Loaded driver \SystemRoot\system32\DRIVERS\ati2mtag.sys
Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\yk51x86.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\system32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
Loaded driver \SystemRoot\system32\DRIVERS\ASACPI.sys
Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\update.sys
Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Impossible to load the driver video \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\drivers\RtkHDAud.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
Loaded driver \SystemRoot\system32\DRIVERS\flpydisk.sys
Impossible to load the driver video \SystemRoot\System32\Drivers\Sfloppy.SYS
Impossible to load the driver video \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipfltdrv.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \??\C:\PROGRA~1\Agnitum\OUTPOS~1\kernel\FILTNT.SYS
Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\system32\drivers\nod32drv.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\rdbss.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \SystemRoot\system32\drivers\amon.sys
Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys


why does not xp load some drivers ?

mantra
November 1st, 2009, 10:49 AM
-{ Quote: "Yes. Take a look at Greatis (makers of RegRun) BootlogXP (http://www.greatis.com/utilities/bootlogxp/). It is the best boot logger I've tried, and it's a payware.

As a simpler, free solution, you shoud look at Sysinternals' Process Monitor (http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx) -

213436

It will not log network events though. Just read the help file, it explains the process." }-


thanks!
bootlog xp is really great!

philby
November 1st, 2009, 11:22 AM
-{ Quote: "thanks

i get

Service Pack 211 1 2009 16:28:02.375
Loaded driver \WINDOWS\system32\ntoskrnl.exe
Loaded driver \WINDOWS\system32\hal.dll
Loaded driver \WINDOWS\system32\KDCOM.DLL
Loaded driver \WINDOWS\system32\BOOTVID.dll
Loaded driver d347bus.sys
Loaded driver ACPI.sys
Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver pciide.sys
Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Loaded driver intelide.sys
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver VolSnap.sys
Loaded driver atapi.sys
Loaded driver iteraid.sys
Loaded driver \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
Loaded driver d347prt.sys
Loaded driver disk.sys
Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Loaded driver fltMgr.sys
Loaded driver PxHelp20.sys
Loaded driver KSecDD.sys
Loaded driver Ntfs.sys
Loaded driver NDIS.sys
Loaded driver Mup.sys
Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
Loaded driver \SystemRoot\system32\DRIVERS\ati2mtag.sys
Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\yk51x86.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\system32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
Loaded driver \SystemRoot\system32\DRIVERS\ASACPI.sys
Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\update.sys
Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Impossible to load the driver video \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\drivers\RtkHDAud.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
Loaded driver \SystemRoot\system32\DRIVERS\flpydisk.sys
Impossible to load the driver video \SystemRoot\System32\Drivers\Sfloppy.SYS
Impossible to load the driver video \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipfltdrv.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \??\C:\PROGRA~1\Agnitum\OUTPOS~1\kernel\FILTNT.SYS
Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\system32\drivers\nod32drv.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\rdbss.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\mrxsmb.sysLoaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \SystemRoot\system32\drivers\amon.sys
Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
Impossible to load the driver video \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys


why does not xp load some drivers ?" }-

Interesting - I've only ever seen "Did not load driver" and have never seen "Impossible to load the driver".

In my ignorance, I would run sfc /scannow.

Anyone else? I've marked the problem entries in red.

philby

mantra
November 1st, 2009, 12:11 PM
-{ Quote: "Interesting - I've only ever seen "Did not load driver" and have never seen "Impossible to load the driver".

In my ignorance, I would run sfc /scannow.

Anyone else? I've marked the problem entries in red.

philby" }-

thank you philby

my xp is not in english , so i translate but i 'm sure that Impossible to load the driver=Did not load driver


but -{ Quote: "I would run sfc /scannow." }- will re-install lots of files from my cd
i have updated my xp (hotfix) many times,i'm scarry it could mess up my windows

philby
November 1st, 2009, 12:44 PM
I think SFC 'understands' that there have been updates and 'knows' where to look for uncorrupted files - it will only ask for the installation disk if it can't find a 'good' file in System32 - which includes new entries created by updates/SPs.

Scroll down to What about Windows Updates? here (http://www.updatexp.com/scannow-sfc.html).

philby

Seer
November 1st, 2009, 05:49 PM
-{ Quote: "why does not xp load some drivers ?" }-

-{ Quote: "In my ignorance, I would run sfc /scannow." }-

I doubt sfc would help, the same is logged on a clean installation (XP SP3) -

Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys

mantra's entries show 'did not (impossible to) load driver video' though.
mantra, have you changed your video drivers recently?

philby
November 1st, 2009, 05:58 PM
OK Nick - let me just check I've understood this right: those "Did not load"s are not load failures - the log would read that way anyway on a clean install?

So does mantra actually have a problem here?

Cheers

philby

Seer
November 1st, 2009, 06:15 PM
-{ Quote: "OK Nick - let me just check I've understood this right: those "Did not load"s are not load failures - the log would read that way anyway on a clean install?" }-

Philby,

They certainly are failures, but that does not automatically suggest that there is something wrong.
TBH, I am not absolutely certain what is going on here. I've been busting my head on the net over this for a while, and din't find a satisfactory explanation. There were suggestions that drivers are not loaded even on a clean install, I checked, and voila.
What is interesting though, is that suffix "video" in mantra's logs.
Let's see what mantra has to say. I am also interested why a need to do boot logging in the first place. Are there any issues on the PC?

philby
November 1st, 2009, 06:32 PM
Thanks Nick

-{ Quote: "There were suggestions that drivers are not loaded even on a clean install, I checked, and voila." }-
Can't get my head round that part - I don't understand why this would be so if they are system drivers.

Will wait and see what Mantra adds to this re. your video driver query...

philby

Seer
November 1st, 2009, 06:42 PM
-{ Quote: "Can't get my head round that part - I don't understand why this would be so if they are system drivers." }-

Some of the drivers refer to non-existant hardware (SCSI floppy and IO controllers, IPNAT for ICS i.e.), but I am not certain about others. Later.

mantra
November 2nd, 2009, 01:37 AM
-{ Quote: "I doubt sfc would help, the same is logged on a clean installation (XP SP3) -

Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys

mantra's entries show 'did not (impossible to) load driver video' though.
mantra, have you changed your video drivers recently?" }-

hi
thank you so much
yes i changed some time ago i guess 30 days ago the video card

Seer
November 2nd, 2009, 03:28 AM
Hello mantra.

-{ Quote: "yes i changed some time ago i guess 30 days ago the video card" }-

So if I understood you correctly, you have changed the whole video card, not just the drivers? What about them, which ones did you install? And what is the exact video card model we are talking about here?
You have not answered all of my previous questions though. Why boot logging? Are there any problems?

mantra
November 2nd, 2009, 05:38 AM
-{ Quote: "Hello mantra.



So if I understood you correctly, you have changed the whole video card, not just the drivers? What about them, which ones did you install? And what is the exact video card model we are talking about here?
You have not answered all of my previous questions though. Why boot logging? Are there any problems?" }-
well my xp did not boot twice , it did freeze during the boot

i changed an ati x800xt for HD 4770 serie , i uninstalled the old drivers , boot in safe mode , run Driver Cleaner.NET -> clean the ati drivers and so on

dismount the x800xt -> install the hd 4770 , and installed the drivers in the hd 4770 box

Seer
November 2nd, 2009, 07:22 AM
-{ Quote: "well my xp did not boot twice , it did freeze during the boot" }-

mantra,

drivers that didn't load are the legacy drivers for hardware you don't have. It is perfectly normal they do not load.
What actually got me interested is this 'video' addition to 'did not load'. Now you say your PC is freezing on boot. Have you tried to install the latest Catalyst drivers (http://game.amd.com/us-en/drivers_catalyst.aspx?p=xp/radeonx-xp) for your ATi and check if freezing persists?