Soll ich alles vom Server mit diesem PC Namen löschen?
Damit waren die Computer und "Computer und Sicherungen" im Dashboard gemeint. Ich habe nun die alten PCs entfernt, aber es hat nichts gebracht.
Die "Eigenschaften der Sicherung" schreibt mir
Sicherung war nicht erfolgreich: 18.03.2018 18:08
Das ist aber auch nur die Uhrzeit, wann mit der Sicherung begonnen wurde. Man glaubt aber kaum, was in einer Sekunde alles so in Procmon abgeht. Hier ein Auszug:
Code: Alles auswählen
18:18:24,8223073 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Providers REPARSE Desired Access: Read
18:18:24,8224120 vssvc.exe 1428 RegEnumKey HKLM\System\CurrentControlSet\Services\VSS\Providers NO MORE ENTRIES Index: 1, Length: 288
18:18:24,8224436 vssvc.exe 1428 FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION C:\Windows\System32\netutils.dll FILE LOCKED WITH ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
18:18:24,8224586 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Diag REPARSE Desired Access: Read/Write
18:18:24,8224805 vssvc.exe 1428 RegQueryValue HKLM\System\CurrentControlSet\Services\VSS\Diag\(Default) NAME NOT FOUND Length: 144
18:18:24,8224945 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} REPARSE Desired Access: Read/Write
18:18:24,8225548 vssvc.exe 1428 RegOpenKey HKCR\CLSID\{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}\TreatAs NAME NOT FOUND Desired Access: Query Value
18:18:24,8225957 vssvc.exe 1428 RegOpenKey HKCR\CLSID\{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}\InprocServer32 NAME NOT FOUND Desired Access: Read
18:18:24,8226100 vssvc.exe 1428 RegOpenKey HKCR\CLSID\{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}\InprocHandler32 NAME NOT FOUND Desired Access: Query Value
18:18:24,8226236 vssvc.exe 1428 RegOpenKey HKCR\CLSID\{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}\InprocHandler NAME NOT FOUND Desired Access: Query Value
18:18:24,8226452 vssvc.exe 1428 FASTIO_NETWORK_QUERY_OPEN C:\Windows\System32\samlib.dll FAST IO DISALLOWED
18:18:24,8228594 vssvc.exe 1428 FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION C:\Windows\System32\samlib.dll FILE LOCKED WITH ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ
18:18:24,8228699 svchost.exe 11108 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Settings REPARSE Desired Access: Read
18:18:24,8228995 svchost.exe 11108 RegQueryValue HKLM\System\CurrentControlSet\Services\VSS\Settings\MaxShadowCopies NAME NOT FOUND Length: 144
18:18:24,8231714 lsass.exe 764 RegOpenKey HKLM\SAM\SAM\DOMAINS\Builtin\Groups\Names\Administratoren NAME NOT FOUND Desired Access: Read
18:18:24,8234033 lsass.exe 764 RegOpenKey HKLM\SAM\SAM\DOMAINS\Builtin\Groups\00000227 NAME NOT FOUND Desired Access: Read/Write
18:18:24,8234994 lsass.exe 764 RegOpenKey HKLM\SAM\SAM\DOMAINS\Builtin\Groups\00000227 NAME NOT FOUND Desired Access: Read/Write
18:18:24,8236186 lsass.exe 764 RegOpenKey HKLM\SAM\SAM\DOMAINS\Builtin\Groups\Names\Sicherungs-Operatoren NAME NOT FOUND Desired Access: Read
18:18:24,8237713 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Settings REPARSE Desired Access: Query Value
18:18:24,8237856 vssvc.exe 1428 RegQueryValue HKLM\System\CurrentControlSet\Services\VSS\Settings\ActiveWriterStateTimeout NAME NOT FOUND Length: 144
18:18:24,8238194 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Diag REPARSE Desired Access: Read/Write
18:18:24,8238322 vssvc.exe 1428 RegQueryValue HKLM\System\CurrentControlSet\Services\VSS\Diag\(Default) NAME NOT FOUND Length: 144
18:18:24,8238436 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer REPARSE Desired Access: Read/Write
18:18:24,8238564 svchost.exe 11108 IRP_MJ_DEVICE_CONTROL D: FAST IO DISALLOWED Control: IOCTL_VOLSNAP_QUERY_DIFF_AREA_MINIMUM_SIZE
18:18:24,8238720 vssvc.exe 1428 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Settings REPARSE Desired Access: Query Value
18:18:24,8238843 vssvc.exe 1428 RegQueryValue HKLM\System\CurrentControlSet\Services\VSS\Settings\TornComponentsMax NAME NOT FOUND Length: 144
18:18:24,8238945 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\volsnap REPARSE Desired Access: Read, Maximum Allowed
18:18:24,8239204 svchost.exe 11108 RegQueryValue HKLM\System\CurrentControlSet\Services\volsnap\MinDiffAreaFileSize NAME NOT FOUND Length: 134
18:18:24,8241297 svchost.exe 11108 IRP_MJ_DEVICE_CONTROL C: FAST IO DISALLOWED Control: IOCTL_VOLSNAP_QUERY_DIFF_AREA_MINIMUM_SIZE
18:18:24,8241588 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\volsnap REPARSE Desired Access: Read, Maximum Allowed
18:18:24,8241824 svchost.exe 11108 RegQueryValue HKLM\System\CurrentControlSet\Services\volsnap\MinDiffAreaFileSize NAME NOT FOUND Length: 134
18:18:24,8243149 svchost.exe 11108 IRP_MJ_DEVICE_CONTROL \Device\HarddiskVolumeShadowCopy1 FAST IO DISALLOWED Control: IOCTL_VOLUME_GET_GPT_ATTRIBUTES
18:18:24,8244722 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\FiringInterfaceIID NAME NOT FOUND Length: 144
18:18:24,8244731 svchost.exe 11108 IRP_MJ_DEVICE_CONTROL \Device\HarddiskVolume2 FAST IO DISALLOWED Control: IOCTL_VOLSNAP_QUERY_DIFF_AREA_MINIMUM_SIZE
18:18:24,8245351 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\CustomConfigCLSID NAME NOT FOUND Length: 144
18:18:24,8245823 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\Description NAME NOT FOUND Length: 144
18:18:24,8246235 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\PublisherID NAME NOT FOUND Length: 144
18:18:24,8246619 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\MultiInterfacePublisherFilterCLSID NAME NOT FOUND Length: 144
18:18:24,8247038 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\ParallelFiringTimeout NAME NOT FOUND Length: 144
18:18:24,8247430 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\AllowPerUserInprocActivation NAME NOT FOUND Length: 144
18:18:24,8247806 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\AllowPerUserActivateAsActivator NAME NOT FOUND Length: 144
18:18:24,8247990 svchost.exe 11108 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Volumes\Associations\{3bc7db5b-0000-0000-0000-100000000000} REPARSE Desired Access: All Access
18:18:24,8248098 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\VSS\Volumes\Associations\{3bc7db5b-0000-0000-0000-100000000000} NAME NOT FOUND Desired Access: All Access
18:18:24,8248212 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\AllowPerUserMoniker NAME NOT FOUND Length: 144
18:18:24,8248588 svchost.exe 11108 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Volumes\Associations\{58fdcef1-6ef6-4105-995d-51c7dd3827ec} REPARSE Desired Access: All Access
18:18:24,8248679 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\VSS\Volumes\Associations\{58fdcef1-6ef6-4105-995d-51c7dd3827ec} NAME NOT FOUND Desired Access: All Access
18:18:24,8248696 svchost.exe 1924 RegQueryValue HKLM\SOFTWARE\Microsoft\EventSystem\{26c409cc-ae86-11d1-b616-00805fc79216}\EventClasses\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}\SerialFiringTimeout NAME NOT FOUND Length: 144
18:18:24,8249148 svchost.exe 11108 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Volumes\Associations\{b201d297-93e2-47a4-bae9-f52c7a6d492b} REPARSE Desired Access: All Access
18:18:24,8249219 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\VSS\Volumes\Associations\{b201d297-93e2-47a4-bae9-f52c7a6d492b} NAME NOT FOUND Desired Access: All Access
18:18:24,8249615 svchost.exe 11108 RegOpenKey HKLM\SYSTEM\CurrentControlSet\Services\VSS\Volumes\Associations\{45f32ccf-5555-4bc6-aa17-c6da6fda39ae} REPARSE Desired Access: All Access
18:18:24,8249683 svchost.exe 11108 RegOpenKey HKLM\System\CurrentControlSet\Services\VSS\Volumes\Associations\{45f32ccf-5555-4bc6-aa17-c6da6fda39ae} NAME NOT FOUND Desired Access: All Access
Die Verantwortlichen Prozesse scheinen zu sein: vssvc.exe, svchost.exe, Launchpad.exe, BackupLaunchpad.exe usw. Generell alles wenn im "Path" steht: VSS, Backup, Windows Server usw.
Das ganze File habe ich mal hier (link entfernt, Nobby1805) hochgeladen[/url] (41k Einträge). Evtl. hilft es dir ja weiter. Folgende Filter waren eingestellt:
- filter.png (26.34 KiB) 6099 mal betrachtet
Ich kann mit den Fehlern jedoch nicht wirklich was anfangen. FAST IO DISALLOWED, NAME NOT FOUND, REPARSE kommen öfters vor.
@Computerschutz:
- Computerschutz.png (34.78 KiB) 6099 mal betrachtet
Ich habe aber jetzt noch nichts deaktiviert. Vielleicht findest du ja was aus dem Log noch was raus.
Komisch an dem Ganzen ist, dass der Fehler immer wieder kommt/gekommen ist. Ist eine installierte Anwendung evtl. Schuld?