Virus? Duplicate csrss.exe and winlogon.exe files outside Windows/System32

Hi,
My computer has been running extremely slowly while performing normal tasks (i.e. web browsing, typing).
I found a second copy of 'csrss.exe', which as I understand is frequently a trojan. The copy is located in the following file path:
C:\Windows\winsxs\x86_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_58ba39fb456943bd
I also found two extra copies of 'winlogon.exe', at the following paths, as well as in Windows\System32:
C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166
C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500
I ran the Norton antivirus scan, the Norton Power Eraser, a few csrss.exe-targeted scans, and spyware search & destroy, none of which detected a virus. I tried moving/renaming the file, but this is denied by the system.
I used Windows Process Explorer, and the first time,  both csrss.exe & winlogon.exe were verified as system processes. This time I ran and the processes have no info (Version: n/a; Build Time: n/a; Path: [Error opening process]).
I'm running Windows 7 Professional on a local domain.
Thanks in advance for your advice.

SOF
The second copy is a backup and in that location probably normal.  I doubt malware is the cause of your system running slow more likely system corruption
Please provide us with your Event Viewer administrative logs by following these steps:
Click Start Menu
Type eventvwr into Search programs and files (do not hit enter)
Right click eventvwr.exe and click Run as administrator
Expand Custom Views
Click Administrative Events
Right click Administrative Events
Save all Events in Custom View As...
Save them in a folder where you will remember which folder and save as Errors.evtx
Go to where you saved Errors.evtx
Right click Errors.evtx -> send to -> compressed (zipped) folder
Upload the .zip file to Onedrive or a file sharing service and put a link to it in your next post
If you have updated to win 8.1 and you get the error message "the system cannot find the file specified" it is a known problem.  The
work around is to edit the registry.  If you are not comfortable doing this DONT.  If you are, backup the key before you do
Press Win+"R" and input regedit
Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels. Delete "Microsoft-Windows-DxpTaskRingtone/Analytic"
Wanikiya and Dyami--Team Zigzag

Similar Messages

  • Faulting application name: w3wp.exe - and Faulting module path: C:\Windows\system32\KERNELBASE.dll

    The environment is aSharepoint2010 and ProjectServer2010we hadlast nighta crach ofapplication poolwithan error on thew3wpandkernelbase.
    We canrevivetheappbutthe firstaccess to the sitewe have thew3wpcrash.
    we did adumpand here are thedetails.
    Information 12/08/2014 15:28:45 Windows Error Reporting 1001 None
    Fault bucket , type 0
    Event Name: APPCRASH
    Response: Not available
    Cab Id: 0
    Problem signature:
    P1: w3wp.exe
    P2: 7.5.7601.17514
    P3: 4ce7afa2
    P4: KERNELBASE.dll
    P5: 6.1.7601.18409
    P6: 5315a05a
    P7: c06d007e
    P8: 000000000000940d
    P9:
    P10:
    Attached files:
    These files may be available here:
    Analysis symbol:
    Rechecking for solution: 0
    Report Id: 9561bd5d-2224-11e4-9566-0050569a0110
    Report Status: 0
    Error 12/08/2014 15:28:46 Application Error 1000 (100)
    Faulting application name: w3wp.exe, version: 7.5.7601.17514, time stamp:
    0x4ce7afa2
    Faulting module name: KERNELBASE.dll, version: 6.1.7601.18409, time stamp: 0x5315a05a
    Exception code: 0xc06d007e
    Fault offset: 0x000000000000940d
    Faulting process id: 0x15d0
    Faulting application start time: 0x01cfb6315831ebbb
    Faulting application path: c:\windows\system32\inetsrv\w3wp.exe
    Faulting module path: C:\Windows\system32\KERNELBASE.dll
    Report Id: 95eaafc7-2224-11e4-9566-0050569a0110
    Warning 12/08/2014 15:28:51 WAS 5011 None
    A process serving application pool 'SharePoint Central Administration v4'
    suffered a fatal communication error with the Windows Process Activation
    Service. The process id was '2448'. The data field contains the error number
    Error 12/08/2014 15:28:51 WAS 5002 None
    Application pool 'SharePoint Central Administration v4' is being automatically
    disabled due to a series of failures in the process(es) serving that
    application pool.
    Le dump du crach donne les informations suivantes
    (990.fb4): Unknown exception - code c06d007e (first/second chance not
    available)
    KERNELBASE!RaiseException+0x39:
    000007fe`fda5940d 4881c4c8000000 add rsp,0C8h
    0:004> .loadby sos clr
    Unable to find module 'clr'
    0:004> .loadby sos clr
    Unable to find module 'clr'
    0:004> !analyze -v
    * Exception Analysis *
    GetPageUrlData failed, server returned HTTP status 404
    URL requested:
    http://watson.microsoft.com/StageOne/w3wp_exe/7_5_7601_17514/4ce7afa2/KERNELBASE_dll/6_1_7601_18409/5315a05a/c06d007e/0000940d.htm?Retriage=1
    FAULTING_IP:
    KERNELBASE!RaiseException+39
    000007fe`fda5940d 4881c4c8000000 add rsp,0C8h
    EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
    ExceptionAddress: 000007fefda5940d (KERNELBASE!RaiseException+0x0000000000000039)
    ExceptionCode: c06d007e
    ExceptionFlags: 00000000
    NumberParameters: 1
    Parameter[0]: 000000000092e820
    DEFAULT_BUCKET_ID: APPLICATION_FAULT
    PROCESS_NAME: w3wp.exe
    ERROR_CODE: (NTSTATUS) 0xc06d007e -
    <unable code="" error="" get="" text="" to="">
    EXCEPTION_CODE: (NTSTATUS) 0xc06d007e -
    <unable code="" error="" get="" text="" to="">
    EXCEPTION_PARAMETER1: 000000000092e820
    MOD_LIST:
    <analysis>
    NTGLOBALFLAG: 0
    APPLICATION_VERIFIER_FLAGS: 0
    MANAGED_STACK: !dumpstack -EE
    OS Thread Id: 0xfb4 (4)
    Child-SP RetAddr Call Site
    FAULTING_THREAD: 0000000000000fb4
    PRIMARY_PROBLEM_CLASS: APPLICATION_FAULT
    BUGCHECK_STR: APPLICATION_FAULT_APPLICATION_FAULT
    LAST_CONTROL_TRANSFER: from 000007fee99ed41d to 000007fefda5940d
    STACK_TEXT:
    00000000`0092e730 000007fe`e99ed41d : 00000000`00000000 00000000`00000000
    00000000`00000391 000007fe`e9b40cd0 : KERNELBASE!RaiseException+0x39
    00000000`0092e800 000007fe`e996d57f : 000007fe`e9c78e70 00000000`0092e820
    00000000`00000000 00000000`00000000 : OWSSVR!DllCanUnloadNow+0x8cfad
    00000000`0092e8b0 000007fe`e96c5244 : 00000000`0000000d 00000000`010dd4f0
    0000000f`001d000b 00000010`001a000c : OWSSVR!DllCanUnloadNow+0xd10f
    00000000`0092e920 000007fe`e96c5313 : 00000000`00000000 00000000`00328ad0
    00000000`778d4564 000007fe`e9c78e28 : OWSSVR!TerminateExtension+0x158
    00000000`0092eaa0 000007fe`e96c5379 : 00000000`0128fcd0 00000000`000000a4
    00000000`00000024 000007fe`faf11827 : OWSSVR!TerminateExtension+0x227
    00000000`0092ebf0 000007fe`e96c18d8 : 00000000`00000000 00000000`00000000
    00000000`01290840 00000000`00000021 : OWSSVR!TerminateExtension+0x28d
    00000000`0092ec20 000007fe`cf5cf94a : 00000000`00000000 00000000`01290840
    00000000`01290840 00000000`0128f800 : OWSSVR!RegisterModule+0x1c
    00000000`0092ec50 000007fe`cf5d9aa4 : 00000000`00000000 00000000`00000000
    00000000`00000000 00000000`00000000 : iiscore!VIRTUAL_MODULE::RegisterModule+0x2a
    00000000`0092ec80 000007fe`cf5daeeb : 00000000`00000078 000007fe`cf5ba944
    00000000`0128f800 000007fe`cf5e87b8 :
    iiscore!W3_SERVER::LoadModulesFromConfig+0x394
    00000000`0092eda0 000007fe`cf5dc2ff : 00000000`0128f800 000007fe`cf5e87b8
    00000000`00000000 00000000`0121fb10 :
    iiscore!W3_SERVER::InitializeGlobalModules+0x3b
    00000000`0092ede0 000007fe`cf5e234d : 00000000`0128f800 00000000`00000002
    00000000`0121fb10 00000000`0000017c : iiscore!W3_SERVER::Initialize+0xaaf
    00000000`0092f040 000007fe`cf5e2405 : 00000000`0128f6b0 00000000`00000000
    00000000`00000000 00000000`0000000c :
    iiscore!IISCORE_PROTOCOL_MANAGER::InitializeGlobals+0x1fd
    00000000`0092f2e0 000007fe`e27a9316 : 00000000`00000000 00000000`00000000
    00000000`005fa7e0 00000000`00000000 :
    iiscore!IISCORE_PROTOCOL_MANAGER::PreloadApplication+0x45
    00000000`0092f320 000007fe`e27a7dd2 : 00000000`005ff4b0 00000000`77997ef5
    00000000`0128f6b0 00000000`0021f070 :
    w3wphost!WP_IPM::HandlePreloadApplications+0xc2
    00000000`0092f370 000007fe`faf141f3 : 00000000`005ff508 00000000`00000000
    00000000`00000000 00000000`00000000 : w3wphost!WP_IPM::AcceptMessage+0x16e
    00000000`0092f3b0 00000000`77bbc251 : 00000000`00000000 00000000`003b3bf0
    00000000`00000000 00000000`0000000c : iisutil!IPM_MESSAGE_PIPE::MessagePipeCompletion+0x44f
    00000000`0092f430 00000000`77bc658c : 00000000`003b3b40 00000000`003693f0
    00000000`0092f5e8 00000000`00000000 : ntdll!RtlpTpWaitCallback+0x92
    00000000`0092f480 00000000`77bd0c56 : 00000000`0035d110 00000000`77cb45e8 00000000`00000000
    00000000`77cb4610 : ntdll!TppWaitpExecuteCallback+0x10c
    00000000`0092f4e0 00000000`779a59ed : 00000000`00000000 00000000`00000000
    00000000`00000000 00000000`00000000 : ntdll!TppWorkerThread+0x5ff
    00000000`0092f7e0 00000000`77bdc541 : 00000000`00000000 00000000`00000000
    00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd
    00000000`0092f810 00000000`00000000 : 00000000`00000000 00000000`00000000
    00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
    STACK_COMMAND: ~4s; .ecxr ; kb
    FOLLOWUP_IP:
    OWSSVR!DllCanUnloadNow+8cfad
    000007fe`e99ed41d 488b442458 mov rax,qword ptr [rsp+58h]
    SYMBOL_STACK_INDEX: 1
    SYMBOL_NAME: owssvr!DllCanUnloadNow+8cfad
    FOLLOWUP_NAME: MachineOwner
    MODULE_NAME: OWSSVR
    IMAGE_NAME: OWSSVR.DLL
    DEBUG_FLR_IMAGE_TIMESTAMP: 51c91cf5
    FAILURE_BUCKET_ID: APPLICATION_FAULT_c06d007e_OWSSVR.DLL!DllCanUnloadNow
    BUCKET_ID: X64_APPLICATION_FAULT_APPLICATION_FAULT_owssvr!DllCanUnloadNow+8cfad
    WATSON_STAGEONE_URL:
    http://watson.microsoft.com/StageOne/w3wp_exe/7_5_7601_17514/4ce7afa2/KERNELBASE_dll/6_1_7601_18409/5315a05a/c06d007e/0000940d.htm?Retriage=1
    Followup: MachineOwner </analysis></unable></unable>

    Hello Roland_Zeki,
    Can you check System in the Windows Log of Event Viewer? Maybe you have some logon failure for one of the services, like in this blog:
    http://www.shareesblog.com/?p=363
    - Dennis | Netherlands | Blog |
    Twitter
    Yes I have verify this point I suspected to be the origine of the problem. But no, the accounts have fixed password and are not locked. I test this point with a valide login on the server, and I reenter the login password for each app pool.

  • EMET 5.1 crashes Outlook.exe, Photoshop.exe and Communicator.exe. Please explain why it would do that?

    Hi,
    EMET 5.1 is crashing/not opening these applications on two of our staff workstations (Both are Windows 7 x86):  Outlook.exe, Photoshop.exe and Communicator.exe.
    One computer, EMET crashes Communicator and Outlook.  The other Computer, the EMET crashes Photoshop only.
    Obviously, it works for everybody else.  Can someone please explain to me why would EMET crash these apps if it works for the rest?  Could it be that it found a possible threat/exploit to the machine? 
    How do I mitigate this problem?
    Please advise.  Below is a sample of the error.
    Fault bucket 1031393421, type 17
    Event Name: APPCRASH
    Response: Not available
    Cab Id: 0
    Problem signature:
    P1: communicator.exe
    P2: 4.0.7577.4103
    P3: 4fd6bebb
    P4: EMET.DLL
    P5: 5.0.0.0
    P6: 545ffd74
    P7: c0000005
    P8: 00060310
    P9: 
    P10: 
    Attached files:
    C:\Users\xx\AppData\Local\Temp\WERD21D.tmp.WERInternalMetadata.xml
    These files may be available here:
    C:\Users\xx\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_communicator.exe_7fba75e97ffde076db3fe52dd74029de19dc38_15d4e56e
    Analysis symbol: 
    Rechecking for solution: 0
    Report Id: 97ed67e2-de0a-11e4-822e-00125a5e8f35
    Report Status: 0
    Faulting application name: Photoshop.exe, version: 15.2.2.310, time stamp: 0x5480306d
    Faulting module name: EMET.DLL, version: 5.0.0.0, time stamp: 0x545ffd74
    Exception code: 0xc0000005
    Fault offset: 0x0006714e
    Faulting process id: 0x15c4
    Faulting application start time: 0x01d0721e6fc383e7
    Faulting application path: C:\Program Files\Adobe\Adobe Photoshop CC 2014 (32 Bit)\Photoshop.exe
    Faulting module path: C:\WINDOWS\AppPatch\EMET.DLL
    Report Id: b159a74a-de11-11e4-86b9-1cc1de578f37

    One guess is that old Outlook plugins can sometimes cause issues with EMET.  Try starting Outlook in safe mode, by holding down the CTRL key when starting Outlook to see if that helps, and look in Outlook in File / Options / Add-Ins menu item to see
    the add-ons that are installed.  Verify that the OS and apps have all the latest patches if you haven't, though you have probably already done that.  If those don't work you could try unchecking the EMET application protection boxes for the
    application that isn't working, one by one.  Note that EMET 5.2 is out now so that might be something to try too. 

  • Oracle.exe and java.exe are running my CPU 100% under XP Prof SP3

    11gR1
    oracle.exe and java.exe are running 100% CPU
    I have increased virtual memory to 4 gig
    I have defragmented the drive.
    I checked the drive for errors.
    I am searching the whole drive for viruses
    I do not have the problem with Redhat Fedora 12 running 11gR1
    I have 1 gig of RAM but cannot install release 2 because the installer expects
    1 gig + 1

    ooops!!! left that off...sorry
    XP Prof SP3 32 bit..*.no problem with Redhat Fedora 12 running MySQL and 11gR1*
    1 gig RAM Dell precision W/S 1.5 Gig rate 74 GiG SCSI HD 15000 RPM
    Don't pass out but I am also running MySQL server 5.1.41 and MS SQL Server Express 2008.
    Lucky it didn't catch fire
    I installed XP prof months ago but this CPU domination occurred only starting last night!
    However slow everything works in 11gR1
    sqlplus myname/password and then select rows from table
    sqldeveloper
    PHP web sites
    I've had plenty of trouble with Java running slow and hogging memory!
    Edited by: landonmkelsey on May 2, 2010 12:21 PM
    Edited by: landonmkelsey on May 2, 2010 12:24 PM
    Let me guess...stop services for MySQL and MS SQL Server and see what happens!
    Edited by: landonmkelsey on May 2, 2010 12:26 PM

  • Adobe Premiere Pro.exe and Dynamiclinkmanager.exe *32  not stopping after closing PP CS6.03

    PP 6.03 will not restart after closing program.  When I try to re-start nothing happens when clicking on the PP6 icon. Looked in task manager and found that Adobe Premiere Pro.exe and Dynamiclinkmanager.exe *32  are not stopping after closing program. Once I manually stop the processes PP will restart as normal. This is on Win 7 Sp1, HP Elitebook 8760W Matrox MXO2 LE. Also Audio meters are not active during capture, can't change clip name during capture.

    Hello Elcuad, and Canino video,
    Please verify the following steps and report back  your findings:
    - uninstall the currently installed MXO2 effects and drivers
    - go to control panel - user accounts - and locate the account you are using, then drop down the UAC level all the way, ok and reboot
    - download our 7.02 driver with Internet Explorer, followed by our effects
    - after the files are downloaded, right click each file, go to properties, and confirm they are not blocked, if they are click the unblock button
    - reinstall the Matrox driver, again, the one we just downloaded, followed by the effects, reboot
    - go to start, all programs and locate the premiere icon, hold shift and ctrl keys down, and launch this particular icon, keeping the keys down until the application opens up
    - please build a new project and try it out

  • Install vstf_testagent.exe and vstf_testcontroller.exe on remote machine and configure

    Hi,
    I am creating a form application where I want to install vstf_testagent.exe and vstf_testcontroller.exe on remote machine and configure it. I copied the files to the remote machine local directory, wanted to know how to install exe on remote machine and
    configure it. could some one help me with code.
    Thanks
    Thanks,

    Hi sayedfarhan,
    Thank you for posting in MSDN forum.
    >>I am creating a form application where I want to install vstf_testagent.exe and vstf_testcontroller.exe on remote machine and configure it.
    According to your issue, as you said that you want to install vstf_testagent.exe and vstf_testcontroller.exe on remote machine and configure it.
    So please you refer the following MSDN document to install and configure the test agent and test controller on this remote machine.
    https://msdn.microsoft.com/en-us/library/dd648127.aspx?f=255&MSPPError=-2147217396
    Generally, I know that we used this test controller and test agent to run automated tests on remote machine. Note:I know that if you want to install and configure test agent and test controller for automated test, it will not need to any code for
    it.
    So whether your issue is related to run your automated tests remotely with the test agent and test controller.
    In addition, as you said that:
    >>I am creating a form application where I want to install vstf_testagent.exe and vstf_testcontroller.exe on remote machine and configure it. 
    Could you please tell me whether you want to install and configure the test controller and test agent for your form app?  
    If I misunderstanding your issue, please tell me more detailed message about your issue.
    Best Regards, 
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • How do I close RSO3MiddleTierService.exe and RSO3Server.exe to install TCS 3.5

    Install of TCS 3.5 wants me to close RSO3MiddleTierService.exe and RSO3Server.exe. As far as I know I don't have these two files open so I don't know what to do next?  Help!

    Thank you! That worked, and I finished the install. I can't find my original
    question in the forum so I'm replying directly.
    Now that I've finished the installer, is there anything I need to do to
    check that these updated files are pulled into the programs I want to use?
    Or is there some other step I need to take?
    Thanks again, Chris

  • What is the difference between ODTwithODAC....exe and ODAC.exe ?

    I found two downloadble files ODTwithODAC....exe and ODAC.exe?
    Ok, they contain Oracle Data Provider for .NET but why are there two versions ?
    Do they contain a full Oracle Express 10g installation or are they ADDITIONAL files
    (additional to the actual OracleExpress 10g) ?
    Or asked the other way: If I install Oracle Express 10g, are then Oracle Data Provider for.NET installed as well or not ?

    I found two downloadble files ODTwithODAC....exe and
    ODAC.exe?
    Ok, they contain Oracle Data Provider for .NET but
    why are there two versions ?
    Check following Thread
    Re: ODAC and Oracle Developer Tools for Visual Studio .NET Install Problems
    Do they contain a full Oracle Express 10g
    installation or are they ADDITIONAL files
    (additional to the actual OracleExpress 10g) ?
    No , they don't contain full Oracle Express 10g . they are just Oracle Data Access Components (ODAC) for Windows
    For more details Check=> .NET Developer Center
    Or asked the other way: If I install Oracle Express
    10g, are then Oracle Data Provider for.NET installed
    as well or not ?No , you need to install it, check following details about it
    Oracle Database Express Edition 2 Day Plus .NET Developer Guide
    # Virag Sharma

  • Error report on win 8.1 about conhost.exe and werfault.exe

    I am not sure exactly what is happening, but I have noticed recently a new problem with CONHOST.EXE and werfault.exe each time I was opened application. and I didn't know exactly about was there have relationship  with my brightness  control
    (increase or decrease) than I can't make any change after first time I have noticed about conhost.exe and werfault.exe. and other problem than my laptop more 'slowly' than before, but the console window will remain open fastly enough. (The host process
    exists, but I can see an orphaned CONHOST.EXE for the application in Task Manager.)
    I hope someone who sees this knows why this is happening, and can help me fix the problem.
    Thanks!

    Hi,
    Here is the details about conhost.exe process:
    Windows 7 / Windows Server 2008 R2: Console Host
    http://blogs.technet.com/b/askperf/archive/2009/10/05/windows-7-windows-server-2008-r2-console-host.aspx
    Same within Windows 8.
    The werfault.exe is used for Windows Error Reporting.
    You can go to event viewer to check if there are any error messages.
    For this kind of issue, you may also try Clean Boot to see if this problem persists.
    Alex Zhao
    TechNet Community Support

  • What's the difference between Acrobat.exe and AcroRd32.exe?

    What's the difference between Acrobat.exe and AcroRd32.exe?

    acrobat.exe is part of Adobe Acrobat and acrord32.exe is part of Adobe Reader.

  • What can i do for syncserver.exe and mobiledevice.exe error?

    hello i have a problem with iTunes.....
    When i plug the phone to computer, itunes get a error:
    synserver.exe,mobiledevicehelper.exe and mobilebackup.exe stopped the working.....
    please help

    Thank you Barbara, for your feedback. I actually got a person in the Adobe chat room to walk me to this link http://helpx.adobe.com/creative-suite/kb/error-licensing-stopped-windows.html . Solution 1 did not work, but Solution 2 worked like a charm. I appreciated the fix!

  • Java JDK 6 without tools javac.exe and jdk.exe in bin directory!

    I miss in the new current JDK 6 download the tools jdb.exe and javac.exe in the bin directory. Is that an incomplete download?
    Wolfgang

    I miss in the new current JDK 6 download the tools
    jdb.exe and javac.exe in the bin directory. Is that
    an incomplete download?You have downloaded a client version of java. You need a development version. You should probably go back and download again, this time making sure that you're getting the entire JDK

  • Re: Satellite C slow due to osIndicator.exe and tosKillerindicator.exe

    Hi!
    In my laptop appear 2 errors called tosIndicator.exe and tosKillerindicator.exe and because of that it is very slow and gets stuck, anyone could hel me?
    I cant remove Toshiba WLAN.

    Your posting is very confusing and maybe you should offer more info.
    Which model do you have exactly?
    Which operating system do you use?
    Do you use original OS that you got with your notebook?
    Why do you want to remove Toshiba WLAN?

  • How do I prevent iTunesHelper.exe and iPodService.exe from start-up?

    How do I prevent iTunesHelper.exe and iPodService.exe from starting every time I boot my PC. I want them to start only when I start iTunes.
    Thanks!
    Dave
    St. Louis

    Hi,
    iChat version through from version 2 to version 6 allowed you to choose whether to Save Transcripts of iChats.
    It was a setting in the App Menu > Preferences > Messages pane.
    In Messages beta this now longer happens and "Saving" is obligatory.
    By default the Chats are stored in a folder called iChats and this is normally in the Documents folder.  (they are still called iChats in Messages).
    In addition Messages Beta also stores some iMessage info in the Home Folder/Library/Messages
    You can access this via the Finder > Go Menu and holding the ALT ley to see the Library listing (It is normally invisible)
    The info is held in the chat-db database.
    At present you cannot turn Off saving the transcripts.
    10:17 PM      Friday; June 8, 2012
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
      iMac 2.5Ghz 5i 2011 (Lion 10.7.4)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb (Snow Leopard 10.6.8)
     Mac OS X (10.7.4),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • CF Startup Errors: swsoc.exe and swagent.exe

    I've installed CF Standard on a new box and am receiving
    Windows startup errors for swagent.exe and swsoc.exe. Two of the CF
    services (ODBC Server and ODBC Agent) also will not run - I believe
    the two events are related.
    Does anybody have any suggestions or experience with
    this?

    Thanks. I reinstalled - no change. I applied the latest MX
    updates - no change. I reset my personal firewall (McAfee) to the
    default values and this time allowed all the verity programs (3 or
    4) access to the Internet - low and behold, fixed.
    My guess is that there is some sort of "call home to mama"
    code that fails miserably if it can't.

Maybe you are looking for