multisy Posted February 2, 2012 Report Share Posted February 2, 2012 The compare took 8 minutes, but creating snapshot took almost 7 hours; using multiserver 7.7.562; with client 7.7.114. This problem also occurs using OEM Professional 7.6.123; with client 7.6.107. This has been an ongoing problem since a Windows Update more than 5 or 6 months ago; on Winodws 7 x86 & x64 clients. + Normal backup using multisy-p at 1/30/2012 12:00 PM (Execution unit 1) To Backup Set Win 7 x86... - 1/30/2012 12:00:00 PM: Copying SSD (C:) on multisy-p File "C:\Boot\BCD": can't read, error -1020 ( sharing violation) File "C:\Boot\BCD.LOG": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Microsoft Antimalware\IMpService1F383481-F70E-4E7A-8B69-C4B4A23928E3.lock": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpScanCache-1.bin": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb": can't read, error -1020 ( sharing violation) File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb": can't read, error -1020 ( sharing violation) File "C:\System Volume Information\Syscache.hve": can't read, error -1020 ( sharing violation) File "C:\System Volume Information\Syscache.hve.LOG1": can't read, error -1020 ( sharing violation) File "C:\System Volume Information\Syscache.hve.LOG2": can't read, error -1020 ( sharing violation) File "C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}": can't read, error -1017 ( insufficient permissions) File "C:\System Volume Information\{67550f1a-46a5-11e1-9b2c-001742365963}{3808876b-c176-4e48-b7ae-04046e6cc752}": can't read, error -1017 ( insufficient permissions) File "C:\Users\Boss\NTUSER.DAT": can't read, error -1020 ( sharing violation) File "C:\Users\Boss\ntuser.dat.LOG1": can't read, error -1020 ( sharing violation) File "C:\Users\Boss\AppData\Local\Microsoft\Windows\UsrClass.dat": can't read, error -1020 ( sharing violation) File "C:\Users\Boss\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1": can't read, error -1020 ( sharing violation) .... File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1": can't read, error -1020 ( sharing violation) File "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\config\RegBack\DEFAULT": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\config\RegBack\SAM": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\config\RegBack\SECURITY": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\config\RegBack\SOFTWARE": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\config\RegBack\SYSTEM": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl": can't read, error -1020 ( sharing violation) File "C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl": can't read, error -1020 ( sharing violation) 1/30/2012 6:51:07 PM: Snapshot stored, 177.3 MB 1/30/2012 6:51:43 PM: Comparing SSD (C:) on multisy-p File "C:\Program Files\Diskeeper Corporation\Diskeeper\Volume{929BC4AF-8D57-11E0-91AD-806E6F6E6963}.dat": different modify date/time (set: 1/30/2012 1:10:07 PM, vol: 1/30/2012 6:09:38 PM) File "C:\ProgramData\Microsoft\Microsoft Antimalware\Support\MPLog-12052011-082509.log": different data size (set: 1,061,824, vol: 1,062,380) File "C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat": different modify date/time (set: 1/30/2012 1:33:09 PM, vol: 1/30/2012 6:52:45 PM) File "C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat": different modify date/time (set: 1/30/2012 1:33:09 PM, vol: 1/30/2012 6:53:06 PM) File "C:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM) File "C:\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM) File "C:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:38 PM) File "C:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 6:02:35 PM) File "C:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat": different modify date/time (set: 1/30/2012 1:12:17 PM, vol: 1/30/2012 4:04:30 PM) File "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.153.gthr": different data size (set: 2,278, vol: 4,164) File "C:\Windows\WindowsUpdate.log": different modify date/time (set: 1/30/2012 12:43:03 PM, vol: 1/30/2012 6:14:55 PM) File "C:\Windows\inf\setupapi.app.log": different modify date/time (set: 1/28/2012 5:15:01 PM, vol: 1/30/2012 6:49:56 PM) File "C:\Windows\Prefetch\AgGlFaultHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:42 PM) File "C:\Windows\Prefetch\AgGlFgAppHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:44 PM) File "C:\Windows\Prefetch\AgGlGlobalHistory.db": different modify date/time (set: 1/29/2012 6:45:38 AM, vol: 1/30/2012 4:00:40 PM) File "C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1935655697-179605362-1801674531-1120.db": different modify date/time (set: 1/29/2012 4:35:26 PM, vol: 1/30/2012 3:48:04 PM) File "C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1935655697-179605362-1801674531-1120.db": different modify date/time (set: 1/29/2012 4:35:26 PM, vol: 1/30/2012 3:47:40 PM) File "C:\Windows\Prefetch\AgRobust.db": different modify date/time (set: 1/29/2012 6:45:37 AM, vol: 1/30/2012 4:00:39 PM) File "C:\Windows\Prefetch\CONHOST.EXE-3218E401.pf": different modify date/time (set: 1/30/2012 1:00:01 PM, vol: 1/30/2012 6:12:52 PM) File "C:\Windows\Prefetch\CSRSS.EXE-8C04D631.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:51:02 PM) File "C:\Windows\Prefetch\LOGONUI.EXE-1BEE4A84.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:52:20 PM) File "C:\Windows\Prefetch\LongTermHist.db": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:46 PM) File "C:\Windows\Prefetch\LongTermHist.db.bt": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:40 PM) File "C:\Windows\Prefetch\LongTermHist.db.dx": different modify date/time (set: 1/30/2012 12:10:28 PM, vol: 1/30/2012 1:50:45 PM) File "C:\Windows\Prefetch\MPCMDRUN.EXE-DBF9CB7D.pf": different modify date/time (set: 1/30/2012 10:12:52 AM, vol: 1/30/2012 6:13:02 PM) File "C:\Windows\Prefetch\RTHLPSVC.EXE-24042594.pf": different modify date/time (set: 1/28/2012 12:23:32 PM, vol: 1/30/2012 1:44:36 PM) File "C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-AA7A1FDD.pf": different modify date/time (set: 1/30/2012 12:06:09 PM, vol: 1/30/2012 5:29:59 PM) File "C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-AFAD3EF9.pf": different modify date/time (set: 1/30/2012 12:06:09 PM, vol: 1/30/2012 5:29:57 PM) File "C:\Windows\Prefetch\SMSS.EXE-1DCD0EB1.pf": different modify date/time (set: 1/29/2012 6:35:14 AM, vol: 1/30/2012 3:50:50 PM) File "C:\Windows\Prefetch\SVCHOST.EXE-74432B26.pf": different modify date/time (set: 1/29/2012 7:12:56 AM, vol: 1/30/2012 3:45:34 PM) File "C:\Windows\Prefetch\SVCHOST.EXE-8FD92526.pf": different modify date/time (set: 1/30/2012 12:00:12 AM, vol: 1/30/2012 1:39:30 PM) File "C:\Windows\Prefetch\TASKHOST.EXE-437C05A8.pf": different modify date/time (set: 1/30/2012 1:10:27 PM, vol: 1/30/2012 6:07:54 PM) File "C:\Windows\Prefetch\VSSVC.EXE-04D079CC.pf": different modify date/time (set: 1/30/2012 12:00:11 AM, vol: 1/30/2012 1:39:29 PM) File "C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf": different modify date/time (set: 1/29/2012 6:35:19 AM, vol: 1/30/2012 3:51:22 PM) File "C:\Windows\Prefetch\WISPTIS.EXE-6C347CFA.pf": different modify date/time (set: 1/29/2012 6:08:12 AM, vol: 1/30/2012 3:52:32 PM) File "C:\Windows\rescache\rc0007\ResCache.hit": different modify date/time (set: 1/30/2012 12:12:53 PM, vol: 1/30/2012 6:07:44 PM) File "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\MpCmdRun.log": different modify date/time (set: 1/30/2012 10:13:50 AM, vol: 1/30/2012 6:14:56 PM) File "C:\Windows\SoftwareDistribution\DataStore\DataStore.edb": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:47 PM) File "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:55 PM) File "C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log": different modify date/time (set: 1/30/2012 10:18:48 AM, vol: 1/30/2012 6:18:56 PM) File "C:\Windows\System32\LogFiles\Scm\9b75c702-ea13-406a-badb-6c588ee4375b": different modify date/time (set: 1/30/2012 10:07:40 AM, vol: 1/30/2012 6:07:44 PM) File "C:\Windows\System32\LogFiles\Scm\a1cfa52f-06f2-418d-addb-cd6456d66f43": different modify date/time (set: 1/30/2012 1:10:17 PM, vol: 1/30/2012 6:00:24 PM) File "C:\Windows\System32\LogFiles\Scm\de8bae53-2809-4f75-85ef-427d364b9b2c": different modify date/time (set: 1/30/2012 10:07:40 AM, vol: 1/30/2012 6:07:42 PM) File "C:\Windows\System32\wbem\Repository\INDEX.BTR": different modify date/time (set: 1/30/2012 1:18:22 PM, vol: 1/30/2012 3:14:27 PM) File "C:\Windows\System32\wbem\Repository\MAPPING2.MAP": different modify date/time (set: 1/30/2012 1:36:21 AM, vol: 1/30/2012 3:14:27 PM) File "C:\Windows\System32\wbem\Repository\OBJECTS.DATA": different modify date/time (set: 1/30/2012 1:18:22 PM, vol: 1/30/2012 3:14:23 PM) File "C:\Windows\System32\wfp\wfpdiag.etl": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Folder Redirection%4Operational.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NlaSvc%4Operational.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\Security.evtx": didn't compare File "C:\Windows\System32\winevt\Logs\System.evtx": didn't compare File "C:\Windows\Temp\MpCmdRun.log": different modify date/time (set: 1/30/2012 10:13:51 AM, vol: 1/30/2012 6:14:55 PM) 1/30/2012 6:59:53 PM: 71 execution errors Completed: 420 files, 5.2 GB, with 2% compression Performance: 102.1 MB/minute (55.3 copy, 654.1 compare) Duration: 06:59:52 (05:16:19 idle/loading/preparing) Quote Link to comment Share on other sites More sharing options...
Lennart_T Posted February 2, 2012 Report Share Posted February 2, 2012 Building snapshot is when Retrospect backs up the Windows' registry. We had one client that took over three hours to build the snapshot on. The solution was to wipe the hard drive and re-install Windows and the applications. Quote Link to comment Share on other sites More sharing options...
multisy Posted February 8, 2012 Author Report Share Posted February 8, 2012 That is not a solution to the problem just a reason to use different backup software. Looking at Process Explorer the pcpds.exe Process moves through files (Handles) very slowly while using high CPU, a fix to pcpds.exe client-side would be a better resolution. Quote Link to comment Share on other sites More sharing options...
Lennart_T Posted February 15, 2012 Report Share Posted February 15, 2012 That is not a solution to the problem just a reason to use different backup software. Looking at Process Explorer the pcpds.exe Process moves through files (Handles) very slowly while using high CPU, a fix to pcpds.exe client-side would be a better resolution. Well, pcpds just calls the standard Windows' APIs, just like any other backup software. So i's Microsoft that needs to speed up their registry access. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.