Yesterday I had a user with the "Crop Circles of Death". I had the luxury of trying to do some of the troubleshooting recommended above by SLHV.
I must admit using the Procmon utility is something new to me and I am not sure if I was able to detect anything relevant.
I should also mention I tried using the Windows Easy Transfer tool to "pretend" that I was moving the User's Profile to another machine. I followed the tools prompts and exported the user's profile to the hard drive and then reversed the process and "transferred" the user to the same PC (i.e. imported the user's profile). Unfortunately this did NOT resolve the "crop circles" issue. This would have been a much simpler and faster fix to the Crop Circles issue compared to deleting the users profile and adding it back which is the only fix i have found to work so far.
Below is an excerpt from the Procmon log during a period of Crop Circles (filtering on the CPOPM06.exe process). Any thoughts if the errors highlighted in bold are significant or not?
11:47:30.8697833 AM CPOPM06.exe 6416 RegQueryKey HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} SUCCESS Query: HandleTags, HandleTags: 0x401
11:47:30.8697972 AM CPOPM06.exe 6416 RegOpenKey HKCU\Software\Classes\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} NAME NOT FOUND Desired Access: Maximum Allowed
11:47:30.8698072 AM CPOPM06.exe 6416 RegQueryValue HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66}\(Default) SUCCESS Type: REG_SZ, Length: 26, Data: RowsetHelper
11:47:30.8698158 AM CPOPM06.exe 6416 RegQueryKey HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} SUCCESS Query: Name
11:47:30.8698237 AM CPOPM06.exe 6416 RegQueryKey HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} SUCCESS Query: HandleTags, HandleTags: 0x401
11:47:30.8698370 AM CPOPM06.exe 6416 RegOpenKey HKCU\Software\Classes\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} NAME NOT FOUND Desired Access: Maximum Allowed
11:47:30.8698459 AM CPOPM06.exe 6416 RegQueryValue HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66}\(Default) SUCCESS Type: REG_SZ, Length: 26, Data: RowsetHelper
11:47:30.8698555 AM CPOPM06.exe 6416 RegQueryKey HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} SUCCESS Query: Name
11:47:30.8698638 AM CPOPM06.exe 6416 RegQueryKey HKCR\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66} SUCCESS Query: HandleTags, HandleTags: 0x401
11:47:30.8698777 AM CPOPM06.exe 6416 RegOpenKey HKCU\Software\Classes\Wow6432Node\CLSID\{92396AD0-68F5-11D0-A57E-00A0C9138C66}\InprocServer32 NAME NOT FOUND Desired Access: Read
Thanks,
Mike
Posted : May 12, 2015 5:06 am